Live data from Hacker News

NSA Brute-Force Keysearch Machine

schneier.com

1–10 of 30 posts

Re: NSA Brute-Force Keysearch Machine

#3

I wonder how programmable it is... Assuming it's not programmable would be an argument not to use standard encryption algorithms.

ASICs are not reprogrammable. And they're expensive to build, but the NSA apparently has the resources to build new ones at semi-regular intervals, so I don't know if switching algorithms would really slow them down that much.

Re: NSA Brute-Force Keysearch Machine

#4
post #3

I wonder how programmable it is... Assuming it's not programmable would be an argument not to use standard encryption algorithms.

ASICs are not reprogrammable. And they're expensive to build, but the NSA apparently has the resources to build new ones at semi-regular intervals, so I don't know if switching algorithms would really slow them down that much.

Considering that it takes 1-2 years to spin custom silicon I would say that it is a viable approach.

Re: NSA Brute-Force Keysearch Machine

#5
post #3

I wonder how programmable it is... Assuming it's not programmable would be an argument not to use standard encryption algorithms.

ASICs are not reprogrammable. And they're expensive to build, but the NSA apparently has the resources to build new ones at semi-regular intervals, so I don't know if switching algorithms would really slow them down that much.

I think grandparent was suggesting custom encryption algorithm (potentially less secure) to prevent use of a brute force approach that's custom made for a specific algorithm.

Re: NSA Brute-Force Keysearch Machine

#6
Schneier often has great insight but this blog post was pretty much the opposite of that. I think I recall reading the original post from the guy who found that NYU info; and I def. read the Intercept piece.

Schneier's post quotes the original article and says unfortunately we don't know more. Literally over 50% of it is a quote from another article which he derides for it's lack of substance. Not sure what the point is.

Re: NSA Brute-Force Keysearch Machine

#7
> Whatever the details, this is exactly the sort of thing the NSA should be spending their money. Breaking the cryptography used by other nations is squarely in the NSA's mission.

I can't tell if it's sarcasm. (it's a serious question)

Re: NSA Brute-Force Keysearch Machine

#8

I wonder how programmable it is... Assuming it's not programmable would be an argument not to use standard encryption algorithms.

It's probably easier to use a standard algorithm in a way that can't be attacked by this machine (e.g. use AES-256 with a properly random key) than it is to create a non-standard algorithm that doesn't have vulnerabilities.

Re: NSA Brute-Force Keysearch Machine

#9
"Unfortunately, the Intercept decided not to publish most of the document, so all of those people with "a Ph.D. in a related field" can't read and understand WindsorGreen's capabilities. What sorts of key lengths can the machine brute force? Is it optimized for symmetric or asymmetric cryptanalysis? Random brute force or dictionary attacks? We have no idea."

When I was reading the news article, I thought to myself, should they really be publishing classified information? The dumb leak was one thing, but publishing it more broadly is a whole different thing. If this was a government contract, I would assume these are classified documents (which they are). Obviously we tax payers should have the right to know, but logically, wouldn't that consider a crime just like leaking to Wiki Leaks?

Re: NSA Brute-Force Keysearch Machine

#10
post #7

> Whatever the details, this is exactly the sort of thing the NSA should be spending their money. Breaking the cryptography used by other nations is squarely in the NSA's mission. I can't tell if it's sarcasm. (it's a serious question)

It's obviously not sarcasm.
Post reply on HN