Live data from Hacker News

Intel In Bed with NSA?

cryptome.org

31–40 of 73 posts

Re: Intel In Bed with NSA?

#31
post #18

Earlier quoted context omitted.

'I speculate that Rijndael is easier to brute force' On what basis?

Well, I guess Rijndael is "easier" to brute force in that it's faster than Twofish. But "easier" to brute force doesn't mean a whole lot; AES-192 is easier to brute force than AES-256, but both are so outside the realm of current-day computation than it doesn't really matter.

Just as a matter of interest, re: the new bitcoin boxes like the butterfly http://arstechnica.com/gadgets/2013/06/how-a-total-n00b-mine...

Do these put a different slant on the whole "current-day computation" angle? Not necessarily these machines, but isn't it feasible that custom hardware could be manufactured using current tech, that upsets the notion of AES brute force feasibility?

Edit:

No. https://bitcointalk.org/index.php?topic=121264.0

Re: Intel In Bed with NSA?

#32
post #3

It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated: > Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there'd be no risk of it causing a s tstorm…

> It is really, really hard for me to see this as anything other than utter paranoia.

It is really really hard for me to imagine Intel not beeing 100% cooperative with the NSA.

Re: Intel In Bed with NSA?

#33
post #29

It's safe to assume every core technology company has been compelled to be in bed with the NSA in some form or another. Intel has been anti-trust managed by the government for nearly two decades. Getting access to the monopoly desktop / laptop processor maker would be far too rich a target to ignore.

This is why I show preference towards AMD chips even when they have the competitive disadvantage. Any sufficiently large company ends up, through their will or the gov'ts, wrapped up in politics. Which is the one of the larger issues of our age.

AMD is probably cooperating with the government on the same level as Intel.

Re: Intel In Bed with NSA?

#35
post #22

Earlier quoted context omitted.

Well, it is documented that the NSA made DES weaker by using less bits for key size (this makes brute forcing easier). I aslo noted that Schiener's AES submission was passed over (I speculate that Rijndael is easier to brute force). The feds used to fight civilian crypto tooth and nail. Then they allowed it, and in one of the crypto books a story was related that the feds were bummed about RSA and friends. The listen…

> The feds used to fight civilian crypto tooth and nail. Curious. I'd like to read about this. Can anyone post any links?

Just do a search for Phil Zimmermann and what they did to him in the 90's for having the audacity to create PGP.

Re: Intel In Bed with NSA?

#36
post #3

It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated: > Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there'd be no risk of it causing a s tstorm…

> It is really, really hard for me to see this as anything other than utter paranoia. It is really really hard for me to imagine Intel not beeing 100% cooperative with the NSA.

You know who else cooperates with the NSA? The Linux community. You know, that whole "SELinux" thing? Yeah, that's an NSA project.

Turns out cooperating with the NSA doesn't automatically mean spying on the public, it could instead be hardening crypto security. Which is the NSA's other job, it turns out.

Re: Intel In Bed with NSA?

#37
post #14

Would appreciate some sort of a summary. Reading some mile long email exchange just to figure out what the headline is really about makes it kinda tricky.

I read the whole thing, but few here would truly feel that my summary of 'paranoia. paranoia everywhere' is not a government plant.

The core concern seems to be the idea that an RNG embedded into Intel's latest kit might actually be a PRNG that could be backdoored by NSA on command somehow with resultant catastrophic effects to crypto primitives on that box, if the Intel RNG were the only source of entropy on the box.

Re: Intel In Bed with NSA?

#38
If the NSA is working with Intel, they're not going to bother with an RNG... The processor is the most trusted part of the computer security model - why would you choose bad random numbers as your attack vector?

Relevant talk: Hardware Backdooring is Practical - Jonathan Brossard https://www.youtube.com/watch?v=j9Fw8jwG07g

Re: Intel In Bed with NSA?

#39
This issue just does not pass the rubber hose test. If the NSA wanted and got a backdoor in intel chips there are so many better ways to do it than introducing a bad hw rng. If you wanted one exploit in the chip, why would you pick a hard to exploit one and user controlled one on top of that? It's classic paranoid thinking: People have a choice to use the hw rng or not. So it becomes a big deal. All the while not addressing the non-choice issue like having a potential backdoor triggered by a specific instruction sequence.

Re: Intel In Bed with NSA?

#40

Earlier quoted context omitted.

> It is really, really hard for me to see this as anything other than utter paranoia. It is really really hard for me to imagine Intel not beeing 100% cooperative with the NSA.

You know who else cooperates with the NSA? The Linux community. You know, that whole "SELinux" thing? Yeah, that's an NSA project. Turns out cooperating with the NSA doesn't automatically mean spying on the public, it could instead be hardening crypto security. Which is the NSA's other job, it turns out.

I assume he means "cooperating with NSA in nefarious ways if the NSA wanted".
Post reply on HN