Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

11–20 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#11

"the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards." This is the part that truly disgusts me.

I think people were speculating this on HN with this article: http://www.wired.com/politics/security/commentary/securityma...

Re: N.S.A. Foils Much Internet Encryption

#12
So does this means they have broken or fund a bug in RSA, fast enough computers to brute force or solved the P versus NP problem. In decreasing chances of possibility. I am also an encryption noob, so I gather that if they have broken a crypto then my 4096 bit files will be no more secure than 1024 bit ones. Right?

Re: N.S.A. Foils Much Internet Encryption

#13

This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability. The issue to me has always been how and what data they access and store, and how it is used.

I guess I'm with you on the ability to crack. Any researcher should be able to try as hard as they want, and succeed.

I draw the line at collecting everything without specific warrants, regardless of what they do with it, against their charter and the Constitution.

I draw the line at hardware backdoors for equipment that I buy, and insertion of vulnerabilities into encryption standards that I take advantage of. Or I guess I should say that take advantage of me.

Re: N.S.A. Foils Much Internet Encryption

#14
post #5

Normal people don't need 256-bit symmetric encryption. That's assault encryption and should only be used on the battlefield. 40-bits is enough and anything over that should be banned. I'm only joking, but the same argument is used against other technologies that governments seek to control/dominate. Edit: Skipjack was 80-bits I think. It was used in Clipper Phones: http://en.wikipedia.org/wiki/Skipjack_(cipher)

People don't take a 256-bit cryptoalgorithm into a middle school and kill kids with it, so I don't think the analogy works exactly. Maybe if you print it out on paper, or use a floppy disk or CD, you could cut a few people.

Re: N.S.A. Foils Much Internet Encryption

#15

This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability. The issue to me has always been how and what data they access and store, and how it is used.

The larger issue here is that they "covertly introduce weaknesses into the encryption standards". It's not that they cleverly and fairly break encryption, it's that they sabotage the standards.

Re: N.S.A. Foils Much Internet Encryption

#16
post #9

The N.S.A. hacked into target computers to snare messages before they were encrypted. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world. This is mostly a confirmation of what has been supposed: No magic, mostly bribed and coerced cooperation from the people who should…

So, should we re-evaluate if Intel/AMD's chips (and possibly even the new ARM ones) contain hardware backdoors for the NSA?

Re: N.S.A. Foils Much Internet Encryption

#17
Can someone who actually knows about encryption comment on whether it's actually physically feasible for the NSA to have actually broken, say, SSL 3.0 (which has 128 bits of entropy, IIRC) on a large scale (i.e., when you're sifting through petabytes of data on a daily basis)?

And if this were really an issue, couldn't you just use 4096-bit RSA (unless they have managed to surreptitiously insert a backdoor in it)?

Re: N.S.A. Foils Much Internet Encryption

#20
So at this rate are there any encryption methods that we're pretty sure that the NSA cannot crack?

  By introducing such back doors, the N.S.A. has
  surreptitiously accomplished what it had failed 
  to do in the open. Two decades ago, officials 
  grew concerned about the spread of strong 
  encryption software like Pretty Good Privacy, 
  or P.G.P., designed by a programmer named Phil 
  Zimmermann. The Clinton administration fought 
  back by proposing the Clipper Chip, which 
  would have effectively neutered digital 
  encryption by ensuring that the N.S.A. always 
  had the key.
Link to Paragraph w/ highlighting: http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet...

Should I bother to read up on PGP?

Post reply on HN