7 ms·
"Unless the feds know of a flaw in the Diffie-Hellman key exchange process at the heart of this scheme..." The only flaw in the DHM algorithm is that it depend
by Sonicmouse 13y ago
"Unless the feds know of a flaw in the Diffie-Hellman key exchange process at the heart of this scheme..."
The only flaw in the DHM algorithm is that it depends on a RNG.
It goes back to the fact that if the NSA has infiltrated the RNG, then DHM key exchange is merely a slight nuisance.
I wrote some software that patched out MS' CryptGenRandom() to only return 0x01's all day. I was easily able to then implement a MITM attack on Adobe RTMPE traffic all day long.
I'm stupid... Imagine what an NSA engineer could accomplish.
- norswap 13y agoYou're probably less stupid than you give yourself the credit for. But yes, NSA could do this. Still, this is not practical for dragnet surveillance. I highly suspect "breaking most of the cryptography on the internet" is an over statement and that most of what they can break derive from people using weak cryptographic algorithms and/or making mistakes in the usage of cryptographic primitives.
- 0x0 13y agoWonder how well Wine implements that, actually.
- lukifer 13y agoWhat's the practical alternative, assuming a compromised RNG? random.org?
- croikle 13y agoNo. You cannot outsource your random number generation unless you have an ultimately trusted third party. The important thing is that nobody knows your random numbers. After all, random.org could be malicious or compromised, too.
- e12e 13y agoIf I were the NSA, I'd definitively try to run a service (or two) like random.org. It'll probably be cheaper than my tor exit nodes, and mixmaster remailers...
- gojomo 13y agoI suppose if you had one RNG that's 0wned by the NSA, and another that's 0wned by the Chinese MSS, and another by the Russian FSB... and you assume they never ever work together or crack each others' systems, you could XOR their results together.
- sliverstorm 13y agoSee, this is the kind of security thinking I can get behind. The kind of realist thinking that says "Ok, we should just assume we've been compromised by every major government entity. Now what."
- codelust 13y agoStrangely, that is what my thoughts on snooping at this level has been for a while. Using a combination of compromising people and infra, it is easy to break pretty much anything if, as a state, you put your mind to it. Unfortunately, the debate is mostly centered around if crypto is broken, while the question to ponder is why is the state suddenly forcing well-meaning people to start thinking like people who have something to hide.
- SilasX 13y agoNope. Random.org could be compromised. XORing it with your /dev/random, plus a locally-generated randomness source would work though.
- Aloisius 13y agoA camera and a lava lamp?
- Quequau 13y agoMy current best guess: A Hardware True Random Number Generator installed on one server combined with entropy broker to commingle all the entropy pools of the devices on my internal network into the entropy pool of that server and then serve that pool back to all devices acting as an entropy server. My intent is that if there is a deliberate weakening of certain entropy sources, that my pool is sufficiently different to at least complicate attacks which are guided by information like browser signatures. Maybe it's not a perfectly secure solution but hopefully my network isn't among the lowest hanging fruit.
- rorrr2 13y ago> It goes back to the fact that if the NSA has infiltrated the RNG NSA has NOT infiltrated the RNG. They did one particular hardware implementation of it. You don't have to use it.
- acqq 13y ago> They did one particular hardware implementation of it. Citation?