Feds put heat on Web firms for master encryption keys
m.cnet.com
m.cnet.com
But coercing Google into handing over TLS keys is unequivocally bad; indefensible, I think. It's one thing to legally compel Google to grant access to data, but another thing entirely to rewire Google itself:
* It provides NSA with a technical capability they do not currently have, enabling them to shoot first and answer questions for a court later, and eliminates a due process element that other providers (notably Yahoo) have been able to avail themselves of.
* If provides the USG with capabilities beyond simple surveillance, for instance by allowing them to spoof Google pages. There can't be any legitimate reason to provide them that blanket authority.
I appreciate the effort and expense it must take for companies like Google to resist these requests.
The US government already has at least Verisign under their belt. They can already MITM just about any SSL connection they could ever want to.
I would wager that they have a large number of private keys anyway. It's not like datacenters would be able to do much when the NSA rocks up with a NSL.
The chief issue in all this is the huge number of trusted CA that are the default in most operating systems. My install of OSX for example has 181 default certificate authorities, and any one of them could be compromised. I'd be willing to bet that a sizeable portion are under nefarious control.
Just to make a point I picked a random CA and tried to look up some information about it. Couldn't reach their site the first time, as they are lacking an A record on their domain root. I've no idea why they would be trusted, as they look sketchy as all hell — http://www.valicert.com/
In the case of an organisation like Google, I don't see why the US government would even need the keys for Googles SSL certificates. Google have all the data they could ever want stored unencrypted anyway (or at least have the ability to decrypt). If they had any legal reason for wanting the content of my gmail account, they could just get the courts to subpoena Google for the data.
I think that's one of the motivations right there. Even if FISA generally gives the government what it wants, it's still a process that the government appears to regard as a hassle to be eliminated.
I think the second reason is that google is a sophisticated enough company that they could perhaps infer things from the data request patterns that the requesting agencies would prefer secret.
Access to the master keys for a SSL/TLS session isn't like that at all. They could retroactively capture, archive, and decrypt any traffic to the site at all with nothing but the undetectable network taps we already believe they have.
That said: the linked article is talking about "legally" compelling Google et. al. I don't think that's the only tool in the box. Surely someone at each of these companies has access to the private keys and can be coerced via an appropriate bribe (which at the scales we're talking about could be staggeringly large!) or blackmail attempt to provide it "illegally".
They can't in every case, especially for Google, who use a newer SSL that supports perfect forward secrecy. You are completely correct in the differing magnitudes of attack detectability though.
So historical SSL data captured anywhere between, say 2002 - 2011, could still be decrypted with these keys, right?
I believe that Google has changed them several times even in the last few years though, so it could be that even they don't have access to the old static keys anymore.
https://community.qualys.com/blogs/securitylabs/2013/06/25/s...
Also, as another comment points out, Google uses PFS, so Apple, Yahoo, Microsoft, etc. are better targets for this type of insider attack.
Red herring. We are never discussing active MITM in these NSA threads because they don't do that.
We are discussing offline decryption of monitored SSL traffic, which a CA's key does not help with in any way.
For that attack, you need the server's long-term key and they have to not be using PFS modes.
I believe that this quote in the article pretty much implies an active attack.
For individuals who put encryption on their traffic, we understand that there would need to be some individualized solutions if we get a wiretap order for such persons...C.f. 'tailored access' http://en.wikipedia.org/wiki/Tailored_Access_Operations
I can envision the NSA wanting to undertake active attacks in rare situations, but we don't know whether it has the technical ability to do so under its relationship with AT&T/Verizon/etc. Also even AT&T/VZ/etc. that have historically opened their networks to the NSA for passive surveillance -- in violation of the law -- may have second thoughts if the attacks are active. I suppose you could posit the installation of devices at the target's ISP, but, again, we have no evidence this is something NSA does.
Convince me you know this for a fact.
Attach additional sheets if necessary.
Why don't we see 50,000 deaths a year in the US from terrorist attacks?
N.B. that the NSA claims to have stopped "dozens" (<=100) of plots with these programs.
But AFAICS no one is claiming that terrorism left unchecked would cause 50,000 deaths/yr, so really it's more of a strawman (and in poor taste too, IMHO).
It's amazing how difficult it is to pull that off successfully, even in discussions with people who know you really well.
I welcome sound arguments against my conclusions, though. I admit they're educated guesses.
I don't think the NSA prevents significant amounts of American deaths. That means that these programs are all pain for practically zero gain. (And, consequently, ambivalence about them is dangerous poison.)
I addressed this question a few days ago: https://news.ycombinator.com/item?id=6062363
TL;DR: Most humans, even those enraged at the killing of their families, simply do not want to commit mass murder.
And, no bullshit, I prompt you this way because I know you to be wickedly smart and I assume good faith. I almost always learn something from discussing things with you, even if they turn out to just be little tidbits here and there.
I've probably learned more from you and rdl than the rest of HN commenters combined.
Homer: Oh, how does it work?
Lisa: It doesn't work.
Homer: Uh-huh.
Lisa: It's just a stupid rock.
Homer: Uh-huh.
Lisa: But I don't see any tigers around, do you?
[Homer thinks of this, then pulls out some money]
Homer: Lisa, I want to buy your rock.
Grabbing them in a virtualized environment is even easier.
The HSM market makes me really sad. I'm kind of considering doing an "open source HSM" -- something using COTS components, ideally a few generations old, with everything totally verifiable by the user/assembler, and a key loadable at manufacture time -- the idea being companies could assemble and certify their own, or a third party or industry association could certify them for their regulees. Goal would be to price a low end version around $100-200, and a high-end (x86-64 performance) in the low thousands, unlike the rape that is Thales or SafeNet ($20k+ for mediocre performance). Plus, if you're at all "interesting", there's no way you'd trust a European defense contractor or a US defense-affiliated company with a "black box for keys, trust us".
Not sure if this would be a good business, though. Would need to raise actual VC for it, and while I know some awesome HW people, including in the tamper-resistance space, I've never done volume production of any hardware myself.
A COTS implementation would be interesting. Securing SSL keys would require very quick public key crypto and probably a PCI-E interface to talk to the server, the PCI-E interface making it much more expensive (FPGAs with PCI-E hard blocks have gone down in price, but are by no means cheap, not to mention the increased cost of the PCB). Prototypes probably wouldn't need VC for a proof of concept, but after that you typically need to put up a bit of money for any manufacturing.
I'd be interested in a way to securely generate and store a Root CA certificate and sign other keys with it. Ideally using something like secret sharing so that no single person can access the Root CA as well without having n out of m people.
Proof of concept can be done with a regular dev board or even a cellphone; it's volume production which requires VC.
Not to be unkind, but I'm honestly repulsed by your ambivalence. Ambivalence is assent, in police state logic. Your opinion, backdated:
"I'm ambivalent about the Stasi's need to request that postmasters allow access to all mail."
"I'm ambivalent about the KGB's need to request that all phone lines be tapped."
Make a choice: either be in favor of the American Police State or oppose it.
Ah. Are these your true colors you are showing us?
You know what bugs me about your political posts? I've been thinking about this for a while, exactly what it is about the way you state your opinions that gets under my skin. Could it be the way that you always manage to sound so reasonable and eloquent? And indeed you do argue against some future possible abuse. Yet you manage to defend some currently reprehensible state of affairs. And you'll argue a minute point to death until your opponent concedes defeat meanwhile the larger issue has gotten lost many turns of the screw back. I have wanted to debate you so many times but given how well known you seem to be and also the way you seem to be held in high regard around here I have been very wary.
You could have written a post about the TLS keys and spared us the (not very surprising) insight into your ambivalence. But you didn't. Why not?
I don't know what you thought my "true colors" were, but if you thought they included an unwillingness to tell the authors of comments like these to go fuck themselves, now you know.
> Obviously, ...
There's nothing obvious about it. Why do you think your ambivalence about the FISA process is germane to the discussion we should be having? You should be aware that it'll trigger an off-topic response and derail the discussion as you see it has done.
> comments like these ...
The person was only (in a bit of a soap opera-ish way I will acknowledge) suggesting that you maybe should give reevaluating your position a try. Is that so unconscionable?
I intend no hostility towards you. I appreciate your energy and your knowledge and insights. Now getting back to the issue at hand, dang them pesky spooks!
And why people on the outside never know the true story of why someone in power (say the government) or PG does what they do. Which is why sometimes it seems wrong and doesn't make any sense or it seems there is an easy alternative.
They only know what they read about it or what they are told or what they understand or have been educated about.
You say something that almost certainly would get a user with lower karma hellbanned but it's totally tolerated.
Now a user who is new to HN may wonder why you can get away with that and then feel that it's ok for them to do the same.
PG (or whoever has hellbanning powers) decides that you are either to big to fail or the benefit that you provide to the community outweighs whatever detriment a comment like this poses by letting you continue on HN saying things like that. You most likely don't even get a warning from the cop. "Ok sarge I'll tone it down".
It's like being tenured or something in academia.
I love this stuff. I like the fact that at least some people on HN can say whatever they want (the freedom of speech we are all supposed to have) without fear of either downvotes or being banned from HN.
And while that doesn't mean I want to have a bunch of FU or abusive language thrown about (which would almost certainly detract and make me leave) it is an illustration of the power of the primadonna in organizations.
(By the way Steve Blank was totally like this at the company that I worked with him at. Untouchable.)
This is practice for that over-thinking.
This has more to do with the weirdness of the hellbanning system, which is a whole other can of worms.
You should all go work on something productive.
It's like the HN equivalent of conspicuous consumption. :D
Now double your karma & make a stack. I'm on to the next one.
(Not a lot of Jay-Z fans on HN NSA threads).
I mean, even my own state (which has about as good a rule of law as they come) has in the past implemented a dragnet that kind of went awry. At least, according to the people that lived through "Rasterfahndung", it seems inevitable that the presumption of innocence goes out the window pretty much as soon as eager law enforcement personnel has access to large databases[1].
* The inevitable asterisk: It seems that it might be possible to keep things from going awry if there is a specific warrant signed by a judge for every _individual_ act of "listening in". Not a warrant for tapping a service provider, but a warrant to look at the data of a single user at that provider. But this is moot, since we are already way past any point where it would have been possible to stop at that.
[1] http://translate.google.com/translate?sl=auto&tl=en&js=n&pre...
What I don't respect are people who have no earthly clue what they're talking about telling me how repellent my views are.
This points to a flaw in the logic of governance that results in accumulated errors when it's used as a precept. The NSA is the interloper in American society and a latecomer to government. The existence of the NSA has no foundation in the so-called social contract that we all share. It's essentially a lawless institution at this point.
The NSA and those that support it that are militantly anti-social. Citizens insisting on their rights aren't the problem. Those that demand or facilitate the infringement of our rights are the actual problem.
If I remember correctly , you don't have a problem with the NSA phone metadata collection either... but wouldn't your same argument apply there as well?
http://www.nytimes.com/2013/07/16/us/double-secret-surveilla...
Since this is apparently new information to you, I hope you update your risk assessment.
The government misusing secret surveillance isn't conspiracy talk, it's first order incentives. It would be bizarre if the data were NOT being abused. I'm a law and order guy, but federal prosecutors have a well documented history of playing as close to the the line as they can and dancing right over the line when they can get away with it. Since they're now trying to hide the line, this should be fairly scary to rational people.
I think the "resistance" by the legal departments of these companies is largely theatre. If someone with the resources of a nation-state agency wants the keys, they will get them. All they need to do is figure out who has access to them, and either bribe them or blackmail them.
That's why we need their power to be limited and defined, as open as possible, and have legitimate avenues of redress for grievances. They are supposed to be public servants, not rogues.
"Another idea is to erect a series of shields to defend against each of the dangerous technologies. The Strategic Defense Initiative, proposed by the Reagan administration, was an attempt to design such a shield against the threat of a nuclear attack from the Soviet Union. But as Arthur C. Clarke, who was privy to discussions about the project, observed: "Though it might be possible, at vast expense, to construct local defense systems that would 'only' let through a few percent of ballistic missiles, the much touted idea of a national umbrella was nonsense. Luis Alvarez, perhaps the greatest experimental physicist of this century, remarked to me that the advocates of such schemes were 'very bright guys with no common sense.'" Clarke continued: "Looking into my often cloudy crystal ball, I suspect that a total defense might indeed be possible in a century or so. But the technology involved would produce, as a by-product, weapons so terrible that no one would bother with anything as primitive as ballistic missiles.""
The threat of terrorism is greatly overplayed by various interest groups. I wonder if the accumulated effect of this attempt to oust terrorists is creating more harm than it's hindering.
More people die in a year on the US roads than have died from all terrorist attacks accumulated.
Some of those that died on the roads most probably chose a car instead of the tediousness that is airports.
If the US government truly where interested in hindering terrorists and saving lives, they wouldn't hide the fact that they are eavesdropping, they would make it obvious and transparent, and possible for each individual citizen to know what they know about you.
I just don't get their logic.
[1] https://www.youtube.com/watch?feature=player_detailpage&v=bA...
I'm a little tired of this argument. "Only" 3000 people died in 9/11. Yet look at the effect that 9/11 had on the world, versus 100 times that many automobile deaths.
As much as we'd like to think the only bad outcome of a terrorist attack is loss of life, that's not really the biggest outcome. It is the impact on society, like it or not.
At the end of the day, terrorism is primarily a tool to affect political situations, their effect on public health situations is not really the point; it is that political damage that is worrying to governments.
Using the vast impact of 9/11 as an argument for further reaction is getting everything backwards.
We would have been vastly better off following 9/11 if the government had gone with a "keep calm and carry on" mentality rather than the "everybody panic and start invading things" reaction they actually had.
Terrorism is like a bee sting, and our reaction to terror attacks in the US is like an allergic reaction. The difference is that the US has control over its own immune system, and could choose not to be allergic if it wished.
That "political damage" is almost all caused by the government, and can't be treated like an independent entity. The excessive impact of terrorism cannot be used to argue that the government needs to pay attention to terrorism, because it is that paying attention which causes the excessive impact in the first place.
The government's overreaction was after the populace had freaked out, that is true, but silence can be damning as well. Silence lets hysteria breed. If the President had gone live on national television with a "keep calm and carry on" message, I believe it would have helped a lot. Instead, the government treated it as an existential threat, invoking the NATO charter, declaring a "war on terror", etc. None of this was necessary, and it was all highly damaging, although not to the people in power.
yeah, I know, my personal opinion is that Cheney definitely did that; invading a country that had nothing to do with terrorism was evidence of that. I don't see this as Obama's motive though, I think he just wants there to be no terrorist attacks under his watch so that he doesn't sustain more political losses on that front alone (look how much flak he took for benghazi). If there was not such a huge political price for terrorism, I get the impression it would be easier for him to reign in the NSA/FBI. But I can't prove any of this, I'm a dem so I'm biased, etc.
I don't recall hysteria in Boston. There was more hysteria over the Moonites than bombings. But I don't think anyone has the bar so low to say that it's all good as long as gov't doesn't create the hysteria. The gov't should be able to dampen hysteria rather than swing it higher.
Nope. Democracies are constrained to the strategic analysis ability of the average voter. Absent a radical eugenics campaign, the average voter will continue to cast superficial, uninformed votes. Democracies die because they vote for their own destruction.
P.S. If the people had voted in a rational nuclear power plan, the Middle East would be just another backwater. The bin Laden clan would be just another bunch of towelheads squabbling over camels.
That's a very dark view of mankind. You are basically saying people are so stupid that it's always going to be that after the loss of life, we'll invade lots of countries and spend a trillion dollars, and give up all of our freedoms.
The point is, equating terrorism to other events strictly in terms of loss of life does absolutely nothing to help the situation. If you want to change the societal psychology of terrorism, that's a noble goal, and if you can figure that one out, the governments of the world will gladly make you the richest man in history.
Of course that's the purpose of it. That's why preventing an overreaction would be more effective at fighting it than falling into the trap of getting trolled by them.
This "impact on society" is exactly what terrorist have in mind. Instead of keeping a cool head (like the Norwegians did after their 2011 attacks) we're playing right along with what a terrorist would want to achieve.
Grandparent's argument is perfectly valid.
Edit: Spelling
Note I have no direct knowledge that this is the motivation, but it strikes me that PFS is a solution to a specific threat model of an eavesdropper having passive access to the network. I'd be eager to hear more from people who are more familiar with the issue than I am.
A: They can credibly argue that they don't have that information, and it won't trigger an avalanche of copycat subpoenas.
B: The crypto key being sought by the subpoena is not one that would enable decryption of all Google, but rather one specific to the connection.
But because Google can be compelled to divulge the plaintext of, say, email messages or G+ posts if subject to a lawful court order, there's no need to perform a more difficult and expensive Title III wiretap. Real-time services like Hangouts are an exception, but it's still easier to serve a Title III order on Google than try to install a box on a rural ISP in Georgia and try to intercept and decode the stream.
Re: your point B, PFS would protect against passive attacks even if the master SSL key is known to Eve, and a subpoena would be insufficient legal process to obtain an ephemeral session key.
Which pretty much in a nutshell encapsulates what's wrong with the U.S. security state we've built. Terrorism is the trump card, the thing that compels/allows the state to take anything it needs. As one official put it recently "We're not trying to spy on you, we're trying to find those among you who are trying to kill you" And anything they do in order to prevent that from happening is fair game. It's a perpetual state of war.
Having said that, this is kind of a good news/bad news situation. The good news? Looks like most of the secret back door rumors, at least when it comes to TLS, were wrong. The bad news? It doesn't matter. If the government can try compel you to release the secret password for millions of users -- and then forbid you even to talk about it in the open -- then there truly is no limit to the monitoring and control they can exert. Whatever they get away with this year, there'll be more to come next year. Fake out https websites, play MITM games with data providers -- if you've got the keys, the world is your oyster.
Back around the turn of the century, I worked on several government projects. Aside from the usual deadwood workers, there are folks that are really eager to push the technology and create as much automation and storage as possible. This is because they like to hack, just like the rest of us. I used to say, jokingly, that the only reason we didn't live in a dystopian security state was that the government was too inept to actually create one.
Looks like the joke was on me. They're pretty fast learners. Make the national transaction and storage system totally secure, then lean on the in-country tech community to give you the keys to all of it. What a terrible way to destroy the national tech economy.
Reporting like this appears[1], and -- coincidence or not -- those observations fit into place.
----
[1] Whether regarding three letter acronyms or protocol weaknesses or whatnot
P.S. I'm not sure why the downvotes. TLS renegotiation weakness. Perfect forward security. Even earlier, nascent deployment of their own intermediate certificate authority -- which disappeared after some months, only to reappear again more recently (at least, in my Gmail connections). More recently, in addition to maintaining perfect forward security, now also replacing the underlying certificates every three weeks or so -- at least, as based upon the changing validity dates that are easier/quicker to compare in/via the browser interface.
I continue to "wonder" where Google comes down in all this... "security/authoritarianism" fracas. If there is a single "Google position". Regardless, they appear to be one of the most proactive parties, from a technical perspective. And politics aside, I continue to think that behind the scenes, there are a lot of people there behind the scenes who want to "do the right thing" and who work hard, within their responsibilities and areas of expertise, to "make it so".
BTW it's every two weeks: http://news.cnet.com/8301-13578_3-57591560-38/facebooks-outm... Langley added: "We would have totally eaten the cost and the speed years ago -- if we could have done it without worries." As an additional precaution, Langley said, Google usually rotates its RSA keys every two weeks.
This is worse than key-escrow and clipper chips and all the other nonsense we fought in the past.
But on the other hand: Snowden was successfully able to evade Boundless Informant and conduct a confidential conversation with Greenwald and Laura Poitras (certainly already an active surveillance target for her film of William Binney).
So the crypto wars are not yet lost.
http://news.cnet.com/8301-13578_3-57591560-38/facebooks-outm... Eran Tromer, an assistant professor of computer science at Tel Aviv University who wrote his 2007 dissertation on custom code-breaking hardware, said it's now "feasible to build dedicated hardware devices that can break 1024-bit RSA keys at a cost of under $1 million per device." Each dedicated device would be able to break a 1,024-bit key in one year, he said.
In any case, major Internet companies have either moved to longer SSL keys or have announced plans to do so.
We won the cryptowars, but it was a Pyrrhic victory. By the time we won the right to distribute strong cryptography there were hundreds of millions of people using the Internet without it, and the important protocols were all insecure. We have spent over a decade trying to jimmy cryptography into those protocols and are now stuck with a complete mess. We are still relying on passwords to authenticate people, we are still sending unsigned email in the clear, etc. Glen Greenwald had to be pestered by another journalist to even bother with OTR when Snowden tried to talk to him.
Perhaps this is a response to growing use of certificate pinning? Facebook apparently has joined google in using pins, and I was recently told that microsoft is enabling pinning as an option in EMET4. But if that was the issue, that would tend to suggest they had been previously accustomed to rewriting some of these providers traffic with unlikely root ca's, something which people have been keeping an eye out for and to my knowledge has never been caught in the wild.
(I'd personally have a really hard time giving them a polite multi-page legal letter saying "sorry, we are unable to comply, and we don't have to, due to x, y, z" -- either a single "No." or perhaps "Nuts!", or trolling them with ASCII art or a return letter demanding NSA turn over their keys. Which is why I'm not a lawyer.)
I've had to think about that case myself.
Kinda off-topic but this statement is false. Facebook HTTPS is not enabled by default, it's opt-in.
They started rolling out HTTPS for everyone on November, 2012 (http://webcache.googleusercontent.com/search?q=cache:develop...)
But since I don't live in the US, it must have taken Facebook a long time to get to my country. I still remember telling all my friends to opt-in to HTTPS in 2012.