Without using the brew dupe and ` --with-keychain-support` flag, I was getting cipher errors when trying to use SSH after following the instructions linked to in TFA.
NB: I am not a security expert.
51–60 of 140 posts
Without using the brew dupe and ` --with-keychain-support` flag, I was getting cipher errors when trying to use SSH after following the instructions linked to in TFA.
NB: I am not a security expert.
I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?
* Hackers/crackers/phishers and organized crime. The NSA data troves _must_ be a juicy target. If any malicious intruder gets access to the data (I know, highly unlikely), what could they use it for? Surveillance, tracking, blackmail, extortion, political affiliations, personal beliefs, etc. What if they don't target you, but rather political leaders in the US. That would make the holders of that information _way_ more powerful than any political campaign donor.
* Have a US security clearance? You are subject to very high standards of conduct. Anything that could impair your judgement or lead to possible blackmail of you or your family is potentially grounds for taking away your security clearance (which likely means you can no longer do your job). Alcohol addiction, gambling addiction, sexual relationships, history of crime, immoral behaviors, etc. Gen David Patreus (Director of the CIA, IIRC) was in an extra-marital affair and tried to his this fact from "the company" and from politicians. In this scenario, he is a "bad guy".
* You are assuming the NSA only uses records for official purposes. We have already heard that some NSA employees have been reprimanded for snooping on their spouses and neighbors using work tools.
* It's not as if the NSA has a perfect record. Snowden wasn't even close to being the first whistleblower and it looks like there may be another post-Snowden disclosure. The NSA doesn't have control of its own people (or contractors) so I assume it doesn't have perfect security procedures either. That means it is open to threats against its data and procedures from both inside and out.
* The NSA is suspected to have tipped off the DEA/DHS and FBI for cases that don't involve terrorism or national security. NSA techniques are suspected to have been adopted by much of DHS. This means the threshold to be considered a "bad guy" is now a lot lower than the NSA used to be tasked with watching. Apply the slippery slope argument. What if the NSA quietly helps out with civil cases (such as MegaUpload) and not just criminal? What if it goes even further?
* The NSA isn't the only organization trying to gain access to sensitive internet communications. If anyone else finds out how to take advantage of some of the same tricks the NSA uses, they could potentially have access to the same data and communications. Think nation-states, organized crime, disorganized criminals, even marketing/tracking companies with questionable ethics.
* If SSL / TLS is no longer beyond cracking in near-real-time, MITM is now possible. This could set back peoples' faith in the security underpinnings of the web even more than it has been eroded in recent years. Even worse if people don't find out about it.
Earlier quoted context omitted.
I don't think the government wants to know about your private family life neither. I mean, it's edgy to imagine that the government has a secret file on all of us. But they don't do they? It's just very silly nonsense.
Sure they do. The details of your private life gives them a source of great power: to embarrass you, expose you, blackmail you, and destroy you. Why would they want this power? Because you might threaten to expose them or otherwise oppose them.
I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?
Anybody who is afraid of parallel construction.
And if you're not, you should be.
Is this really a "best practice" to disable dhe in firefox/chrome? Won't that just make the server/browser negotiate an even weaker scheme if they cannot find a matching higher set? My firefox goes from: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA TLS_ECDHE_RSA_WITH_AES_256_CB…
Ideally, you would want to just disable all ciphersuites that don't use ECDHE to do the key exchange, but that would probably hurt compatibility.
If you're having trouble following the instructions to secure SSH on OSX, try following the directions here: https://mochtu.de/2015/01/07/updating-openssh-on-mac-os-x-10... Without using the brew dupe and ` --with-keychain-support` flag, I was getting cipher errors when trying to use SSH after following the instructions linked to in TFA. NB: I am not a security expert.
I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?
Earlier quoted context omitted.
Not really. This precomputation attack only works because attacks on 1024 bit discrete logs were already plausible. We don't choose cryptographic parameters to make the NSA's job harder ; we choose them to make the job implausible . So it's exactly the wrong message to take from this paper that we should mix up parameters more; rather, the message is: don't use weak moduli.
> don't use weak moduli. By this do you mean don't use 1024 bit keys? Would using 2048 bit (or larger) mean that the NSA wouldn't be able to buy a computer that could do the computation within a year? Why don't we all use 2048 bit keys then? Is the communication and processing overhead so high that we'd rather be vulnerable? Edit to add: I'm not an expert, but I'm competent enough to force a certain level of crypto o…
Keep in mind, going from 1024 to 2048 bit DH parameters doesn't double the search space, it raises it from 2^1024 to 2^2048. At some point the search space gets so large that you'd need more energy than required to boil all of Earth's oceans to find the key, which makes such a brute-force attack implausible.
Earlier quoted context omitted.
I don't think the government wants to know about your private family life neither. I mean, it's edgy to imagine that the government has a secret file on all of us. But they don't do they? It's just very silly nonsense.
That was the argument before Snowden, but we now know that the government passively records and stores as much information as possible on anyone. So they can build a secret file on anyone should they feel like it. And they'll use every piece of information at their disposal (private family life, shopping and travel habits, what websites you browse, what media you consume, etc.) to profile you. Ever download a copyrig…
That's highly impratical. NSA's budget isn't infinite and they have many other operations that would also require funding.
Earlier quoted context omitted.
Sure they do. The details of your private life gives them a source of great power: to embarrass you, expose you, blackmail you, and destroy you. Why would they want this power? Because you might threaten to expose them or otherwise oppose them.
People expose and oppose the government everyday in various forms. You would expect the news to be filled with scandals of government opposers or we would have no opposition at all in the US due to them being blackmailed etc. Neither is true.