2 ms·
The NSA (and FBI et al.) have a pretty workable solution for strong encryption on the wire - they attack the client. The client computer (or mobile) is pretty m
by trotsky 15y ago
The NSA (and FBI et al.) have a pretty workable solution for strong encryption on the wire - they attack the client. The client computer (or mobile) is pretty much full of holes, if someone wants in they'll get in, and sooner rather than later.
Related, the Germans seemed to have commissioned a trojan to monitor skype and tls traffic on the endpoint: http://www.wired.com/threatlevel/2008/01/leaked-document/ http://www.wired.com/threatlevel/2008/01/leaked-document/
Somewhat related, the FBI routinely uses flaws to install CIPAV: http://www.wired.com/politics/law/news/2007/07/fbi_spyware http://www.wired.com/politics/law/news/2007/07/fbi_spyware
Granted, none of this enables the wholesale monitoring of skype communications. Practically, even if the NSA had access to individual signing keys or some kind of side channel leakage it probably wouldn't be getting used en masse. The computation requirements of decrypting all traffic are likely significant, and operational security would discourage the wide use of a closely held leakage bug in fear of disclosure like happened with the domestic wiretapping scandal.
As an aside, I found it quite amusing to read "For example, a person in Germany, talking to a person in Russia using land-line phones would previously have been out of reach for NSA" - ultraparanoid? Pshaw.