Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

171–180 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#171
post #143

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

> [...] and this enabled others to OCR it, and recompile it offshore. Did it? Or did it just give them plausible deniability? I remember playing with OCR as a kid and all the software I could get my hands on gave horrendous results, even if the input was as perfect as one could hope for. And even today I sometimes run tesseract on perfect screenshots and it still makes weird mistakes. Would be interesting to know if…

Not so much plausible deniability, as a clear First Amendment argument. If you’re forbidden from exporting computer code, that was some new-fangled magic thing that nobody could possibly understand. If you’re banned from exporting a book, well that has some clear and obvious precedent as a restriction of free speech.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#172
i believe the cryptomuseum has a more extensive list than the one in the link: https://www.cryptomuseum.com/intel/nsa/backdoor.htm particularly one is interesting as i have reverse engineered and proven its existence: https://www.cryptomuseum.com/crypto/philips/px1000/nsa.htm

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#173
post #95

Earlier quoted context omitted.

> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Then what is it based on, if it happens across different devices and different IP addresses? I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't conta…

there are MANY different ways to fingerprint something or someone, see e.g. https://abrahamjuliot.github.io/creepjs/ or https://scrapeops.io/web-scraping-playbook/how-to-bypass-clo... . also fun fact, even Tor Browser can't hide the real OS you're running when a site uses javascript-based OS queries.

[dead]

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#174

I was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0 ^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive ) I could no longer access the NSA website…

I'm curious as to why the NSA still has http:// urls.

It redirects to HTTPS.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#175
post #155

Earlier quoted context omitted.

At the time, I had a t-shirt that said "this t-shirt is a munition", because it also had on it the RSA public key algorithm encoded as a barcode.

i seem to have vague recollection of a variant of this shirt that had a perl script on it? or was the perl script for decoding the barcode?

Memory claims: It was RSA in Perl, text shape of a dolphin, but it may be wrong.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#176

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

Thawte happily sold certs to US entities like universities (I was a sysadmin at one of those universities with such a cert :) )

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#177

Earlier quoted context omitted.

Would be interesting what similar companies are (in parts) most likely agency fronts. My guess would be quite a few in the soft privacy selling business, such as VPN or email providers.

Proton mail is a CIA front email provider

Proton Mail's extremely bureaucratic operational deafness, and their glacial pace of product features and open-sourcing, would certainly lend support to that idea.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#178
post #107
post #82

Earlier quoted context omitted.

I know. We definitely aren't a nation founded on outright treason and insurrection, and thumbing our nose at authority and doing the moral thing isn't in our DNA in any way, shape, or form. Frustrating that some people think otherwise.

There can be moral reasons for treason. The founding fathers certainly considered themselves moral and principled. Your frustration is misguided. Simply do not confuse illegality with immorality. Human beings generally want to feel like they're doing more good than bad. As for "the DNA of a nation," we would probably spend a few hours figuring out the definition of what that even is just for starters.

[deleted]

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#179
post #107
post #82

Earlier quoted context omitted.

I know. We definitely aren't a nation founded on outright treason and insurrection, and thumbing our nose at authority and doing the moral thing isn't in our DNA in any way, shape, or form. Frustrating that some people think otherwise.

There can be moral reasons for treason. The founding fathers certainly considered themselves moral and principled. Your frustration is misguided. Simply do not confuse illegality with immorality. Human beings generally want to feel like they're doing more good than bad. As for "the DNA of a nation," we would probably spend a few hours figuring out the definition of what that even is just for starters.

Then my sarcasm worked. We are all of the things I said we aren't.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#180
post #107

Earlier quoted context omitted.

There can be moral reasons for treason. The founding fathers certainly considered themselves moral and principled. Your frustration is misguided. Simply do not confuse illegality with immorality. Human beings generally want to feel like they're doing more good than bad. As for "the DNA of a nation," we would probably spend a few hours figuring out the definition of what that even is just for starters.

From the outside, unironically calling any group of politicians "fathers" feels so weird. I know it's a super common turn of phrase, and that's kinda what gets me. > Human beings generally want to feel like they're doing more good than bad We're experts at convincing ourself that what is beneficial to us is also "good", whatever this actually means.

It's because they created a nation from whole cloth.

Also, forefathers is a common term.

Post reply on HN