This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…
N.S.A. Foils Much Internet Encryption
271–280 of 395 posts
Re: N.S.A. Foils Much Internet Encryption
#272Earlier quoted context omitted.
Yeah, I'm a little baffled by Schneier's reaction to this. The revelation is advanced cryptanalytic capabilities at NSA, which is literally an article of faith with Schneier. Why is he freaking out about this when he didn't instead freak out about wholesale call record database dumps or AT&T fiber taps?
I think there is a fundamental difference advanced Cryptanalysis (which we always assumed they had due to hiring practices and history) and being able to break crypto by subverting infrastructure. If the NSA said, "Our super smart brain trust figured out how to own your stuff with math five years ago ... ha ha!", I think we would be Totally Fine with that. Hats off to them for winning that game, but at least they pla…
I disagree. Certainly they'll be doing that too, but breaking crypto is hazardous to the populace independently of how it's broken, right?
Either way from NSA's perspective they are fighting a war, with terrorism, with other nation's crypto efforts, etc. In that context there are very few "unfair" ways to fight. And indeed, the U.S. has done something like this to a certain Soviet pipeline, as I recall.
Besides, this at least leaves open the possibility of like-minded people to maintain countermeasures. If crypto is broken in general then we're all naked. If weak implementations are weak then we would need to be fixing those anyways.
I just wish I knew which one it is we're looking at.
Re: N.S.A. Foils Much Internet Encryption
#273Earlier quoted context omitted.
Yeah, I'm a little baffled by Schneier's reaction to this. The revelation is advanced cryptanalytic capabilities at NSA, which is literally an article of faith with Schneier. Why is he freaking out about this when he didn't instead freak out about wholesale call record database dumps or AT&T fiber taps?
I think there is a fundamental difference advanced Cryptanalysis (which we always assumed they had due to hiring practices and history) and being able to break crypto by subverting infrastructure. If the NSA said, "Our super smart brain trust figured out how to own your stuff with math five years ago ... ha ha!", I think we would be Totally Fine with that. Hats off to them for winning that game, but at least they pla…
Re: N.S.A. Foils Much Internet Encryption
#274Earlier quoted context omitted.
Yeah, I'm a little baffled by Schneier's reaction to this. The revelation is advanced cryptanalytic capabilities at NSA, which is literally an article of faith with Schneier. Why is he freaking out about this when he didn't instead freak out about wholesale call record database dumps or AT&T fiber taps?
I think there is a fundamental difference advanced Cryptanalysis (which we always assumed they had due to hiring practices and history) and being able to break crypto by subverting infrastructure. If the NSA said, "Our super smart brain trust figured out how to own your stuff with math five years ago ... ha ha!", I think we would be Totally Fine with that. Hats off to them for winning that game, but at least they pla…
Re: N.S.A. Foils Much Internet Encryption
#275You can't have read Applied Cryptography from the mid-90s and not understand this to have been NSA's M.O. from the jump. Bruce Scheier, who was quoted in the Guardian piece about the same story, is America's foremost popularizer of the notion of NSA as crypto's global passive adversary. People who build real cryptosystems have never, ever been allowed to rely on the goodwill of the NSA not to cryptanalyze their syste…
Can you expand a bit on chrome's anti-surveilance capabilities?
Re: N.S.A. Foils Much Internet Encryption
#276Earlier quoted context omitted.
Yeah, I'm a little baffled by Schneier's reaction to this. The revelation is advanced cryptanalytic capabilities at NSA, which is literally an article of faith with Schneier. Why is he freaking out about this when he didn't instead freak out about wholesale call record database dumps or AT&T fiber taps?
This is not just about cryptanalysis. The NSA has been deliberately introducing weaknesses into cryptosystems used by the general public. That is beyond keeping cryptanalysis techniques secret, which we all assumed they would do and which few really drew any issue with. We are talking about an honest-to-goodness conspiracy , one that yesterday many would have written off as a conspiracy theory that was not even worth…
Er...speak for yourself buddy. If you thought that you could get proper crypto security from a boxed software product then I'd like to offer you a fantastic deal on a bridge.
Re: N.S.A. Foils Much Internet Encryption
#277Earlier quoted context omitted.
I think we know very well which encryption has been foiled by the NSA. This is not speculation, but quasi-certainty: 1024-bit RSA. - Crytographers all acknowledge 1024-bit RSA is dead [1]. - Attack cost 10 years ago was estimated to be a few million USD to build a device able to crack a 1024-bit key every 12 months [2]. - "Much of" the "secure" HTTPS websites use such weak key sizes [3]. - NSA had a budget of 10.8 bi…
I am confused. When I see HN or facebook certs they show 128 bit encryption in the browser box. 128 bit seems pretty low.
Re: N.S.A. Foils Much Internet Encryption
#278Earlier quoted context omitted.
That security systems are designed in the most paranoid fashion possible doesn't tell you anything about the real nature of the threat. Schneier's book doesn't tell you that the NSA has been strong arming corporations into giving up their private keys and into installing backdoors on chips. In fact Schneier himself is outraged to the point that he seems to be calling for a redesign of basic Internet protocols and gov…
Yeah, I'm a little baffled by Schneier's reaction to this. The revelation is advanced cryptanalytic capabilities at NSA, which is literally an article of faith with Schneier. Why is he freaking out about this when he didn't instead freak out about wholesale call record database dumps or AT&T fiber taps?
Re: N.S.A. Foils Much Internet Encryption
#279Up until very recently, the received wisdom was: the crypto wars are over, we fought the law and the law gave up, the NSA has quit trying to crack encryption, they have decided the USA is best strengthened by having a reliable internet which business rival nations can't just read like the morning's news. The NSA knows the problems in crypto and their suggestions make it stronger against attacks we don't know. Trust t…
So now every single decision that was taken with help from the NSA (SELinux, TLS, elliptic curves, etc) needs unpicking and running by a cryptographer who isn't a shill. Cryptographers have already been looking very carefully at everything that comes out of the NSA. Lots of security researchers, in and out of the US, would love to find NSA-introduced flaws.
Re: N.S.A. Foils Much Internet Encryption
#280Earlier quoted context omitted.
I think there is a fundamental difference advanced Cryptanalysis (which we always assumed they had due to hiring practices and history) and being able to break crypto by subverting infrastructure. If the NSA said, "Our super smart brain trust figured out how to own your stuff with math five years ago ... ha ha!", I think we would be Totally Fine with that. Hats off to them for winning that game, but at least they pla…
I would be keeping my hat on. They would have done it with the taxpayers' money but without their consent or even knowledge. They would then be withholding a major scientific breakthrough from the public that financed it. A scientific breakthrough that might have all sorts of applications that could make our lives better. They would be exposing all the people that rely in strong cryptography to major risks. Including…