Live data from Hacker News

How to Protect Yourself from NSA Attacks on 1024-bit DH

eff.org

61–70 of 140 posts

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#62
post #48

Earlier quoted context omitted.

Sure they do. The details of your private life gives them a source of great power: to embarrass you, expose you, blackmail you, and destroy you. Why would they want this power? Because you might threaten to expose them or otherwise oppose them.

People expose and oppose the government everyday in various forms. You would expect the news to be filled with scandals of government opposers or we would have no opposition at all in the US due to them being blackmailed etc. Neither is true.

"The government" is not a person and has no feelings. Additionally, the government has massive resources and one individual has humble resources (even the very wealthy ones). This is an asymmetrical comparison.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#63
post #9

It's strange that this is all coming up just now. The NSA has had this technology since at least 1992 when it was revealed in the gripping documentary movie "Sneakers".

A good deal of this is to try to take the US down a notch because they are seen as too powerful. This is why it is rarely mentioned how close the entire West works together, hell what are you going to do hate the entire West? Recently they have had to concede the UK and eventually will have to concede the entire West and then the game is over unless you like actual authoritarianism like China and Russia.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#64
post #9

It's strange that this is all coming up just now. The NSA has had this technology since at least 1992 when it was revealed in the gripping documentary movie "Sneakers".

Then again in Enemy of the State, which should have won the Pulitzer Prize. Hollywood has been warning us about this stuff for years!

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#65
post #38

I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?

Well, if every time you sent a message or visited a web site, your computer asked you "Do you want to send a copy of this message or URL to the NSA? [Yes] [No]", what would you click?

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#66
post #38

I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?

Protecting yourself against the NSA is a good proxy for protecting yourself against other bad actors. The NSA has thousands of employees, a multi-billion dollar budget, and works 24 hours to crack, hack or otherwise gain unauthorized access to computer systems. So, if I can defend myself against the NSA, I've probably inoculated myself against other attackers using similar attack vectors.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#67
post #18

Earlier quoted context omitted.

Do you know what VPN protocol it is? I wonder if it would be easy to figure out in Wireshark if you had a recording of the beginning of a session.

QUIC is what WireShark says I am looking at. I can see the DNS lookup, and then a stream of encrypted UDP packets with not much plain text in the payloads. I get what the other poster says about asking the provider, but I wouldn't have much confidence in the answer.

I'm not really familiar with QUIC, but are there any cryptographic setup steps that Wireshark can parse out of the first (say) three or four packets that get exchanged? (Or maybe the key was established when you first used the VPN and is being cached on your machine and re-used whenever you reconnect?)

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#68
post #33
post #7

Earlier quoted context omitted.

FWIU of the situation, we have reason to suspect the government has 'cracked' the default large primes that are commonly used by a bunch of different software packages, including web servers. Assuming they have, the challenge is then defined as determining which applications and sites tend to use these standardized or hard-coded primes. > Breaking a second 1024-bit prime would allow passive eavesdropping on connectio…

"FWIU of the situation, we have reason to suspect the government has 'cracked' the default large primes that are commonly used by a bunch of different software packages, including web servers." This is just nonsense. Am I the only sane one here? Can no-one else see that the response is hysterical? There's no evidence whatsover that any of this has happened. It's conspiracy conjecture. Look, I know the cultural narrat…

Why is it not a reasonable assumption that the NSA (and possibly other actors with the means) are doing so? / Why wouldn't you do it in their position?

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#69

If you're having trouble following the instructions to secure SSH on OSX, try following the directions here: https://mochtu.de/2015/01/07/updating-openssh-on-mac-os-x-10... Without using the brew dupe and ` --with-keychain-support` flag, I was getting cipher errors when trying to use SSH after following the instructions linked to in TFA. NB: I am not a security expert.

You may have a cipher mismatch with the server. If you use ssh with the -vv flag you can see which ciphers the server is supporting and compare that to the ciphers your client supports.

Thanks for the tip--the server supports that cipher though, it was just an issue with my client.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#70
post #48

Earlier quoted context omitted.

Sure they do. The details of your private life gives them a source of great power: to embarrass you, expose you, blackmail you, and destroy you. Why would they want this power? Because you might threaten to expose them or otherwise oppose them.

People expose and oppose the government everyday in various forms. You would expect the news to be filled with scandals of government opposers or we would have no opposition at all in the US due to them being blackmailed etc. Neither is true.

Just because it isn't happening now does not mean it won't happen in the future.
Post reply on HN