6 ms·
The NSA is not made of magic (2014)
- empath75 8y agoI think you can make an analogy to actual magic, in that a lot of magic tricks only work because the audience doesn't know the extent to which the magician will go to fool them. They'll use stooges, lie to you, glue magnets to playing cards, eavesdrop on the audience for mentalism tricks, etc. Similarly, the NSA can accomplish what would seem like magic by doing brute force stuff like tapping an undeground cable with a submarine or getting you to hire moles into your organization, or just plain breaking and entering. 10 billion dollars may not buy you a lot of computers but it buys you more man hours than their targets can ever hope to expend on protecting themselves.
- evan_ 8y ago“Sometimes, magic is just someone spending more time on something than anyone else might reasonably expect.” –Teller
- Zigurd 8y agoQuite so. You can say "there is no magical technology for bridging air gaps." Unless you include suitcases full of money to compromise the people traversing those air gaps. Beyond being reasonably certain the NSA can't break strong encryption to access data at rest in situations where the key can't be bought, this is some comfort, but not a lot of comfort.
- jacquesm 8y ago> Unless you include suitcases full of money to compromise the people traversing those air gaps. Most of the time it takes significantly less than suitcases full of money. There are plenty of examples out there where hurt feelings, a sense of patriotism, a sense of honor or even simply a need to be recognized were enough.
- strictnein 8y agoI mean, there's quite a few ways to communicate between air gapped systems. The biggest difficulty is getting your code running on the internal air gapped system, so it can talk back to the first system. And transmission methods are typically pretty slow. A recent public example, but there's lots of other techniques: https://www.youtube.com/watch?v=ZD8CNxYe5dk https://www.youtube.com/watch?v=ZD8CNxYe5dk Paying lots of money to access data at rest would really be more under the CIA, to be honest. The CIA is, theoretically, only supposed to go after data at rest, and leave all the sigint to the NSA.
- BigJono 8y agoHas anyone else noticed a small 'click' when scrubbing to a section of that video where data is being transferred. I'm assuming that's not co-incidental?
- jessaustin 8y ago[2014] Otherwise the references are a bit confusing...
- sctb 8y agoWe've updated the headline. Thank you!
- onetimemanytime 8y agoMagic it is when a country with $20 Trillion GDP is behind you...and not just with money, but with everything. Are you a US telecom and help the NSA? DOJ will not bother you for a lot of things
- sillysaurus3 8y agohttps://en.wikipedia.org/wiki/Joseph_Nacchio https://en.wikipedia.org/wiki/Joseph_Nacchio He was convicted of 19 counts of insider trading in Qwest stock on April 19, 2007[1] – charges his defense team claimed were U.S. government retaliation for his refusal to give customer data to the National Security Agency in February, 2001.[2] This defense was not admissible in court because the U.S. Department of Justice filed an in limine motion,[3] which is often used in national security cases, to exclude information which may reveal state secrets. Information from the Classified Information Procedures Act hearings in Mr. DiNaccio's case was likewise ruled inadmissible.
- Jabbles 8y agohttps://arstechnica.com/information-technology/2012/06/flame-crypto-breakthrough/ https://arstechnica.com/information-technology/2012/06/flame... Sounds like "super-secret cryptanalysis" to me. That was 2012 and Schneier was writing in 2014. I wonder what would qualify as magic to him?
- JoachimSchipper 8y agoOn one hand, that is ahead of the state-of-the-art; on the other hand, that advance was foreseen. Scary as hell, but no paradigm-breaking sorcery.
- SiempreViernes 8y agoHow is it ahead of state of the art when it was deployed a full year after MD5 was supposed to be removed because practical exploits had been released?
- dfox 8y agoIIRC Mikle had demonstrated practical X.509 certificate forgery by reusing the original Wang's collision few weeks after Wang's result was published.
- dbasedweeb 8y agoAny sufficiently advanced technology is indistinguishable from magic.
- SiempreViernes 8y agoA new collision attack 6 years after the first public example counts as magic? In the press release[0] by the authors of the discovery they describe the backstory: > The first cryptographic collision attack against the cryptographic hash function MD5 was invented by Xiaoyun Wang et al. in 2004, which however did not pose a serious immediate threat due to technical limitations. Subsequently, we have devised a more flexible collision attack against MD5 in 2007, a so-called chosen-prefix collision attack. This posed a greater threat due to the removal of the most important technical limitation. Finally, we refined our attack in 2008 and used it to construct a rogue Certification Authority, thereby demonstrating a serious vulnerability in internet security. Our demonstration convinced Microsoft and various governments to raise the security standards for Certification Authorities, by disallowing the use of MD5-based signatures effective 15 January 2009. Flame was probably deployed around February 2010 and the practical attack was announced May 2007, giving 2.5 years for finding a variant and make and debug the malware. Seems reasonable if you have good cryptographers and development team, since the collision is fairly well contained functionality that doesn't block other parts of the project. Generally I would reserve the term "magic" for secret crypto that is better than state of the art, a new variant of state of the art is simply impressive. [0]: https://www.cwi.nl/news/2012/cwi-cryptanalist-discovers-new-cryptographic-attack-variant-in-flame-spy-malware https://www.cwi.nl/news/2012/cwi-cryptanalist-discovers-new-...
- deleted 8y ago[deleted]
- anvandare 8y agoPart of the security of observation comes from the observed not knowing whether or not they are being watched. The Stasi (as well as every other secret police) never had the manpower to keep eyes on everyone. (Of course, that was before massive computational power, widespread cameras, voluntary personal trackers (cellphones), facial recognition AI, etc.). They had to rely a lot on reputation and fear to get their job done (securing the state). It's in the NSA's interests to make themselves seem spooky and magical. The encryption algorithms themselves might be unbreakable, but there are so many other stages involved in communication. And all it takes is one weak link in the chain, one tiny mistake or opening, and humans make plenty of those. No, the magician did not look at you picking your card, but he found a way (based on your inherent inability to be fully attentive to everything) to figure it out anyway. Then again, maybe they do have magic and it's a massive triple bluff. Or maybe...
- gdubs 8y agoWhat you’re describing is basically a panopticon. [1] 1: https://en.m.wikipedia.org/wiki/Panopticon https://en.m.wikipedia.org/wiki/Panopticon
- cfadvan 8y agoOf course one serious downside from the POV of the observers will be the inherent imperfections of any system, and the ability of the “inmates” to discover them. The result can be overconfidence and over reliance on the “panopticon” without even being aware of the metaphorical drug deals and stabbings going on in the showers. I mean, this how you get a couple of hobbits up in your shit before you know it.
- deleted 8y ago[deleted]
- skummetmaelk 8y agoIf Stasi had had todays technology, the wall would never have fallen.
- lallysingh 8y agoHe's right, of course. I went through the docs when they came out and was seriously underwhelmed. But with all the people (e.g. costs) NSA has, I don't think much of their budget goes to the kind of blue sky research you need to make their own magic.
- killjoywashere 8y agoIf you read Michael Hayden's book, one gets the sense a lot of the NSA is farm work. He had to buck the system from above to find bands of "young Turks" in the organization and empower them. The problem of managers afraid of letting good people executeis everywhere.
- whataretensors 8y agoThey want to create magic with regulation like gdpr that removes the ability for other organizations to have as much data. NSA-types are trying to appoint themselves as the only people able to massively collect data with no opt out.
- rantanplan 8y agoWhat you say makes zero sense. NSA benefited from companies having access to people's data. Those companies were doing their job for them, for free.
- whataretensors 8y agoWhat doesn't make sense? They would rather have sole access to all the data even at the expense of having to build their own tools. It's not the first or the last attempt of government taking power through 'protection'.
- saagarjha 8y agoWhere would they get their data from? People voluntarily and freely give their data to many companies; if they stopped doing that the NSA would significantly fewer places to gather their data from.
- whataretensors 8y agoExcept they don't have to delete information. They can try any trick that will work and aren't limited to what the users provide. Data is power. The rule setters change the rules to favor themselves, as they always do.
- rantanplan 8y agoYou just throw aphorisms around, with no elaboration whatsoever. You answered neither to my nor your immediate parent's post.
- wpdev_63 8y agoI've heard from a close friend of mine that the NSA order over 200 sex robots to their headquarters in Maryland. Not sure why but that's what I've heard.
- bangonkeyboard 8y agoSchneier likened NSA crypto to alien technology just a few days ago [0], which I guess is not technically magic. [0]: https://www.schneier.com/blog/archives/2018/04/two_nsa_algorit.html https://www.schneier.com/blog/archives/2018/04/two_nsa_algor...
- dfox 8y agoWhat he probably means by this is that lot of NSA-designed crypto contains somewhat weird design choices and it is interesting to try to find out what is rationale behind such choices. One well-known example of this are DES S-boxes, while the somewhat complex key-schedule of Speck/Simon is also interesting (both algorithms use essentially same feistel network for both key schedule and main cipher). Another interesting thing is NSA's tendency to design cryptographic primitives with explicit key checksums byked into them (parity bits in DES, BATON with 320bit key out of which 160bits (!) apparently are checksum...).
- Rebelgecko 8y agoWhat makes Simon/Speck more complex than something like Chacha20? They seem to be based on the same operations, just shifted around and with some slightly different bit shifts