5 ms·
I'd say "switch to ECC", but the fact that the NSA are strong proponents of it rather makes one wonder why.
by madaxe 13y ago
I'd say "switch to ECC", but the fact that the NSA are strong proponents of it rather makes one wonder why.
- jloughry 13y agoNSA is really two organizations in one. One side of the house is tasked with Information Assurance (IA), i.e., protecting the U.S. government's information. The other side of the house is tasked with interception. Cryptanalysis folks at NSA straddle both activities, necessarily.
- madaxe 13y agoSure, but I just can't understand why they would be recommending to the general public that they improve their crypto, as it goes directly against the NSA's interests.
- LoganCale 13y agoNow that they are in the domestic surveillance game, they have contradictory interests. They were originally intended to jointly ensure the security of U.S. interests while breaking the security of everyone else. So it made sense to advocate improved crypto for, say, U.S. businesses, because that would benefit the U.S. in general by preventing the intelligence agencies of other countries from stealing U.S. corporate secrets.
- devcpp 13y agoTo take it further, I suppose they want to protect US citizens, companies and government from crypto attacks while using US laws to snoop on them easily. That way, they prevent foreign threats by making it very hard for everyone to break any system in the US. And on the other hand, they can still read everything by issuing subpoenas to any company and ISP they feel like (with borderline constitutional legality in some cases).
- Locke1689 13y agoBecause the NSA's task is twofold: protect US govt interests by conducting SIGINT on foreign govts, and protect US govt interest by keeping US company trade secrets and infrastructure secure. Worse than the NSA being unable to break network traffic is foreign govts being able to break US network traffic.
- B-Con 13y agoBreaking crypto is the hard way to get information. Way easier to get it at one of the endpoints. (Industry lingo would say: attack data at rest, not data in transit.) Poison RNGs, get backdoors into the biggest services and software, and you have the majority of what you could need with almost no computing power.
- betterunix 13y agoThe NSA gives pretty good reasons for using ECC, and they are not alone in supporting it. The cryptography research community is also very supportive of ECC. If that does not convince you or if you would prefer systems with security reductions to worst-case NP-hard problems, you should look here: https://en.wikipedia.org/wiki/Learning_with_errors https://en.wikipedia.org/wiki/Learning_with_errors There is a lot of theoretical excitement about LWE right now, not only for public key encryption and signing systems but also for exotic things like fully homomorphic encryption and attribute based encryption. Unfortunately, there is are costs that hamper practical deployment. There keys will be larger. There are even more parameters to set, and bad choices can be fatal to security. The security of LWE-based systems is not as well-understood as ECC (making parameter choices even more difficult). Widely used standards like TLS and PGP do not have support for lattice / hidden codes systems. High-performance implementations are still under development.
- madaxe 13y agoAye, aware of LWE, and it's interesting stuff, and understand the theory as to why ECC is secure, and why DH key exchanges are increasingly not so. I'm just inherently suspicious of anything the NSA are in favour of, as their focus seems to be on breaking crypto, rather than recommending strong crypto - to recommend a key exchange mechanism that they can't snoop on seems to be a counterintuitive step.
- betterunix 13y agoActually, the NSA both breaks crypto and recommends crypto systems for government use. Much of their ability to recommend cryptosystems comes from their expertise in attacking cryptosystems. This played out in a very interesting way with DES. Most of the theories about an NSA conspiracy to weaken DES have been falsified. The changes to the s-box structure was later discovered to strengthen the cipher against a certain class of attacks. The small key size was later discovered to be right around the actual security level the cipher provides (larger key sizes would not have improved security by much). In the case of public key crypto, one of the most important things we need is to know what parameter sizes to use. Cryptanalysis is critical to making such estimates, and once again the NSA's expertise comes in handy here. To put it another way, if you knew nothing about factoring integers, 1024 bit RSA keys would appear to be overkill -- the only reason key sizes have become so large is because of GNFS and similar developments. In general you should avoid assuming that large, sprawling agencies like the NSA have a single goal. Yes the NSA conducts signals intelligence and would prefer that those signals not be encrypted. On the other hand the NSA also wants to ensure that foreign governments cannot spy on American government communications. With the vast reliance on contractors to develop software for sensitive systems there is a need for the NSA to make good recommendations to the public (even at the risk of improving our opponents' security); it is a classic NSA dilemma.
- tptacek 13y agoNobody in academia likes ECC because the NSA recommends it; ECC's virtues over simple finite field IFP/DLP crypto are obvious. There's no sane conclusion you can reach by letting NSA's approval or disapproval of technology head-fake you; what you're basically saying is that there's a series of stimuli NSA could issue that'd get you to use FEAL and knapsack algorithms.