14 ms·
N.S.A. Foils Much Internet Encryption
- uptown 13y agoThis essentially bolsters the claims in this article that the NSA has "neutralized" SSL. http://rt.com/usa/allegations-nsa-tool-decrypts-https-085/ http://rt.com/usa/allegations-nsa-tool-decrypts-https-085/
- lazyjones 13y agoThis "SSL Locksmith" software isn't really a top-secret NSA tool: http://www.accessdata.com/products/cyber-security/ssl-locksmith http://www.accessdata.com/products/cyber-security/ssl-locksm... It's a MITM solution that injects fake certificates, i.e. nothing groundbreaking and equivalent to compromised/corrupt CAs (which, as we know, exist and are able and willing to hand out fake intermediate certs etc. to rogue entities). The Whole CA ecosystem is broken and basically snake oil and pretty much everyone knows it.
- dailyrorschach 13y agoThis is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability. The issue to me has always been how and what data they access and store, and how it is used.
- mhurron 13y agoIf the NSA can, others can. It makes the whole thing useless.
- draugadrotten 13y agoEncryption is still useful. The NSA can read your messages - but not everyone. Encryption will still protect your bank transactions and wikipedia reading. No encryption will protect you from a goverment turned Evil, and I hope you realise this. If the US government is good or evil is all a matter of perspective. War is peace, Mr O wrote, and surely there has been a lot of that going on in US foreign policy the last few decades.
- a3n 13y agoI guess I'm with you on the ability to crack. Any researcher should be able to try as hard as they want, and succeed. I draw the line at collecting everything without specific warrants, regardless of what they do with it, against their charter and the Constitution. I draw the line at hardware backdoors for equipment that I buy, and insertion of vulnerabilities into encryption standards that I take advantage of. Or I guess I should say that take advantage of me.
- dailyrorschach 13y agoI'd agree with that. I've often been wondering if where we're headed is a some kind of reform compromise. Not that I think it's ideal or right, but for example I could see the NSA having a Chinese wall around data for Americans, such that FBI and other investigators could not use data collected by the NSA, but could open their own collections with a warrant. I'm quite opposed to what the NSA has done - but I don't see anything happening that will change it. If the recent revelations haven't done anything to stir Congress to action I don't know what will. Additionally, until and/or unless the NSA ever uses data collected this way against an American citizen in a judicial/criminal way, the courts are quite likely to find that petitioners lack any standing.
- swombat 13y agoAs a non-American, I find your lack of support for people who weren't born in your little patch of land quite uninspiring.
- dailyrorschach 13y agoWell I also assume that many other signals intelligence agencies are collecting data. Having worked at a time for a large global PR firm, I am sure many if not most of our communications were intercepted, especially with work once done for a Chinese based phone hardware maker. I think it would be a massive mistake to assume this is a United States only issue, so far the United States is the only country to have someone leak the information. So - yes, my most immediate legal concern is how the US government could use the data collection against me contrary to protections given. That doesn't mean there are many more and larger concerns to be thought through, I was merely speaking to one of them.
- haakon 13y agoThe larger issue here is that they "covertly introduce weaknesses into the encryption standards". It's not that they cleverly and fairly break encryption, it's that they sabotage the standards.
- smtddr 13y agoI have a problem with encryption being breakable, regardless of who's doing the breaking. I want encryption to be mathematically solid with the only option being brute-force older-than-age-of-earth time. When we get to quantum computing, then I don't know what we'll do...
- gizmo686 13y agoQuantom computing cannot break all of crypto. Anything based on P!=NP is believed to be secure against quantom computing, and there are several encryption methods backed by P!=NP
- mcherm 13y ago> Quantom computing cannot break all of crypto. Correct (except for the spelling of "Quantum"). > Anything based on P!=NP is believed to be secure against quantom computing, and there are several encryption methods backed by P!=NP Incorrect, well mostly. The deal is that there are problems that can be done in "polynomial time" (how long it takes is not exponential in the size of they key) for a normal computer (or person); the set of these is called "P", the ones that CANNOT be done on polynomial time is "NP". And there are problems that can be done in "polynomial time" (with reasonable limits on errors) by a quantum computer; the set of these is called "BQP". If P = BQP it would mean that quantum computers can (in reasonable time) solve all the same problems that classical computers can. But in fact, P is a subset of BQP: there are problems that are "hard" for classical computers but "easy" for quantum computers. An example of this is factoring numbers. Shor's algorithm is a way to factor numbers using a quantum computer and it runs in polynomial time. Now it isn't practical today: the biggest quantum computers in existence are hard put to factor the number "10", much less some 40-digit monstrosity. But computers only get better. Fortunately, there are problems which are NOT in BQP -- problems that are hard even for quantum computers. And these are the ones you want (not those in NP) if you want to stymie a quantum computer. For more details, see http://www.scottaaronson.com/papers/bqpph.pdf http://www.scottaaronson.com/papers/bqpph.pdf or frankly ANYTHING written by Scott Aaronson (http://www.scottaaronson.com/blog/ http://www.scottaaronson.com/blog/).
- jonknee 13y ago> I have no problem with the NSA being able to break encryption, that's in fact part of their job. Their "breaking" of encryption is a combination of purposefully introducing vulnerabilities into standards, surreptitiously altering software and hardware to give the NSA a backdoor, hacking into private systems and stealing keys, etc etc. I'm cool with an NSA super computer trying to brute force my VPN traffic to YouTube, I'm not cool with the NSA planting an engineer at a chip fab and changing designs to add a backdoor (a backdoor that could also be exploited by other actors).
- XorNot 13y agoI will bet good money that the NSA has never bothered to try and plant backdoors in encryption standards. If the NSA recommends AES to the US government, but knows there's a vulnerability, then they have to assume that any adversary may be as good as whoever designed it. Which means an adversary would be perfectly capable of discovering and exploiting the weakness. Which in turn means the NSA has just made the entire US government vulnerable to foreign or non-state actors. The same applies to anything you might imagine doing to chipmakers. Not only is there the risk of being found out (how do you explain to a talented engineer spotting a flaw in a schematic, how high up do you have to go to try and stop that leaking?) but there's the more serious risk that you've just added a backdoor to hardware you yourself need to be secure. Which again, could be discovered by an adversary and used against you. This whole line of argument has always been speculative fiction on the part of the internet: it's looking for unicorns because you heard hoofs.
- gaius 13y agoWhich in turn means the NSA has just made the entire US government vulnerable to foreign or non-state actors. Yes, and it says this in the article. And it makes perfect sense too. If you were the NSA, wouldn't you want a heads up if someone was talking about budget cuts?
- jonknee 13y ago> I will bet good money that the NSA has never bothered to try and plant backdoors in encryption standards. Did you read the article? > By this year, the Sigint Enabling Project had found ways inside some of the encryption chips that scramble information for businesses and governments, either by working with chipmakers to insert back doors or by surreptitiously exploiting existing security flaws, according to the documents. Seems pretty cut and dry.
- stdgy 13y agoThe problem isn't that they're working to break encryption. The problem is that they're maliciously inserting backdoors and subverting crypto-research and publication, which puts all of our security at risk. (Not to mention runs counter to their stated mission)
- mullingitover 13y agoIt's definitely great knowing that our government is willing and able to commit pretty serious industrial espionage, and if anyone tries to do anything about it, hey, we have nukes too. Don't worry everyone, we're the good guys! We promise to send you some foreign aid after you've come to terms with your subjugation. /s
- alasdair_ 13y agoThere are a couple of other issues, even if one agreed with your view: 1. They obviously can't keep their own secrets, so it's unlikely that they will do any better than keeping yours. Eventually, your data will leak out to non-NSA people. 2. By adding backdoors, they weaken the encryption. This implies that anyone with sufficient skill who goes looking for backdoors may be able to exploit the hole that the NSA opened up. This is a big deal, especially if you have secrets that you need to protect.
- eruditely 13y agoWe cannot rely on them to be always good so we have to also have the prior, encryption to protect us if the law or law makers are not working for our best interest.
- yuhong 13y ago"Cryptographers have long suspected that the agency planted vulnerabilities in a standard adopted in 2006 by the National Institute of Standards and Technology, the United States’ encryption standards body, and later by the International Organization for Standardization, which has 163 countries as members." Wonder if it is referring to the Dual_EC_DRBG RNG.
- lambda 13y agoWell, it goes on to say "Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency." The Dual_EC_DRBG vulnerability was revealed by two Microsoft researchers in 2007: http://rump2007.cr.yp.to/15-shumow.pdf http://rump2007.cr.yp.to/15-shumow.pdf So I'd say yes, it sounds like that's what they're talking about. Speaking of which, I'm really quite frustrated how many of these recent reports about the NSA elide the technical details. You have to read between the lines to figure out what's really going on, what weaknesses there really are. As a matter of security, it would be better to know specifically what vulnerabilities there really are. Merely the announcement of vulnerabilities can allow a dedicated black-hat to find and exploit it; but someone who's trying to secure their system, and isn't following cryptography incredibly closely, won't know what they need to do or change to make their systems more secure against these types of attacks. There's a reason that the security community advocates for full disclosure (or at least responsible disclosure, if it's possible to selectively disclose to a few vendors so they can do a coordinated release that fixes the vulnerability before it becomes public), in which you completely disclose a vulnerability so people aren't left guessing about it.
- mcherm 13y ago> Speaking of which, I'm really quite frustrated how many of these recent reports about the NSA elide the technical details. Are you? Well please sign up to work for the NSA, learn the technical details, then go public with them. The reason that the NYTimes isn't publishing the technical details is because they DON'T KNOW THEM. (They might not publish them if they did.) They don't know them because Edward Snowden was a system administrator not a cryptography expert and he's releasing memos about the process.
- 16s 13y agoNormal people don't need 256-bit symmetric encryption. That's assault encryption and should only be used on the battlefield. 40-bits is enough and anything over that should be banned. I'm only joking, but the same argument is used against other technologies that governments seek to control/dominate. Edit: Skipjack was 80-bits I think. It was used in Clipper Phones: http://en.wikipedia.org/wiki/Skipjack_(cipher) http://en.wikipedia.org/wiki/Skipjack_(cipher)
- yuhong 13y agoThe funny thing is 56-bit encryption is still in use in the form of PPTP with MS-CHAPv2. I bet most of the decrypted VPN traffic mentioned in the article uses that.
- voltagex_ 13y agoYep, I'm ashamed I didn't make the connection last week when I signed up for a PPTP VPN. They've been broken for a while now.
- cromwellian 13y agoPeople don't take a 256-bit cryptoalgorithm into a middle school and kill kids with it, so I don't think the analogy works exactly. Maybe if you print it out on paper, or use a floppy disk or CD, you could cut a few people.
- dictum 13y ago"The NSA is just doing its job."
- w_t_payne 13y agoIn a sense, yes. In fact, it is good that they put the effort into breaking these systems, and good that Snowden let us know about it. Now we know that the vulnerabilities exist, we can go about fixing it.
- ternaryoperator 13y ago"the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards." This is the part that truly disgusts me.
- abat 13y agoI think people were speculating this on HN with this article: http://www.wired.com/politics/security/commentary/securitymatters/2007/11/securitymatters_1115 http://www.wired.com/politics/security/commentary/securityma...
- kamjam 13y agoWhy are you surprised, or even disgusted? They've moved on from governments (http://www.bbc.co.uk/news/world-middle-east-23762970 http://www.bbc.co.uk/news/world-middle-east-23762970) to using technology to do it. I use the term "moved on" loosely, because it is still happening no doubt. The US has long used it might and influence around the world, esp Latin America, to do very questionable things and really no one has batted an eye lid apart from the little guys getting screwed over. Terrorism is the just the new guise they are using to justify their actions.
- Zigurd 13y agoThe N.S.A. hacked into target computers to snare messages before they were encrypted. And the agency used its influence as the world’s most experienced code maker to covertly introduce weaknesses into the encryption standards followed by hardware and software developers around the world. This is mostly a confirmation of what has been supposed: No magic, mostly bribed and coerced cooperation from the people who should be keeping our communications secure. And while it doesn't do anything for the credibility of US-based companies, N.B.: "hardware and software developers around the world."
- devx 13y agoSo, should we re-evaluate if Intel/AMD's chips (and possibly even the new ARM ones) contain hardware backdoors for the NSA?
- Zigurd 13y agoI would assume the NSA has evaluated every plausible attack, and implemented them based on what they want to get out of it, and that they have global reach into chips, peripherals, and software. If you are a foreign government, hostile or friendly, I don't see much of a case to made for "Naw, they wouldn't..." They would, they probably can, and the probably already did. If you are a consumer, the main problem is the creepiness factor. Who wants to use incrementally more technology if along with it you get incrementally more surveillance?
- tubbzor 13y agoIf the source code/hardware diagrams are kept private you should assume backdoors, always, with everything. How is there any other way to know for sure otherwise? These government agencies are obviously dug much deeper in private industry than many expected so I wouldn't put it past them
- chris_mahan 13y agoIf you see the diagram, and someone else makes the chip, how do you know the diagram matches exactly with what's on the chip? Unless you can make your own chip from the diagram, you still cannot be sure.
- Achshar 13y agoSo does this means they have broken or fund a bug in RSA, fast enough computers to brute force or solved the P versus NP problem. In decreasing chances of possibility. I am also an encryption noob, so I gather that if they have broken a crypto then my 4096 bit files will be no more secure than 1024 bit ones. Right?
- patdennis 13y agoIf they solved P vs NP... well. Yeah. That would be interesting.
- jessaustin 13y agoWell, if they found a constructive proof, that is.
- _phred 13y agoThe best publicly known attacks on RSA reduce the attack time by a few orders of magnitude at best. A functional quantum CPU could reduce that by a few more orders. Your 4096-bit RSA key is still 2^3072 times harder to break, so even with reductions we're still talking about "heat death of the universe" amounts of time to brute force. RSA has issues but as of yet hasn't yielded entirely to cryptanalysis. As the article says, it's easier to attack the system and try to get the plaintext, or coerce you into giving up your key through legal means. Edit: adding a link to Wikipedia's article on post-quantum crypto, it's a good place to start understanding how to answer these type of questions: http://en.wikipedia.org/wiki/Post-quantum_cryptography http://en.wikipedia.org/wiki/Post-quantum_cryptography
- Dylan16807 13y agoAre you sure about that? As far as I understand it, generic quantum computation would cut that '3072' in half, and using quantum computers specifically for factoring reduces problems to a low polynomial time.
- 13y ago
- w1ntermute 13y agoCan someone who actually knows about encryption comment on whether it's actually physically feasible for the NSA to have actually broken, say, SSL 3.0 (which has 128 bits of entropy, IIRC) on a large scale (i.e., when you're sifting through petabytes of data on a daily basis)? And if this were really an issue, couldn't you just use 4096-bit RSA (unless they have managed to surreptitiously insert a backdoor in it)?
- jonknee 13y agoBrute force is only required if there isn't a vulnerability (either in the algorithm or that the NSA has a key). > Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency. The N.S.A. wrote the standard and aggressively pushed it on the international group, privately calling the effort “a challenge in finesse.” > N.S.A. documents show that the agency maintains an internal database of encryption keys for specific commercial products, called a Key Provisioning Service, which can automatically decode many messages. If the necessary key is not in the collection, a request goes to the separate Key Recovery Service, which tries to obtain it.
- regularfry 13y agoNeither of those apply to SSL 3.0, do they?
- pfortuny 13y agoIt might be but it is highly dubious. However, they MIGHT have put some effort into "plugging" each implementation and planting a subtle bug in them. You never can tell. It is not somuch the protocol what matters but the implementations. Imagine they "rig" all those beatiful hardware RNG. Could you tell the difference? Are you sure renowned developer X van Y is not an NSA mole?
- Canada 13y agoRemember the OpenBSD IPSec backdoor allegation? https://lwn.net/Articles/420858/ https://lwn.net/Articles/420858/
- nrmilstein 13y agoCan someone elaborate on how secure the underlying algorithms still are? Most of the NSA's "foiling" seems to be done via coercing corporations and side-channel attacks. Are TLS, AES, etc. still thought of as secure?
- dannyobrien 13y agoBruce Schneier has seen the documents, and here's his advice: http://www.theguardian.com/world/2013/sep/05/nsa-how-to-remain-secure-surveillance http://www.theguardian.com/world/2013/sep/05/nsa-how-to-rema...
- nrmilstein 13y agoSaw that too. Thanks!
- chacham15 13y agoCan someone boil this down and tell me the same thing from the technical side? I.e. what technical barriers have they managed to break (RSA, DSA, AES, etc.) ?
- ternaryoperator 13y agoI think you have to assume the answer is: all.
- donohoe 13y agoSo at this rate are there any encryption methods that we're pretty sure that the NSA cannot crack? By introducing such back doors, the N.S.A. has surreptitiously accomplished what it had failed to do in the open. Two decades ago, officials grew concerned about the spread of strong encryption software like Pretty Good Privacy, or P.G.P., designed by a programmer named Phil Zimmermann. The Clinton administration fought back by proposing the Clipper Chip, which would have effectively neutered digital encryption by ensuring that the N.S.A. always had the key. Link to Paragraph w/ highlighting: http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html?pagewanted=all#p[Eapdst],h[Bisaht,3] http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet... Should I bother to read up on PGP?
- mindslight 13y agoI feel like these kinds of articles are meant to induce a sense of hopelessness regarding the ability to push back against the NSA. If it turns out one way functions actually don't exist, I'll give in and learn to love big brother. Withstanding that, I'll continue considering communications freedom (and all that it implies) as our manifest right and view these types of breaks as implementation errors.
- jrochkind1 13y agoYou mean ability to push back _technologically_ against the NSA, right? This sort of article makes you think you can't beat the NSA tech, they will outsmart you. What this sort of article does to me (unlike you, I make no claims to know what the article was 'meant' to do, other than report the news) is make it clear that we need to push back against the NSA _politically_ to win, make what they are doing illegal, change the gag order laws, etc. We aren't going to beat them technologically, but (for those of in the U.S.), it's theoretically a democracy, we can tell them to stop. I've seen that argument made before, several times, in essays linked to on HN. It's a political problem, not a tech problem, that the NSA can force corporations to install back doors and give the NSA the keys.
- mindslight 13y agoThe problem is technological, as deficiencies in relied-upon communication technologies is what have allowed surveillance to scale from human intelligence on prioritized targets to dragnet scrutiny of everybody. No matter how much effort is required, "law enforcement" will always be snooping on some suspects - what we'd like to prevent is an institutionalized fishing expedition. You're signing up for a losing game. The myth of Democracy (tm) is another layer of control over individuals. 1. Most people will never have a problem with what the NSA is doing. They support the NSA's goals (tautology, since as you've mentioned, it is responsible to the majority), and if its methods end up causing harm to enough people, they will simply be adjusted to reduce aggregate harm (not to rule out any possible harm). The feedback loop of democracy works on specific actualities, not hypothetical corner cases. 2. The most memetically fit ideas are the simplest ones that elicit the strongest feelings (see: bikeshedding). Outrage peddlers swamp the political reception bandwidth with lowest common denominator controversy - usually judgments on other's lifestyles. 3. Even if there is a widespread preference to reduce the scope of the NSA, the people simply do not have the transmit bandwidth to make this preference clearly known. And they are easily led into squandering their input on the aforementioned manufactured controversy. 4. Elected figures don't actually run the government, the entrenched bureaucracy does at an imperceptible glacial pace. The elected figures run interference by making the majority believe they voted for this shit.
- abeinstein 13y agoSo, NSA has solved P vs NP and they're just not telling us?
- lurkinggrue 13y agoWhat they have is a bunch of telepaths in tanks that can see dimly into the future and they recover the keys.
- reinmen 13y agoassume the simplest explanation. 1) they have found/introduced a bug in encryption standards 2) they have solved a fiendishly hard math problem to which no known solution exists and on which solution there is a price of 1 mio $ working in dev i assume (1) is several orders of magnitude more likely.
- MattJ100 13y agoSnowden claimed a while back that encryption itself was not broken by the NSA, but that the endpoint security usually was (no surprise there): http://www.theguardian.com/world/2013/jun/17/edward-snowden-nsa-files-whistleblower?commentpage=1#block-51bf3588e4b082a2ed2f5fc5 http://www.theguardian.com/world/2013/jun/17/edward-snowden-...
- untog 13y agoBecause strong encryption can be so effective, classified N.S.A. documents make clear, the agency’s success depends on working with Internet companies — by getting their voluntary collaboration, forcing their cooperation with court orders or surreptitiously stealing their encryption keys or altering their software or hardware. That's the money quote there- the NSA hasn't cracked encryption. They've just put back doors in. And we can't even be that angry at the (e.g.) Microsoft execs that authorise the back doors- they potentially face jail time if they resist NSA requests. All the while presumably not able to talk about the requests publicly. EDIT: and the really fun part - did you know the former head of the NSA serves on the board of directors for Motorola Solutions? http://en.wikipedia.org/wiki/Michael_Hayden_(general) http://en.wikipedia.org/wiki/Michael_Hayden_(general)
- teleclimber 13y agoThat's the quote that jumped out at me too. The solution for those who want to stay out of NSA's reach is to use your own hardware, and use open source software (where it's hard to put a backdoor without being discovered) and strong encryption.
- electic 13y agoRemember when Microsoft would trash Linux because it was open source and "not secure." Well, this settles it. Using your own hardware and open source software helps but someone determined will still get in...
- untog 13y agoEven "your own hardware" is going to be pretty damn hard: working with chipmakers to insert back doors So you're going to need to make your own chips, too.
- captainmojo 13y agohttp://opencores.org/or1k/Main_Page http://opencores.org/or1k/Main_Page
- conorh 13y agoIt always seemed likely to me that governments can generate fake trusted certs for browser TLS traffic and then man in the middle the traffic, but what are the likely modes of attack otherwise? I don't really see what they are from this article - do they have a database of keys they have acquired nefariously?
- jashkenas 13y agoWith a byline from our very own "thejefflarson" (on HN). That's a lovely thing to see.
- induscreep 13y agoI am not really concerned about this encryption business...but have they managed to solve P=NP in the process of cracking crypto algos??
- jonknee 13y ago> The N.S.A. hacked into target computers to snare messages before they were encrypted. I wonder which computer viruses belong to the NSA.
- wvenable 13y agoWindows, Mac OS, Android, iOS, Symbian, and any Linux distribution you haven't culled together and compiled yourself.
- __david__ 13y ago> ...any Linux distribution you haven't culled together and compiled yourself. And maybe even ones you have compiled yourself "from scratch": http://cm.bell-labs.com/who/ken/trust.html http://cm.bell-labs.com/who/ken/trust.html
- brown9-2 13y agoThe most fascinating part of this article to me is this part, which proves that even a super-secure intelligence agency can still have very weak links that can be penetrated: Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among them, but he nonetheless managed to obtain dozens of classified documents referring to the program’s capabilities, methods and sources. Who knows what other documents other internal hackers could have stolen?
- danso 13y ago> The documents are among more than 50,000 shared with The New York Times and ProPublica, the nonprofit news organization, by The Guardian, which has published its own article. They focus primarily on GCHQ but include thousands either from or about the N.S.A. Is this the first time we've seen a 5-digit number to describe the number of documents Snowden has? Of course, these are just the ones used for this story...
- jlgaddis 13y agoI noticed that number as well and don't recall seeing it before, but I do seem to recall reading something about "multiple laptops" of Snowden's. Obviously, one can store a helluva lot of documents on three or four laptops.
- lurkinggrue 13y agoBest to only use Open Source encryption software.
- outside1234 13y agoyeah, cuz there's no way the NSA could contribute code to that too.
- kamjam 13y agoIt might be time for the community to do some thorough code audits on stuff like this... :(
- eCa 13y agoSearch this thread for "Theo de Raadt" and read the link...
- quotemstr 13y agoWhat's truly frightening is this line from the Guardian's article on the topic: > The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace". What does that even mean? That statement is at the same time paranoid, arrogant, and subtly threatening. It's as if to say that without the ability to decrypt interesting traffic, the NSA would be forced to take stronger measures to curtail internet traffic.
- ganeumann 13y agoThat was what caught my eye also. It seems to imply that if they can't read our Internet traffic then they'll have to take the US off the Internet. That's a pretty drastic threat.
- ihsw 13y agoIt means there are two choices for America's participation in the global internet: decryption capabilities or America's Great Firewall. The statement implies that in the absence of "strong decryption programs" then there would be only restricted access to and use of cyberspace. I'm sure the intelligence leadership in the US Government look at China's Great Firewall with both trepidation and admiration.
- wiredfool 13y agoIt makes sense if "the US" = "the NSA". Stuff's been encrypted, for the NSA to continue to have access, they've gotta break it.
- snowwrestler 13y agoI think the key to understanding this is to remember that it was written by the NSA for the understanding of the NSA, or other highly authorized eyeballs in the government. In many government documents, use of the name "U.S." is shorthand for the U.S. national government, not the entirety of the nation. Sometimes it is even shorthand for the particular agency that authored the document (since, in theory, they represent and act on behalf of the entire nation). So what this internal NSA document most likely means by "unrestricted access and use" is the NSA's unrestricted access to, and use of, whatever data they want. Think of it like a budget justification (since that is the purpose of at least half of all internal government reports). "You need to keep spending a lot of money on this program if you want us to keep getting all that data you like so much."
- Scramblejams 13y agoSingle page link: http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html?pagewanted=all http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet...
- smutticus 13y agoReminds me of this: http://marc.info/?l=openbsd-tech&m=129236621626462&w=2 http://marc.info/?l=openbsd-tech&m=129236621626462&w=2 As someone who has been following the NSA and government monitoring of online activity for close to 15 years the Snowden leaks just keep taking the wind out of me. It's like everything that we thought might be going on was actually going on. When Theo de Raadt wrote the above mail I, like many at the time, assumed it was tinfoil hat territory. I was clearly wrong.
- m0nastic 13y agoIn that particular instance you weren't wrong[1], but that's the problem when stories like this come out, is that it makes it much harder to know what's a crazy conspiracy theory and what's real. [1] Those claims made by Greg are completely untrue. I ran the professional services group for that company and will happily attest to whomever asks that at no time did we insert a backdoor (or anything that could even be construed as such) into IPSEC.
- unimpressive 13y ago>Those claims made by Greg are completely untrue. I ran the professional services group for that company and will happily attest to whomever asks that at no time did we insert a backdoor (or anything that could even be construed as such) into IPSEC. Somehow I doubt if you did that you could tell us. You might even have to lie to be able to comment on that letter at all.
- m0nastic 13y agoI'm still unclear on the government's ability to compel falsehoods (even the discussions around National Security Letters seem to indicate that they prevent disclosure, but can't require lying), but I don't think I can convince you of that. When all the hullabaloo around the alleged IPSEC backdoor occurred, it was frustrating to not be able to be as open about it as I wanted (not because of any government/security issues, but because at the time I still worked for the company and we were advised against talking about it). You are free to assume that even right now as I type this, a shadowy figure in an ill-fitting Brooks Brothers suit is standing over me dictating my responses, and then chastising me for spending my time on HackerNews.
- MarcusBrutus 13y agoThe Allies had broken most of the Nazi codes during WWII but they still withheld information from commanders unless the information concerned an absolutely strategic battlefield that hang on the balance. Better suffer a few dead or some minor setbacks than let the Germans grow suspicious and start doubting their cryptography. Morale of the story: unless you're the next Osama or Showden or some major narco-trafficker it doesn't apply to you.
- vkou 13y agoOr the next MLK...
- tc 13y agoThis is really damaging. Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here. On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys? ---- [Edit 1] Some speculation: By careful hardware design -- and lots of it -- the NSA may be able to find keys large enough that we would be mildly surprised but not shocked. It's not well known that searching for many keys in parallel amortizes well -- it's much cheaper than finding all the keys individually. DJB has a great paper about this: http://cr.yp.to/snuffle/bruteforce-20050425.pdf http://cr.yp.to/snuffle/bruteforce-20050425.pdf If I were looking for subverted hardware, I'd be really interested in reverse engineering Ethernet chips and BMCs. The CPU would be an obvious choice as well -- could there be some sequence of instructions that enables privilege escalation? On protocols, the best sort of vulnerability for the NSA would be the kind that is still somewhat difficult and expensive to exploit. They want the security lowered just far enough that they can get the plaintext, but not so far that our adversaries can. There is some history with not taking timing attacks seriously enough. Perhaps careful timing observation, which the NSA is well positioned to do, could give more of an edge than we suspect. Or perhaps you could push vendors to make their products susceptible to this kind of attack, secure in the belief that it may be difficult for others to detect. [Edit 2] I gave a talk that discussed what I think we as engineers should do here: https://www.youtube.com/watch?v=c7oK59DZwR4#t=1m46s https://www.youtube.com/watch?v=c7oK59DZwR4#t=1m46s And Phil Zimmermann and I discussed a number of these issues in a Q&A session: https://www.youtube.com/watch?v=W42i8zCEizI#t=49m55s https://www.youtube.com/watch?v=W42i8zCEizI#t=49m55s
- kamjam 13y agoImagine this is proved in France, this would add some weight to the investigation and case against the US, esp if they can prove personal encryptyed information was stolen! http://www.reuters.com/article/2013/08/28/us-usa-security-france-idUSBRE97R0WE20130828 http://www.reuters.com/article/2013/08/28/us-usa-security-fr...
- lambda 13y agoOne of the vulnerabilities was already discovered by researchers in 2007: http://rump2007.cr.yp.to/15-shumow.pdf http://rump2007.cr.yp.to/15-shumow.pdf At the time, it wasn't clear if this was a deliberate backdoor or an accident, but it was proven that there there was a possibility that there was a secret key that would allow someone to predict future values of a pseudo random number generator based on previous values. Now it looks pretty clear that it was a deliberate backdoor. This really reduces trust in US based cryptographic standards. And US based cryptographic hardware, as they mention in the article that they convinced hardware manufacturers to insert backdoors for hardware shipped overseas.
- pedrocr 13y ago>the Bullrun program, the successor to one called Manassas — both names of American Civil War battles. A parallel GCHQ counterencryption program is called Edgehill, named for the first battle of the English Civil War of the 17th century. Spying on your own citizens codenamed as civil war. How nice. >Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among them, but he nonetheless managed to obtain dozens of classified documents referring to the program’s capabilities, methods and sources. Once again, the people spying on everyone suck at keeping their own secrets. How many others have taken the information with them and sold it off instead of leaking it? >In one case, after the government learned that a foreign intelligence target had ordered new computer hardware, the American manufacturer agreed to insert a back door into the product before it was shipped, If you're a non-US company how can you keep trusting US IT vendors? I wouldn't want to be one of these companies' reps at Airbus for example.
- squozzer 13y agoWhat's in a name? Perhaps your intended targets. Can't wait to see Project Auschwitz.
- asploder 13y agoHumorously, the United States Army lost both Battles of Bull Run to the Confederates.
- brown9-2 13y agoSpying on your own citizens codenamed as civil war. How nice. Nowhere in the article does it state that these methods can be used against US persons separate from other protections against surveillance on US persons, nor does it give the impression that this is special to US persons: The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the deliberate targeting of Americans’ e-mails or phone calls without a warrant. Let's keep in mind the fact that an intelligence agency is built to gather intelligence on other governments/organizations and that often involves breaking other jurisdiction's rules.
- 13y ago
- solnyshok 13y agoKnowing what kind of encryption NSA uses internally, can tell all about what is compromised and what's still secure.
- reinmen 13y agoThe money quote is this: The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace". from the Guardian article, also here on HN http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryp...
- albertsun 13y ago"In one case, after the government learned that a foreign intelligence target had ordered new computer hardware, the American manufacturer agreed to insert a back door into the product before it was shipped, someone familiar with the request told The Times." Wow.... this really puts all the furor over Huawei contracts in the US in context.
- wyck 13y agoI will just leave this here: http://www.csoonline.com/article/707542/china-not-to-blame-for-backdoor-in-us-military-chip http://www.csoonline.com/article/707542/china-not-to-blame-f... http://www.extremetech.com/computing/133773-rakshasa-the-hardware-backdoor-that-china-could-embed-in-every-computer http://www.extremetech.com/computing/133773-rakshasa-the-har...
- pja 13y agoAll that furore over Huawei contracts in the US was just projection wasn't it? You're might be more secure buying your network kit from Huawei than from a US manufacturer.
- theintern 13y agoSounds like it was justified really, the NSA know since they've done similar things themselves that it's possible, so it's not a stretch to assume China is doing the same thing.
- tptacek 13y agoYou can't have read Applied Cryptography from the mid-90s and not understand this to have been NSA's M.O. from the jump. Bruce Scheier, who was quoted in the Guardian piece about the same story, is America's foremost popularizer of the notion of NSA as crypto's global passive adversary. People who build real cryptosystems have never, ever been allowed to rely on the goodwill of the NSA not to cryptanalyze their systems. Entire crypto schemes, from the RIPEMD hash to the specific parameter generation mechanism in DSA, are premised on the idea that USG-sponsored crypto concepts aren't inherently trustworthy. Similarly, all of Applied Cryptography was premised on the idea that NSA was decades ahead of commercial and academic crypto. Of the revelations about NSA, this has to be the least revelatory (it's up/down there with the "revelation" that NSA employs teams of people whose job it is to break into Windows computers); it essentially restates something we were already supposed to have taken for granted. That's not to say this isn't a fascinating story. It is; just keep it in context. Things to remember: * You really want to know whether NSA is directly attacking cryptographic primitives or whether they're subverting endpoints. I think if you talk to cryptographers, you'll get a slight bias towards the belief that it's the latter: that there are implementation weaknesses at play here more than fundamental breaks in crypto. * You want to keep in mind that breaks in cryptosystems represent new knowledge, and that the enterprise of breaking cryptosystems is an issue distinct from the public policy concern of where NSA is allowed to deploy those breaks. * Bear in mind that in the legacy TLS security model, before things like pinning and TACK, NSA would only require a viable attack on a small subset of CAs to gain (along with pervasive network taps) massive capabilities. The payoff for these kinds of capabilities is radically degraded by the anti-surveillance mechanisms of modern browsers like Chrome, which is something you probably want to be thanking people like Adam Langley, Trevor Perrin, and Moxie Marlinspike for pushing so hard to implement.
- guelo 13y agoThat security systems are designed in the most paranoid fashion possible doesn't tell you anything about the real nature of the threat. Schneier's book doesn't tell you that the NSA has been strong arming corporations into giving up their private keys and into installing backdoors on chips. In fact Schneier himself is outraged to the point that he seems to be calling for a redesign of basic Internet protocols and governance in his article today, http://www.theguardian.com/commentisfree/2013/sep/05/government-betrayed-internet-nsa-spying http://www.theguardian.com/commentisfree/2013/sep/05/governm...
- tytso 13y agoI am so glad I resisted pressure from engineers working at Intel to let /dev/random in Linux rely blindly on the output of the RDRAND instructure. Relying solely on an implementation sealed inside a chip and which is impossible to audit is a BAD idea. Quoting from the article... "By this year, the Sigint Enabling Project had found ways inside some of the encryption chips that scramble information for businesses and governments, either by working with chipmakers to insert back doors..."
- magicalist 13y agoWas that really a seriously considered plan? I don't see how that would ever be a suitable /dev/random replacement. Obviously it works for /dev/urandom, but it should be added to the entropy pool for /dev/random at most.
- lambda 13y agoMatt Mackall, the former maintainer of /dev/random, actually stepped down over this issue, because Linus overrode Matt and applied Intel's patch that used their hardware random number generator directly: http://comments.gmane.org/gmane.comp.security.cryptography.randombit/4689 http://comments.gmane.org/gmane.comp.security.cryptography.r... > It's worth noting that the maintainer of record (me) for the Linux RNG quit the project about two years ago precisely because Linus decided to include a patch from Intel to allow their unauditable RdRand to bypass the entropy pool over my strenuous objections. > From a quick skim of current sources, much of that has recently been rolled back (/dev/random, notably) but kernel-internal entropy users like sequence numbers and address-space randomization appear to still be exposed to raw RdRand output. Ted Ts'o later reverted this, separating out Intel's hardware random number generation into a separate function that could be used to seed the entropy pool but wouldn't be trusted directly as the main kernel source of random numbers: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c2557a303ab6712bb6e09447df828c557c710ac9 http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.g...
- Zoepfli 13y agoSounds like Linus has some explaining to do...
- josephlord 13y agoTLS/SSL has a whole bunch of options that are negotiated between client and server to find one that they can both accept. I speculate that some of these may be badly broken by the NSA but the exact ones haven't been revealed so we don't know which ones need taking off the table. Is there anything unusual about the cipher options offered by NSA/GCHQ servers? Or any recent changes at The NYTimes or Guardian's servers.
- bhauer 13y agoOut of humor and a bit of worry, I had previously posed a conspiracy theory that the NSA/etc. had undermined (coerced, compromised, whatever) the Internet's certificate authorities. I no longer am comfortable dismissing it as silly humor. I worry that such a theory has about equal parts merit as not. I now want viable open source web-of-trust encryption for the web as soon as possible.
- ihsw 13y agoThe worrying part is the "etc" part of your sentence, namely that all federal agencies in the US Government now have unrestricted access to encrypted communications. The DEA and the IRS are only the tip of the iceberg. If one government agency has your data then the rest of them do too.
- Filligree 13y agoOh, don't forget other governments. If the NSA can do it, China and Russia certainly can too.
- wildster 13y agoIt would be so damaging for Intel or AMD if a credible leak revealed they had backdoors built in, is it this really conceivable?
- ianstallings 13y agoI really wish these guys would understand how they're impacting Internet-based commerce. What good is controlling the Internet if people stop using it because of privacy concerns? They seem completely unconcerned about how IT drives the US economy and how a lack of confidence in that sector leads to bad things.
- lelf 13y agoOne-page http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html?pagewanted=all http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet...
- 16s 13y agoSome organizations have IT security departments that attempt to foil encryption already. They use devices to terminate SSL before it leaves their network and forge certs back to clients and basically act as a MITM for the clients making the TLS/SSL request. They do this to inspect the traffic before it leaves the network. I predict that in the next 5 to 10 years, many organizations across all industry sectors will drop/reject encrypted packets (SSL, SSH, SFTP, etc) that they cannot decrypt. And the reason they'll give is that it makes them more secure. The concern I have (as a security technologist) is that most people who use encryption are not bad, however everyone is punished and every packet must now be inspected because a few people use encryption to do bad things. So one day soon, I'm afraid that anyone who uses encryption will be suspect simply because they do and the stronger the encryption, then the more suspect they'll be. Will it become illegal to do encryption research or use OpenPGP unless you agree to escrow your private key or will everyone be forced to use very weak ciphers? In today's climate (encryption is evil), I see all of these things as very real possibilities.
- wiml 13y agoCisco firewalls, by default, perform a MITM protocol downgrade attack on the SMTP sessions they see. They modify the SMTP setup to prevent the endpoints from negotiating STARTTLS and cause them to fall back to cleartext communication. Has been true for years. You can turn it off... but how many admins do? If you want an example of behavior which is completely plausibly-deniable, but which immensely reduces internet security, this is a good one.
- croddin 13y agoThis thread reminds me of an xkcd comic which is a good description of what might be happening: http://xkcd.com/538/ http://xkcd.com/538/
- lambda 13y ago> A 2010 document calls for “a new approach for opportunistic decryption, rather than targeted.” By that year, a Bullrun briefing document claims that the agency had developed “groundbreaking capabilities” against encrypted Web chats and phone calls. Its successes against Secure Sockets Layer and virtual private networks were gaining momentum. This paragraph interests me the most. For one, it's clear that their goal is opportunistic decryption; that is, decrypting everything and being able to search through it, rather than targeting known endpoints. This is an important point that a lot of people miss when debating cryptography. While it's fairly likely that the government can find ways to access any communication they want in a targeted manner, as they have so many means to do so (hacking the endpoints, physically breaking in and performing an evil maid attack, etc), widespread encryption is generally good enough to prevent opportunistic data gathering. The other point I note is that they only mention "web chats and phone calls" in their breakthrough. It doesn't sound like the breakthrough is something that works well for arbitrary SSL connections. The main link I can see between web chats and phone calls is that they are long lived connections, with bursty traffic (HTTP or email protocols, on the other hand, tend to stream a lot of data at once, and then the connection is closed). I'm wondering if there's some kind of traffic or timing analysis vulnerability that they've discovered. Also interesting is this quote from the Guardian article: > To help secure an insider advantage, GCHQ also established a Humint Operations Team (HOT). Humint, short for "human intelligence" refers to information gleaned directly from sources or undercover agents. > > This GCHQ team was, according to an internal document, "responsible for identifying, recruiting and running covert agents in the global telecommunications industry." Various technology companies have been adamant in maintaining that they haven't been been giving the NSA direct access to their data. However, with HUMINT programs like this, you always have to wonder if the NSA has hired anyone within such companies to put backdoors into their systems, without authorization by the company. Obviously, they'd have to be subtle about it (it's hard to install new gigabit fiber pipes to siphon off the data without anyone noticing), but just setting up a way for the NSA to covertly run queries, disguised as some other type of job that would normally run on the system, would probably not be too hard to do.
- venomsnake 13y agoAs Snowden showed you need only one rogue admin most of the times to get what you want
- JulianMorrison 13y agoUp until very recently, the received wisdom was: the crypto wars are over, we fought the law and the law gave up, the NSA has quit trying to crack encryption, they have decided the USA is best strengthened by having a reliable internet which business rival nations can't just read like the morning's news. The NSA knows the problems in crypto and their suggestions make it stronger against attacks we don't know. Trust the NSA. Would that it were true! It would make sense. This makes no damn sense. Just recently I would have ruled out huge conspiracies as implausible because they inevitably leak (roll save against ethics how many times?). The joke's on me, folks. The NSA has no sense. And the conspiracy leaked. So now every single decision that was taken with help from the NSA (SELinux, TLS, elliptic curves, etc) needs unpicking and running by a cryptographer who isn't a shill. What a damn drag. And meanwhile, the aftershocks will run for years trashing trust in the networked economy. Fuckin' brilliant, NSA. You screwed the pooch. You accidentally the whole internet.
- cbr 13y agoSo now every single decision that was taken with help from the NSA (SELinux, TLS, elliptic curves, etc) needs unpicking and running by a cryptographer who isn't a shill. Cryptographers have already been looking very carefully at everything that comes out of the NSA. Lots of security researchers, in and out of the US, would love to find NSA-introduced flaws.
- mpyne 13y agoIt would even be ironic if people's aversion to things like SELinux caused them to use software which is even less secure, and correspondingly easier for NSA to break. They know the long game too...
- D_Alex 13y ago>they inevitably leak (roll save against ethics how many times?) Haha, nicely put. Note too that sooo many "roll save against temptation" must happen to avoid abuses of the NSA capabilities.
- caf 13y ago
- eggoa 13y agoSo the Feds mandate data security, e.g. HIPAA, and then actively subvert our ability to achieve that security.
- w_t_payne 13y agoWow .... so SSH is broken? Wow ....
- wfunction 13y agoI've take a look at half the article so far and still can't find a single specific example of a "backdoor". The entire thing seems hand-wavy.
- pdonis 13y agoAs is usually the case with an article in the mainstream media, the most interesting part is what isn't in it. If much Internet traffic is vulnerable to the NSA (and to the UK's GCHQ), doesn't that imply that much Internet traffic is also vulnerable to other governments? Such as, oh, say, China and Russia?
- csense 13y ago> In effect, facing the N.S.A.’s relentless advance, [Lavabit] surrendered I disagree with this characterization. Surrendering to the NSA would be Google/Facebook/Microsoft's approach of unconditional cooperation. Lavabit's refusal to work with the NSA -- even though apparently the only alternative was shutting down their business or going to jail -- is more along the lines of a scorched earth retreat (destroying your own stuff when you can't hold the line).
- deleted 13y ago[deleted]
- jjoe 13y agoThis doesn't make sense. It can't be. Why would cryptography be subject to export regulations then? If we follow this logic, you would think export barriers would have been brought down decades ago and use of NSA cryptography highly encouraged worldwide.
- peterhunt 13y agoWhere are the original documents (primary sources)?
- codex 13y agoI wonder if RHEL and Ubuntu distros have NSA/FBI root kit backdoors in their kernel binaries and/or subscription services.
- SEMW 13y agoYou think no-one's tried recreating various distros' binaries from their published source, to check they're the same? E.g. Jos van den Oever did that for Debian, Fedora, and OpenSUSE here[1]. Which isn't to say that backdoors inserted into the binary that aren't in the published source are impossible, only that they need something more subtle than the crude/easily-detectable 'merge backdoor, compile, ship'. Something like a Ken Thompson 'Trusting Trust'[2]-style attack. (Though there are ways of at least having a good chance of detecting even those - see [3]). (More likely, IMHO, are just deliberately-introduced, plausibly-deniable bugs in the source - think [4]. Yeah, they might be found & reported by an outsider reviewing the source, in which case you thank them, fix it, and introduce another couple somewhere else next week). [1] http://blogs.kde.org/2013/06/19/really-source-code-software http://blogs.kde.org/2013/06/19/really-source-code-software [2] http://cm.bell-labs.com/who/ken/trust.html http://cm.bell-labs.com/who/ken/trust.html [3] http://www.dwheeler.com/trusting-trust/ http://www.dwheeler.com/trusting-trust/ [4] http://underhanded.xcott.com/ http://underhanded.xcott.com/
- 16s 13y agoIf we are going to vilify encryption, then we should just stop teaching math. That's all encryption is.
- Cyranix 13y agoThat is a really weird conclusion to draw from this article. I don't know who you think is "vilifying" encryption as an application of mathematics.
- csense 13y agoSpeaking as an American, it's not a problem that the capability to break encryption exists and the NSA has it. It really does make national security stronger if your intelligence people can read enemy communications. The problem is that the NSA apparently used those capabilities on basically everyone, millions of innocent Americans whose activities should be of no interest to intelligence agencies, not just the handful of genuine spooks and terrorists our intelligence agencies are supposed to protect us from. (To international people: Cosmically speaking, you're not less important than we are, but the NSA's first responsibility is to protect and serve the USA, so them spying on innocent Americans is at least as bad as them spying on innocent foreigners.) And it has been shown that the NSA provided information to ordinary criminal investigations with no links to terrorism or foreign intelligence, having police say "it's a lucky traffic stop," where the government actually knew the drugs were in that car ahead of time due to a decrypted phone call. This makes a mockery of the Fourth Amendment because, when prosecutors/police lie to the courts about the origin of evidence, the courts cannot properly answer the question of whether their methods of gathering evidence violate the defendant's Constitutional protection against unreasonable search and seizure. In short, this is coming out -- which, as the article said, will weaken those capabilities -- because the NSA went too far outside their mission scope. If they hadn't done those two things, I'd be willing to bet Snowden wouldn't have leaked this data.
- 7952 13y agoA political counter-argument is that this program may represent terrible value for money in the long run. If we are in a security arms race this money neither buys weapons or a defence that can't be overcome by opponents simply buying better weapons and defences. The NSA could have made more of an effort to harden American business and infrastructure to attack. They could have spent the money on developing intelligence sources who actually work for opponents instead of US telcos. They could have fixed zero day exploits. We are rapidly approach a time where oponents will be able to attack completely annonymously. American infrastructure or buisness could be damanaged and know one ever know who or why. If that happens cold war tactics will seem hopelessly naive.
- vasilipupkin 13y agoI am saddened by how out of control this is
- junto 13y agoThere is an old saying that states that a jealous husband or wife can't be trusted. They don't trust you because they are, have, or are thinking about fucking someone else. When the combined '5 eyes' come out and ban Lenovo / Huawei from being used on any of their secure networks, because of fears of back doors [1], one has to imagine that the same is true of themselves. The hardware is most likely backdoored as well as firmware, the OS and installed software. I would not trust anything, even open source, because to be perfectly honest, there a very few people who really are smart enough to understand the in depth cryptographic requirements. If there are people, then they probably already work for the NSA or GCHQ. If you want to plan a terrorist attack or become a politician or business leader who does not want to be blackmailed, don't do anything on the internet apart from share pictures of cute cats. My advice to any terrorists is to go dark. Speak in private. Write it down pass the note and then burn it. Use old methods like book ciphers. Touch and electronic device and they have you. Legal note: Of course I'm not advocating 'advising' terrorists, well only the good ones, you know those ones that we call 'freedom fighters'. The ones western governments like to back when it suits their purposes. [1] http://www.infosecurity-magazine.com/view/33679/lenovo-computers-banned-by-the-five-eyes-spy-agencies/ http://www.infosecurity-magazine.com/view/33679/lenovo-compu...
- jacquesm 13y agoFrom the other article on the same subject: "Among the specific accomplishments for 2013, the NSA expects the program to obtain access to "data flowing through a hub for a major communications provider" and to a "major internet peer-to-peer voice and text communications system". " That second one is hard to read other than 'skype'.
- ChrisAntaki 13y agoThe NSA promises to make our country stronger, then they purposefully weaken it. Then they name the programs after battles in the Civil War.
- pyaniv 13y agoJust shame on the rest of countries around the world to let the USA control and abuse the internet and all relevant technologies. Every major chip, OS and software is created in the USA. If people elsewhere lack the brains and innovation of USA, they should accept the consequences. Of course, I'm part of the dumb ass rest of the world.
- consonants 13y agoI want to take a step away from the personal privacy violations here, and approach from an angle that (unfortunately) would motive those with money to lobby against this: your business secrets are out there being collected and reviewed by an organization composed of the smartest and most secretive people in our country. There really should be no doubt at all that there is corporate espionage and insider trading going on. On one hand, if the NSA approached this with giving helpful 'heads up' when a US-based multinational's overseas factory might be planning to strike, or provide their foreign competitors' private dealings etc etc, they could win brownie points. But you know it won't stop with screwing around with overseas business. If they are not already, you can bet that internal insider information is going to be traded and sold. You can't trust a rogue, so as long as it is not dismantled they are indirectly if not directly a hostile threat to your ability to conduct business.
- jlgaddis 13y agoIf you need me, I'll be off changing every password that I've ever stored in LastPass (incidentally enough, I just realized that their Corporate HQ is just outside Washington, D.C.).
- quenlinlom 13y agoIt's been out ten days already before the news agencies decided to report it: https://encyclopediadramatica.se/PRISM#Parabon_Leaks https://encyclopediadramatica.se/PRISM#Parabon_Leaks Magnet link of the alleged software used to break encryption methods: magnet:?xt=urn:btih:f8a942ccff260f7b9035bbf3b8af5c3013e21097&dn=Parabon+Leaks
- joe_the_user 13y agoCan I spotlight exactly why installing backdoor in software is especially worrisome? Why is this not just the same as the other clever ways the smart NSA listens in things (not that I'd like but there's something more)? Well, the thing about backdoors is they get installed on the outside of everyone's software/chips/machines and then ... someone else, someone with less to loose than the NSA, starts to use them for more crudely nefarious reasons, either criminal activity or spying by other nations. All of this bears resemblance to the former USSR. Once bureaucracy claimed unlimited political power, the next step was for the "mafiya" to take advantage of the universal silence and surveillance.
- ivarv 13y agoShouldn't this result in a drastic devaluation of crypto currencies like bitcoin?
- Mordor 13y agoAll the more reason for choosing Chinese own brand.
- B-Con 13y ago> The N.S.A.’s Commercial Solutions Center, for instance, invites the makers of encryption technologies to present their products to the agency with the goal of improving American cybersecurity. But a top-secret N.S.A. document suggests that the agency’s hacking division uses that same program to develop and “leverage sensitive, cooperative relationships with specific industry partners” to insert vulnerabilities into Internet security products. That sounds a lot like "the division to provide security advice was providing advice that would make it easier for the NSA to break". Page 4 of the article was the most interesting.
- zorlem 13y agoI wonder if the recently discovered problems with non-unique key parameters could be the result of the cooperation of particular network gear vendors with NSA. https://factorable.net/weakkeys12.conference.pdf https://factorable.net/weakkeys12.conference.pdf https://www.usenix.org/system/files/conference/usenixsecurity12/sec12-final228.pdf https://www.usenix.org/system/files/conference/usenixsecurit...