3 ms·
Has there been any known exploit(by government or any other actor) that worked by exploiting advanced cryptography. I feel using a zero day is more easier way f
by likelynew 9y ago
Has there been any known exploit(by government or any other actor) that worked by exploiting advanced cryptography. I feel using a zero day is more easier way for exploiting anything. Also, there are limited ways in which one can exploit cryptography, unlike zero days for which there is a free market and continuous supply.
- dsacco 9y agoTo your first question: I'm interpreting you to mean a zero day of the form, "The NSA is aware of a cryptanalytic weakness in this encryption algorithm"; as opposed to a backdoor, e.g. "Microsoft provided a way for the NSA to bypass Skype's encryption without breaking it." I don't recall any specific examples off the top of my head, but I believe it's probably happened and does happen. But backdoors are much more common; so much so in fact, that I'm led to believe the NSA doesn't have significantly greater cryptanalytic capabilities than academia and industry these days, given that their modus operandi is usually to demand a backdoor rather than breaking it. Their advantages probably stem from access to superior computing power or simply much more of it. I imagine a lot of the agency's research is in fundamental paradigm shifts that can broadly attack many algorithms (like quantum computing) - my edit at the bottom gives an example of this. To your (implied) second question: it's probably not true that zero days are easier. When a company like Apple develops a novel cryptosystem, the NSA is not likely to break it for years (barring conspiracy-theoretic capabilities that we have no way of verifying). Zero days incur massive amounts of research and development time to go from identifying a useful cryptanalytic weakness (i.e. get an algorithm from exponential, to sub-exponential to quadratic time) to deploying an exploit. All the while, earnest cryptographers in industry and academia are attempting the same thing, except they'll publish their results. And if the NSA has a functional exploit, they will use it like you would a classified weapon: sparingly. EDIT: Actually, your question reminded me of differential cryptanalysis. That's more of a paradigm of attacks against a variety of algorithms instead of a zero day against any one particular encryption algorithm; still, the NSA apparently developed differential cryptanalysis and maintained it as a classified capability before the public community independently came up with it. That probably qualifies for your question.
- likelynew 9y agoI was referring to zero days as in the way to gain the ability to run the malicious code in user's device, preferably in the root account which cannot be stopped by updating the software, something like that was done in jailbreaking using browser(a long time ago), or pwn2own. I was not thinking of encryption related zero day specifically. If someone gets root access, they get access to all the contents, no matter what transport security is used.
- nikcub 9y agomd5 collision in signing Flame malware[0] [0] https://arstechnica.com/security/2012/06/flame-wields-rare-collision-crypto-attack/ https://arstechnica.com/security/2012/06/flame-wields-rare-c...