Live data from Hacker News

What the CIA WikiLeaks Dump Tells Us: Encryption Works

nytimes.com

241–250 of 270 posts

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#241
post #232
post #195

Earlier quoted context omitted.

Very true. Maybe I misread your previous comment as being more binary than you intended. Keep in mind that reviewers of free software are also often employees and may have some agenda beyond pure altruism, even if the software isn't copyright of the employer. Open source is big business these days.

Maybe Open Source is big business, but not free software.

It all is. The person contributing to gcc needs to make money somehow.

Well, at least it could be considered tainted by self-interest if you're paranoid. My point was that commercial interest does not prevent quality/security.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#242

Earlier quoted context omitted.

The sad truth is, until we've spent a lot more time analysing and attacking those algorithms, they aren't as secure as what we've got.

There's an extremely simple method which is to onion multiple algorithms. If you want to add the promised security features of a new algorithm that hasn't been battle-tested it's well worth the effort.

I know next to nothing about this subject, but this suggestion sounds like the kinds of things that amateurs suggest but experts scoff at. So my question to any actual experts: is this legit? Note that breaking A+B is not necessarily as hard as breaking both A and B, but it certainly seems likely to be true most of the time.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#243
post #11

The article mentions WhatsApp multiple times as a service that successfully made the transition to end-to-end encryption, but it always seemed to me that this claim is rather meaningless when we don't have the possibility of auditing their source code.

It's not hard to demonstrate that apps are performing end-to-end encryption even if you don't have access to the source code. Reverse engineering this stuff is really pretty straightforward.

While you can verify that the software is in fact encrypting the data and not sending anything it should not send, you can never know who has access to the encryption keys. They are created by WhatsApp, who knows how and where they store them and who can access them.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#244
post #67

I don't see any mention of quantum computers in here so I thought I'd mention: the NSA themselves are concerned that quantum computing will be a great threat to encryption in the near future. Keep in mind that the NSA and god knows who else are storing encrypted communications to break them later. Quantum computing will defeat RSA, DH, ECC, asymmetric crypto, but it will only weaken symmetric crypto (eg. AES) by a fa…

[deleted]

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#245
post #205
post #156

Earlier quoted context omitted.

I saw that strongSwan had already supported two post-quantum key exchange algorithms (NTRU and NewHope) for IPSec IKEv2. Good. https://wiki.strongswan.org/projects/strongswan/wiki/IKEv2Ci...

If IPSec is a complicated, commitee-designed and NSA interfered technology, and moreover not recommended by information security researchers, isn't a detail such as support for post-quantum algorithms irrelevant? http://www.mail-archive.com/cryptography@metzdowd.com/msg123... https://www.schneier.com/academic/paperfiles/paper-ipsec.pdf

From Schneier's IPSec paper

Conclusions

We are of two minds about IPsec. On the one hand, IPsec is far better than any IP security protocol that has come before: Microsoft PPTP, L2TP, etc.

On the other hand, we do not believe that it will ever result in a secure operational system.

It is far too complex, and the complexity has lead to a large number of ambiguities, contradictions, inefficiencies, and weaknesses.

It has been very hard work to perform any kind of security analysis; we do not feel that we fully understand the system, let alone have fully analyzed it.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#246
post #236

Earlier quoted context omitted.

Devices that produce a trickle of truly random numbers can be produced for a few bucks. They're included in modern CPUs, for example. But that was never the problem. The problem is, now what? To use this OTP you need to securely deliver pads to everybody you'll ever send a message to. So, OTP is practical for a handful of secret agents who'll receive messages of a few dozen words per year from a single controller, an…

Snarkily: a one time pad reduces the problem of exchanging secret messages to exchanging secret keys of the same length.. The only thing that OTP buys you is that you can exchange the pads at your convenience any time before.

You only need to meet once.

With a few GB (a couple bucks in a supermarket will buy a 8GB usb stick) you can communicate in text about 16 thousand books worth of words.

In other words, to deplete the pad you would have to write sixteen thousand books.

I think that's pretty convenient, as far as literally unbreakable encryption goes!

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#247

Earlier quoted context omitted.

> the NSA themselves are concerned that quantum computing will be a great threat to encryption in the near future. pardon my ignorance. but, isn't this an inevitability? not just a possibility?

No. For two reasons, a general reason and a specific reason. Firstly, quantum computing at scale _might_ be possible in our universe but it might not. One of the spookiest things that might still be true would be a thing called finite non-local hidden state. In this scenario the whole universe has some sort of hidden state, a bit like the seed value of a Minecraft world. Quantum computing in a universe with finite no…

So... how come they are selling them?

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#248
post #246
post #236

Earlier quoted context omitted.

Snarkily: a one time pad reduces the problem of exchanging secret messages to exchanging secret keys of the same length.. The only thing that OTP buys you is that you can exchange the pads at your convenience any time before.

You only need to meet once. With a few GB (a couple bucks in a supermarket will buy a 8GB usb stick) you can communicate in text about 16 thousand books worth of words. In other words, to deplete the pad you would have to write sixteen thousand books. I think that's pretty convenient, as far as literally unbreakable encryption goes!

Oh, definitely. The convenience of being able to secure your communication in advance is great.

It's just that key-sharing is basically the most complicated and vulnerable part of modern cryptography.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#249

The only encryption I truly trust is one-time pad. Discrete log may be NP-intermediate (if P!=NP, which is open), and we know from the Snowden disclosures that NSA was working with U Maryland on a quantum computer which will be a reality at some point (Shor's algorithm). With 'collect it all,' today's ciphertext is tomorrow's plaintext. Always be skeptical.

Your downvotes courtesy of NSA's botnet ;)

Do you use OTP? I've done some little experiments.

I'm surprised at the lack of interest in the only form of encryption that is literally unbreakable, in this age of surveillance paranoia.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#250
post #197

Earlier quoted context omitted.

You seen to be so sure quantum computing will actually be done.

It's already been done, just not on very many qubits. Scaling up to more qubits is a tractable engineering challenge, and there's plenty of money on the table, so we have every reason to expect that practical quantum computers will emerge in the near future.

If, and that is a big if, quantum computing was here, you won't be reading about qbits.

All the headlines will be: "Heisenberg uncertainty principle violated; science, technology and life as you know it will change'.

This has nothing to do with 'engineering challenges'. You are dealing with hard cold physics limiting our understanding of the standard model, just because the barrier is there.

Post reply on HN