Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

31–40 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#31
It always seemed likely to me that governments can generate fake trusted certs for browser TLS traffic and then man in the middle the traffic, but what are the likely modes of attack otherwise? I don't really see what they are from this article - do they have a database of keys they have acquired nefariously?

Re: N.S.A. Foils Much Internet Encryption

#32

Can someone who actually knows about encryption comment on whether it's actually physically feasible for the NSA to have actually broken, say, SSL 3.0 (which has 128 bits of entropy, IIRC) on a large scale (i.e., when you're sifting through petabytes of data on a daily basis)? And if this were really an issue, couldn't you just use 4096-bit RSA (unless they have managed to surreptitiously insert a backdoor in it)?

SSL relies on a chain of trust, and it's prudent to assume that the NSA has the private keys necessary to produce valid certificates that will be accepted by the certificates that ship with Windows, OS X, Firefox, etc out of the box.

So man-in-the-middle attacks are certainly within their capability and fairly hard to detect. As to whether the NSA can passively intercept and decrypt SSL traffic, I don't know, but they may not need to.

Re: N.S.A. Foils Much Internet Encryption

#33
post #24

Earlier quoted context omitted.

People don't take a 256-bit cryptoalgorithm into a middle school and kill kids with it, so I don't think the analogy works exactly. Maybe if you print it out on paper, or use a floppy disk or CD, you could cut a few people.

People who intend to enter a middle school and kill kids can hide their plans and communications using 256-bit encryption. Edit: Devil's advocate.

Or they could be loners or they could meet and communicate face to face.

Re: N.S.A. Foils Much Internet Encryption

#34
post #5

Normal people don't need 256-bit symmetric encryption. That's assault encryption and should only be used on the battlefield. 40-bits is enough and anything over that should be banned. I'm only joking, but the same argument is used against other technologies that governments seek to control/dominate. Edit: Skipjack was 80-bits I think. It was used in Clipper Phones: http://en.wikipedia.org/wiki/Skipjack_(cipher)

People don't take a 256-bit cryptoalgorithm into a middle school and kill kids with it, so I don't think the analogy works exactly. Maybe if you print it out on paper, or use a floppy disk or CD, you could cut a few people.

It is used to aid in the creation and distribution of child pornography, so the analogy is exact - unless of course you don't view the molestation of those middle schoolers to be an attack on them (as the downvotes seem to indicate).

Re: N.S.A. Foils Much Internet Encryption

#36

This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability. The issue to me has always been how and what data they access and store, and how it is used.

> I have no problem with the NSA being able to break encryption, that's in fact part of their job.

Their "breaking" of encryption is a combination of purposefully introducing vulnerabilities into standards, surreptitiously altering software and hardware to give the NSA a backdoor, hacking into private systems and stealing keys, etc etc.

I'm cool with an NSA super computer trying to brute force my VPN traffic to YouTube, I'm not cool with the NSA planting an engineer at a chip fab and changing designs to add a backdoor (a backdoor that could also be exploited by other actors).

Re: N.S.A. Foils Much Internet Encryption

#37
post #5

Normal people don't need 256-bit symmetric encryption. That's assault encryption and should only be used on the battlefield. 40-bits is enough and anything over that should be banned. I'm only joking, but the same argument is used against other technologies that governments seek to control/dominate. Edit: Skipjack was 80-bits I think. It was used in Clipper Phones: http://en.wikipedia.org/wiki/Skipjack_(cipher)

People don't take a 256-bit cryptoalgorithm into a middle school and kill kids with it, so I don't think the analogy works exactly. Maybe if you print it out on paper, or use a floppy disk or CD, you could cut a few people.

Another difference: You don't need a gun to perform the most basic of functions securely.

They occupy exactly opposite quadrants on the useful/dangerous axis.

Re: N.S.A. Foils Much Internet Encryption

#38
post #13

This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability. The issue to me has always been how and what data they access and store, and how it is used.

I guess I'm with you on the ability to crack. Any researcher should be able to try as hard as they want, and succeed. I draw the line at collecting everything without specific warrants, regardless of what they do with it, against their charter and the Constitution. I draw the line at hardware backdoors for equipment that I buy, and insertion of vulnerabilities into encryption standards that I take advantage of. Or I…

I'd agree with that. I've often been wondering if where we're headed is a some kind of reform compromise. Not that I think it's ideal or right, but for example I could see the NSA having a Chinese wall around data for Americans, such that FBI and other investigators could not use data collected by the NSA, but could open their own collections with a warrant.

I'm quite opposed to what the NSA has done - but I don't see anything happening that will change it. If the recent revelations haven't done anything to stir Congress to action I don't know what will. Additionally, until and/or unless the NSA ever uses data collected this way against an American citizen in a judicial/criminal way, the courts are quite likely to find that petitioners lack any standing.

Re: N.S.A. Foils Much Internet Encryption

#40
post #16
post #9

The N.S.A. hacked into target computers to snare messages before they were encrypted. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world. This is mostly a confirmation of what has been supposed: No magic, mostly bribed and coerced cooperation from the people who should…

So, should we re-evaluate if Intel/AMD's chips (and possibly even the new ARM ones) contain hardware backdoors for the NSA?

I would assume the NSA has evaluated every plausible attack, and implemented them based on what they want to get out of it, and that they have global reach into chips, peripherals, and software.

If you are a foreign government, hostile or friendly, I don't see much of a case to made for "Naw, they wouldn't..." They would, they probably can, and the probably already did.

If you are a consumer, the main problem is the creepiness factor. Who wants to use incrementally more technology if along with it you get incrementally more surveillance?

Post reply on HN