Live data from Hacker News

New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

wired.com

51–60 of 122 posts

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#51
post #45

What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?

NSA could purchase more GPUs, FPGAs and custom designed ASICs than all the world's bitcoin miners combined for a small fraction of its $11 billion annual budget.

NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#52

What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?

So maybe there's an agency out there with codes that all start with a number of leading zeros?

oh, I forgot about the leading zeros part =/

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#53
post #2

I think observers have long assumed NSA is some number of years ahead – say, 2-30 years ahead – of openly published results in cryptanalysis and cryptosystem vulnerabilities.

But it's really hard to assume that - that's assuming true mathematical leaps and invention. Admittedly if you put enough cryptographers on the payroll they may form their own university, but they still need the air of their peers on the outside. Imagine a cosmologist today transported 30 years back and asked to attend conferences - they would gain no inspiration. I think we put too much emphasis on the single data p…

But what if there are quantitatively and qualitatively more full-time, well-funded cryptographers inside the NSA (and its collaborating sibling organizations in its close allies) than outside? They may have an internal system, with geographically-distributed schools of thought, specialties, and long-running debates, as rich and open as the outside world - just completely segregated.

At least, that's how I'd do it, if I found myself a global superpower after WW2, thanks in large part to superior signals/crypto work, and didn't want any other emergent groups to surprise me from a "higher perch" of signals omniscience.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#54
post #6

But information on the NSA's efforts to crack the encrypted portion of that traffic — which would include much of the email bouncing around the net — has remained absent What Wired.com? Much of the email bouncing around the net and even internal networks, save for traversals like gmail-to-gmail, are NOT a portion of the encrypted traffic. It's important you report this correctly, because "the masses" are otherwise ma…

A lot of SMTP server-to-server traffic is encrypted. But a lot of it isn't, and it only takes one exposed hop. So as a general rule email isn't effectively or reliably encrypted. There's probably also a lot of email traffic being carried over crackable VPN links such as PPTP.

You're certainly right. By "much" and especially in cases involving security, I don't think we can be happy with or report on the system's security with just a "majority" being all that's need to feel safe. In fact, I'd go as far to say that unless approaching 100% and without considering circumstances like those that involve an NSL, all bets are off. Circumstances concerning an NSL are another matter, and that's where we should eliminate the on-the-wire concerns and opt for PGP-like communication.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#55
post #30
post #14

This makes me think that it might be good to have a "security by obscurity" layer on top of the existing security layer. A big weakness of a public security protocol is that a huge government might privately crack it and tell nobody.

On the other hand, without peer-review your obscure system could be trivially cracked once the government has an interest in it.

Not advocating non standard crypto, but if the system is at least somewhat good ( that is, not susceptible to automatic attacks), it would keep a actual human busy. And you don't loose security, assuming that the cyphertext of the obscure system is again encrypted by a well established cypher.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#56
post #45

Earlier quoted context omitted.

NSA could purchase more GPUs, FPGAs and custom designed ASICs than all the world's bitcoin miners combined for a small fraction of its $11 billion annual budget.

NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.

NSA has its own fab, located at Ft. Meade.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#57
post #45

Earlier quoted context omitted.

NSA could purchase more GPUs, FPGAs and custom designed ASICs than all the world's bitcoin miners combined for a small fraction of its $11 billion annual budget.

NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.

The Trusted Foundry Program isn't even a secret. (Unless you believe it's some kind of misdirection.)

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#58
post #26

Compared to the rest of the HN crowd, my knowledge of crypto is very light, so I could be incorrect... But aren't most widely adopted algorithms decently future proof? To where you would sort of have to break math in order for them to be crackable, if used with a very strong password? Sure, flaws were found in RSA, etc. But does something like that have a decent chance of happening again?

The problem is partly that you personally aren't using just a widely adopted algorithm, you're using a specific implementation layered on some monster protocol stack with weird legacy support for "Look the other way and ROT13" mode as well as AES-$Whatever. HTTPS, for example, depends on both crypto algorithm implementation, SSL/TLS, the responsible Certificate Authority[1], your random number generator, your OS, you…

If CAs gave up valid certs/signing keys for google.com, would the fingerprint be different? And if so, would it be possible to verify the fingerprint if Google hosted it at like pki.google.com?

I've been wondering if there's a public registry of certificate fingerprints somewhere to verify you're getting the cert the domain owner knows about.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#60
post #57

Earlier quoted context omitted.

NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.

The Trusted Foundry Program isn't even a secret. (Unless you believe it's some kind of misdirection.)

Never heard of it before, here are the results of my google search for anyone interested:

The Trusted Foundry Program (TFP) was established as a joint effort between Department of Defense and National Security Agency ... in response to Deputy Secretary of Defense Paul Wolfowitz’s 2003 Defense Trusted IC Strategy memo

- Program is administered by NSA’s Trusted Access Program Office (TAPO)

- DoD component resides in the Office of the Secretary of Defense, ASD R&E and is managed by Defense Microelectronics Activity (DMEA)

By the end of the program in FY2013, DoD will have invested >$700M to ensure access to microelectronics services and manufacturing for a wide array of devices with feature sizes down to 32nm on 300 mm wafers Program Provides National Security And Defense Programs With Access To Semiconductor Integrated Circuits From Secure Sources

[1] http://www.ndia.org/Divisions/Divisions/SystemsEngineering/D...

Post reply on HN