The NSA is not made of magic (2014)
schneier.com
schneier.com
The encryption algorithms themselves might be unbreakable, but there are so many other stages involved in communication. And all it takes is one weak link in the chain, one tiny mistake or opening, and humans make plenty of those.
No, the magician did not look at you picking your card, but he found a way (based on your inherent inability to be fully attentive to everything) to figure it out anyway.
Then again, maybe they do have magic and it's a massive triple bluff. Or maybe...
I mean, this how you get a couple of hobbits up in your shit before you know it.
Similarly, the NSA can accomplish what would seem like magic by doing brute force stuff like tapping an undeground cable with a submarine or getting you to hire moles into your organization, or just plain breaking and entering. 10 billion dollars may not buy you a lot of computers but it buys you more man hours than their targets can ever hope to expend on protecting themselves.
A recent public example, but there's lots of other techniques: https://www.youtube.com/watch?v=ZD8CNxYe5dk
Paying lots of money to access data at rest would really be more under the CIA, to be honest. The CIA is, theoretically, only supposed to go after data at rest, and leave all the sigint to the NSA.
Most of the time it takes significantly less than suitcases full of money. There are plenty of examples out there where hurt feelings, a sense of patriotism, a sense of honor or even simply a need to be recognized were enough.
Sounds like "super-secret cryptanalysis" to me. That was 2012 and Schneier was writing in 2014. I wonder what would qualify as magic to him?
> The first cryptographic collision attack against the cryptographic hash function MD5 was invented by Xiaoyun Wang et al. in 2004, which however did not pose a serious immediate threat due to technical limitations. Subsequently, we have devised a more flexible collision attack against MD5 in 2007, a so-called chosen-prefix collision attack. This posed a greater threat due to the removal of the most important technical limitation. Finally, we refined our attack in 2008 and used it to construct a rogue Certification Authority, thereby demonstrating a serious vulnerability in internet security. Our demonstration convinced Microsoft and various governments to raise the security standards for Certification Authorities, by disallowing the use of MD5-based signatures effective 15 January 2009.
Flame was probably deployed around February 2010 and the practical attack was announced May 2007, giving 2.5 years for finding a variant and make and debug the malware. Seems reasonable if you have good cryptographers and development team, since the collision is fairly well contained functionality that doesn't block other parts of the project.
Generally I would reserve the term "magic" for secret crypto that is better than state of the art, a new variant of state of the art is simply impressive.
[0]: https://www.cwi.nl/news/2012/cwi-cryptanalist-discovers-new-...
DES also defended against a technique that wasn’t developed in the public until two decades later. That technique was originally developed at IBM and NSA merely convinced them to keep it secret, so I’m not sure how that qualifies.
Edit: Schneier has written about these before, of course. I wonder if his point here is not that the NSA was always boring, but rather that its lead is way less impressive than it once was.
But with all the people (e.g. costs) NSA has, I don't think much of their budget goes to the kind of blue sky research you need to make their own magic.
[0]: https://www.schneier.com/blog/archives/2018/04/two_nsa_algor...
Are you a US telecom and help the NSA? DOJ will not bother you for a lot of things
He was convicted of 19 counts of insider trading in Qwest stock on April 19, 2007[1] – charges his defense team claimed were U.S. government retaliation for his refusal to give customer data to the National Security Agency in February, 2001.[2] This defense was not admissible in court because the U.S. Department of Justice filed an in limine motion,[3] which is often used in national security cases, to exclude information which may reveal state secrets. Information from the Classified Information Procedures Act hearings in Mr. DiNaccio's case was likewise ruled inadmissible.
Otherwise the references are a bit confusing...
NSA benefited from companies having access to people's data. Those companies were doing their job for them, for free.
Data is power. The rule setters change the rules to favor themselves, as they always do.
You answered neither to my nor your immediate parent's post.