Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

331–340 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#331

Earlier quoted context omitted.

I'd agree with that. I've often been wondering if where we're headed is a some kind of reform compromise. Not that I think it's ideal or right, but for example I could see the NSA having a Chinese wall around data for Americans, such that FBI and other investigators could not use data collected by the NSA, but could open their own collections with a warrant. I'm quite opposed to what the NSA has done - but I don't se…

As a non-American, I find your lack of support for people who weren't born in your little patch of land quite uninspiring.

Well I also assume that many other signals intelligence agencies are collecting data. Having worked at a time for a large global PR firm, I am sure many if not most of our communications were intercepted, especially with work once done for a Chinese based phone hardware maker. I think it would be a massive mistake to assume this is a United States only issue, so far the United States is the only country to have someone leak the information.

So - yes, my most immediate legal concern is how the US government could use the data collection against me contrary to protections given. That doesn't mean there are many more and larger concerns to be thought through, I was merely speaking to one of them.

Re: N.S.A. Foils Much Internet Encryption

#332
post #176

Earlier quoted context omitted.

Sure. I think we agree. If "it" is a crypto weakness they are actually exploiting, "it" is not Dual-EC DRBG.

Ah, yes, I wasn't trying to say they were exploiting that particular vulnerability. Just that we now have better evidence that that really was a (rather poor) attempt to subvert standards to make them easier to decrypt. The NSA seems to be really divided between SIGINT and COMSEC. COMSEC wants to provide good, strong encryption, that can help secure US government and corporate communication. SIGINT wants to be able t…

> The NSA seems to be really divided between SIGINT and COMSEC.

Anybody care to guess which group was responsible for the FUBAR that gave Snowden the keys to the kingdom?

Re: N.S.A. Foils Much Internet Encryption

#333

Up until very recently, the received wisdom was: the crypto wars are over, we fought the law and the law gave up, the NSA has quit trying to crack encryption, they have decided the USA is best strengthened by having a reliable internet which business rival nations can't just read like the morning's news. The NSA knows the problems in crypto and their suggestions make it stronger against attacks we don't know. Trust t…

Note that SELinux isn't crypto - it's code to implement mandatory access control, which is just regular bitbashing that any software engineer is completely qualified to audit.

Re: N.S.A. Foils Much Internet Encryption

#334

Earlier quoted context omitted.

>Those claims made by Greg are completely untrue. I ran the professional services group for that company and will happily attest to whomever asks that at no time did we insert a backdoor (or anything that could even be construed as such) into IPSEC. Somehow I doubt if you did that you could tell us. You might even have to lie to be able to comment on that letter at all.

I'm still unclear on the government's ability to compel falsehoods (even the discussions around National Security Letters seem to indicate that they prevent disclosure, but can't require lying), but I don't think I can convince you of that. When all the hullabaloo around the alleged IPSEC backdoor occurred, it was frustrating to not be able to be as open about it as I wanted (not because of any government/security is…

The effect of all of this is mistrust and suspicion of nearly everything. Which, compared to the alternative of implicitly trusting nearly everything, may not be a bad thing.

I'm hoping open development models(open source, peer production, peer review) end up providing the correct institutional incentives for us to innovate away the mistrust.

To misquote Linus: “given enough eyeballs, all backdoors are shallow.”

Re: N.S.A. Foils Much Internet Encryption

#335
post #85

You can't have read Applied Cryptography from the mid-90s and not understand this to have been NSA's M.O. from the jump. Bruce Scheier, who was quoted in the Guardian piece about the same story, is America's foremost popularizer of the notion of NSA as crypto's global passive adversary. People who build real cryptosystems have never, ever been allowed to rely on the goodwill of the NSA not to cryptanalyze their syste…

I agree that they are probably subverting endpoints. Nobody has mentioned it yet, but I suspect that differential power analysis plays a big role. The published attacks using DPA have been both devastating and trivial.

The allegations of widespread hardware backdoors are ludicrous. The backdoors would eventually become public, requiring the replacement of billions of dollars worth of equipment, and the several times that cost in audits. Only a spymaster with a suicidal death wish would chain his career to that. More likely is that people are misinterpreting backdoors in a few chosen endpoints, which we can take as standard operating procedure.

Re: N.S.A. Foils Much Internet Encryption

#336

Earlier quoted context omitted.

But why would you ever have assumed this? I mean, I don't really care whether something was a mistake in good faith or covert sabotage; the useful question is whether something is secure or not as far as I can tell. Assessing the motivations is a complete waste of my time as an individual.

It does matter if the NSA is actively sabotaging our cryptosystems. If people are making mistakes we can solve the problem as a community by improving the techniques we use to develop, document, and test cryptosystems. If we are dealing with people who are deliberately weakening our cryptosystems, it will be harder to push better techniques because our adversary will push back against them, or sabotage the techniques…

In my view this was true anyway, since any mistake could be the result of foolishness or malice - if not on the part of the NSA, on that of the Russian, Chinese, British, Israeli, (etc.) security services. Crypto is an arms race between people with conflicting interests, and always has been; I don't mean to be rude, but I think your former view of the way things operated was a bit naive.

Re: N.S.A. Foils Much Internet Encryption

#337
post #149
post #68

This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…

I think we know very well which encryption has been foiled by the NSA. This is not speculation, but quasi-certainty: 1024-bit RSA. - Crytographers all acknowledge 1024-bit RSA is dead [1]. - Attack cost 10 years ago was estimated to be a few million USD to build a device able to crack a 1024-bit key every 12 months [2]. - "Much of" the "secure" HTTPS websites use such weak key sizes [3]. - NSA had a budget of 10.8 bi…

Considering http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/ I wouldn't bet on "deep encryption" either ...

Re: N.S.A. Foils Much Internet Encryption

#339
It's been out ten days already before the news agencies decided to report it: https://encyclopediadramatica.se/PRISM#Parabon_Leaks

Magnet link of the alleged software used to break encryption methods: magnet:?xt=urn:btih:f8a942ccff260f7b9035bbf3b8af5c3013e21097&dn=Parabon+Leaks

Re: N.S.A. Foils Much Internet Encryption

#340
post #176

Earlier quoted context omitted.

Ah, yes, I wasn't trying to say they were exploiting that particular vulnerability. Just that we now have better evidence that that really was a (rather poor) attempt to subvert standards to make them easier to decrypt. The NSA seems to be really divided between SIGINT and COMSEC. COMSEC wants to provide good, strong encryption, that can help secure US government and corporate communication. SIGINT wants to be able t…

As you may well know, the NSA has its own ciphers (Suite A) it uses for top secret classified traffic, which to me is positive proof you can't trust anything they recommend (AES) - when they don't even use it themselves.

They use AES when dealing with "outsiders", but I have trouble believing that they use it internally (and instead use the Suite A ciphers -- it's impossible for others to break them if they don't know anything about them, right?)
Post reply on HN