Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

91–100 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#91

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

> The company had about 230 employees, had offices in Abidjan, Abu Dhabi, Buenos Aires, Kuala Lumpur, Muscat, Selsdon and Steinhausen, and did business throughout the world.

That's a... really strange list of office locations, especially considering the relatively small number of employees.

> The owners of Crypto AG were unknown, supposedly even to the managers of the firm, and they held their ownership through bearer shares.

How does this work in practice? If management doesn't know who owns the company, how can the owners exercise influence on company business?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#92
I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that.

Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive) I could no longer access the NSA website. Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage.

Still in place today:

  Access Denied

  You don't have permission to access "http://nsa.gov/serve-from-netstorage/" on this server.
0: https://en.wikipedia.org/wiki/SHA-1#Development

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#93

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

I never understood the story about the book-printed PGP source code. Isn't source code protected speech under the first amendment anyway, regardless of the form in which it is transmitted? All kinds of media receive first amendment protection, including things like monetary donations, corporate speech, art, etc. I've never heard of there being a requirement for the printed form. Did the interpretation of the first amendment change recently in this regard?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#94
post #63

Earlier quoted context omitted.

Intel ME allows intentional remote access through the ME in some enterprise scenarios (vPro). The driver support matrix is quite small and this is a massively overblown concern IMO, but it’s the root of a lot of the hand wringing. However, onboard firmware based attacks are absolutely accessible remotely and after boot in many scenarios. It’s certainly plausible in theory that an exploit in ME firmware could, for exa…

> The closed-sourceness is only a tiny part of the problem, too - a lot of the worst attacks so far are actually in open source based EFI firmware, which is riddled with bugs. Can you elaborate and/or provide context/links?

https://eclypsium.com/blog/understanding-detecting-pixiefail...

https://binarly.io/posts/The_Far_Reaching_Consequences_of_Lo...

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#95

I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…

> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage.

Then what is it based on, if it happens across different devices and different IP addresses?

I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't contain any sensitive information).

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#96
post #59

I like that typo in the image label - the Chipper Clip lol

We've had enough of chipper clips to last a lifetime!

  It looks like you're writing an article about encryption. Would you like help?

  (o) Insert a joke about Apple forcing a U2 album on us

  (o) Let me write the joke myself

  [x] Don't show me this tip again

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#97

One of my favorite comics about cryptography. https://xkcd.com/538/ Government routinely posits a desperate need for backdoors in crypto and crypto secured products, but almost universally they get the data they want without needing a manufacturer provided backdoor. So why they insist on continuing to do that is beyond me. It's almost security theater. If they really want your protected information they will be able…

[deleted]

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#98
post #95

I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…

> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Then what is it based on, if it happens across different devices and different IP addresses? I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't conta…

Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe.

Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :)

https://imgur.com/a/rNIjrB2

Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#99
post #93

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

I never understood the story about the book-printed PGP source code. Isn't source code protected speech under the first amendment anyway, regardless of the form in which it is transmitted? All kinds of media receive first amendment protection, including things like monetary donations, corporate speech, art, etc. I've never heard of there being a requirement for the printed form. Did the interpretation of the first am…

The idea was to make it blatantly clear that it's not a "munition".

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#100

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

[flagged]

It really depends on the kind of law that you have. As the Soviet joke goes, "severity of the laws is mitigated by not having to follow them".
Post reply on HN