4 ms·
Regarding your first point, there's some confusion between active exploits (i.e. botnet infections, etc) and passive intercepts. They are indeed cautious about
by AlyssaRowan 11y ago
Regarding your first point, there's some confusion between active exploits (i.e. botnet infections, etc) and passive intercepts. They are indeed cautious about using exploits and botnet platforms (I don't think that makes any of it right).
Absolutely NSA & GCHQ should be able to crack RSA-1024: it is not magical, and it is definitely well within their budget, but it still isn't particularly cheap timewise, so unless something is really super important, it's not going to join the crypt attack queue for supercomputing resources, and they would not be waving it around too widely.
By comparison, we know RC4 is toast. We have a rough sketch of the attack (though please correct me if any of this is wrong): passive; returns plaintext from ciphertext, with either no or a few bytes of known plaintext header at most; runs in software on blades and other places at mass-intercept scale in real-time, so we have an upper bound on its complexity (and it's very low compared to RSA-1024).
We don't know many technical details about the attack yet. RC4 is a peculiar beast, quite unlike semi-modern or modern ciphers like AES or Salsa20/ChaCha20: huge state; crappy diffusion; several known weaknesses, but no public break yet. I can't wait to find out more: this is one of the few areas NSA actually are ahead, as the public sphere definitely know RC4 is too wobbly to use, but still quite some way off decrypts of it. Whatever technique is used may well not be applicable to ciphers of a more modern design (but what about Spritz?).
If you've been using RC4, ever, this should give you pause. Think about what's ever gone out using it. Think about what someone could have recorded - likely did record. Do you need to be changing any passwords?
If you're still using or accepting RC4 anywhere for any reason (ahem, Mozilla, Google, Microsoft?), for heaven's sake, get your arses in gear. You're not beating the attackers, you're now only limiting the damage. Given the RFC and everything, and the internal discussions you've been having, I personally would be loathe to consider any further delay ethical before action. Please do remember Holmes' Law of Reverse-Engineering: what one can invent, another can discover.
- noinsight 11y ago> If you're still using or accepting RC4 anywhere for any reason (ahem, Mozilla, Google, Microsoft?), for heaven's sake, get your arses in gear. Amazon AWS signup, as of last night? http://i.imgur.com/Wq0lnnR.png http://i.imgur.com/Wq0lnnR.png
- wolf550e 11y agohttps://www.ssllabs.com/ssltest/analyze.html?d=portal.aws.amazon.com https://www.ssllabs.com/ssltest/analyze.html?d=portal.aws.am... If your TLS client tried stronger cipher suites before weaker ones (which only MSIE does, and it considers only RC4 weak), you can get TLS 1.0 with RSA key exchange, AES-256-CBC encryption, HMAC-SHA1 authentication with that server. That's not secure (only TLS 1.2 with PFS and AEAD is secure).