Live data from Hacker News

Intel In Bed with NSA?

cryptome.org

51–60 of 73 posts

Re: Intel In Bed with NSA?

#51
post #3

It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated: > Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there'd be no risk of it causing a s tstorm…

And how long ago would the idea that the NSA get call logs for every call in the USA have been utter paranoia? Or that they tap and record all international internet traffic?

Just because you are paranoid doesn't mean that they aren't out to get you!

If you random number generator isn't then all of your crypto is basically useless. Paranoid is the correct state of mind for these systems.

Re: Intel In Bed with NSA?

#53
post #22

Earlier quoted context omitted.

> The feds used to fight civilian crypto tooth and nail. Curious. I'd like to read about this. Can anyone post any links?

http://www.loundy.com/Roadside_T-Shirt.html is one example, there are probably others. It ended up going in a sane direction, but it's a bit crazy to imagine in hindsight.

More illegal crypto T-Shirts: http://www.cypherspace.org/adam/uk-shirt.html

This was one of my favorite shirts, but it finally gave up the ghost a few years ago.

Re: Intel In Bed with NSA?

#54
post #3

It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated: > Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there'd be no risk of it causing a s tstorm…

That's an argument from ignorance fallacy.

"I can't imagine how that (potential) backdoor can be abused, therefore it doesn't exist".

Random generators controlled by a third party are ABSOLUTELY a problem for any crypto system based on them.

Your (b) argument is even more ridiculous, considering the NSA events that just unfolded.

Your (c) argument makes zero sense, considering it got detected.

Re: Intel In Bed with NSA?

#55
post #22

Earlier quoted context omitted.

Well, it is documented that the NSA made DES weaker by using less bits for key size (this makes brute forcing easier). I aslo noted that Schiener's AES submission was passed over (I speculate that Rijndael is easier to brute force). The feds used to fight civilian crypto tooth and nail. Then they allowed it, and in one of the crypto books a story was related that the feds were bummed about RSA and friends. The listen…

> The feds used to fight civilian crypto tooth and nail. Curious. I'd like to read about this. Can anyone post any links?

Read up on the Clipper chip: A chip which sort of being promoted to be the "official" way to do crypto in the US. Specifically designed to be decryptable by the NSA via "key escrow".

https://en.wikipedia.org/wiki/Clipper_chip

It died when Matt Blaze figured out a way to trick the clipper chip doing encryption that the NSA could NOT decrypt.

Re: Intel In Bed with NSA?

#56
post #37
post #14

Would appreciate some sort of a summary. Reading some mile long email exchange just to figure out what the headline is really about makes it kinda tricky.

I read the whole thing, but few here would truly feel that my summary of 'paranoia. paranoia everywhere' is not a government plant. The core concern seems to be the idea that an RNG embedded into Intel's latest kit might actually be a PRNG that could be backdoored by NSA on command somehow with resultant catastrophic effects to crypto primitives on that box, if the Intel RNG were the only source of entropy on the box…

Uh, RdRand is definitely a pseudo random number generator. The question is about whether it's cryptographically secure or not, or more specifically, whether it can be or is backdoored.

Re: Intel In Bed with NSA?

#57
post #49
post #3

It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated: > Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there'd be no risk of it causing a s tstorm…

Definitely paranoia. If you want to believe NSA is spying trough your Intel system, they could do it trough vPro and not some RNG calculations. One might assume that NSA can easily tap into the built in VNC server[1] of the CPU. [1] Computers with particular Intel® Core™ vPro™ processors enjoy the benefit of a VNC-compatible Server embedded directly onto the chip, enabling permanent remote access and control. A RealV…

Basic Assumptions:

> You have activated Intel vPro technology on the PCs through configuration of the Management Engine BIOS extension (MEBx).1

http://www.vnc.com/products/viewerplus/ViewerPlusUseCases.pd...

Re: Intel In Bed with NSA?

#58
post #3

It is really, really hard for me to see this as anything other than utter paranoia. As one of the messages in the thread stated: > Right. How exactly would you backdoor an RNG so (a) it could be effectively used by the NSA when they needed it (e.g. to recover Tor keys), (b) not affect the security of massive amounts of infrastructure, and (c) be so totally undetectable that there'd be no risk of it causing a s tstorm…

And how long ago would the idea that the NSA get call logs for every call in the USA have been utter paranoia? Or that they tap and record all international internet traffic? Just because you are paranoid doesn't mean that they aren't out to get you! If you random number generator isn't then all of your crypto is basically useless. Paranoid is the correct state of mind for these systems.

> And how long ago would the idea that the NSA get call logs for every call in the USA have been utter paranoia? Or that they tap and record all international internet traffic?

Before 1988, if you were paying attention. So the idea that the NSA was watching everything you did is almost 30 years old now.

Re: Intel In Bed with NSA?

#59
post #22

Earlier quoted context omitted.

Well, it is documented that the NSA made DES weaker by using less bits for key size (this makes brute forcing easier). I aslo noted that Schiener's AES submission was passed over (I speculate that Rijndael is easier to brute force). The feds used to fight civilian crypto tooth and nail. Then they allowed it, and in one of the crypto books a story was related that the feds were bummed about RSA and friends. The listen…

> The feds used to fight civilian crypto tooth and nail. Curious. I'd like to read about this. Can anyone post any links?

Read "Crypto: how the code rebels beat the government, saving privacy in the digital age" by Steven Levy. He outlines the whole story of public crypto until about 2000. Good read, too.

Re: Intel In Bed with NSA?

#60

Earlier quoted context omitted.

> It is really, really hard for me to see this as anything other than utter paranoia. It is really really hard for me to imagine Intel not beeing 100% cooperative with the NSA.

You know who else cooperates with the NSA? The Linux community. You know, that whole "SELinux" thing? Yeah, that's an NSA project. Turns out cooperating with the NSA doesn't automatically mean spying on the public, it could instead be hardening crypto security. Which is the NSA's other job, it turns out.

Yes and no better example than DES in which the NSA hardened DES against differential cryptanalysis and then reduced the key size from 128 bits to 54 bits so they could break it. Given the prior actions of the NSA is doesn't seem unbelievable that they would both harden and backdoor linux.
Post reply on HN