The documents says they are "... investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit internet traffic." Not that they have achieved groundbreaking cryptanalytic capabilities. It's common for people to suggest that the NSA is 20 years ahead of the private sector, but it's not clear how true this is. That number is commonly cited as a result of changes the NSA made to D…
> "...investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit internet traffic." This could be little more than a way of making the purchase of a bunch of D-Wave boxes sound more compelling than it might really be at this time. The problem with secret organizations with no oversight is that we'll probably never know for sure.
New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
61–70 of 122 posts
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#62Earlier quoted context omitted.
NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.
NSA has its own fab, located at Ft. Meade.
Info on Fort meade: http://news.google.com/newspapers?nid=110&dat=19890417&id=Ye...
San Antonia former Sony plant: http://www.chron.com/news/houston-texas/houston/article/NSA-...
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#63Earlier quoted context omitted.
NSA could have its own fabs for that kind of budget. Some people believe that they do, or at one time did. My guess is that they'd probably just prefer to book a midnight run on US industry fabs these days.
NSA has its own fab, located at Ft. Meade.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#64Earlier quoted context omitted.
The problem is partly that you personally aren't using just a widely adopted algorithm, you're using a specific implementation layered on some monster protocol stack with weird legacy support for "Look the other way and ROT13" mode as well as AES-$Whatever. HTTPS, for example, depends on both crypto algorithm implementation, SSL/TLS, the responsible Certificate Authority[1], your random number generator, your OS, you…
If CAs gave up valid certs/signing keys for google.com, would the fingerprint be different? And if so, would it be possible to verify the fingerprint if Google hosted it at like pki.google.com? I've been wondering if there's a public registry of certificate fingerprints somewhere to verify you're getting the cert the domain owner knows about.
Certificate Pinning[1] (bundle your cert with Chrome/$browser)
HSTS[2] (cache the cert you receive on this connection for $num days, bitch vocally if it changes)
Convergence (Dead?) / TACK[3] (add an independent site-specific key to cross-sign the CA-provided certs, like pinning but more flexible)
And the more passive detection approach I mentioned like the SSL Observatory[4] which looks for "unexpected" changes in certs.
To finally answer your question, no, I don't think there is any sort of list. Doing essentially that without any centralised bookkeeping (I mean, why trust those guys any more than the CAs? Not to mention it'd be hard to scale) is the plan.
DNSSec might have some sort of role in there, but I'm sufficiently hazy on how it works, and you're back to trusting your registrars/registries again anyway (see recent excitement at the NYTimes for why that's not such a great idea)
[1] https://www.imperialviolet.org/2011/05/04/pinning.html
[2] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
[3] http://tack.io/
[4] https://www.eff.org/observatory (built into HTTPS Everywhere[5] but disabled by default, IIRC)
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#65Edward Snowden, in Q&A session at The Guardian's homepage, 17 June 2013
http://www.theguardian.com/world/2013/jun/17/edward-snowden-...
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#66I think observers have long assumed NSA is some number of years ahead – say, 2-30 years ahead – of openly published results in cryptanalysis and cryptosystem vulnerabilities.
But it's really hard to assume that - that's assuming true mathematical leaps and invention. Admittedly if you put enough cryptographers on the payroll they may form their own university, but they still need the air of their peers on the outside. Imagine a cosmologist today transported 30 years back and asked to attend conferences - they would gain no inspiration. I think we put too much emphasis on the single data p…
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#67:( up until just a few years ago, I always looked at the NSA organization with a sense of awe and pride ... that we (the US) were so advanced. Now it's just a source of shame that such powerful knowledge is being directed at us, rather than used as a tool for our benefit.
NSA capabilities are primarily directed out of country. It's the other guy's capabilities I think they're more worried about.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#68Earlier quoted context omitted.
On the other hand, without peer-review your obscure system could be trivially cracked once the government has an interest in it.
As a professional scientist: One should be very careful about using peer review as a mark of quality. It's not necessary nor sufficient.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#69Earlier quoted context omitted.
On the other hand, without peer-review your obscure system could be trivially cracked once the government has an interest in it.
Not advocating non standard crypto, but if the system is at least somewhat good ( that is, not susceptible to automatic attacks), it would keep a actual human busy. And you don't loose security, assuming that the cyphertext of the obscure system is again encrypted by a well established cypher.
Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking
#70Earlier quoted context omitted.
NSA has its own fab, located at Ft. Meade.
Besides Forte Meade, the NSA recently purchased the Sony chip fabrication plant in San Antonio (94,000-square-foot) and has business connections with many manufacturers including National Semiconductor/Texas Instruments. Info on Fort meade: http://news.google.com/newspapers?nid=110&dat=19890417&id=Ye... San Antonia former Sony plant: http://www.chron.com/news/houston-texas/houston/article/NSA-...
Twenty-five years of Moore's law later the price and complexity of an operational chip foundry has doubled similar to transistor count. The former Sony plant is 633,000 ft2, reportedly valued as $72M and being leased at $35/ft2.
I don't see any evidence they're using it for anything other than datacenter and office space.