Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

111–120 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#111
post #104
post #68

This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…

One of the vulnerabilities was already discovered by researchers in 2007: http://rump2007.cr.yp.to/15-shumow.pdf At the time, it wasn't clear if this was a deliberate backdoor or an accident, but it was proven that there there was a possibility that there was a secret key that would allow someone to predict future values of a pseudo random number generator based on previous values. Now it looks pretty clear that it w…

This is almost definitely not "one of the vulnerabilities" implicated in the story today, because nobody uses CSPRNGs based on Elliptic Curve.

Re: N.S.A. Foils Much Internet Encryption

#112
I really wish these guys would understand how they're impacting Internet-based commerce. What good is controlling the Internet if people stop using it because of privacy concerns? They seem completely unconcerned about how IT drives the US economy and how a lack of confidence in that sector leads to bad things.

Re: N.S.A. Foils Much Internet Encryption

#114
post #42

> The N.S.A. hacked into target computers to snare messages before they were encrypted. I wonder which computer viruses belong to the NSA.

Windows, Mac OS, Android, iOS, Symbian, and any Linux distribution you haven't culled together and compiled yourself.

Re: N.S.A. Foils Much Internet Encryption

#115
post #77
post #4

"Cryptographers have long suspected that the agency planted vulnerabilities in a standard adopted in 2006 by the National Institute of Standards and Technology, the United States’ encryption standards body, and later by the International Organization for Standardization, which has 163 countries as members." Wonder if it is referring to the Dual_EC_DRBG RNG.

Well, it goes on to say "Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency." The Dual_EC_DRBG vulnerability was revealed by two Microsoft researchers in 2007: http://rump2007.cr.yp.to/15-shumow.pdf So I'd say yes, it sounds like that's what they're talking about. Speaking of which, I'm really quite frustrated how many of…

> Speaking of which, I'm really quite frustrated how many of these recent reports about the NSA elide the technical details.

Are you? Well please sign up to work for the NSA, learn the technical details, then go public with them. The reason that the NYTimes isn't publishing the technical details is because they DON'T KNOW THEM. (They might not publish them if they did.) They don't know them because Edward Snowden was a system administrator not a cryptography expert and he's releasing memos about the process.

Re: N.S.A. Foils Much Internet Encryption

#116
post #99
post #71

Earlier quoted context omitted.

That's a false sense of security. You can inspect every line of code in SSL but unless you are a world-class cryptographer yourself, how will you spot a backdoor in the algorithm ?

The strength of open source lies in the number of eyes with access to the code. Perhaps I lack the wherewithal to identify security vulnerabilities in deployed code, but there's a good chance that there are others who are able to spot said vulns.

Actually, we don't know if there's a good chance or not. All the best cryptographers in the world, who aren't already working for intelligence agencies, are reliant on government funding (i.e. they're in academia). The fact that these have gone undiscovered so long suggests that finding them will not be trivial.

Re: N.S.A. Foils Much Internet Encryption

#117
post #70

> the Bullrun program, the successor to one called Manassas — both names of American Civil War battles. A parallel GCHQ counterencryption program is called Edgehill, named for the first battle of the English Civil War of the 17th century. Spying on your own citizens codenamed as civil war. How nice. > Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among…

Humorously, the United States Army lost both Battles of Bull Run to the Confederates.

Re: N.S.A. Foils Much Internet Encryption

#118
post #99
post #71

Earlier quoted context omitted.

That's a false sense of security. You can inspect every line of code in SSL but unless you are a world-class cryptographer yourself, how will you spot a backdoor in the algorithm ?

The strength of open source lies in the number of eyes with access to the code. Perhaps I lack the wherewithal to identify security vulnerabilities in deployed code, but there's a good chance that there are others who are able to spot said vulns.

ability to spot algorithmic vulnerabilities on that level? and doing it for free? the chances are nill

Re: N.S.A. Foils Much Internet Encryption

#119
post #104

Earlier quoted context omitted.

One of the vulnerabilities was already discovered by researchers in 2007: http://rump2007.cr.yp.to/15-shumow.pdf At the time, it wasn't clear if this was a deliberate backdoor or an accident, but it was proven that there there was a possibility that there was a secret key that would allow someone to predict future values of a pseudo random number generator based on previous values. Now it looks pretty clear that it w…

This is almost definitely not "one of the vulnerabilities" implicated in the story today, because nobody uses CSPRNGs based on Elliptic Curve.

so what was the vulnerability found by ms in 2007 that they are referring to? (search for 2007 in single page version at http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet...)

edit: reading in more detail around there, i am pretty sure that section of the article is referring to the CSPRNG vulnerability above. the article covers a lot of ground and not all of it is about problems with ssl. that particular section seems to be arguing that the nsa is trying to put backdoors into standards wherever it can.

Re: N.S.A. Foils Much Internet Encryption

#120

Earlier quoted context omitted.

Plus (form the Guardian article) there are covert agents in all the companies, presumably lifting all the certs, which may well be unauthorised, but you can't prosecute. Do you know who your covert agents are?

Why couldn't you prosecute, if you found out? I assume theft is still theft, even if done by a government employee.

Perhaps they could arrest you with the old "interfering with a government agent in the performance of his duties" bit.
Post reply on HN