Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

21–30 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#21

Earlier quoted context omitted.

It's not a false claim, assuming the feds will keep such a key "secure" is not backed by evidence. Top secret materials are leaked all the time. Private keys from well secured systems are extracted from hacks. The FBI having such a key would make them a very profitable target for the various corps that specialize in hacking for hire. For example, NSO group. If the power doesn't exist, nobody can exploit it.

Do military cryptographic keys leak often? Do nuclear codes leak? The times highly valuable cryptographic keys leaked for various cryptocurrency exchanges it has generally if not always been due to gross negligence. Such a key would be highly sensitive and it would also require very little traffic to use. You would just need to send the secure system a KEM ( I don't doubt they could secure it. Can even split the key…

> Do nuclear codes leak?

For many years, the code was 00000000.

https://arstechnica.com/tech-policy/2013/12/launch-code-for-...

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#23

This topic comes up a bunch still. Someone please correct me, but as I understand it anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch. I know puri.sm[0] takes some steps to try to plug the hole, but haven't read up to see if it's effective or no. [0] https://puri.sm/learn/intel-me/

> anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch

Not really; anyone using chips with Intel ME or AMD PSP have an additional large binary blob running on their system which may or may not contain bugs or backdoors (of course, also realizing a sufficiently bad bug is indistinguishable from a backdoor).

There are tens to hundreds of such blobs running on almost any modern system and these are just one example. I would argue that ME and PSP are not the worst blob on many systems; they have both unsupported but almost certainly effective (MEcleaner / ME code removal), supported and almost certainly effective (HAP bit), or supported and likely effective (ME / PSP disable command) mechanisms to disable their functionality, and they are comparatively well-documented versus the firmware that runs on every other peripheral (networking, GPU, etc.) and comparatively hardened versus EFI.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#24

Earlier quoted context omitted.

It's not a false claim, assuming the feds will keep such a key "secure" is not backed by evidence. Top secret materials are leaked all the time. Private keys from well secured systems are extracted from hacks. The FBI having such a key would make them a very profitable target for the various corps that specialize in hacking for hire. For example, NSO group. If the power doesn't exist, nobody can exploit it.

Do military cryptographic keys leak often? Do nuclear codes leak? The times highly valuable cryptographic keys leaked for various cryptocurrency exchanges it has generally if not always been due to gross negligence. Such a key would be highly sensitive and it would also require very little traffic to use. You would just need to send the secure system a KEM ( I don't doubt they could secure it. Can even split the key…

What are you going to do with a nuclear code without access or authority to launch the nukes?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#25

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

You assume a perfect implementation of the backdoor. Even if the cryptographic part were well-implemented, someone will accidentally ship a release build with a poorly safeguarded test key, or with a disabled safety that they normally use to test it.

It's an unnecessary moving part that can break, except that this particular part breaking defeats the whole purpose of the system.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#26

Earlier quoted context omitted.

And Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?

Source/reference? I’m not aware of such a backdoor

See the posting above about the Arstechnica article.

During the last days of 2023 there was a big discussion, also on HN, after it was revealed that all recent Apple devices had a hardware backdoor that allowed bypassing all memory access protections claimed to exist by Apple.

It is likely that the backdoor consisted in some cache memory test registers used during production, but it is absolutely incomprehensible how it has been possible for many years that those test registers were not disabled at the end of the manufacturing process but they remained accessible for the attackers who knew Apple's secrets. For instance any iPhone could be completely controlled remotely after sending to it an invisible iMessage message.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#27

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

> As long as the government can keep a private key secure only they could make use of it.

Well, keep in mind they would have to keep it secure in perpetuity. Any leak over the lifetime of any of that hardware would be devastating to the owners. Blue Team/Defensive security is often described as needing to be lucky every time, where as Red Team/attackers just have to get lucky once.

This attack vector is in addition to just exploiting the implementation in some way, which I don't think can be handwaved away.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#28

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

More details here:

https://web.archive.org/web/20200212014117/https://www.washi...

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#29

This topic comes up a bunch still. Someone please correct me, but as I understand it anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch. I know puri.sm[0] takes some steps to try to plug the hole, but haven't read up to see if it's effective or no. [0] https://puri.sm/learn/intel-me/

Most consumer products (as opposed to some of those marketed to businesses) don't have enough of the components in place for the ME to accomplish anything, good or bad.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#30

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

>As long as the government can keep a private key secure only they could make use of it.

That's a big "if". Look at how the government has protected physical keys...

Ever since the TSA accidentally leaked them, you can buy a set of keys on Amazon for $5 that opens 99% of "TSA approved" locks

Post reply on HN