Earlier quoted context omitted.
This is almost definitely not "one of the vulnerabilities" implicated in the story today, because nobody uses CSPRNGs based on Elliptic Curve.
Nobody uses them because they came out of the NSA with little precedent in the open literature, and independent analysis quickly uncovered this vulnerability.
N.S.A. Foils Much Internet Encryption
181–190 of 395 posts
Re: N.S.A. Foils Much Internet Encryption
#182Re: N.S.A. Foils Much Internet Encryption
#183"The NSA is just doing its job."
Re: N.S.A. Foils Much Internet Encryption
#184You can't have read Applied Cryptography from the mid-90s and not understand this to have been NSA's M.O. from the jump. Bruce Scheier, who was quoted in the Guardian piece about the same story, is America's foremost popularizer of the notion of NSA as crypto's global passive adversary. People who build real cryptosystems have never, ever been allowed to rely on the goodwill of the NSA not to cryptanalyze their syste…
It may be widely believe in cryptography circles, but this release wipes away the plausible deniability that governments and American corporations have always depended on. Just last week, the German government was pooh-pooh'ing claims that Windows and TPM chips had backdoors inserted by the NSA.[1] These documents all but confirm it. [1] http://www.zdnet.com/german-government-refutes-windows-backd...
Re: N.S.A. Foils Much Internet Encryption
#185Earlier quoted context omitted.
> I have no problem with the NSA being able to break encryption, that's in fact part of their job. Their "breaking" of encryption is a combination of purposefully introducing vulnerabilities into standards, surreptitiously altering software and hardware to give the NSA a backdoor, hacking into private systems and stealing keys, etc etc. I'm cool with an NSA super computer trying to brute force my VPN traffic to YouTu…
I will bet good money that the NSA has never bothered to try and plant backdoors in encryption standards. If the NSA recommends AES to the US government, but knows there's a vulnerability, then they have to assume that any adversary may be as good as whoever designed it. Which means an adversary would be perfectly capable of discovering and exploiting the weakness. Which in turn means the NSA has just made the entire…
The leaked documents confirm that this is exactly what happened.
Re: N.S.A. Foils Much Internet Encryption
#186Earlier quoted context omitted.
Sure. I think we agree. If "it" is a crypto weakness they are actually exploiting, "it" is not Dual-EC DRBG.
Ah, yes, I wasn't trying to say they were exploiting that particular vulnerability. Just that we now have better evidence that that really was a (rather poor) attempt to subvert standards to make them easier to decrypt. The NSA seems to be really divided between SIGINT and COMSEC. COMSEC wants to provide good, strong encryption, that can help secure US government and corporate communication. SIGINT wants to be able t…
I think maybe it's the fact that I started in the industry during the era of Clipper that stuff like this doesn't faze me much.
Re: N.S.A. Foils Much Internet Encryption
#187> the Bullrun program, the successor to one called Manassas — both names of American Civil War battles. A parallel GCHQ counterencryption program is called Edgehill, named for the first battle of the English Civil War of the 17th century. Spying on your own citizens codenamed as civil war. How nice. > Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among…
Nowhere in the article does it state that these methods can be used against US persons separate from other protections against surveillance on US persons, nor does it give the impression that this is special to US persons:
The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the deliberate targeting of Americans’ e-mails or phone calls without a warrant.
Let's keep in mind the fact that an intelligence agency is built to gather intelligence on other governments/organizations and that often involves breaking other jurisdiction's rules.
Re: N.S.A. Foils Much Internet Encryption
#188Earlier quoted context omitted.
It may be widely believe in cryptography circles, but this release wipes away the plausible deniability that governments and American corporations have always depended on. Just last week, the German government was pooh-pooh'ing claims that Windows and TPM chips had backdoors inserted by the NSA.[1] These documents all but confirm it. [1] http://www.zdnet.com/german-government-refutes-windows-backd...
What? Which documents confirm backdoors in TPM chips?
Re: N.S.A. Foils Much Internet Encryption
#189The problem is that the NSA apparently used those capabilities on basically everyone, millions of innocent Americans whose activities should be of no interest to intelligence agencies, not just the handful of genuine spooks and terrorists our intelligence agencies are supposed to protect us from. (To international people: Cosmically speaking, you're not less important than we are, but the NSA's first responsibility is to protect and serve the USA, so them spying on innocent Americans is at least as bad as them spying on innocent foreigners.)
And it has been shown that the NSA provided information to ordinary criminal investigations with no links to terrorism or foreign intelligence, having police say "it's a lucky traffic stop," where the government actually knew the drugs were in that car ahead of time due to a decrypted phone call. This makes a mockery of the Fourth Amendment because, when prosecutors/police lie to the courts about the origin of evidence, the courts cannot properly answer the question of whether their methods of gathering evidence violate the defendant's Constitutional protection against unreasonable search and seizure.
In short, this is coming out -- which, as the article said, will weaken those capabilities -- because the NSA went too far outside their mission scope. If they hadn't done those two things, I'd be willing to bet Snowden wouldn't have leaked this data.
Re: N.S.A. Foils Much Internet Encryption
#190This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…
Please clarify what you mean by "our".
Please clarify what you mean by "adversaries".