4 ms·
Group (1) also wants their adversaries to feel confident that the encryption promoted by (2) is secure, so that they use it to communicate candidly. It that re
by rhplus 2y ago
Group (1) also wants their adversaries to feel confident that the encryption promoted by (2) is secure, so that they use it to communicate candidly.
It that respect, (2) is just a mouthpiece for (1), provided there’s a back door or vulnerability that only (1) knows about.
- chefandy 2y ago> provided there’s a back door or vulnerability that only (1) knows about. Do you have any examples from existing tools, e.g. Tor, for which that's true? Tor's been around a long time-- surely something would have surfaced at this point, but I haven't really paid attention to it.
- inhumantsar 2y agoTor is an interesting example. A number of attacks are made possible by monitoring Tor exit node traffic, especially at the scale nation states can bring to the table. https://en.m.wikipedia.org/wiki/Tor_(network)#Exit_node_eavesdropping https://en.m.wikipedia.org/wiki/Tor_(network)#Exit_node_eave...
- chefandy 2y agoSure-- but that structural shortcoming has been a thing for a long time-- I wouldn't consider it a secret vulnerability that Tor was facilitating for US intelligence, as was initially implicated. I'm not in the field, but it seems like it would be way more useful for law enforcement working against criminals naive enough to think tor would be a one-stop op-sec solution (e.g. ANOM) than for nation-state-level counterintelligence.
- Jerrrrrrry 2y agoI'm not in the field, but it seems like it would be way more useful for law enforcement working against criminals naive enough to think tor would be a one-stop op-sec solution (e.g. ANOM) than for nation-state-level counterintelligence. you must have noise to hide a signal
- seanlinehan 2y agohttps://blog.cloudflare.com/how-the-nsa-may-have-put-a-backdoor-in-rsas-cryptography-a-technical-primer/ https://blog.cloudflare.com/how-the-nsa-may-have-put-a-backd...
- chefandy 2y agoI think that's the most solid example.
- throwaway201606 2y agoMethods provide the highest leverage if you “own” the common element used across the most system components ie the lowest common denominator. Saying it another way, don’t attack platforms, tools and channels, attack protocols since they are used across platforms, tools and channels To this end, some examples: Attack on 1) encryption - RSA backdoor https://blog.cloudflare.com/how-the-nsa-may-have-put-a-backdoor-in-rsas-cryptography-a-technical-primer/ https://blog.cloudflare.com/how-the-nsa-may-have-put-a-backd... 2) hardware - Processor Backdoor https://forums.whonix.org/t/expert-claims-nsa-has-backdoors-in-intel-amd-processors/12573 https://forums.whonix.org/t/expert-claims-nsa-has-backdoors-... (this link is specifically great for this subject as it lists more than 10 different attack / compromise programs that are being run - with quite a few of them being protocol attacks - in the comments section ) 3) networking - network gear firmware backdoor https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a https://www.cisa.gov/news-events/cybersecurity-advisories/aa...
- antishatter 2y agoUk gov selling or giving enigma away knowing they had broken it
- yencabulator 2y agoUK government selling a German product / war gadget? That doesn't make sense.
- natpalmer1776 2y agoIf I remember correctly, Tor has been broken due to 'threat actors' owning enough exit nodes to successfully de-anonymize traffic given enough time and information. pretty sure this is hearsay from a message board, but I can't for the life of me recall where or when I heard this.
- ants_everywhere 2y agoCarnegie Mellon has worked on this https://www.theverge.com/2015/11/11/9719098/fbi-reportedly-paid-1-million-carnegie-mellon-tor https://www.theverge.com/2015/11/11/9719098/fbi-reportedly-p...
- OutOfHere 2y agoThere is no real evidence that DARPA is morally compromised by the NSA in any way. This is unlike for NIST where there is evidence of such compromise. Moreover, it is not DARPA doing the development. They fund other entities to do it.
- hangonhn 2y ago> There is no real evidence that DARPA is morally compromised by the NSA in any way. This is unlike for NIST where there is evidence of such compromise. Wait. Can you clarify this? I know that NIST's standards were compromised by the NSA or at least there is evidence of it. However, this is not necessarily the same as being morally compromised. The story I've read is that the NIST was taken for a ride by the NSA but weren't in bed with them. Is the narrative I have incorrect?
- qchris 2y agoIf you haven't seen it already, there was a post a couple of years ago here that got some traction on this subject, in context of a FOIA-related lawsuit filing by a (I'm to understand) well-regarded cryptologist: https://news.ycombinator.com/item?id=32360533 https://news.ycombinator.com/item?id=32360533
- hangonhn 2y agoThat's really informative. Thank you! Thank you!
- deleted 2y ago[deleted]