Insecure by design: protocols for encrypted phone calls
benthamsgaze.org
benthamsgaze.org
The reality is the telecommunication industries in UK, US and other nations are complicit with such activity because they are legally required to provide access to their partners in government intelligence. And they operate in highly regulated environments that they will be shut out of if they don't cooperate.
Encryption has moved to the OS level, which is why we're seeing similar pressure being presented to Apple with this terrorist's iPhone.
Yes, but the NSA did have a hand in AES
Nowdays the NIST is guiding the process of standartisation, but does not itself activally doing anything. Most cryptographers agree that in the process for SHA3 ran quite smothly and they did a good job. However when the NIST tried to over some improvments, the crypto community heavly stomped them and these improvments never went into the standart.
There were talks on these subject in the last couple of Chaos Communication Congresses.
There's enough to be paranoid about already. No need to looking for problems where there aren't any.
In any technical field, it is important for the “good” and “best” people from that field to participate in group activities so that there is a better chance of sane decision-making. And in any sufficiently-complex field that has a government agency, you would certainly hope that at least some of those “good” and “best” people are working for the government. So what to do?
Perhaps one approach is to make sure no one group is over-represented, e.g. 5 different organizations that each have one vote or something.
To me, this says that they would be more likely to recommend fundamentally sound encryption schemes, but choose parameters where they can have hidden knowledge that lets them undermine it. Stuff like what people think they may have done with the eliptic curve constants, where they [supposedly] have chosen constants that they have extra knowledge about, but the method itself is apparently otherwise quite solid.
If I'm reading this right then they basically have access to all 3G/4G data and they do so in a way that cannot be detected.
My home country is rather delightful, isn't it. :(
I'm French so of course I would tend to agree about UK (;-) but if I start to look at my country there are a lot of things not to be proud of ... and if I look at the neighbors it's the same, even Switzerland helped South Africa back in the apartheid days on a project to gas their ghettos !
Maybe Iceland ?
If anyone thinks that France, Germany and others aren't doing the exact same stuff, then they're very mistaken.
The UK is so bad that the NSA has more rights in the UK then in the US.
The UK's surveillance program was even ruled illegal once it was found out what they were doing. So what if a lot of the German public are against surveillance - so are a lot of Brits - they just don't know what their government is doing in secret.
I'd bet everything I own the French and Germans and every other major country are doing the exact same stuff.
Germany is somewhat different because of its history. We know quite a bit about what the BND does, in terms of monitoring extremist groups. We have pirates in pretty important positions and the CCC is regularly working with government in oversight commissions.
It is pretty hard to hide all that you are doing, both in terms of physical infrastructure and in terms of financials. Now it may be that the BND is extremely clever and hiding all of this from basically everybody. However given the competence displayed by the BND on various action that they have taken, it is a really hard sell that they are operating a infrastructure close to the US or UK one.
My point is that a lot of the outrage is only because the UK and US are the only ones we know of.
Countries spy for most of them it would irresponsible not to do so because riding on the high horse doesn't have much rewards on its own.
What! Please provide a source on that.
I found some links in French stating that Switzerland launched an investigation in 2002 about this.
So good sir, you are absolutely mistaken.
As a post script, Apartheid was bad but it was not much more than legalized discrimination. Let's not demonize Apartheid any more than for what it really was. And the current situation in South Africa is far worse than the situation ever was during the reign of Apartheid.
How did you reach that conclusion? While probably true, this article merely (poorly) describes how GCHQ "improved" on another backdoored encryption standard by making snooping impossible to detect.
This is only a thing because GCHQ has started certifying software and supporting the MIKEY-SAKKE protocol is a hard requirement.