> the field is called computer security; not computer optimism I'd like to go even further and propose the following terms: * computer wishful thinking * security by credulity * zero-skepticism proof
The NSA actually had their own term for this, NOBUS, which meant "nobody but us". They were fond of attacks that they thought nobody but the NSA could exploit. They were arrogant enough to think they were better than all adversaries.
The NSA's Backdoor in Dual EC
61–70 of 95 posts
Re: The NSA's Backdoor in Dual EC
#62Earlier quoted context omitted.
This has nothing to do with brain power. This was a deliberately backdoored algorithm that any cryptographer familiar with elliptic curve cryptography could've come up with. It wasn't even good or clever, seeing as people saw through it almost immediately. The only thing it had going for it is it was plausibly deniable and that allowed the US government to force people to implement it, since nobody could prove the NS…
> The NSA doesn't break real crypto any more, they just find or make software bugs. They still can, and do break crypto. The Snowden papers (IIRC) mentioned that NSA factored a bunch of primes by throwing ridiculous amounts of compute at it: billions of dollars. With that,they could break schemes with no forward secrecy at their leisure (from all the historical internet traffic they had gathered), and they could decr…
Re: The NSA's Backdoor in Dual EC
#63A bit of a tangent, but why do people insist on posting these things to twitter? They are so annoying to read like that. What does twitter offer that other platforms, designed for this type of content, don't?
Re: The NSA's Backdoor in Dual EC
#64Earlier quoted context omitted.
This has nothing to do with brain power. This was a deliberately backdoored algorithm that any cryptographer familiar with elliptic curve cryptography could've come up with. It wasn't even good or clever, seeing as people saw through it almost immediately. The only thing it had going for it is it was plausibly deniable and that allowed the US government to force people to implement it, since nobody could prove the NS…
> The NSA doesn't break real crypto any more, they just find or make software bugs. They still can, and do break crypto. The Snowden papers (IIRC) mentioned that NSA factored a bunch of primes by throwing ridiculous amounts of compute at it: billions of dollars. With that,they could break schemes with no forward secrecy at their leisure (from all the historical internet traffic they had gathered), and they could decr…
Re: The NSA's Backdoor in Dual EC
#65Earlier quoted context omitted.
Sure there is! There are people who act with malice and sadism, people driven to harm others, people overwhelmed by greed and people consumed by a lust for power. And there are people who devote their lives to aiding others, people who are mindful of their community's needs, people who take opportunities to help others over opportunities to help themselves. All these sorts can be found across the whole spectrum of we…
While I generally agree with your take, it's important to remember that the road to hell is paved with good intentions. Sometimes the most evil actors are those knights who believe they are fighting for some great holy cause.
Re: The NSA's Backdoor in Dual EC
#66Earlier quoted context omitted.
The NSA actually had their own term for this, NOBUS, which meant "nobody but us". They were fond of attacks that they thought nobody but the NSA could exploit. They were arrogant enough to think they were better than all adversaries.
What do you mean "were"..?
Not saying that will change behaviour but it's hard even for the massively delusional to continue to really believe they can walk on water when they find themselves under it.
Re: The NSA's Backdoor in Dual EC
#67Earlier quoted context omitted.
The attackers didn't get the keys to the back door. They actually replaced the entire door with a new door that they made, which went unnoticed (by Juniper) for 3 years, locking out the owners of the original back door too. It's a rather impressive attack.
No, the attackers just re-pinned the backdoor lock cylinder that the NSA put on their "secure" door. That's why nobody noticed. The NSA conveniently left them a door with a backdoor they could hijack in a way that is effectively invisible. Replacing the whole door would've been like replacing the entire DRBG, which would've much more likely raised alarms.
Re: The NSA's Backdoor in Dual EC
#68https://threadreaderapp.com/thread/1433470109742518273.html
Quote: "Addendum: the White House Press Secretary was asked about this story, and their answer is “please stop asking about this story.” h/t " - https://youtu.be/Hfa6bih_gVc?t=1740
That's f*ing hilarious