Live data from Hacker News

New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

wired.com

41–50 of 122 posts

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#41
post #2

I think observers have long assumed NSA is some number of years ahead – say, 2-30 years ahead – of openly published results in cryptanalysis and cryptosystem vulnerabilities.

But it's really hard to assume that - that's assuming true mathematical leaps and invention. Admittedly if you put enough cryptographers on the payroll they may form their own university, but they still need the air of their peers on the outside. Imagine a cosmologist today transported 30 years back and asked to attend conferences - they would gain no inspiration. I think we put too much emphasis on the single data p…

Well, we have at least twice as many data points as that. IBM discovered differential cryptanalysis in the early 70s, and the NSA apparently knew about it before then, and nobody else found out until the late 80s.

I don't know what organization spends the most money on cryptanalysis every year, but the NSA's gotta be near the top. It's reasonable to assume they've found important results that the public won't know of for several years.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#42

Compared to the rest of the HN crowd, my knowledge of crypto is very light, so I could be incorrect... But aren't most widely adopted algorithms decently future proof? To where you would sort of have to break math in order for them to be crackable, if used with a very strong password? Sure, flaws were found in RSA, etc. But does something like that have a decent chance of happening again?

> But aren't most widely adopted algorithms decently future proof?

Absolutely not.

The algorithms rely on assumptions, and they're not at all future-proof.

One is about certain classes of mathematical problems being hard (in RSA, it's factoring numbers). We don't know whether they're hard (there's no proof; it's an "open problem").

Another is that random numbers selected in encryption are uniformly distributed and unpredictable. (In RSA, you pick two large prime numbers, p and q. If two people share a number, say my p is the same as your q, then we're both screwed. This particular assumption has been already been violated a bunch of times in the past twenty years; from the Debian OpenSSL thing, to the Android/Bitcoin thing.)

There are many other assumptions (Certificate Authorities can be trusted, etc.) that a paranoid person would have to worry about.

I think the new hotness is elliptic curve cryptography (e.g. ECDSA), but I don't understand it well enough to know if it's substantially better than the RSA implementations that are currently popular. I'd say what we have now is like a lock on the door -- it's enough to prevent the neighbour's kid from getting in, but not enough to stop a determined lockpick or the government.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#43
post #2

I think observers have long assumed NSA is some number of years ahead – say, 2-30 years ahead – of openly published results in cryptanalysis and cryptosystem vulnerabilities.

Bruce Schneier wrote in Applied Cryptography, Second Edition (around 1996):

"The NSA probably possesses cryptographic expertise many years ahead of public state of the art (in algorithms, but probably not in protocols) and can undoubtedly break many of the systems used in practise."

In 2010 former NSA technical director mentioned that they have been losing ground to their public counterparts during the last twenty years but that they would probably be still ahead of the public by "handful of years". [1]

[1] http://www.networkworld.com/news/2010/030410-rsa-cloud-secur...

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#44

What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?

If you know anything about bitcoin, you'll realize this is a silly proposition.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#45

What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?

NSA could purchase more GPUs, FPGAs and custom designed ASICs than all the world's bitcoin miners combined for a small fraction of its $11 billion annual budget.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#46
post #6

But information on the NSA's efforts to crack the encrypted portion of that traffic — which would include much of the email bouncing around the net — has remained absent What Wired.com? Much of the email bouncing around the net and even internal networks, save for traversals like gmail-to-gmail, are NOT a portion of the encrypted traffic. It's important you report this correctly, because "the masses" are otherwise ma…

A lot of SMTP server-to-server traffic is encrypted. But a lot of it isn't, and it only takes one exposed hop. So as a general rule email isn't effectively or reliably encrypted. There's probably also a lot of email traffic being carried over crackable VPN links such as PPTP.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#47

Compared to the rest of the HN crowd, my knowledge of crypto is very light, so I could be incorrect... But aren't most widely adopted algorithms decently future proof? To where you would sort of have to break math in order for them to be crackable, if used with a very strong password? Sure, flaws were found in RSA, etc. But does something like that have a decent chance of happening again?

To get the regular mantra out of the way: Humans are always the weakest link.

But, speaking algorithmically, it is likely you can rely on a well-vetted symmetric algorithm like AES, used conservatively according to current best practices, to keep information secret during your lifetime.

Asymmetric algorithms are another matter. RSA relied on unproven assumptions that are turning out to be squishier than we might have hoped. ECC relies on assumptions that, for the moment, appear less squishy. I'm not a mathematician, so I can't have a truly informed judgement on how likely they are to remain unsquished, but the empirical history of public-key crypto means my confidence in ECC will remain well below my confidence in the likes of AES.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#48
post #30
post #14

This makes me think that it might be good to have a "security by obscurity" layer on top of the existing security layer. A big weakness of a public security protocol is that a huge government might privately crack it and tell nobody.

On the other hand, without peer-review your obscure system could be trivially cracked once the government has an interest in it.

As a professional scientist: One should be very careful about using peer review as a mark of quality. It's not necessary nor sufficient.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#49

Mostly I'm surprised at the pay distribution on page 9 of the included document. GS pay tops out around $117k. Is that how much we're paying for top level cryptography research? Do contractors like Snowden get to make $200k because that's just what their consulting firm bills for?

My understanding is that huge pay increases are in fact the primary motivation behind the shift to these quasi-private sector contracting arrangements. It's basically an accounting scheme to either "retain the brightest", or to defraud the taxpayers, depending on how you look at it.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#50
post #40

The documents says they are "... investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit internet traffic." Not that they have achieved groundbreaking cryptanalytic capabilities. It's common for people to suggest that the NSA is 20 years ahead of the private sector, but it's not clear how true this is. That number is commonly cited as a result of changes the NSA made to D…

> "...investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit internet traffic."

This could be little more than a way of making the purchase of a bunch of D-Wave boxes sound more compelling than it might really be at this time. The problem with secret organizations with no oversight is that we'll probably never know for sure.

Post reply on HN