Live data from Hacker News

How to Protect Yourself from NSA Attacks on 1024-bit DH

eff.org

131–140 of 140 posts

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#131
post #120

Earlier quoted context omitted.

It seems like you're calling section 4.1 of the paper "magical"; do you have something specific in it to object to that makes you think the estimates are severely mistaken? In order to defend against adversaries with undisclosed capabilities, you have to extrapolate known attack methods and hardware to produce estimates of what may be practical. Every paper that proposes keylength and parameter size recommendations d…

It is magical. There is a magic 36000-core (?) computer that has been running for years (?). Well no, the paper just invents it. On the hearsay that an "anonymous nsa official" said they'd cracked something. It astonishes me that people are running about like rabbits in a headlight on such flimsy nonsense. But I understand. It makes us feel important. The new James Bond movie is coming out. And imagine! We're like a…

Classified documents published by Der Spiegel [46] indicate that NSA is passively decrypting IPsec connections at significant scale. The documents do not describe the crypt- analytic techniques used, but they do provide an overview of the attack system architecture.

Due to the Snowden leaks, we know the NSA is doing something that they haven't been able to do previously. The paper just explains, given what we know today, how this is plausible. There's nothing magical about that.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#132
post #23

Earlier quoted context omitted.

... but clients can guard against weak server-side DHE by rejecting DHE ciphersuites. So I think the GP was correct that this diagnostic should be updated.

No, because as agwa pointed out, howsmyssl checks client security. There's nothing wrong with a DHE cipher suite and it can be used in a secure manner quite easily. Since this is wholly on the server, and howsmyssl has no way of testing a server you're connecting to, then there's no possible way for it to know if your specific connections are okay or not. Based solely on the client suites tested, DHE would still be c…

weakdh can be mitigated client side. The website[0] itself has a test for it, which works by requesting this file[1].

[0]: https://weakdh.org/

[1]: https://dhe512.zmap.io/dhe512test.js

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#133
post #2

Does anyone have links to bugs for the affected programs to make 2048 the minimum by default? It seems like we shouldn't have to continue to manually configure secure settings. OpenVPN? SSH? Nginx? Apache? Where are the bugs to make these not use insecure dhparams by default?

Easy-rsa[1] (OpenVPN's key/cert generation/signing tool) version 3 will generate a 2048 bit diffie hellman key by default. Previous versions of easy-rsa used 1024 bit as default. Here is a comment written in the vars configuration file for easy-rsa 2.2.2: # Increase this to 2048 if you # are paranoid. This will slow # down TLS negotiation performance # as well as the one-time DH parms # generation process. export KEY…

How can I tell what DH size I'm using from the OpenVPN client side when I connect to an OpenVPN server?

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#134
post #3

The OpenVPN section is misleading. The dh option is only supported on the server side. If you try to use it on the client side (which is what this guide appears to be tailored towards) it will be ignored and you'll use whatever DH parameters the server provides.

How can I tell what DH size I'm using from the OpenVPN client side when I connect to an OpenVPN server?

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#135
post #123

Earlier quoted context omitted.

Protecting yourself against the NSA is a good proxy for protecting yourself against other bad actors. The NSA has thousands of employees, a multi-billion dollar budget, and works 24 hours to crack, hack or otherwise gain unauthorized access to computer systems. So, if I can defend myself against the NSA, I've probably inoculated myself against other attackers using similar attack vectors.

I highly doubt that, and I don't think it's a good logic. You cannot compare the power, tools and jurisdiction the NSA has and compare that to other bad actors. The NSA literally has the right to spy on you, but it will get very difficult for somebody else to do something comparable if they don't have the same resources AND the same intentions.

> The NSA literally has the right to spy on you

Wow. Seriously, why would you think they had that right?

If the link in their HN profile is to be believed, the person you are replying to is almost certainly a US citizen. The NSA is not authorized for domestic surveillance, as General Alexander admitted when he perjured himself in front of Congress[1]. It's in their charter, it's in the 4th Amendment and a couple hundred years of legal precedent. We even addressed these limitations in the Church Committee.

So I really don't understand why you would believe they had the right to spy on domestic targets. Besides, the game played by the FVEY members is letting GCHQ do the spying on US targets, not the NSA.

[1] https://www.youtube.com/watch?v=QUY_MBzc42o#t=882

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#136

Earlier quoted context omitted.

Because this particular military spy organisation is being deployed by the US government against its own citizens, en masse, as an end-around well-established due process and constitutional protections that require individualised suspicion of wrongdoing. It also represents a giant exfiltration target for other state actors, like those who breached OPM. NSA hurts the security of Americans under the guise of preventing…

"Because this particular military spy organisation is being deployed by the US government against its own citizens, en masse" But it's not. That's the problem. There's no evidence whatsoever of it doing that.

So you're telling me there's no evidence that the NSA has committed call logs of every US Verizon subscriber to their own persistent storage for later inspection? No evidence that NSA intercepted inter-datacenter transfers of American companies, who were housing the personal data of Americans? No evidence that Americans have been swept up in overly-broad "one foreign end" wiretaps? All of the weakdh.org people are crazy? That well-documented room in the AT&T building in San Francisco was just a big misunderstanding?

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#137

My big picture take-away is: It seems that the NSA (and possibly other state-level actors) can access encrypted traffic that uses 1024-bit Diffie-Hellman that use commonly-used prime numbers. This means HTTPS, SSH, IPsec, SMTPS, and protocols that rely on TLS are potentially vulnerable. Where’s there’s smoke, there’s fire and there’s a lot of smoke indicating the NSA can do this. They have the money, technology, infr…

"It seems that the NSA (and possibly other state-level actors) can access encrypted traffic that uses 1024-bit Diffie-Hellman that use commonly-used prime numbers." How does it "seem this"? There's no evidence, no plausibility, no sense here whatsoever. Someone hypothetically conjectured a magic all-powerful computer that could magically crack a prime, and that would magically make us all vulnerable to the government…

Perhaps you should remove yourself from the discussion then.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#138
post #43
post #40

Earlier quoted context omitted.

One of the main things I want to keep private is just family life - conflicts, love, sex, etc. I don't want the government to know about my private family life. I don't see how a free, thoughtful, creative society can flourish if the government can always know the goods on everybody.

I don't think the government wants to know about your private family life neither. I mean, it's edgy to imagine that the government has a secret file on all of us. But they don't do they? It's just very silly nonsense.

You haven't been paying attention to the news over the last two years.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#139
post #127

Earlier quoted context omitted.

That my friend is called Democracy. When a majority rules..

And that's why the United States was designed precisely to avoid becoming a democracy and instead be a republic.

And look how that's turned out.

It took less than 200 years for it to devolve into a full-blown plutocracy.

Re: How to Protect Yourself from NSA Attacks on 1024-bit DH

#140
post #124

Earlier quoted context omitted.

But who exactly would really want to protect themselves from the NSA? Anybody who is afraid of parallel construction. And if you're not, you should be.

> parallel construction I've read the wikipedia article, and I don't see how I should be afraid of it. Or maybe I don't understand it properly. Anyway, this article would be targeting people who are the target of the NSA, like political dissidents or journalists.

> people who are the target of the NSA, like political dissidents or journalists.

That in itself should worry you.

Post reply on HN