You could more easily and credibly argue that NSA has solved the conventional discrete log problem.
I can't speak to a slide deck; We've only seen some slides for one program (PRISM). I am quite sure that NSA has several different programs variously encompassing collection and decryption. Hopefully in the next few days or weeks we'll see details about more of them.
I don't think it's beyond the realm of possibility for a nation-state adversary with a ca. $10bn annual budget (that happens to be the same country where Google lives) to get a copy of Google's key, no.
But everything that is plausible is not probable.
Do we not? The only reason to think that the situation for Google and DDG is different is that DDG may be insignificant enough to ignore.
This is how other hacked SSL certs have been caught in the wild, remember? Do you think Iran has more GMail users than the U.S.?
Even my own S/MIME private key the NSA wouldn't be able to get a hold of without actually having to take my smartcard, and I'd certainly notice that.
Either way, there's something that the NSA has actually screwed up so I'm honestly a bit surprised that people are still arguing so much about a FISA compliance API. That horse is already essentially dead and buried. So dead and buried that others are saying that tptacek is tearing down a strawman for still mentioning it...
I'm sure there are browsers out there that won't negotiate PFS DHE modes with Google (which were only enabled a year ago serverside anyway). NSA has had long-haul and undersea fibers tapped for many years.
Cert pinning won't help because it's not MITM.
How would we know otherwise?
As you note, that "would be a more outrageous and damning discovery" - so there's more incentive to keep it closely held. It would help the NSA do what it feels it must, simply by using its other network taps. And, it would help minimize the risk of discovery without involving extra employees and ongoing connections, all while retaining the ability for Page/Drummond/etc to deny involvement.
Those add up to making a key compromise more attractive for NSA and Google than the alternatives.
[1] http://security.stackexchange.com/questions/26142/do-client-...
This is why the DHE/EDH modes exist. It uses DH to agree on a session key, then uses the long term key just to ensure the DH agreement hasn't been actively mitm'd. The session key is never transmitted or permanently stored, so once the connection cache expires, nobody can decrypt retroactively, not even the parties to the conversation.
Second, it's unfathomable to me to imagine the NSA isn't doing their damnedest to obtain all private keys. I have no idea how many they do have, but it seems foolish to assume they don't have a specific private key.
Why do you think the NSA would regard private keys as some kind of sacred ground? For example, they could go after it the same way the Chinese do - phishing attacks against employees. They most certainly use those techniques outside the US, how can you be sure they don't within the US?
I could never pretend to be sure they -are- doing it, but it seems a lot more difficult to be sure they -are not-.
(Here it's worth noting that mail between Google Mail users doesn't ever hit the public Internet in plaintext SMTP).
I do not think it's unfathomable that NSA has Google Mail's public key. I do think it's unfathomable that, having illicitly obtained that key, their possession of it wouldn't be one of the most closely guarded secrets in the agency.
Main point - I'd be willing to bet that the NSA collects as many private keys as it can. Can't prove it, don't need to. I'll conduct myself as if they have all the private keys. That's a loss of freedom, and that's not what the authors of the fourth amendment intended.
The same technique used by former CIA Director David Petraeus and Paula Broadwell to communicate.
SSL and TLS are for the purposes of this discussion the same thing; the distinction between the two is actually less important in SMTP than it is with HTTP.
The term "direct access" may have been fuzzy speak, and indicative of an "impedance mismatch" between what different concentric layers of the NSA knows. The author of the PRISM deck understood it to be "direct access" based on what he'd been told, and the low-lag operation he'd seen. But perhaps that was still be FISA-order based, just really fast: an analyst flags a name at their terminal. The name is forwarded the Google and the FISA court. Google does its "review" but knows a request of exactly this specific form always wins -- they don't get to challenge the reasons for the request, which they don't even see. Now it's 'reviewed', the SFTP dumps begin... but they aren't one-time, but perhaps daily... or even hourly or faster... to keep up with the target's ongoing mail activity. (They didn't go through the trouble of using one of their thousands of requests just to get old activity, did they?) To the PRISM deck authors, that still feels like "direct access" – and colloquially, it is.
But given compartmentalization within the NSA, what if some of the data is arriving via another, deeper capability? The PRISM deck author, the average analyst may just think it's from the other process. It's not their business to know more; the rows/records appear in their tool, and they get on with their work, happy for the bounty of info from other 'acquisition' programs which sometimes (often!) work in mysterious ways.
They use a PFS cipher spec: http://googleonlinesecurity.blogspot.com/2011/11/protecting-...