Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

201–207 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#201

I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…

IIUC blocking people from making FOIA requests is illegal / can be grounds for a lawsuit, and they can always just classify anything they don’t want to give away, so it doesn’t really make sense for the NSA to do something like that. Their website is probably just broken.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#202

One of my favorite comics about cryptography. https://xkcd.com/538/ Government routinely posits a desperate need for backdoors in crypto and crypto secured products, but almost universally they get the data they want without needing a manufacturer provided backdoor. So why they insist on continuing to do that is beyond me. It's almost security theater. If they really want your protected information they will be able…

They can't break all the kneecaps. They do want all the data.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#203
post #141

Earlier quoted context omitted.

I wrote blog entry on this subject with a very similar name [0] which covers the CryptoAG story in more detail. It doesn't have the 2020 news. [0]: A Brief History of NSA Backdoors (2013), https://www.ethanheilman.com/x/12/index.html

> I wrote blog entry on this subject with a very similar name [0] which covers the CryptoAG story in more detail. It doesn't have the 2020 news. [0]: A Brief History of NSA Backdoors (2013), https://www.ethanheilman.com/x/12/index.html Wow this is super interesting I noticed this paragraph in the text. > 2013, Enabling for Encryption Chips: In the NSA's budget request documents released by Edward Snowden, one of the…

Good find, if I get around to updating that blog I'll add and credit your hn name.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#204

Earlier quoted context omitted.

Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)

This seems like a good way to learn what information your system is leaking that it shouldn't be leaking, eg if you use a VPN and they still block you, your VPN is probably not doing what it claims to be doing. (AFAIK a correctly implemented VPN would not send any of your computer or browser information to nsa.gov.)

> and they still block you, your VPN is probably not doing what it claims to be doing.

Of course it's doing what it should: binds IP address to a credit card used to pay for VPN! It's much solid that browser fingerprinting.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#206
post #91

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

> The company had about 230 employees, had offices in Abidjan, Abu Dhabi, Buenos Aires, Kuala Lumpur, Muscat, Selsdon and Steinhausen, and did business throughout the world. That's a... really strange list of office locations, especially considering the relatively small number of employees. > The owners of Crypto AG were unknown, supposedly even to the managers of the firm, and they held their ownership through beare…

IIRC the CEO was part of the board of directors, but the other directors were anonymous or represented by proxies.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#207
post #138
post #126

Earlier quoted context omitted.

Via lawyer / legal representative if I had to hazard a guess.

How does that representative prove that they really represent the owners, if the owners aren't known to management? How can they authorize someone without revealing identifying information?

Bearer Shares authorize the holder to show up at a shareholders meeting and vote to select certain representatives as board members. https://en.wikipedia.org/wiki/Bearer_instrument
Post reply on HN