Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

231–240 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#231
post #188

Earlier quoted context omitted.

Even without naming the companies involved, it's very hard to imagine they are inserting backdoors in less-valued products while somehow missing the crown jewels of Windows and TPM.

I keep finding myself in the awkward position of trying to refute conspiracy theories, but not being at liberty to share everything I know about these scenarios (I really need to work somewhere besides DC), so I'll tread lightly. Taking for granted that the NSA actually backdoored TPM's (which I can assert professionally is very unlikely, but I don't expect anyone to take my word for it), they are far from "crown jew…

"I keep finding myself in the awkward position of trying to refute conspiracy theories, but not being at liberty to share everything I know about these scenarios"

There are things I want to say about that sort of thinking, but I am afraid to say them. What a wonderful world...

Re: N.S.A. Foils Much Internet Encryption

#232
post #190

Earlier quoted context omitted.

> but not so far that our adversaries can. Please clarify what you mean by "our". Please clarify what you mean by "adversaries".

Come now, we know enough about the NSA at this point to know that our, adversaries = America, !America right?

The NSA are "our" adversaries.

Re: N.S.A. Foils Much Internet Encryption

#233
post #131

> A 2010 document calls for “a new approach for opportunistic decryption, rather than targeted.” By that year, a Bullrun briefing document claims that the agency had developed “groundbreaking capabilities” against encrypted Web chats and phone calls. Its successes against Secure Sockets Layer and virtual private networks were gaining momentum. This paragraph interests me the most. For one, it's clear that their goal…

    (it's hard to install new gigabit fiber pipes to siphon
    off the data without anyone noticing)
If you have access to manufacturers that can put in back doors for you, I reckon you don't even need your mole to install stuff for you. Instead you just ask your mole to inform you want is going to be installed and then make sure that the company gets backdoored systems when hardware is installed/upgraded/replaced.

I'm wondering is datacenter monitoring utilities like the stuff Boundary[0] is working on could be used to identify anomalies in how network hardware is behaving versus how it should be behaving. I know that in my conversations with cliff, they are trying to get their monitoring solution to the point where they can visualize "the circulatory system" of a data system with the goal of spotting things that don't look quite right.

[0] http://boundary.com/

Re: N.S.A. Foils Much Internet Encryption

#234

Earlier quoted context omitted.

If I was in the NSA (which I am not) I would place a backdoor in the browser themselves, and since the browsers auto-update from the internet anyway, I would change the DNS provider for the machine being watched (remember the DNS settings generally default to that provided by your ISP) to point to the NSA-version of the browser, and then the user would be browsing securely, but after decryption and before display, th…

Your machine would be showing an extra outbound connection.

Very few people have any idea how many outbound connections their machine opens or which software is opening them. There seems to be just enough people paying attention to this that it would be caught but most people would never know.

Re: N.S.A. Foils Much Internet Encryption

#235
post #70

> the Bullrun program, the successor to one called Manassas — both names of American Civil War battles. A parallel GCHQ counterencryption program is called Edgehill, named for the first battle of the English Civil War of the 17th century. Spying on your own citizens codenamed as civil war. How nice. > Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among…

Spying on your own citizens codenamed as civil war. How nice. Nowhere in the article does it state that these methods can be used against US persons separate from other protections against surveillance on US persons, nor does it give the impression that this is special to US persons: The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the del…

"The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the deliberate targeting of Americans’ e-mails or phone calls without a warrant."

Rules which are enforced internally, with an inspector general chosen by the same executive branch that commands the NSA's leadership. Yes, we can really rely on these rules when push comes to shove.

Re: N.S.A. Foils Much Internet Encryption

#236
post #212

Earlier quoted context omitted.

You realize that these are exactly the same arguments that were brought up to argue against the details revealed in these documents, so perhaps appeals to authority and use of the words 'conspiracy theories' may be taken with a few more grains of salt. NSA backdoors have been alleged for decades now, and the response is always that they're a 'conspiracy theory'.

My argument isn't that the NSA hasn't backdoored TPM's (which I freely admit I can't convince you of), it's that TPM's are not "The Crown Jewels".

TPM 2.0 is a crown jewel for the NSA. Windows 8 full-disk encryption is based on TPM, and Windows 8.1 certification requires a TPM 2.0 module. It already is or soon will be universal in PC hardware. The NSA was involved its creation, and resisted changes to the standard. At the same time the German government was claiming there were no backdoors in Windows or TPM, privately they had already concluded it was compromised.

Source: http://news.techworld.com/security/3465259/is-windows-8-a-tr...

Re: N.S.A. Foils Much Internet Encryption

#237

Earlier quoted context omitted.

This is all theoretical, but you could use decentralized services/protocols that would eliminate such an opportunity.

If I was in the NSA (which I am not) I would place a backdoor in the browser themselves, and since the browsers auto-update from the internet anyway, I would change the DNS provider for the machine being watched (remember the DNS settings generally default to that provided by your ISP) to point to the NSA-version of the browser, and then the user would be browsing securely, but after decryption and before display, th…

For a specific target? Sure, why not.

But if they did that to everyone? Surely it would be noticed. Probably very quickly. There are a LOT of smart security researchers scouring browsers for bugs and running them in carefully controlled environments every day. Someone would also eventually notice that the production binary doesn't match the version built from source, especially for open-source browsers.

Re: N.S.A. Foils Much Internet Encryption

#238
post #37

Earlier quoted context omitted.

People don't take a 256-bit cryptoalgorithm into a middle school and kill kids with it, so I don't think the analogy works exactly. Maybe if you print it out on paper, or use a floppy disk or CD, you could cut a few people.

Another difference: You don't need a gun to perform the most basic of functions securely. They occupy exactly opposite quadrants on the useful/dangerous axis.

The ability to defend one's self is a basic function. Being dangerous can be useful. Encryption is a tool for guarding privacy, and weapons are tools for guarding against physical threats.

Re: N.S.A. Foils Much Internet Encryption

#239
post #189

Speaking as an American, it's not a problem that the capability to break encryption exists and the NSA has it. It really does make national security stronger if your intelligence people can read enemy communications. The problem is that the NSA apparently used those capabilities on basically everyone , millions of innocent Americans whose activities should be of no interest to intelligence agencies, not just the hand…

A political counter-argument is that this program may represent terrible value for money in the long run. If we are in a security arms race this money neither buys weapons or a defence that can't be overcome by opponents simply buying better weapons and defences.

The NSA could have made more of an effort to harden American business and infrastructure to attack. They could have spent the money on developing intelligence sources who actually work for opponents instead of US telcos. They could have fixed zero day exploits.

We are rapidly approach a time where oponents will be able to attack completely annonymously. American infrastructure or buisness could be damanaged and know one ever know who or why. If that happens cold war tactics will seem hopelessly naive.

Re: N.S.A. Foils Much Internet Encryption

#240

Earlier quoted context omitted.

I keep finding myself in the awkward position of trying to refute conspiracy theories, but not being at liberty to share everything I know about these scenarios (I really need to work somewhere besides DC), so I'll tread lightly. Taking for granted that the NSA actually backdoored TPM's (which I can assert professionally is very unlikely, but I don't expect anyone to take my word for it), they are far from "crown jew…

Disagree. Over the medium term, TPMs (which message board geeks have been unhelpfully demonizing for years) are part of a system of technologies that could make laptop encryption much harder to break. Laptop encryption is a real operational challenge for both HUMINT and law enforcement.

That's true, but I've spent a good portion of the last year and half dealing with them and disagree on the likelihood of them ever achieving any widespread adoption. My company would love for me to be wrong about this.
Post reply on HN