3 ms·
Sorry to see you conclude the piece, or that portion, is malpractice :-\ The paragraph you quote was intended to give an overview of one type of work a machine
by mapgrep 9y ago
Sorry to see you conclude the piece, or that portion, is malpractice :-\
The paragraph you quote was intended to give an overview of one type of work a machine like WindsorGreen might do, in broad terms. While it's true we mention RSA as a very basic example of the sort of thing a government would be /interested/ in breaking, we also specifically quote a security researcher saying WindsorGreen “might also have applications for things like … breaking older/weaker (1024 bit) RSA keys” and then quote another (bunnie) saying "“Even if [WindsorGreen] gave a 100x advantage in cracking strength, it’s a pittance compared to the additional strength conferred by going from say, 1024-bit RSA to 4096-bit RSA or going from SHA-1 to SHA-256.”
It's really not clear to me how the piece "puts forward a narrative that the USG is collaborating with IBM to build supercomputers that would break all of RSA" -- indeed, it specifically says this would be of use primarily against 1024-bit RSA.
That said, I'm definitely curious how you think the piece could have framed this more obviously for the lay reader.
(If it's not clear, I work at The Intercept.)
- schoen 9y agoI'm guessing Thomas thinks that only problems that supercomputers can, in fact, usefully attack should be mentioned as the likely targets of this computer. :-) Although the experts quoted only mention 1024-bit keys as targets of attack, the particular paragraph that Thomas mentioned really seems to suggest that RSA in general may be within reach. The worst problem is the last two sentences: > Luckily for those using encryption, the numbers in question are so long that they can only be factored down to their prime numbers with an extremely large amount of computing power. Unluckily for those using encryption, government agencies in the U.S., Norway, and around the globe are keenly interested in computers designed to excel at exactly this purpose. This doesn't mention anything about key lengths, but in a sense key lengths are nearly the whole story with regard to the feasibility of brute-force attacks against RSA. Particularly, both sentences refer to "those using encryption" as an undifferentiated class put at risk by this sort of project, and that's one thing that particularly suggests that all of RSA is at risk.
- tptacek 9y agoThis exactly. Thanks for saying it more clearly than I could.
- mapgrep 9y agoI appreciate the explanation from schoen, I can grasp the argument more clearly. I do believe that is an aggressive reading of the paragraph, out of its context, and that "malpractice" is unfair. The paragraph you quoted is followed, after just a single intervening paragraph, by this, which I would argue speaks explicitly and accurately to your point: --- A very important question remains: What exactly could WindsorBlue, and then WindsorGreen, crack? Are modern privacy mainstays like PGP, used to encrypt email, or the ciphers behind encrypted chat apps like Signal under threat? The experts who spoke to The Intercept don’t think there’s any reason to assume the worst. “As long as you use long keys and recent-generation hashes, you should be OK,” said Huang. “Even if [WindsorGreen] gave a 100x advantage in cracking strength, it’s a pittance compared to the additional strength conferred by going from say, 1024-bit RSA to 4096-bit RSA or going from SHA-1 to SHA-256.” Translation: Older encryption methods based on shorter strings of numbers, which are easier to factor, would be more vulnerable, but anyone using the strongest contemporary encryption software (which uses much longer numbers) should still be safe and confident in their privacy. --- If someone read a sentence saying encryption users are unlucky that the U.S. government is buying supercomputers to crack encryption, which used RSA as an example of something the government wanted to crack, and concluded that this means RSA is broken, they would be cleared of this misreading within a few paragraphs, no? We are diligent in our reporting, research, editing, and fact checking; this piece involved no small number of staffers doing all of those things and more. A term like "malpractice" we take seriously, but seems to have been tossed off a bit casually here.
- tptacek 9y ago"Don't think there's any reason to assume the worst"? We know there's no reason to assume the worst, or really even suspect it. RSA-4096? The 2048-bit moduli which are the industry standard today are hopelessly out of reach of conventional computers; your story implicitly makes a case that people might be at risk for using them. The difference between 2048 and 4096 is a lot of computing power for defenders. There are other quotes in the article that are also presented without enough context to avoid misleading. For instance, you can see speculation in this thread about the utility of this system for breaking "signatures" on updates --- but again, that's only possible if the systems in question are already using weak cryptography. I stand by my criticism of the article. The paragraph I quoted was poorly constructed, and I think the narrative subtext of the whole piece is "worry that the USG is going to subvert all mainstream cryptography". That narrative is extraordinarily harmful. As someone who has done some recent pro-bono training for at-risk people, it's hard enough to get people to adopt best practices without having to beat back concerns that all the effort is for naught. I further agree with everyone else here who have pointed out that without the documents, or at least far more of them, or far more comments from experts than are present in the article, this story isn't providing much value. It's not exactly a secret that the USG IC invests heavily in compute for these purposes. What have we really learned here?
- jackhack 9y ago"supercomputers" are archaic in a day when one can rent a 40,000 core GPU system with 732GB of RAM for $14/hour, on demand, via Amazon Web Services. Available whether you need one or a hundred (4 million cores crunching on a problem with 20Gb/second throughput is still only $1400 per hour). edit: more thorough response.
- dman 9y agoWhere are you getting the 40000 core number from?
- jackhack 9y agohttps://aws.amazon.com/blogs/aws/new-p2-instance-type-for-amazon-ec2-up-to-16-gpus/ https://aws.amazon.com/blogs/aws/new-p2-instance-type-for-am...
- pvg 9y agoNo, they aren't. Unless you think everyone building them is stuck in the past and wasting a lot of money, unaware of Amazon's offerings.
- 21 9y agoA CUDA core and a CPU core is not quite the same thing. 40000 CUDA cores are much slower and more constrained than 40000 CPU cores.
- ryao 9y agoWhy did you not publish the documents for readers? The story seems pointless without the documents.
- deleted 9y ago[deleted]