Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

201–210 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#201
post #115
post #77

Earlier quoted context omitted.

Well, it goes on to say "Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency." The Dual_EC_DRBG vulnerability was revealed by two Microsoft researchers in 2007: http://rump2007.cr.yp.to/15-shumow.pdf So I'd say yes, it sounds like that's what they're talking about. Speaking of which, I'm really quite frustrated how many of…

> Speaking of which, I'm really quite frustrated how many of these recent reports about the NSA elide the technical details. Are you? Well please sign up to work for the NSA, learn the technical details, then go public with them. The reason that the NYTimes isn't publishing the technical details is because they DON'T KNOW THEM. (They might not publish them if they did.) They don't know them because Edward Snowden was…

From the article:

> "Intelligence officials asked The Times and ProPublica not to publish this article, saying that it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read. The news organizations removed some specific facts but decided to publish the article because of the value of a public debate about government actions that weaken the most powerful tools for protecting the privacy of Americans and others."

NYT, the Guardian, etc do have access to these details, but chose not to publish them.

Re: N.S.A. Foils Much Internet Encryption

#202
The most fascinating part of this article to me is this part, which proves that even a super-secure intelligence agency can still have very weak links that can be penetrated:

Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among them, but he nonetheless managed to obtain dozens of classified documents referring to the program’s capabilities, methods and sources.

Who knows what other documents other internal hackers could have stolen?

Re: N.S.A. Foils Much Internet Encryption

#203
post #165
post #149

Earlier quoted context omitted.

I think we know very well which encryption has been foiled by the NSA. This is not speculation, but quasi-certainty: 1024-bit RSA. - Crytographers all acknowledge 1024-bit RSA is dead [1]. - Attack cost 10 years ago was estimated to be a few million USD to build a device able to crack a 1024-bit key every 12 months [2]. - "Much of" the "secure" HTTPS websites use such weak key sizes [3]. - NSA had a budget of 10.8 bi…

Some popular browsers still do not support newer versions. We tried turning this on with a newer, more secure key and ended up having downtime for some customers.

Which browsers in particular?

Re: N.S.A. Foils Much Internet Encryption

#204
post #188

Earlier quoted context omitted.

What? Which documents confirm backdoors in TPM chips?

Even without naming the companies involved, it's very hard to imagine they are inserting backdoors in less-valued products while somehow missing the crown jewels of Windows and TPM.

I keep finding myself in the awkward position of trying to refute conspiracy theories, but not being at liberty to share everything I know about these scenarios (I really need to work somewhere besides DC), so I'll tread lightly.

Taking for granted that the NSA actually backdoored TPM's (which I can assert professionally is very unlikely, but I don't expect anyone to take my word for it), they are far from "crown jewels".

The only "meaningful" large scale use of TPMs is actually within the department of defense. It's been a pretty uphill battle getting them deployed and used in other environments.

Re: N.S.A. Foils Much Internet Encryption

#205
post #128

Earlier quoted context omitted.

That security systems are designed in the most paranoid fashion possible doesn't tell you anything about the real nature of the threat. Schneier's book doesn't tell you that the NSA has been strong arming corporations into giving up their private keys and into installing backdoors on chips. In fact Schneier himself is outraged to the point that he seems to be calling for a redesign of basic Internet protocols and gov…

Yeah, I'm a little baffled by Schneier's reaction to this. The revelation is advanced cryptanalytic capabilities at NSA, which is literally an article of faith with Schneier. Why is he freaking out about this when he didn't instead freak out about wholesale call record database dumps or AT&T fiber taps?

This is not just about cryptanalysis. The NSA has been deliberately introducing weaknesses into cryptosystems used by the general public. That is beyond keeping cryptanalysis techniques secret, which we all assumed they would do and which few really drew any issue with. We are talking about an honest-to-goodness conspiracy, one that yesterday many would have written off as a conspiracy theory that was not even worth considering.

Basically, what we thought were the rules of the game are not the rules of the game. We thought we knew where we stood with the NSA -- they would try to attack, we would try to defend. Now we need to be thinking of a much different set of rules, one in which the NSA is not just attacking ciphers but also deliberately sabotaging our defense, and doing so covertly. We cannot even assume that mistakes really are mistakes anymore -- they could be the NSA's doing.

Re: N.S.A. Foils Much Internet Encryption

#206
post #71

Earlier quoted context omitted.

That's a false sense of security. You can inspect every line of code in SSL but unless you are a world-class cryptographer yourself, how will you spot a backdoor in the algorithm ?

Your statement reveals a real lack of understanding of opensource. Hint; it's open to all, all includes world-class cryptographers. Each contributes their ability for the greater good of all. WCC may not spend their time coding or packaging or whatever. Others will.

No, I'm afraid it is you who are mistaken... About a great many things.

Re: N.S.A. Foils Much Internet Encryption

#207
post #70

> the Bullrun program, the successor to one called Manassas — both names of American Civil War battles. A parallel GCHQ counterencryption program is called Edgehill, named for the first battle of the English Civil War of the 17th century. Spying on your own citizens codenamed as civil war. How nice. > Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among…

Spying on your own citizens codenamed as civil war. How nice. Nowhere in the article does it state that these methods can be used against US persons separate from other protections against surveillance on US persons, nor does it give the impression that this is special to US persons: The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the del…

>the rules that prohibit the deliberate targeting of Americans’ e-mails or phone calls without a warrant

The previous leaks show these rules to not be particularly effective. For me and most of the world that distinction is irrelevant anyway. The position of the US government is that it can order its tech companies, with whom I have contractual/financial relationships to give them all my data with no warrant.

Re: N.S.A. Foils Much Internet Encryption

#208

Earlier quoted context omitted.

In that particular instance you weren't wrong[1], but that's the problem when stories like this come out, is that it makes it much harder to know what's a crazy conspiracy theory and what's real. [1] Those claims made by Greg are completely untrue. I ran the professional services group for that company and will happily attest to whomever asks that at no time did we insert a backdoor (or anything that could even be co…

>Those claims made by Greg are completely untrue. I ran the professional services group for that company and will happily attest to whomever asks that at no time did we insert a backdoor (or anything that could even be construed as such) into IPSEC. Somehow I doubt if you did that you could tell us. You might even have to lie to be able to comment on that letter at all.

I'm still unclear on the government's ability to compel falsehoods (even the discussions around National Security Letters seem to indicate that they prevent disclosure, but can't require lying), but I don't think I can convince you of that.

When all the hullabaloo around the alleged IPSEC backdoor occurred, it was frustrating to not be able to be as open about it as I wanted (not because of any government/security issues, but because at the time I still worked for the company and we were advised against talking about it).

You are free to assume that even right now as I type this, a shadowy figure in an ill-fitting Brooks Brothers suit is standing over me dictating my responses, and then chastising me for spending my time on HackerNews.

Re: N.S.A. Foils Much Internet Encryption

#209

Earlier quoted context omitted.

This is all theoretical, but you could use decentralized services/protocols that would eliminate such an opportunity.

If I was in the NSA (which I am not) I would place a backdoor in the browser themselves, and since the browsers auto-update from the internet anyway, I would change the DNS provider for the machine being watched (remember the DNS settings generally default to that provided by your ISP) to point to the NSA-version of the browser, and then the user would be browsing securely, but after decryption and before display, th…

Your machine would be showing an extra outbound connection.

Re: N.S.A. Foils Much Internet Encryption

#210
post #71

Earlier quoted context omitted.

That's a false sense of security. You can inspect every line of code in SSL but unless you are a world-class cryptographer yourself, how will you spot a backdoor in the algorithm ?

Can we combine multiple algorithms such that having any one of them be secure is safe? For example, instead of encrypting with just RSA, do one pass with RSA and then another pass with ECC. Instead of just using AES, do one pass with AES, another pass with Twofish, and a third pass with RC4. Does that actually help?

Yes, though there are some subtleties, it's fairly straightforward overall.

The reason we don't do that is, of course, CPU cost.

Post reply on HN