Live data from Hacker News

What the CIA WikiLeaks Dump Tells Us: Encryption Works

nytimes.com

151–160 of 270 posts

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#151
post #140
post #23

Earlier quoted context omitted.

You rely on a net of diverse independent reviewers instead of a single entity with a particular interest. A peer reviewed distributed trust net is much more trustworthy.

That single entity consists of many diverse individuals with differing ethics. As much as the law might try to pretend, companies are not people. Uh, except in the sense that they are compromised of people. So, they literally are people, people combined with capital.

People in a single entity are by definition not independent.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#152
post #105
post #53

Earlier quoted context omitted.

There's no such net, nobody is signing the binaries.

Signing is not necessary. Only a comprehensible bug report or patch.

Without signing 1000 people can say it is secure but the maintainer can still send whatever they want

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#153
post #76
post #59

Earlier quoted context omitted.

Practically nobody is running own mail server these days. Email is extremely centralized

I still run my own for personal email (postfix + dovecot). Runs off a Linode VM atm and has no problem getting through to Gmail, Hotmail etc. users.

"Most people don't know rocket science" "Actually I know some rocket science!"

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#154

Earlier quoted context omitted.

Then you probably meant to start a new thread. The one you are replying to is about encryption exclusively.

Nope, the poster I replied to talked about asymmetric crypto in general, which includes signatures.

I think that was in reference to public key cryptography, not in reference to hashing, but I'll leave it to the OP to clarify, that's at least how I interpreted it.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#155

Another thing is important: trust. As a naive user I have no idea what's going on on my phone, hardware or software wise We are essentially trusting these companies with everything. Encryption is no good if Apple and Google provide backdoors to their systems to the CIA or NSA.

Encryption in transit defeats dragnet surveillance. Forcing the NSA et al to actually break into the phones they're interested in substantially reduces the amount of information they can actually collect. They can't just tap internet backbones and read everything, like they do with plaintext communication.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#156
post #79
post #67

I don't see any mention of quantum computers in here so I thought I'd mention: the NSA themselves are concerned that quantum computing will be a great threat to encryption in the near future. Keep in mind that the NSA and god knows who else are storing encrypted communications to break them later. Quantum computing will defeat RSA, DH, ECC, asymmetric crypto, but it will only weaken symmetric crypto (eg. AES) by a fa…

Symmetric encryption not being broken doesn't really help you if the encryption key has been exchanged using a (presumably quantum-breakable) form of asymmetric encryption. Most encryption in the wild works this way.

I saw that strongSwan had already supported two post-quantum key exchange algorithms (NTRU and NewHope) for IPSec IKEv2. Good.

https://wiki.strongswan.org/projects/strongswan/wiki/IKEv2Ci...

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#157
post #75

Earlier quoted context omitted.

If it's airgapped, how do you use it for communication?

I'm thinking about giving both machines a little speaker and microphone and using high frequency pulses to transfer the text. (modem) I don't know enough about computer security to understand whether a specially crafted piece of morse code audio (transferred through actual sound waves) could be used as an exploit, but I'm leaning towards "implausible".

Honestly a floppy drive that you only connect to the raspi to transfer stuff is the only secure-ish way I can think of transferring data to your non-networked computer. Floppies are nice and dumb.

If you want a persistent, networked connection then just use a serial cable, but then... you're not airgapped anymore.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#158
post #110
post #79

Earlier quoted context omitted.

Symmetric encryption not being broken doesn't really help you if the encryption key has been exchanged using a (presumably quantum-breakable) form of asymmetric encryption. Most encryption in the wild works this way.

True. Note that some "post-quantum" key exchange schemes already exist (based on lattice cryptography, for which there are no known poly-time quantum attacks), e.g. https://eprint.iacr.org/2015/1092 . But I haven't heard of it being used anywhere.

The sad truth is, until we've spent a lot more time analysing and attacking those algorithms, they aren't as secure as what we've got.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#159
post #151
post #140

Earlier quoted context omitted.

That single entity consists of many diverse individuals with differing ethics. As much as the law might try to pretend, companies are not people. Uh, except in the sense that they are compromised of people. So, they literally are people, people combined with capital.

People in a single entity are by definition not independent.

In that sense, no one is independent. We've all got friends and family, or at least people we know. By definition, if you've heard of someone else's software, that person had a social network by which they distributed the software to you.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#160
It only tells you that encryption works against the tools included in the leak. It doesn't seem credible to me that the US government's tooling in this area is pretty much the same as what is generally available, given the billions invested in cyber stuff.

There are many reasons beyond self interest (like the viability of online commerce) that would lead an organization like the CIA to compartmentalize more advanced/strategic methods.

Post reply on HN