Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

151–160 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#151

Earlier quoted context omitted.

The real security of Bitcoin is the choice of secp256k1. Basically unused before Bitcoin, but chosen specifically because he was more confident it wasn’t backdoored. https://bitcoin.stackexchange.com/a/83623

And ed25519 was out of the question, since -- being brand new -- its use would have given away the fact that DJB was among the group of people who presented themselves as Satoshi Nakamoto .

Evidence?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#152
This leaves out at least one other proven case - the NSA worked to weaken an early encrypted telephone system that was sold to numerous other governments and allowed them to listen in on conversations.

Then there's this: https://www.cnet.com/tech/tech-industry/nsa-secret-backdoor-...

And then there was the Tailored Access Operations group that backdoored hundreds if not thousands of computers and networking gear https://en.wikipedia.org/wiki/Tailored_Access_Operations

And then there's Bullrun where they partnered with commercial software and hardware companies to insert backdoors, specifically in many commercial VPN systems https://en.wikipedia.org/wiki/Bullrun_(decryption_program)

Let's also not forget the backdooring of Windows NT: https://en.wikipedia.org/wiki/NSAKEY

...and Lotus Notes was also backdoored, as well.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#153

In case anyone is wondering about the context for this 2016 article, it was right after the 2015 San Bernardino attack and the FBI was trying to get into one of the attacker's phones. Apple resisted the request primarily because they wanted a certificate that would allow them to install any rogue firmware/app/OS on any iPhone, not just the attacker's. https://en.wikipedia.org/wiki/2015_San_Bernardino_attack

The FBI has used damn near every major incident to push for nerfing encryption, and inbetween they bray about child porn.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#154

Earlier quoted context omitted.

Would be interesting what similar companies are (in parts) most likely agency fronts. My guess would be quite a few in the soft privacy selling business, such as VPN or email providers.

Proton mail is a CIA front email provider

I actually wish this was true. I want an email service that would last forever and is secure enough from my threats, namely security breaches of the email host and account takeover from non state actors.

Gmail is close enough, but I want an alternative. An email service run by the nsa or the cia would be great.

(No sarcasm is intended)

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#155

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

At the time, I had a t-shirt that said "this t-shirt is a munition", because it also had on it the RSA public key algorithm encoded as a barcode.

i seem to have vague recollection of a variant of this shirt that had a perl script on it? or was the perl script for decoding the barcode?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#156
post #143

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

> [...] and this enabled others to OCR it, and recompile it offshore. Did it? Or did it just give them plausible deniability? I remember playing with OCR as a kid and all the software I could get my hands on gave horrendous results, even if the input was as perfect as one could hope for. And even today I sometimes run tesseract on perfect screenshots and it still makes weird mistakes. Would be interesting to know if…

Banks used it on checques for ages, why would it be that difficult? You do need a compatible typesetting though.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#157
post #138
post #126

Earlier quoted context omitted.

Via lawyer / legal representative if I had to hazard a guess.

How does that representative prove that they really represent the owners, if the owners aren't known to management? How can they authorize someone without revealing identifying information?

Where would this need to really prove anything arise from? The intermediaries just hire and pay the managers, that's enough

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#158

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

> As long as the government can keep a private key secure only they could make use of it.

That's a disingenuous claim since it's known they can't

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#159

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

RSA = Republic of South Africa

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#160

Earlier quoted context omitted.

Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)

This seems like a good way to learn what information your system is leaking that it shouldn't be leaking, eg if you use a VPN and they still block you, your VPN is probably not doing what it claims to be doing. (AFAIK a correctly implemented VPN would not send any of your computer or browser information to nsa.gov.)

VPNs do not do what you seem to think they do. A VPN is a privacy tool as much as restarting your router to get a new IP lease is a privacy tool.
Post reply on HN