Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

131–140 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#131
> A 2010 document calls for “a new approach for opportunistic decryption, rather than targeted.” By that year, a Bullrun briefing document claims that the agency had developed “groundbreaking capabilities” against encrypted Web chats and phone calls. Its successes against Secure Sockets Layer and virtual private networks were gaining momentum.

This paragraph interests me the most.

For one, it's clear that their goal is opportunistic decryption; that is, decrypting everything and being able to search through it, rather than targeting known endpoints. This is an important point that a lot of people miss when debating cryptography. While it's fairly likely that the government can find ways to access any communication they want in a targeted manner, as they have so many means to do so (hacking the endpoints, physically breaking in and performing an evil maid attack, etc), widespread encryption is generally good enough to prevent opportunistic data gathering.

The other point I note is that they only mention "web chats and phone calls" in their breakthrough. It doesn't sound like the breakthrough is something that works well for arbitrary SSL connections. The main link I can see between web chats and phone calls is that they are long lived connections, with bursty traffic (HTTP or email protocols, on the other hand, tend to stream a lot of data at once, and then the connection is closed). I'm wondering if there's some kind of traffic or timing analysis vulnerability that they've discovered.

Also interesting is this quote from the Guardian article:

> To help secure an insider advantage, GCHQ also established a Humint Operations Team (HOT). Humint, short for "human intelligence" refers to information gleaned directly from sources or undercover agents. > > This GCHQ team was, according to an internal document, "responsible for identifying, recruiting and running covert agents in the global telecommunications industry."

Various technology companies have been adamant in maintaining that they haven't been been giving the NSA direct access to their data. However, with HUMINT programs like this, you always have to wonder if the NSA has hired anyone within such companies to put backdoors into their systems, without authorization by the company. Obviously, they'd have to be subtle about it (it's hard to install new gigabit fiber pipes to siphon off the data without anyone noticing), but just setting up a way for the NSA to covertly run queries, disguised as some other type of job that would normally run on the system, would probably not be too hard to do.

Re: N.S.A. Foils Much Internet Encryption

#132
post #51
post #36

Earlier quoted context omitted.

> I have no problem with the NSA being able to break encryption, that's in fact part of their job. Their "breaking" of encryption is a combination of purposefully introducing vulnerabilities into standards, surreptitiously altering software and hardware to give the NSA a backdoor, hacking into private systems and stealing keys, etc etc. I'm cool with an NSA super computer trying to brute force my VPN traffic to YouTu…

I will bet good money that the NSA has never bothered to try and plant backdoors in encryption standards. If the NSA recommends AES to the US government, but knows there's a vulnerability, then they have to assume that any adversary may be as good as whoever designed it. Which means an adversary would be perfectly capable of discovering and exploiting the weakness. Which in turn means the NSA has just made the entire…

> I will bet good money that the NSA has never bothered to try and plant backdoors in encryption standards.

Did you read the article?

> By this year, the Sigint Enabling Project had found ways inside some of the encryption chips that scramble information for businesses and governments, either by working with chipmakers to insert back doors or by surreptitiously exploiting existing security flaws, according to the documents.

Seems pretty cut and dry.

Re: N.S.A. Foils Much Internet Encryption

#133
post #109

Earlier quoted context omitted.

Quantom computing cannot break all of crypto. Anything based on P!=NP is believed to be secure against quantom computing, and there are several encryption methods backed by P!=NP

> Quantom computing cannot break all of crypto. Correct (except for the spelling of "Quantum"). > Anything based on P!=NP is believed to be secure against quantom computing, and there are several encryption methods backed by P!=NP Incorrect, well mostly. The deal is that there are problems that can be done in "polynomial time" (how long it takes is not exponential in the size of they key) for a normal computer (or pe…

> the ones that CANNOT be done on polynomial time is "NP".

I see you've solved one of the great open problems!

NP is defined as problems that a nondeterministic turing machine can solve in polynomial time. Imagine, if you will, a turing machine that when it "branches" always chooses the right path (Or: chooses "both" without overhead)

Re: N.S.A. Foils Much Internet Encryption

#134

Earlier quoted context omitted.

Plus (form the Guardian article) there are covert agents in all the companies, presumably lifting all the certs, which may well be unauthorised, but you can't prosecute. Do you know who your covert agents are?

Why couldn't you prosecute, if you found out? I assume theft is still theft, even if done by a government employee.

Good luck with that. You would need the government to prosecute and the government makes it illegal to talk about what you want to prosecute.

Re: N.S.A. Foils Much Internet Encryption

#135
Up until very recently, the received wisdom was: the crypto wars are over, we fought the law and the law gave up, the NSA has quit trying to crack encryption, they have decided the USA is best strengthened by having a reliable internet which business rival nations can't just read like the morning's news. The NSA knows the problems in crypto and their suggestions make it stronger against attacks we don't know. Trust the NSA.

Would that it were true! It would make sense. This makes no damn sense. Just recently I would have ruled out huge conspiracies as implausible because they inevitably leak (roll save against ethics how many times?). The joke's on me, folks. The NSA has no sense. And the conspiracy leaked.

So now every single decision that was taken with help from the NSA (SELinux, TLS, elliptic curves, etc) needs unpicking and running by a cryptographer who isn't a shill. What a damn drag. And meanwhile, the aftershocks will run for years trashing trust in the networked economy.

Fuckin' brilliant, NSA. You screwed the pooch. You accidentally the whole internet.

Re: N.S.A. Foils Much Internet Encryption

#136

Earlier quoted context omitted.

so what was the vulnerability found by ms in 2007 that they are referring to? (search for 2007 in single page version at http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet... ) edit: reading in more detail around there, i am pretty sure that section of the article is referring to the CSPRNG vulnerability above. the article covers a lot of ground and not all of it is about problems with ssl. that particular…

I don't know. I'm just saying, weakening a CSPRNG design that nobody uses or is ever likely to use (it's extremely expensive) is not a particularly meaningful action.

Not a crypto expert at all, but did they knew in advance that nobody would use it? Otherwise it could just be a failed attempt.

Re: N.S.A. Foils Much Internet Encryption

#137
post #128
post #85

You can't have read Applied Cryptography from the mid-90s and not understand this to have been NSA's M.O. from the jump. Bruce Scheier, who was quoted in the Guardian piece about the same story, is America's foremost popularizer of the notion of NSA as crypto's global passive adversary. People who build real cryptosystems have never, ever been allowed to rely on the goodwill of the NSA not to cryptanalyze their syste…

That security systems are designed in the most paranoid fashion possible doesn't tell you anything about the real nature of the threat. Schneier's book doesn't tell you that the NSA has been strong arming corporations into giving up their private keys and into installing backdoors on chips. In fact Schneier himself is outraged to the point that he seems to be calling for a redesign of basic Internet protocols and gov…

Yeah, I'm a little baffled by Schneier's reaction to this. The revelation is advanced cryptanalytic capabilities at NSA, which is literally an article of faith with Schneier. Why is he freaking out about this when he didn't instead freak out about wholesale call record database dumps or AT&T fiber taps?

Re: N.S.A. Foils Much Internet Encryption

#138

Earlier quoted context omitted.

I don't know. I'm just saying, weakening a CSPRNG design that nobody uses or is ever likely to use (it's extremely expensive) is not a particularly meaningful action.

Not a crypto expert at all, but did they knew in advance that nobody would use it? Otherwise it could just be a failed attempt.

I don't know what they expected, but Dual-EC is self-evidently noncompetitive.

Re: N.S.A. Foils Much Internet Encryption

#139
post #64
post #63

Earlier quoted context omitted.

Remember when Microsoft would trash Linux because it was open source and "not secure." Well, this settles it. Using your own hardware and open source software helps but someone determined will still get in...

Even "your own hardware" is going to be pretty damn hard: working with chipmakers to insert back doors So you're going to need to make your own chips, too.

Refusing to rely on the RNG in Intel processors doesn't seem particularly unreasonable in the light of this revelation does it?

Re: N.S.A. Foils Much Internet Encryption

#140
post #58
post #16

Earlier quoted context omitted.

So, should we re-evaluate if Intel/AMD's chips (and possibly even the new ARM ones) contain hardware backdoors for the NSA?

If the source code/hardware diagrams are kept private you should assume backdoors, always, with everything. How is there any other way to know for sure otherwise? These government agencies are obviously dug much deeper in private industry than many expected so I wouldn't put it past them

If you see the diagram, and someone else makes the chip, how do you know the diagram matches exactly with what's on the chip? Unless you can make your own chip from the diagram, you still cannot be sure.
Post reply on HN