7 ms·
To summarise: the authors speculate that the NSA invested in a lot of resources into breaking Diffie-Hellman key exchange for certain 1024-bit primes. Just a fe
by hyper_reality 6y ago
To summarise: the authors speculate that the NSA invested in a lot of resources into breaking Diffie-Hellman key exchange for certain 1024-bit primes. Just a few hardcoded 1024-bit primes were used in the majority of VPN handshakes and a significant minority of HTTPS and SSH handshakes worldwide in 2015. This would give the NSA the ability to recover the shared symmetric key used in these encrypted communications, and therefore decrypt them.
Since then several protocols have shifted towards preferring Elliptic Curve Diffie-Hellman key exchange which doesn't suffer from the same attack, or at least using larger primes for plain DHKE (1536-bit and above). However I don't know the extent of this - a lot of VPNs at least are still using the old, weak DH keys.
- nimbius 6y agoBingo. Garbage primes that were either pushed by NIST to vendors or bribed to be included as default. The absolute arrogance of the authors in the Snowden papers in detailing the leak was probably the most powerful driver of things like dh parameters that roll every few days, and ed25519 that flat out rejected the nsa premise that primes were at all trustworthy Fast forward to today, and devs/cryptographers absolutely threw the nsa and cia out on their asses for their SPECK kernel argument hinging on the seemingly ironclad credibility of "it's classified." Corporate players will still sneak backdoors;it's what they do. But the real blow to the intelligence community is the loss of default trust and the active denial by the open source community.
- api 6y agoMy understanding is that it wasn't that the primes were bad but that they were hard coded, never changed, and the bit size was small enough to make attacks based on that practical. I'm on the fence about speck. It's so simple that there isn't much room in there for a back door, meaning that if there is one it implies that the NSA knows something we don't about ARX ciphers. If the NSA knows something we dont about ARX, then could they also know something about ChaCha?
- Taek 6y agoAll you need to know is one unique property to slip in a backdoor that nobody else may suspect for a long time. The NSA has given us good reason to question everything they release.
- jas- 6y agoHave you considered the adversary and their tactics?
- cryptonector 6y agoRotating DH groups periodically is difficult. SSHv2, for example, has support for this. It takes a lot of computation to generate new groups, but then how do the client and server agree on a group? Well, the server tells the client, and the client has to like it -- i.e., the client has to trust the server's group. This isn't better than just having a bigger nothing-up-my-sleeves group to begin with. That, ultimately, has been the solution the community landed at: nothing-up-my-sleeve curves for ECDH and EdDSA. The nothing-up-my-sleeve part is all about setting / agreeing to obvious and hard guidelines for generating and selecting curves before doing the selection, then you can see that a curve was generated and selected without any hidden agendas. We have several of these now that are generally thought to be secure, though, of course, it's hard to say for sure. It's a pretty good outcome.
- ustolemyname 6y agoIf the client doesn't trust the server, the crypto protocol is a little irrelevant. I otherwise agree that we (ostensibly) are in a better place now with pre-defined curves.
- dcow 6y ago> If the client doesn't trust the server, the crypto protocol is a little irrelevant. What? No. The protocol is the only thing that is relevant. Peers don't generally trust each other a priori at all. They trust the protocol. If they can authenticate each other within the bounds of the protocol then they trust each other. If one party no has reason to distrust a certain protocol, then it should not be used as a basis for establishing trust. If the two peers can't agree on a protocol: stalemate. If I compromise your server and only serve weak protocols a responsible client won't authenticate me whereas a vulnerable client would take my word that my protocol is secure.
- StanislavPetrov 6y ago>But the real blow to the intelligence community is the loss of default trust and the active denial by the open source community. Their loss is our gain.
- nuker 6y ago> Since then several protocols have shifted towards preferring Elliptic Curve Diffie-Hellman key exchange which doesn't suffer from the same attack .. There was a strange twist in this story: "Then, in August of this year, NSA freaked out.". And this guy is a professional. https://blog.cryptographyengineering.com/2015/10/22/a-riddle-wrapped-in-curve/ https://blog.cryptographyengineering.com/2015/10/22/a-riddle...
- ChristianBundy 6y agoInteresting. Is it possible to tell which Diffie-Hellman primes are used on an HTTPS connection? Back in 2016 I noticed that OpenSSL was using the wrong primes (https://github.com/openssl/openssl/commit/fb015ca6f05e09b11a3932f89d25bae697c8af1e https://github.com/openssl/openssl/commit/fb015ca6f05e09b11a...) and since then I've been very curious to know how prevalent the previous DH primes are.