What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?
New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
21–30 of 122 posts
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#22Compared to the rest of the HN crowd, my knowledge of crypto is very light, so I could be incorrect... But aren't most widely adopted algorithms decently future proof? To where you would sort of have to break math in order for them to be crackable, if used with a very strong password? Sure, flaws were found in RSA, etc. But does something like that have a decent chance of happening again?
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#23Compared to the rest of the HN crowd, my knowledge of crypto is very light, so I could be incorrect... But aren't most widely adopted algorithms decently future proof? To where you would sort of have to break math in order for them to be crackable, if used with a very strong password? Sure, flaws were found in RSA, etc. But does something like that have a decent chance of happening again?
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#24I think observers have long assumed NSA is some number of years ahead – say, 2-30 years ahead – of openly published results in cryptanalysis and cryptosystem vulnerabilities.
But it's really hard to assume that - that's assuming true mathematical leaps and invention. Admittedly if you put enough cryptographers on the payroll they may form their own university, but they still need the air of their peers on the outside. Imagine a cosmologist today transported 30 years back and asked to attend conferences - they would gain no inspiration. I think we put too much emphasis on the single data p…
It's also much easier to invent a cryptosystem than to break one.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#25Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#26Compared to the rest of the HN crowd, my knowledge of crypto is very light, so I could be incorrect... But aren't most widely adopted algorithms decently future proof? To where you would sort of have to break math in order for them to be crackable, if used with a very strong password? Sure, flaws were found in RSA, etc. But does something like that have a decent chance of happening again?
HTTPS, for example, depends on both crypto algorithm implementation, SSL/TLS, the responsible Certificate Authority[1], your random number generator, your OS, your hardware, and, of course, much the same list for the people at the remote end.
The other part of the problem is that, IIRC, the NSA is one of the largest employers of crypto/number-theoretic mathematicians, and from the article, this program with a 35k headcount probably has a bunch of them. Between them, and compute clusters not implausibly denominated in acres, a teeny tiny little flaw might be enough, if they think you deserve the effort.
[1] On a tangent, has anyone explored the implications of a "give us some valid certs/signing keys for $whoever and lie to everyone who asks" NSL to one of their domestic CAs? Apart from the EFF SSL-observatory or someone else maybe noticing, of course.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#27I wonder why do newspapers insist on labelling Snowden a 'leaker'. Why not 'whistleblower', or 'privacy advocate'?
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#28What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#29Compared to the rest of the HN crowd, my knowledge of crypto is very light, so I could be incorrect... But aren't most widely adopted algorithms decently future proof? To where you would sort of have to break math in order for them to be crackable, if used with a very strong password? Sure, flaws were found in RSA, etc. But does something like that have a decent chance of happening again?
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#30This makes me think that it might be good to have a "security by obscurity" layer on top of the existing security layer. A big weakness of a public security protocol is that a huge government might privately crack it and tell nobody.