Live data from Hacker News

How to Protect Yourself from NSA Attacks on 1024-bit DH

eff.org

41–50 of 140 posts

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#41
post #37
post #31

Earlier quoted context omitted.

"If we all use a single "strong" prime number with our crypto then the NSA has a huge incentive to pre-compute results from that single strong number. Now that we know that the NSA is doing this" We don't know the NSA is doing this. There's no evidence whatsoever beyond conspiracy theory stuff.

> We don't know the NSA is doing this. There's no evidence whatsoever beyond conspiracy theory stuff. We don't know the NSA is not doing this. There is ample evidence that they do a lot more than we conspired about.

"We don't know the NSA is not doing this."

Please look at what you wrote! Am I dreaming? This is the level of argument that is being used?

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#42
post #33
post #7

Earlier quoted context omitted.

FWIU of the situation, we have reason to suspect the government has 'cracked' the default large primes that are commonly used by a bunch of different software packages, including web servers. Assuming they have, the challenge is then defined as determining which applications and sites tend to use these standardized or hard-coded primes. > Breaking a second 1024-bit prime would allow passive eavesdropping on connectio…

"FWIU of the situation, we have reason to suspect the government has 'cracked' the default large primes that are commonly used by a bunch of different software packages, including web servers." This is just nonsense. Am I the only sane one here? Can no-one else see that the response is hysterical? There's no evidence whatsover that any of this has happened. It's conspiracy conjecture. Look, I know the cultural narrat…

You want a sensible discussion? How about starting with not calling people "conspiracy theorists" for merely wanting to be as safe as possible?

And how about not asking things such as "Am I the only sane one here?" then? You're surrounded with very smart people on this website, most of which will tell you that it's not insane to assume the worst of the NSA, and yet you hop around calling people crazy. If you're not going to do this for the sake of reason, at least do it for the sake of humility.

You want a sensible discussion, you start.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#43
post #40
post #38

I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?

One of the main things I want to keep private is just family life - conflicts, love, sex, etc. I don't want the government to know about my private family life. I don't see how a free, thoughtful, creative society can flourish if the government can always know the goods on everybody.

I don't think the government wants to know about your private family life neither. I mean, it's edgy to imagine that the government has a secret file on all of us. But they don't do they? It's just very silly nonsense.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#44
post #33
post #7

Earlier quoted context omitted.

FWIU of the situation, we have reason to suspect the government has 'cracked' the default large primes that are commonly used by a bunch of different software packages, including web servers. Assuming they have, the challenge is then defined as determining which applications and sites tend to use these standardized or hard-coded primes. > Breaking a second 1024-bit prime would allow passive eavesdropping on connectio…

"FWIU of the situation, we have reason to suspect the government has 'cracked' the default large primes that are commonly used by a bunch of different software packages, including web servers." This is just nonsense. Am I the only sane one here? Can no-one else see that the response is hysterical? There's no evidence whatsover that any of this has happened. It's conspiracy conjecture. Look, I know the cultural narrat…

"The Snowden documents also hint at some extraordinary capabilities: they show that NSA has built extensive infrastructure to intercept and decrypt VPN traffic and suggest that the agency can decrypt at least some HTTPS and SSH connections on demand... Based on the evidence we have, we can’t prove for certain that NSA is doing this. However, our proposed Diffie-Hellman break fits the known technical details about their large-scale decryption capabilities better than any competing explanation. For instance, the Snowden documents show that NSA’s VPN decryption infrastructure involves intercepting encrypted connections and passing certain data to supercomputers, which return the key. The design of the system goes to great lengths to collect particular data that would be necessary for an attack on Diffie-Hellman but not for alternative explanations, like a break in AES or other symmetric crypto. While the documents make it clear that NSA uses other attack techniques, like software and hardware “implants,” to break crypto on specific targets, these don’t explain the ability to passively eavesdrop on VPN traffic at a large scale."

https://freedom-to-tinker.com/blog/haldermanheninger/how-is-...

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#46
post #38

I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?

Literally everyone.

The power of the government getting into your personal life to blackmail you into submission (for a multitude of purposes) is something everyone needs to worry about.

The fact that they are the defacto spy agency means they can simply lie about you, and claim their spy powers tell them so, and therefore you are guilty. (Just make sure to claim national security privileges on the information gathered so they cant argue against their accuser.)

I might be wrong, but I feel like I must have misunderstood entirely the thrust of your comment due to how oppositely I interpret this question.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#47
post #36

Earlier quoted context omitted.

Thank you I had an idea of the performance delta. But, comparatively (to something like TLS_RSA_WITH_AES_[256|128]_CBC_SHA) how does it compare? Edit: Thanks for the edit! What I was looking for.

Very poorly: http://zombe.es/post/4078724716/openssl-cipher-selection

Thank you for the reference!

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#48
post #43
post #40

Earlier quoted context omitted.

One of the main things I want to keep private is just family life - conflicts, love, sex, etc. I don't want the government to know about my private family life. I don't see how a free, thoughtful, creative society can flourish if the government can always know the goods on everybody.

I don't think the government wants to know about your private family life neither. I mean, it's edgy to imagine that the government has a secret file on all of us. But they don't do they? It's just very silly nonsense.

Sure they do. The details of your private life gives them a source of great power: to embarrass you, expose you, blackmail you, and destroy you. Why would they want this power? Because you might threaten to expose them or otherwise oppose them.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#49
post #43
post #40

Earlier quoted context omitted.

One of the main things I want to keep private is just family life - conflicts, love, sex, etc. I don't want the government to know about my private family life. I don't see how a free, thoughtful, creative society can flourish if the government can always know the goods on everybody.

I don't think the government wants to know about your private family life neither. I mean, it's edgy to imagine that the government has a secret file on all of us. But they don't do they? It's just very silly nonsense.

That was the argument before Snowden, but we now know that the government passively records and stores as much information as possible on anyone. So they can build a secret file on anyone should they feel like it. And they'll use every piece of information at their disposal (private family life, shopping and travel habits, what websites you browse, what media you consume, etc.) to profile you. Ever download a copyrighted file or view pornography? That will be used against you.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#50
post #35
post #34

Earlier quoted context omitted.

Except, you know, actual leaked documents and it being the most reasonable expectation for their claimed capabilities.

IOW no evidence whatsoever.

Sure, if you dismiss all the evidence there is, then there's no evidence. If that reassures you, great. Just don't be surprised that the rest of us are not reassured...
Post reply on HN