9 ms·
This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has lon
by dailyrorschach 13y ago
This is likely a minority view, but I have no problem with the NSA being able to break encryption, that's in fact part of their job. Decoding encryption has long been part of their mission. I also suspect they're not alone in terms of signals intelligence groups in having this capability.
The issue to me has always been how and what data they access and store, and how it is used.
- mhurron 13y agoIf the NSA can, others can. It makes the whole thing useless.
- draugadrotten 13y agoEncryption is still useful. The NSA can read your messages - but not everyone. Encryption will still protect your bank transactions and wikipedia reading. No encryption will protect you from a goverment turned Evil, and I hope you realise this. If the US government is good or evil is all a matter of perspective. War is peace, Mr O wrote, and surely there has been a lot of that going on in US foreign policy the last few decades.
- a3n 13y agoI guess I'm with you on the ability to crack. Any researcher should be able to try as hard as they want, and succeed. I draw the line at collecting everything without specific warrants, regardless of what they do with it, against their charter and the Constitution. I draw the line at hardware backdoors for equipment that I buy, and insertion of vulnerabilities into encryption standards that I take advantage of. Or I guess I should say that take advantage of me.
- dailyrorschach 13y agoI'd agree with that. I've often been wondering if where we're headed is a some kind of reform compromise. Not that I think it's ideal or right, but for example I could see the NSA having a Chinese wall around data for Americans, such that FBI and other investigators could not use data collected by the NSA, but could open their own collections with a warrant. I'm quite opposed to what the NSA has done - but I don't see anything happening that will change it. If the recent revelations haven't done anything to stir Congress to action I don't know what will. Additionally, until and/or unless the NSA ever uses data collected this way against an American citizen in a judicial/criminal way, the courts are quite likely to find that petitioners lack any standing.
- swombat 13y agoAs a non-American, I find your lack of support for people who weren't born in your little patch of land quite uninspiring.
- dailyrorschach 13y agoWell I also assume that many other signals intelligence agencies are collecting data. Having worked at a time for a large global PR firm, I am sure many if not most of our communications were intercepted, especially with work once done for a Chinese based phone hardware maker. I think it would be a massive mistake to assume this is a United States only issue, so far the United States is the only country to have someone leak the information. So - yes, my most immediate legal concern is how the US government could use the data collection against me contrary to protections given. That doesn't mean there are many more and larger concerns to be thought through, I was merely speaking to one of them.
- haakon 13y agoThe larger issue here is that they "covertly introduce weaknesses into the encryption standards". It's not that they cleverly and fairly break encryption, it's that they sabotage the standards.
- smtddr 13y agoI have a problem with encryption being breakable, regardless of who's doing the breaking. I want encryption to be mathematically solid with the only option being brute-force older-than-age-of-earth time. When we get to quantum computing, then I don't know what we'll do...
- gizmo686 13y agoQuantom computing cannot break all of crypto. Anything based on P!=NP is believed to be secure against quantom computing, and there are several encryption methods backed by P!=NP
- mcherm 13y ago> Quantom computing cannot break all of crypto. Correct (except for the spelling of "Quantum"). > Anything based on P!=NP is believed to be secure against quantom computing, and there are several encryption methods backed by P!=NP Incorrect, well mostly. The deal is that there are problems that can be done in "polynomial time" (how long it takes is not exponential in the size of they key) for a normal computer (or person); the set of these is called "P", the ones that CANNOT be done on polynomial time is "NP". And there are problems that can be done in "polynomial time" (with reasonable limits on errors) by a quantum computer; the set of these is called "BQP". If P = BQP it would mean that quantum computers can (in reasonable time) solve all the same problems that classical computers can. But in fact, P is a subset of BQP: there are problems that are "hard" for classical computers but "easy" for quantum computers. An example of this is factoring numbers. Shor's algorithm is a way to factor numbers using a quantum computer and it runs in polynomial time. Now it isn't practical today: the biggest quantum computers in existence are hard put to factor the number "10", much less some 40-digit monstrosity. But computers only get better. Fortunately, there are problems which are NOT in BQP -- problems that are hard even for quantum computers. And these are the ones you want (not those in NP) if you want to stymie a quantum computer. For more details, see http://www.scottaaronson.com/papers/bqpph.pdf http://www.scottaaronson.com/papers/bqpph.pdf or frankly ANYTHING written by Scott Aaronson (http://www.scottaaronson.com/blog/ http://www.scottaaronson.com/blog/).
- jonknee 13y ago> I have no problem with the NSA being able to break encryption, that's in fact part of their job. Their "breaking" of encryption is a combination of purposefully introducing vulnerabilities into standards, surreptitiously altering software and hardware to give the NSA a backdoor, hacking into private systems and stealing keys, etc etc. I'm cool with an NSA super computer trying to brute force my VPN traffic to YouTube, I'm not cool with the NSA planting an engineer at a chip fab and changing designs to add a backdoor (a backdoor that could also be exploited by other actors).
- XorNot 13y agoI will bet good money that the NSA has never bothered to try and plant backdoors in encryption standards. If the NSA recommends AES to the US government, but knows there's a vulnerability, then they have to assume that any adversary may be as good as whoever designed it. Which means an adversary would be perfectly capable of discovering and exploiting the weakness. Which in turn means the NSA has just made the entire US government vulnerable to foreign or non-state actors. The same applies to anything you might imagine doing to chipmakers. Not only is there the risk of being found out (how do you explain to a talented engineer spotting a flaw in a schematic, how high up do you have to go to try and stop that leaking?) but there's the more serious risk that you've just added a backdoor to hardware you yourself need to be secure. Which again, could be discovered by an adversary and used against you. This whole line of argument has always been speculative fiction on the part of the internet: it's looking for unicorns because you heard hoofs.
- gaius 13y agoWhich in turn means the NSA has just made the entire US government vulnerable to foreign or non-state actors. Yes, and it says this in the article. And it makes perfect sense too. If you were the NSA, wouldn't you want a heads up if someone was talking about budget cuts?
- jonknee 13y ago> I will bet good money that the NSA has never bothered to try and plant backdoors in encryption standards. Did you read the article? > By this year, the Sigint Enabling Project had found ways inside some of the encryption chips that scramble information for businesses and governments, either by working with chipmakers to insert back doors or by surreptitiously exploiting existing security flaws, according to the documents. Seems pretty cut and dry.
- stdgy 13y agoThe problem isn't that they're working to break encryption. The problem is that they're maliciously inserting backdoors and subverting crypto-research and publication, which puts all of our security at risk. (Not to mention runs counter to their stated mission)
- mullingitover 13y agoIt's definitely great knowing that our government is willing and able to commit pretty serious industrial espionage, and if anyone tries to do anything about it, hey, we have nukes too. Don't worry everyone, we're the good guys! We promise to send you some foreign aid after you've come to terms with your subjugation. /s
- alasdair_ 13y agoThere are a couple of other issues, even if one agreed with your view: 1. They obviously can't keep their own secrets, so it's unlikely that they will do any better than keeping yours. Eventually, your data will leak out to non-NSA people. 2. By adding backdoors, they weaken the encryption. This implies that anyone with sufficient skill who goes looking for backdoors may be able to exploit the hole that the NSA opened up. This is a big deal, especially if you have secrets that you need to protect.
- eruditely 13y agoWe cannot rely on them to be always good so we have to also have the prior, encryption to protect us if the law or law makers are not working for our best interest.