Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

341–350 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#341
post #190

Earlier quoted context omitted.

> but not so far that our adversaries can. Please clarify what you mean by "our". Please clarify what you mean by "adversaries".

Come now, we know enough about the NSA at this point to know that our, adversaries = America, !America right?

I think that "our = {NSA,U.S. government}, adversaries = !our" is more accurate nowadays.

If you are not the U.S. government, you are their adversary (even if you are a U.S. business or citizen).

Re: N.S.A. Foils Much Internet Encryption

#342
post #169

What's truly frightening is this line from the Guardian's article on the topic: > The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace". What does that even mean? That statement is at the same time paranoid, arrogant, and subtly threatening. It's as if to say that without the ability to decrypt interesting traffic, the NSA would be…

Look at what's happening in the UK, in Australia, in France, in Italy, in Spain... the Chinese model is winning hearts and minds of politicians everywhere, and how could it not? If you're into politics, you likely want to reach a Platonic ideal of harmonic society, where nobody is offended, nobody is threatened, and all laws are perfectly respected and enacted. You can't have that on a fully-open network. How can you…

Completely off-base. The US has, by longstanding tradition, had a more expansive attitude towards free speech than Europe. Consider blasphemy laws in the UK, which were only abolished in 2008 but would never have been constitutional in the US. Consider laws against Holocaust denial or displaying Nazi symbols in continental Europe that would be unconstitutional in the US. In Germany you can be arrested for displaying a swastika. In the United States, the courts (in National Socialist Party of America v. Village of Skokie) allowed a Nazi group to march through a neighborhood populated largely by Jewish Holocaust survivors. None of these have to do with controlling networks. They have to do with the first amendment and with both jurisprudence and attitudes towards freedom of speech that are different in the US than in many other countries.

Re: N.S.A. Foils Much Internet Encryption

#343

Earlier quoted context omitted.

In this pdf[1] , they discuss security issues in intel chips.They mention strange responses from intel. Also it's possible, but very hard to exploit those issues , which is optimal in this case. 1[] http://pavlinux.ru/jr/Software_Attacks_on_Intel_VT-d.pdf

Forgive me if I don't open a PDF from a .ru domain. (and yes, I know how silly that response is)

If you were actually interested in the content, there are countless ways to open a PDF safely.

* Open the PDF in a non-adobe reader such as Foxit and Sumatra w/ JavaScript disabled

* Both FF and Chromes internal PDF viewers ignore JS

* You can preview a PDF in Google drive

* Open the PDF in a sandboxed VM.

Guessing for your history of spammming 1 line pointless comments, you probably already know this.

Re: N.S.A. Foils Much Internet Encryption

#344
post #190
post #68

This is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design --…

> but not so far that our adversaries can. Please clarify what you mean by "our". Please clarify what you mean by "adversaries".

Adversary in security means anyone you don't want reading your data.

Re: N.S.A. Foils Much Internet Encryption

#345
Can I spotlight exactly why installing backdoor in software is especially worrisome?

Why is this not just the same as the other clever ways the smart NSA listens in things (not that I'd like but there's something more)?

Well, the thing about backdoors is they get installed on the outside of everyone's software/chips/machines and then ... someone else, someone with less to loose than the NSA, starts to use them for more crudely nefarious reasons, either criminal activity or spying by other nations.

All of this bears resemblance to the former USSR. Once bureaucracy claimed unlimited political power, the next step was for the "mafiya" to take advantage of the universal silence and surveillance.

Re: N.S.A. Foils Much Internet Encryption

#346
post #172

Earlier quoted context omitted.

I think there is a fundamental difference advanced Cryptanalysis (which we always assumed they had due to hiring practices and history) and being able to break crypto by subverting infrastructure. If the NSA said, "Our super smart brain trust figured out how to own your stuff with math five years ago ... ha ha!", I think we would be Totally Fine with that. Hats off to them for winning that game, but at least they pla…

But speaking as a non-American here, what do you expect? The NSA is in the spying business, and ultimately its performance is measured by results, not methodologies. All this hand-wringing is a bit like people expressing horror over the discovery that the CIA sometimes stoops to burglary or deception. I mean, in an ideal world the only way to compromise my password would be to for a beautiful lady spy to seduce me an…

I think there's some cognitive dissonance at work here in the hacker community. It's easier to look up to the NSA et. al. if they're just better at math than you. It's so clean, so pure, if you ignore the black-bag jobs and kinetic side of their work.

Re: N.S.A. Foils Much Internet Encryption

#347
post #343

Earlier quoted context omitted.

Forgive me if I don't open a PDF from a .ru domain. (and yes, I know how silly that response is)

If you were actually interested in the content, there are countless ways to open a PDF safely. * Open the PDF in a non-adobe reader such as Foxit and Sumatra w/ JavaScript disabled * Both FF and Chromes internal PDF viewers ignore JS * You can preview a PDF in Google drive * Open the PDF in a sandboxed VM. Guessing for your history of spammming 1 line pointless comments, you probably already know this.

You are right. I didn't know that PDF.js in Firefox was somewhat safer, though.

Re: N.S.A. Foils Much Internet Encryption

#348
post #37

Earlier quoted context omitted.

Another difference: You don't need a gun to perform the most basic of functions securely. They occupy exactly opposite quadrants on the useful/dangerous axis.

The ability to defend one's self is a basic function. Being dangerous can be useful. Encryption is a tool for guarding privacy, and weapons are tools for guarding against physical threats.

Not having widespread access to firearms in a society doesn't imply that its citizens are defenceless. I.e. some societies skew towards longer-term strategies like reducing desperation or increasing self-control.

There is a cost to having a society saturated with firearms. The vivid, individualistic, but rarely used benefit of personal defence has to be weighed against the boring, common case of excessive violence and escalation due to access to and glamorization of firearms.

Re: N.S.A. Foils Much Internet Encryption

#349
post #2

This essentially bolsters the claims in this article that the NSA has "neutralized" SSL. http://rt.com/usa/allegations-nsa-tool-decrypts-https-085/

This "SSL Locksmith" software isn't really a top-secret NSA tool: http://www.accessdata.com/products/cyber-security/ssl-locksm...

It's a MITM solution that injects fake certificates, i.e. nothing groundbreaking and equivalent to compromised/corrupt CAs (which, as we know, exist and are able and willing to hand out fake intermediate certs etc. to rogue entities). The Whole CA ecosystem is broken and basically snake oil and pretty much everyone knows it.

Post reply on HN