Live data from Hacker News

The NSA called me after midnight and requested my source code (2018)

medium.com

121–130 of 219 posts

Re: The NSA called me after midnight and requested my source code (2018)

#121

Interesting story, but wouldn’t be surprised if the real play here was to get his source code so they could get some bad guys to use a modified version that the NSA could crack. Put a back door in and then intercept traffic trying to download the encryption app to download the back-doored version. The fact that the NSA has to call him in the middle of the night to learn that the free version didn’t use strong encrypt…

I doubt it. For one, how could they expect to distribute it in a way that a bad guy was more likely to download than by going to the official site? But also, if they did want to do that, they could probably backdoor it pretty easily just by patching the binary a bit. Reverse engineering and changing binaries is way easier than cracking encryption, and they probably have some of the world's top reverse engineers. The…

> how could they expect to distribute it in a way that a bad guy was more likely to download than by going to the official site?

Man in the Middle attacks work even if one goes to the official site. It could have looked something like this.

1) User attempts to go to the official site https://...

2) NSA intercepts the message, downgrades to http and sends back a dummy site with the malicious binary [1].

3) The user doesn't notice the change and uses the malicious binary.

Today, a series of steps have been taken to make such an attack more difficult. Now browsers tend to try to warn the user and sites can take advantage of HSTS preload lists[2]. However, this article was written about an event in early 2000 when many of these safeguards didn't exist.

[1] https://en.wikipedia.org/wiki/Downgrade_attack

[2] https://blog.mozilla.org/security/2012/11/01/preloading-hsts...

Re: The NSA called me after midnight and requested my source code (2018)

#122

Earlier quoted context omitted.

I doubt it. For one, how could they expect to distribute it in a way that a bad guy was more likely to download than by going to the official site? But also, if they did want to do that, they could probably backdoor it pretty easily just by patching the binary a bit. Reverse engineering and changing binaries is way easier than cracking encryption, and they probably have some of the world's top reverse engineers. The…

> how could they expect to distribute it in a way that a bad guy was more likely to download than by going to the official site? Man in the Middle attacks work even if one goes to the official site. It could have looked something like this. 1) User attempts to go to the official site https://.. . 2) NSA intercepts the message, downgrades to http and sends back a dummy site with the malicious binary [1]. 3) The user d…

Right. They could possibly do this and have done it before. But they wouldn't need to request the source code from the author in order to do it - they could patch the binary. Also, it's a pretty involved thing to do and not that easy to pull off in a situation like this. For example, presumably all of the targets already have the software installed, and they may have no reason to visit the official site again; especially if updates are very infrequent.

Finally, it wouldn't do them any good for trying to crack things that are already encrypted with it, which from the conversation does seem like was at least one of their goals. (Could be deception, but that's the most likely reading, to me.)

I'm just saying that that doesn't seem to be a likely reason for requesting the source code.

The reason is likely what they said it was: they want to look at the source code to see if there's some way to crack the encryption faster than they otherwise could - for example, some bug causing key generation to be somewhat predictable.

Re: The NSA called me after midnight and requested my source code (2018)

#124
post #103
post #87

Earlier quoted context omitted.

I can't even imagine there is a valid legal argument. If somebody calls me, I can say whatever I want. If I want to answer the phone by saying "Department of Defense, how can I help you?" the First Amendment guarantees me the right to do that. Now, I certainly could not call other people and claim to be the Department of Defense. That's fraud. The same applies if I had done something like put up flyers claiming my ph…

I am in Norway, so the First Amendment carries little weight around here; our equivalent is 'Article 100' (of the Constitution) stating pretty much the same thing as the First Amendment. (This is hardly relevant; I just grasped the opportunity to stress that the HN crowd resides in the most peculiar places...)

Now, I definitely am biased, being a norwegian myself. But I see people mentioning themselves being norwegians everywhere here on HN. I don’t recall seeing half as many people going around saying, «I’m a dane» or similar; this seems peculiar, Norway is small. I wonder if it actually is at it seems to me, or if I just miss these seemingly non–but—actually-not–non-existant remarks.

Re: The NSA called me after midnight and requested my source code (2018)

#125

Certainly doesn't make me want to use any software made by this guy.

Why not? I mean, if the cops turned up at your door with a search warrant, you'd let them in, right?

If I ran an neighborhood ISP, and the cops asked me to spy on a neighbor (for reasons they wouldn't even provide), then I'd shut down first.

If they just wanted to search _my_ stuff, sure. But if the only reason that I'm even capable of assisting the government in spying on somebody is that they are my customer, neighbor, friend, or user then I will not offer that assistance. That would be evil. Don't be evil.

Re: The NSA called me after midnight and requested my source code (2018)

#126
post #85

Earlier quoted context omitted.

Being willing to provide source code is entirely different than inserting a backdoor or purposefully holding back security updates. One should have zero impact, as I said, modern crypto algorithms do not depend on keeping the algorithm secret to maintain security. Implementation can absolutely be full of bugs that are incorrectly using crypto primitives though. The other has a direct impact on security. I don't think…

Source availability helps in crafting successful exploits in the real world. Providing the source of a closed source project to an adversary so that they can break your software is nefarious. If the author's justification was... "My crypto implementation is perfect. There are no bugs in my code, so providing source code (which the user community does not have) to an adversary does not have any effect on any user's se…

Your argument is that withholding source code raises the cost of attack for the NSA. They'll have to buy expensive decompilers, hire competent assembly/C programmers, it'll take longer, etc.

Seems like it would similarly be unethical for a local bakery to give the NSA a discount on cheesecake.

Re: The NSA called me after midnight and requested my source code (2018)

#127

Earlier quoted context omitted.

Why not? I mean, if the cops turned up at your door with a search warrant, you'd let them in, right?

If I ran an neighborhood ISP, and the cops asked me to spy on a neighbor (for reasons they wouldn't even provide), then I'd shut down first. If they just wanted to search _my_ stuff, sure. But if the only reason that I'm even capable of assisting the government in spying on somebody is that they are my customer, neighbor, friend, or user then I will not offer that assistance. That would be evil. Don't be evil.

The cops plant CP your servers. Help them spy on Joey Beer or they'll pursue criminal charges against you. Now what?

Re: The NSA called me after midnight and requested my source code (2018)

#128
post #52

I can't help but feel like the author sounds excessively credulous. I had to stop reading after he wrote "I could tell something big was up and there simply wasn’t time to debate the merits of handing over my source code to the NSA", because at that point my eyes rolled so hard they fell right out the back of my head. After I put them back in, I skipped down to the comments. I have a hard time not agreeing vehemently…

I'm sorry but if you think the NSA is the shadiest government agency on the planet, then you live in an information bubble. Do you think the NSA is shadier than the KGB? What about the Iranian Revolutionary Guard? Or even the CIA? I know people are upset about the Snowden revelations but there are much graver sins that have been committed by other agencies.

What bubble is that? Which sources are you basing this on? Who owns them?

Re: The NSA called me after midnight and requested my source code (2018)

#129
>>I probed again, this time about their capability at 40 bits; maybe that reduced level wasn’t such a State secret. But again, Dave was mum.

I recall that 40 bit encrypted Word documents obtained from Al-Qaeda safe houses in Afghanistan after 9/11 were successfully cracked. It was reported in the media, so it was an open secret after that.

Re: The NSA called me after midnight and requested my source code (2018)

#130
post #124
post #103

Earlier quoted context omitted.

I am in Norway, so the First Amendment carries little weight around here; our equivalent is 'Article 100' (of the Constitution) stating pretty much the same thing as the First Amendment. (This is hardly relevant; I just grasped the opportunity to stress that the HN crowd resides in the most peculiar places...)

Now, I definitely am biased, being a norwegian myself. But I see people mentioning themselves being norwegians everywhere here on HN. I don’t recall seeing half as many people going around saying, «I’m a dane» or similar; this seems peculiar, Norway is small. I wonder if it actually is at it seems to me, or if I just miss these seemingly non–but—actually-not–non-existant remarks.

They just like to point it out. :-D I suppose they are afraid someone would take them for a Swede, that'd be embarrassing.
Post reply on HN