Earlier quoted context omitted.
This has nothing to do with brain power. This was a deliberately backdoored algorithm that any cryptographer familiar with elliptic curve cryptography could've come up with. It wasn't even good or clever, seeing as people saw through it almost immediately. The only thing it had going for it is it was plausibly deniable and that allowed the US government to force people to implement it, since nobody could prove the NS…
> The NSA doesn't break real crypto any more, they just find or make software bugs. They still can, and do break crypto. The Snowden papers (IIRC) mentioned that NSA factored a bunch of primes by throwing ridiculous amounts of compute at it: billions of dollars. With that,they could break schemes with no forward secrecy at their leisure (from all the historical internet traffic they had gathered), and they could decr…
The NSA's Backdoor in Dual EC
71–80 of 95 posts
Re: The NSA's Backdoor in Dual EC
#72> the field is called computer security; not computer optimism I'd like to go even further and propose the following terms: * computer wishful thinking * security by credulity * zero-skepticism proof
The NSA actually had their own term for this, NOBUS, which meant "nobody but us". They were fond of attacks that they thought nobody but the NSA could exploit. They were arrogant enough to think they were better than all adversaries.
Re: The NSA's Backdoor in Dual EC
#73The amount of brain power that the NSA is using is staggering, it is not surprising they have such upper hand on cryptography. I've heard the NSA is one of the biggest employer of math people. At that point, I'm guessing some form of obscurity might somehow be a better idea to protect data from the NSA, or at least it would force NSA employees to analyze some obfuscated data, buying more time than just using mainstre…
>I've heard the NSA is one of the biggest employer of math people. What are the other options for pure maths people? Academia? Does that really pay any better, plus, depending on your teaching level, there's a good chance you're just a babysitter. A cush gov't job probably sounds pretty good where you will actively be using your skills on a daily basis. Are there FAANG opportunties for math people at the same level a…
Re: The NSA's Backdoor in Dual EC
#74The entire concept of a backdoor that only the good guys have the keys too is so moroinic as to make my blood boil. The TSA locks were picked because a photo of the keys were posted online. The NSA forced an encryption method that they knew how to defeat got pwned. Yet the backdoor method still gets bandied about like it's the one thing to save us when it is exactly what will sink us.
> The entire concept of a backdoor that only the good guys have the keys too is so moroinic as to make my blood boil. Uhm...isn't the whole basis of modern cryptography the idea that you can have keys that only the good guys know? Every time you use an HTTPS site for example you are relying on the existence of keys that only the good guys know. Every time you use an end to end encrypted messaging system you are relyi…
No it in any way, but based on your other examples, maybe you're thinking about certificate authorities?
Re: The NSA's Backdoor in Dual EC
#75Earlier quoted context omitted.
No, the attackers just re-pinned the backdoor lock cylinder that the NSA put on their "secure" door. That's why nobody noticed. The NSA conveniently left them a door with a backdoor they could hijack in a way that is effectively invisible. Replacing the whole door would've been like replacing the entire DRBG, which would've much more likely raised alarms.
Having a convenient backdoor already integrated definitely aided the attack, but a sophisticated attacker with the ability to silently modify your codebase is a pretty bad place to start from regardless.
Re: The NSA's Backdoor in Dual EC
#76https://threadreaderapp.com/thread/1433470109742518273.html
Re: The NSA's Backdoor in Dual EC
#77"In a July 2020 response to Wyden and other members of Congress, Juniper provided few new details of the case but blamed the intrusions on a “sophisticated nation-state hacking unit.” NSA told Wyden’s staff in 2018 that there was a “lessons learned” report, but the agency “now asserts that it cannot locate this document,” according to a Wyden aide. "
Re: The NSA's Backdoor in Dual EC
#78> the field is called computer security; not computer optimism I'd like to go even further and propose the following terms: * computer wishful thinking * security by credulity * zero-skepticism proof
The NSA actually had their own term for this, NOBUS, which meant "nobody but us". They were fond of attacks that they thought nobody but the NSA could exploit. They were arrogant enough to think they were better than all adversaries.
Re: The NSA's Backdoor in Dual EC
#79The amount of brain power that the NSA is using is staggering, it is not surprising they have such upper hand on cryptography. I've heard the NSA is one of the biggest employer of math people. At that point, I'm guessing some form of obscurity might somehow be a better idea to protect data from the NSA, or at least it would force NSA employees to analyze some obfuscated data, buying more time than just using mainstre…
> In the end, I don't think nobody has good enough reason to hide stuff from the US government, at least that's my opinion, as long as the US gov is not too evil or not too corrupt. As long as other dangerous governments or criminals can't do too much cyber damage, things are fine. Such a bizarre take. The US government is one of the most belligerent and feared governments in the world, with a known track record of s…
Re: The NSA's Backdoor in Dual EC
#80> the field is called computer security; not computer optimism I'd like to go even further and propose the following terms: * computer wishful thinking * security by credulity * zero-skepticism proof