Live data from Hacker News

Unraveling NSA's TURBULENCE Programs

robert.sesek.com

21–28 of 28 posts

Re: Unraveling NSA's TURBULENCE Programs

#21

Would love to know more about the "Pairing and Crypt attacks" along with "Cryptovariable management". Probably the pairing here is referring to the pairing between client and server rather than the cryptographic technique of using pairings ... but it seems this hasn't surfaced in any of the other snowden docs. I often wish the journalists working on that story had released more source material.

They're only slides. We don't have audio of the presentations. :) I did wonder about that, but no "common" internet encryption protocols use pairing-friendly (in the open source cryptographic community sense) primitives. I think you're about right and it probably refers to matching public and private keys for CAs in SSL/TLS, looking up suitable intermediate CAs, for which they may have a few keys stashed away. They d…

> I think you're about right and it probably refers to matching public and private keys for CAs in SSL/TLS, looking up suitable intermediate CAs, for which they may have a few keys stashed away.

Compromise of a CA's key does not permit decryption of traffic encrypted by server keys that use certificates (signatures) from those CAs. This is a common misconception.

It would allow for issuing (signing) a rogue, second key that could then be used to silently active MITM a connection - but getting the CA's key does not give you the VPN server's key.

(Remember, a certificate is just a signature by a CA over the hash of the VPN server's public key. The CA never sees the private key of the VPN server, nor is the CA's key used for anything other than signing.)

Re: Unraveling NSA's TURBULENCE Programs

#22

Earlier quoted context omitted.

They're only slides. We don't have audio of the presentations. :) I did wonder about that, but no "common" internet encryption protocols use pairing-friendly (in the open source cryptographic community sense) primitives. I think you're about right and it probably refers to matching public and private keys for CAs in SSL/TLS, looking up suitable intermediate CAs, for which they may have a few keys stashed away. They d…

To extend your statements: * breaking 1024-bit RSA is believed to be well within the resources of the NSA given public research/attacks.[0] * MD5 is already completely broken in the public research and the NSA has used MD5 collisions in malware attacks that are independent of public methods[1]. * RC4 has been attacked for a number of years, and someone who has seen unreleased Snowden documents claimed that the NSA ha…

Yes - I concur that the "cryptanalytic breakthrough" GCHQ talked about the NSA having a few years ago was most probably some kind of a practical RC4 break, from context. (Schneier thought this one of the likely possibilities too.) It's used enough in TLS (especially at the time these documents were penned, as some advising on BEAST countermeasures actually encouraged people to use it, instead of switching to TLSv1.2 to use the strong AEAD ciphers - awfully convenient for them!) that if they have, say a known-plaintext-prefix attack of reasonable complexity that can be hardware-accelerated, that would be widely leveragable into very real breaks to them - and the structure of such a thing would look remarkably like what we see here.

RC4 is about as good as such a simple crypter can be, but it really is too simple and not good enough now, and I strongly suspect it is already toast and way too late to safely phase out - which is why the IETF are hopefully about to publish an RFC strongly recommending it MUST NOT be used in TLS, at all. (Worse, even if RC4 isn't toast to everyone right now, an attacker who can put your data on ice for a few years - like just about every Nation State Adversary does - may very well make toast with it down the line and read all your data.)

We don't have any second-preimages in MD5, yet; what's demonstrated are techniques for efficient collisons. They might, but collisions are easily enough for practical problems as many have publicly demonstrated. SHA-1 hasn't been publicly demonstrated with a collision yet, but it has all the same underlying problems as MD5 (and the original SHA), just to a lesser extent - I suspect that NSA can produce SHA-1 collisions with enough effort. Don't expect them to spend more effort than they need, however, to save money and avoid revealing capabilities where possible. Several attackers have happily leveraged simpler shortcuts - there's a piece of (probably South Korean) malware that has signing keys co-opted from hapless developers who've somehow been derping around with 512-bit RSA keys. I could break those, so that's completely ridiculous!

By the way - do be on the look out for PGP signatures with 1024-bit DSA signing keys. There's a lot of them. Upgrade to at least 3072-bit RSA, I suggest (or Ed25519).

Re: Unraveling NSA's TURBULENCE Programs

#23
post #2

This is so disturbing. I honestly feel that with every one of these revelations, my interest in the technology world is degraded more and more. The existence of such heinous things as the TAO, and its tendrils, brings on a serious depression. Just who do these people think they are, to defeat our lives so completely, for their own sakes? Despicable.

You had to have been very naive for these revelations to be so shocking to you.

You use Google for email? Don't be surprised that someone else is reading it. You have willingly and continuously divulged your personal data to an unknown number of people.

You use someone else's cables for data transfer? You are willingly broadcasting your information to anyone who's willing to listen.

You're blindly trusting an encryption system made by some strangers? Be aware of the consequences. You're merely trusting someones unwillingness to risk their reputation (if anything at all).

True security and privacy are achievable, but you need to put effort into that. If you're walking around 24/7 with a GPS tracker and listening device in your pocket willingly, don't go crying over someones ability to collect this information for their own gain.

Re: Unraveling NSA's TURBULENCE Programs

#24
post #9
post #2

This is so disturbing. I honestly feel that with every one of these revelations, my interest in the technology world is degraded more and more. The existence of such heinous things as the TAO, and its tendrils, brings on a serious depression. Just who do these people think they are, to defeat our lives so completely, for their own sakes? Despicable.

> my interest in the technology world is degraded > brings on a serious depression Yes I feel this way, too. It's come a long way from learning GR and HGR in Apple Basic. Telephony modems were fun... Usenet was interesting, the Internet over ethernet was fun but people started to take it seriously... Spam was an amusing nuisance. Around the time of LAMP and RealAudio, circa 1997-2000, things got a little shaky for me…

> I suppose most of the NSA's work is the result of our own base, human natures...

It is in the best interest of the state to cripple the internet as much as possible. This isn't to protect you, it is to control you - ranchers don't build fencing to protect cattle. Why would any state want you to be able to freely communicate with the "violent, hating, warlike, unequal" others? Aside from generating tax revenue through commerce, there is no reason.

Re: Unraveling NSA's TURBULENCE Programs

#25
post #2

This is so disturbing. I honestly feel that with every one of these revelations, my interest in the technology world is degraded more and more. The existence of such heinous things as the TAO, and its tendrils, brings on a serious depression. Just who do these people think they are, to defeat our lives so completely, for their own sakes? Despicable.

I can understand that. For me this is just what I already assumed them to be doing and find it all rather unsurprising. I would rather have your mindset, I think.

This whole thing has made for some interesting people watching opportunities. I think the only people who were completely unsurprised by all this are those who:

1) Understood the technical requirements to pull this level of surveillance off.

2) Understood that the government does not love them.

You combine the two to arrive at the conclusion that if something is within the government's ability, and it furthers its own interests, it will do it. The reaction from the folks in group 1 have been the most entertaining, as it is apparently easier for people in group 2 to adapt to changes in technology.

Re: Unraveling NSA's TURBULENCE Programs

#26
post #21

Earlier quoted context omitted.

They're only slides. We don't have audio of the presentations. :) I did wonder about that, but no "common" internet encryption protocols use pairing-friendly (in the open source cryptographic community sense) primitives. I think you're about right and it probably refers to matching public and private keys for CAs in SSL/TLS, looking up suitable intermediate CAs, for which they may have a few keys stashed away. They d…

> I think you're about right and it probably refers to matching public and private keys for CAs in SSL/TLS, looking up suitable intermediate CAs, for which they may have a few keys stashed away. Compromise of a CA's key does not permit decryption of traffic encrypted by server keys that use certificates (signatures) from those CAs. This is a common misconception. It would allow for issuing (signing) a rogue, second k…

Yes, but they're man-on-the-side already, and they already have the QUANTUM set of attacks and similar for actively racing an MITM on any TCP/UDP/ESP/etc/IP connection they want - and if they have a CA trusted for the purpose by the relevant endpoint, they can safely man-in-the-middle TLS, IPSec, etc.

That's what the diagram shows, essentially: the front end of that attack.

Re: Unraveling NSA's TURBULENCE Programs

#27

Earlier quoted context omitted.

A plug here that the promoted and stated goal "stopping the next 9/11" is a politics of fear and not what ultimately justifies the capabilities to each administration. Reprised from an earlier comment: If you look at the Snowden documents (and leaks by others) you'll see essentially nothing other than the international nature of the programs. For example, you'll remember from the Snowden leaks that the NSA hacked the…

> Digital communications are so insecure that the attackers always win. Always. And digital communications play a huge role (next to satellite and radio communications) in modern espionage and sabotage. If you just play a defensive game, you lose. The US feels it needs these capabilities for these reasons - not because of terrorism. The role of NSA programs like BULLRUN in making digital communications insecure by de…

Absolutely. There's a nice boiling soup of both.

I should add here that the NSA has a concept called NOBUS. The concept is that "nobody but us" should be able to exploit the vulnerabilities we add. There isn't a lot of factual data on how successful this concept has been.

Re: Unraveling NSA's TURBULENCE Programs

#28
post #9
post #2

This is so disturbing. I honestly feel that with every one of these revelations, my interest in the technology world is degraded more and more. The existence of such heinous things as the TAO, and its tendrils, brings on a serious depression. Just who do these people think they are, to defeat our lives so completely, for their own sakes? Despicable.

> my interest in the technology world is degraded > brings on a serious depression Yes I feel this way, too. It's come a long way from learning GR and HGR in Apple Basic. Telephony modems were fun... Usenet was interesting, the Internet over ethernet was fun but people started to take it seriously... Spam was an amusing nuisance. Around the time of LAMP and RealAudio, circa 1997-2000, things got a little shaky for me…

Let me focus on one phrase you mentioned: "people started to take it seriously".

it was serious from the beginning. Experts on both sides disagree and this disagreement will continue.

Post reply on HN