3 ms·
Last year's winner should have been NPR's U.S. Worries NSA Leaker's Files Could Be Hacked (Tom Gjelten) [0] http://www.npr.org/templates/story/story.php?s
by iconjack 12y ago
Last year's winner should have been NPR's
U.S. Worries NSA Leaker's Files Could Be Hacked (Tom Gjelten)
[0] http://www.npr.org/templates/story/story.php?storyId=203531584 http://www.npr.org/templates/story/story.php?storyId=2035315...
This story came out when Snowden was still at the Moscow airport. At issue is whether Snowden's files can fall into the hands of the Russians or Chinese. This is a fair question. But the piece focuses on physical access to the files on Snowden's laptops, which is simply comical. Of course they can take his files. A listener would get the impression that Snowden's protection of the data consists of holding tight to his computers while the Russians attempt to wrest them from his arms, or his ability to sleep with one eye open and his laptops at his bedside. My favorite gem was when security expert Lee explained that you can get at a laptop's hard drive using nothing more than an ordinary screwdriver. Will the Russians be able to locate a screwdriver? Only time will tell.
Gjelten tells us: "For Snowden to have kept his files secure, he would have had to keep his laptops powered off and disconnected from the Internet. Plus, he'd need physical control of the machines at all times." This statement is irresponsibly misleading. A trusting listener would have no choice but to conclude that Snowden's secrets are unprotectable after hearing this. But the truth, access to the files themselves are unimportant, because they are surely encrypted.
Eventually they did get around to talking about encryption. Their experts on the matter were the likes of Mark Weatherford, ex-DHS undersecretary who now works at the Chertoff Group (as in Michael Chertoff), who told us that "Encryption really only buys you time. You can eventually decrypt it. It just takes time to do that, and it's really dependent on the algorithm and the keys." Again, it's being emphasized that it's only a matter of time before the Russians have the goods. What is not mentioned is that a modest-sized encryption key buys billions of billions of billions of years [1]. It would be an earth-shattering breakthrough if the Russians or the Chinese or the Americans had an algorithm that could beat this.
At one point, Michael Sutton of Zscaler admits: "If Snowden were using the best possible encryption and he was using a strong key, it would be virtually impossible for NSA, China, Russia - anyone - to access that data." But Gjelten immediately smothers this thought: "At least in the short run. There are ways to break a code, if only by what cyber technologists call brute force - essentially having a computer try every possible key combination until the correct one is found. Mark Weatherford, now at the Chertoff Group, points out that no encryption lasts forever." Not forever, but much longer than the age of the universe. At no time in this story is it revealed the kinds of time frames we are talking about. By the way, "the best possible encryption" is available for free and runs on any computer, and a strong key takes an insignificant amount of effort to generate.
Finally, the piece ends with "In all, cyber security experts agree, the likelihood is good that the Chinese or the Russians or both, will sooner or later have whatever documents Snowden has taken with him, whether he intended to share them, or not." This is false. Not only is it untrue that the Russians are likely to get the data, it is also untrue that cyber experts agree that they will, which Tom Gjelten would have known had he asked any non-government-affiliated encryption expert.
In short, Gjelten spent the first half of the piece addressing physical access to the files, which is ludicrous, and the second half convincing us that encryption is futile, which is the opposite of the truth.
[0] http://www.npr.org/templates/story/story.php?storyId=203531584 http://www.npr.org/templates/story/story.php?storyId=2035315...
[1] http://www.eetimes.com/document.asp?doc_id=1279619 http://www.eetimes.com/document.asp?doc_id=1279619