Live data from Hacker News

The NSA's crypto "breakthrough"

economist.com

31–40 of 101 posts

Re: The NSA's crypto "breakthrough"

#31
post #9

Breaking public-key crypto would have to be the biggest coup in SIGINT in the history of ever . Much bigger than cracking the Enigma. Just thinking about the sheer volume of internet traffic at every level and in every country that relies on the security of encryption makes the possibility of it being fundamentally broken a literal nightmare. I don't think it has happened. But if it had , that would be the kind of se…

Wouldn't they start moving important web sites off of SSL then? Surely they couldn't be the only ones able to exploit if they found it. Or at least, if they found it, others could theoretically as well.

Re: The NSA's crypto "breakthrough"

#32
post #31
post #9

Breaking public-key crypto would have to be the biggest coup in SIGINT in the history of ever . Much bigger than cracking the Enigma. Just thinking about the sheer volume of internet traffic at every level and in every country that relies on the security of encryption makes the possibility of it being fundamentally broken a literal nightmare. I don't think it has happened. But if it had , that would be the kind of se…

Wouldn't they start moving important web sites off of SSL then? Surely they couldn't be the only ones able to exploit if they found it. Or at least, if they found it, others could theoretically as well.

Can't imagine the NSA or any agency puts anything too important on the Web in the first place.

Re: The NSA's crypto "breakthrough"

#33
post #2

Sounds like we need a couple more Snowden's to come out from NSA.

Why? Because the government doesn't deserve to have any secret programs whatsoever? I've said it before and I'll say it again: Even if leaking XKeyscore and PRISM was morally justified, leaking the intelligence budget or leaking other programs is probably unwise. Remember that when we talk about leaking, we're talking about weakening the American government. We should at least think about the implications.

Leaking the intelligence budget was probably the most justified leak. Even if you want a geopolitically strong American government, the intelligence budget tells the public how much effort the USG puts into covert programs. So without it you can not have a meaningful debate about the size of the intelligence agencies. But on the other hand, I do not believe that other agencies can infer much from it, since everybody already knows that there is a quite big budget. So even in a real politics interpretation, the budget tells other intelligence agencies, how nice the chess board is, not what strategy is played.

Re: The NSA's crypto "breakthrough"

#34
post #12
post #5

One of the "nice" things about the NSA: they rely on pretty standard crypto--the same kind the rest of us do!--for their less sensitive, but still classified, secrets. NSA Ciphersuite B ( http://en.m.wikipedia.org/wiki/NSA_Suite_B_Cryptography ) is built into a lot of gov/mil communications technology. And it's just RSA, ECDHE, and so on--all that same stuff available in TLS. In other words: if the NSA break one of t…

Suite B does not contain RSA. EDIT: To your latter point, some people would consider this to be a telling fact.

It's telling that RSA is not practical to deploy at 256-bit security today.

Re: The NSA's crypto "breakthrough"

#35
post #15
post #3

The Economist: > Does the NSA have a quantum computer in the basement of its headquarters in Maryland (pictured above)? It is theoretically possible, but pretty unlikely... A Canadian firm called D-Wave is presently selling a specialised kind of quantum computer—Lockheed Martin, an American defence giant, and Google have each bought one—but it is not suitable for this kind of work. In-Q-Tel - "About Us" > "We make in…

The most advanced math a quantum computer has done to date is "factored 21 into 3×7, with high probability (Martín-López et al. 2012)." Remember: companies are in the game of marketing hype to ride your scifi hopes and dreams. When you see a company saying "quantum" anything, discount their unqualified claims greatly. (Investors are not immune to being manipulated by hype. Claiming "they must be good because they hav…

> a hobo claiming he keeps the airplane aloft by snapping his fingers every 3.2 seconds Interesting comparison :p Sounds like it might be rooted in personal experience. Is it?

Re: The NSA's crypto "breakthrough"

#36
post #5

One of the "nice" things about the NSA: they rely on pretty standard crypto--the same kind the rest of us do!--for their less sensitive, but still classified, secrets. NSA Ciphersuite B ( http://en.m.wikipedia.org/wiki/NSA_Suite_B_Cryptography ) is built into a lot of gov/mil communications technology. And it's just RSA, ECDHE, and so on--all that same stuff available in TLS. In other words: if the NSA break one of t…

What I find really interesting about the NSA is their Suite A: classified algorithms (!) used to protect the most sensitive documents (!!) with hilariously bad security records (!!!).

Take for instance the Skipjack cipher (https://en.wikipedia.org/wiki/Skipjack_(cipher)), a Type I cipher ("endorsed by the NSA for securing classified and sensitive U.S. Government information") which was evaluated, for the purpose of security, by "some of the world's most accomplished and famous experts in combinatorics and abstract algebra", and finally declassified due to concerns expressed by other cryptographers about its security.

Biham and Shamir broke it the day after it was declassified.

Re: The NSA's crypto "breakthrough"

#38
post #19
post #12

Earlier quoted context omitted.

Suite B does not contain RSA. EDIT: To your latter point, some people would consider this to be a telling fact.

Or non-EC DH, either. (It does include ECDH.) Perhaps they were simply anticipating DLP progress and wanted to be future-proof?

It's more likely because you can't achieve modern security levels with cryptosystems built on the DLP or IFP at acceptable performance.

Suite B aims for 128-bit or 192-bit security levels; for comparison 1024-bit modulus RSA is currently thought to provide 73-bit security.

(The next natural question is why the internet community is still failing to widely deploy cryptosystems with appropriate security levels. I don't know. But HTTPS, OTR and DNSSEC are all built of cheese in this respect.)

Re: The NSA's crypto "breakthrough"

#39
post #23
post #9

Breaking public-key crypto would have to be the biggest coup in SIGINT in the history of ever . Much bigger than cracking the Enigma. Just thinking about the sheer volume of internet traffic at every level and in every country that relies on the security of encryption makes the possibility of it being fundamentally broken a literal nightmare. I don't think it has happened. But if it had , that would be the kind of se…

Well, it would be a very well guarded secret. But even then the question is how public key crypto is broken. If they can easily generate exploits for implementations, because they know a essential implementation detail everybody else is missing, then it would be fundamentally different from being able to break RSA directly, or if they have a constructive prove of P=NP.

[deleted]

Re: The NSA's crypto "breakthrough"

#40
post #21
post #5

One of the "nice" things about the NSA: they rely on pretty standard crypto--the same kind the rest of us do!--for their less sensitive, but still classified, secrets. NSA Ciphersuite B ( http://en.m.wikipedia.org/wiki/NSA_Suite_B_Cryptography ) is built into a lot of gov/mil communications technology. And it's just RSA, ECDHE, and so on--all that same stuff available in TLS. In other words: if the NSA break one of t…

I'm not sure if this would be true. It's a game theory problem, surely. I'm not especially crypto-literate, but if player A has the ability to read the majority of currently encrypted comms world-wide, broadcasting that ability (by suddenly and dramatically changing their own encryption methodologies) would be a very silly move unless there was a very serious reason to believe somebody else was very close to developi…

I also think that since this would be exploited against non-state actors as well as states changes the payouts calculations significantly. Much, if not most, of the value is derived from exploiting non-state actors (i.e. Al Qaeda) who almost certainly would not have this capability or would not be able to keep it quite if they did. By signaling to the state actor on these capabilities, they would be giving up the value of exploiting the information from the non-state actors. So, even if you believed that state actors had these capabilities, it may be better to be kept a secret between the two countries and allow low priority secrets to be exploited than to have the info publicly known and the capability lost.
Post reply on HN