Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

161–170 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#161
As is usually the case with an article in the mainstream media, the most interesting part is what isn't in it. If much Internet traffic is vulnerable to the NSA (and to the UK's GCHQ), doesn't that imply that much Internet traffic is also vulnerable to other governments? Such as, oh, say, China and Russia?

Re: N.S.A. Foils Much Internet Encryption

#162
> In effect, facing the N.S.A.’s relentless advance, [Lavabit] surrendered

I disagree with this characterization. Surrendering to the NSA would be Google/Facebook/Microsoft's approach of unconditional cooperation. Lavabit's refusal to work with the NSA -- even though apparently the only alternative was shutting down their business or going to jail -- is more along the lines of a scorched earth retreat (destroying your own stuff when you can't hold the line).

Re: N.S.A. Foils Much Internet Encryption

#163
post #79
post #71

Earlier quoted context omitted.

That's a false sense of security. You can inspect every line of code in SSL but unless you are a world-class cryptographer yourself, how will you spot a backdoor in the algorithm ?

It's a bit harder to sneak in junk in open source projects. You can see the checkins. However, you are right, if the flaw is in the algorithm itself, it's hopeless.

http://underhanded.xcott.com/ You can't rely on a backdoor looking like this:

    if(!strcmp(username, "secretagentman")) { … }

Re: N.S.A. Foils Much Internet Encryption

#164
This doesn't make sense. It can't be. Why would cryptography be subject to export regulations then? If we follow this logic, you would think export barriers would have been brought down decades ago and use of NSA cryptography highly encouraged worldwide.

Re: N.S.A. Foils Much Internet Encryption

#165
post #149
post #68

This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…

I think we know very well which encryption has been foiled by the NSA. This is not speculation, but quasi-certainty: 1024-bit RSA. - Crytographers all acknowledge 1024-bit RSA is dead [1]. - Attack cost 10 years ago was estimated to be a few million USD to build a device able to crack a 1024-bit key every 12 months [2]. - "Much of" the "secure" HTTPS websites use such weak key sizes [3]. - NSA had a budget of 10.8 bi…

Some popular browsers still do not support newer versions. We tried turning this on with a newer, more secure key and ended up having downtime for some customers.

Re: N.S.A. Foils Much Internet Encryption

#166

What's truly frightening is this line from the Guardian's article on the topic: > The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace". What does that even mean? That statement is at the same time paranoid, arrogant, and subtly threatening. It's as if to say that without the ability to decrypt interesting traffic, the NSA would be…

I think the key to understanding this is to remember that it was written by the NSA for the understanding of the NSA, or other highly authorized eyeballs in the government.

In many government documents, use of the name "U.S." is shorthand for the U.S. national government, not the entirety of the nation. Sometimes it is even shorthand for the particular agency that authored the document (since, in theory, they represent and act on behalf of the entire nation).

So what this internal NSA document most likely means by "unrestricted access and use" is the NSA's unrestricted access to, and use of, whatever data they want.

Think of it like a budget justification (since that is the purpose of at least half of all internal government reports). "You need to keep spending a lot of money on this program if you want us to keep getting all that data you like so much."

Re: N.S.A. Foils Much Internet Encryption

#167
post #104

Earlier quoted context omitted.

One of the vulnerabilities was already discovered by researchers in 2007: http://rump2007.cr.yp.to/15-shumow.pdf At the time, it wasn't clear if this was a deliberate backdoor or an accident, but it was proven that there there was a possibility that there was a secret key that would allow someone to predict future values of a pseudo random number generator based on previous values. Now it looks pretty clear that it w…

This is almost definitely not "one of the vulnerabilities" implicated in the story today, because nobody uses CSPRNGs based on Elliptic Curve.

Nobody uses them because they came out of the NSA with little precedent in the open literature, and independent analysis quickly uncovered this vulnerability.

Re: N.S.A. Foils Much Internet Encryption

#168
post #71

Earlier quoted context omitted.

That's the quote that jumped out at me too. The solution for those who want to stay out of NSA's reach is to use your own hardware, and use open source software (where it's hard to put a backdoor without being discovered) and strong encryption.

That's a false sense of security. You can inspect every line of code in SSL but unless you are a world-class cryptographer yourself, how will you spot a backdoor in the algorithm ?

Can we combine multiple algorithms such that having any one of them be secure is safe? For example, instead of encrypting with just RSA, do one pass with RSA and then another pass with ECC. Instead of just using AES, do one pass with AES, another pass with Twofish, and a third pass with RC4. Does that actually help?

Re: N.S.A. Foils Much Internet Encryption

#169

What's truly frightening is this line from the Guardian's article on the topic: > The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace". What does that even mean? That statement is at the same time paranoid, arrogant, and subtly threatening. It's as if to say that without the ability to decrypt interesting traffic, the NSA would be…

Look at what's happening in the UK, in Australia, in France, in Italy, in Spain... the Chinese model is winning hearts and minds of politicians everywhere, and how could it not? If you're into politics, you likely want to reach a Platonic ideal of harmonic society, where nobody is offended, nobody is threatened, and all laws are perfectly respected and enacted. You can't have that on a fully-open network. How can you keep your people from enduring child porn and Islamic propaganda, without censorship?

So most states are slowly moving towards implementing their own little firewalls. The only notable absence? The US. Despite occasional campaigns from religious nutters of various sizes and shapes and continuous pressures from commercial telcos, subsequent US administrations repeatedly affirmed that fundamental Net freedoms would not be curtailed.

This document states that such a position is not coming from idealism or even commercial convenience: it's a way to persuade the rest of the world to do business over networks and protocols that the NSA can tap at will. Should this capability be forcefully contained, there wouldn't be a political incentive to keep the Net flowing freely through US routers.

It's a perfectly reasonable and plausible position, and that's why it's so terrifying.

Re: N.S.A. Foils Much Internet Encryption

#170

Reminds me of this: http://marc.info/?l=openbsd-tech&m=129236621626462&w=2 As someone who has been following the NSA and government monitoring of online activity for close to 15 years the Snowden leaks just keep taking the wind out of me. It's like everything that we thought might be going on was actually going on. When Theo de Raadt wrote the above mail I, like many at the time, assumed it was tinfoil hat territory.…

In that particular instance you weren't wrong[1], but that's the problem when stories like this come out, is that it makes it much harder to know what's a crazy conspiracy theory and what's real.

[1] Those claims made by Greg are completely untrue. I ran the professional services group for that company and will happily attest to whomever asks that at no time did we insert a backdoor (or anything that could even be construed as such) into IPSEC.

Post reply on HN