Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

51–60 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#51
post #23

Earlier quoted context omitted.

> anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch Not really; anyone using chips with Intel ME or AMD PSP have an additional large binary blob running on their system which may or may not contain bugs or backdoors (of course, also realizing a sufficiently bad bug is indistinguishable from a backdoor). There are tens to hundreds of such blobs run…

Yeah, this lives in the back of my mind too. I run debian on 11th gen intel, but with the non-free blobs included to make life easier. I've been meaning to try it without them, but it's too tempting to just get things 'up' instead of hacking on it.

Debian has been hacked by Intel's blobs from my point of view

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#52

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

The same government that failed to keep all of it's Top Secret clearance paperwork secure? How soon we forget the OPM hack...

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#53
post #48

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

The CIA/BND connection wasn't known, but the collusion with certain agencies was known to different degrees for decades: https://en.wikipedia.org/w/index.php?title=Crypto_AG&oldid=7...

Considering that I remember reading the CIA’s own historical document on this operation, I would guess its usefulness had run its course. If I’m not mistaken, it was the CIA who released the document to journalists; it seemed like bragging.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#54

Earlier quoted context omitted.

Source/reference? I’m not aware of such a backdoor

See the posting above about the Arstechnica article. During the last days of 2023 there was a big discussion, also on HN, after it was revealed that all recent Apple devices had a hardware backdoor that allowed bypassing all memory access protections claimed to exist by Apple. It is likely that the backdoor consisted in some cache memory test registers used during production, but it is absolutely incomprehensible how…

"Convenient software/hardware bugs"... but "they are not backdoors, I swear!"

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#56

This topic comes up a bunch still. Someone please correct me, but as I understand it anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch. I know puri.sm[0] takes some steps to try to plug the hole, but haven't read up to see if it's effective or no. [0] https://puri.sm/learn/intel-me/

Are these blob type of attacks accessible after boot? Essentially, are these only accessible if you have physical access? And at that point, isn't it game over anyways?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#57

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

> As long as the government can keep a private key secure only they could make use of it. Your devices would be secure as long as a private key that happened to be the most valuable intelligence asset in the United States, accessed thousands of times per day, by police spread across the entire nation, was never copied or stolen.

Well, it's a good thing that we don't have to worry about corrupt police /s

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#58
post #48

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

The CIA/BND connection wasn't known, but the collusion with certain agencies was known to different degrees for decades: https://en.wikipedia.org/w/index.php?title=Crypto_AG&oldid=7...

To add another dimension to this, personally i think that the Crypto AG relationship is what is referred to as "HISTORY" in this leaked NSA ECI codenames list.

https://robert.sesek.com/2014/10/nsa_s_eci_compartments.html

> HISTORY HST NCSC (TS//SI//NF) Protects NSA and certain commercial cryptologic equipment manufacturer relationships.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#60
One of my favorite comics about cryptography. https://xkcd.com/538/

Government routinely posits a desperate need for backdoors in crypto and crypto secured products, but almost universally they get the data they want without needing a manufacturer provided backdoor. So why they insist on continuing to do that is beyond me. It's almost security theater.

If they really want your protected information they will be able to get it. Either through a wrench or a legal wrench. In lieu of that they can use practically unlimited resources at their disposal from who they employ (or contract out to) to the long axis to which most secured devices succumb from, time.

My personal threat model isn't to defeat the government. They will get the data eventually. My personal threat model is corporations that want to know literally everything about me and bad faith private actors (scammers, cybercrime and thieves) that do too.

Ultimately it will take strict legislation and compliance measurement along with penalties to protect the government from overstepping the bounds they promise not to step over already, let alone new ones. It will take even stricter legislation to stop corporations from doing it. There are significant financial and political incentives for our ruling bodies to not do that, unfortunately.

I mean honestly, when you have this kind of ability at your disposal...

https://www.npr.org/2021/06/08/1004332551/drug-rings-platfor...

Post reply on HN