8 ms·
The history in this blog post is excellently researched on the topic of NSA and NIST cryptographic sabotage. It presents some hard won truths that many are unco
by throwaway654329 4y ago
The history in this blog post is excellently researched on the topic of NSA and NIST cryptographic sabotage. It presents some hard won truths that many are uncomfortable to discuss, let alone to actively resist.
The author of the blog post is also well known for designing and releasing many cryptographic systems as free software. There is a good chance that your TLS connections are secured by some of these designs.
One of his previous lawsuits was critical to practically protecting free speech during the First Crypto War: https://en.m.wikipedia.org/wiki/Bernstein_v._United_States https://en.m.wikipedia.org/wiki/Bernstein_v._United_States
I hope he wins.
- aliqot 4y agoGiven his track record, and the actual meat of this suit, I think he has a good chance. - He is an expert in the domain - He made a lawful request - He believes he's experiencing an obstruction of his rights I don't see anything egregious here. Being critical of your government is a protected right for USA. Everyone gets a moment to state their case if they'd like to make an accusation. Suing sounds offensive, but that is the official process for submitting an issue that a government can understand and address. I'm seeing some comments here that seem aghast at the audacity to accuse the government at your own peril, and it shows an ignorance of history.
- maerF0x0 4y agoI'd add * and it's been 20 yrs since the 9/11 attacks which predicated a lot of the more recent dragnets
- feet 4y agoI'll also add Which have not prevented anything and instead are used in parallel construction to go after Americans
- gene91 4y agoI don’t like the collateral damages of many policies. But it’s not fair to say that the policies “have not prevented anything” because we simply don’t know. The policies could have stopped in-progress evil acts (but they were never revealed to the public for intel reasons) or prevented attempts of an evil acts (well, nothing happened, nothing to report).
- feet 4y agoI find it rather funny that we know about the parallel construction which they attempt to keep hidden, yet don't know about any successful preventions. I would assume they would at least want people to know if a program was a success. To me, the lack of information speaks volumes This is on top of all the entrapment that we also know about, performed by the FBI and associated informants on Islamic/Muslim communities The purpose of a system is what it does
- sweetbitter 4y agoConsidering that they do not obey the law, if they had actually stopped any terrorists we would be hearing all about it from "anonymous leakers" by now.
- deleted 4y ago[deleted]
- maerF0x0 4y agoIt also could have stopped the Gods from smiting us all, but there's no evidence that it has. This article[1] is a good start at realizing the costs outweigh the benefits. There's little or no evidence of good caused, but plenty of evidence of harms caused. [1]: https://www.eff.org/deeplinks/2014/06/top-5-claims-defenders-nsa-have-stop-making-remain-credible https://www.eff.org/deeplinks/2014/06/top-5-claims-defenders...
- daniel-cussen 4y agoThere is evidence of that, in fact. There were many serious terrorist attacks in Europe, like in Spain's subway (300 dead) and Frankfurt, in the aftermath of 9/11 and other...uh howmy gonna say this...other stuff, the Spanish terrorist attacks were done by Basque nationalists or such, not Muslims. So there's your control group, Europe.
- kevin_thibedeau 4y agoThe dragnets existed before 9/11. That just gave justification for even more funding.
- throwaway654329 4y agoWhich programs do you mean specifically? We know the nature of the mass surveillance changed and expanded immensely after 9/11 in a major way, especially domestically.
- KennyBlanken 4y agoEvery piece of mail that passes through a high-speed sorting machine is scanned, front and back, OCR'd, and stored - as far as we know, indefinitely. That's how they deliver the "what's coming in your mailbox" images you can sign up to receive via email. Those images very often show the contents of the envelope clearly enough to recognize and even read the contents, which I'm quite positive isn't an accident. The USPS is literally reading and storing at least part of nearly every letter mailed in the United States. The USPS inspectors have a long history of being used as a morality enforcement agency, so yes, this should be of concern.
- greyface- 4y agoSome more details: https://en.wikipedia.org/wiki/Mail_Isolation_Control_and_Tracking https://en.wikipedia.org/wiki/Mail_Isolation_Control_and_Tra...
- UpstandingUser 4y agoI've heard rumors that this was going on for a long time before it's been publicly acknowledged to have -- before OCR should have been able to handle that sort of variety of handwriting (reliably), let alone at scale. Like a snail-mail version of the NSA metadata collection program.
- nuclearnice1 4y ago
- newsclues 4y agoTrump Card: National Security
- CaliforniaKarl 4y agoThat's a valid reason (specifically, 1.4(g) listed at https://www.archives.gov/declassification/iscap/redaction-codes.html https://www.archives.gov/declassification/iscap/redaction-co...). And while the NIST returning such a response is possible, it goes against the commitment to transparency. But still, that requires a response, and there hasn't been one.
- deleted 4y ago[deleted]
- Kubuxu 4y ago"National Security" response implies cooperation with NSA and destroys NIST's credibility.
- trasz 4y ago>Being critical of your government is a protected right for USA. Everyone gets a moment to state their case if they'd like to make an accusation. Unless a kangaroo “FISA court” says you can’t - in which case you’re screwed, and can’t even tell anyone about the “sentence” if it included a gag order. Still better than getting droned I suppose.
- nimbius 4y agothe author was also part of the Linux kernel SPECK cipher talks that broke down in 2013 due to the nsa's stonewalling and hand waving for technical data and explanations. nsa speck was never adopted. https://en.m.wikipedia.org/wiki/Speck_(cipher) https://en.m.wikipedia.org/wiki/Speck_(cipher)
- ddingus 4y agoInteresting read!
- gonehome 4y agoI remember reading about this in Steven Levy's crypto and elsewhere, there was a lot of internal arguing about lots of this stuff at the time and people had different opinions. I remember that some of the suggested changes from NSA shared with IBM were actually stronger against a cryptanalysis attack on DES that was not yet publicly known (though at the the time people suspected they were suggesting this because it was weaker, the attack only became publicly known later). I tried to find the specific info about this, but can't remember the details well enough. Edit: I think it was this: https://en.wikipedia.org/wiki/Differential_cryptanalysis https://en.wikipedia.org/wiki/Differential_cryptanalysis They also did intentionally weaken a standard separately from that and all the arguing about 'munitions export' intentionally requiring weak keys etc. - all the 90s cryptowar stuff that mostly ended after the clipper chip failure. They also worked with IBM on DES, but some people internally at NSA were upset that they shared this after the fact. The history is a lot more mixed with a lot of people arguing about what the right thing to do is and no general consensus on a lot of this stuff.
- api 4y ago> I remember that some of the suggested changes from NSA shared with IBM were actually stronger against a cryptanalysis attack on DES that was not yet publicly known So we have that and other examples of NSA apparently strengthening crypto, then we have the dual-EC debacle and some of the info in the Snowden leaks showing that they've tried to weaken it. I feel like any talk about NSA influence on NIST PQ or other current algorithm development is just speculation unless someone can turn up actual evidence one way or another. I can think of reasons the NSA would try to strengthen it and reasons they might try to weaken it, and they've done both in the past. You can drive yourself nuts constructing infinitely recursive what-if theories.
- gonehome 4y agoI think it's just both. It's a giant organization of people arguing in favor of different things at different times over its history, I'd guess there's disagreement internally. Some arguing it's critical to secure encryption (I agree with this camp), others wanting to be able to break it for offense reasons despite the problems that causes. Since we only see the occasional stuff that's unclassified we don't really know the details and those who do can't share them.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- matthewmcg 4y agoRight came here to make the same point. The first lawsuit alluded to in the blog post title resulted in an important holding that source code can be protected free expression.