Encryption is meaningless with cpu-level side-channel memory key dumps active on most modern platforms. The reality is if you have been targeted for financial or technological reasons, than any government will eventually get what they are after. One can't take it personally, as all despotic movements also started with sycophantic idealism. Have a great day, =) https://xkcd.com/538/
A brief history of the U.S. trying to add backdoors into encrypted data (2016)
111–120 of 207 posts
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#112Earlier quoted context omitted.
The idea was to make it blatantly clear that it's not a "munition".
Why would that matter, if source code is protected speech anyway? And why is it more "clear" with a printed book vs. an emailed text file?
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#113As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG
I wrote blog entry on this subject with a very similar name [0] which covers the CryptoAG story in more detail. It doesn't have the 2020 news. [0]: A Brief History of NSA Backdoors (2013), https://www.ethanheilman.com/x/12/index.html
This was of particular interest to me:
>>>"...1986 Reagan tipped off the Libyans that the US could decrypt their communications by talking about information he could only get through Libya decrypts on TV15. In 1991 the Iranians learned that the NSA could break their diplomatic communications when transcripts of Iranian diplomatic communications ended up in a French court case..."
Because, in 1986 - thats effectively when a lot of the phreaking and social engineering was at a peak - Cyberpunk was moving from imagination --> zeitgeist --> reality.
Social engineering and line-printer litter recovery were yielding the backdoors into the Telecom Switching system. BBS's were raging [0].
So when you get a gaph-guffaw look into infosec in a slipup like these ones, it reinforces in mind that the 80s were some really wild times all around as technology tsunami'd from people's minds business and reality.
[0] BBS Docu - https://www.imdb.com/title/tt0460402/
[1] phreaking - https://en.wikipedia.org/wiki/Phreaking
[2] history of phreaking - https://www.youtube.com/watch?v=8PmkUPBhL4U
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#114Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#115Earlier quoted context omitted.
I know. We definitely aren't a nation founded on outright treason and insurrection, and thumbing our nose at authority and doing the moral thing isn't in our DNA in any way, shape, or form. Frustrating that some people think otherwise.
There can be moral reasons for treason. The founding fathers certainly considered themselves moral and principled. Your frustration is misguided. Simply do not confuse illegality with immorality. Human beings generally want to feel like they're doing more good than bad. As for "the DNA of a nation," we would probably spend a few hours figuring out the definition of what that even is just for starters.
> Human beings generally want to feel like they're doing more good than bad
We're experts at convincing ourself that what is beneficial to us is also "good", whatever this actually means.
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#116Earlier quoted context omitted.
I wrote blog entry on this subject with a very similar name [0] which covers the CryptoAG story in more detail. It doesn't have the 2020 news. [0]: A Brief History of NSA Backdoors (2013), https://www.ethanheilman.com/x/12/index.html
This is an epically cool blog post! - submit it to HN on its own merits. This was of particular interest to me: >>> "...1986 Reagan tipped off the Libyans that the US could decrypt their communications by talking about information he could only get through Libya decrypts on TV15. In 1991 the Iranians learned that the NSA could break their diplomatic communications when transcripts of Iranian diplomatic communications…
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#117Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…
At the time, I had a t-shirt that said "this t-shirt is a munition", because it also had on it the RSA public key algorithm encoded as a barcode.
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#118As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG
Would be interesting what similar companies are (in parts) most likely agency fronts. My guess would be quite a few in the soft privacy selling business, such as VPN or email providers.
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#119Encryption is meaningless with cpu-level side-channel memory key dumps active on most modern platforms. The reality is if you have been targeted for financial or technological reasons, than any government will eventually get what they are after. One can't take it personally, as all despotic movements also started with sycophantic idealism. Have a great day, =) https://xkcd.com/538/
Agree with this. Makes me think that the code-breakers themselves must be using specialized hardware to protect their own side-channels. But for this to be feasible you need to have big chipmakers in on it. Fascinating to consider
I once insisted I could be bribed to avoid the escalation of coercion as a joke, that was funny until someone actually offered $80k for my company workstation one day.
It is a cultural phenomena, as in some places it is considered standard acceptable practice.
My advice is to be as boring as possible, legally proactive, and keep corporate financial profit modes quiet.
Good luck =)
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#120I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…
> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Then what is it based on, if it happens across different devices and different IP addresses? I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't conta…
also fun fact, even Tor Browser can't hide the real OS you're running when a site uses javascript-based OS queries.