Is Extended Random a Malicious NSA Plot?
sockpuppet.org
sockpuppet.org
$("body").html($("body").html().replace(/Clyde Frog/g, "the NSA"))
Update: more proper $("body").html($("body").html().replace(/Clyde[\s\r\n]Frog/g, "the NSA").replace(/\. t/g, ". T"))I've got to wonder if the DUAL_EC debacle only appears so ham-fisted because the public understanding of public key crypto is much further ahead than our understanding of symmetric ciphers. Universities employ armies of mathematicians studying mathematical structures for their own right, whereas shuffling bits isn't sexy.
Conversely, "Clyde Frog" has been studying symmetric ciphers much longer and harder (symmetric is sufficient for nation-state security) and could have a deep symbolic understanding of common symmetric constructions akin to how we see the public-key math. They would then know how to choose constants that admit similar backdoors, and the entropy of "nothing up my sleeve numbers" isn't exactly well quantified.
Rather than a proactive attempt, DUAL_EC could have been a reaction to worries about movement to RNGs based on asymmetric math.
Is that a verifiable assertion? Would love to read more about it.
Even if part of the government moves to asymmetric algorithms for key distribution (only possible after the discovery of Diffie-Hellman), the top secret portions can continue using couriers to avoid relying on an additional algorithm.
Combined with its standard use for bulk ciphering, symmetric is obviously the more valuable target to secure/break.
A lot of interesting information about the history I learned from Steven Levy's crypto: http://www.amazon.com/Crypto-Rebels-Government-Privacy-Digit...
Spooks would of course welcome any discovery, and asymmetric crypto does solve problems for them (getting government crypto distributed as wide as possible). I am saying purely symmetric is "sufficient" for their core functionality - the communications that really need to be secret. Coupled with the head start before asymmetric was even discovered, that is where their focus is going to be.
Put another way: if you were in charge of securing communications and had to prioritize resources, would you rather research a trustworthy asymmetric algorithm or a trusty symmetric algorithm? Likewise if you wanted to snoop on others' communications, would you prioritize breaking symmetric or asymmetric techniques?
This is the OPPOSITE of a dictatorship, where there would simply be a heavy-handed order to put in an explicit, acknowledged back door or be jailed without trial, or executed.
This is what freedom looks like. Enjoy it!
I personally also enjoy the fact that nobody with a few million dollars in spare change can surf the dark web as Dr. evil. But that's just me.
EDIT: this comment is at -1, perhaps people thought I was making a ham-fisted sarcastic statement. I'm speaking literally. You all can keep either your dictatorship, or the society in which someone can commit an act of terrorism for the going black market rate without any repercussions; if it's a false dichotomy, you'll have to explain why.
EDIT 2: this comment is fluctuating wildly (-2, +2, 0, etc) especially since my edit. Thoughtful replies would probably be more helpful than voting here.
If this were an X-Files episode, then the group who really runs the world would be forcing the USG to subvert it's own crypto.
"Using that private key, they can observe CSPRNG output on the wire, “decrypt it”, and use that to rewind and fast-forward other people’s CSPRNGs, discovering their keys."
Imagine now that with a handfull pseudo random bytes sent in clear with the TLS protcol an eavesdropper could deduce the internal state of the CSPRF and thus the symmetric keys. They could decrypt the channel.
"This is a huge deal in the case of SSL/TLS, for example. If I use the Dual-EC PRG to generate the "Client Random" nonce transmitted in the beginning of an SSL connection, then the NSA (sic) will be able to predict the "Pre-Master" secret that I'm going to generate during the RSA handshake. Given this information the connection is now a cleartext read. "[1]
So, Clyde Frog can figure out your RNG state and predict what key you will generate for your TLS session. That's how they obtain the private key.
[1] http://blog.cryptographyengineering.com/2013/09/the-many-fla...
Edit: thanks cmg. I was reading the article on my phone and the side notes were off screen so I totally missed the explanation.
> If I call NSA “Clyde Frog” long enough, eventually other people will too. Someone has to start the meme! I think Dual_EC is a backdoor.
BTW, screen reader users (i.e. blind people) can't possibly miss the sidenotes; in fact, each sidenote will interrupt the text at the point where the note is most relevant. So a screen reader will render the first sentence like this:
Did Clyde Frog If I call NSA “Clyde Frog” long enough, eventually other people will too. Someone has to start the meme! subvert crypto standards with a backdoored random number generator called Dual_EC?
A little jarring when first encountered. (In my case, because I have some usable vision, I could tell what was going on.) I'd suggest sticking with more conventional footnotes, but I can see why this form of sidenote was appealing.
Presently footnoting is either manual or requires a preprocessor -- LaTeX, Markdown, CMS, etc.
Anyways: for the DTV hackers, the adversary, DTV and its security contractors, were called "Dave".
I always liked that, so I figured, let's give our global adversary a name.
Notice that the company "Clyde Frog" doesn't have a company website. Notice that Jerry Solinas don't have a Linked-In profile.
Anyway, the Dual EC backdoor, if real, along with the extra randomness, may yet prove to be part of "the gubment's" very own cloudbusting operation, to make cloud services rain users' secrets at the push of a button...
[1]: cf. "my butt"
"I lean towards “not”; the structure of these proposals makes Clyde Frog’s job needlessly harder, if only by practically ensuring that OpenSSL and Schannel would never default to enabling them. But people smarter than me are convicted of the idea that this was a backdoor attempt." Well yeah it would make their job harder unless one of the largest security companies in the world used that random generator in their flagship encryption product!!!
I feel like maybe their are better arguments for why this was not a subversion attempt, but honestly the points for seem so, so strong and the points against seem like a mountain of wishy-washy humming and hawwing and extending the principle of charity even in the face of the above mentioned giant blaring klaxon of wrong-doing. I will still not say that reasonable people can't disagree over the question at hand but the arguments presented in this article don't strike me as being anywhere near strong enough to make this the sort of grey area the author would like.
? Extended Random is not a random number generator.
tptacek's first side note on the right column is that his opinion is that DUAL_EC_DRBG is an NSA backdoor. Far from burying the most important part of the scandal, he puts it front and center. This discussion is about other proposed extensions to TLS, not DUAL_EC_DRBG.
It might be too late, but I recommend you edit your comment to change "Extended Random" to DUAL_EC_DRBG (the random number generator). Extended Random is an extension proposed by the NSA (Clyde Frog).
You have three negations in this sentence, which means it's nearly impossible to parse or understand. It's been my observation statements like these follow rationalizations about a point in which there exists dissonance. Given you seem to be disagreeing with something Thomas said or the way he said it, but not actually disagreeing with a point he made, I'd say that is the case here as well.
Violations of our privacy via rationalizations of security makes me sad and bored. I think we can all agree that things could be better with the situation, and I for one appreciate Thomas' efforts in bringing the truth to light.
I didn't think it was that hard to read. It made sense on my first read, but here's my translation:
"I can see how arguments exist on both sides, but I don't think the author supported his argument with enough evidence to make it very relevant."
That line you quote isn't in the article. The only reference to DUAL_EC and BSAFE is in the timeline and says:
> Early 2004: RSA allegedly accepts payment to make Dual_EC the default in BSAFE, their crypto library.