Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

111–120 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#111

Encryption is meaningless with cpu-level side-channel memory key dumps active on most modern platforms. The reality is if you have been targeted for financial or technological reasons, than any government will eventually get what they are after. One can't take it personally, as all despotic movements also started with sycophantic idealism. Have a great day, =) https://xkcd.com/538/

Agree with this. Makes me think that the code-breakers themselves must be using specialized hardware to protect their own side-channels. But for this to be feasible you need to have big chipmakers in on it. Fascinating to consider

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#112
post #104
post #99

Earlier quoted context omitted.

The idea was to make it blatantly clear that it's not a "munition".

Why would that matter, if source code is protected speech anyway? And why is it more "clear" with a printed book vs. an emailed text file?

I think if you’re looking for a logical answer from first principles, you won’t find one. It’s more that the legal system runs on precedent, and a book fits far more squarely in the fact patterns of previous First Amendment cases. Likely the source code case would end up with the same outcome, but it doesn’t hurt to make it more obvious.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#113

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

I wrote blog entry on this subject with a very similar name [0] which covers the CryptoAG story in more detail. It doesn't have the 2020 news. [0]: A Brief History of NSA Backdoors (2013), https://www.ethanheilman.com/x/12/index.html

This is an epically cool blog post! - submit it to HN on its own merits.

This was of particular interest to me:

>>>"...1986 Reagan tipped off the Libyans that the US could decrypt their communications by talking about information he could only get through Libya decrypts on TV15. In 1991 the Iranians learned that the NSA could break their diplomatic communications when transcripts of Iranian diplomatic communications ended up in a French court case..."

Because, in 1986 - thats effectively when a lot of the phreaking and social engineering was at a peak - Cyberpunk was moving from imagination --> zeitgeist --> reality.

Social engineering and line-printer litter recovery were yielding the backdoors into the Telecom Switching system. BBS's were raging [0].

So when you get a gaph-guffaw look into infosec in a slipup like these ones, it reinforces in mind that the 80s were some really wild times all around as technology tsunami'd from people's minds business and reality.

[0] BBS Docu - https://www.imdb.com/title/tt0460402/

[1] phreaking - https://en.wikipedia.org/wiki/Phreaking

[2] history of phreaking - https://www.youtube.com/watch?v=8PmkUPBhL4U

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#114

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

[dead]

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#115
post #107
post #82

Earlier quoted context omitted.

I know. We definitely aren't a nation founded on outright treason and insurrection, and thumbing our nose at authority and doing the moral thing isn't in our DNA in any way, shape, or form. Frustrating that some people think otherwise.

There can be moral reasons for treason. The founding fathers certainly considered themselves moral and principled. Your frustration is misguided. Simply do not confuse illegality with immorality. Human beings generally want to feel like they're doing more good than bad. As for "the DNA of a nation," we would probably spend a few hours figuring out the definition of what that even is just for starters.

From the outside, unironically calling any group of politicians "fathers" feels so weird. I know it's a super common turn of phrase, and that's kinda what gets me.

> Human beings generally want to feel like they're doing more good than bad

We're experts at convincing ourself that what is beneficial to us is also "good", whatever this actually means.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#116

Earlier quoted context omitted.

I wrote blog entry on this subject with a very similar name [0] which covers the CryptoAG story in more detail. It doesn't have the 2020 news. [0]: A Brief History of NSA Backdoors (2013), https://www.ethanheilman.com/x/12/index.html

This is an epically cool blog post! - submit it to HN on its own merits. This was of particular interest to me: >>> "...1986 Reagan tipped off the Libyans that the US could decrypt their communications by talking about information he could only get through Libya decrypts on TV15. In 1991 the Iranians learned that the NSA could break their diplomatic communications when transcripts of Iranian diplomatic communications…

Thanks, just submitted

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#117

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

At the time, I had a t-shirt that said "this t-shirt is a munition", because it also had on it the RSA public key algorithm encoded as a barcode.

Had the same t-shirt with the barcode readable source code on it. I think prompted by seeing Greg Rose wear one, may have gotten it from him/mutual friends. As an foreign citizen I was never brave enough to wear it through a USA entry airport.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#118

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

Would be interesting what similar companies are (in parts) most likely agency fronts. My guess would be quite a few in the soft privacy selling business, such as VPN or email providers.

Proton mail is a CIA front email provider

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#119

Encryption is meaningless with cpu-level side-channel memory key dumps active on most modern platforms. The reality is if you have been targeted for financial or technological reasons, than any government will eventually get what they are after. One can't take it personally, as all despotic movements also started with sycophantic idealism. Have a great day, =) https://xkcd.com/538/

Agree with this. Makes me think that the code-breakers themselves must be using specialized hardware to protect their own side-channels. But for this to be feasible you need to have big chipmakers in on it. Fascinating to consider

No need, data collection is a different function than exploitation. People that are turned into assets are often not even aware how they are being used.

I once insisted I could be bribed to avoid the escalation of coercion as a joke, that was funny until someone actually offered $80k for my company workstation one day.

It is a cultural phenomena, as in some places it is considered standard acceptable practice.

My advice is to be as boring as possible, legally proactive, and keep corporate financial profit modes quiet.

Good luck =)

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#120
post #95

I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…

> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Then what is it based on, if it happens across different devices and different IP addresses? I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't conta…

there are MANY different ways to fingerprint something or someone, see e.g. https://abrahamjuliot.github.io/creepjs/ or https://scrapeops.io/web-scraping-playbook/how-to-bypass-clo....

also fun fact, even Tor Browser can't hide the real OS you're running when a site uses javascript-based OS queries.

Post reply on HN