4 ms·
> This comment in particular seems to imply that government agencies can break e2e encryption. Much E2E encryption can be broken by government agencies. For HT
by jwtadvice 10y ago
> This comment in particular seems to imply that government agencies can break e2e encryption.
Much E2E encryption can be broken by government agencies. For HTTPS for instance, the government is a certificate authority accepted by your browser - as well as there having been multiple cases of collaboration with well known CAs to have certs minted for them. In this case there's no need to break RSA. In any case, much of TLS is open to various kinds of breakage (that is not as hard as RSA), and NSA docs showed a number of instances where intelligence agencies would sit behind load balancers and at data center chokepoints in domestic companies to gather information where PKI no longer poses a problem (behind the load balancers being referred to here as "end-to-end").
Basically, there's many ways to thwart "e2e" that isn't cracking 4096 bit RSA. Intelligence agencies do all of them.
- hendersoon 10y agoYes, very much this. Full circle back to the famous xkcd comic that's always posted in HN articles like this. https://xkcd.com/538/ https://xkcd.com/538/
- ThatGeoGuy 10y agoPerhaps we need to clarify our terminology. Typically when discussing HTTPS or TLS, we are discussing transport security, not end-to-end. I wouldn't classify either HTTPS or TLS as end to end, although I can see if you read my comment a certain way it almost seems as if I did. That said, I am still unconvinced that governments have somehow compromised most end-to-end systems, especially not the ones that experts suggest work (PGP, Signal Protocol, OMEMO, etc). I should make particular mention that compromising and end-to-end system has nothing to do with whether or not a specific target can be made to give you their key(s). If you're being solely targeted by a billion dollar agency, regardless of their origins or motives, you probably won't be able to run or hide for very long. It's important to consider targeted attacks too, but let's not assume Hollywood scenarios here when discussing whether entire crypto-systems have been compromised.
- jwtadvice 10y agoHere's a recent Thinktank summary of the encryption and what access is difficult for the government. https://csis-prod.s3.amazonaws.com/s3fs-public/publication/170203_Lewis_EffectOfEncryption_Web.pdf?Gqb5hXxckXykb3WAphuoVHrHfDTwuFkN https://csis-prod.s3.amazonaws.com/s3fs-public/publication/1... You will find that the following summary is correct: The federal government does not have an issue getting the plaintexts it desires today. This is because of a large number of capabilities come together: first most communications does not have unrecoverable encryption. Strong encryption is extremely rare, composing very small percentages of the communications available. Then, where encryption is available it isn't applied by default. Then, where encryption is available and applied by default, there are key escrow mechanisms for most of these cases. Then, there is a legal mechanism that requires communication service providers to provide decryption for any of the encryption that they provide. Then, what encryption can is build over the mechanisms for providers and services offer, most of it can be defeated. Then, what can not be defeated mathematically, access can be gained from other types of law enforcement activity, including lawful hacking exercises and capture of unlocked target devices. Then, what can't be gained by any of this can be inferred from metadata that is almost always available in plaintext, provided by mass surveillance collections. I encourage you to read the associated literature, both reports like the above, and the contents of the Snowden Disclosures. Namely: both law enforcement and intelligence operations are able to thwart the very vast majority of communications among Americans as well as those abroad. There do exist some systems that lead to unrecoverable encryption - they are in the very vast majority and can and are thwarted using other types of operations (if the cost-benefit analysis deems it necessary). And so it is not a reasonable position to remain skeptical in the face of overwhelming evidence. It should also be noted that a number of "Hollywood scenarios" have been disclosed and have been seriously debated on a national level: before the 90s all cryptography in the United States was mandated to be weak to government interception (this isn't that long ago) and can we go without mentioning DRGB? Apparently we can't. The sum total of all of this is that by and large, as a rule, federal intelligence and usually even regional law enforcement are able to access almost all civilian communications (in Seattle, for example, all of the cities communications including social media posts are hoovered up by our city police).