NSA can retain encrypted communications of Americans possibly indefinitely
pcworld.com
pcworld.com
We do have an idea, let's label it 'Clapperspeak'. "Common accepted best practices of espionage trade craft" gives state sanctioned CLASSIFIED license to lie, cheat, steal, bear false witness, interpret 12 ways to Sunday, anything and everything.
What if a communication itself is not encrypted but contains encrypted elements, like maybe a session ID?
I am told that the FBI does not actually draw such a distinction when dealing with criminal messages. The term "null cipher" is used to refer to messages encoded in a non-randomized fashion that does not involve any secret key. I was being a bit sarcastic above, but honestly, I would not be surprised if the government tried to claim that base64 encoding counted as "encryption" in this situation.
While such a wide use of encryption seems unlikely, would it be possible to achieve the same effect by feeding the system with encrypted garbage? Even if it is eventually decrypted, it adds a lot of noise to the analysis effort, further increasing the cost.
The NSA knows how fucked they'd really be if everyone used end to end encryption. You can smell their fear.
Let's do the math to see if that would even be possible:
* 144 billion emails per day in the U.S.
* Average email size is 75 kb.
* Works out to about 10 petabytes/day.
That facility they're building in Utah is exascale, so the computational burden isn't that much if they're simply looking at metadata. Obviously, decryption is more complicated.Last I checked, a MW/year runs about $1m with long term agreements (old number; probably $2m now). Assuming a budget on the order of billions, that isn't a huge hurdle for a government snoop to clear.
The Utah facility is supposed to be able to store the next 100 years of all Internet data + traffic, even at the current projected rate of growth.
Given the reach of PRISM and related projects, and given that a lot of the internet was using 1024-bit RSA keys for HTTPS, it's a good question wondering how much of those private keys are still ... private.
"Longer key lengths are better, but only up to a point. AES will have 128-bit, 192-bit, and 256-bit key lengths. This is far longer than needed for the foreseeable future. In fact, we cannot even imagine a world where 256-bit brute force searches are possible. It requires some fundamental breakthroughs in physics and our understanding of the universe.
One of the consequences of the second law of thermodynamics is that a certain amount of energy is necessary to represent information. To record a single bit by changing the state of a system requires an amount of energy no less than kT, where T is the absolute temperature of the system and k is the Boltzman constant. (Stick with me; the physics lesson is almost over.)
Given that k = 1.38 × 10^−16 erg/K, and that the ambient temperature of the universe is 3.2 Kelvin, an ideal computer running at 3.2 K would consume 4.4 × 10−16 ergs every time it set or cleared a bit. To run a computer any colder than the cosmic background radiation would require extra energy to run a heat pump.
Now, the annual energy output of our sun is about 1.21 × 10^41 ergs. This is enough to power about 2.7 × 10^56 single bit changes on our ideal computer; enough state changes to put a 187-bit counter through all its values. If we built a Dyson sphere around the sun and captured all its energy for 32 years, without any loss, we could power a computer to count up to 2^192. Of course, it wouldn't have the energy left over to perform any useful calculations with this counter.
But that's just one star, and a measly one at that. A typical supernova releases something like 1^051 ergs. (About a hundred times as much energy would be released in the form of neutrinos, but let them go for now.) If all of this energy could be channeled into a single orgy of computation, a 219-bit counter could be cycled through all of its states.
These numbers have nothing to do with the technology of the devices; they are the maximums that thermodynamics will allow. And they strongly imply that brute-force attacks against 256-bit keys will be infeasible until computers are built from something other than matter and occupy something other than space."
Schneier's argument that 3.2K is a limit is perhaps not the best one? Dilution fridges let you into the millikelvin quickly. Optical cooling can readily reach nanokelvin. Power dissipation remains a significant problem, but the power requirement is reduced by ~10^9.
From the quantum-computing side of things, it's not that crazy to imagine a 256 bit quantum computer, especially if you have a GDP-caliber budget. Researchers worldwide are working hard on the relevant technological precursors.
In addition to this, I don't know how well quantum computers help against (good) symmetric encryption. They help against certain types of PKI because they give you the aforementioned speedup in factoring large integers. However, I think Schneier's argument holds, because brute forcing 2^256 possible keys is.. well, see the argument above about forcing a counter through all those states.
(apologies for not citing sources. Hopefully someone more knowledgeable can weigh in)
So, if you have terrifically huge enemies, who will burn galaxies to get at your secrets, you might want to use a few more bits.
You might worry about quantum computers, too, since afaik Grover's algorithm halves effective key size.
If you have enemies who can burn galaxies, then you have really other problems than keeping any possible secret.
However, it's entirely possible (though unlikely) that actual, significant progress will be made either in DLP or in attacking AES/RC4 -- at which case, yeah, that data is as good as clear.
[1]https://www.schneier.com/blog/archives/2009/09/the_doghouse_...
[0]: https://en.wikipedia.org/wiki/Key_size#Asymmetric_algorithm_...
test the forever stored future with ten thousand inviting Voynich manuscripts with buried url tripwire alert beacons and countdown n-folded damascene crypto layerings that annunciate when finally cracked and the hunter bot-spider races along the breadcrumbs, trips the wire, and `hello'!