German intelligence agencies can decrypt PGP?
translate.google.com
translate.google.com
Means (answering the question if the technology can partially decrypt or analyze SSH or PGP):
"Yes, the used technology is basically (or in principle) capable of doing that, depending on the kind and quality of decryption."
This sentence is so much generalized that the writer almost certainly meant "yes, we can bruteforce a weak encryption".
Also the question includes the capability of "analyzing" SSH or PGP. That would (imo) include reading meta-data. So, in fact, if they are capable of telling the encryption scheme used in a PGP message, they would qualify to answer "yes, we can" here.
So, that's not surprising and the article is kind of link-bait.
Do they have an actual method for breaking PGP, or do they have some sort of backdoor they've planted? Or some sort of access to the keys through other means?
If they have an actual method to break PGP, does it work against all the algorithms, or just one or a few? Does it work against arbitrary key length, or is there a maximum they can break?
If it's general-purpose enough to be just "PGP" regardless of algorithm/key length, how quickly can they decrypt? Is this real time? Is it "we can decrypt in time to find out where next week's attack will be"? Is it "we can decrypt in time to present evidence at this guy's trial next year"?
Without that sort of information this reads like a scary mistranslation, and not the sort of thing a government would disclose anyway.
http://en.wikipedia.org/wiki/Triple_DES#Security - ok, that has chosen plaintext weaknesses.
I don't see much information on CAST5 aka CAST128, can someone chime in with its current status?
I suppose you could encrypt an image using ECB. Would PGP allow this kind of broken configuration? http://pthree.org/2012/02/17/ecb-vs-cbc-encryption/
For some context: The news releases from German security agencies tend to be imprecise on technical details in a way that suggests that the lack of precision is not on purpose. From all that I've heard on the German media, practically all surveillance techniques they use to get at encrypted communications consist of compromising your machine and thus getting at the unencrypted data. At least that was the real story when they claimed they wanted to "wiretap" skype.
The question is quite vague - can the government decrypt, at least partially, encrypted communications (e.g. PGP or SSH)
The answer is even vaguer, something along the lines of 'The deployed technology is, in principle, capable of that, depending on the type and quality of encryption'.
Both the question and the answer are so woolly they can mean anything from 'German intelligence can partially decrypt ROT13' to 'German intelligence can read 4096 bit PGP encrypted messages like a morning newspaper'.
One can also be reasonably sure that in the extremely unlikely event some entity somewhere were capable of breaking PGP, they'd go to great lengths not to tell anyone about it - such a (again, wildly improbable) capability becomes a lot less valuable if it was common knowledge.
"Eine starke Verschlüsselung mit PGP gilt als sicher, wenn es Angreifern nicht gelingt, den privaten geheimen Schlüssel, den nur der Empfänger besitzt, und sein Kennwort zu stehlen."
A strong encryption with PGP can be considered as secure, if attackers do not succeed in stealing the private secret key that only the recipient holds.
Basically, as long as they can't get your secret key and brute-force it because of a stupid password, you'll be fine.
Edit: fixed numerus
Es würden Anwendungen der deutschen Firmen Utimaco,
Ipoque oder Trovicor genutzt, um möglichst tief in die
private Kommunikation einzudringen.
They use applications of the German companies Utimaco
Ipoque or Trovicor to penetrate as deeply as possible
into the private communications.
The linked PDF doesn't support this claim. It contains a question about the companies involved, but all it says is that the answer is not public.If true it might be interesting that former PGP lead developer Gerhard Eschelbeck is CTO of Sophos (owner of Utimaco).
Nothing changed, technically speaking. The NSA merely broke rules. They didn't do anything technologically special.
ZKA is Zollkriminalamt (customs police) and CCC is Chaos Computer Club - quite different organisations.
But actually I did only comment to ask, if there is a way to switch from Google translate to the actual site, not the "original" button which still goes through Google servers. ( Especially since Google also renders PDF as HTML, when I click on a PDF link in the page.)
[1]http://www.andrej-hunko.de/start/download/doc_download/225-s... (pdf, German)
If the government tells you, they have a technology that can in principle be used, depending on type and quality of encryption, history shows us that this either means they can decrypt almost everything, or, most likely, not much. Both ways, they are not telling the complete truth at all.
Especially the german government likes to tell us that they have something that can in principle be used for something, like using your issued ID for online activities, a nation wide health-card system, a working toll collect system, etc., the list just goes on and on and on...
Anecdote: I remember, a couple of years ago, sitting in the audience of the yearly Chaos Communication Congress in Berlin in a talk by a pretty popular lawyer specializing in internet laws and regulation (IIRC the title was something like You have the right to stay silent; if you understand german, watch it, it's hilarious), where in the Q&A session somebody jumps up and tells the audience (paraphrased):
...the last time the police raided my home (much laughter from the audience) they took my encrypted disks with them (probably dmcrypt/luks or truecrypt) and after almost one year they still have not been able to decrypt a single bit of it...
I'm pretty sure not much has changed with ciphers becoming even stronger these days. I, at least, sleep well at night, trusting that my PGP2 encrypted mails are safe.
Note that they would also claim that they can decode SSH, ie SSL.
The question was if the technology they have is capable of decoding encrypted transmissions (e.g. SSH or PGP).
The reply was that in general yes, depending on the type and quality of the encryption.
What I would note is that neither the question nor the reply are about a particular encryption technology. I would not take it to mean that they can decrypt PGP in general.
For example, you can generate your own RSA private key (say, from the command line on a UNIX/Linux box).
You can use that key and generate an "SSL certificate" and have it signed by a certificate authority (a "public" for-profit CA or your own private internal CA).
You can use that same key with SSH for authentication.
You can use that same key with GnuPG for e-mail signing and authentication.
The average case for finding something equaly distributed in a space is half the time, or about 5 * 10^59 seconds, what is about the same thing, because with numbers that big "about" usualy means anything from *10 to /10.
Of course, RSA keys aren't equaly distributed at the key space. That gives an speedup of sume number between 1 and 2 that I can remember (still about the same thing), and there are search algorithms that reduce the number of tries by some non-trivial amount. I'm not up-to-date on them.
Reason? Physics: http://security.stackexchange.com/questions/25375/why-not-us...
edit: So this is from over a year ago. Probably safe to stop panicking.