Live data from Hacker News

How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

schneier.com

11–20 of 62 posts

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#11
post #7
post #4

Earlier quoted context omitted.

Agreed. One advantage the NSA has is it can pay some of the best mathematicians to be full-time pure mathematicians. There are very few mathematicians that have the opportunity to do something like that -- even professors have to teach a few classes. I imagine it's a powerful draw to top talent and gives them the ability to spend more time on a problem than most others.

On the other hand your work is secret and you will never be recognized for what you do.

You would be recognized inside the NSA, a large technical population.

In addition, as with the CIA and other clandestine US government organizations, they appeal to patriotism and helping the national interest. That appeal seems to be fraying somewhat lately for the NSA.

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#12
post #8

Yet they let one random contractor steal a ton of their secrets. What are the odds that one person out of those 35,000 that knows these secrets, if they exist, and has a conscience won't come forth and spill the magic beans.

If we stipulate the possibility of a person of conscience in that pool, can we then infer the possibility of people of "evil intent"? By that, I mean people who will attempt (carefully of course) to use NSA knowledge for their own enrichment, apart from the "accepted" goals of the NSA.

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#13
post #7
post #4

Earlier quoted context omitted.

Agreed. One advantage the NSA has is it can pay some of the best mathematicians to be full-time pure mathematicians. There are very few mathematicians that have the opportunity to do something like that -- even professors have to teach a few classes. I imagine it's a powerful draw to top talent and gives them the ability to spend more time on a problem than most others.

On the other hand your work is secret and you will never be recognized for what you do.

Not everyone works for public recognition. There are enough people who are willing to work on neat problems in exchange for plenty of money who are also willing to forgo public recognition.

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#14
post #5

If you're a brilliant mathematician who has made a breakthrough in breaking cryptography, wouldn't you want to make a deal with the NSA? Reveal breakthrough in return for more knowledge.

I see two much more plausible scenarios:

1) Publish. Get famous. Guaranteed employment for the rest of your life.

2) Use it to break into systems. Become rich or get caught and jailed, likely for life.

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#15
We can and we must.

I'm glad that Bruce Schneier has now had a chance to view some of the primary source documents from the Snowden leaks, because I trust him to speak frankly and I trust his technical ability.

(I'm referring to http://www.schneier.com/blog/archives/2013/09/the_nsa_is_bre..., not the above link).

Both he and Snowden have essentially said that we can still trust the math. Modern symmetric crypto has enough safety margin that even extremely surprising breakthroughs wouldn't give the NSA practical decryption capabilities. (Asymmetric crypto is less certain, but even there Schneier still says discrete-log-based methods with sufficiently large keys are likely ok, and I would bet he's right.)

So the bottom line is this:

- using crypto correctly really matters, because they really are out to get you. Most software gets it wrong, not because there are no good cryptosystems, but because people are ignorant of how to do it right.

- build attack-resistant organizations, not just protocols. The more transparent, flat, and distributed an organization, the harder it is to secretly coerce into cooperating with the NSA. It's a lot harder to force a backdoor into Firefox than into Chrome.

- it turns out open source really matters. The tinfoil hat brigade is vindicated. Closed source vendors really are actively working against their customer's security.

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#16
post #5

If you're a brilliant mathematician who has made a breakthrough in breaking cryptography, wouldn't you want to make a deal with the NSA? Reveal breakthrough in return for more knowledge.

Well, on those feet, I'd ask for money, not knowledge. That has the advantage that the NSA may actually accept the deal, instead of just blackmailing me (or worse).

That is, if I wanted to make any kind of deal with the NSA.

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#17
post #2

Politics and civil freedoms aside, I think it's fascinating that there can essentially be this black box, i.e. the NSA, that can make breakthroughs in new mathematics with only its employees and those on the outside sworn to secrecy. They obviously have brilliant mathematicians, but more brilliant than the best ones at the world's best universities or tech companies? Or are their suspected/hypothetical theoretical br…

The most common estimate I've seen is that the NSA has 600 mathematicians. I'd not be at all surprised if, for the areas of mathematics the NSA cares about, that is more than the total for the top 100 universities in the world.

I've also read that the work environment for mathematicians there is very much like a research university. They do their research, write papers for internal publication, give and attend seminars, and so on--and they don't have their research interrupted by someone asking them to teach calculus to freshmen, and without having to worry about impressing a tenure committee to avoid years and years of bouncing between temporary positions.

The combination of a very large number of people, and a pretty nice environment that lets those people throw themselves fully into research makes it plausible that they do make occasional significant breakthroughs.

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#19
post #15

We can and we must. I'm glad that Bruce Schneier has now had a chance to view some of the primary source documents from the Snowden leaks, because I trust him to speak frankly and I trust his technical ability. (I'm referring to http://www.schneier.com/blog/archives/2013/09/the_nsa_is_bre... , not the above link). Both he and Snowden have essentially said that we can still trust the math. Modern symmetric crypto has…

If the NSA had really broken asymmetric crypto it would imply that they were sitting on an huge unpublished result in one or more of a) complexity theory b) quantum computing c) number theory d) ?? something even more outlandish. It's difficult to imagine even them keeping a lid on that. Mathematics is not a large field nor is it by nature a secretive one. (Arguably recognition is the thing driving most mathematicians.) The furtive whispers would accumulate.

Re: How Advanced Is the NSA's Cryptanalysis, and Can We Resist It?

#20
Schneier has been giving some pretty weird advice lately. This is probably the weirdest thing I've seen from him:

"Prefer conventional discrete-log-based systems over elliptic-curve systems; the latter have constants that the NSA influences when they can."

There are plenty of ECC systems that have virtually no chance of NSA influence. Curve25519/Ed25519 come to mind.

Post reply on HN