Live data from Hacker News

What the CIA WikiLeaks Dump Tells Us: Encryption Works

nytimes.com

261–270 of 270 posts

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#261
post #260

Earlier quoted context omitted.

I have not. I had discussed a theoretical len(CT) == len(key) system with a friend for about 30 mins as a thought experiment, but we immediately poked a number of holes in it -- not the least of which being that we couldn't say anything about the security of the system on which it was deployed. Other questions: what to do with the key material files (their remnants would no doubt be left intact in NAND by opaque eMMC…

1. Security of the system: I'm thinking about this lately: below in this thread I mentioned a setup involving an airgapped non-intel (eg. Rpi) computer that communicates ascii in morse code. This machine would hold the keys and encrypt / decrypt. 2. What to do with the files? You'd need to keep them as long as you need to use them. In my scenario it would be on an SD card in the raspberry pi. Afterwards.. there are m…

In theory, a reasonable hash or CRC _inside_ the OTP stream would prevent tampering.

TEMPEST and DPA are other things I didn't consider in our thought experiment, but if I really wanted to be thorough, I would have. (I suspect there's very little signal for either in the OTP scheme).

I think the key exchange (sneakernet) is what makes the OTP approach unwieldy. If the source of randomness is good, and keys are not reused, in theory, it's the highest quality system out there.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#262
Shouldn't the headline be that; if you have a safe system encryption can work?

Because as long as encryption that has been broken (or systems that have been compromised) is used what you are basically doing is giving mr V is a receipt that you have made a transaction...

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#263
post #260

Earlier quoted context omitted.

1. Security of the system: I'm thinking about this lately: below in this thread I mentioned a setup involving an airgapped non-intel (eg. Rpi) computer that communicates ascii in morse code. This machine would hold the keys and encrypt / decrypt. 2. What to do with the files? You'd need to keep them as long as you need to use them. In my scenario it would be on an SD card in the raspberry pi. Afterwards.. there are m…

In theory, a reasonable hash or CRC _inside_ the OTP stream would prevent tampering. TEMPEST and DPA are other things I didn't consider in our thought experiment, but if I really wanted to be thorough, I would have. (I suspect there's very little signal for either in the OTP scheme). I think the key exchange (sneakernet) is what makes the OTP approach unwieldy. If the source of randomness is good, and keys are not re…

I am thinking about a system for transmitting keys through the mail.

A microSD card is small enough to conceal inside of something else. I'm thinking of some kind of packaging where you could easily tell if it has been opened, and it would be impossible to re-seal perfectly.

It does not matter if the key is intercepted, as long as the recipient knows this, and does not use the key.

--

As far as TEMPEST goes, I think at the point the adversary is physically near you, you've got bigger things than encryption to worry about.

You could wrap the raspberry pi's case in aluminium foil. I'm not sure if the usb power cable leaks any signals: wrap it too for good measure ;)

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#264

Earlier quoted context omitted.

Peer-to-peer IrLAN [1] is less prone to interference then sound, and being directional is harder to attack if the air-gap is small. Nowadays its probably obscure enough to make creating an exploit prohibitively expensive, even more so if you write your own drivers. With some electronics knowledge you could probably build your own simple transceivers too.

How does an obscure transport help you if it's still just a LAN connection?

In the scenario I am describing it would only ever be used to transmit ASCII for a cryptosystem. I do not require networking or internet or file transfer, just a low bitrate modem for text input and output.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#265
post #129

Earlier quoted context omitted.

Basically, you can do 64 bit calculations on a 16 bit traditional computer, it just takes more steps and some RAM. However, to do 64 bit quantum calculations you need a 64 quibit quantum computer. Now, we may be able to build a 64 QC, bout even that is useless for real world encryption. Further, it while it does not take more time to run a 64vs 4096 quibit QC, it does become exponentially harder to build. Sort of lik…

Good analogy; and quite accurate. It's not just the number of bits that affects signal to noise ratio, though... It's also the complexity of the calculation; more gate operations and longer storage in memory leads to more quantum decoherence. And AFAIK, each type of calculation must be implemented in hardware, because reversible quantum gates must be used. This means you would need a specialized chip for each algorit…

Re: need custom hardware for each algorithm

Something tells me, for an intelligence agency, building a quantum computer only for the purpose of breaking cryptographic keys would be a worthwhile investment.

An investment they have already made:

The effort to build “a cryptologically useful quantum computer” -- a machine exponentially faster than classical computers-- is part of a $79.7 million research program called “Penetrating Hard Targets.”

article

https://www.washingtonpost.com/world/national-security/nsa-s...

leaked document

http://apps.washingtonpost.com/g/page/world/a-description-of...

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#266

Earlier quoted context omitted.

> the NSA themselves are concerned that quantum computing will be a great threat to encryption in the near future. pardon my ignorance. but, isn't this an inevitability? not just a possibility?

No. For two reasons, a general reason and a specific reason. Firstly, quantum computing at scale _might_ be possible in our universe but it might not. One of the spookiest things that might still be true would be a thing called finite non-local hidden state. In this scenario the whole universe has some sort of hidden state, a bit like the seed value of a Minecraft world. Quantum computing in a universe with finite no…

yeah- my response neglected "near future"- i don't believe our current encryption methods are "near" broken. to that end, i was obviously wrong.

but i appreciate you reading between the lines and following up with a great response- i have a lot to Google. :)

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#267
post #207
post #200

Earlier quoted context omitted.

In blog spammer terminology, the AP is a shallow content farm that subscribers can either copy verbatim or spin into new articles to avoid duplicate content filters, as long as they provide credit/backlinks.

Not exactly. The majority of local news organizations don't have the resources to investigate and report on all the events happening throughout the world and so the international wire services like AP and Reuters fill this gap. However, this means the majority of national/international stories being reported by the downstream local newspapers and media outlets throughout the nation/world come from just a few big upst…

Thank you, you explained it better than I could put into words. It still baffles me that "wire services" is even a thing or considered acceptable. shrug

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#268
post #3

What a welcome shift in public sentiment. Mainstream media is starting to recommend end-to-end encryption, without back doors, for everybody. (Though the New York Times might represent the leading edge of the change in popular opinion.)

You tend to see that sort of change every eight years or so. The fake liberals come back around to pretending to support all civil liberties again. Ashcroft does X, it's evil and given intense scrutiny. Holder does X, it's mostly given a pass by the msm. Bush does X, it's evil. Obama does X (eg regime change in Syria; what, no million person protests?), it's mostly given a pass by the msm. That's how the media has fu…

> egregious abuses directed at the press under Obama

I'm curious, because I haven't heard of these before. Examples?

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#269
post #216
post #168

Earlier quoted context omitted.

If you trust a one-time pad---which no one actually uses---you can trust stream ciphers, which are actually practical.

That doesn't follow at all...

Sure it does. A stream cipher is essentially the practical version of a one-time pad. Neither system is vulnerable to quantum attacks. For both, the weak link is in keeping the key secure. If you can keep a one-time pad secure, you can keep a 256-bit key secure.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#270
post #269
post #216

Earlier quoted context omitted.

That doesn't follow at all...

Sure it does. A stream cipher is essentially the practical version of a one-time pad. Neither system is vulnerable to quantum attacks. For both, the weak link is in keeping the key secure. If you can keep a one-time pad secure, you can keep a 256-bit key secure.

By all means, continue using RC4, A5, etc.
Post reply on HN