Crypto breakthrough shows Flame was designed by world-class scientists
arstechnica.com
arstechnica.com
What's more interesting to me, though, isn't that they had this technique, it's that they let it out for ... what? It seems like this is a garden variety public worm. One would think that if the NSA had the ability to forge windows code signatures like this, they would have used it more selectively. Some spook is in deep trouble about this.
After all, it's been in the wild since at least 2010. The entire Arab Spring has happened since then.
Attribution is a bitch. It's not a slam dunk to suggest that a particular agency is at fault without supporting evidence.
It's easy to pin it on a nation state or intelligence agency, but it's worth considering the possibility that it was rogue elements in one (or both worlds) that exploited this (and various people) for purely financial gain.
Correct. But they kept the fact that they did secret for decades. That's what I meant, apologies if it was ambiguous (I can't actually edit the comment now to fix it).
Now, would the NSA have shared this particular attack? I'm guessing no, since they probably wrote it to begin with.
Source: http://www.nsa.gov/research/tech_transfer/advanced_math/inde...
Even worse -- and this is off-topic so I'll keep it brief -- I don't know if the intelligence gleaned from this operation would produce any benefit at all. Theoretically, if we discovered that Iran's nuclear program wasn't a threat, we could save ourselves a lot of worry. It might save a lot of time and money, and possibly even save lives if it prevented military action. But after Iraq who can be confident that an accurate assessment of the threat from Iran would have any effect on policy? We might be disseminating dangerous knowledge for nothing.
Edit: The breakthrough that Flame introduced can be read here[8, 9]
SHA-1 is not yet broken, as MD5 is, but fortunately we are having the SHA-3[6] competition (like we had for AES[7]).
[1] http://www.springerlink.com/content/d7pm142n58853467/?MUD=MP
[2] http://www.computer.org/portal/web/csdl/doi/10.1109/CIS.2009...
[3] http://eprint.iacr.org/2010/643
[4] http://stackoverflow.com/questions/1999824/whats-the-shortes...
[5] http://code.google.com/p/hashclash/
[6] http://en.wikipedia.org/wiki/Sha3
[7] http://en.wikipedia.org/wiki/Advanced_Encryption_Standard
[8] http://www.cwi.nl/news/2012/cwi-cryptanalist-discovers-new-c...
More interestingly, the results have shown that not our published chosen-prefix collision attack was used, but an entirely new and unknown variant. Therefore it is not unreasonable to assume that the particular chosen-prefix collision attack variant underlying Flame had already been in development before June 2009. This has led to our conclusion that the design of Flame is partly based on world-class cryptanalysis.
[1] http://www.cwi.nl/news/2012/cwi-cryptanalist-discovers-new-c...
To respond to your hellfire missile analogy, if I am in Canada or the US, I'm not worrying about it but if I'm in the middle east, it's a different story.
But if it's something that can evade detection for years, you have no idea you're being spied on. That's slightly unsettling, no?
[1] http://en.wikipedia.org/wiki/Export_of_cryptography_in_the_U...
While I do agree that it was indeed developed by one, I'm not sure how it could only have been developed by one. Would it truly take massive levels of money to do or simply some smart, determined people?
At least, you would _hope_ criminal enterprises don't actually have the means to fund and recruit their own secret, cutting-edge math research labs/networks :)
It's not like drug cartels are Dr. No like enterprises...
But what about, well, drugs? Don't drug cartels employ chemists to refine old drugs and develop "better" ones?
No, of course not :). The point was about crime organizations hiring elite specialists to do high-tech research for them.
They mostly iterate on known drugs to make their making cheaper / more addictive. And they can easily test on junkies (I presume).
Of course, sometimes they get it wrong, and you end up with face flesh eating humans in Florida.
Citation?
Also, I don't own a TV, don't watch TV, and get my news from friends and NPR. So I don't generally see much of this news-of-the-wierd. Thankfully, it appears.
During years EPO wasn't detectable by anti-doping testing. Correct me if I'm wrong but I think it requires cutting edge pharmaceutical drug research to avoid detection.
Its non-trivial building these submarines and most competent engineers would balk at being asked to, explaining they were not competent enough.
Don't mistake a lack of polish, fanfare and machined parts for primitive as in easy to make work.
Value is a subjective thing. Some people want money and fame, and for them it would be better to publish. But if you want to get rid of Iran's nuclear program because, well, you don't like nukes, or you don't like Iran, or you Just Want To Watch The World Burn, then well...
> At least, you would _hope_ criminal enterprises don't actually have the means to fund and recruit their own secret, cutting-edge math research labs/networks :)
Why not? Big business is big business.
What these people are saying, essentially is that very few countries have lots of smart people in different industry's, which is wrong.
The zero days can come from all over, the PLC and SCADA system knowledge is all over the world.
meh, I'm rambling now, I agree with you kposehn. Its more obvious that this is the work of USA/Israel simply because they are the ones desperate enough to try anything. I might be wrong but who else is threatening war with Iran?
http://www.wisegeek.com/what-is-a-nation-state.htm
You people are fucking ignorant.
EDIT: Or compare the US and the EU. The typical New Yorker regards people in Florida as the same sort of person as them, so the permanent fiscal transfers from New York to Florida don't spark the sort of outrage in the US that permanent transfers from Germany to Greece do.
From what I've read, SCADA leaves an aspect of its system wide open and insecure, to make development easier.
Plus, we can all guess what wealthy nation-state developed the software and similar things in the past, let's not be hypocritical here...
There are a lot of organizations in the world, corporate, criminal, and otherwise, that can muster say $25 million (which, I admit is a number I just pulled out of my ass) to accomplish a monumental task. I'm just not sure that I'm ready to believe that the money amounts we're talking here are restricted only to the wealthiest of nation states. Is the claim that you would need literally billions of dollars to get the smart people and equipment?
Plausible deniability is useful after all.
I realize something like that is totally conjecture; but, I don't see it as any further conjecture than, "it must be the US and / or Israel"
[Edit] Since somehow this didn't come across in my post; throwing up conjecture at another possible source of Flame outside of US / Israel doesn't mean I believe any of these explanations--my point was merely that both ideas are pure conjecture with little (at least that I'm aware of) evidence to support the claim.
I mean, if I had the capability to screw up Iran's nuclear program in my spare time I probably would, because, y'know, fuck Iran.
Several smart, determined people capable of it together would be easier to find, and well within the reach of many nations and large organizations.
Fuck Iran why exactly? Because toppling their democratically elected government and establishing a puppet in the fifties wasn't enough? Or arming Saddam's Iraq to fight them in the eighties?
Or maybe because, say, TX can execute 15 year old "criminals" and ban abortion and/or gay marriage, but Iranians don't get to decide how they want to live? Or maybe because what's OK for Saudi Arabia is not OK for everybody?
Or is it because they haven't harmed anyone in the region, where other nations have already invaded 2 nearby countries?
Or just because, you know, muslims are bad in general? (I don't like the religion myself, but they have the right to do as they damn please in their OWN country).
Sure, but those are "refugees/dissidents", of course they would think that. It's not like the great Iranian masses are held there by force or hate their culture.
In general, dissidents are also overplayed for political gain by other countries. I mean, even the USSR played upon US political dissidents, the McCarthy era etc. If you are going to judge a whole country better ask the locals, not the dissidents.
You are arguing a very weak position.
Now, put this to perspective. The Kent students were shot doing a mostly harmless protesting, in a country that had sent troops to a third country (Cambodia), and that was in no danger itself. The tension in Iran, on the other hand, is in a country that feels threatened by the US, that has seen 2 other countries invaded in the region, and that foreign powers are known to support vocal dissidents and minorities against the state. In the name of "democracy" of course, and not crude oil. Same foreign powers do nothing for countries having even more extreme muslims, and far less democracy, like, say, Saudi Arabia.
What would the US police do if the US was feeling directly threatened, say like in the WWII? Well, we know what they did at the time: concentration camps for Japanese, for example.
Ok, look man, I'm down with anyone who wants to say the US could do better. I could do better. You could do better. But a fact, always beats a strawman, which is what you presented previously. Because the reality is that the Iranian government killed a bunch of its own people and did their level best to suppress that information. Now you've switched from defending Iran to reaching back a generation to find something you can cite to prosecute the United States.
Just to add another fact, Here's a more comprehensive discussion of casualties in the protests where that Iranian lady died
http://en.wikipedia.org/wiki/2009_Iranian_election_protests#...
My point stands: you are arguing from a very weak position. Further weakened by the fact that your thesis keeps moving around. If you're going take on the martyr's quest of defending an outrageous position, you can expect you're going to be expected to present an outragously good argument: all your shit in one bag, sewn up tight. If you're frustrated that people can come along and shoot holes in your argument with a sentence or two, maybe you could consider that as evidence that your argument may not ever hold water.
There's a great passage, I think it's TH White's Once and Future King, where Lancelot has a dream where he sees two armies of knights, white and black fighting. The white side is loosing, so he takes their side. And gets slaughtered. On waking, he is told: know what you're fighting for. Don't fight for the losing side just because they're losing.
Western media just overplays dissidents and people that talk to our "sentiments". Insignificant opposition parties and small protests are elevated to the level of mass popular protest.
If the situation was reversed, imagine what other countries would say of the 2000 US Bush-Gore elections, what with the electoral fraud et al, or things like the Vietnam protests, etc.
And it amuses me, because, you have an example right in your backyard: the "middle america" has tens of millions of people that want to live in a Christian state, with no evolution teaching in schools, no abortions, no gay marriages, the death penalty, Bible, etc. Those people are not "forced by the state" to want to live like so. If anything, they think the state FAILS them by not being more christian.
If you consider this --that even within the US there are people who want those kinds of things--, you might understand why your San Franciscan or whatever ideas are not directly applicable to muslim countries, with a much different history and culture than what the US has.
Just saying.
No, because of polluting what is generally a rational place of discussion with ludicrous extremist propaganda and general idiocy.
In World War II, you had such in Poland: http://en.wikipedia.org/wiki/Marian_Rejewski (Who deserves some of the credit for cracking Enigma and thus for the outcome of World War II.)
What you can get for lots of money, you can also get for patriotism and somewhat less money. There are over 30 countries with populations over 40 million. Most of these are industrialized. The odds are that they've produced the requisite mathematical talent. The only question is if they've been able to retain and apply it.
Plus, the rest of the context is the target of the attack and precedence. Given those constraints, one can only thing of 2 such states. And it's not like those "30 countries with populations over 40 million" are not spied to death already, or that they had foreign policy autonomy on the level of making such attacks without asking consent from a certain power.
Industrial espionage would be similar: hard to keep secret, fairly high risk and in most cases it'd be easier and more reliable just to take your megabucks and pay someone for whatever data you want. Why spend millions funding a big R&D team when you could just pay one of your target's sysadmins a million or two to get the data for sure?
Are there any details on what's new with this particular attack, compared to the known previously published ones? Why wouldn't earlier public research (such as that ps3 fake SSL CA stunt) suffice?
We don't yet have details on the differences. I've looked at the evil colliding cert and, AFAICT, the "MD5 Considered Harmful" technique would probably have been sufficient to pull this off.
The rogue-ca thing is awesome indeed! :)
Further to other people's comments here; Has anyone seen an estimated cost to produce something like Flame or Stuxnet?
Now this news comes out that they used a pretty powerful crypto attack to essentially create their own trusted root to be able to sign their code to make it look like it came from Microsoft.
Why would you need both vectors? It seemed (yesterday) that the Microsoft bug alone was enough to trick Windows Update into installing your code.
But the problem with later is that the more people know about it and the longer it takes to make such malware, the higher are the chances of a pre release leak, or some double agent doing his work. So one or two very intelligent people doing it in very small time make more practical sense for a covert mission.
Oh, this and that. Let's see what's in the news, shall we?
"There were mathematicians doing new science to make Flame work."
the government thinks that this is just like normal weapons research.
what they don't realize is that "secure-enough" crypto is far more important to the world economy than their small use in breaking it.
if a government could spend $800B and prove/create a machine that makes asymmetric cryptography impossible - and will be reverse-engineered and known to the world within 3 years of when they start using it, they probably would.
meanwhile, the world loses a lot more than $800B if you can't do anything secure over the public Internet anymore, or have to have previously exchanged a one-time pad to anyone you want a secure connection with.
this isn't just another weapon. mathematics is a public good. Of course, if you can spend $800B on new math and then break it, then in some sense it was "always broken." In another sense, however, that's not true at all. Quit messing it up for everyone.
It seems as though the governments of western democracies are spending a lot more effort on digital swords to stab at our enemies than on digital shields to protect their citizens.
The alternative is waiting 10 years for academia to discover the vulnerability, the whole time risking that an even worse organization will discover and exploit it.
Ideally they would spend the $800B breaking it, along with another $200B developing something to replace it before it goes public. Even if they don't do the second part, it's still no worse than what would happen eventually anyway.
This will only become an arms race, or skipping that entirely; the web will just be a destructive place. Another battlefield. Where in the history of civilization can we pull similarities and find a solution?
As the facts appear today; someone (or group, or government) attacked someone else (or group, or government) abusing a mechanism millions upon millions rely upon. Now the instructions to mimic that abuse is in the hands of another malignant.
How have we avoided this in the past?
This is unprecedened. I chose $800B as an absurdly large sum that I believe is more than Academia would spend on this question in a few years. (I could be wrong though.)
Downvoter: I know you think it's not secure if a trillion dollars of research can break it - but guess what: there is a nonzero chance that between here and 800 billion dollars from here there is a quantum device. that doesn't mean it actually exists. it means it could exist if one of the world's biggest economies throws that much military R&D at it. I'm saying they shouldn't. at least, not with that goal (breakig crypto for everyone; quantum computing itself is a welcome advance). Please be more practical.