Live data from Hacker News

NYU Accidentally Exposed Military Code-Breaking Computer

theintercept.com

51–60 of 65 posts

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#51
post #14

Earlier quoted context omitted.

Sorry to see you conclude the piece, or that portion, is malpractice :-\ The paragraph you quote was intended to give an overview of one type of work a machine like WindsorGreen might do, in broad terms. While it's true we mention RSA as a very basic example of the sort of thing a government would be /interested/ in breaking, we also specifically quote a security researcher saying WindsorGreen “might also have applic…

"supercomputers" are archaic in a day when one can rent a 40,000 core GPU system with 732GB of RAM for $14/hour, on demand, via Amazon Web Services. Available whether you need one or a hundred (4 million cores crunching on a problem with 20Gb/second throughput is still only $1400 per hour). edit: more thorough response.

A CUDA core and a CPU core is not quite the same thing.

40000 CUDA cores are much slower and more constrained than 40000 CPU cores.

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#52
post #48
post #37

Earlier quoted context omitted.

This exactly. Thanks for saying it more clearly than I could.

I appreciate the explanation from schoen, I can grasp the argument more clearly. I do believe that is an aggressive reading of the paragraph, out of its context, and that "malpractice" is unfair. The paragraph you quoted is followed, after just a single intervening paragraph, by this, which I would argue speaks explicitly and accurately to your point: --- A very important question remains: What exactly could WindsorB…

"Don't think there's any reason to assume the worst"? We know there's no reason to assume the worst, or really even suspect it. RSA-4096? The 2048-bit moduli which are the industry standard today are hopelessly out of reach of conventional computers; your story implicitly makes a case that people might be at risk for using them. The difference between 2048 and 4096 is a lot of computing power for defenders.

There are other quotes in the article that are also presented without enough context to avoid misleading. For instance, you can see speculation in this thread about the utility of this system for breaking "signatures" on updates --- but again, that's only possible if the systems in question are already using weak cryptography.

I stand by my criticism of the article. The paragraph I quoted was poorly constructed, and I think the narrative subtext of the whole piece is "worry that the USG is going to subvert all mainstream cryptography". That narrative is extraordinarily harmful. As someone who has done some recent pro-bono training for at-risk people, it's hard enough to get people to adopt best practices without having to beat back concerns that all the effort is for naught.

I further agree with everyone else here who have pointed out that without the documents, or at least far more of them, or far more comments from experts than are present in the article, this story isn't providing much value. It's not exactly a secret that the USG IC invests heavily in compute for these purposes. What have we really learned here?

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#53

So where are the documents? Not much of a story without them....

They're classified...if the guy who discovered they were publicly revealed on accident had actually provided them to the Intercept, he would certainly have lost his job, and likely ended up in prison.

Some of the IBM documents are not classified, as even the article states.

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#54
post #52
post #48

Earlier quoted context omitted.

I appreciate the explanation from schoen, I can grasp the argument more clearly. I do believe that is an aggressive reading of the paragraph, out of its context, and that "malpractice" is unfair. The paragraph you quoted is followed, after just a single intervening paragraph, by this, which I would argue speaks explicitly and accurately to your point: --- A very important question remains: What exactly could WindsorB…

"Don't think there's any reason to assume the worst"? We know there's no reason to assume the worst, or really even suspect it. RSA-4096? The 2048-bit moduli which are the industry standard today are hopelessly out of reach of conventional computers; your story implicitly makes a case that people might be at risk for using them. The difference between 2048 and 4096 is a lot of computing power for defenders. There are…

Again, the article states very clearly and explicitly that WindsorGreen should not impact people using strong crypto.

You criticize a reference to RSA-4096 as implying RSA-2048 is weak. That reference was made in a quote by bunnie huang, a security researcher, who, like us, was using it to illustrate a broader point, with no insinuation that 2048 is weak. The quote was surrounded by higher level paragraphs from us saying, again, that contemporary crypto should be safe from WindsorGreen.

If we were advancing that narrative — that crypto is useless or will soon be rendered useless — I can see why you'd be concerned. But you have to blow past explicit, lengthy blocks of text saying the opposite of that, and ignore them, to come to that conclusion.

(I'm also not sure why we'd promote that narrative when we ourselves put a lot of effort into crypto education, here's just from Micah Lee and the video team that works with him, only a portion of what I'm talking about: https://theintercept.com/staff/micah-lee/ )

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#55
post #12

This is malpractice: Widespread modern encryption methods like RSA, named for the initials of the cryptographers who developed it, rely on the use of hugely complex numbers derived from prime numbers. Speaking very roughly, so long as those original prime numbers remain secret, the integrity of the encoded data will remain safe. But were someone able to factor the hugely complex number — a process identical to the so…

Well said, but note that this assumes partial solutions aren't possible, that brute force is the only way in. For example, it assumes that you can't guess a single prime and then successfully test for more uniformity in the resulting (failed) test decryption. Maybe that's a great and true assumption. Maybe it ain't.

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#56
post #54
post #52

Earlier quoted context omitted.

"Don't think there's any reason to assume the worst"? We know there's no reason to assume the worst, or really even suspect it. RSA-4096? The 2048-bit moduli which are the industry standard today are hopelessly out of reach of conventional computers; your story implicitly makes a case that people might be at risk for using them. The difference between 2048 and 4096 is a lot of computing power for defenders. There are…

Again, the article states very clearly and explicitly that WindsorGreen should not impact people using strong crypto. You criticize a reference to RSA-4096 as implying RSA-2048 is weak. That reference was made in a quote by bunnie huang, a security researcher, who, like us, was using it to illustrate a broader point, with no insinuation that 2048 is weak. The quote was surrounded by higher level paragraphs from us sa…

I like Bunnie Huang as much as anyone here. Your publication chose to quote him in a manner suggesting that people should be adopting RSA-4096 because of NSA supercomputers. I think it's fair to criticize you for doing that.

I'm not sure why I'm meant to care about the work you've done to educate people about cryptography, or how that's germane to the discussion. I assume The Intercept is broadly supportive of cryptography. That doesn't mean you can't write a bad story about it, or even that your incentives will tend to keep you from doing that --- those incentives, after all, are mostly about growing a readership, just like any other publication.

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#57
post #54
post #52

Earlier quoted context omitted.

"Don't think there's any reason to assume the worst"? We know there's no reason to assume the worst, or really even suspect it. RSA-4096? The 2048-bit moduli which are the industry standard today are hopelessly out of reach of conventional computers; your story implicitly makes a case that people might be at risk for using them. The difference between 2048 and 4096 is a lot of computing power for defenders. There are…

Again, the article states very clearly and explicitly that WindsorGreen should not impact people using strong crypto. You criticize a reference to RSA-4096 as implying RSA-2048 is weak. That reference was made in a quote by bunnie huang, a security researcher, who, like us, was using it to illustrate a broader point, with no insinuation that 2048 is weak. The quote was surrounded by higher level paragraphs from us sa…

It's eerie to read this thread - I know little about crypto, after reading the article, I thought the NSA was clearly planning to break all HTTPS traffic. Its unimpressive to watch whoever you are (author? Publisher? Someone who repeatedly implies they have a connection to The Intercept but doesn't explicate it?) to be argumentative with, frankly, poor excuses whenever someone points out its possible for someone to misread the article exactly the way I misread it.

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#58
post #12

This is malpractice: Widespread modern encryption methods like RSA, named for the initials of the cryptographers who developed it, rely on the use of hugely complex numbers derived from prime numbers. Speaking very roughly, so long as those original prime numbers remain secret, the integrity of the encoded data will remain safe. But were someone able to factor the hugely complex number — a process identical to the so…

> breaking RSA isn't a really big IBM purchase order away from happening

You seem to also be completely discounting the possibility of implementation flaws or unpublished advancements against RSA that simply require a ton of hardware to pull off.

What if we don't know that a major RSA implementation is leaking enough key material that it brings the attack down from physically impossible to really really hard?

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#59
post #58
post #12

This is malpractice: Widespread modern encryption methods like RSA, named for the initials of the cryptographers who developed it, rely on the use of hugely complex numbers derived from prime numbers. Speaking very roughly, so long as those original prime numbers remain secret, the integrity of the encoded data will remain safe. But were someone able to factor the hugely complex number — a process identical to the so…

> breaking RSA isn't a really big IBM purchase order away from happening You seem to also be completely discounting the possibility of implementation flaws or unpublished advancements against RSA that simply require a ton of hardware to pull off. What if we don't know that a major RSA implementation is leaking enough key material that it brings the attack down from physically impossible to really really hard?

I'm not discounting it; it's simply orthogonal to the story. We already know NSA spends huge on compute. None of us are surprised that they have a custom supercomputer contracted from IBM. So we can't derive from that revelation that they've got a viable attack on RSA-2048 --- which, by the way, if they did, would be some of the most closely held information in the world, as there is nothing on the horizon (short of QC) suggesting RSA-2048 will ever fall.

If they had a break on RSA, that would be the story!

Re: NYU Accidentally Exposed Military Code-Breaking Computer

#60
post #12

This is malpractice: Widespread modern encryption methods like RSA, named for the initials of the cryptographers who developed it, rely on the use of hugely complex numbers derived from prime numbers. Speaking very roughly, so long as those original prime numbers remain secret, the integrity of the encoded data will remain safe. But were someone able to factor the hugely complex number — a process identical to the so…

Well said, but note that this assumes partial solutions aren't possible, that brute force is the only way in. For example, it assumes that you can't guess a single prime and then successfully test for more uniformity in the resulting (failed) test decryption. Maybe that's a great and true assumption. Maybe it ain't.

The security impact of the relationship between RSA primes is well studied. Also: if you know q and n (which is p * q, and also public)...

It's always possible that NSA has new science unknown to the rest of the world. But they've also always been huge consumers of compute hardware, so an attempt to read tea leaves here is pretty much conspiracy-theoretic. If you believe this, there's no reason to believe any (practical, non-information-theoretically-secure) crypto is safe.

Post reply on HN