Earlier quoted context omitted.
The American government is collecting as much data about as many humans as it can, which I find morally repugnant. I support efforts to make that more difficult, even if it weakens the American government.
Government strength is relative. Weakening the American government is equivalent to strengthening other Governments. Would you mind telling us which ones you prefer and why they are morally superior?
The NSA's crypto "breakthrough"
81–90 of 101 posts
Re: The NSA's crypto "breakthrough"
#82One of the "nice" things about the NSA: they rely on pretty standard crypto--the same kind the rest of us do!--for their less sensitive, but still classified, secrets. NSA Ciphersuite B ( http://en.m.wikipedia.org/wiki/NSA_Suite_B_Cryptography ) is built into a lot of gov/mil communications technology. And it's just RSA, ECDHE, and so on--all that same stuff available in TLS. In other words: if the NSA break one of t…
But now every plane spotter has instant cross-correlation with every other one - and those secret flights stand out as being, well, private flights.
So long story short, if I did magically invent quantum computing, I would let the rest of the low grade secrets go hang. One of the 3 million (!) security cleared US personnel will throw Assange a copy soon enough - so lets use the advantage, to our advantage.
This of course means that if our security services have the brains and the political muscle, they will need to choose themselves which are the truly secret things and arrange a government in a government to keep it in shape. That's not likely to be a good thing.
Re: The NSA's crypto "breakthrough"
#83Earlier quoted context omitted.
Show some gratitude. You have no idea how many individuals had to sacrifice their personal lives to get that picture into the commons.
What do you mean? As far as I can tell, it is freely available on NSA's website: http://www.nsa.gov/about/_images/pg_hi_res/nsa_aerial.jpg
(I'm sure I have that wrong - so a prize to whoever corrects the quote from memory :-)
Re: The NSA's crypto "breakthrough"
#84Earlier quoted context omitted.
Well, it would be a very well guarded secret. But even then the question is how public key crypto is broken. If they can easily generate exploits for implementations, because they know a essential implementation detail everybody else is missing, then it would be fundamentally different from being able to break RSA directly, or if they have a constructive prove of P=NP.
Remember that factoring primes isn't know to be NP Hard. There is no complexity breakthrough required, we just don't know how to do it quickly. So we don't get P=NP from any factoring breakthrough.
Re: The NSA's crypto "breakthrough"
#85Earlier quoted context omitted.
What do you mean? As far as I can tell, it is freely available on NSA's website: http://www.nsa.gov/about/_images/pg_hi_res/nsa_aerial.jpg
It's just a joke, sorry. I'm well aware humor isn't appreciated around here and actually I understand it because humor is a slippery slope ending in reddit-style banal meme-threads, but every once in a while I can't help myself and karma be damned.
Re: The NSA's crypto "breakthrough"
#86Earlier quoted context omitted.
The most advanced math a quantum computer has done to date is "factored 21 into 3×7, with high probability (Martín-López et al. 2012)." Remember: companies are in the game of marketing hype to ride your scifi hopes and dreams. When you see a company saying "quantum" anything, discount their unqualified claims greatly. (Investors are not immune to being manipulated by hype. Claiming "they must be good because they hav…
I think that's for "normal" quantum computers. D-wave is a different kind of quantum computer.
For example, the quantum computer that factored 21 into 3 x 7 did it by using Shor's algorithm for quantum factoring in polynomial time. The D-Wave machine cannot implement Shor's algorithm.
The D-Wave machine would be more capable on a different problem, one that maps efficiently onto the D-Wave machine's problem space. But we're talking about factoring here.
Re: The NSA's crypto "breakthrough"
#87Breaking public-key crypto would have to be the biggest coup in SIGINT in the history of ever . Much bigger than cracking the Enigma. Just thinking about the sheer volume of internet traffic at every level and in every country that relies on the security of encryption makes the possibility of it being fundamentally broken a literal nightmare. I don't think it has happened. But if it had , that would be the kind of se…
Breaking RSA keys up to 1024 bits is one less-outlandish-than-some possibility. NSA published a note advocating use of ECC in 2009: http://www.nsa.gov/business/programs/elliptic_curve.shtml NSA's statement wasn't "we've got an RSA-breaking machine" or anything like that; the highlights are 0) folks are using RSA-1024, which public sources only ascribe 80 bits' worth of security to, smaller than the usual margin; 1) R…
It is then a simple matter of waiting for a user to leak personable identifiable information. A visit to Facebook or an email account, etc whilst connected to the VPN is all it takes, and then you can group and map browser headers (roughly) to VPN users.
Maybe they can break small key length SSL when they really need to. If there is TLS traffic of interest popping out from the VPN exit, then they store it and process it later, probably in some massive AWS compute intensive cloud service even.
VPN users have to remember that their traffic is protected from your machine as far as the VPN exit node. After that exit point onwards to the requested web server, you are as naked as before. Worse is that it lulls users into a false sense of security.
Re: The NSA's crypto "breakthrough"
#88Earlier quoted context omitted.
And, as a corrolary of this, you presently won't have much to fear if this break has happened, simply because the NSA would only use it _very_ sparingly, like how the allies used the Enigma break during WW2. Of course, if the cat ever gets out of the bag, that situation would change.
Carrying on from that thought, the various mathematician-employing agencies have now had over 60 years to study the problem of "how much can we use this critical information-revealing tool without exposing its existence?" If they can identify an upper bound on "sparingly", that's immensely valuable.
Now killing a submarine once you know where it is, is pretty easy. The problem is finding the submarine, and explaining how you were found. To handle that, the Allies used a form of parallel construction. They would send a spotting plane over the area, to spot the sub and give a plausible reason to have located the submarine.
Re: The NSA's crypto "breakthrough"
#89Earlier quoted context omitted.
Carrying on from that thought, the various mathematician-employing agencies have now had over 60 years to study the problem of "how much can we use this critical information-revealing tool without exposing its existence?" If they can identify an upper bound on "sparingly", that's immensely valuable.
During WW2, the Allies would crack messages to locate submarines. Now killing a submarine once you know where it is, is pretty easy. The problem is finding the submarine, and explaining how you were found. To handle that, the Allies used a form of parallel construction. They would send a spotting plane over the area, to spot the sub and give a plausible reason to have located the submarine.
Re: The NSA's crypto "breakthrough"
#90Earlier quoted context omitted.
Government strength is relative. Weakening the American government is equivalent to strengthening other Governments. Would you mind telling us which ones you prefer and why they are morally superior?
Weakening the American government is equivalent to strengthening other Governments. No, building petabyte-scale data centers to spy on you and me is what's weakening the American government. We're not the problem, right? The NSA is like the drunk who looks for his lost keys under the lamppost, "because that's where the light is." Not only does the American government's idea of a hypersecure state not make us any more…