How long to the revelation that AES256 and and PGP have been broken?
Predicting the next NSA Revelation - breaking of AES256 & PGP?
1–10 of 10 posts
Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#2Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#3Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#4Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#5Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#6In the spirit of the zeitgeist ("let 100 flowers bloom"!), I shall disclose: (high ranking, not a cog, multiple conflicts background) UN military COMSEC/SIGINT type, 2012. Looked me in the eyes, measured their words, and then said "PGP [meaning GPG] has been compromised since early versions".
Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#7In the spirit of the zeitgeist ("let 100 flowers bloom"!), I shall disclose: (high ranking, not a cog, multiple conflicts background) UN military COMSEC/SIGINT type, 2012. Looked me in the eyes, measured their words, and then said "PGP [meaning GPG] has been compromised since early versions".
These are far from the sturdiest constructions we have in cryptography; a conservative design today wouldn't be using RSA or DSA at all. But they're proven and used all over the place, including on government traffic no reasonable person could believe the USG would accept a mass compromise of.
If you believe that anyone at the UN can decrypt PGP and would have under any circumstances ever shared that with you, I have some dead aliens from Roswell to sell you.
It may be that he was confused. Very early versions of PGP, from when Zimmerman was apparently just learning what cryptography was, used a cipher of his own design that turned out to be broken.
Being 2 hops from a lot of people with active clearances, I'll add that this is a very popular bit of gossip. The last one I heard was Blowfish; "don't use Blowfish!" "Why would I? It's super old?" "Never mind that. My friend just got out of NSA and said they could trivially break Blowfish. Something about the sboxes."
A credible claim you might make right now: with some degree of effort (ie, not in real time), it might be possible to break large-ish RSA keys.
Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#8Your banking is pwned. Domestic SWIFT-ish scandal. Not for big dollar amounts; every transaction -- at the least, every one that exits a local branch and/or bank.
And/or, my personal favorite:
Your shopping loyalty card mined for "suspicious" foods. ;-)
--
P.S. Yeah, I know the second one is redundant in as much as so many people shop with credit cards. But I've always been suspicious of those loyalty cards. And everyone knows that, while the [keyword] may shop with cash, they can't pass up a bargain.
Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#9It's been done before and since:
http://www.schneier.com/blog/archives/2008/01/nsa_backdoors_...
Re: Predicting the next NSA Revelation - breaking of AES256 & PGP?
#10and/or
They can listen into you at any time using your mobile _when you're not on a call_.