What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?
NSA could purchase more GPUs, FPGAs and custom designed ASICs than all the world's bitcoin miners combined for a small fraction of its $11 billion annual budget.
New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
51–60 of 122 posts
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#52What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?
So maybe there's an agency out there with codes that all start with a number of leading zeros?
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#53I think observers have long assumed NSA is some number of years ahead – say, 2-30 years ahead – of openly published results in cryptanalysis and cryptosystem vulnerabilities.
But it's really hard to assume that - that's assuming true mathematical leaps and invention. Admittedly if you put enough cryptographers on the payroll they may form their own university, but they still need the air of their peers on the outside. Imagine a cosmologist today transported 30 years back and asked to attend conferences - they would gain no inspiration. I think we put too much emphasis on the single data p…
At least, that's how I'd do it, if I found myself a global superpower after WW2, thanks in large part to superior signals/crypto work, and didn't want any other emergent groups to surprise me from a "higher perch" of signals omniscience.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#54But information on the NSA's efforts to crack the encrypted portion of that traffic — which would include much of the email bouncing around the net — has remained absent What Wired.com? Much of the email bouncing around the net and even internal networks, save for traversals like gmail-to-gmail, are NOT a portion of the encrypted traffic. It's important you report this correctly, because "the masses" are otherwise ma…
A lot of SMTP server-to-server traffic is encrypted. But a lot of it isn't, and it only takes one exposed hop. So as a general rule email isn't effectively or reliably encrypted. There's probably also a lot of email traffic being carried over crackable VPN links such as PPTP.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#55This makes me think that it might be good to have a "security by obscurity" layer on top of the existing security layer. A big weakness of a public security protocol is that a huge government might privately crack it and tell nobody.
On the other hand, without peer-review your obscure system could be trivially cracked once the government has an interest in it.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#56Earlier quoted context omitted.
NSA could purchase more GPUs, FPGAs and custom designed ASICs than all the world's bitcoin miners combined for a small fraction of its $11 billion annual budget.
NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#57Earlier quoted context omitted.
NSA could purchase more GPUs, FPGAs and custom designed ASICs than all the world's bitcoin miners combined for a small fraction of its $11 billion annual budget.
NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#58Compared to the rest of the HN crowd, my knowledge of crypto is very light, so I could be incorrect... But aren't most widely adopted algorithms decently future proof? To where you would sort of have to break math in order for them to be crackable, if used with a very strong password? Sure, flaws were found in RSA, etc. But does something like that have a decent chance of happening again?
The problem is partly that you personally aren't using just a widely adopted algorithm, you're using a specific implementation layered on some monster protocol stack with weird legacy support for "Look the other way and ROT13" mode as well as AES-$Whatever. HTTPS, for example, depends on both crypto algorithm implementation, SSL/TLS, the responsible Certificate Authority[1], your random number generator, your OS, you…
I've been wondering if there's a public registry of certificate fingerprints somewhere to verify you're getting the cert the domain owner knows about.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#59Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#60Earlier quoted context omitted.
NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.
The Trusted Foundry Program isn't even a secret. (Unless you believe it's some kind of misdirection.)
The Trusted Foundry Program (TFP) was established as a joint effort between Department of Defense and National Security Agency ... in response to Deputy Secretary of Defense Paul Wolfowitz’s 2003 Defense Trusted IC Strategy memo
- Program is administered by NSA’s Trusted Access Program Office (TAPO)
- DoD component resides in the Office of the Secretary of Defense, ASD R&E and is managed by Defense Microelectronics Activity (DMEA)
By the end of the program in FY2013, DoD will have invested >$700M to ensure access to microelectronics services and manufacturing for a wide array of devices with feature sizes down to 32nm on 300 mm wafers Program Provides National Security And Defense Programs With Access To Semiconductor Integrated Circuits From Secure Sources
[1] http://www.ndia.org/Divisions/Divisions/SystemsEngineering/D...