The NSA's crypto "breakthrough"
economist.com
economist.com
I don't think it has happened. But if it had, that would be the kind of secret that would go in the President's book of secrets right along with the existence of National Treasure or the Men in Black. :P Snowden would never have a clue.
NSA published a note advocating use of ECC in 2009: http://www.nsa.gov/business/programs/elliptic_curve.shtml
NSA's statement wasn't "we've got an RSA-breaking machine" or anything like that; the highlights are 0) folks are using RSA-1024, which public sources only ascribe 80 bits' worth of security to, smaller than the usual margin; 1) RSA gets slow with long keys: according to public sources, 256-bit security requires RSA-3072, which is 64x slower than the equivalent ECC-512; 2) RSA-breaking implementations keep getting gradually better over time, whereas ECC's effort-to-break has basically stood still.
Their own ("Suite B") guidelines for use of public algorithms to protect classified data tell the US government to use ECC, not RSA. (AES-256 is fine, though.) They licensed patents for particular implementation techniques: http://en.wikipedia.org/wiki/NSA_Suite_B_Cryptography
Bruce Schneier, reacting to Bamford's statement about a cryptographic breakthrough, said: "Another option is that the NSA has built dedicated hardware capable of factoring 1024-bit numbers. There's quite a lot of RSA-1024 out there, so that would be a fruitful project. So, maybe."
(There's a lot of RSA-1024 out there partly because old 1024-bit SSL certs die hard, and people are lazy about switching to bigger keys if, for example, it would make establishing SSL sessions more expensive.)
Finally, perhaps not related to public-key crypto but really interesting, the XKeyScore deck had the bullet point "Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users" as one of the things you can tell the system to do. That could just refer to one of those protocols that everyone knows is broken but is still in use (MS-CHAP/PPTP) or to either a protocol/implementation break or something else affecting VPNs we currently think are secure.
Maybe the best argument against a crypto breakthrough is that it's clearly extremely hard (none of the brilliant mathematicians working in the open are close) whereas attacks on implementations and protocols are relatively easy. If you have a big bag of 0-days, have stolen some certificates (as Stuxnet seemed to indicate), and are inside a bunch of service providers, it seems almost redundant to put a lot of effort into factoring big numbers, unless some big technical improvement basically falls in your lap.
It is then a simple matter of waiting for a user to leak personable identifiable information. A visit to Facebook or an email account, etc whilst connected to the VPN is all it takes, and then you can group and map browser headers (roughly) to VPN users.
Maybe they can break small key length SSL when they really need to. If there is TLS traffic of interest popping out from the VPN exit, then they store it and process it later, probably in some massive AWS compute intensive cloud service even.
VPN users have to remember that their traffic is protected from your machine as far as the VPN exit node. After that exit point onwards to the requested web server, you are as naked as before. Worse is that it lulls users into a false sense of security.
Of course, if the cat ever gets out of the bag, that situation would change.
Now killing a submarine once you know where it is, is pretty easy. The problem is finding the submarine, and explaining how you were found. To handle that, the Allies used a form of parallel construction. They would send a spotting plane over the area, to spot the sub and give a plausible reason to have located the submarine.
In other words: if the NSA break one of these "public" algorithms, you'll be able to tell; they'll soon be picking new Suite B ciphers. (There will be a time-delay, but not of the intentional "let's capture+break foreign transmissions before scaring them away from this cipher" kind. Re-securing our own transmissions takes priority, always. Even if it was broken because of some "quantum leap"--pardon the pun--we have to assume our enemies are advancing their own tech at roughly the same rate, so if we can crack it, they can too.)
Take for instance the Skipjack cipher (https://en.wikipedia.org/wiki/Skipjack_(cipher)), a Type I cipher ("endorsed by the NSA for securing classified and sensitive U.S. Government information") which was evaluated, for the purpose of security, by "some of the world's most accomplished and famous experts in combinatorics and abstract algebra", and finally declassified due to concerns expressed by other cryptographers about its security.
Biham and Shamir broke it the day after it was declassified.
In cryptography, if you break 1 bit, you've broken it. No excuse.
Skipjack was designed using building blocks and
techniques that date back more than forty years.
I think it's safe to assume they have much stronger stuff now.So it basically comes down to whether or not we 'assume our enemies are advancing their own tech at roughly the same rate.' The NSA probably has an okay idea of what 'roughly' is, and if you had this ability you wouldn't be showing your hand lightly.
Way more speculatively, I'd be curious to know whether or not it would be possible to add 'next-gen' crypto to existing practices in such a way that it might be transparent?
If you check some scientific breakthroughs during the Cold War they were very close on the both sides in the matter of months.
Also with 5% of the world population NSA have limited talent pool. Assuming you are first to the goal in that case is ... overly confident. (Even if we correct for a lot of people that are not easy to tap in the outside populations chances are not on the NSA side). And I am sure a lot of the messages in other countries communications are fake and testing just to see if someone is snooping.
EDIT: To your latter point, some people would consider this to be a telling fact.
Perhaps they were simply anticipating DLP progress and wanted to be future-proof?
Suite B aims for 128-bit or 192-bit security levels; for comparison 1024-bit modulus RSA is currently thought to provide 73-bit security.
(The next natural question is why the internet community is still failing to widely deploy cryptosystems with appropriate security levels. I don't know. But HTTPS, OTR and DNSSEC are all built of cheese in this respect.)
I agree with your point, but do you think they'd force widespread cipher switch across government bodies? Or leave other government entities using broken encryption so they can more easiler spy?
But now every plane spotter has instant cross-correlation with every other one - and those secret flights stand out as being, well, private flights.
So long story short, if I did magically invent quantum computing, I would let the rest of the low grade secrets go hang. One of the 3 million (!) security cleared US personnel will throw Assange a copy soon enough - so lets use the advantage, to our advantage.
This of course means that if our security services have the brains and the political muscle, they will need to choose themselves which are the truly secret things and arrange a government in a government to keep it in shape. That's not likely to be a good thing.
you only notice once they call upon the more public parts of gov to switch to another 'secure' algo. also, NSA themselves probably use the Suite A algos that we know batshit about.
but, reality check: THIS IS ALL SPECULATION. there is no evidence that they have broken anything.
Second, they use an example from GCHQ's public key cryptography work rather than the more relevant NSA work on differential cryptanalysis, which became public knowledge in the late 1980s, was discovered by IBM in 1974, and which the NSA was already "well aware of" in 1974 [0].
[0]: https://en.wikipedia.org/wiki/Differential_cryptanalysis#His...
It is too much to ask the nation's photographers just to take a few more pictures from different angles? ;) It's as bad as as the Onion's opinion on Snowden ("Nation Demands New Photograph Of Edward Snowden"):
https://www.google.com/search?safe=off&q=%22Nation+Demands+N...
There has been some paranoia around photographers taking photographs in public. The London police force had to issue guidelines for their officers about correct procedure. (http://content.met.police.uk/Site/photographyadvice) (http://www.bjp-online.com/british-journal-of-photography/new...)
It's probably not a good idea to stand outside GCHQ's fence and take photos. They'll claim it's to protect secrets - the privacy and secrecy of who works for them, for example. (Because there is mostly carpark between the doughnut and the public road). I don't know if someone would get arrested, but "they" would certainly feel able to use their anti-terror powers and the experience would not be pleasant.
It's a pity that I can't source this specifically, but I vaguely remember reading in either James Bamford's "The Shadow Factory" [1] or his "Body of Secrets" [2] that the NSA once leased an entire office building that had been built near the edge of Fort Meade, simply because the top floors could see onto the campus.
[1] http://en.wikipedia.org/wiki/The_Shadow_Factory [2] http://en.wikipedia.org/wiki/Body_of_Secrets
(I'm sure I have that wrong - so a prize to whoever corrects the quote from memory :-)
Banthas are the large beasts-of-burden on Tatooine. Bothans are humanoid aliens with cat/dog-like faces. Why do I know that? I play a lot of Star Wars video and card games :)
EDIT: just googled for the quote. The full one is "Many Bothans died to bring us this information."
Maybe it's just me
>Does the NSA have a quantum computer in the basement of its headquarters in Maryland (pictured above)? It is theoretically possible, but pretty unlikely...
A Canadian firm called D-Wave is presently selling a specialised kind of quantum computer—Lockheed Martin, an American defence giant, and Google have each bought one—but it is not suitable for this kind of work.
In-Q-Tel - "About Us"
>"We make investments in startup companies that have developed commercially-focused technologies that will provide strong, near-term advantages (within 36 months) to the IC mission. We design our strategic investments to accelerate product development and delivery for this ready-soon innovation, and specifically to help companies add capabilities needed by our customers in the Intelligence Community.
"D-Wave Systems, Inc., the World's First Commercial Quantum Computing Company, Secures $30 Million in a New Equity Round From Investors Including Bezos Expeditions and In-Q-Tel" [0]
"Burnaby, BC - Milpitas, CA - October 4, 2012 - D-Wave Systems, Inc. today announced that it has closed a $30 million round of equity funding. Bezos Expeditions and In-Q-Tel (IQT) have joined the investment round. Bezos Expeditions is the personal investment company of Jeff Bezos. IQT is the strategic investment firm that delivers innovative technology solutions in support of the missions of the U.S. Intelligence Community."
[0] http://www.dwavesys.com/en/pressreleases.html#investment_201...
Remember: companies are in the game of marketing hype to ride your scifi hopes and dreams. When you see a company saying "quantum" anything, discount their unqualified claims greatly. (Investors are not immune to being manipulated by hype. Claiming "they must be good because they have fancy investors!" provides no more weight to their ability than a hobo claiming he keeps the airplane aloft by snapping his fingers every 3.2 seconds.)
For example, the quantum computer that factored 21 into 3 x 7 did it by using Shor's algorithm for quantum factoring in polynomial time. The D-Wave machine cannot implement Shor's algorithm.
The D-Wave machine would be more capable on a different problem, one that maps efficiently onto the D-Wave machine's problem space. But we're talking about factoring here.
There are some who believe that wasting incredible resources on military / defense is actually weakening the country in light of the fact that we have no superpower enemy with even the remote potential to match our military. This leaves us vulnerable to other novel attacks, as well as just spending ourselves into oblivion. You know, the same way we 'overcame' the USSR's military threat via the arms race when their economy could not match the pace of ours.
Yes, the US gov't should be weakened by any account; given the degree which it has overstepped its stated bounds.
No, building petabyte-scale data centers to spy on you and me is what's weakening the American government. We're not the problem, right?
The NSA is like the drunk who looks for his lost keys under the lamppost, "because that's where the light is." Not only does the American government's idea of a hypersecure state not make us any more free, there's vanishingly little evidence that it accomplishes its purpose of making us any more secure.
That sounds like a fair trade considering the cost in human lives... except that there's no evidence we're "trading" anything but our own treasure and freedom.
I suppose that Snowden leaks were not a great surprise to the foreign governments.
Now one day over-the-counter quantum computers will probably become a reality. In that age we'll see more information on it because the secret will be no secret at all.
But who knows. Maybe Snowden emboldened a few people who will be able to shine some light on these things in a more quiet manner.
ASICs may well be involved, but they'd need math advances or implementation bugs rather than just brute force.
There are no answers and there will never be, b/c:
We can never trust/accept any statements from any government, except for admissions of guilt.
1) There's an attack against RSA which doesn't involve factorization
2) There's an attack against AES / Serpent / Twofish
I'd say the second is considerably more likely, firstly because the one NSA quote we have on it is "cryptanalyze, or break, unfathomably complex encryption systems" - which sounds much more like a new attack like differential cryptanalysis which provides a general purpose attack against complex symmetric crypto ("unfathomly complex" sounds much more like AES than RSA).
In addition we have numerous quotes in recent days about how GCHQ is working on breaking the encryption on the Miranda hard-drive; which we now know to be a truecrypt drive.
But I don't think the fact they're still using it means it hasn't been broken. Historically countries have sacrificed countless soldiers because saving them would have revealed that the enemy crypto-system had been broken.
They have to recommend Suite B to the government and military in cases where NSA validated hardware can't be used. Examples would be military communications with allies, garden variety agencies that can't afford or can't be trusted with Suite A modules.
(or to put it another way: revealing a secret to a population where the vast majority do not know it)
Snowden revealed the scale of the operation too, and the depth of the rabbit hole.
"An all knowing deity is a cheap cop."
http://en.wikipedia.org/wiki/Integer_factorization#Difficult...
I never said it wasn't.
> And a breakthrough in P?=NP could have implications for factorization.
Indeed, but what's implied in the article is that they might have made a breakthrough in factorization specifically, not in fundamental CS theory at large.