4 ms·
My conspiracy theory is that AES 256 has been cracked by NSA/CIA but they just shut up about it so everyone feels safe.
by shmde 3y ago
My conspiracy theory is that AES 256 has been cracked by NSA/CIA but they just shut up about it so everyone feels safe.
- slackfan 3y agoTry to implement out-of-spec authentication and watch your logs fill up with bots.
- sunk1st 3y agoWhat’s the implication? Sorry. I can see it going either way.
- sandworm101 3y agoIf AES is cracked by the NSA then they know that there is a fault. They must therefore assume that others could know about it and might exploit that fault, either now or in the future. A massive amount of American infrastructure, including intelligence services, relies upon AES not having such holes. They wouldn't sit on such information.
- TrapLord_Rhodo 3y agoThe government is known to horde and deploy zero days for surveillance... That was part of the snowden leak. google/Ask chatgpt about Tailored Access Operations revealed under the snowden papers.
- AnimalMuppet 3y agoThey wouldn't go public with such information. They would very quietly get the most important parts moved off of it, quickly, with as little noise as possible.
- sandworm101 3y agoMoving any part of the US government off of AES would be noticed. The NSA doesn't send IT people to do installs. They set standards which are then incorporated into products by outside contractors selling to government agencies. Any attempted migration away from AES would be news here on HN within hours.
- c0pium 3y agoAs an example of one such standard which was recently updated and still includes AES256, https://en.m.wikipedia.org/wiki/Commercial_National_Security_Algorithm_Suite https://en.m.wikipedia.org/wiki/Commercial_National_Security...
- tptacek 3y agoThat’s not the point: if there’s a grave flaw in AES, other countries can find it too.
- 4bpp 3y agoIf the flaw in AES is subtle enough, they may be (justifiedly?) convinced that nobody else's capabilities will suffice to discover and/or exploit it - or, at least, that they have enough of a grasp of what everyone else is doing that no other actor could discover the flaw without the NSA finding out about this.
- jongjong 3y agoIt seems reasonable that they would set a self-imposed expiry date on exploits then get them patched quietly.
- deleted 3y ago[deleted]
- c0pium 3y agoEncryption bugs are fundamentally different than other exploits; if I send traffic protected by encryption then it needs to remain encrypted as long as the information needs to be secret. With national security that can be decades.
- mike_d 3y ago> including intelligence services, relies upon AES not having such holes. They wouldn't sit on such information. The NSA uses a completely different set of algorithms called Suite A. They don't use AES for exactly this reason.
- The_Colonel 3y ago> Suite A will be used for the protection of some categories of especially sensitive information (a small percentage of the overall national security-related information assurance market) From https://en.wikipedia.org/wiki/NSA_Suite_A_Cryptography https://en.wikipedia.org/wiki/NSA_Suite_A_Cryptography
- mike_d 3y ago> a small percentage of the overall national security-related information assurance market That quote does not exist in the one Wikipedia citation. I am not sure where they got it. Any time data flows from one physical location to another it is encrypted with Suite A algorithms, which is arguably where it matters the most.
- sandworm101 3y agoNSA is but one of maybe a dozen US intelligence agencies.
- mike_d 3y ago18 to be exact, but NSA houses the Cryptographic CoE and sets the relevant standards for the entire IC.
- solsane 3y agohttps://en.wikipedia.org/wiki/Multiprogram_Research_Facility https://en.wikipedia.org/wiki/Multiprogram_Research_Facility
- lmm 3y agoIf they can find a flaw in AES 256, others can too. My theory is they've got a backdoor in the iPhone hardware random number generator. It's the most obvious high-value target, it's inherently almost undetectable (the output of a CSPRNG is indistinguishable from real random numbers), and you can keep crypto researchers busy with fights about whose cryptosystem is best, safe in the knowledge that it doesn't matter what they come up with, they were owned from the start.
- bmc7505 3y agoThey would be foolish not to at least try, either by intercepting entropy-supplying syscalls or compromising the hardware directly. RNG attacks are easy to design and nearly impossible to detect. https://en.wikipedia.org/wiki/Yao%27s_test https://en.wikipedia.org/wiki/Yao%27s_test