I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…
A brief history of the U.S. trying to add backdoors into encrypted data (2016)
201–207 of 207 posts
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#202One of my favorite comics about cryptography. https://xkcd.com/538/ Government routinely posits a desperate need for backdoors in crypto and crypto secured products, but almost universally they get the data they want without needing a manufacturer provided backdoor. So why they insist on continuing to do that is beyond me. It's almost security theater. If they really want your protected information they will be able…
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#203Earlier quoted context omitted.
I wrote blog entry on this subject with a very similar name [0] which covers the CryptoAG story in more detail. It doesn't have the 2020 news. [0]: A Brief History of NSA Backdoors (2013), https://www.ethanheilman.com/x/12/index.html
> I wrote blog entry on this subject with a very similar name [0] which covers the CryptoAG story in more detail. It doesn't have the 2020 news. [0]: A Brief History of NSA Backdoors (2013), https://www.ethanheilman.com/x/12/index.html Wow this is super interesting I noticed this paragraph in the text. > 2013, Enabling for Encryption Chips: In the NSA's budget request documents released by Edward Snowden, one of the…
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#204Earlier quoted context omitted.
Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)
This seems like a good way to learn what information your system is leaking that it shouldn't be leaking, eg if you use a VPN and they still block you, your VPN is probably not doing what it claims to be doing. (AFAIK a correctly implemented VPN would not send any of your computer or browser information to nsa.gov.)
Of course it's doing what it should: binds IP address to a credit card used to pay for VPN! It's much solid that browser fingerprinting.
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#205Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#206As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG
> The company had about 230 employees, had offices in Abidjan, Abu Dhabi, Buenos Aires, Kuala Lumpur, Muscat, Selsdon and Steinhausen, and did business throughout the world. That's a... really strange list of office locations, especially considering the relatively small number of employees. > The owners of Crypto AG were unknown, supposedly even to the managers of the firm, and they held their ownership through beare…
Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)
#207Earlier quoted context omitted.
Via lawyer / legal representative if I had to hazard a guess.
How does that representative prove that they really represent the owners, if the owners aren't known to management? How can they authorize someone without revealing identifying information?