5 ms·
I think so. Yes. IIRC, the first time I saw this leaked was a combo leak by a Navy Seal and a member of the Executive. The Seal leaked that they powered down Bi
by vabmit 13y ago
I think so. Yes. IIRC, the first time I saw this leaked was a combo leak by a Navy Seal and a member of the Executive. The Seal leaked that they powered down Bin Laden's computers to take his hard drives after they shot him. The Executive member said that the drives were encrypted and it would take a few days to get the data. Jihadis are known to use a custom version of PGP with 2048bit RSA keys. They either used that, a COTS drive encryption program (unlikely), or reviewed and adapted an open source drive encryption program. In either of the likely scenarios they would have been using 2048bit RSA. Therefor, it is highly likely (due to the NSA having target motivation even if the drives weren't well encrypted) that the smooth barrier does not exist and the NSA can factor 2048bit RSA in a hours to days scale time frame.
Also, it was leaked that NSA TAO had a 70%+ success rate compromising Chinese systems. Even with the tech companies giving them secret zero days for an extended period of time, anyone that has been a blackhat knows they're not getting to a 70% success rate through exploits. Therefor, it's highly likely they can decrypt VPN/SSH (TLS) traffic encrypted with AES256/RC4-128/3DES and/or the RSA/EC public cryptography used. As you noted the leaked slide seems to indicate that.
- jstalin 13y agoGood info. Do you have any sources online you can point to?
- vabmit 13y agoNavy Seal Leak: _No_Easy_Day_ available from Amazon: http://www.amazon.com/No-Easy-Day-Firsthand-ebook/dp/B008MG1E4A/ http://www.amazon.com/No-Easy-Day-Firsthand-ebook/dp/B008MG1... (Notice how he makes no mention of ISA even being there, or doing any SSE). I don't recall the source of the Executive comment. It was kind of buried in a news piece with a broad focus that I read. I'll look for it. Unfortunately, I can't recall the exact language to do a good search and find it. Sorry. But, here they are saying they have it, it's encrypted, and they can get it in "weeks or months" (despite the large number of drives/filesystems with presumably different keys): http://www.cbsnews.com/8301-31727_162-20059825-10391695.html http://www.cbsnews.com/8301-31727_162-20059825-10391695.html The Executive and Legislature couldn't keep something secret to save their lives. And, JSOC leaks like a fucking sieve. If I can't find that particular leak on the web, I'm sure there will be another one soon with the same info. Every guy likes to talk to pretty news reporters and seem important. Claimed 75%+ success rate attacking Chinese systems: http://www.scmp.com/news/hong-kong/article/1260306/edward-snowden-classified-us-data-shows-hong-kong-hacking-targets http://www.scmp.com/news/hong-kong/article/1260306/edward-sn... Asrar al-Mujahideen (the Jihadi PGP fork w/ 2048bit RSA): http://www.rbijou.com/2013/03/18/an-overview-of-jihadist-encryption-programs/ http://www.rbijou.com/2013/03/18/an-overview-of-jihadist-enc... The news coverage sucks something awful. The thing is having enough knowledge of mil/ir/tech/math to put all the leaks together.
- MAGZine 13y agoBreaking RSA is just a matter of managing to factor prime numbers faster than anyone else, isn't it? Unless if there is some sort of oversight inside the RSA algorithm that allows the encryption to be broken easier. Do you have more information on the smooth barrier? I did a quick google but didn't see much relevant.
- vabmit 13y agoAs the size of a semiprime increases, the number of smooth numbers that can be discovered (the "yield") by the GNFS with polynomials selected with academically known optimal polynomial selection algorithms decreases. With a reduction in smooth candidates the GNFS sieve operation can be wholly unsuccessful. If a smooth barrier exists (such as a semiprime size where smooth yield becomes deficient) factoring time degenerates from the GNFS improved rate to old school factoring rates due to the need to pivot. Yield decay has been observed <2048bit. If 2048bit is easily factorable for the NSA, no barrier challenge is suggested.
- vabmit 13y agoOr, they have a better (probably non-Ring) factoring method. I can't conceptualize what that might be, though.
- nulldevnull 13y agoI'm not sure it's relevant whether the b-smooth barrier exists of not, since that assume use of NFS. There's a reason the NSA is pushing folks to use Suite B ciphers including Elliptic Curve along specific curves. It's not unreasonable to think that the NSA mathematicians have proven some relationship between EC and prime number theory in general. There is some public domain work on this topic. See [https://en.wikipedia.org/wiki/Lenstra_elliptic_curve_factorization https://en.wikipedia.org/wiki/Lenstra_elliptic_curve_factori...]. This might help explain in part the NSA's desire for large memory vector supercomputers going back to the 1990s over distributed memory MP systems.
- vabmit 13y ago
- uptown 13y agoI know nothing about this stuff, so apologies for my naiveté, but what technical barriers prevent us from changing from 2048 bit encryption to something of a much much greater magnitude? 2,048,000 bit (or whatever).
- vabmit 13y agoRNG/PRNG output quality and the internals of the algorithms.