The Economist: > Does the NSA have a quantum computer in the basement of its headquarters in Maryland (pictured above)? It is theoretically possible, but pretty unlikely... A Canadian firm called D-Wave is presently selling a specialised kind of quantum computer—Lockheed Martin, an American defence giant, and Google have each bought one—but it is not suitable for this kind of work. In-Q-Tel - "About Us" > "We make in…
The most advanced math a quantum computer has done to date is "factored 21 into 3×7, with high probability (Martín-López et al. 2012)." Remember: companies are in the game of marketing hype to ride your scifi hopes and dreams. When you see a company saying "quantum" anything, discount their unqualified claims greatly. (Investors are not immune to being manipulated by hype. Claiming "they must be good because they hav…
The NSA's crypto "breakthrough"
51–60 of 101 posts
Re: The NSA's crypto "breakthrough"
#52One of the "nice" things about the NSA: they rely on pretty standard crypto--the same kind the rest of us do!--for their less sensitive, but still classified, secrets. NSA Ciphersuite B ( http://en.m.wikipedia.org/wiki/NSA_Suite_B_Cryptography ) is built into a lot of gov/mil communications technology. And it's just RSA, ECDHE, and so on--all that same stuff available in TLS. In other words: if the NSA break one of t…
What I find really interesting about the NSA is their Suite A: classified algorithms (!) used to protect the most sensitive documents (!!) with hilariously bad security records (!!!). Take for instance the Skipjack cipher ( https://en.wikipedia.org/wiki/Skipjack_(cipher) ), a Type I cipher ("endorsed by the NSA for securing classified and sensitive U.S. Government information") which was evaluated, for the purpose of…
Re: The NSA's crypto "breakthrough"
#53Earlier quoted context omitted.
Suite B does not contain RSA. EDIT: To your latter point, some people would consider this to be a telling fact.
Judging from the wikipedia link, Suite B does not contain a public key cypher. Which either tells us, that the NSA does not use asymmetric cyphers because they are broken. Or that they have a technical reason for it, like being able to do everything they want with key exchange, signature and symmetric cypher. So it is probably worth pointing out, that this speculations are interesting, but ultimately fruitless since…
Re: The NSA's crypto "breakthrough"
#54Totally tangential, but... I must have seen that exact same photo of NSA headquarters 100 times over the past month, at the head of every blog entry related to it. It is too much to ask the nation's photographers just to take a few more pictures from different angles? ;) It's as bad as as the Onion's opinion on Snowden ("Nation Demands New Photograph Of Edward Snowden"): https://www.google.com/search?safe=off&q=%22Na…
Re: The NSA's crypto "breakthrough"
#55One of the "nice" things about the NSA: they rely on pretty standard crypto--the same kind the rest of us do!--for their less sensitive, but still classified, secrets. NSA Ciphersuite B ( http://en.m.wikipedia.org/wiki/NSA_Suite_B_Cryptography ) is built into a lot of gov/mil communications technology. And it's just RSA, ECDHE, and so on--all that same stuff available in TLS. In other words: if the NSA break one of t…
What I find really interesting about the NSA is their Suite A: classified algorithms (!) used to protect the most sensitive documents (!!) with hilariously bad security records (!!!). Take for instance the Skipjack cipher ( https://en.wikipedia.org/wiki/Skipjack_(cipher) ), a Type I cipher ("endorsed by the NSA for securing classified and sensitive U.S. Government information") which was evaluated, for the purpose of…
Skipjack was designed using building blocks and
techniques that date back more than forty years.
I think it's safe to assume they have much stronger stuff now.Re: The NSA's crypto "breakthrough"
#56Earlier quoted context omitted.
Judging from the wikipedia link, Suite B does not contain a public key cypher. Which either tells us, that the NSA does not use asymmetric cyphers because they are broken. Or that they have a technical reason for it, like being able to do everything they want with key exchange, signature and symmetric cypher. So it is probably worth pointing out, that this speculations are interesting, but ultimately fruitless since…
There's ECDH and ECDSA.
Re: The NSA's crypto "breakthrough"
#571) There's an attack against RSA which doesn't involve factorization
2) There's an attack against AES / Serpent / Twofish
I'd say the second is considerably more likely, firstly because the one NSA quote we have on it is "cryptanalyze, or break, unfathomably complex encryption systems" - which sounds much more like a new attack like differential cryptanalysis which provides a general purpose attack against complex symmetric crypto ("unfathomly complex" sounds much more like AES than RSA).
In addition we have numerous quotes in recent days about how GCHQ is working on breaking the encryption on the Miranda hard-drive; which we now know to be a truecrypt drive.
Re: The NSA's crypto "breakthrough"
#58There's at least two other significant possibilities: 1) There's an attack against RSA which doesn't involve factorization 2) There's an attack against AES / Serpent / Twofish I'd say the second is considerably more likely, firstly because the one NSA quote we have on it is "cryptanalyze, or break, unfathomably complex encryption systems" - which sounds much more like a new attack like differential cryptanalysis whic…
Re: The NSA's crypto "breakthrough"
#59Sounds like we need a couple more Snowden's to come out from NSA.
Chances are, if this system exists it will be accessible by only a very small number of people and kept a secret from the others with obfuscation and compartmentalization. So we'd need a very specific leaker out of a small group of people. It would be akin to hoping we'll see the secrets of the "nuclear football". Now one day over-the-counter quantum computers will probably become a reality. In that age we'll see mor…
Re: The NSA's crypto "breakthrough"
#60Breaking public-key crypto would have to be the biggest coup in SIGINT in the history of ever . Much bigger than cracking the Enigma. Just thinking about the sheer volume of internet traffic at every level and in every country that relies on the security of encryption makes the possibility of it being fundamentally broken a literal nightmare. I don't think it has happened. But if it had , that would be the kind of se…
Breaking RSA keys up to 1024 bits is one less-outlandish-than-some possibility. NSA published a note advocating use of ECC in 2009: http://www.nsa.gov/business/programs/elliptic_curve.shtml NSA's statement wasn't "we've got an RSA-breaking machine" or anything like that; the highlights are 0) folks are using RSA-1024, which public sources only ascribe 80 bits' worth of security to, smaller than the usual margin; 1) R…