18 ms·
The NSA called me after midnight and requested my source code (2018)
- peter_d_sherman 6y agoWhat I find interesting about this article is that the poster was apparently permitted by the NSA to share his experience publicly... Compare and contrast this with National Security Letters, which apparently (based on the ones that I have seen, that have been publicly posted on the Internet by other people) request or require absolute secrecy...
- implicator 6y agoThe cup is probably a listening device.
- pcmasterdave 6y agoI think the question asked by the author at the end was already answered by Snowden.
- superhuzza 6y agoCertainly doesn't make me want to use any software made by this guy.
- pixxel 6y agoThis was pre 9/11 too, so he didn’t hesitate to hand over the source code based on any sense of patriotism.
- Hnrobert42 6y agoThere were patriots before 9/11.
- partiallypro 6y agoI guess to be fair, this was in 2000. Before we knew the Snowden revelations, etc. I also wonder if he handed over just the source code to the shareware version or the full version? Also, nearly everything is open sourced now...so I guess it isn't the biggest boundary to cross?
- secfirstmd 6y agoWe knew about Crypto AG and Echelon at this point though.
- jacobush 6y agoI knew about Echelon in 1998, but nobody I talked to would believe a word of it. (Or rather, I "knew" what other people ranted about on web pages with badly scanned photos of satellite dishes. But still.)
- raverbashing 6y ago> I also wonder if he handed over just the source code to the shareware version or the full version? It's probably an #IFDEF or an if (registered) somewhere in the source code.
- marcus_holmes 6y agoWhy not? I mean, if the cops turned up at your door with a search warrant, you'd let them in, right?
- burrows 6y agoThe NSA agent didn't have a "search warrant".
- marcus_holmes 6y agoNo they didn't, but they proved who they were to the OP's satisfaction, and left it to him to decide whether he should help them or not. To me, this is a bit of a no-brainer. A government agency wants my help to do something. Do I trust them? Do I help them? Well... yes. They're the government. Incompetent sometimes, irrelevant a lot of the time, inefficient, sure. But ultimately there to provide a service for me as a citizen. If they need my help, then I should probably help them. I understand that Americans don't trust their government like this. I'm not sure why not.
- duncan_bayne 6y agohttps://en.m.wikipedia.org/wiki/Tuskegee_syphilis_experiment https://en.m.wikipedia.org/wiki/Tuskegee_syphilis_experiment https://en.m.wikipedia.org/wiki/PRISM_(surveillance_program) https://en.m.wikipedia.org/wiki/PRISM_(surveillance_program) Those two spring to mind immediately, and I'm not American, I'm Australian. Personally, I don't understand why anyone trusts their Government more than the bare minimum required to support the rule of law.
- ycombi3 6y agoYou can lead a horse to water.... People are way to trusting.
- rcoveson 6y agoIf I ran an neighborhood ISP, and the cops asked me to spy on a neighbor (for reasons they wouldn't even provide), then I'd shut down first. If they just wanted to search _my_ stuff, sure. But if the only reason that I'm even capable of assisting the government in spying on somebody is that they are my customer, neighbor, friend, or user then I will not offer that assistance. That would be evil. Don't be evil.
- voz_ 6y agoWait, why would you not want to use software relied on for national security interests?
- Frost1x 6y agoDoes this jump into the "something/nothing to hide" argument? The idea that there's an intentional backdoor through security for some institution that may or may not be acting in your best interest is enough for me to not want to use it. Just about everyone has something to hide, but what they're hiding and the reasons they're hiding it may only be used as leverage against them and have nothing that's a threat to anyone else. My encrypted data has some old tax returns and past medical records--nothing too exciting or compromising, but neither are things I want random people having access to should my copy of the data be compromised. There are plenty of valid reasons not to want a government agency to be able to pry into every aspect of it's citizens lives. I'd say most people hiding things do it for a lot of social/cultural purposes that aren't too significant at least not in terms of national security. Take most peoples' browser history--few people want others crawling through searches that might make them feel stupid or insecure for whatever reason. Perhaps they looked at someone's public profile they're interested in dating and don't want to be labeled a 'creep' or perhaps they've been making great use of the free PornHub Premium access lately. People have rights to secure/hide those things and they're no real threat to national security.
- deleted 6y ago[deleted]
- Hnrobert42 6y agoThat’s not the question. The question is, why would opening source to the NSA cause you to lose trust in the quality of work. You seem to have answered the question, “Why is privacy good?” Your answer, at least to me, seems valid, but if you are answering other questions, I would ask, “Can you imagine situations in which individual liberties are trumped by physical safety of a large number of folks?” How have you reacted to CoVID-19 restrictions? Are those two things really so different?
- 6y ago
- selykg 6y agoCurious why... Your security should never depend upon security of your source code. If you're doing things correctly, then the source code doesn't change anything about the security of the data that is encrypted. Perhaps you mean that he chose to use 40-bit keys instead of 256-bit keys in the free version? I mean, I guess. But that's just a matter of better understanding the details. It sounds like he outlined this clearly and anyone looking for more security knew to pay for the product to get the 256-bit keys.
- stevep98 6y agoAt that time, if you made software available for export (and that included making a version freely downloadable), it was limited by law to 40 bits.
- hinkley 6y agoThe practice of looking up algorithms by name dates back to that same time. The phrasing of the law, since they were treated as munitions, was that you couldn't even export something that was designed to have crypto bolted on. So you made it so anything could be bolted on and some of them just happened to be crypto. The legacy being things like the blacklist/whitelist discussion we had the other day about case sensitivity in crypto algorithms. We still look up algorithms by string name (instead of enum or some other mechanism) decades later.
- mratsim 6y agoBut books had exemptions and you could export crypto as long as it was printed on a book
- rcoveson 6y ago> Your security should never depend upon security of your source code. For sure. I don't think it's about that, though. Even if the application in question were open source, if the project lead is willing to cooperate in any way their government asks, they could probable ensure the existence of a back door. For this reason, where possible, I would prefer to use encryption software written by people who are principled to a fault (or who at least do a good job acting as if they were). Let's imagine Linus Torvalds or Greg Kroah-Hartman in this same situation. Linux source is available, so let's say they were asked to ensure that a certain patch to a cryptographic API was not accepted before a certain window. Maybe the crypto API maintainers were on the call as well saying that they were on board with the plan (apologies to those people, I don't know you and mean no offense). I like to think that they would: 1. Turn down the NSA. 2. Attempt to get the word out about what they had been asked. 3. Find new crypto maintainers. And yes, it's entirely possible that this is not at all how it would go down. Maybe they would be very cooperative. I don't know any of these people personally. But what I do know is that they have not, as of yet, made a blog post about that time when the NSA did ask them to betray an unspecified user and how they did everything they asked without resistance. I don't think I'm being idealistic here. Software and encryption are global endeavors. People who blindly believe that the enemies of their state are also their enemies, or even that obedience to local laws is a moral imperative, should not write crypto software. Or at least, I hope they make their beliefs known like this guy did so that I can avoid their software.
- xenocyon 6y agoAs others have pointed out, the source code isn't endangering the user(s). Nonetheless, I agree with you. The writer appears emotionally swayed and flattered by the request, like a protagonist in a WWII-era young-adult novel ("Your country needs you!"), and is eager to satisfy the ask immediately without the slightest bit of skepticism or diligence. That's not the kind of temperament one would want an encryption software dev to have.
- tinus_hn 6y agoBetter not use any software by Microsoft then. Also definitely none of that scary open source stuff by people who’ll just hand over the code to anyone who asks.
- superhuzza 6y agoKind of missing the point, it's not about the source code. It's about the authors willingness to cooperate just because an NSA agent implied "it's important".
- tinus_hn 6y agoConsider the amount of cooperation which in this case was ‘send them the source code’.
- Hnrobert42 6y agoSo you don’t use any open source stuff, huh?
- webmobdev 6y agoInteresting read. I wonder whether this was an attempt at social engineering†? While we tend to think of the NSA (or other foreign agencies in this field) working on intercepting information only through electronic means, sometimes a direct approach is often easier (obligatory - xkcd: https://xkcd.com/538/ https://xkcd.com/538/). Perhaps all they wanted was the source code of his application to repackage (after introducing a backdoor) and distribute it on the internet or directly to targets of interest ... perhaps it was part of his training ... †Social Engineering (https://en.wikipedia.org/wiki/Social_engineering_(security) https://en.wikipedia.org/wiki/Social_engineering_(security)) in the context of information security, is the psychological manipulation of people into performing actions or divulging confidential information.
- burrows 6y agoOnly works if the 411 call was MiTMd. edit I was confused and my reply is confusing. I was trying to say that a third party could have stolen the source code by MiTMing the 411 call.
- webmobdev 6y agoI meant perhaps NSA agents are trained in social engineering too. Or it may not have been the NSA, but FBI or CIA or even Military Intelligence too, pretending to be NSA.
- papermachete 6y agoAre you being naive on purpose, friend?
- webmobdev 6y agoLooks like I missed something ... ? What's the context in which you think so?
- papermachete 6y ago
- jessaustin 6y agoWow it's a good thing they were examining a "dumb criminal's" laptop instead of preventing 9/11. If they had done that the armaments manufacturers would have missed out on a bonanza.
- voz_ 6y agoAre you trolling?
- jessaustin 6y agoI didn't post TFA. What NSA are described as doing in TFA (investigating some "dumb criminal") is clearly outside the mission granted them by statute. Furthermore, they so regularly act in contravention of law that there is a commonly-known phrase that describes this activity: "parallel construction". Furthermore, they are lauded rather than criticized in TFA for this unlawful behavior. Furthermore, they regularly pay "journalists" and "influencers" to publish pro-NSA anti-liberty BS in the media and online. Furthermore, if they had better management in 2000 they might have transferred resources from the Overnight Cross-Country Dumb Criminal Parallel Construction Department to the Prevent Terrorism Department. So yeah, I'm the one trolling. ps: It's also interesting to note that comments like that above start out with four or five upvotes, from honest HN users. Within ten minutes, however, they're downvoted into oblivion. USA-MIC has a strong HN game.
- at-fates-hands 6y agoYou do realize regardless of resources they had at their disposal, the reason 9/11 happened was because of inter-agency competition and the lack of knowledge sharing between said agencies? This is the primary reason the Department of Homeland Security was created in the first place.
- jessaustin 6y agoI'm not nearly as certain as you seem to be, about any of the claims you make here. I remember the debate about creating "Homeland Security". (Starting with the neo-Nazi name...) No one with any management experience, including Bush the Lesser, thought it was a good idea. Organizations that have lost their way due to bureaucratic bullshit are not made more effective by more layers of bureaucratic bullshit. Congress was convinced, however, and W's handlers didn't want to "waste" political capital preventing an obvious disaster. Before this debacle, FEMA had been an effective organization (that incidentally had nothing to do with "security"), largely due to its relative independence from the rest of the executive branch. After this debacle, Hurricane Katrina happened. Everybody agreed to blame the hapless "heck of a job" guy because they hoped we stupid voters would forget when they torpedoed the agency two years before the storm. Why are we supposed to believe that "inter-agency competition" was the cause of 9/11? The guy who did it, ObL, claimed it was in response to USA military presence on the Peninsula. Why don't we blame that? If we don't blame our stupid military decisions, why not blame the intelligence community for not noticing potential consequences of those stupid decisions, a single decade after they didn't predict the most important thing that ever happened with respect to their "mission"? The unsupervised services are just like the military, in this respect: WWII was a long time ago, and they've never once been judged on their performance since that time. (JFK tried to hold them to a standard, but not for long...) All they have to do is spend money, and at that they excel. 9/11 itself helped them spend a great deal more than they ever had before. Anyway, even the goofs at NSA could have figured it out in time, if they hadn't just axed ThinThread in favor of Trailblazer. That was a human lapse in judgment that could have taken place at any bureaucratic level. When they make a similar mistake in the next decade, the interference of "Homeland Security" won't have done a thing to prevent it.
- code4tee 6y agoInteresting story, but wouldn’t be surprised if the real play here was to get his source code so they could get some bad guys to use a modified version that the NSA could crack. Put a back door in and then intercept traffic trying to download the encryption app to download the back-doored version. The fact that the NSA has to call him in the middle of the night to learn that the free version didn’t use strong encryption (a fact that seems to have been a selling point for the non-free version) just sounds a bit dubious, but that’s just my sense. Nice mug regardless.
- kapitalx 6y agoFrom the story, I didn't get the sense that Dave didn't know that the shareware version used 40-bit encryption. But that it was a revelation for the author. Sounded like Dave didn't give up any information, other than the relevant version.
- thisisnico 6y agoI see so many tactics of an expert negotiator here. Being incredibly nice and respectful. They were able to get what they wanted. They were able to convince you of an issue, with urgency, without any evidence of the use of your code other than the words of the officer. The story could have absolutely been fabricated to obtain access to the source code per an initiative to have access to cryptographic software, or it could have been true.
- vl 6y agoBeing NSA they could have easily have gotten source code in the covert way - one of the employees had copy at home, they emailed it around! But for encryption software there is no value in source code in the first place - algorithms are standard, and software can be disassembled anyway. All access to the source code does is allows them to save time on disassembly. Author knew all this and this is why he gave them source code in the first place. Basically fabricating this story and risking exposure just wasn’t necessary.
- 6y ago
- StillBored 6y agoWell they do have mugs in the gift store, and the one in the third picture [1] from the end looks like a nice one, although not exactly the same. Of course the picture there is 16 years later. Sounds like a fun social engineering trick though, if you can subvert the local phone switch. Probably would make more of an impression if the FBI/etc knocked on your door and handed you the phone... [1] https://www.businessinsider.com/nsa-gift-shop-2016-5?op=1 https://www.businessinsider.com/nsa-gift-shop-2016-5?op=1
- kyuudou 6y agoI think I'd say "oh wow, gift exchange!" and hand them this: https://www.zazzle.com/the_nsa_parody_shirt-235720294444336131 https://www.zazzle.com/the_nsa_parody_shirt-2357202944443361...
- miles 6y agoDiscussion with 133 comments from late 2018: https://news.ycombinator.com/item?id=18293940 https://news.ycombinator.com/item?id=18293940
- op03 6y agoJuly 2000 is I guess a pre-Google world...so how would "Call 411 and ask for the number of main naval base in Bethesda, MD" work? Just curious how the operator did these lookups?
- bradford 6y agohttps://en.wikipedia.org/wiki/Telephone_directory https://en.wikipedia.org/wiki/Telephone_directory
- Mountain_Skies 6y agoUnless I'm remembering wrong, 411 only gave directory assistance for your area code. To get the phone number for a naval base in another state, he would need to dial that area code plus 555-1212 to contact the local directory assistance for that location. Might be wrong though. Where I grew up there was a charge for using directory assistance so my parent prohibited us from ever using it instead of the phone book.
- Aloha 6y agoby 2000, you could get national DA by calling 411.
- Hnrobert42 6y agoHaha. I remember phone charges for stuff like that. *69 to see who called you was 50 cents. So many nickel and dime charges. Of course, back then, monthly phone bills weren’t equal to a healthy percentage of a car payment.
- svenfaw 6y agoAlmost everybody was already using Google by late 1999.
- klodolph 6y agoThat date is off, it was somewhere in the 2002-2004 range. Back in 1999 I think Yahoo! was the most popular, or maybe AOL’s search engine.
- frollo 6y agoThis sounds like spy training from Burn Notice. Like, you have to get the source code of this program, from a guy who isn't at home right now and the whole budget of the operation is a just enough to buy a mug from our gift shop. Good luck Dave!
- GlenTheMachine 6y agoYou make it sound like that’s not how it usually is. I have bad news. That’s how it usually is.
- toomuchtodo 6y agoSometimes you don’t even get enough for a nice mug.
- jessaustin 6y agoWhere is the $60B/yr going? It's not all AWS. They could buy a lot of mugs for that.
- frollo 6y agoThey keep giving you the mug budget even after training?
- lakkal 6y agoI bought an NSA mug at the National Cryptologic Museum in 2000 or so. I was amused when it developed cracks and started leaking around the time Snowden was just getting into the news.
- avipars 6y agothis is from 2018
- meroes 6y agoSo, if his encryption was implemented perfectly the source code would do nothing to speed up decryption. Author admits this in the 2018 thread. If there was some bug or oversight, he gave the NSA a way to break into millions of machines. So should we conclude author doesn't trust his own software as advertised? Without even getting into the social engineering possibility. I don't see a way this looks good for the author.
- GlenTheMachine 6y agoI have been to the NSA gift shop, and they do sell the blue mugs there. But you have to have the right clearances to even get to where the gift shop is...
- _not_the_nsa_ 6y agoThis isn't true, unless it's changed in recent years. There's a gift shop at the Cryptologic museum on Ft. Meade. I've taken my folks there before, although I haven't worked there in almost a decade, so maybe it's not there anymore. There are gift shops inside the buildings though, but they sell the same stuff as the other one. You don't necessarily have to be cleared to get to those, you just have to have a reason to be in the building (i.e. interviewing) Now the CIA has a gift shop you can't get to without being able to get into the building. ;)
- GlenTheMachine 6y agoTouché. I’ve never been to the museum. There’s a gift shop inside NSA proper.
- MR4D 6y agoIf you read the article (you should - it's a good one and well written), then you should also read the comments. My favorite nugget from the comments: "I hope you’re keeping that mug in an opaque Faraday cage, well grounded."
- mhh__ 6y agohttps://en.wikipedia.org/wiki/The_Thing_(listening_device) https://en.wikipedia.org/wiki/The_Thing_(listening_device) Not realistic here but it has been done
- remcob 6y agoI know it's a joke but: Mugs have a tendency to be put in microwaves, making them a dangerous place for electronics. If you find yourself receiving a questionable mug, time for a glass of warm milk.
- marcosdumay 6y agoMicrowave ovens are not that horrible against bipolar transistors. They are completely lethal for MOS-FETs, but one can make electronics that survive it.
- remcob 6y agoDo you have more information on how to do that? Making things resilient against a kilowatt of non-ionizing microwave radiation seems challenging, in my experience it will burn the traces right off the PCB. A different game from the more common radiation-hardening where the concern is low power ionizing radiation.
- marcosdumay 6y agoEmbedding your conductive trails into a large non-conductive material helps, as does putting unrelated trails apart, and making them at the right size. Completely surrounding them with a ground plane helps too, but I have no idea how to include an antenna.
- LiamPa 6y agoMitnick?
- at-fates-hands 6y agoProbably not. Mitnick was just getting out of jail in 2000. I was thinking along the same lines though. Who were some high profile hackers that were on the FBI/NSA most wanted list? Max Butler maybe? Aleksey Ivanov?
- lb1lf 6y agoI drew the ire of our security services in a much dumber way sometime in the early nineties; after having seen Wargames, I set up my MicroVAX, rescued from a dumpster at the local bank, to ID as a DoD box whenever any of my friends dialled into it. A few weeks into this, I get a summons to get down to the local police station ASAP. The commissioner then gives me a good verbal beating for being such a stupid kid; apparently someone had dialled into the uVAX by mistake or wardialling, figured it was a real DoD machine, had reported the security breach and had gotten all sorts of gears moving. He wound up the sermon by telling me whoever had called him from the relevant department at military intelligence had chuckled and told him they kind of found it funny - but could he please get hold of me and tell me to stop doing it immediately, or else have my landline terminated?
- jessaustin 6y agoI can see why that would have been intimidating. With the decades of experience you've had since, do you think he could have gotten your landline terminated? What would be the legal argument?
- lb1lf 6y ago-I am quite convinced it was just meant to drive home the point that they were being serious about me changing the welcome message. I do not think there is any legal way they could have severed my (well, my parents') phone service over such an issue - but then again, I had no desire to have to explain to my parents why the phone was dead, and promptly replaced the welcome with something along the lines of "This computer is so secret the DoD told the op not to ID it!" (Which, while rather flippant, was definitely true... Ah, the joys of being fifteen!)
- jaywalk 6y agoI can't even imagine there is a valid legal argument. If somebody calls me, I can say whatever I want. If I want to answer the phone by saying "Department of Defense, how can I help you?" the First Amendment guarantees me the right to do that. Now, I certainly could not call other people and claim to be the Department of Defense. That's fraud. The same applies if I had done something like put up flyers claiming my phone number was related to the DoD or something like that. I'm not a lawyer, but that's how I see it.
- ebg13 6y agoI can't help but feel like the author sounds excessively credulous. I had to stop reading after he wrote "I could tell something big was up and there simply wasn’t time to debate the merits of handing over my source code to the NSA", because at that point my eyes rolled so hard they fell right out the back of my head. After I put them back in, I skipped down to the comments. I have a hard time not agreeing vehemently with the top comment on the post, which says: "You took time off your vacation to help the shadiest government agency on the planet do God-knows-what, as well as give them your IP for free. In addition, your ignorance and glee motivated you write this propaganda post, helping their cause, all for the price of a mug with a fancy sticker on it."
- moogleii 6y agoI'm also okay with the author's response, which is, for the record: "I’ve seen a lot of commentary like this. It was a different time back then. Just one year later the Towers came down. If in 2002 I got that same call, people would hate me for not cooperating. I didn’t invent the ciphers — those are public. I gave up nothing important. I’m okay with my decisions."
- starpilot 6y agoHN is so paranoid. All government is bad, anyone from a spy agency is some double/triple/quadruple agent who's actually a terrorist child soldier working for Facebook on the side.
- smolder 6y agoIs that surprising? They do stuff that is rather paranoia-inducing, like: illegitimate dragnet spying on our populous, breaking into networks to eavesdrop and gather secret keys/intel, backdooring random number generators, etc.
- droffel 6y agoIs it really paranoia if the evidence of mass surveillance and abuse of power is right in front of our eyes? It isn't 2012 anymore, Snowden kind of made it quite clear what's actually going on behind the curtain.
- bayouborne 6y agoMy first job in the early '80's was for a phototypesetter manufacturer. Logically, the NSA had one of our machines for in-house use. Whenever there was a issue with the machine I flew up to Virginia to look at it. My experience was roughly the same as the article's, super-nice people, all of us immediately on a first name (only) basis. The two kind of uniquely funny things about those visits was 1) that the machine (PDP-11 based) was kept in a small room with nothing in else it - a door opened into a room with the machine exactly in the center of the space. The other thing 2) which did make sense was the the core memory was always wiped w/a walking 1's and 0's paper-tape utility prior to me getting access to it.
- RandomBacon 6y agoMaybe it was just kept in that room while you worked on it. Perhaps that's the room where they move equipment that needs servicing so they only have to secure one route and room for technicians to use.
- gist 6y ago> But seriously, this laptop idiot was planning to blow up a building, or something equally as bad, but wasn’t smart enough or flush enough to pop for the $39.99 to step up to the maximum-strength encryption? Says the developer who could have been social engineered to give away what he had done by being rushed in a way that others would perhaps call 'not smart enough'. And where does the skill set of knowing about encryption come close to what someone needs to know in order to 'blow up a building'? Why would you expect that someone understands the difference or the risk? Or should? After all it's risky to begin with what they are doing. This is just another and different risk. Now the question is if you were the NSA and of course I have no clue how they operate but maybe it would have made more sense to send the local police to a house to deliver the message AND the other part 'call this number' etc. And who knows how that could have been fake for that matter (it all hinged on calling 411 as being definitive and/or someone not intercepting a legit call). Sure someone could social engineer the local police to show up (I would think that would be easy for someone who knows how they operate or with whoever is on shift at that time). Also the coffee cup is strange. Secretive agency but they send a gift as a thank you with their name so you have some kind of proof that allows you to detail how they operate and that they did this? Would make more sense that they got you to agree to not reveal they had requested the info not that they gave you some kind of bragging rights and story.
- TomMckenny 6y agoSince the source code could not help with decryption and the file was trivial to decrypt anyway, the NSA was either playing four dimensional chess that requires making a pointless midnight phone call or it's actually fallible. Rather than fairly justified suspicion of the NSA, we might want to apply Hanlon's razor in this case.
- Talanes 6y agoAgreed, the NSA is a large organization with many moving parts. If the guys who suddenly find themselves needing to break encryption have natural talents that lend themselves more toward tracking people down and talking things out of them, it makes perfect sense for them to start chasing some weird leads.
- AmericanChopper 6y agoI’ve had the pleasure of working in some organisations that had mountains of legacy applications that didn’t always have any source code. When I’ve had to fix bugs that involved those apps, reverse engineering them was always tedious and time consuming, and having the original engineers on hand to answer questions always sped things up. Regardless of the NSAs technical capabilities, it seems all he helped them do was something they could have done without his help, only faster.
- KMnO4 6y agoI think the NSA was rather asking him if there was a backdoor. A phone call will always be cheaper and faster than bruteforcing [current decade] cryptography.
- ahi 6y agoDave really does know everyone.
- g8oz 6y ago>>I probed again, this time about their capability at 40 bits; maybe that reduced level wasn’t such a State secret. But again, Dave was mum. I recall that 40 bit encrypted Word documents obtained from Al-Qaeda safe houses in Afghanistan after 9/11 were successfully cracked. It was reported in the media, so it was an open secret after that.
- KurtMueller 6y agoIsn't it always after midnight?
- grayed-down 6y agoShould have just driven to Ft Meade and had "Dave" meet you at the gate. It's only a 3 1/2 hour drive...
- dba7dba 6y agoAdam Savage (Myth Busters) once got a call from FBI because of a Star Wars movie prop (thermal detonator) he was making for a project. He meant to call his supervisor to leave a voicemail regarding the thermal detonator prop used in Star Wars, but apparently it was left at a wrong number. And that random person called FBI because he heard thermal detonator in the voicemail. Here's the link :) https://youtu.be/ZjpPgv9XtJA?t=1008 https://youtu.be/ZjpPgv9XtJA?t=1008
- valuearb 6y agoI would have demanded, at a minimum, to be told exactly how the NSA located me in exchange for my source code.
- moneysake 6y ago2018
- mesozoic 6y agoHanding stuff over to the supposed feds with no reasoning or warrant is not exactly something to be proud of.
- pensatoio 6y agoIt was pre-9/11, no? The world was a different place.