Bonum Certa Men Certa

Crypto AG tricked ETH Zurich student internship

posted by Roy Schestowitz on Nov 08, 2025

15:00 Fri, 07 Nov 2025

Reprinted with permission from Daniel Pocock.

In 2020, news reports around the world revealed that a Swiss IT security company, Crypto AG, had secretly been owned by the CIA and the German spy agency since 1970.

The story is not unique. A similar story emerged about the ANOM app and Operation Trojan Shield. However, the latter involved a much wider collaboration with the justice department while the Crypto AG operation ran for a much longer period of time and with much less, if any, oversight.

For most ordinary people, the moral of the story is clear: don't do bad stuff.

More significantly, if you don't have the knowledge to fully understand computer security and encryption, it is always better not to use it at all.

Students in computer science and engineering courses are being prepared to work with this technology in a professional environment. ETH Zurich is one of Switzerland's top universities and their graduates go on to become responsible for information security in leading Swiss institutions. Diana von Bidder-Senn, the wife of Adrian von Bidder-Senn, completed her PhD on the theme of computer security, I contemplate that in a related blog post.

One of the ETH Zurich students, Marco Fischer completed an internship at Crypto AG. He wrote an article about the internship, in German, for the student newspaper. Here is a translation:

Internship at Crypto AG

The company description reads: Crypto AG, a financially and legally independent Swiss company, has been a leader in information technology since 1952. The company specializes in the deployment of security solutions in all types of communication networks.

The Message Scheduler

Crypto AG develops encryption devices that can be administered from a remote management station. This requires distributing management messages to the devices via an IP network at a defined time and receiving corresponding acknowledgments from the devices. This functionality is to be implemented in a message scheduler, which is placed between the management station and the public network containing the end devices.

My task was to create a PC application that simulates the message scheduler as a partner of the management station for testing purposes and enables interaction. The main functions of this application were receiving, analyzing, displaying, and persistently storing messages, as well as sending and receiving receipts. In a second step, I extended the message scheduler application for communication with end devices.

On the technical side, development involved object-oriented modeling with UML using a modeling tool. Implementation was done in C++ with MFC (Microsoft Foundation Classes). The development environment was Microsoft's Visual Studio .NET. Source code management using PVCS was also part of the process, as were ongoing tests and the integration of the individual components.

Learning new things – Gathering information – Applying knowledge

At the beginning of the internship, the first challenge was absorbing a huge amount of new information, structuring it, and not forgetting it immediately. During the first few weeks, I often found myself in situations where I had learned or heard about certain things, but still lacked that final piece of understanding.

(Like everybody else who was tricked by this operation)

However, I could count on a very helpful team.

(Team = CIA and BND working together)

Every question was answered patiently, and every problem was resolved promptly and easily. At this point, I would like to sincerely thank everyone who supported me in any way during this internship! As the weeks passed, I gradually got used to the new, initially unfamiliar environment. I became more familiar with the tools used daily, and the work transformed more and more from simply absorbing and learning to the creative implementation of my own ideas and solutions. As soon as the first versions of my software performed reasonably well, the collaboration within the team also became closer. I had the opportunity to test the "real" management station together with a physical encryption device. To my relief, this revealed not only outstanding issues and errors on my end.

20 Weeks – Far Too Long?

ETH Zurich requires a minimum 10-week internship for its computer science program. With the initial intention of gaining my first practical experience abroad, I took a semester off in the summer of 2003 to have enough time for an exciting and challenging internship.

After an initially positive response from Canada, this didn't pan out. Other avenues through exchange organizations also proved unsuccessful. So I was forced to look for a suitable internship in Switzerland. After several applications, Crypto invited me for an interview, where all I had to do was accept.

Looking back, I'm very glad I took the time. I had the opportunity to complete an independent project from start to finish, which ultimately interacted with other projects under development and became a valuable component.

In my opinion, the 10 weeks required by ETH Zurich are far too short. It's difficult to find a suitable task that can be completed in such a short time. Whenever possible, you should allow yourself ample time for initial practical experience. It's extremely valuable for your future career and a fundamental component of your studies. This makes me even more convinced that it's essential to have worked in a company for a period of time during your engineering studies at ETH Zurich.

And how do projects actually work?

Do projects really proceed as we're taught in relevant supplementary and application courses? On the one hand, yes; the experiences we're told about certainly largely reflect reality. On the other hand, however, none of the lectures mentioned can replace working on a 'real' project. It was exciting to observe the technical progress, attend the weekly team meetings, discuss current problems, and implement agreed-upon approaches.

It's not always just about bits and bytes.

But what fascinated me even more was the human aspect of such collaboration. It's about the ability to defer at the right time, but also to stand up for your point of view and find compromises. Communication skills play a crucial role – how aptly and precisely someone can express themselves, and whether their arguments resonate with colleagues. Ultimately, I believe I developed personally in this area – social skills – at least as much as in technical matters.

I would go back to Crypto in a heartbeat!

In conclusion, there's not much more to say except that it was an inspiring and intense period full of valuable new impressions and experiences. In my opinion, my role was perfectly suited to an internship within this context. It was a real pleasure to work in such a dynamic team. I can only praise the competent supervision, and I couldn't have imagined a more pleasant relationship with my superiors. In short: It was fantastic!

The FSFE misfits pretending to be associated with the real FSF are another interesting example of a social engineering attack. Are the CIA and BND behind that too or is it just Google and IBM Red Hat?

Read more about the FSFE misfits.

Other Recent Techrights' Posts

Giving a Voice to the Community (Even When It's Inconvenient or 'Scary')
Once upon a time we were threatened with deplatforming for merely reposting articles by Daniel Pocock; we no longer have this problem
Judgment: French army vanquishes German FSFE on Hitler's birthday, Microsoft contract dispute (1716711)
Reprinted with permission from Daniel Pocock
Projection Tactics - Part IV: SLAPP by Americans Against Techrights (UK) to Hide Serious Abuses Against American Women
"PRs need to stop being complicit in suppression of information via SLAPPs"
 
Diversity, Grooming & Debian transgender Zero
Reprinted with permission from Daniel Pocock
Pauline / Maria / Alice Climent(-Pommeret) & Debian transgender offensive cybersecurity deception
Reprinted with permission from Daniel Pocock
Did judge with transgender sister & Debian conflict of interest help cover-up a death?
Reprinted with permission from Daniel Pocock
Links 24/01/2026: CBS News Demolished From the Inside and Many Publishers Admit Layoffs
Links for the day
Gemini Links 24/01/2026: Dreams and Raspberry Pi Zero 2W
Links for the day
Richard Stallman's First Talk in US College Since 2018: Videos and Photos
There are some backstories
Judge Richard Oulevey (Grandcour Choeur, Tribunal Vaud) & Debian shaming abuse victims and witnesses
Reprinted with permission from Daniel Pocock
EDPB/CNIL privacy expert Amandine Jambert (cryptie, FSFE) implicitly admitted lying about harassment when she resigned admitting conflict of interest
Reprinted with permission from Daniel Pocock
Links 24/01/2026: TikTok Controlled by Alt Reich in US Now, White House Shares Fake, Manipulated, Misleading Images Already
Links for the day
Dirty Laundry at Debian and Elsewhere
We cannot just brush aside real issues involving real people and their families
Illegal, Unconstitutional Kangaroo Court for Patents Drops the Masks, Shows Its Real Purpose is to Serve Multinational Monopolists and Crush European SMEs
Europe (or the EU) is rapidly becoming a corporate project, not a unified governance initiative
The "Alicante Mafia" - Part X - EPO Strikes to Begin Next Week
Things gradually escalate this month
Gemini Links 24/01/2026: Snow, Boxing, and Lisp is Fun
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, January 23, 2026
IRC logs for Friday, January 23, 2026
Senior management and HR email privacy: Martin Ebnoether (venty), Axel Beckert (xtaran) & Debian abuse in Switzerland
Reprinted with permission from Daniel Pocock
Pierre-Elliott Bécue, ANSSI & Debian cybertorture
Reprinted with permission from Daniel Pocock
MJ Ray, Micah Anderson & Debian on drugs, prostitution at DebConf6 fight
Reprinted with permission from Daniel Pocock
Excellence in Ethics: a list of victories for the truth
Reprinted with permission from Daniel Pocock
Richard Stallman Giving Public Talk, Answering Questions From the Audience
We understand (from the organisers) that there will be a video of the talk
Forbes Covers in 2026 What Was Already Clear for Over a Decade: Microsoft's BitLocker 'Encryption' is a Back Door
One that's promoted by the loudest boosters of UEFI 'secure boot' as well
The Grapevine Says IBM's American RAs (Mass Layoffs) Soon to Follow European RAs, PIPs and "Reviews" as Pretext for a Likely Baseless Dismissal
The days of honourable corporations and work ethics are long gone it seems...
Links 23/01/2026: Minus 24 deg C in South Korea, "Iran Internet Blackout Passes Two-Week Mark"
Links for the day
Gemini Links 23/01/2026: "Witch Watch" and English on the Net
Links for the day
Reminder That "Linux" in the Site's Name (and Domain) Does Not Imply Authentic Journalism About GNU/Linux
the sad fact that some once-legitimate sites became slopfarms
Further Comments Illuminate Observations Regarding IBM's Layoffs (RAs) Plan for Europe
Some shed light on the expected scale
Links 23/01/2026: Growing Censorship, Intel Falls (Another Bubble, Propped Up by Cheeto Bailout), and Huge GAFAM Layoffs Continue
Links for the day
Working for Freedom Makes You a Target
it's not about what you do but about who gets served
Appeasing Bullies Doesn't Work
The reason we're still here and very active is that we're good at what we do
Claim That IBM Mass Layoffs Began Again in Europe, With Rumours It'll Close Offices
Unless IBM issues a statement (admission) to the media or issues WARN notices (in the US), the lousy media will simply assume - however wrongly - that nothing is happening and there's nothing to report
How Microsoft Will Tell Shareholders That the Business is Failing in a Few Days
It'll resort to "AI" storytelling (lying about slop having potential for some unspecified future year)
Flying to See Today's Talk by Richard Stallman
It's probably not too late to reserve a seat for today's talk
The Fall of Freenode Didn't Kill IRC and the Web's Issues (Not Limited to LLM Slop) Didn't Kill Everything
As long as there are enough people willing to keep the simple (or "old") stuff it'll refuse to die
GAFAM Layoffs by Performance Improvement Plans (PIPs) Hide the Real Scale of Their Financial Troubles
the "official" numbers of layoffs will never tell the true story
'Domesticated' Animals Not More Valuable Than Free-range Wildlife, Proprietary ('Commercial') Software Isn't Better Than Free Software
the proprietary software giants (companies like SAP or Microsoft) have a lot of lobbyists
The "Alicante Mafia" - Part IX - EPO Budget Funnelled Into Cocaine and Moreover Rewards Cocaine-Addicted Management for Getting Busted by Police
Any day that passes without European media and European politicians doing anything about it merely discredits the media and the EU (or national governments)
Richard Stallman Won't Talk About "AI", He'll Talk About Chatbots and LLMs Lacking Any Intelligence
This really irritates people who dislike the message; so they attack the person
Slopfarms Still Fed by Google, Boosting Fake 'Articles' That Pretend to Cover "Linux"
At this point about 80-90% of the search results appear not to be slopfarms
Gemini Links 23/01/2026: The Danish Approach to Deepfakes and Random vi Things
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, January 22, 2026
IRC logs for Thursday, January 22, 2026
Five Years Ago, After We Broke the Story About Richard Stallman Rejoining the FSF's Board, All Hell Broke Loose (for Me and My Family)
They generally seem to target anyone who thinks Richard Stallman (RMS) should be in charge or thinks alike about computing
Links 22/01/2026: Slop Fantasy About Patents, Retirement in China Now Reached at Age Seventy
Links for the day
Gemini Links 22/01/2026: Why Europe Does Not Need GAFAMs, XScreenSaver Tinkering, FlatCube
Links for the day
Salvadorans' Usage of GNU/Linux Measured at Record Levels
All-time high
Links 22/01/2026: Ubisoft Layoffs Disguised as "RTO", US "Congress Wants To Hand Your Parenting To GAFAM", Americans' Image Tarnished Among Canadians (Now Planning to "Repel US Invasion")
Links for the day
10 Easy Steps to Follow for Digital Sovereignty in Nations That Distrust GAFAM et al
When "enough is enough"
No, the Problem at IBM/Red Hat Isn't Diversity
Microsoft Lunduke also openly shows his admiration for Pedo Cheeto
Do Not Link to Linuxiac Anymore, Linuxiac Became a Slopfarm
now Linuxiac is slop
Dr. Andy Farnell Explains Why Slop Companies Like Anthropic and Microsoft 'Open' 'AI' Basically Plunder and Rob People
This article was published last night at around 10
Richard Stallman (RMS) at Georgia Tech Tomorrow
After the talk we'll write a lot about "cancel culture" and online mobs fostered and emboldened in social control media
Software Patents by Any Other Name
There is no such thing as "AI" patents
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, January 21, 2026
IRC logs for Wednesday, January 21, 2026
The "Alicante Mafia" - Part VIII - Salary Cuts to Staff, 100,000 Euros to Managers Busted Using Cocaine (for Doing Absolutely Nothing, Just Pretending to be "Sick")
Today we look at slides from the union
Gemini Links 22/01/2026: Forest Monk, Aurora Observation, and Arduino Officially Launches the More Powerful Arduino UNO Q 4GB Single-Board Computer
Links for the day
Next Week is Close Enough for Wall Street Storytelling About 'Efficiency' by Layoffs for "AI"
This coming week GAFAM and others will tell some creative tales about how "AI" something something...
Google News Still a Feeder of Slop About "Linux", Which Became Rarer in 2026
Our main concern these days is what happened to Linuxiac. Bobby Borisov became a chatbots addict.