6 ms·
Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all y
by JunkDNA 13y ago
Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have really clammed up the past few days are the telecoms in all this.
- jonknee 13y agoIt has been well known that they already do the beam splitting portion, so it's really just up to the keys.
- commandar 13y agoIf anyone's not familiar, information about that began to leak in 2006. http://en.wikipedia.org/wiki/Room_641A http://en.wikipedia.org/wiki/Room_641A
- est 13y agoThat's why IMHO secret sharing[1] algorithms are so important We store only parity of data in one data center, and some in another on a different continent. Any data intercepted or lost does not damage the integrity of the whole, plus this makes ISP can not discriminate raw binary data. [1] http://en.wikipedia.org/wiki/Secret_sharing http://en.wikipedia.org/wiki/Secret_sharing, invented by Adi Shamir, the S of RSA
- jcampbell1 13y agoThis is exactly the conclusion I came to. My guess is they have the SSL/TLS keys. That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.
- kalmi10 13y agoThe linked quora answer (from the co-author of Firesheep) says that even in that case one can't launch a passive man in the middle attack if perfect forward secrecy is used. Google.com uses Diffie–Hellman key exchange which provides perfect forward secrecy. So... If I understand everything correctly, it should be impossible to decrypt passively captured HTTPS traffic to/from google.com. http://www.quora.com/SSL-Secure-Sockets-Layer/Is-it-ever-possible-to-decrypt-passively-sniffed-SSL-TLS-traffic/answer/Ian-Gallagher-2 http://www.quora.com/SSL-Secure-Sockets-Layer/Is-it-ever-pos... Could someone more knowledgeable confirm this?
- herf 13y agoactually everyone seems to have switched to the "fast" SSL ciphers instead - only dropbox defaults to DHE: > openssl s_client -connect google.com:443 RC4-SHA > openssl s_client -connect dropbox.com:443 DHE-RSA-AES256-SHA Again, this is usually done for speed, but all of the companies on the list are using "fast" SSL/TLS ciphers rather than more secure ones.
- zaroth 13y agoThanks for this. "Dropbox coming soon" indeed.
- kalmi10 13y agoI not really an expert in this at all, but we were not discussing ciphers, but key exchange methods. I open google.com in Chrome, click on lockpad icon, go to the second tab, and it says: Key exchange method: ECDHE_ECDSA Some googling turns up that: "ECDHE-ECDSA provide perfect forward secrecy" http://nmav.gnutls.org/2011/12/price-to-pay-for-perfect-forward.html http://nmav.gnutls.org/2011/12/price-to-pay-for-perfect-forw...
- herf 13y agoyes it appears Google has PFS for Chrome/Firefox: http://www.imperialviolet.org/2011/11/22/forwardsecret.html http://www.imperialviolet.org/2011/11/22/forwardsecret.html
- andreyf 13y agoEven without keys, the metadata from the packet headers and traffic analysis can be quite useful. Could you link to tptacek's comments you're referring to?
- kalmi10 13y agoIt's gone.
- jcampbell1 13y ago> Could you link to tptacek's comments you're referring to? https://news.ycombinator.com/item?id=5842915 https://news.ycombinator.com/item?id=5842915 I was being a bit devious. I am just so tired of tptacek dismissing stuff I say with asinine arguments and then watching my comment get downvoted to hell.
- lifeguard 13y agoSSL broken by design: http://cryptome.org/0005/ssl-broken.htm http://cryptome.org/0005/ssl-broken.htm
- nullc 13y agoIf you hold the theory that the traffic is being intercepted and the parties have compromised the TLS keys: The test for complicity is obvious: failing to rotate out the TLS keys, failure to HSTS, and failure to switch to EDH ciphersuites everywhere. These are all moderately 'cheap' steps if you believe you're being compromised in this manner.
- JunkDNA 13y agoIndeed, I'm highly inclined to defer to tptacek's experience here.
- alyx 13y agoOk so they split and copy all the packets, nobody else is concerned with the complexity of tagging, filtering, rebuilding and contextualizing this conceptual volume of packet data? Beam splitters are not enough, they would need something to interpret this traffic. Something is missing here.
- venomsnake 13y agoLike the huge number crunching center in utah?
- deleted 13y ago[deleted]
- 7952 13y agoThen you just process basic metadata. Size, IP source, destination, timing, and statistical analysis of the binary. Assuming that they have ways of converting IP to an identity that information alone would be hugely revealing. In fact basic metadata is what they have admitted to recording.