Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

131–140 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#131
post #95

Earlier quoted context omitted.

> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Then what is it based on, if it happens across different devices and different IP addresses? I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't conta…

Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)

This seems like a good way to learn what information your system is leaking that it shouldn't be leaking, eg if you use a VPN and they still block you, your VPN is probably not doing what it claims to be doing. (AFAIK a correctly implemented VPN would not send any of your computer or browser information to nsa.gov.)

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#132

Earlier quoted context omitted.

Would be interesting what similar companies are (in parts) most likely agency fronts. My guess would be quite a few in the soft privacy selling business, such as VPN or email providers.

Proton mail is a CIA front email provider

It is impossible to tell if this is satire or not.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#133

Earlier quoted context omitted.

Even now, if you join a discussion on crypto and say something like "Why don't we double the key length" or "Why not stack two encryption algorithms on top of one another because then if either is broken the data is still secure", you'll immediately get a bunch of negative replies from anonymous accounts saying it's unnecessary and that current crypto is plenty secure.

Well, I think that would sevearly inhibit future development. Scaling on bitcoin has been a delicate game of optimizing every bit that gets recorded, but also support future developments that dont even exist yet, there is no undo button either. New signature schemas and clevar cryptography tricks can do quite a bit, but when you slap another layer of cryptography on you will inevitably make things worse in the long r…

The real security of Bitcoin is the choice of secp256k1. Basically unused before Bitcoin, but chosen specifically because he was more confident it wasn’t backdoored.

https://bitcoin.stackexchange.com/a/83623

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#134

I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…

That url (http://nsa.gov/serve-from-netstorage/) works via Tor, so maybe try that? ;)

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#135
post #107

Earlier quoted context omitted.

There can be moral reasons for treason. The founding fathers certainly considered themselves moral and principled. Your frustration is misguided. Simply do not confuse illegality with immorality. Human beings generally want to feel like they're doing more good than bad. As for "the DNA of a nation," we would probably spend a few hours figuring out the definition of what that even is just for starters.

From the outside, unironically calling any group of politicians "fathers" feels so weird. I know it's a super common turn of phrase, and that's kinda what gets me. > Human beings generally want to feel like they're doing more good than bad We're experts at convincing ourself that what is beneficial to us is also "good", whatever this actually means.

We can either rage against the era we were born into, or we can accept what we can change and what we cannot. One path leads to less frustration than the other. Be careful that you don't find yourself enjoying irritation.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#136

Earlier quoted context omitted.

Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)

This honestly seems kinda fun. If one was really dedicated: buy new device with cash; purchased and used outside city of residence; don’t drive there, non-electric bike or walk; only use device to connect to the website from public wifi; never connect to own wifi; don’t use same VPN service as usual. Not sure if I missed anything. Probably did.

Or walk into an internet cafe. Cafe membership systems, if any, probably aren't yet connected enough to prevent showing you the raw Internet for first few minutes, for few more years. Everyone who's vocal online should try this once in a while. Even Google search results noticeably change depending on your social classes inferred from location and whatnot.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#137

I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…

I'm curious as to why the NSA still has http:// urls.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#138
post #126
post #91

Earlier quoted context omitted.

> The company had about 230 employees, had offices in Abidjan, Abu Dhabi, Buenos Aires, Kuala Lumpur, Muscat, Selsdon and Steinhausen, and did business throughout the world. That's a... really strange list of office locations, especially considering the relatively small number of employees. > The owners of Crypto AG were unknown, supposedly even to the managers of the firm, and they held their ownership through beare…

Via lawyer / legal representative if I had to hazard a guess.

How does that representative prove that they really represent the owners, if the owners aren't known to management? How can they authorize someone without revealing identifying information?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#139
post #23

Earlier quoted context omitted.

> anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch Not really; anyone using chips with Intel ME or AMD PSP have an additional large binary blob running on their system which may or may not contain bugs or backdoors (of course, also realizing a sufficiently bad bug is indistinguishable from a backdoor). There are tens to hundreds of such blobs run…

Yeah, this lives in the back of my mind too. I run debian on 11th gen intel, but with the non-free blobs included to make life easier. I've been meaning to try it without them, but it's too tempting to just get things 'up' instead of hacking on it.

There's little we can do about it short of running ancient libreboot computers. We'll never be truly free until we have the technology to manufacture free computer chips at home, just like we can make free software at home.
Post reply on HN