How to Protect Yourself from NSA Attacks on 1024-bit DH
61–70 of 140 posts
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#62Earlier quoted context omitted.
Sure they do. The details of your private life gives them a source of great power: to embarrass you, expose you, blackmail you, and destroy you. Why would they want this power? Because you might threaten to expose them or otherwise oppose them.
People expose and oppose the government everyday in various forms. You would expect the news to be filled with scandals of government opposers or we would have no opposition at all in the US due to them being blackmailed etc. Neither is true.
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#63It's strange that this is all coming up just now. The NSA has had this technology since at least 1992 when it was revealed in the gripping documentary movie "Sneakers".
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#64It's strange that this is all coming up just now. The NSA has had this technology since at least 1992 when it was revealed in the gripping documentary movie "Sneakers".
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#65I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#66I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#67Earlier quoted context omitted.
Do you know what VPN protocol it is? I wonder if it would be easy to figure out in Wireshark if you had a recording of the beginning of a session.
QUIC is what WireShark says I am looking at. I can see the DNS lookup, and then a stream of encrypted UDP packets with not much plain text in the payloads. I get what the other poster says about asking the provider, but I wouldn't have much confidence in the answer.
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#68Earlier quoted context omitted.
FWIU of the situation, we have reason to suspect the government has 'cracked' the default large primes that are commonly used by a bunch of different software packages, including web servers. Assuming they have, the challenge is then defined as determining which applications and sites tend to use these standardized or hard-coded primes. > Breaking a second 1024-bit prime would allow passive eavesdropping on connectio…
"FWIU of the situation, we have reason to suspect the government has 'cracked' the default large primes that are commonly used by a bunch of different software packages, including web servers." This is just nonsense. Am I the only sane one here? Can no-one else see that the response is hysterical? There's no evidence whatsover that any of this has happened. It's conspiracy conjecture. Look, I know the cultural narrat…
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#69If you're having trouble following the instructions to secure SSH on OSX, try following the directions here: https://mochtu.de/2015/01/07/updating-openssh-on-mac-os-x-10... Without using the brew dupe and ` --with-keychain-support` flag, I was getting cipher errors when trying to use SSH after following the instructions linked to in TFA. NB: I am not a security expert.
You may have a cipher mismatch with the server. If you use ssh with the -vv flag you can see which ciphers the server is supporting and compare that to the ciphers your client supports.
Re: How to Protect Yourself from NSA Attacks on 1024-bit DH
#70Earlier quoted context omitted.
Sure they do. The details of your private life gives them a source of great power: to embarrass you, expose you, blackmail you, and destroy you. Why would they want this power? Because you might threaten to expose them or otherwise oppose them.
People expose and oppose the government everyday in various forms. You would expect the news to be filled with scandals of government opposers or we would have no opposition at all in the US due to them being blackmailed etc. Neither is true.