Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

211–220 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#212
post #188

Earlier quoted context omitted.

Even without naming the companies involved, it's very hard to imagine they are inserting backdoors in less-valued products while somehow missing the crown jewels of Windows and TPM.

I keep finding myself in the awkward position of trying to refute conspiracy theories, but not being at liberty to share everything I know about these scenarios (I really need to work somewhere besides DC), so I'll tread lightly. Taking for granted that the NSA actually backdoored TPM's (which I can assert professionally is very unlikely, but I don't expect anyone to take my word for it), they are far from "crown jew…

You realize that these are exactly the same arguments that were brought up to argue against the details revealed in these documents, so perhaps appeals to authority and use of the words 'conspiracy theories' may be taken with a few more grains of salt. NSA backdoors have been alleged for decades now, and the response is always that they're a 'conspiracy theory'.

Re: N.S.A. Foils Much Internet Encryption

#213

Earlier quoted context omitted.

Can you expand a bit on chrome's anti-surveilance capabilities?

They pin certificates, so that a CA compromise that would enable MITM attack by the global passive adversary would be detectable (and in fact that mechanism has already been used to detect CA compromises.)

Why do you say "passive adversary"? I wouldn't call an MITM with a fake cert "passive".

Re: N.S.A. Foils Much Internet Encryption

#214
There is an old saying that states that a jealous husband or wife can't be trusted. They don't trust you because they are, have, or are thinking about fucking someone else.

When the combined '5 eyes' come out and ban Lenovo / Huawei from being used on any of their secure networks, because of fears of back doors [1], one has to imagine that the same is true of themselves.

The hardware is most likely backdoored as well as firmware, the OS and installed software. I would not trust anything, even open source, because to be perfectly honest, there a very few people who really are smart enough to understand the in depth cryptographic requirements. If there are people, then they probably already work for the NSA or GCHQ.

If you want to plan a terrorist attack or become a politician or business leader who does not want to be blackmailed, don't do anything on the internet apart from share pictures of cute cats.

My advice to any terrorists is to go dark. Speak in private. Write it down pass the note and then burn it. Use old methods like book ciphers. Touch and electronic device and they have you.

Legal note: Of course I'm not advocating 'advising' terrorists, well only the good ones, you know those ones that we call 'freedom fighters'. The ones western governments like to back when it suits their purposes.

[1] http://www.infosecurity-magazine.com/view/33679/lenovo-compu...

Re: N.S.A. Foils Much Internet Encryption

#215
post #212

Earlier quoted context omitted.

I keep finding myself in the awkward position of trying to refute conspiracy theories, but not being at liberty to share everything I know about these scenarios (I really need to work somewhere besides DC), so I'll tread lightly. Taking for granted that the NSA actually backdoored TPM's (which I can assert professionally is very unlikely, but I don't expect anyone to take my word for it), they are far from "crown jew…

You realize that these are exactly the same arguments that were brought up to argue against the details revealed in these documents, so perhaps appeals to authority and use of the words 'conspiracy theories' may be taken with a few more grains of salt. NSA backdoors have been alleged for decades now, and the response is always that they're a 'conspiracy theory'.

My argument isn't that the NSA hasn't backdoored TPM's (which I freely admit I can't convince you of), it's that TPM's are not "The Crown Jewels".

Re: N.S.A. Foils Much Internet Encryption

#216
post #21

This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability. The issue to me has always been how and what data they access and store, and how it is used.

I have a problem with encryption being breakable, regardless of who's doing the breaking. I want encryption to be mathematically solid with the only option being brute-force older-than-age-of-earth time. When we get to quantum computing, then I don't know what we'll do...

If we get quantum cryptography out the door in a reasonable space of time, then we can do secure one time pad exchanges on there. Doesn't matter what you throw at that, since with the right keys you can derive any message of the same length from it.

Re: N.S.A. Foils Much Internet Encryption

#217

Earlier quoted context omitted.

What amazes and saddens me about this, though, is that I was one of the people who thought that we could draw a line -- the NSA was obviously going to keep its cryptanalysis techniques secret, they probably listened to everything, but the idea that they were actively sabotaging cryptosystems just seemed like to far-fetched a conspiracy theory. Half their mission is to protect US communications from foreigners, and ba…

No, that's not NSA's doing. PGP predates the theoretical constructions you're referring to. Bellare/Namprempre was something like 5 years after the first "modern" PGP (IIRC the original PGP used a terribly broken cipher of Zimmerman's own design). Also, malleability is not a particularly lucrative capability for NSA to have, even if you want to assume that the integrity mechanisms in PGP are broken.

I am pretty sure that the OpenPGP standard has been updated since that work, and that it is still not quite following the constructions.

Also, I do not think the NSA would have no interest at all in malleability. Suppose the NSA is trying to track messages sent through anonymous remailers (Type I, maybe because the target is using a nym server) and there is a "Max-Count: 1" header. An easy attack that exploits malleability would be the maul the message somewhere after the headers and see where a mauled messages exits the remailer network. This is probably possible with the NSA's resources and expertise, and the NSA is probably concerned about anonymity systems in general (and perhaps looking for ways to attack them).

My real point, though, is that we need to stop for a moment and re-evaluate pretty much all the cryptography standards we depend on. We really cannot say that these systems have not been deliberately sabotaged by the NSA, not with this latest revelation.

Re: N.S.A. Foils Much Internet Encryption

#218

"In one case, after the government learned that a foreign intelligence target had ordered new computer hardware, the American manufacturer agreed to insert a back door into the product before it was shipped, someone familiar with the request told The Times." Wow.... this really puts all the furor over Huawei contracts in the US in context.

I will just leave this here:

http://www.csoonline.com/article/707542/china-not-to-blame-f...

http://www.extremetech.com/computing/133773-rakshasa-the-har...

Re: N.S.A. Foils Much Internet Encryption

#219
post #70

> the Bullrun program, the successor to one called Manassas — both names of American Civil War battles. A parallel GCHQ counterencryption program is called Edgehill, named for the first battle of the English Civil War of the 17th century. Spying on your own citizens codenamed as civil war. How nice. > Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among…

Spying on your own citizens codenamed as civil war. How nice. Nowhere in the article does it state that these methods can be used against US persons separate from other protections against surveillance on US persons, nor does it give the impression that this is special to US persons: The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the del…

You must have been living under a rock for the past few months. Welcome to September, where we now know that to not be the case.

Re: N.S.A. Foils Much Internet Encryption

#220

"In one case, after the government learned that a foreign intelligence target had ordered new computer hardware, the American manufacturer agreed to insert a back door into the product before it was shipped, someone familiar with the request told The Times." Wow.... this really puts all the furor over Huawei contracts in the US in context.

All that furore over Huawei contracts in the US was just projection wasn't it? You're might be more secure buying your network kit from Huawei than from a US manufacturer.
Post reply on HN