3 ms·
This is a bit like saying you can't trust AES because it was declassified by the NSA and offered to the public. It works well enough within its limits. There i
by XaYdEk 10y ago
This is a bit like saying you can't trust AES because it was declassified by the NSA and offered to the public.
It works well enough within its limits. There is nothing that will protect you from active surveillance from a global actor and given enough time passive surveillance will de-anonymize you as well.
As for the part with government level actors using Tor, it's not surprising or new, why wouldn't they use it ? Just another tool.
And if you are using Tor to sign in to Google, then your threat vector is local and you are trying to increase security (privacy) in communicating with your trusted party (Google), not anonimity. Or that would be the logical assumption in using Tor this way.
I'd keep going, but the point is he seems to misunderstand what Tor can and can't do and even how to use it for any given scenario. As though the default usage in any scenario should offer complete anonimity against all possible forms of surveillance.
It kind of reminds me of "we need backdoors in crypto that only we can access" level of understanding.
- EvanAnderson 10y agoA pedantic point: AES was never "declassified by the NSA". AES is a standardized version of the Rijndael algorith which was developed by Belgian cryptographers and standardized by US standards bodies after a public submission period. The DES, which preceded AES as the US standard encryption algorithm, was based on an IBM-developed algorithm (Lucifer) that was modified by the NSA. The modification to the DES S-boxes by the NSA was regarded by many as a weakening or backdooring of the algorithm, but subsequently it was revealed that the NSA was aware of a type of attack that the modification rendered the resulting DES algorithm immune to (differential cryptanalysis).
- XaYdEk 10y agoTrue, should've said 'because the NSA was involved in the design of the standard'. They never classified it (the design), but I think they did in DES. And it makes sense, especially at the time, to harden against differential cryptanalysis because it's the more efficient method, scales better and requires way less computing power than trying to bruteforce the key. But pushing for the shorter key suggests they were trying to leave themselves a reasonable chance of succes if they had to go last resort and try to bruteforce the key, as they were one of the few actors at the time that had access to enough computing power.