8 ms·
Is Extended Random a Malicious NSA Plot?
- kens 11y agoI hate to ask a dumb question, but the article discusses the actions of Clyde Frog a lot. Is Clyde Frog a person, a company, a government project, or what? A web search found a TV show and a stuffed animal, so I'm honestly puzzled. Edit: thanks cmg. I was reading the article on my phone and the side notes were off screen so I totally missed the explanation.
- cmg 11y agoIn small (11px), light-ish (#777777) next to the first paragraph: > If I call NSA “Clyde Frog” long enough, eventually other people will too. Someone has to start the meme! I think Dual_EC is a backdoor.
- mwcampbell 11y agoFirst time I've ever seen sidenotes done like that. BTW, screen reader users (i.e. blind people) can't possibly miss the sidenotes; in fact, each sidenote will interrupt the text at the point where the note is most relevant. So a screen reader will render the first sentence like this: Did Clyde Frog If I call NSA “Clyde Frog” long enough, eventually other people will too. Someone has to start the meme! subvert crypto standards with a backdoored random number generator called Dual_EC? A little jarring when first encountered. (In my case, because I have some usable vision, I could tell what was going on.) I'd suggest sticking with more conventional footnotes, but I can see why this form of sidenote was appealing.
- vitd 11y agoIt also happens if you use "Reader" mode in Safari. It was very strange, but I caught on once I looked at the article in regular mode and it wasn't there.
- dredmorbius 11y agoProper support for footnotes / sidenotes in HTML itself would be dandy. There's not, so people write hacks.I've done a few myself. Presently footnoting is either manual or requires a preprocessor -- LaTeX, Markdown, CMS, etc.
- TheCoelacanth 11y agoDo screen readers do any special handling of parentheticals? For a note that short, I wouldn't have been surprised if it were inserted inline in parentheses.
- nubb 11y agoSouth Park reference the author is making for fun.
- tptacek 11y agoBack in the late 90s, there was a huge collaborative effort to break DirecTV's content controls. People would hack DTV smart cards, and then DTV would break the hacks, and there was an arms race for several years, during which, if you wanted, you could reprogram your DTV smart card to get all the local channels in every DTV market, and then program your DVR to record 18 episodes of The Simpsons every day, and I digress. Anyways: for the DTV hackers, the adversary, DTV and its security contractors, were called "Dave". I always liked that, so I figured, let's give our global adversary a name.
- deadmik3 11y agoWow I am a lot less lost after reading the explanation
- BWStearns 11y agoI'm actually a South Park fan and I was chuckling when I read Clyde Frog initially (before the side notes) because I assumed it was an employee/contractor who was involved with these developments. My initial reaction was to wonder how much he hated South Park after they introduced CF. I could get behind Clyde Frog being an NSA alias for shits and giggles.
- ghshephard 11y agoCan anyone figure out whether USG is Unix Systems Group or United States Government. (I think we're safe in assuming they aren't United States Gypsum (though, from my trips through Empire to Gerlach, that was the first thing that came to mind)). [Edit - if you read through the entire (epic and wonderful resource) article, United States Government is used where USG might be - so I think we are safe in assuming it is United States Government. tptacek, might be worth introducing the acronym at the beginning.]
- jgon 11y agoDoesn't this essay absolutely bury one of the most important parts of this scandal, that RSA used DUAL_EC as the default random number generator in their FIPS certified encryption product for almost a decade!?! I note that this is glossed over with a description so marginal I would tempted to call it dishonest if I were not trying to apply the principle of charity to its author. "RSA BSAFE had support for DUAL_EC." Support!? Uh no, it used it as the default generator. "I lean towards “not”; the structure of these proposals makes Clyde Frog’s job needlessly harder, if only by practically ensuring that OpenSSL and Schannel would never default to enabling them. But people smarter than me are convicted of the idea that this was a backdoor attempt." Well yeah it would make their job harder unless one of the largest security companies in the world used that random generator in their flagship encryption product!!! I feel like maybe their are better arguments for why this was not a subversion attempt, but honestly the points for seem so, so strong and the points against seem like a mountain of wishy-washy humming and hawwing and extending the principle of charity even in the face of the above mentioned giant blaring klaxon of wrong-doing. I will still not say that reasonable people can't disagree over the question at hand but the arguments presented in this article don't strike me as being anywhere near strong enough to make this the sort of grey area the author would like.
- tedunangst 11y ago> "RSA BSAFE had support for Extended Random." Support!? Uh no, it used it as the default generator. ? Extended Random is not a random number generator.
- linkregister 11y agojgon, maybe you're also reading this on a mobile client. tptacek's first side note on the right column is that his opinion is that DUAL_EC_DRBG is an NSA backdoor. Far from burying the most important part of the scandal, he puts it front and center. This discussion is about other proposed extensions to TLS, not DUAL_EC_DRBG. It might be too late, but I recommend you edit your comment to change "Extended Random" to DUAL_EC_DRBG (the random number generator). Extended Random is an extension proposed by the NSA (Clyde Frog).
- kordless 11y ago
- Raj123123 11y agoPKRNG - if the attacker obtains the private key, why do they need the 28+bytes?
- tedunangst 11y agoThe attacker doesn't have the TLS private key, they have the RNG key. But they don't have the RNG seed. Recovering the seed is necessary to predict other RNG outputs and break TLS, but requires observing more RNG output than one typically sees.
- rst 11y agoFWIW, the operative theory here is that "Extended Random" was designed to work in concert with the DUAL_EC DBRG/RNG, which almost certainly allows "Clyde Frog" to predict all future output on the basis of very few samples.
- Raj123123 11y agoseems they aren't limited to just future output: "Using that private key, they can observe CSPRNG output on the wire, “decrypt it”, and use that to rewind and fast-forward other people’s CSPRNGs, discovering their keys."
- chmike 11y agoIndeed. So the issue here is to deduce the symetric keys generated with a Cryptographically Secure Psoeudo Random Function (CSPRF) seeded with information exchanged during the initiating handshake and using the respective public and prvate keys, without having any private keys. Imagine now that with a handfull pseudo random bytes sent in clear with the TLS protcol an eavesdropper could deduce the internal state of the CSPRF and thus the symmetric keys. They could decrypt the channel.
- AngrySkillzz 11y agoIf the victim is using Dual_EC_DRBG and Clyde Frog can obtain ~32 bytes of RNG output, they can figure out in reasonable time what the seed to the RNG was (assuming they know how the curve parameters were generated). "This is a huge deal in the case of SSL/TLS, for example. If I use the Dual-EC PRG to generate the "Client Random" nonce transmitted in the beginning of an SSL connection, then the NSA (sic) will be able to predict the "Pre-Master" secret that I'm going to generate during the RSA handshake. Given this information the connection is now a cleartext read. "[1] So, Clyde Frog can figure out your RNG state and predict what key you will generate for your TLS session. That's how they obtain the private key. [1] http://blog.cryptographyengineering.com/2013/09/the-many-flaws-of-dualecdrbg.html http://blog.cryptographyengineering.com/2013/09/the-many-fla...
- ackalker 11y agoIt may be my (somewhat archaic) sense of crypto humor, but any time I read the term "Dual EC", my mind says "CE lauD", making it sound like someone saying the word "cloud" with an accent expressing a lot of disdain[1]. Anyway, the Dual EC backdoor, if real, along with the extra randomness, may yet prove to be part of "the gubment's" very own cloudbusting operation, to make cloud services rain users' secrets at the push of a button... [1]: cf. "my butt"
- euroclydon 11y agoExcept for Hoffman’s last proposal, the extensions are cordoned off to the US Government. The sponsors of the standards and their authors make very little effort to provide a use case for normal Internet users. If this were an X-Files episode, then the group who really runs the world would be forcing the USG to subvert it's own crypto.
- mindslight 11y agoTangential forward-looking paranoia: I've got to wonder if the DUAL_EC debacle only appears so ham-fisted because the public understanding of public key crypto is much further ahead than our understanding of symmetric ciphers. Universities employ armies of mathematicians studying mathematical structures for their own right, whereas shuffling bits isn't sexy. Conversely, "Clyde Frog" has been studying symmetric ciphers much longer and harder (symmetric is sufficient for nation-state security) and could have a deep symbolic understanding of common symmetric constructions akin to how we see the public-key math. They would then know how to choose constants that admit similar backdoors, and the entropy of "nothing up my sleeve numbers" isn't exactly well quantified. Rather than a proactive attempt, DUAL_EC could have been a reaction to worries about movement to RNGs based on asymmetric math.
- why-el 11y ago> symmetric is sufficient for nation-state security Is that a verifiable assertion? Would love to read more about it.
- mindslight 11y agoGovernments can afford to employ people to transport N^2 keying material. Additionally, they have predefined communications patterns. Even if part of the government moves to asymmetric algorithms for key distribution (only possible after the discovery of Diffie-Hellman), the top secret portions can continue using couriers to avoid relying on an additional algorithm. Combined with its standard use for bulk ciphering, symmetric is obviously the more valuable target to secure/break.
- fossuser 11y agoPublic Key crypto was discovered by GCHQ (and then given to the NSA) several years before it was publicly discovered by Diffie-Hellman and RSA. I think this was to avoid having to have the symmetric keys under armed guard. The public discovery is also what kicked off the 'crypto wars'. I'd be surprised if modern nation state intelligence communities found symmetric encryption sufficient. A lot of interesting information about the history I learned from Steven Levy's crypto: http://www.amazon.com/Crypto-Rebels-Government-Privacy-Digital/dp/0140244328 http://www.amazon.com/Crypto-Rebels-Government-Privacy-Digit...
- logicallee 11y agoMay I just say, I am extremely happy that the NSA has to jump through such incredibly laborious hoops to gain a glimpse into anything, a capability which they would then fail to acknowledge at any price. This is the OPPOSITE of a dictatorship, where there would simply be a heavy-handed order to put in an explicit, acknowledged back door or be jailed without trial, or executed. This is what freedom looks like. Enjoy it! I personally also enjoy the fact that nobody with a few million dollars in spare change can surf the dark web as Dr. evil. But that's just me. EDIT: this comment is at -1, perhaps people thought I was making a ham-fisted sarcastic statement. I'm speaking literally. You all can keep either your dictatorship, or the society in which someone can commit an act of terrorism for the going black market rate without any repercussions; if it's a false dichotomy, you'll have to explain why. EDIT 2: this comment is fluctuating wildly (-2, +2, 0, etc) especially since my edit. Thoughtful replies would probably be more helpful than voting here.
- deleted 11y ago[deleted]
- seiji 11y agoFor your web inspector console: $("body").html($("body").html().replace(/Clyde Frog/g, "the NSA")) Update: more proper $("body").html($("body").html().replace(/Clyde[\s\r\n]Frog/g, "the NSA").replace(/\. t/g, ". T"))
- tptacek 11y agoThat's not perfectly accurate; the reason I think an abstract name is helpful is that GCHQ is just as bad, if not worse: it's handy to have a name that captures all of them.
- seiji 11y agoIn my defense, when I first skimmed the article I missed the note about the secondary meaning and was quite confused. "New hacker group? Old hacker group I don't know about? Kids these days..."
- jlgaddis 11y agoI did too. I assumed it was referring to an individual working for USG (although "Frog" is a pretty uncommon surname, I'd think).
- gghh 11y agoJust out of curiosity, are those jabber chat rooms public? tptacek mentions some jabber logs of the TLS working group.
- typeformer 11y agoCertainly seems like a very well crafted but poorly executed plot to me. The tricky thing is how the hell do you really expose it? There are so many levels of obfuscation both by the people who are putting forth the proposal and the technical details as well.
- DonHopkins 11y agohttps://bugzilla.mozilla.org/show_bug.cgi?id=1001989 https://bugzilla.mozilla.org/show_bug.cgi?id=1001989 Bug 1001989 - NSA partisan coder Steps to reproduce: I found a big bug in Mozilla. Would you please remove Eric Rescorla and other NSA-partisans from your software? Actual results: NSA partisans were introducing bugs and vulnerabilites into Mozilla. Sourcecode is not published. Expected results: Remove NSA partisans from Mozilla., publish the sourcecode.
- tptacek 11y agoMozilla was much kinder to you in their response than you deserve: https://bugzilla.mozilla.org/show_bug.cgi?id=1001989 https://bugzilla.mozilla.org/show_bug.cgi?id=1001989
- deleted 11y ago[deleted]
- DonHopkins 11y agoGood for you, that's the exact same link I posted, and if you'll read the whole bug report like I did, you'll see that I'm not the one who reported it, nor the one who reported the duplicate. Reported: 2014-04-27 03:09 PDT by Zakharias https://bugzilla.mozilla.org/show_bug.cgi?id=993224 https://bugzilla.mozilla.org/show_bug.cgi?id=993224 Reported: 2014-04-07 19:02 PDT by Katrien So why do you believe that Mozilla shouldn't remove NSA stooges and partisans from their software and audit their contributions? Doesn't that fall under their mission to "protect Firefox from the NSA"? Mozilla calls on users to protect Firefox from the NSA: http://www.wired.co.uk/news/archive/2014-01/15/mozilla http://www.wired.co.uk/news/archive/2014-01/15/mozilla Brendan Eich's Blog: Trust but Verify: https://brendaneich.com/2014/01/trust-but-verify/ https://brendaneich.com/2014/01/trust-but-verify/ Call to Action To ensure that no one can inject undetected surveillance code into Firefox, security researchers and organizations should: regularly audit Mozilla source and verified builds by all effective means; establish automated systems to verify official Mozilla builds from source; and raise an alert if the verified bits differ from official bits. [...] Through international collaboration of independent entities we can give users the confidence that Firefox cannot be subverted without the world noticing, and offer a browser that verifiably meets users’ privacy expectations.
- HashThis 11y agoThat is because Jerry Solinas works for the NSA. Jerry Solinas @ NSA @ jasolin@orion.ncsc.mil. Notice that the company "Clyde Frog" doesn't have a company website. Notice that Jerry Solinas don't have a Linked-In profile.
- tptacek 11y agowoosh
- Raj123123 11y agoWhy would Certicom bother filing a patent(s) on this. The only likely buyer/licensee would be a nation state - which can easily appropriate whatever IP it desires. Further, NSA paying/licensing with a foreign company (Canadian Certicom) only adds to the number of people in the know. Likely Certicom realized this and contributes to the reason why some of the patent applications were never pursued beyond provisional patent applications.