The NSA's Backdoor in Dual EC
twitter.com
The NSA's Backdoor in Dual EC
1–10 of 95 posts
Re: The NSA's Backdoor in Dual EC
#2Re: The NSA's Backdoor in Dual EC
#3I'd like to go even further and propose the following terms:
* computer wishful thinking
* security by credulity
* zero-skepticism proofRe: The NSA's Backdoor in Dual EC
#4No, I am not. But, I understand information theory and people. I don't need an ivory tower credential to call out potential bullshit or leverage my own intuition.
This kind of nonsense also makes me wonder how many of those "dont roll your own crypto" people are intentionally pushing developers towards these state-sponsored libraries & methods.
Re: The NSA's Backdoor in Dual EC
#5Can we have more technical details regarding this? I guess some heavy math (number theory) is involved here but really intrigued how it was developed.
Re: The NSA's Backdoor in Dual EC
#6> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm in 2012, according to two people involved with Juniper’s investigation and an internal document detailing its findings that Bloomberg reviewed. The hackers altered the algorithm so they could decipher encrypted data flowing through the virtual private network connections created by NetScreen devices. They returned in…
As i understand it, the hackers replaced a magic number Q with a different value than the standards compliant one, where they had pre-computed P.
Re: The NSA's Backdoor in Dual EC
#7Re: The NSA's Backdoor in Dual EC
#8That the "re-keying" edit fits in 32 bytes is a neat math trick, but doesn't seem to me like a central issue. What am I misunderstanding?
>"In practice this would simply mean hacking into a major firewall manufacturer’s poorly-secured source code repository, changing 32 bytes of data, and then waiting for the windfall when a huge number of VPN connections suddenly became easy to decrypt. And that’s what happened. 10/"
Re: The NSA's Backdoor in Dual EC
#9> Members of a hacking group linked to the Chinese government called APT 5 hijacked the NSA algorithm in 2012, according to two people involved with Juniper’s investigation and an internal document detailing its findings that Bloomberg reviewed. The hackers altered the algorithm so they could decipher encrypted data flowing through the virtual private network connections created by NetScreen devices. They returned in…
https://dl.acm.org/doi/pdf/10.1145/3266291 goes into it in some detail
Re: The NSA's Backdoor in Dual EC
#10Calling out the cryptographic community on this has always resulted in becoming tarred & feathered in my experience. "How dare you question these experts? You are not a cryptographer." No, I am not. But, I understand information theory and people. I don't need an ivory tower credential to call out potential bullshit or leverage my own intuition. This kind of nonsense also makes me wonder how many of those "dont roll…