Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

321–330 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#321
post #198

Earlier quoted context omitted.

Was that really a seriously considered plan? I don't see how that would ever be a suitable /dev/random replacement. Obviously it works for /dev/urandom, but it should be added to the entropy pool for /dev/random at most.

Matt Mackall, the former maintainer of /dev/random, actually stepped down over this issue, because Linus overrode Matt and applied Intel's patch that used their hardware random number generator directly: http://comments.gmane.org/gmane.comp.security.cryptography.r... > It's worth noting that the maintainer of record (me) for the Linux RNG quit the project about two years ago precisely because Linus decided to include…

Sounds like Linus has some explaining to do...

Re: N.S.A. Foils Much Internet Encryption

#322
post #68

This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…

In this pdf[1] , they discuss security issues in intel chips.They mention strange responses from intel. Also it's possible, but very hard to exploit those issues , which is optimal in this case. 1[] http://pavlinux.ru/jr/Software_Attacks_on_Intel_VT-d.pdf

Forgive me if I don't open a PDF from a .ru domain. (and yes, I know how silly that response is)

Re: N.S.A. Foils Much Internet Encryption

#323
post #270

Earlier quoted context omitted.

I am confused. When I see HN or facebook certs they show 128 bit encryption in the browser box. 128 bit seems pretty low.

Probably AES, not RSA. IIRC a 128-bit AES key is about equivalent in security to a 2048-bit RSA key.

2048 bit RSA is usually described as roughly equivalent in security margin to a 112 bit symmetric key, and 3072 bit RSA to be 128 bit symmetric equivalent.

Re: N.S.A. Foils Much Internet Encryption

#324
post #7
post #5

Normal people don't need 256-bit symmetric encryption. That's assault encryption and should only be used on the battlefield. 40-bits is enough and anything over that should be banned. I'm only joking, but the same argument is used against other technologies that governments seek to control/dominate. Edit: Skipjack was 80-bits I think. It was used in Clipper Phones: http://en.wikipedia.org/wiki/Skipjack_(cipher)

The funny thing is 56-bit encryption is still in use in the form of PPTP with MS-CHAPv2. I bet most of the decrypted VPN traffic mentioned in the article uses that.

Yep, I'm ashamed I didn't make the connection last week when I signed up for a PPTP VPN. They've been broken for a while now.

Re: N.S.A. Foils Much Internet Encryption

#325

Earlier quoted context omitted.

This is almost definitely not "one of the vulnerabilities" implicated in the story today, because nobody uses CSPRNGs based on Elliptic Curve.

A RNG that is reducible to a different believed-hard problem has possible features, so it's not like there could never be a reason for someone to choose this generator. What we could be seeing is the discovery of one failed attempt of a shotgun approach to promulgate insecure primitives. It's hard to know what will happen to become commercially successful, so spray and pray. Something this blatant does seem like a se…

> A RNG that is reducible to a different believed-hard problem has possible features

I think you got it backwards... shouldn't you reduce hard problems down to the problem whose difficulty you're trying to understand?

Re: N.S.A. Foils Much Internet Encryption

#326
post #176

Earlier quoted context omitted.

Sure. I think we agree. If "it" is a crypto weakness they are actually exploiting, "it" is not Dual-EC DRBG.

Ah, yes, I wasn't trying to say they were exploiting that particular vulnerability. Just that we now have better evidence that that really was a (rather poor) attempt to subvert standards to make them easier to decrypt. The NSA seems to be really divided between SIGINT and COMSEC. COMSEC wants to provide good, strong encryption, that can help secure US government and corporate communication. SIGINT wants to be able t…

As you may well know, the NSA has its own ciphers (Suite A) it uses for top secret classified traffic, which to me is positive proof you can't trust anything they recommend (AES) - when they don't even use it themselves.

Re: N.S.A. Foils Much Internet Encryption

#327
post #68

This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…

I would not be at all surprised to learn that the major advance these disclosures refer to is an on-demand RSA-1024 factoring capability. RSA-1024 is already known to be unsafe (Eran Tromer estimates a 7 figure cost for a dedicated hardware cracker, which is approximately the threshold DES was at in the late '90s, when nobody believed DES was secure). On-demand offline RSA-1024 attacks would have major implications,…

That makes sense. I think it unlikely they've discovered an actual break through. They do have their own fab, how many chips do you need to build to Mae that worthwhile? It's the US government after all, a machine with 10million specialized RSA chips doesn't seem impossibly difficult, just expensive.

Re: N.S.A. Foils Much Internet Encryption

#328

Earlier quoted context omitted.

A RNG that is reducible to a different believed-hard problem has possible features, so it's not like there could never be a reason for someone to choose this generator. What we could be seeing is the discovery of one failed attempt of a shotgun approach to promulgate insecure primitives. It's hard to know what will happen to become commercially successful, so spray and pray. Something this blatant does seem like a se…

> A RNG that is reducible to a different believed-hard problem has possible features I think you got it backwards... shouldn't you reduce hard problems down to the problem whose difficulty you're trying to understand?

Yep, I misspoke. I simply meant 'is based on', and shouldn't have used big words so cavalierly.

Re: N.S.A. Foils Much Internet Encryption

#329

Earlier quoted context omitted.

I would not be at all surprised to learn that the major advance these disclosures refer to is an on-demand RSA-1024 factoring capability. RSA-1024 is already known to be unsafe (Eran Tromer estimates a 7 figure cost for a dedicated hardware cracker, which is approximately the threshold DES was at in the late '90s, when nobody believed DES was secure). On-demand offline RSA-1024 attacks would have major implications,…

That makes sense. I think it unlikely they've discovered an actual break through. They do have their own fab, how many chips do you need to build to Mae that worthwhile? It's the US government after all, a machine with 10million specialized RSA chips doesn't seem impossibly difficult, just expensive.

Governments are big, dumb animals, so make whatever you're trying to protect very expensive ($20-50 Billion range) to brute-force within usability constraints.

Btw... apart from Scrypt paper, has anyone put together a practical guide on crypto parameter brute force costs? (say volume pricing of gear and asics in huge qty)

Re: N.S.A. Foils Much Internet Encryption

#330

Up until very recently, the received wisdom was: the crypto wars are over, we fought the law and the law gave up, the NSA has quit trying to crack encryption, they have decided the USA is best strengthened by having a reliable internet which business rival nations can't just read like the morning's news. The NSA knows the problems in crypto and their suggestions make it stronger against attacks we don't know. Trust t…

>they inevitably leak (roll save against ethics how many times?)

Haha, nicely put. Note too that sooo many "roll save against temptation" must happen to avoid abuses of the NSA capabilities.

Post reply on HN