Live data from Hacker News

New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

wired.com

71–80 of 122 posts

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#71
This is as good a thread as any to perhaps start a discussion on something that's been on my mind ever since I learnt about the NSA's penchant for hiring mathematicians and cryptographers.

How would you reasonably estimate the NSA's academic prowess when it comes to crypto/codebreaking? How does this compare to the state-of-the-art in academia?

I am less interested (but definitely so) in knowing or estimating more about how such a budget helps in deploying and building systems to collect/store intelligence information. I also wouldn't be surprised if they are fairly ahead of the curve in terms of zero-day exploits and the like.

The thing that most makes me curious is in terms of pure mathematics (like better factoring algorithms, better predictors of pseudorandomness, weaknesses in commonly used parameters or poor choice of certain elliptic curves, say).

There are few interesting pieces of information that would help

-- a rough headcount of people in positions comparable to post-docs and professors in the worldwide crypto/math community. I find it incredibly hard to imagine a mathematical breakthrough without significant training and continuous involvement in the research community. Do they get a fair share of the best mathematicians out there? Does the pay make it a fairly attractive destination?

-- whether or not they have an active "collaboration" and "internal publication" environment, once again, comparable to the dozen or so reputable conferences occurring yearly that allows for exchange of several interesting ideas across 100s of people with the express incentive in attending these conferences being discussion and collaboration.

-- how much we can extrapolate from just 2 instances (from what I know) of the NSA being a decade or more ahead of the curve (the DES S-box and public-key cryptosystem examples). What's a reasonable way, as outsiders, of starting to get a legitimate guess? Do we have more examples or at least hints of such possible examples?

(ps: I see after posting this that several other people have raised similar points in the thread. I'd love to learn more about why Bruce Schneier thought that the NSA was decades ahead in 1996 and whether he holds the same opinion in 2013)

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#72

What if the "groundbreaking" crypto-cracking was that the NSA discovered you could trick people into cracking "bountied" SHA-256 hashes in a massively parallel operation?

It doesn't work like that. The information being hashed is the hash of the merkle tree root of all the transaction in a block, and a nonce. They are hashing data in a very specific format, not every possible bytes sequence.

Also, the proof-of-work is completed when you find a hash that begins with a specified number of zeros, and not when you reach a specific hash.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#73
It's one thing to leak documents about the NSA being in a grey area in regards to US citizens rights. But this last month or so all the articles I see here are about Snowden trying to actively 1) attempt to hurt the USA and 2) attempt to embarrass the USA.

I don't get it? What is he thinking he is doing?

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#74
post #71

This is as good a thread as any to perhaps start a discussion on something that's been on my mind ever since I learnt about the NSA's penchant for hiring mathematicians and cryptographers. How would you reasonably estimate the NSA's academic prowess when it comes to crypto/codebreaking? How does this compare to the state-of-the-art in academia? I am less interested (but definitely so) in knowing or estimating more ab…

Some people [1] get involved in crypto without specific training.

[1] http://cm.bell-labs.com/cm/cs/who/dmr/crypt.html

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#75
post #59

Is there a reason why the groundbreaking crypto-cracking could not be a quantum computer that tries all possible passwords/keys simultaneously? (I'm no expert on this subject.)

Yes, because this is not how quantum computers work. That is, they don't perform all computation paths non deterministically and then give you the 'right' answer. The answer that you get is a composition of all paths; it is not known how to use this to solve NP-complete problems.

On the other hand, most modern encryption systems are based on the assumption that factoring is a difficult problem. Famously, quantum computers can factor numbers efficiently. So a large scale quantum computer could break current cryptosystems, but there are in fact cryptosystems (such as lattice cryptography) that are secure against quantum computers.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#76
post #71

This is as good a thread as any to perhaps start a discussion on something that's been on my mind ever since I learnt about the NSA's penchant for hiring mathematicians and cryptographers. How would you reasonably estimate the NSA's academic prowess when it comes to crypto/codebreaking? How does this compare to the state-of-the-art in academia? I am less interested (but definitely so) in knowing or estimating more ab…

On inventing public-key crypto, GCHQ was 3 or 4 years ahead of the public: http://en.wikipedia.org/wiki/Public-key_cryptography#History

That source says nothing about the NSA. Is it believed the NSA invented it earlier and didn't share with GCHQ?

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#77
post #71

This is as good a thread as any to perhaps start a discussion on something that's been on my mind ever since I learnt about the NSA's penchant for hiring mathematicians and cryptographers. How would you reasonably estimate the NSA's academic prowess when it comes to crypto/codebreaking? How does this compare to the state-of-the-art in academia? I am less interested (but definitely so) in knowing or estimating more ab…

I think it's an excellent question.

The "intelligence community" sponsors a lot of math and fundamental physics work in academia and the national labs. The grants are laundered through an intermediary, so you don't know who and in what agency is interested in the work. I think of that visible side as one way for them to keep their foot in the door, to check the pace of advances on the unclassified side.

But you're really asking about the classified "shadow" of that open work, which by definition is hard to measure. I think one easy yardstick is "how much a mathematician makes" versus the intelligence budget. This leads me to think that they can hire a lot of mathematicians.

And let's face it, the subject matter is really cool. There's a reason that mathematicians throughout history have been interested in coding. Now imagine someone paying them to do it.

A senior academic I knew (in the information theory area) consulted at the NSA for several summers. His work was done in a Faraday cage, and that's all he would say about it. He was top-notch in his field, and he wouldn't waste his summers with fools. I think that there are lots of similar stories.

My working belief is that, in certain areas, they are way, way ahead of the open state of the art. Like with Keyhole, or tapping fiber optic cables, etc. Not everywhere, but they don't have to be ahead everywhere, just in a few places.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#78

It's one thing to leak documents about the NSA being in a grey area in regards to US citizens rights. But this last month or so all the articles I see here are about Snowden trying to actively 1) attempt to hurt the USA and 2) attempt to embarrass the USA. I don't get it? What is he thinking he is doing?

Help the USA?

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#79
I wonder what is top secret there? Those things look quite mundane to me and I don't really understand how revealing, for example, that $1 bn is spent on "mission ground stations" would hurt national security. Revealing more deep details - maybe, I can see it, but on this level it doesn't look like it should be secret at the first place.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#80
post #50

Earlier quoted context omitted.

> "...investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit internet traffic." This could be little more than a way of making the purchase of a bunch of D-Wave boxes sound more compelling than it might really be at this time. The problem with secret organizations with no oversight is that we'll probably never know for sure.

Sounds like a natural fit for quantum.

Not really. Quantum annealing, D-wave's quantum method, cannot solve these kinds problems any more efficiently than a normal computer.
Post reply on HN