Can we even trust encryption? How can we know that the NSA haven’t found weaknesses in common encryption algorithms? They have some of this field’s best people in the world on this.
Can we even trust encryption? How can we know that the NSA haven’t found weaknesses in common encryption algorithms? They have some of this field’s best people in the world on this.
"According to another top official also involved with the program, the NSA made an enormous breakthrough several years ago in its ability to cryptanalyze, or break, unfathomably complex encryption systems employed by not only governments around the world but also many average computer users in the US."
What do many average computer users use? TLS is my guess. So, perhaps they've found a way to get into RC4, or made an advance in factoring. And the history of cryptanalysis says that they are likely years and years ahead of what's known outside. So, what can you do?
Well, you can read the ECRYPT II report [2] and see for yourself what Europe's cryptographers think about the security of various algorithms and what key lengths they recommend.
For example, the report recommends that an asymmetric key of 3,248 bits should be secure to 2040 (they recommend a symmetric key of 128 bits for the same period). So, the subtext is that an 2,048 bit RSA key is going to be breakable soon by a powerful adversary.
The report says, for example of RSA OAEP: "If used, we recommend at least |N|>1024 for legacy systems and |N|>2432 for new systems."
My brief summary is that I'm happiest with RSA keys of 4,096 bits or above and with symmetric keys of 256 bits.
[1] http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/
PS I'd be curious to know what key length Snowden used for the GPG key he apparently used when communicating with Greenwald.
Undoubtedly the NSA is ahead of everyone else in cryptanalysis but I think it is also advantageous for the NSA to have foreign governments think the NSA has a bigger lead than they actually do. This belief would cause foreign governments to use larger key sizes, and so drive up their costs, or switch to less well tested encryption methods that the NSA might be able to break.
I would think it is more advantageous for the NSA to have others believe that it has less capabilities than they actually do.
The NSA is well known for its disinformation campaigns. Why wouldn't they try to make others (governments, end users, etc.) believe that they don't have the ability to break various key sizes.
This could provide a false sense of security to others and cause them to believe that, for example, a 2048-bit PGP key is more than sufficient when, in fact, it isn't.
But there are also situations where they would want the opposite. For example, suppose the NSA has no advantage in breaking RSA over public knowledge, but can easily break NTRU and their goal is to read as many encrypted messages as possible. Then if they can get everyone to believe they can break RSA but not any cryptosystem based on lattices then some people will switch to NTRU. Now its much cheaper for the NSA to achieve their goal of breaking lots of encrypted messages since they have a very efficient algorithm for reading NTRU encryptions.
(This belief could be spread simply by having an "anonymous but very senior" official talk to Wired about how the US government has made a major step towards building the first scalable quantum computer)
In short, what they should want the world to believe depends on their capabilities and goals. Without knowing those anything is possible.
- Are you managing TEMPEST? Do you know what's on the other side of your walls?
- Who else has an access card/PIN/key to get near your computer? Cleaning service? Custodians? Other tenants?
- Are you running Windows?
- Do you read and fully understand every line of code of every security patch all of the time? Do you compile them yourself? Because no matter how much you may believe in Linux, package maintainers and repository owners are still people who are subject the laws of a sovereign nation.
- Do you trust your BIOS? Does your motherboard have Intel vPro or similar?
- Is your Java out of date?
- Where else have you used your password?
- If you're doing anything other than Gmail via Chrome, do you check to make sure the SSL certificate is from the correct CA? Do you check it every time?
- Do you know that everyone you ever communicate with is always perfectly on top of all of these (and other) potential vulnerabilities all of the time with no exceptions ever?
If not, then it doesn't matter whether we can still trust encryption. Because we certainly can't (by default) trust endpoints.
It is extremely unlikely that your email is important enough to the NSA for them to risk disclosing their ability and pushing everyone to different or stronger algorithms.
The more widely they allow such attacks to be used, the more people need know of its existence, and the greater their risk of exposure (even if the victims of these attacks are themselves oblivious).
Depending on who we're imagining as the victim, you also don't necessarily have to publish at all.
Now, maybe something has changed since then, but I am fairly confident that is not the case.