Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

221–230 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#221
From the other article on the same subject:

"Among the specific accomplishments for 2013, the NSA expects the program to obtain access to "data flowing through a hub for a major communications provider" and to a "major internet peer-to-peer voice and text communications system". "

That second one is hard to read other than 'skype'.

Re: N.S.A. Foils Much Internet Encryption

#222
post #188

Earlier quoted context omitted.

Even without naming the companies involved, it's very hard to imagine they are inserting backdoors in less-valued products while somehow missing the crown jewels of Windows and TPM.

Ah, so if we can imagine it, it must be true.

No, but now we cannot just assume that cryptosystems are being developed in good faith or that mistakes are not actually covert sabotage. We need to check these systems before we put our trust in them.

Re: N.S.A. Foils Much Internet Encryption

#223
post #190
post #68

This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…

> but not so far that our adversaries can. Please clarify what you mean by "our". Please clarify what you mean by "adversaries".

Come now, we know enough about the NSA at this point to know that

our, adversaries = America, !America

right?

Re: N.S.A. Foils Much Internet Encryption

#224

Up until very recently, the received wisdom was: the crypto wars are over, we fought the law and the law gave up, the NSA has quit trying to crack encryption, they have decided the USA is best strengthened by having a reliable internet which business rival nations can't just read like the morning's news. The NSA knows the problems in crypto and their suggestions make it stronger against attacks we don't know. Trust t…

    So now every single decision that was taken with help
    from the NSA (SELinux, TLS, elliptic curves, etc) needs
    unpicking and running by a cryptographer who isn't a
    shill.
Cryptographers have already been looking very carefully at everything that comes out of the NSA. Lots of security researchers, in and out of the US, would love to find NSA-introduced flaws.

Re: N.S.A. Foils Much Internet Encryption

#225

This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability. The issue to me has always been how and what data they access and store, and how it is used.

We cannot rely on them to be always good so we have to also have the prior, encryption to protect us if the law or law makers are not working for our best interest.

Re: N.S.A. Foils Much Internet Encryption

#227

I feel like these kinds of articles are meant to induce a sense of hopelessness regarding the ability to push back against the NSA. If it turns out one way functions actually don't exist, I'll give in and learn to love big brother. Withstanding that, I'll continue considering communications freedom (and all that it implies) as our manifest right and view these types of breaks as implementation errors.

You mean ability to push back _technologically_ against the NSA, right? This sort of article makes you think you can't beat the NSA tech, they will outsmart you. What this sort of article does to me (unlike you, I make no claims to know what the article was 'meant' to do, other than report the news) is make it clear that we need to push back against the NSA _politically_ to win, make what they are doing illegal, chan…

The problem is technological, as deficiencies in relied-upon communication technologies is what have allowed surveillance to scale from human intelligence on prioritized targets to dragnet scrutiny of everybody. No matter how much effort is required, "law enforcement" will always be snooping on some suspects - what we'd like to prevent is an institutionalized fishing expedition.

You're signing up for a losing game. The myth of Democracy (tm) is another layer of control over individuals.

1. Most people will never have a problem with what the NSA is doing. They support the NSA's goals (tautology, since as you've mentioned, it is responsible to the majority), and if its methods end up causing harm to enough people, they will simply be adjusted to reduce aggregate harm (not to rule out any possible harm). The feedback loop of democracy works on specific actualities, not hypothetical corner cases.

2. The most memetically fit ideas are the simplest ones that elicit the strongest feelings (see: bikeshedding). Outrage peddlers swamp the political reception bandwidth with lowest common denominator controversy - usually judgments on other's lifestyles.

3. Even if there is a widespread preference to reduce the scope of the NSA, the people simply do not have the transmit bandwidth to make this preference clearly known. And they are easily led into squandering their input on the aforementioned manufactured controversy.

4. Elected figures don't actually run the government, the entrenched bureaucracy does at an imperceptible glacial pace. The elected figures run interference by making the majority believe they voted for this shit.

Re: N.S.A. Foils Much Internet Encryption

#228
post #188

Earlier quoted context omitted.

Even without naming the companies involved, it's very hard to imagine they are inserting backdoors in less-valued products while somehow missing the crown jewels of Windows and TPM.

I keep finding myself in the awkward position of trying to refute conspiracy theories, but not being at liberty to share everything I know about these scenarios (I really need to work somewhere besides DC), so I'll tread lightly. Taking for granted that the NSA actually backdoored TPM's (which I can assert professionally is very unlikely, but I don't expect anyone to take my word for it), they are far from "crown jew…

Disagree. Over the medium term, TPMs (which message board geeks have been unhelpfully demonizing for years) are part of a system of technologies that could make laptop encryption much harder to break. Laptop encryption is a real operational challenge for both HUMINT and law enforcement.

Re: N.S.A. Foils Much Internet Encryption

#229

Earlier quoted context omitted.

Is it harder to sneak in junk in open source projects? I'm reminded of Ken Thompson's Turing Award lecture, "Reflections on Trusting Trust". http://cm.bell-labs.com/who/ken/trust.html Could someone add a backdoor to git that hides backdoors from showing up in git? Could gcc be backdoored to add backdoors to arbitrary software? How likely is it that NSA has a few zero-days lying around they could use to hack into the…

There are countermeasures concerning the Trusting Trust attack: http://www.schneier.com/blog/archives/2006/01/countering_tru... , though I'm not sure if anyone has ever seriously attempted to deploy them.

I have given some thought to this kind of thing, and one thing I realized is that the limits of the trusting trust attack can be exploited as well. Let's support you only have one compiler. Now, it is going to try to insert the worm into any compiler it compiles, right? The problem is that it must be able to detect that it is actually compiling a compiler.

This, however, is not a decidable problem. It is possible to construct a program that will fool the worm and thus you can create a compiler that you know you can trust for this test. It will probably be a hard compiler to use, but you will need it at most twice -- once to check for an attack, and if there is an attack once more to bootstrap a clean compiler.

Re: N.S.A. Foils Much Internet Encryption

#230
post #71

Earlier quoted context omitted.

That's a false sense of security. You can inspect every line of code in SSL but unless you are a world-class cryptographer yourself, how will you spot a backdoor in the algorithm ?

Can we combine multiple algorithms such that having any one of them be secure is safe? For example, instead of encrypting with just RSA, do one pass with RSA and then another pass with ECC. Instead of just using AES, do one pass with AES, another pass with Twofish, and a third pass with RC4. Does that actually help?

You can do this but it will probably make it less secure, not more.

Nobody seems to know if the NSA actually has practical attacks against primitives like AES or SHA-2. We do know for sure that they go after higher level implementation flaws. The more complex your encryption scheme is, the more likely it is that you'll introduce a grave flaw. It only takes one.

I'd suggest that our best bet already exists: NaCl[1]. It's by Daniel Fucking Bernstein, so the implementation is as flawless as it gets. Better yet, it doesn't use a single US-approved primitive (not even the NIST curves Schneier was warning against in his Guardian piece).

Funnily, before the leaks Bernstein's use of all his own primitives was seen as a bit wacky and concerning, but now it seems almost sensible.

[1]: http://nacl.cr.yp.to

Post reply on HN