3 ms·
NSA didn't need to backdoor DES when they just forced everyone to use weak keys: > 1979 - Present, DES: The Data Encryption Standard was altered by the NSA to
by salient 13y ago
NSA didn't need to backdoor DES when they just forced everyone to use weak keys:
> 1979 - Present, DES: The Data Encryption Standard was altered by the NSA to make it harder to mathematically attack but easier to attack via Brute Force methods. The original version of DES, called Lucifer, used a block and key length of 128-bits and was vulnerable to differential cryptanalysis. NSA requested that the already small DES key size of 64-bits be shrunk even more to 48-bits, IBM resisted and they compromised on 56-bits11. This key size allowed the NSA to break communications secured by DES.
http://ethanheilman.tumblr.com/post/70646748808/a-brief-history-of-nsa-backdoors http://ethanheilman.tumblr.com/post/70646748808/a-brief-hist...
This is why any known NSA employee from security standards groups (including IETF and Trusted Computing Group [1]) must be forbidden to participate in the making of that standard. Their role there can only be seen as to facilitate weakening of the standards, either by weakening the algorithms themselves, or if that's too hard and/or obvious, to convince everyone else to use a weaker version of it (which NIST kind of tried to do with SHA-3 recently, too).
As long as there's any chance of NSA being involved even remotely in a security standard, I'm going to lose faith in that whole standard and the group.
[1] - http://www.securitycurrent.com/en/writers/richard-stiennon/it-is-time-for-the-trusted-computer-group-to-repudiate-the-nsa http://www.securitycurrent.com/en/writers/richard-stiennon/i...
- abadidea 13y agoI did consider trying to work in the part where they shortened the keys and eventually DES became useless because of it, but it was a bit of a diversion from the salient (heh) reason I put this on the timeline, that they improved the s-boxes without explanation and that colors any subsequent requests they made to do similar.
- jonpeda 13y agoFWIW, being crackable with extreme brute force (that only the best-funded attackers have) can be a reasonable compromise -- NSA can't crack everything, just the few pieces of data they are willing to spend compute on. The part that I don't understand is Moore's law: if a government lab can crack 56-bits11 in 1979, surely my phone can crack it today?