How the NSA Got So Smart So Fast
on.wsj.com
on.wsj.com
1. Do they already have a functional quantum computer, capable of rendering most modern encryption useless?
2. Do they have a mathematical breakthrough that allows them to factor products of large prime numbers multiplied together, far faster than anyone suspects - which would render most / all modern encryption useless?
3. Have they planted backdoors and vulnerabilities in popular, widely distributed hardware / software platforms?
etc.
There are highly skilled and better financed tech companies with huge R&D teams. Why would the NSA be able to outperform them?
It's more likely their power is their access to the latest zero-day exploits via sourcing information - something they are extremely good at.
More to the point, they don't (presumably) have some secret pipeline of highly talented people. I mean, the pool of graduates in mathematics, statistics, computer science, etc., year in and year out, is available to everyone, NSA, other public sector, other private sector, etc. And while the NSA probably prioritizes hiring brilliant math wonks and what-not, so do wall street hedge fund companies, tech companies, etc. And given that at least some small percentage of "really smart people" would probably refuse to work for the NSA just on ideological grounds, I don't see any reason to believe that they have a monopoly on smart people who can do crypto research and what-not.
As for their financing, however... I don't know. I'm not real big on conspiracy theories, but I don't doubt the existence of secret budgets and "off the books" stuff to fund certain government programs. I mean, just go back to the Iran/Contra affair[1] and you can see that some sneaky stuff does go on, at least on occasion.
[1]: http://en.wikipedia.org/wiki/Iran%E2%80%93Contra_affair
[1]Projected US Gov't R&D spending - 2012: http://www.battelle.org/media/press-releases/battelle-r-d-ma...)
Unlikely. And given the secrecy surrounding their budgets, how could you know for sure? Even if you did, the dollars themselves are only part of the picture. The dynamic surrounding the money also has a big influence on how it can be used. A private company needing to post a profit operates under a set of constraints that are dramatically different from those that govern R&D in the military.
Also, unlike private R&D teams, the military can unilaterally classify and restrict entirely categories of hardware (e.g. GPS units that function over specific altitudes or above certain velocities). And they can seize (in secret) any instances that threaten national security.
That's a set of competitive advantages that the private sector, almost by definition, can never hope to match. Or at least not independently.
And you forgot a point: can they get an SSL root certificate signed for them, in order to perform MitM attacks on seemingly secured connections? Here again it's a foregone conclusion, several less technically-savvy countries have been caught doing that.
Yes, that is a good point that I forgot. I tend to assume the answer is "yes".
Can they take control of an MS-Windows PC without the cooperation of my router maker and my firewall maker? And what does it cost them to do so for the different makers?
You know? I'm fairly sure they can, after all if some kiddy off the internet can what are the chances they can't. But what's the cost to cover the different profiles? Is there a single point of failure?
For 2. I think it's safe to assume that they know a few tricks that we don't. Probably enough to hasten breaking encryption, but probably not enough to make encryption useless.
For 3. Yes, isn't that obvious?
Here's a recent discovery regarding FPGA's, maybe not the NSA, but it didn't get there by accident. http://www.cl.cam.ac.uk/~sps32/sec_news.html
I suspect that some bugs like this one in Intel networking chips may not be bugs http://blog.krisk.org/2013/02/packets-of-death.html
If it is technically feasible, then it is almost certainly being done.
D'oh... yes, of course, that's what I meant to say. Sorry, too much on my mind right now!
I think the chance of it containing a backdoor is low, though. It's been reviewed by any number of top kernel developers since it was published.
Here is a complete (I assume) version. http://finance.yahoo.com/news/nsa-could-smart-fast-235100722...
[1]: http://en.wikipedia.org/wiki/Security-Enhanced_Linux#Overvie...
SELinux, however, prevented the TFTP transfer from happening. We saw this in the audit logs, investigated, and discovered what had happened (and, of course, updated the PHP application).
If the attack had succeeded, I'm convinced that it eventually would have ended up as a full ("root-level") compromise.
How can anyone find them credible in such a role with such huge glaring conflicts of interests, and their demonstrated lack of trustworthiness?
Just because the DOD bombs civilians with drones in far off doesn't mean we should hold the National Park Service in the same light.
My orignal response was to someone wondering why the NSA can violate constitutional rights while at the same time open sourcing technologies for enhanced securities. My example of the DOD vs the NPS was to show that entities within the same organizational structure can have opposed goals.
And you can just look at the NSA's guide to securing Red Hat Linux.
http://www.nsa.gov/ia/_files/os/redhat/rhel5-guide-i731.pdf
It's not substantially different than the information you'd find in any other book about security. Anyone is free to review or comment on it. I don't find it plausible that the NSA would hide any tricks in that document so they could track you. At best, they might omit information, such as knowledge of a 0-day exploit.
As far as the NSA's published guide you linked, of course it is in the national interest for them to do things like that, and given the nature of a public document it would be foolish for them to put false or misleading information in it. That would be both bad, and comically obvious. I was thinking more along the lines of them promoting or mandating the use of encryption/technology that has weaknesses known only to them.
For instance, NSA fixed a problem in what became IBM's DES crypto standard before the cryptanalytic community even knew what the attack was. So there's at least evidence that NSA takes that part of their mission goals seriously, and that NSA required the knowledge/skills/abilities of their "other half" in order to properly carry out those duties.
Their trustworthiness on technical matters is a matter of public record--for example, as far as I know, Linux experts independently agree that SELinux is a very secure Linux configuration.