3 ms·
> Just wiretapping isn't sufficient Please explain, I was under the impression that the above could not reasonably be claimed anymore with any kind of certaint
by tP5n 10y ago
> Just wiretapping isn't sufficient
Please explain, I was under the impression that the above could not reasonably be claimed anymore with any kind of certainty [1][2][3]. Perhaps I'm misunderstanding something important here or the 'Happy Dance!!' slide [4] made me paranoid.
[1] http://arstechnica.com/security/2016/10/how-the-nsa-could-put-undetectable-trapdoors-in-millions-of-crypto-keys/ http://arstechnica.com/security/2016/10/how-the-nsa-could-pu...
[2] http://arstechnica.com/security/2016/08/cisco-firewall-exploit-shows-how-nsa-decrypted-vpn-traffic/ http://arstechnica.com/security/2016/08/cisco-firewall-explo...
[3] http://arstechnica.com/security/2015/10/how-the-nsa-can-break-trillions-of-encrypted-web-and-vpn-connections/ http://arstechnica.com/security/2015/10/how-the-nsa-can-brea...
[4] http://www.spiegel.de/media/media-35515.pdf http://www.spiegel.de/media/media-35515.pdf
- rtpg 10y agoin the slides, check Slide 28. There's a bunch of useful software for wiretapping, but they need access to things like the Pre-Shared Key, or to be using an easily-exploitable connection mechanism like PPTP. Of course router/firmware exploits cannot be prevented in the general case, so NSA-likes could figure out a way get in. But the null hypothesis is still that the NSA cannot crack strong encryption without some sort of pre-built backdoor IMO. Based off of the leaks, NSA gets into things via two ways: - poisoning the encryption methods - social engineering/legal coercion to get keys