The NSA Called Me After Midnight and Requested My Source Code
medium.com
medium.com
Your users used the software to protect them, or even paid for it. Now this "Dave" can crack files generated by this shareware. Maybe "Dave" had a genuine national security situation. But was it really? What if Dave just wanted to prank the author, during a boring afternoon? What if it were a couple of guys parked outside who hijacked the phone system, so even if you call 411, it would route to their van outside? Or what if Dave already did the same demand to dozens of other security vendors, effectively having the source code of all encryption software? And even if it was a national security situation, what is the legal basis of giving up source code and keys?
What I get is "I was just a regular computer programmer and overnight, I was actually important enough to be useful for the NSA"
There are way too many people like that in tech, who don't stop to take in the bigger picture before performing the requested action.
Fast forward a year to 9/11, and the question would be, "What is the legal basis for not doing everything you can to help the NSA?"
There are laws and a constitution, you can't just throw it out the window at the first phone call.
The NSA has been reverse engineering binaries for decades. Having the source saves them time and resources from doing that. Today, however, I would expect the NSA has their own binary decompiler.
> There are laws and a constitution, you can't just throw it out the window at the first phone call.
In pretty much most cases there are no laws preventing a private individual from fully cooperating with a government agency under your own free will. There may be professional consequences and civil damages, but it's not outright illegal. You would see this in cases of child porn, terrorist attacks, etc.
And frankly, most people would be so happy to see child pornographers locked up, that they wouldn't ask for a warrant from the investigating agency.
Yes, the author was way too quick to give up the source code, but it was just source code, not a backdoor key.
This means all users of the software are less safe. If the NSA can find a bug in the code, they can unlock everyone's files, but nobody else could ever uncover that bug.
They specifically asked for the code for this purpose. If you made no mistakes, your action did not help them nor hurt your customers. But if you have made a mistake that you're not yet aware, you took a conscious step to make it easier for the NSA to exploit that.
While the availability of source code does not make a difference in theory, this falls apart once you realize that even though the NSA has lots of resources, those resources aren't infinite.
However, I would probably respond along the lines, "I'd be happy to supply this, right after you show me a court order". Otherwise, no matter what, I cannot see how it would not be used for anything other than a nefarious purpose.
I'm willing to bet Dave was a government employee, though I won't give up the possiblity he wasn't NSA and more likely some other government organization that needed to stop something yesterday but didn't have the clout to get the big 3 letter organizations to pay attention and help them out
Calling him at his parents’ place late at night seems less like a coincidence and more like an ominous demonstration of their power. I know that would influence me, and I’d feel more disposed to cooperate.
I could forgive someone making a rash decision after midnight while traveling. But here it is, some time later, and the author still seems to think it’s a cool story. Nice to know that a maker of privacy software doesn’t think skeptically about the government.
And just because a cipher is public does not mean that there does not exist a side channel in the implementation of the ciphers or a mistake in your usage of them.
And just because they have the source code, doesn't mean they couldn't get it from reverse engineering the binary. I have not seen a binary that was completely resistant to reverse engineering yet.
Likely he was just saving them time.
That's an enormous assumption based on zero evidence. The only resource the NSA is limited by is time. Money and man power (up to diminishing returns) are effectively limitless.
They were trying to skip a step, but there's absolutely no reason to believe they could have (and would have) done without through reverse engineering the binary. The NSA guy implied time was the major factor, and wanting the source certainly implies that was the case.
If you want to go further back, there's the Church Committee (which concluded that security agencies were way out of control and had to be reined in).
What I am saying is that in hindsight, this seems like the wrong decision, and I would hope a maker of crypto software would realize that.
Offering broken encryption that appears to work is dangerous, unethical, and stupid.
The author ought to be ashamed and people ought to be smarter.
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
The software was capable of strong encryption it was restricted by being paid for.
Also the lawsuit was against Phil Zimmermann himself, not PGP.
It was also what was legally exportable at the time.
Providing some security is better than providing none. You lock your doors but have glass windows.
Taking slightly longer for a computer to open your files while I put my feet up and drink coffee doesn't suggest an increased degree of security unless it requires a truly substantial investment in hardware or time. The encryption in question could have been broken on a home computer 4 years later in 2 weeks.
Seen as bad is a poor benchmark it WAS bad.
The legal limitations on crypo export is a bad argument on so many fronts its hard to pick one.
- The legal matter of exporting encryption was well on its way to settled by 2000 see https://en.wikipedia.org/wiki/Bernstein_v._United_States where such restrictions were found to be illegal in 1999.
- Author sold a higher grade of encryption including abroad
- Author either didn't care about the law or would have been afoul of it with his paid version.
- The laws against exporting encryption were a useless farce that never did anything useful
Knowing that his customers privacy was on the line, knowing that there was no due process, knowing that revealing the source would help the NSA violate his customers privacy, not needing any explanation or legal paperwork, not even truly knowing if the person on the other end of the line actually was the NSA, not a private citizen trying to violate the privacy of another citizen he decided to comply without question.
Ticking bomb scenarios that can be solved by cracking encryption are so rare I'm not aware of any existing in history.
The right answer was to request a court order and wait. If it was truly a matter of national security they can also wake up the judge in the middle of the night and have an officer of the court serve it.
They were obsequious about it because they didn't have a leg to stand on. 50 50 they weren't even the NSA but rather a sailor trying to spy on a mates computer.
Seeing as all you did was call a naval base and get transferred several times how do we know he wasn't talking to a random individual at the base.
Logically the fact that you called into the navy base indicates you are talking to them but by the time you get transferred how do you know who you are ultimately talking to?
Couldn't you be talking to anyone who works at the navy or works with someone who works at the navy? One great thing about court orders is that its trivial to authenticate them and they get the exciting task of making sure the person asking for them is a legitimate actor on legitimate business.
If a random private wanted to fool you couldn't they have had you call in in such a way as you would trivially be talking to a known party who will ultimately transfer you said party? Hey this joker is going to be transferred to your extension asking to speak to john doe at the NSA send him to my extension please.
Considering that we now know that intelligence apparatus was used to spy on love interests how do you know you were collaborating with a legitimate legal operation as opposed to illegal spying on citizens?
Likely you aren't in a position to judge right which is why we have you know judges and court orders and such ceremony.
I respond to random calls that seem strange by hanging up and telling them to send me something official in the mail.
Neither the people who claim they would like me to give me a fortune I inherited overseas, the guy who claimed I won the lottery, or the guy that claimed to be the IRS demanding immediate payment have followed up yet.
At best your judgement is questionable.
But in response to the people here who think I was tricked. That's not the case. What I didn't put in the post was that a team from the NSA visited me in California a few months later. But again, had I been tricked, it wouldn't have mattered.
I'm sorry this is utterly beyond belief.
If I understand correctly such a request could be made by anyone running your software.
"But there’s still one thing that continues to nag me after all these years -
how the hell did Dave track me down 3,000 miles away from home after midnight
on that hot summer’s eve in Bristol, Connecticut?"
Assuming the author flew cross-country from California and his brother had a phone number in the family name, it doesn't seem too hard to piece together with good old fasioned detective work - on top of good old fashioned databases open to the NSA. I wonder if Dave got it right on the first call?Boy, you sure seem confident in your assessment of the severity of the situation. It's not like the NSA would have any idea how to get information out of people by convincing them the situation was something other than what it actually was.
Granted 18 years ago was a much different time than today. It's a shame that these agencies have proven their motives so untrustworthy.
Though, kudos to "Dave" if this was just a ruse to avoid paying for the $39.99 version.
A funny thing about people who live in Maryland: the NSA has a big sign that says "NSA" on the highway. We all know where it exists, and there are funny local stories about ignorant criminals taking the wrong road and ending up in the NSA checkpoint. Its a famous local landmark.
http://www.capitalgazette.com/news/ph-ac-cn-carjacking-suspe...
People tell me that you can even drive up and go to a public gift-shop they have out front, by the National Cryptologic Museum (which is run by the NSA). Its literally a public place and they let anyone in to see some cool stuff. https://www.nsa.gov/about/cryptologic-heritage/museum/
----------
The thing is: the guy seems to have been called by Naval Support Activity, Bethesda.
https://www.cnic.navy.mil/regions/ndw/installations/nsa_beth...
This is a "different" NSA, and not "THE NSA" that people talk about.
Whether or not its actually part of protocol: I dunno. But maybe "Naval Support Activity" dudes like to pretend they are "the NSA" as a prank. Or maybe they really are part of national security (I mean, the US Navy is still... technically national security, right?)
---------
In short: my expectation.
1. Naval Support Activity called this guy up to ask for a favor. They misrepresent themselves (but without lying: they are the "NSA" after all) to kinda encourage this guy to do something for them.
2. They feel bad about pranking the dude. So they drive to the Cryptographic Museum and buy him the first "real NSA"-branded gear that they find. Then they ship it to him.
If these pranksters were really in Bethesda, it wouldn't take much longer than 40 minutes or so to drive over to "real NSA", buy the mug, and then come back to their office.
The NSA exists beyond Ft Meade
> Dave told me he was with the NSA in Bethesda — the National Security Agency.
So did DAVE say he was with "National Security Agency", or did Dave only say "I'm with the NSA in Bethesda", and then the author misinterpreted the claim?
I 100% believe the mysterious man said "I'm Dave from the NSA in Bethesda". But what I DON'T believe, is that Dave is with the National Security Agency.
I believe "Dave" is from the Naval Support Activity in Bethesda. EDIT: Although the article seems to say that they were really interested in breaking his encryption. Which seems like a "real NSA" thing to do.
EDIT2: Regardless, it was an entertaining read.
It is odd that the writer refers to them specifically, they have no connection with the actual NSA of which I'm aware.
This wouldn't be the first time I heard of a US Military dude prank-call someone.
Well, now I'm neutral on the subject. There's details that make me disbelieve the story. But tracking down the author and finding the right phone number to call him seems like a feat that would require decent resources.
Basically: that's a level of effort that goes well above and beyond a typical prank call.
Yes. In 2015, two drugged-out tranny hookers in a stolen SUV went down the employee entrance road. They tried to crash through the gate. They didn't get very far.[1][2]
[1] https://www.nbcnews.com/nightly-news/video/feds-say-nsa-gate... [2] https://abcnews.go.com/US/injured-nsa-headquarters-fort-mead...
Unless the pranker had complete control of his phone and could route dialed numbers to anywhere.
The coffee cup is from the NSA gift shop at the National Cryptologic Museum.
[1] https://www.businessinsider.com/nsa-gift-shop-2016-5#right-a... [2] https://www.nsa.gov/about/contact-us/
In case you need to ever thank anyone for helping you.
Deleted comment
Plus the complete lack of understanding of the encryption standards that were legally exportable (which is also mentioned in the story) and seen as good enough is kind of stunning. 40 bit encryption in 2000 was decent. It wasn't great, but it would deter almost anyone.
> You attempted to reach www.safehousesoftware.com, but the server presented a certificate signed using a weak signature algorithm (such as SHA-1). This means that the security credentials that the server presented could have been forged, and the server may not be the server that you expected (you may be communicating with an attacker).
In any case, they didn't need the source if their goal was as some say, not to decrypt files a bit faster but to produce a backdoored version.
For backdooring, getting it to compile might take longer than putting the right jumps in and linking the desired dll, depending on how standard the compilation toolchain is and how experienced you are in backdooring.
This is all assuming that they have the program in the first place and not only the encrypted file, though it sounds like they did.
I'd really love to see any of these people in such situation. Or maybe even further, in a situation in which they actually have a tangible proof that "something bad is going to happen".
So all in all, I could see it coming that he would be offering the source code on the silver platter to the NSA after reading the first couple of paragraphs from the post.
I also like how he calls that guy a "dumb criminal" for not buying his military-grade encrypted software, as if he hadn't already admitted that he was giving the source code for the full version to the NSA anyway. In other words, he didn't just break the trust of the free users, but also of those paying him to keep their conversations private. This is why I said he had dubious ethics.
As for sharing the source code with the NSA, I think you have a better argument there. That said, it's kind of like helping someone install a secure lock on their door to keep out criminals, yet being willing to share a master key with police if it's a matter of life and death.
He also didn't bother to verify whether it was a matter of life or death, he just immediately assumed he was helping break into a file containing the deactivation code for a bomb or something, who knows what the NSA was actually doing.
As long as that wasn't a hidden fact from the users, I don't see the issue.
But otherwise, super useful analogy.
This really depends on the business you're in.
30 minutes later after he has left and you have closed the door to go back to your chores, you're wondering why you ordered 2 magic-mix blenders...