Earlier quoted context omitted.
The real security of Bitcoin is the choice of secp256k1. Basically unused before Bitcoin, but chosen specifically because he was more confident it wasn’t backdoored. https://bitcoin.stackexchange.com/a/83623
And ed25519 was out of the question, since -- being brand new -- its use would have given away the fact that DJB was among the group of people who presented themselves as Satoshi Nakamoto .
A brief history of the U.S. trying to add backdoors into encrypted data (2016)
151–160 of 207 posts
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#152Then there's this: https://www.cnet.com/tech/tech-industry/nsa-secret-backdoor-...
And then there was the Tailored Access Operations group that backdoored hundreds if not thousands of computers and networking gear https://en.wikipedia.org/wiki/Tailored_Access_Operations
And then there's Bullrun where they partnered with commercial software and hardware companies to insert backdoors, specifically in many commercial VPN systems https://en.wikipedia.org/wiki/Bullrun_(decryption_program)
Let's also not forget the backdooring of Windows NT: https://en.wikipedia.org/wiki/NSAKEY
...and Lotus Notes was also backdoored, as well.
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#153In case anyone is wondering about the context for this 2016 article, it was right after the 2015 San Bernardino attack and the FBI was trying to get into one of the attacker's phones. Apple resisted the request primarily because they wanted a certificate that would allow them to install any rogue firmware/app/OS on any iPhone, not just the attacker's. https://en.wikipedia.org/wiki/2015_San_Bernardino_attack
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#154Earlier quoted context omitted.
Would be interesting what similar companies are (in parts) most likely agency fronts. My guess would be quite a few in the soft privacy selling business, such as VPN or email providers.
Proton mail is a CIA front email provider
Gmail is close enough, but I want an alternative. An email service run by the nsa or the cia would be great.
(No sarcasm is intended)
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#155Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…
At the time, I had a t-shirt that said "this t-shirt is a munition", because it also had on it the RSA public key algorithm encoded as a barcode.
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#156Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…
> [...] and this enabled others to OCR it, and recompile it offshore. Did it? Or did it just give them plausible deniability? I remember playing with OCR as a kid and all the software I could get my hands on gave horrendous results, even if the input was as perfect as one could hope for. And even today I sometimes run tesseract on perfect screenshots and it still makes weird mistakes. Would be interesting to know if…
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#157Earlier quoted context omitted.
Via lawyer / legal representative if I had to hazard a guess.
How does that representative prove that they really represent the owners, if the owners aren't known to management? How can they authorize someone without revealing identifying information?
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#158FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…
That's a disingenuous claim since it's known they can't
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#159Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#160Earlier quoted context omitted.
Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)
This seems like a good way to learn what information your system is leaking that it shouldn't be leaking, eg if you use a VPN and they still block you, your VPN is probably not doing what it claims to be doing. (AFAIK a correctly implemented VPN would not send any of your computer or browser information to nsa.gov.)