Live data from Hacker News

New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

wired.com

91–100 of 122 posts

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#91
post #71

This is as good a thread as any to perhaps start a discussion on something that's been on my mind ever since I learnt about the NSA's penchant for hiring mathematicians and cryptographers. How would you reasonably estimate the NSA's academic prowess when it comes to crypto/codebreaking? How does this compare to the state-of-the-art in academia? I am less interested (but definitely so) in knowing or estimating more ab…

>whether or not they have an active "collaboration" and "internal publication" environment.

Back in highschool one of my friends had an internship with the NSA. What he was doing is classified, but he is allowed to say that his work got published internally.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#92
Great, thanks Wired, I just had SECRET/NOFORN material open on a government unclas computer and "I have a dream..." [1].

Both from the front page of Hacker News. Both apparently potentially a violation of law (intel and copyright). This makes the third open post, "Spy Kids" [2], also on the front page, all the more premoniscient.

Who needs Kafka. Or Orwell. Or Huxley. It's all here.

[1] http://www.archives.gov/press/exhibits/dream-speech.pdf [2] https://news.ycombinator.com/item?id=6296086

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#93

> The Post said it withheld the rest, and kept some information out of its reporting, in consultation with the Obama administration to protect U.S. intelligence sources and methods. Weird. Why now? They (admin) refused to do that with WikiLeaks.

Did wikileaks approach the admin for consultation? If not, then it's impossible to refuse.

Yes, Wikileaks and its media partners requested that for the cables. The USGov refused to help censor the cables to protect sources and other people.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#94
You know what's crazy about Snowden? Every time the guy releases something, people freak out.

Why? Because nobody knows exactly what he stole. The even crazier thing is, this could all be a huge misinformation campaign and nobody would notice because we're all

Snowden takes documents, gives them to press, and they release them. How do they verify their validity? Oh yeah, they can't since it's all top secret. What a grand one-way street this guy just built for a bullet proof story of his own liking.

I think it's strange nobody is questioning the veracity of the documents he's releasing. They just accept them as de facto truth.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#96

It's one thing to leak documents about the NSA being in a grey area in regards to US citizens rights. But this last month or so all the articles I see here are about Snowden trying to actively 1) attempt to hurt the USA and 2) attempt to embarrass the USA. I don't get it? What is he thinking he is doing?

What makes you think Snowden is doing anything at this point? What makes you think he is still in contact with reporters? He probably hastily sent them a bunch of documents when he was worried that he would be sent back the USA, and now the journalists are deciding what will be published.

>He probably hastily sent them a bunch of documents when he was worried that he would be sent back the USA

Really!? You think that's probably what he did? You believe that it's more likely than not that he got all flustered with the USA's response, and sent a bunch of documents to Greenwald that he didn't want released?

That's just absurd.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#97
post #80

Earlier quoted context omitted.

Sounds like a natural fit for quantum.

Not really. Quantum annealing, D-wave's quantum method, cannot solve these kinds problems any more efficiently than a normal computer.

We don't know this for a fact. There are quantum annealing algorithms for factoring numbers.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#98

You know what's crazy about Snowden? Every time the guy releases something, people freak out. Why? Because nobody knows exactly what he stole. The even crazier thing is, this could all be a huge misinformation campaign and nobody would notice because we're all Snowden takes documents, gives them to press, and they release them. How do they verify their validity? Oh yeah, they can't since it's all top secret. What a g…

Perhaps you've been living under a rock, and haven't noticed tons of indipendent verifications and evidence showing his stuff is accurate.

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#99
post #53

Earlier quoted context omitted.

But it's really hard to assume that - that's assuming true mathematical leaps and invention. Admittedly if you put enough cryptographers on the payroll they may form their own university, but they still need the air of their peers on the outside. Imagine a cosmologist today transported 30 years back and asked to attend conferences - they would gain no inspiration. I think we put too much emphasis on the single data p…

But what if there are quantitatively and qualitatively more full-time, well-funded cryptographers inside the NSA (and its collaborating sibling organizations in its close allies) than outside? They may have an internal system, with geographically-distributed schools of thought, specialties, and long-running debates, as rich and open as the outside world - just completely segregated. At least, that's how I'd do it, if…

How do you keep all that so secret for so long?

Re: New Snowden Leak Reports 'Groundbreaking' NSA Crypto-Cracking

#100
post #26

Earlier quoted context omitted.

The problem is partly that you personally aren't using just a widely adopted algorithm, you're using a specific implementation layered on some monster protocol stack with weird legacy support for "Look the other way and ROT13" mode as well as AES-$Whatever. HTTPS, for example, depends on both crypto algorithm implementation, SSL/TLS, the responsible Certificate Authority[1], your random number generator, your OS, you…

If CAs gave up valid certs/signing keys for google.com, would the fingerprint be different? And if so, would it be possible to verify the fingerprint if Google hosted it at like pki.google.com? I've been wondering if there's a public registry of certificate fingerprints somewhere to verify you're getting the cert the domain owner knows about.

They could then generate a new key for site.com, trusted by browsers that don't support cert pinning, but yes, that new key for site.com would have a different fingerprint. The only way to keep the same cert fingerprint is to get site.com's cert's private key, either by demanding it with a NSL or FISA order, or by breaking RSA (2048bit, in most cases) if the site uses RSA as almost all of them do.

Generating a new cert from a trusted CA would be caught by EFF's SSL observatory (an optional feature in the HTTPS everywhere extension) and similar efforts.

It would fail if used against a site that has its certificate's CA pinned in the browser, unless the NSA gets the CA private key for the right CA.

Therefore, if they do have CA root key(s), they wouldn't MITM all the ssl connections they can. They would use that capability sparingly.

Post reply on HN