Live data from Hacker News

N.S.A. Foils Much Internet Encryption

nytimes.com

1–10 of 395 posts

Re: N.S.A. Foils Much Internet Encryption

#3
This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability.

The issue to me has always been how and what data they access and store, and how it is used.

Re: N.S.A. Foils Much Internet Encryption

#4
"Cryptographers have long suspected that the agency planted vulnerabilities in a standard adopted in 2006 by the National Institute of Standards and Technology, the United States’ encryption standards body, and later by the International Organization for Standardization, which has 163 countries as members."

Wonder if it is referring to the Dual_EC_DRBG RNG.

Re: N.S.A. Foils Much Internet Encryption

#5
Normal people don't need 256-bit symmetric encryption. That's assault encryption and should only be used on the battlefield. 40-bits is enough and anything over that should be banned.

I'm only joking, but the same argument is used against other technologies that governments seek to control/dominate.

Edit: Skipjack was 80-bits I think. It was used in Clipper Phones: http://en.wikipedia.org/wiki/Skipjack_(cipher)

Re: N.S.A. Foils Much Internet Encryption

#7
post #5

Normal people don't need 256-bit symmetric encryption. That's assault encryption and should only be used on the battlefield. 40-bits is enough and anything over that should be banned. I'm only joking, but the same argument is used against other technologies that governments seek to control/dominate. Edit: Skipjack was 80-bits I think. It was used in Clipper Phones: http://en.wikipedia.org/wiki/Skipjack_(cipher)

The funny thing is 56-bit encryption is still in use in the form of PPTP with MS-CHAPv2. I bet most of the decrypted VPN traffic mentioned in the article uses that.

Re: N.S.A. Foils Much Internet Encryption

#9
The N.S.A. hacked into target computers to snare messages before they were encrypted. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world.

This is mostly a confirmation of what has been supposed: No magic, mostly bribed and coerced cooperation from the people who should be keeping our communications secure.

And while it doesn't do anything for the credibility of US-based companies, N.B.: "hardware and software developers around the world."

Re: N.S.A. Foils Much Internet Encryption

#10

This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability. The issue to me has always been how and what data they access and store, and how it is used.

If the NSA can, others can. It makes the whole thing useless.
Post reply on HN