4 ms·
I'm surprised more people haven't read between the lines: the NSA is in possession of quantum computers and interference based decryption is probably already in
by IBCNU 13y ago
I'm surprised more people haven't read between the lines: the NSA is in possession of quantum computers and interference based decryption is probably already in standard use. Insiders also have dropped hints the Tor networks is, in fact, a trojan horse. We basically have two * extreme * options: 1) a trusted courier with a sealed envelope (don't underestimate this Game of Thrones like scenario as the US Military defeated itself in the largest wargame in the gulf by using courier, sealed envelopes, and motorbikes) and 2) quantum cryptographic communication. The latter is still only the realm of university labs and down at LANL but I read a paper which stated it's physically possible to pass keys along ethernet cable, but all parties need a device which acts as a gate. This in turn opens up Alice and Bob to traditional decryption methods if they're not air gapped from the web.
- deleted 13y ago[deleted]
- gibybo 13y agoQuantum computers do not allow you to break all public key cryptography, they only allow you to break the common forms in use today. For some example algorithms that are not vulnerable to quantum computers, see: http://en.wikipedia.org/wiki/Post-quantum_cryptography http://en.wikipedia.org/wiki/Post-quantum_cryptography Also, it would be quite remarkable if the NSA had quantum computers capable of breaking 2048 RSA or PGP keys. Possible, but extremely unlikely.
- IBCNU 13y agoAh, thank you for sharing this. I agree it's unlikely but given some of the * cough * political events as of late it seems more and more likely. Taking off my aluminum foil hat now...
- __alexs 13y ago> Possible, but extremely unlikely. It doesn't seem improbable that the NSA are already recording encrypted communications because they are cheap to store and and have a reasonable chance of being broken in the future. They don't even need to break the algorithm for that data to become useful. In particular SSL encrypted web traffic of sites they suspect they might physically raid (or have cooperation with) in future seem like an excellent target. Although hopefully the increasing awareness and deployment of perfect forward secrecy should help with that attack.
- kimlelly 13y agoExactly, the only real solution I see is to break up the government into many small governments, with small budgets, and controlled by the people. Not the other way round.
- bradleyjg 13y agoIt's very unlikely. Just look at who they are hiring, still mostly mathematicians. Quantum computing is mostly physics, chemistry, and a lot of painstaking engineering. Unless they are secretly borrowing people hired on at e.g. the DoE, I just don't see it.
- abrichr 13y agoConsider that In-Q-Tel, the VC firm whose sole purpose is keeping US intelligence agencies ahead of the game, [1] is one of the primary investors [2] into D-Wave, the first company to create a commercially viable quantum computer. [3] [1] http://en.wikipedia.org/wiki/In-Q-Tel http://en.wikipedia.org/wiki/In-Q-Tel [2] http://www.dwavesys.com/en/pressreleases.html#investment_2012 http://www.dwavesys.com/en/pressreleases.html#investment_201... [3] http://en.wikipedia.org/wiki/D-Wave_Systems http://en.wikipedia.org/wiki/D-Wave_Systems
- bradleyjg 13y agoWhich wouldn't make a lot of sense if they already had a generation of quantum computers with enough qubits to brute force RSA-1024.
- AJ007 13y agoGoogle moving to 2048-bit is probably an indicator of what they see as vulnerable. Because of the current developments int the press this challenge is being viewed in the context of the NSA, but other foreign intelligence services also pose a threat to user data.
- skue 13y ago> Quantum computers do not allow you to break all public key cryptography, they only allow you to break the common forms in use today. True, but it's the public key cryptography in use today that I'm concerned with!
- clicks 13y agoConcerning whether Tor networks might or might not be compromised trojan horses: Reason why it might be: 80% of the Tor Project's $2M annual budget comes from the United States government (says wiki), this perhaps implies that the US gov. has some influence or control over what goes into Tor, and so if there's anyone who knows how to identify Tor users, it's the US gov. Reason why it might not be: Snowden had Tor stickers on his laptop, that sort of lends credence to the fact that NSA doesn't have it down yet on how to id Tor users and it is still a good and reliable anonymity tool.
- lambada 13y agoYou missed the biggest reason why it probably isn't: Tor is Open Source. The chance of any deliberate Trojan Horse being added in such a high profile project is virtually nil.
- skue 13y agoHe was referring to the possibility that the NSA can already crack the underlying encryption algorithms via quantum computing, etc. If that's the case, being open source and correctly implementing the encryption algorithms is moot.
- dfc 13y agoLOL. You offer the presence of stickers on a laptop as proof of anything. What a joke. Perhaps the govt money is because the gov needs cover traffic just like everyone else. Or perhaps the feds have a vested interest in providing a secure comm channel or dissidents in unfriendly countries. I need to reinstate my moratorium on reading HN prism discussions. I can't wait to tell people: "Its not the academic literature or availability of the source code that makes me confident in tor's security, its the stickers I saw on a laptop"
- mpyne 13y agoDidn't we just see a story posted to HN about how those who believe in one conspiracy theory are likely to believe in others? They make the evidence fit their worldview, not the other way around.
- lifeformed 13y agoQuantum decryption sounds expensive and time consuming, so they wouldn't be able to apply it to everything. As long as you have something basic going it might be enough deterrent to keep you out of the light. You just need a better bike lock than the other bikes have on the rack. I guess if you're being targeted specifically then there's not much you can do though. Also, do you have more info about the courier/motorbike thing? It sounds interesting.
- dfc 13y agoPlease show me where the hints about Tor being a trojan horse. That is not a challenge, I am really interested. If these allegations are true they represent a serious reputation risk to the EFF.
- kgo 13y agoOkay, so lets assume that the NSA has quantum computers that can decrypt RSA and ECC with ease. They would have to assume another state funded effort by someone like China could do so as well. Then the NSA wouldn't issue recommendations that the US Government itself use these encryption methods for TOP SECRET and CONFIDENTIAL documents.
- mpyne 13y agoThe military exercise in the gulf that you mention is the near-equivalent of what Kirk did in the Kobayashi Maru scenario, so I'd be careful with how much you draw from that inference. There are certainly lessons to learn, don't get me wrong, but unless you have the details on the war game and the training to understand what happened and why then you're guessing just as much as anyone else is. Besides, the government can easily get human informants; there's no such thing as a truly trusted courier system.