The NSA called me after midnight and requested my source code (2018)
medium.com
medium.com
A few weeks into this, I get a summons to get down to the local police station ASAP. The commissioner then gives me a good verbal beating for being such a stupid kid; apparently someone had dialled into the uVAX by mistake or wardialling, figured it was a real DoD machine, had reported the security breach and had gotten all sorts of gears moving.
He wound up the sermon by telling me whoever had called him from the relevant department at military intelligence had chuckled and told him they kind of found it funny - but could he please get hold of me and tell me to stop doing it immediately, or else have my landline terminated?
What instantly came to my mind was the Kevin Mitnick trial, where "law enforcement officials convinced a judge that he had the ability to 'start a nuclear war by whistling into a pay phone'"[0].
0.https://en.wikipedia.org/wiki/Kevin_Mitnick#Arrest,_convicti...
Raymond Chen could scream the 300 baud carrier tone: https://devblogs.microsoft.com/oldnewthing/20111111-00/?p=91...
I do not think there is any legal way they could have severed my (well, my parents') phone service over such an issue - but then again, I had no desire to have to explain to my parents why the phone was dead, and promptly replaced the welcome with something along the lines of "This computer is so secret the DoD told the op not to ID it!" (Which, while rather flippant, was definitely true... Ah, the joys of being fifteen!)
If somebody calls me, I can say whatever I want. If I want to answer the phone by saying "Department of Defense, how can I help you?" the First Amendment guarantees me the right to do that.
Now, I certainly could not call other people and claim to be the Department of Defense. That's fraud. The same applies if I had done something like put up flyers claiming my phone number was related to the DoD or something like that.
I'm not a lawyer, but that's how I see it.
(This is hardly relevant; I just grasped the opportunity to stress that the HN crowd resides in the most peculiar places...)
Although, in fairness, even more common are EU people noting the consequences of EU rules that attempt to govern non-EU websites.
> Article 100
> There shall be liberty of the Press. No person may be punished for any writing, whatever its contents, which he has caused to be printed or published, unless he wilfully and manifestly has either himself shown or incited others to disobedience to the laws, contempt of religion, morality or the constitutional powers, or resistance to their orders, or has made false and defamatory accusations against anyone. Everyone shall be free to speak his mind frankly on the administration of the State and on any other subject whatsoever.
I always get interested in how other free speech laws are worded because I enjoy the way Madison worded the First Amendment so damn much. When somebody points to an Article # or something like that, it makes my pursuit of this hobby a bit easier.
> Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.
Compare and contrast. One is a grant, essentially a permission, to the people of Norway, and the other is basically telling the US Congress to fuck off because it has no right nor permission and not even a wink and a nod to make any law on the matters which follow. The liberty is inherent, Congress’ powers are not.
Mind this is a translation, I unfortunately do not know any Norwegian to verify the original Article 100.
https://leginfo.legislature.ca.gov/faces/codes_displayText.x...
Now compare and contrast with the California State Constitution. I’m providing a link because it is much wordier, and starts at Sec 2 and runs for a few more sections. While California is under the same structures of as the First Amendment in modern times, that wasn’t always the case. If you read the wording here, it is downright inferior to both the US First Amendment and the Norwegians Article 100, spares too many words, and phrases it’s equivalents mostly in a manner of a permission under the CA Constitution rather than telling the State legislature to fuck off. An unfortunate choice, but most of the State’s Constitution is a long tragedy of errors and poor choices, one of the most unfortunate being the choice to grant voters the right to amend the bloody rag by referendum.
To amend our Constitution, two sessions of Parliament -with an election inbetween- must ratify the change proposed at two thirds majority.
That being said, long-standing consensus on Article 100 is that any power-that-be attempts to mess with §100 at their own peril.
During the ratification process for the Constitution, there was some debate about whether a Bill of Rights was even necessary, but there were many States that didn’t want to ratify without one. The reason for the debate is that the liberties in the Bill of Rights were taken to already be natural rights and so spelling them out was unnecessary, but the Anti-Federalist faction wasn’t convinced.
Madison eventually won his seat in the election of the First Congress against Monroe (fun fact, they traveled together while campaigning!) by campaigning on the promise to draft and propose a Bill of Rights, but he didn’t see the lack of one as a reason to hold up the ratification conventions.
So repealing the First Amendment wouldn’t have the effect of repealing Free speech per se. Congress would still have to justify regulating speech under its enumerated powers (and could still lose elections over the issue) and many State constitutions already have their own takes on it. Some more like Norway’s Article 100, and some more like the First Amendment.
I'd be more concerned with making false statements to federal agents, which is a crime, when answering the phone using those words. At that point in the call, you are announcing yourself and making verifiable statements, although in jest. But if you're talking to someone who wants to ruin your weekend, they will find a way to do so.
In that video it says "User Access Verification", he probably changed his to "Dept. of Defense"...
Telnet requires a functioning network stack.
Before we had that, we had modems, which I assume was the case since wardialing is mentioned. They could run ANY protocol - or indeed none at all. You could tie it directly to the text I/O of any program(easy on unix systems, not as easy on MSDOS or early Windows versions). Many "BBS" systems worked this way.
EDIT: also early "multiplayer" games, which would talk to the modem directly. I've spend hours playing Descent over a 9600bps modem connection. That was only running... whatever protocol Descent used. You kids and your fancy packets.
If a file was being transferred you could do nothing else. If you were specially high-tech, you would use ZModem for the transfer. If not, you would be using something like XModem, or even Kermit or something proprietary.
The fact that the NSA has to call him in the middle of the night to learn that the free version didn’t use strong encryption (a fact that seems to have been a selling point for the non-free version) just sounds a bit dubious, but that’s just my sense. Nice mug regardless.
Basically fabricating this story and risking exposure just wasn’t necessary.
But also, if they did want to do that, they could probably backdoor it pretty easily just by patching the binary a bit. Reverse engineering and changing binaries is way easier than cracking encryption, and they probably have some of the world's top reverse engineers.
The fact that they asked for an existing algorithm backdoor, among other things, makes me think they really were trying to crack at least one thing encrypted with it. As for whether it was to deal with a time-critical situation or whether that was just a confidence trick to make him more likely to give up the code, who knows.
Man in the Middle attacks work even if one goes to the official site. It could have looked something like this.
1) User attempts to go to the official site https://...
2) NSA intercepts the message, downgrades to http and sends back a dummy site with the malicious binary [1].
3) The user doesn't notice the change and uses the malicious binary.
Today, a series of steps have been taken to make such an attack more difficult. Now browsers tend to try to warn the user and sites can take advantage of HSTS preload lists[2]. However, this article was written about an event in early 2000 when many of these safeguards didn't exist.
[1] https://en.wikipedia.org/wiki/Downgrade_attack
[2] https://blog.mozilla.org/security/2012/11/01/preloading-hsts...
Finally, it wouldn't do them any good for trying to crack things that are already encrypted with it, which from the conversation does seem like was at least one of their goals. (Could be deception, but that's the most likely reading, to me.)
I'm just saying that that doesn't seem to be a likely reason for requesting the source code.
The reason is likely what they said it was: they want to look at the source code to see if there's some way to crack the encryption faster than they otherwise could - for example, some bug causing key generation to be somewhat predictable.
The original is both pay to own and not available outside of the US. So changing either of those things would work.
You have to think that intelligence agencies have people inside hacking groups, giving backdoored hacked products a sheen of legitimacy.
My favorite nugget from the comments:
"I hope you’re keeping that mug in an opaque Faraday cage, well grounded."If you find yourself receiving a questionable mug, time for a glass of warm milk.
Making things resilient against a kilowatt of non-ionizing microwave radiation seems challenging, in my experience it will burn the traces right off the PCB. A different game from the more common radiation-hardening where the concern is low power ionizing radiation.
Not realistic here but it has been done
Also, fun fact: The Liberty Bell cracked some time ago in history (between 1752 and 1846), when exactly is debated by historians, but "The last big crack happened on Washington’s Birthday. The Liberty Bell cracked up, literally, in February 1846, when it was rung on President’s Day, celebrated on Washington’s birthday, and then stopped ringing because of damage from a major crack."
https://constitutioncenter.org/blog/10-fascinating-facts-abo...
So what that means exactly, I don't claim to know...
I have bad news. That’s how it usually is.
Oh, and don't forget all the nice paper for the notes.
Your security should never depend upon security of your source code. If you're doing things correctly, then the source code doesn't change anything about the security of the data that is encrypted.
Perhaps you mean that he chose to use 40-bit keys instead of 256-bit keys in the free version? I mean, I guess. But that's just a matter of better understanding the details. It sounds like he outlined this clearly and anyone looking for more security knew to pay for the product to get the 256-bit keys.
For sure. I don't think it's about that, though.
Even if the application in question were open source, if the project lead is willing to cooperate in any way their government asks, they could probable ensure the existence of a back door. For this reason, where possible, I would prefer to use encryption software written by people who are principled to a fault (or who at least do a good job acting as if they were).
Let's imagine Linus Torvalds or Greg Kroah-Hartman in this same situation. Linux source is available, so let's say they were asked to ensure that a certain patch to a cryptographic API was not accepted before a certain window. Maybe the crypto API maintainers were on the call as well saying that they were on board with the plan (apologies to those people, I don't know you and mean no offense). I like to think that they would:
1. Turn down the NSA.
2. Attempt to get the word out about what they had been asked.
3. Find new crypto maintainers.
And yes, it's entirely possible that this is not at all how it would go down. Maybe they would be very cooperative. I don't know any of these people personally. But what I do know is that they have not, as of yet, made a blog post about that time when the NSA did ask them to betray an unspecified user and how they did everything they asked without resistance.
I don't think I'm being idealistic here. Software and encryption are global endeavors. People who blindly believe that the enemies of their state are also their enemies, or even that obedience to local laws is a moral imperative, should not write crypto software. Or at least, I hope they make their beliefs known like this guy did so that I can avoid their software.
One should have zero impact, as I said, modern crypto algorithms do not depend on keeping the algorithm secret to maintain security. Implementation can absolutely be full of bugs that are incorrectly using crypto primitives though.
The other has a direct impact on security.
I don't think one blurs the line to the other, they're fundamentally different things.
If anything, this is further proof that you need to use crypto properly because it literally means someone with code in hands won't have any advantages in attempting to break that encryption.
To me anyway, someone willing to give source code to the NSA doesn't imply they'd be willing to do nefarious things. There's nothing inherently nefarious about giving the NSA source code.
That said, I can understand being skeptical, but people love to talk about how open source is more secure because it has eyeballs on it. But now we try to pull the "it's not secure because the source was given to the NSA"
It can't be both ways.
Providing the source of a closed source project to an adversary so that they can break your software is nefarious.
If the author's justification was...
"My crypto implementation is perfect. There are no bugs in my code, so providing source code (which the user community does not have) to an adversary does not have any effect on any user's security."
...then the author is simply incompetent, not malicious. But I am not inclined to accuse the author of such incompetence.
You might be the only person around here to ever try that argument in public.
Most people who argue that open source is equally or more secure than close source software do not argue that access to source code provides zero benefit to attackers. Instead, they argue that the benefit gained by the many additional sets of eyes belonging to researchers and other "good guys" outweighs the detrimental effect of letting the "bad guys" see as well.
The question in this instance is not whether the closed-source-superior or open-source-superior security camps is correct. The only related question is: "Does access to source code provide any benefit whatsoever to an attacker?"
I don't think I'm the "only person around here" who would argue that yes, it does. And that if you're taking the closed-source route, like this project's author, you can't provide copies of your source code to one specific attacker when they ask. If you do that, you're _definitely_ worse off (from a security perspective) than the people in the open source camp. I'm sure the closed-source-superiority people would agree.
Seems like it would similarly be unethical for a local bakery to give the NSA a discount on cheesecake.
When the NSA asks you to help them do bad things, you say no. If you feel inspired to give them a cheesecake discount because of the good things they do, that is fine.
Likelihood that the authors/owners of software are willing to cooperate, and capable of cooperating, with adversaries is an important metric for comparing options. Very high profile open source maintainers are less capable, due to the oversight of the community. Anarchist- or security-absolutist type personalities are less likely. The author and his project don't fit either bill.
I'm not arguing that this is the only metric that matters when considering one's options. But it does matter.
The legacy being things like the blacklist/whitelist discussion we had the other day about case sensitivity in crypto algorithms. We still look up algorithms by string name (instead of enum or some other mechanism) decades later.
It's probably an #IFDEF or an if (registered) somewhere in the source code.
Nonetheless, I agree with you. The writer appears emotionally swayed and flattered by the request, like a protagonist in a WWII-era young-adult novel ("Your country needs you!"), and is eager to satisfy the ask immediately without the slightest bit of skepticism or diligence. That's not the kind of temperament one would want an encryption software dev to have.
I mean, if the cops turned up at your door with a search warrant, you'd let them in, right?
To me, this is a bit of a no-brainer. A government agency wants my help to do something. Do I trust them? Do I help them? Well... yes. They're the government. Incompetent sometimes, irrelevant a lot of the time, inefficient, sure. But ultimately there to provide a service for me as a citizen. If they need my help, then I should probably help them.
I understand that Americans don't trust their government like this. I'm not sure why not.
https://en.m.wikipedia.org/wiki/PRISM_(surveillance_program)
Those two spring to mind immediately, and I'm not American, I'm Australian.
Personally, I don't understand why anyone trusts their Government more than the bare minimum required to support the rule of law.
If they just wanted to search _my_ stuff, sure. But if the only reason that I'm even capable of assisting the government in spying on somebody is that they are my customer, neighbor, friend, or user then I will not offer that assistance. That would be evil. Don't be evil.
If we give up faith in those things then we will succumb to a lawless, might-makes-right society. What makes you think you know better than the duly elected and appointed representatives of the people? Ok, fine. Tell it to a judge. But if you lose, then comply.
TL;DR: I don’t like “the man” either, but in the end, the man is us. We thwart him at our peril.
No, it often is. I don't think I need to cite examples.
I'm not advocating for anarchy, and I haven't given up faith in the justice system as a whole. However, there are still many things that I will not do, despite being legally compelled. Leveraging my relationships, professional or personal, to help an agency with a dirty track record spy on people is among those things.
Statements like this...
> Tell it to a judge. But if you lose, then comply.
...are extremely problematic. You can argue that most of the time, in a social order that you believe to be a net positive, you should comply rather than rebel. But phrasing it as an absolute perpetuates any existing authority, no matter how corrupt, forever. If you are sufficiently confident that the right thing to do, taking into account all the disruption it may cause, is not to comply, then you are still morally obligated not to comply.
What is right and what is legal do not always agree. And yes, that is still true even in a society that theoretically allows for change "through the proper channels". Even in the US, many of the most important changes to the law have been made by breaking it. Again, I don't feel the need to cite examples, since we have entire days of the year to celebrate most of them.
The great thing about technology is that it doesn't have to put up with things like useless warrants. Using encryption is the equivalent to have a reinforced door protecting you from people who want to do harm to you that ignores all warrants and cannot be broken or talked down. Thank god for encryption that works, it literally saves lives from the current crops of tyrannical governments worldwide.
Of course I'll say yes, and I hope it's true. Thankfully, I probably won't ever have to find out. But if it does come to that, and I choose wrong, I know I won't write a blog post about it.
Check out what the fbi was doing to people a few years back hacking into victim's networks.
The idea that there's an intentional backdoor through security for some institution that may or may not be acting in your best interest is enough for me to not want to use it.
Just about everyone has something to hide, but what they're hiding and the reasons they're hiding it may only be used as leverage against them and have nothing that's a threat to anyone else. My encrypted data has some old tax returns and past medical records--nothing too exciting or compromising, but neither are things I want random people having access to should my copy of the data be compromised.
There are plenty of valid reasons not to want a government agency to be able to pry into every aspect of it's citizens lives. I'd say most people hiding things do it for a lot of social/cultural purposes that aren't too significant at least not in terms of national security.
Take most peoples' browser history--few people want others crawling through searches that might make them feel stupid or insecure for whatever reason. Perhaps they looked at someone's public profile they're interested in dating and don't want to be labeled a 'creep' or perhaps they've been making great use of the free PornHub Premium access lately. People have rights to secure/hide those things and they're no real threat to national security.
You seem to have answered the question, “Why is privacy good?” Your answer, at least to me, seems valid, but if you are answering other questions, I would ask, “Can you imagine situations in which individual liberties are trumped by physical safety of a large number of folks?” How have you reacted to CoVID-19 restrictions? Are those two things really so different?
ftfy
I recall that 40 bit encrypted Word documents obtained from Al-Qaeda safe houses in Afghanistan after 9/11 were successfully cracked. It was reported in the media, so it was an open secret after that.
Sounds like a fun social engineering trick though, if you can subvert the local phone switch. Probably would make more of an impression if the FBI/etc knocked on your door and handed you the phone...
[1] https://www.businessinsider.com/nsa-gift-shop-2016-5?op=1
Now the CIA has a gift shop you can't get to without being able to get into the building. ;)
Rather than fairly justified suspicion of the NSA, we might want to apply Hanlon's razor in this case.
The dot com bubble killed the competition.
He meant to call his supervisor to leave a voicemail regarding the thermal detonator prop used in Star Wars, but apparently it was left at a wrong number. And that random person called FBI because he heard thermal detonator in the voicemail.
Here's the link :) https://youtu.be/ZjpPgv9XtJA?t=1008
I had to stop reading after he wrote "I could tell something big was up and there simply wasn’t time to debate the merits of handing over my source code to the NSA", because at that point my eyes rolled so hard they fell right out the back of my head.
After I put them back in, I skipped down to the comments. I have a hard time not agreeing vehemently with the top comment on the post, which says:
"You took time off your vacation to help the shadiest government agency on the planet do God-knows-what, as well as give them your IP for free. In addition, your ignorance and glee motivated you write this propaganda post, helping their cause, all for the price of a mug with a fancy sticker on it."
"I’ve seen a lot of commentary like this. It was a different time back then. Just one year later the Towers came down. If in 2002 I got that same call, people would hate me for not cooperating. I didn’t invent the ciphers — those are public. I gave up nothing important. I’m okay with my decisions."
Do you think the NSA is shadier than the KGB? What about the Iranian Revolutionary Guard? Or even the CIA?
I know people are upset about the Snowden revelations but there are much graver sins that have been committed by other agencies.
Anyways, plenty of countries have security agencies whose main job is to violently protect the local kleptocrats these days. China might be a better example to point to for even worse behavior, with their balkanized net and mass surveillance being used to carry out the mass internment and repression of ethnic minorities in regions like Xinjiang.
it actually does [0] - at least in belarus and some of the russian-occupied pseudo-republics
[0] https://en.wikipedia.org/wiki/State_Security_Committee_of_th...
The Russians have definitely gone back to the old ways, I'm not sure the distinction between the old and new matters much any more (The GRU is the same organization, the FSB still reside in the Lubyanka - "the tallest building in Moscow")
https://theintercept.com/2017/07/20/cameroonian-troops-tortu...
EDIT: Don't forget that NSA acquires data to create actionable intelligence that can be passed onto another actor. Whatever you think about them, their work is being used in many cases ultimately by another agency or government.
You're right about the detail (probably) and also very wrong to be focusing on that particular detail instead of interpreting it as just barely mild hyperbole.
You've gone to "it's not the absolute worst, therefore I dismiss the statement" instead of "it's not the absolute worst, but it's still really fucking bad so I'm going to recognize the premise and move on".
It's not whataboutism if the claim is making a comparison against all other possibilities. "shadiest government agency on the planet" may be an objectively false statement as applied to the NSA. You can compare the NSA to other contenders for "most shady" using any number of metrics and create an ordered list. None of that is whataboutism.
If I tried to justify the NSA's behavior _because_ of what the GRU/IRA/CIA does, that is whataboutism. Hope this was a bit helpful.
They are not talking about the Office of Information and Regulatory Affairs or the Office of the Comptroller of the currency... It is a comment on the NSA. From what we know, everything they do is a bit creepy. Far from "All government is bad" ... The comment is about an agency that Snowden warned us about.
Also, historically speaking the US government (various departments) has done a lot of really shady things.
"They" are not going to let us know all of the shenanigans they are up to. The list of mischievous things we are aware of surely isn't everything. Are we aware of 70%? 60%? I'm going to bet lower.
So you have a opaque organization with a fairly long list of misdeeds and (this is just my sense of things) a growing boldness. NSA programs, patriot act, etc - those are bold programs they have in place. Those are not the "top secret" things we don't get to know about.
It does not take a lot of imagination to make that leap.
Good thing, because this would amplify radio frequencies. This trope needs to die.
I suppose thinking about it like an antenna, it would aplify. But I would think the bowl shape on my head would reflect my thoughts back into my head. Where a bowl upside-down on my head would act more like a dish to collect external waves.
Pretty sure anyone listening to my thoughts would get bored. Have the gold fishes song stuck in there since the 90's.
I love the fishes 'cause they're so delicious
Gotta go fishin'
I could eat them everyday
And my mom says that's ok
I love the fishes 'cause they're so delicious
Get Goldfishes!
This is why he was asking about their ability to break 256 or 40 bit encryption.
So there was no trust broken in sharing the source code.
That's true and yet unhelpful because all software has errors, some obvious, some not.
And now you can use proof assistants that are used to prove mathematical formulas to generate crypto code: https://github.com/mit-plv/fiat-crypto
Compare and contrast this with National Security Letters, which apparently (based on the ones that I have seen, that have been publicly posted on the Internet by other people) request or require absolute secrecy...
Perhaps all they wanted was the source code of his application to repackage (after introducing a backdoor) and distribute it on the internet or directly to targets of interest ... perhaps it was part of his training ...
†Social Engineering (https://en.wikipedia.org/wiki/Social_engineering_(security)) in the context of information security, is the psychological manipulation of people into performing actions or divulging confidential information.
A counterargument against that is A: if the goal is to produce a version with a backdoor, they don't need the source to accomplish that and B: if that was the goal, they wouldn't want to give the original author any reason to know they were asking about it, so that when the backdoor is found in the wild he can pipe up and go "Oh, yeah, that reminds me, the NSA got my source code a few months ago..."
It certainly would make their job easier (and be a lot cheaper)!
> B: if that was the goal, they wouldn't want to give the original author any reason to know they were asking about it,
That's a good point - unless they were targeting a specific target.
edit
I was confused and my reply is confusing. I was trying to say that a third party could have stolen the source code by MiTMing the 411 call.
Agreed. A couple of ideas for better authenticating the NSA boogeyman.
1. Verify the number in a phone book.
2. Call a friend and ask them to follow the 411 protocol.
3. Drive to a hotel in a different state then follow the 411 protocol.
4. Overnight a cell phone to the NSA headquarters and wait for Dave to call you from it.
5. Call the FBI and ask them for the NSA number.
He was called in a land line. The caller could just have pretended to hangout and faked tones when the author called back.
I'm not saying that is what happened, but it's way easier than a real 411 MITM.
I was thinking along the same lines though. Who were some high profile hackers that were on the FBI/NSA most wanted list?
Max Butler maybe? Aleksey Ivanov?
Without even getting into the social engineering possibility. I don't see a way this looks good for the author.
Says the developer who could have been social engineered to give away what he had done by being rushed in a way that others would perhaps call 'not smart enough'.
And where does the skill set of knowing about encryption come close to what someone needs to know in order to 'blow up a building'? Why would you expect that someone understands the difference or the risk? Or should? After all it's risky to begin with what they are doing. This is just another and different risk.
Now the question is if you were the NSA and of course I have no clue how they operate but maybe it would have made more sense to send the local police to a house to deliver the message AND the other part 'call this number' etc. And who knows how that could have been fake for that matter (it all hinged on calling 411 as being definitive and/or someone not intercepting a legit call). Sure someone could social engineer the local police to show up (I would think that would be easy for someone who knows how they operate or with whoever is on shift at that time).
Also the coffee cup is strange. Secretive agency but they send a gift as a thank you with their name so you have some kind of proof that allows you to detail how they operate and that they did this? Would make more sense that they got you to agree to not reveal they had requested the info not that they gave you some kind of bragging rights and story.