Live data from Hacker News

How to Protect Yourself from NSA Attacks on 1024-bit DH

eff.org

121–130 of 140 posts

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#121
post #120

Earlier quoted context omitted.

"It seems that the NSA (and possibly other state-level actors) can access encrypted traffic that uses 1024-bit Diffie-Hellman that use commonly-used prime numbers." How does it "seem this"? There's no evidence, no plausibility, no sense here whatsoever. Someone hypothetically conjectured a magic all-powerful computer that could magically crack a prime, and that would magically make us all vulnerable to the government…

It seems like you're calling section 4.1 of the paper "magical"; do you have something specific in it to object to that makes you think the estimates are severely mistaken? In order to defend against adversaries with undisclosed capabilities, you have to extrapolate known attack methods and hardware to produce estimates of what may be practical. Every paper that proposes keylength and parameter size recommendations d…

It is magical. There is a magic 36000-core (?) computer that has been running for years (?). Well no, the paper just invents it. On the hearsay that an "anonymous nsa official" said they'd cracked something.

It astonishes me that people are running about like rabbits in a headlight on such flimsy nonsense.

But I understand. It makes us feel important. The new James Bond movie is coming out. And imagine! We're like a superhero secret agent. We can protect from the big bad government by increasing all the keys to 2048 bits! And we get to feel special and important.

Sigh.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#122
post #40
post #38

I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?

One of the main things I want to keep private is just family life - conflicts, love, sex, etc. I don't want the government to know about my private family life. I don't see how a free, thoughtful, creative society can flourish if the government can always know the goods on everybody.

Yes, but can your government really turn up to be your enemy ? I mean if you're a wealthy businessman, and if you can step on some political subject, I'd agree, but this article doesn't aim to explain it to everybody.

If the government was so repressive, people would know about it. It's america, not Russia. There are many things in place which makes it difficult for the government to literally take advantage of all this data.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#123
post #38

I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?

Protecting yourself against the NSA is a good proxy for protecting yourself against other bad actors. The NSA has thousands of employees, a multi-billion dollar budget, and works 24 hours to crack, hack or otherwise gain unauthorized access to computer systems. So, if I can defend myself against the NSA, I've probably inoculated myself against other attackers using similar attack vectors.

I highly doubt that, and I don't think it's a good logic. You cannot compare the power, tools and jurisdiction the NSA has and compare that to other bad actors. The NSA literally has the right to spy on you, but it will get very difficult for somebody else to do something comparable if they don't have the same resources AND the same intentions.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#124
post #38

I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?

But who exactly would really want to protect themselves from the NSA? Anybody who is afraid of parallel construction. And if you're not, you should be.

> parallel construction

I've read the wikipedia article, and I don't see how I should be afraid of it. Or maybe I don't understand it properly. Anyway, this article would be targeting people who are the target of the NSA, like political dissidents or journalists.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#125
post #83
post #38

I get that NSA snooping is abusive if it's the norm. But who exactly would really want to protect themselves from the NSA? I mean ultimately, isn't the problem the NSA is snooping on people who aren't aware of it ? Why would someone try to hide itself from the NSA ? Is it just because it's a political principle or to just annoy the NSA and discourage them ? I mean wouldn't this help the bad guys more ?

Anyone who values privacy should care.

Everyone does, but I don't think a lot of people will actually use those advices.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#126
post #58

Earlier quoted context omitted.

> By this do you mean don't use 1024 bit keys? Would using 2048 bit (or larger) mean that the NSA wouldn't be able to buy a computer that could do the computation within a year? Keep in mind, going from 1024 to 2048 bit DH parameters doesn't double the search space, it raises it from 2^1024 to 2^2048. At some point the search space gets so large that you'd need more energy than required to boil all of Earth's oceans…

I haven't had much crypto-in-practice background (outside of thought experiments), but I have some math background so I'm quite curious. Shouldn't people also be worried about non brute force attacks based on finding mathematical solutions? I mean, "The Uneasy Relationship Between Mathematics and Cryptography"[0]? [0] http://www.ams.org/notices/200708/tx070800972p.pdf

The attacks we're talking about are non-brute-force mathematical attacks (specifically, in this case, the index calculus). A pure brute-force attack on a 2^1024 search space would be comically implausible.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#127

Earlier quoted context omitted.

> they serve at our pleasure No it actually doesn't and shouldn't. It would create a tyranny of the majority.

That my friend is called Democracy. When a majority rules..

And that's why the United States was designed precisely to avoid becoming a democracy and instead be a republic.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#128

Earlier quoted context omitted.

Because this particular military spy organisation is being deployed by the US government against its own citizens, en masse, as an end-around well-established due process and constitutional protections that require individualised suspicion of wrongdoing. It also represents a giant exfiltration target for other state actors, like those who breached OPM. NSA hurts the security of Americans under the guise of preventing…

"Because this particular military spy organisation is being deployed by the US government against its own citizens, en masse" But it's not. That's the problem. There's no evidence whatsoever of it doing that.

There's also no evidence that you are a government/elitist shill, but I still think you are. How's that for levying blame?

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#129
post #120

Earlier quoted context omitted.

It seems like you're calling section 4.1 of the paper "magical"; do you have something specific in it to object to that makes you think the estimates are severely mistaken? In order to defend against adversaries with undisclosed capabilities, you have to extrapolate known attack methods and hardware to produce estimates of what may be practical. Every paper that proposes keylength and parameter size recommendations d…

It is magical. There is a magic 36000-core (?) computer that has been running for years (?). Well no, the paper just invents it. On the hearsay that an "anonymous nsa official" said they'd cracked something. It astonishes me that people are running about like rabbits in a headlight on such flimsy nonsense. But I understand. It makes us feel important. The new James Bond movie is coming out. And imagine! We're like a…

People who protect other people's communications security are special and important.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#130
post #120

Earlier quoted context omitted.

It seems like you're calling section 4.1 of the paper "magical"; do you have something specific in it to object to that makes you think the estimates are severely mistaken? In order to defend against adversaries with undisclosed capabilities, you have to extrapolate known attack methods and hardware to produce estimates of what may be practical. Every paper that proposes keylength and parameter size recommendations d…

It is magical. There is a magic 36000-core (?) computer that has been running for years (?). Well no, the paper just invents it. On the hearsay that an "anonymous nsa official" said they'd cracked something. It astonishes me that people are running about like rabbits in a headlight on such flimsy nonsense. But I understand. It makes us feel important. The new James Bond movie is coming out. And imagine! We're like a…

From the paper:

With standard transistor costs and utilization, this would cost about $2 per chip to manufacture, after fixed design and tape-out costs of roughly $2M [32]. This suggests that an $8M investment would buy enough ASICs to complete the DH-1024 sieving precomputation in one year.

$8 million is pocket change for the NSA, who's estimated yearly budget is around $10 billion.

Post reply on HN