Live data from Hacker News

Intel In Bed with NSA?

cryptome.org

21–30 of 73 posts

Re: Intel In Bed with NSA?

#21
post #19

Earlier quoted context omitted.

> also made DES more resistent to differential cryptanalysis Was that the result of the last-minute "black box" change? I never heard the result of that, so any light you shed would be welcome.

Correct. The NSA suggested changes in the DES S-boxes, which led to many questions. Ultimately, what was discovered is that their changes strengthened DES, not weakened it, as some had feared. You can read more about their involvement here: http://crypto.stackexchange.com/questions/16/how-were-the-de...

Very interesting, and not exactly news, which tells you the last time I looked at this. Obviously, I'm a dinosaur.

Thanks for the pointer.

Re: Intel In Bed with NSA?

#22
post #3

It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated: > Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there'd be no risk of it causing a s tstorm…

Well, it is documented that the NSA made DES weaker by using less bits for key size (this makes brute forcing easier). I aslo noted that Schiener's AES submission was passed over (I speculate that Rijndael is easier to brute force). The feds used to fight civilian crypto tooth and nail. Then they allowed it, and in one of the crypto books a story was related that the feds were bummed about RSA and friends. The listen…

> The feds used to fight civilian crypto tooth and nail.

Curious. I'd like to read about this. Can anyone post any links?

Re: Intel In Bed with NSA?

#23
post #22

Earlier quoted context omitted.

Well, it is documented that the NSA made DES weaker by using less bits for key size (this makes brute forcing easier). I aslo noted that Schiener's AES submission was passed over (I speculate that Rijndael is easier to brute force). The feds used to fight civilian crypto tooth and nail. Then they allowed it, and in one of the crypto books a story was related that the feds were bummed about RSA and friends. The listen…

> The feds used to fight civilian crypto tooth and nail. Curious. I'd like to read about this. Can anyone post any links?

http://www.loundy.com/Roadside_T-Shirt.html is one example, there are probably others. It ended up going in a sane direction, but it's a bit crazy to imagine in hindsight.

Re: Intel In Bed with NSA?

#24

Earlier quoted context omitted.

Well, it is documented that the NSA made DES weaker by using less bits for key size (this makes brute forcing easier). I aslo noted that Schiener's AES submission was passed over (I speculate that Rijndael is easier to brute force). The feds used to fight civilian crypto tooth and nail. Then they allowed it, and in one of the crypto books a story was related that the feds were bummed about RSA and friends. The listen…

The NSA, working with IBM, also made DES more resistent to differential cryptanalysis, which was not widely understood at the time.

The change the NSA made was to replace the s-boxes used with ones that made using differential crypto analysis slightly less efficient than brute force. As it happens, the s-boxes provided by the NSA were also among the worst 9%-16% possible with respect to linear crypto analysis. "A software implementation of this attack recovered a DES key in 50 days using 12 HP9000/735 workstations" [1]. I do not know the specs of said workstations, but for reference the book claims that was the fastest attack at the time of writing (1996).

This is not to say that the NSA was aware of linear crypto analysis when they made their recomendation. Indeed the fact that their s-boxes also happened to be just good enough to beet differential, and the fact that an independent government investigation (the details of which are classified) cleared them of wrongdoing, are enough to convince that they did not intend to introduce a hole. Furthermore, the NSA has also now published the requirements they used to generate their s-boxes. Schneier suggests in his book that the s-boxes were weakened unintentionally by the act of introducing structure to them, without knowing to defend against linear analysis.

[1] Bruce Schneier, Applied Cryptography

Re: Intel In Bed with NSA?

#25
post #9

Hanlon's razor help in this kind of discussions. Maybe when Linus took that option didn't saw Intel as something that would intentionally make predictable its RNG for following government orders, and just choose to not reimplement the wheel where it was already available. Would he take another option since last month? Maybe in the light of this he could take back that choice.

Linus does not have the option to reimplement the wheel. Software cannot generate random numbers.

Re: Intel In Bed with NSA?

#27
It's safe to assume every core technology company has been compelled to be in bed with the NSA in some form or another. Intel has been anti-trust managed by the government for nearly two decades. Getting access to the monopoly desktop / laptop processor maker would be far too rich a target to ignore.

Re: Intel In Bed with NSA?

#29

It's safe to assume every core technology company has been compelled to be in bed with the NSA in some form or another. Intel has been anti-trust managed by the government for nearly two decades. Getting access to the monopoly desktop / laptop processor maker would be far too rich a target to ignore.

This is why I show preference towards AMD chips even when they have the competitive disadvantage. Any sufficiently large company ends up, through their will or the gov'ts, wrapped up in politics. Which is the one of the larger issues of our age.

Re: Intel In Bed with NSA?

#30
post #3

It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated: > Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there'd be no risk of it causing a s tstorm…

>anything other than utter paranoia.

I want hackers, cypherpunks, and cryptographers to be utterly paranoid.

Post reply on HN