The following papers are a good starting point:
[1] Guessing the URLs being browsed by users over an encrypted TLS session: https://research.microsoft.com/en-us/um/people/gdane/papers/...
[2] Guessing the co-ordinates of where a user is scrolling around on Google Maps over an encrypted TLS session: http://www.ioactive.com/pdfs/SSLTrafficAnalysisOnGoogleMaps....
[3] Guessing the content of encrypted VoIP conversations: http://www.cs.unc.edu/~amw/resources/hooktonfoniks.pdf
[4] Guessing communication paths on the Tor network with only a partial view of the network (not strictly related to encryption but the principles of traffic analysis are relevant): http://www.cl.cam.ac.uk/users/sjm217/papers/oakland05torta.p...
[5] Guessing passwords sent over the SSH protocol using keystroke timing analysis: http://users.ece.cmu.edu/~dawnsong/papers/ssh-timing.pdf
(a) narrow down or uniquely identify each party
(b) provide information on the mood of each party (are they interrupting other speakers more often than usual?)
(c) guess the nature of the call (information dump from one person to another, one person quizzing another person, ...)
(d) determine the languages used in the conversation
(e) guess demographic information from the conversation including approximate level of education/intellect, age, male/female, ...
(f) narrow down the physical location of speakers who are attempting to mask their identity through intermediate nodes
VoIP is covered by CALEA, but it isn't yet clear if Video is covered. There's a bit of a raging debate about this in Telco circles. There are basically two arguments:
1) Companies that do not operate exchanges are not liable for CALEA compliance
2) CALEA compliance is not clear.
For the first argument, many folks interpret the law as only covering companies that have equipment inside of phone exchanges (CLECs and ILECs). There is a 3rd class of operator that is only IP with no equipment in the exchange. It is not yet clear if this 3rd class has CALEA as a requirement (Goolge is all IP).
On the second point, there's no clear documentation about acceptable formats for release. Can I send raw log files? Does it have to be a csv? None of this is clearly defined anywhere.
In short, it's a lot more tangled when it comes to video. I'm not certain the Feds could've gotten access to Skype monitoring without $MSFT buying Skype.
How strong is your 'locked' box? It's only a bunch of 1s and 0s.
I wouldn't be surprised. Basically 9/10 people that study cryptography in the US end up working for the NSA. Look at the NSA's budget, and then look at how many cryptography professors there are.
However, that said, IF they managed to decrypt AES somehow, they are severely limited in what they can do with that information. Basically anything they do with the decrypted data has to in no way alert anyone that they have that capability.
So that data DEFINITELY can't be used in court, nor for a whole array of other more covert operations.
It seems unlikely in the extreme that the NSA is both so far ahead of the rest of the world, and so sure that their discoveries will not be replicated for decades.
Sources: http://arxiv.org/ftp/arxiv/papers/1003/1003.4085.pdf http://delivery.acm.org/10.1145/360000/358718/p465-merkle.pd...