N.S.A. Foils Much Internet Encryption
nytimes.com
nytimes.com
Not only will this cause other countries to put up barriers against US (and UK) services and products, it's going to affect uptake of standards developed here.
On the lighter side, a treasure hunt was just announced. Can you find one of these vulnerabilities, or evidence of the NSA having attacked a particular system to steal keys?
----
[Edit 1] Some speculation:
By careful hardware design -- and lots of it -- the NSA may be able to find keys large enough that we would be mildly surprised but not shocked. It's not well known that searching for many keys in parallel amortizes well -- it's much cheaper than finding all the keys individually. DJB has a great paper about this:
http://cr.yp.to/snuffle/bruteforce-20050425.pdf
If I were looking for subverted hardware, I'd be really interested in reverse engineering Ethernet chips and BMCs. The CPU would be an obvious choice as well -- could there be some sequence of instructions that enables privilege escalation?
On protocols, the best sort of vulnerability for the NSA would be the kind that is still somewhat difficult and expensive to exploit. They want the security lowered just far enough that they can get the plaintext, but not so far that our adversaries can.
There is some history with not taking timing attacks seriously enough. Perhaps careful timing observation, which the NSA is well positioned to do, could give more of an edge than we suspect. Or perhaps you could push vendors to make their products susceptible to this kind of attack, secure in the belief that it may be difficult for others to detect.
[Edit 2]
I gave a talk that discussed what I think we as engineers should do here:
https://www.youtube.com/watch?v=c7oK59DZwR4#t=1m46s
And Phil Zimmermann and I discussed a number of these issues in a Q&A session:
- Crytographers all acknowledge 1024-bit RSA is dead [1].
- Attack cost 10 years ago was estimated to be a few million USD to build a device able to crack a 1024-bit key every 12 months [2].
- "Much of" the "secure" HTTPS websites use such weak key sizes [3].
- NSA had a budget of 10.8 billion USD in 2013.
Drawing a conclusion is not very hard.
[1] http://arstechnica.com/uncategorized/2007/05/researchers-307... [2] http://www.cs.tau.ac.il/~tromer/twirl/ [3] https://www.eff.org/pages/howto-using-ssl-observatory-cloud
I can't comment on Android Browser on Google TV, but I very highly doubt it fails to support 2048-bit RSA keys. If that was the case, half the HTTPS websites would be unbrowsable(!) [1]
[1] Per the EFF SSL observatory dataset, roughly 1 in 2 websites uses key lengths strictly higher than 1024 bits.
In the context of SSL, an assymetric algorithm like RSA is used to exchange symmetrc keys, which are used afterwards.
I'm not sure what the crypto best practice is regarding key strength for 128 bit for symmetric crypto, but presumably it would depend on the cipher used.
Generalized 1024-bit RSA keys are dead. Lenstra is making a comment on generalized 1024-bit RSA keys in this sentence. Not on Mersenne number factorization (which is, yes, the main topic of this article).
My link [2] tells you concretely how to break 1024-bit RSA and estimates the cost to $10M, well within NSA's capabilities.
1. What are the chances that crypto will keep the NSA out of your communications generally? and
2. What are the chances that crypto will keep the NSA out of your communications if they really, really want to read them?
Those questions are very different. I wonder, for example, of what would happen if all internet traffic was encrypted end to end with something as weak as DES. Could the NSA brute force it? Of course. Could they brute force all of it? doubtful.
One of the clear in-between-the-lines things in the article is that crypto is still problematic to the point where the NSA prefers to attack endpoints and get access that way instead of attacking the crypto itself.
Btw... apart from Scrypt paper, has anyone put together a practical guide on crypto parameter brute force costs? (say volume pricing of gear and asics in huge qty)
At the time, it wasn't clear if this was a deliberate backdoor or an accident, but it was proven that there there was a possibility that there was a secret key that would allow someone to predict future values of a pseudo random number generator based on previous values. Now it looks pretty clear that it was a deliberate backdoor.
This really reduces trust in US based cryptographic standards. And US based cryptographic hardware, as they mention in the article that they convinced hardware manufacturers to insert backdoors for hardware shipped overseas.
edit: reading in more detail around there, i am pretty sure that section of the article is referring to the CSPRNG vulnerability above. the article covers a lot of ground and not all of it is about problems with ssl. that particular section seems to be arguing that the nsa is trying to put backdoors into standards wherever it can.
> Simultaneously, the N.S.A. has been deliberately weakening the international encryption standards adopted by developers. One goal in the agency’s 2013 budget request was to “influence policies, standards and specifications for commercial public key technologies,” the most common encryption method.
> Cryptographers have long suspected that the agency planted vulnerabilities in a standard adopted in 2006 by the National Institute of Standards and Technology, the United States’ encryption standards body, and later by the International Organization for Standardization, which has 163 countries as members.
> Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency. The N.S.A. wrote the standard and aggressively pushed it on the international group, privately calling the effort “a challenge in finesse.”
> “Eventually, N.S.A. became the sole editor,” the memo says.
Now, that may not have been an effective technique, as you point out it's so slow that no one is ever going to use it, and this vulnerability was discovered not long after it was published.
So, that's obviously not a vulnerability that they are actively exploiting. If they are actively exploiting a vulnerability that they introduced, it must be something else. It wasn't clear from the article that that's actually the case; it may be that the vulnerabilities they are exploiting are ones they've found, not introduced deliberately.
But it does appear to be an example of a vulnerability that they were able to get standardized, in the hopes of being able to exploit it. Until now, it has been only speculation that it was a deliberate vulnerability, but it now seems clear that it was.
Something this blatant does seem like a severe misstep, but perhaps what led to discovery of this case is the wide body of public knowledge on number theoretic crypto. The energy of the public sphere seems mostly devoted to studying problems with interesting mathematical structure. Symmetric crypto has been around a lot longer, and is sufficient for state security purposes, so one would expect the NSA to have a deep analytic understanding of it (hence the differential analysis olive branch). It's not hard to imagine that they'd have ways of creating trapdoor functions out of bit primitives, generating favorable numbers with plausibly-impartial explanations, etc.
I think you got it backwards... shouldn't you reduce hard problems down to the problem whose difficulty you're trying to understand?
http://www.reuters.com/article/2013/08/28/us-usa-security-fr...
Please clarify what you mean by "our".
Please clarify what you mean by "adversaries".
our, adversaries = America, !America
right?
If you are not the U.S. government, you are their adversary (even if you are a U.S. business or citizen).
* Open the PDF in a non-adobe reader such as Foxit and Sumatra w/ JavaScript disabled
* Both FF and Chromes internal PDF viewers ignore JS
* You can preview a PDF in Google drive
* Open the PDF in a sandboxed VM.
Guessing for your history of spammming 1 line pointless comments, you probably already know this.
Entire crypto schemes, from the RIPEMD hash to the specific parameter generation mechanism in DSA, are premised on the idea that USG-sponsored crypto concepts aren't inherently trustworthy. Similarly, all of Applied Cryptography was premised on the idea that NSA was decades ahead of commercial and academic crypto.
Of the revelations about NSA, this has to be the least revelatory (it's up/down there with the "revelation" that NSA employs teams of people whose job it is to break into Windows computers); it essentially restates something we were already supposed to have taken for granted.
That's not to say this isn't a fascinating story. It is; just keep it in context. Things to remember:
* You really want to know whether NSA is directly attacking cryptographic primitives or whether they're subverting endpoints. I think if you talk to cryptographers, you'll get a slight bias towards the belief that it's the latter: that there are implementation weaknesses at play here more than fundamental breaks in crypto.
* You want to keep in mind that breaks in cryptosystems represent new knowledge, and that the enterprise of breaking cryptosystems is an issue distinct from the public policy concern of where NSA is allowed to deploy those breaks.
* Bear in mind that in the legacy TLS security model, before things like pinning and TACK, NSA would only require a viable attack on a small subset of CAs to gain (along with pervasive network taps) massive capabilities. The payoff for these kinds of capabilities is radically degraded by the anti-surveillance mechanisms of modern browsers like Chrome, which is something you probably want to be thanking people like Adam Langley, Trevor Perrin, and Moxie Marlinspike for pushing so hard to implement.
Yet here we have proof that the NSA is truly in the business of sabotaging cryptosystems that are in general use. Those systems protect US interests as much as foreign interests, and now they are not trustworthy. Now I am left wondering -- PGP, for example, deviates from theoretical constructions of non-malleable encryption; might that have been the NSA's doing? What about the problems in various versions of TLS? Now it is hard to say what is an honest mistake and what is a deliberate effort to undermine computer security.
We are now past the point of not blaming on malice what we can attribute to stupidity, because we have evidence that there is actual malice on a grand scale. It is a truly sad day for this world...
Also, I do not think the NSA would have no interest at all in malleability. Suppose the NSA is trying to track messages sent through anonymous remailers (Type I, maybe because the target is using a nym server) and there is a "Max-Count: 1" header. An easy attack that exploits malleability would be the maul the message somewhere after the headers and see where a mauled messages exits the remailer network. This is probably possible with the NSA's resources and expertise, and the NSA is probably concerned about anonymity systems in general (and perhaps looking for ways to attack them).
My real point, though, is that we need to stop for a moment and re-evaluate pretty much all the cryptography standards we depend on. We really cannot say that these systems have not been deliberately sabotaged by the NSA, not with this latest revelation.
In fact Schneier himself is outraged to the point that he seems to be calling for a redesign of basic Internet protocols and governance in his article today, http://www.theguardian.com/commentisfree/2013/sep/05/governm...
Basically, what we thought were the rules of the game are not the rules of the game. We thought we knew where we stood with the NSA -- they would try to attack, we would try to defend. Now we need to be thinking of a much different set of rules, one in which the NSA is not just attacking ciphers but also deliberately sabotaging our defense, and doing so covertly. We cannot even assume that mistakes really are mistakes anymore -- they could be the NSA's doing.
Er...speak for yourself buddy. If you thought that you could get proper crypto security from a boxed software product then I'd like to offer you a fantastic deal on a bridge.
If the NSA said, "Our super smart brain trust figured out how to own your stuff with math five years ago ... ha ha!", I think we would be Totally Fine with that. Hats off to them for winning that game, but at least they played mostly fairly. (In theory.)
However, this is different. Winning the cryptanalyis game because they backdoored protocols, gained access to trusted entities' private keys, etc, just means that they are really good at the SPYING game, not at the cryptanalysis game, and somehow that just feels worse.
I mean, in an ideal world the only way to compromise my password would be to for a beautiful lady spy to seduce me and trick me into revealing it in a moment of passion, but in the meantime it's a safer bet that they'll just try and fish it out of my modem/router/ISP/etc.
Note to NSA: I'm actually happily married, so please don't send over any beautiful lady spies, which would be totally awkward.
They would be exposing all the people that rely in strong cryptography to major risks. Including people that have done nothing illegal and helped fund their research.
And more importantly, they shouldn't be reading our emails to being with, independently of them being encrypted or not. That was never the deal, no democratic process ever gave them the right.
I disagree. Certainly they'll be doing that too, but breaking crypto is hazardous to the populace independently of how it's broken, right?
Either way from NSA's perspective they are fighting a war, with terrorism, with other nation's crypto efforts, etc. In that context there are very few "unfair" ways to fight. And indeed, the U.S. has done something like this to a certain Soviet pipeline, as I recall.
Besides, this at least leaves open the possibility of like-minded people to maintain countermeasures. If crypto is broken in general then we're all naked. If weak implementations are weak then we would need to be fixing those anyways.
I just wish I knew which one it is we're looking at.
[1] http://www.zdnet.com/german-government-refutes-windows-backd...
Taking for granted that the NSA actually backdoored TPM's (which I can assert professionally is very unlikely, but I don't expect anyone to take my word for it), they are far from "crown jewels".
The only "meaningful" large scale use of TPMs is actually within the department of defense. It's been a pretty uphill battle getting them deployed and used in other environments.
Yes, we had to assume it was happening and we'd have been foolish not to. But to have it laid out in no uncertain terms, is somehow quite devastating.
Do you think it's easier to discover attacks on AES or court order CA's?
You need to trust your OS, Chrome cryptography implementation, AES and RSA, and the end point, its OS and its possible role as a mute puppet, oh and don't forget everyones hardware!.
Users running extensions that use things like EFF's SSL Observatory (SSL Everywhere has an option to report to that) will cause those NSA-generated certs to show up, and someone will get suspicious eventually. The only reports I've seen recently on that front were things like middle eastern users sending in samples of MITM certs. I'm not saying the NSA can't do it, but what evidence is there that the NSA has done MITM on SSL traffic? For all we know, couldn't the MITM ssl certs in the mideast be an NSA false flag op?
The allegations of widespread hardware backdoors are ludicrous. The backdoors would eventually become public, requiring the replacement of billions of dollars worth of equipment, and the several times that cost in audits. Only a spymaster with a suicidal death wish would chain his career to that. More likely is that people are misinterpreting backdoors in a few chosen endpoints, which we can take as standard operating procedure.
"By this year, the Sigint Enabling Project had found ways inside some of the encryption chips that scramble information for businesses and governments, either by working with chipmakers to insert back doors..."
A bug deliberately introduced in an AES instruction, or in general purpose instructions that detects crypto operations and leaks information somehow, is much, much harder to implement and hide than a pseudo-random number generator that passes all tests that you apply to it, but produces predictable output for someone who knows some secret key.
http://comments.gmane.org/gmane.comp.security.cryptography.r...
> It's worth noting that the maintainer of record (me) for the Linux RNG quit the project about two years ago precisely because Linus decided to include a patch from Intel to allow their unauditable RdRand to bypass the entropy pool over my strenuous objections.
> From a quick skim of current sources, much of that has recently been rolled back (/dev/random, notably) but kernel-internal entropy users like sequence numbers and address-space randomization appear to still be exposed to raw RdRand output.
Ted Ts'o later reverted this, separating out Intel's hardware random number generation into a separate function that could be used to seed the entropy pool but wouldn't be trusted directly as the main kernel source of random numbers:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.g...
If I had to guess what happened, some intel people pushed this as a feature, probably pushing it via one of the x86 git trees, and Linus either (a) didn't notice, or (b) didn't understand the implications, and then Matt quit in a huff --- by just stopping to do work, and not even updating the entry in the MAINTAINERS file. (That didn't happen until I took over the random driver again.)
http://thread.gmane.org/gmane.linux.kernel/1173350/focus=117...
It doesn't really look like he had NAKed it on paranoia grounds, but more on design grounds; others brought up the paranoia arguments. You were even involved in that thread, so you should have seen his stepping down, although he didn't submit a patch to MAINTAINERS.
Regardless, I'm glad that paranoia did eventually prevail, despite Linus's original strong objections.
---
"The NSA's codeword for its decryption program, Bullrun, is taken from a major battle of the American civil war. Its British counterpart, Edgehill"
"N.S.A. spends more than $250 million a year on its Sigint Enabling Project, which “actively engages the U.S. and foreign IT industries to covertly influence and/or overtly leverage their commercial products’ designs” to make them “exploitable.”"
-- http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryp...
--
Bull Mountain, is Intel's code name for both the RdRand instruction and the underlying random number generator (RNG) hardware implementation.
--
bull [mountain|hill] [intel|processor]
http://www.googlewhack.com/ https://xkcd.com/936/ http://subrabbit.wordpress.com/2011/08/26/how-much-entropy-i...
did Linus ever comment on the roll-back ?
That's the money quote there- the NSA hasn't cracked encryption. They've just put back doors in.
And we can't even be that angry at the (e.g.) Microsoft execs that authorise the back doors- they potentially face jail time if they resist NSA requests. All the while presumably not able to talk about the requests publicly.
EDIT: and the really fun part - did you know the former head of the NSA serves on the board of directors for Motorola Solutions? http://en.wikipedia.org/wiki/Michael_Hayden_(general)
From the article: "Intelligence officials asked The Times and ProPublica not to publish this article, saying that it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read."
Also: “Properly implemented strong crypto systems are one of the few things that you can rely on,” - Snowden
I would assume that because Snowden used Lavabit & they shut down that the NSA took issue with how secure Lavabit actually was.
Do you know who your covert agents are?
Go ahead, call the cops and media. I hope you have a ton of money on hand and some jewelry stashed away in various locations before you do so.
Undercover agents at all levels of law enforcement commit apparently criminal acts every day, with no fear of prosecution. There's no reason for this to be any different.
It's not like they've just gotten secret keys. They've specifically gotten chip manufacturers to add backdoors to hardware, as well as significantly influenced actual cryptography standards themselves:
> "The N.S.A. wrote the standard and aggressively pushed it on the international group, privately calling the effort “a challenge in finesse.”
> “Eventually, N.S.A. became the sole editor,” the memo says.
Could someone add a backdoor to git that hides backdoors from showing up in git? Could gcc be backdoored to add backdoors to arbitrary software? How likely is it that NSA has a few zero-days lying around they could use to hack into the servers that host git or gcc or any other tool you rely on? What if they had agents among the committers and maintainers of these projects?
Security against a well-armed, well-funded, well-organized, secretive adversary is hard.
You can't rely on a backdoor looking like this:
if(!strcmp(username, "secretagentman")) { … }Perhaps I lack the wherewithal to identify security vulnerabilities in deployed code, but there's a good chance that there are others who are able to spot said vulns.
Nobody seems to know if the NSA actually has practical attacks against primitives like AES or SHA-2. We do know for sure that they go after higher level implementation flaws. The more complex your encryption scheme is, the more likely it is that you'll introduce a grave flaw. It only takes one.
I'd suggest that our best bet already exists: NaCl[1]. It's by Daniel Fucking Bernstein, so the implementation is as flawless as it gets. Better yet, it doesn't use a single US-approved primitive (not even the NIST curves Schneier was warning against in his Guardian piece).
Funnily, before the leaks Bernstein's use of all his own primitives was seen as a bit wacky and concerning, but now it seems almost sensible.
[1]: http://nacl.cr.yp.to
The reason we don't do that is, of course, CPU cost.
working with chipmakers to insert back doors
So you're going to need to make your own chips, too.
Spying on your own citizens codenamed as civil war. How nice.
>Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among them, but he nonetheless managed to obtain dozens of classified documents referring to the program’s capabilities, methods and sources.
Once again, the people spying on everyone suck at keeping their own secrets. How many others have taken the information with them and sold it off instead of leaking it?
>In one case, after the government learned that a foreign intelligence target had ordered new computer hardware, the American manufacturer agreed to insert a back door into the product before it was shipped,
If you're a non-US company how can you keep trusting US IT vendors? I wouldn't want to be one of these companies' reps at Airbus for example.
Nowhere in the article does it state that these methods can be used against US persons separate from other protections against surveillance on US persons, nor does it give the impression that this is special to US persons:
The agency’s success in defeating many of the privacy protections offered by encryption does not change the rules that prohibit the deliberate targeting of Americans’ e-mails or phone calls without a warrant.
Let's keep in mind the fact that an intelligence agency is built to gather intelligence on other governments/organizations and that often involves breaking other jurisdiction's rules.
Rules which are enforced internally, with an inspector general chosen by the same executive branch that commands the NSA's leadership. Yes, we can really rely on these rules when push comes to shove.
The previous leaks show these rules to not be particularly effective. For me and most of the world that distinction is irrelevant anyway. The position of the US government is that it can order its tech companies, with whom I have contractual/financial relationships to give them all my data with no warrant.
Welcome to September, where the NSA can keep any data it accidentally collected about US persons for five years if its plaintext. And if that data is encrypted, it can keep data on US persons forever.
> The NSA describes strong decryption programs as the "price of admission for the US to maintain unrestricted access to and use of cyberspace".
What does that even mean? That statement is at the same time paranoid, arrogant, and subtly threatening. It's as if to say that without the ability to decrypt interesting traffic, the NSA would be forced to take stronger measures to curtail internet traffic.
So most states are slowly moving towards implementing their own little firewalls. The only notable absence? The US. Despite occasional campaigns from religious nutters of various sizes and shapes and continuous pressures from commercial telcos, subsequent US administrations repeatedly affirmed that fundamental Net freedoms would not be curtailed.
This document states that such a position is not coming from idealism or even commercial convenience: it's a way to persuade the rest of the world to do business over networks and protocols that the NSA can tap at will. Should this capability be forcefully contained, there wouldn't be a political incentive to keep the Net flowing freely through US routers.
It's a perfectly reasonable and plausible position, and that's why it's so terrifying.
These laws were included in the German constitution following the "denazification" of Germany by the USA, where Nazi symbols were banned and literature burned.
The laws against Holocaust denial and Nazi symbols were pretty much forced by the USA. It's extremely ironic how often they're mentioned as an illustration of the USA's devotion to free speech.
So why doesn't German remove the laws now that they've served their wartime reconstruction purpose?
And that is why they were put in, the same reason that even in the U.S. free speech was curtailed in many areas during the American Civil War.
In many government documents, use of the name "U.S." is shorthand for the U.S. national government, not the entirety of the nation. Sometimes it is even shorthand for the particular agency that authored the document (since, in theory, they represent and act on behalf of the entire nation).
So what this internal NSA document most likely means by "unrestricted access and use" is the NSA's unrestricted access to, and use of, whatever data they want.
Think of it like a budget justification (since that is the purpose of at least half of all internal government reports). "You need to keep spending a lot of money on this program if you want us to keep getting all that data you like so much."
The statement implies that in the absence of "strong decryption programs" then there would be only restricted access to and use of cyberspace. I'm sure the intelligence leadership in the US Government look at China's Great Firewall with both trepidation and admiration.
Would that it were true! It would make sense. This makes no damn sense. Just recently I would have ruled out huge conspiracies as implausible because they inevitably leak (roll save against ethics how many times?). The joke's on me, folks. The NSA has no sense. And the conspiracy leaked.
So now every single decision that was taken with help from the NSA (SELinux, TLS, elliptic curves, etc) needs unpicking and running by a cryptographer who isn't a shill. What a damn drag. And meanwhile, the aftershocks will run for years trashing trust in the networked economy.
Fuckin' brilliant, NSA. You screwed the pooch. You accidentally the whole internet.
So now every single decision that was taken with help
from the NSA (SELinux, TLS, elliptic curves, etc) needs
unpicking and running by a cryptographer who isn't a
shill.
Cryptographers have already been looking very carefully at everything that comes out of the NSA. Lots of security researchers, in and out of the US, would love to find NSA-introduced flaws.Haha, nicely put. Note too that sooo many "roll save against temptation" must happen to avoid abuses of the NSA capabilities.
As someone who has been following the NSA and government monitoring of online activity for close to 15 years the Snowden leaks just keep taking the wind out of me. It's like everything that we thought might be going on was actually going on. When Theo de Raadt wrote the above mail I, like many at the time, assumed it was tinfoil hat territory. I was clearly wrong.
[1] Those claims made by Greg are completely untrue. I ran the professional services group for that company and will happily attest to whomever asks that at no time did we insert a backdoor (or anything that could even be construed as such) into IPSEC.
Somehow I doubt if you did that you could tell us. You might even have to lie to be able to comment on that letter at all.
When all the hullabaloo around the alleged IPSEC backdoor occurred, it was frustrating to not be able to be as open about it as I wanted (not because of any government/security issues, but because at the time I still worked for the company and we were advised against talking about it).
You are free to assume that even right now as I type this, a shadowy figure in an ill-fitting Brooks Brothers suit is standing over me dictating my responses, and then chastising me for spending my time on HackerNews.
I'm hoping open development models(open source, peer production, peer review) end up providing the correct institutional incentives for us to innovate away the mistrust.
To misquote Linus: “given enough eyeballs, all backdoors are shallow.”
I'm only joking, but the same argument is used against other technologies that governments seek to control/dominate.
Edit: Skipjack was 80-bits I think. It was used in Clipper Phones: http://en.wikipedia.org/wiki/Skipjack_(cipher)
Edit: Devil's advocate.
:-/
I just think that a politician moved by the desire to do something could construe non-backdoored encryption as something that "helps the enemy."
They occupy exactly opposite quadrants on the useful/dangerous axis.
There is a cost to having a society saturated with firearms. The vivid, individualistic, but rarely used benefit of personal defence has to be weighed against the boring, common case of excessive violence and escalation due to access to and glamorization of firearms.
Wow.... this really puts all the furor over Huawei contracts in the US in context.
By introducing such back doors, the N.S.A. has
surreptitiously accomplished what it had failed
to do in the open. Two decades ago, officials
grew concerned about the spread of strong
encryption software like Pretty Good Privacy,
or P.G.P., designed by a programmer named Phil
Zimmermann. The Clinton administration fought
back by proposing the Clipper Chip, which
would have effectively neutered digital
encryption by ensuring that the N.S.A. always
had the key.
Link to Paragraph w/ highlighting: http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet...Should I bother to read up on PGP?
This is mostly a confirmation of what has been supposed: No magic, mostly bribed and coerced cooperation from the people who should be keeping our communications secure.
And while it doesn't do anything for the credibility of US-based companies, N.B.: "hardware and software developers around the world."
If you are a foreign government, hostile or friendly, I don't see much of a case to made for "Naw, they wouldn't..." They would, they probably can, and the probably already did.
If you are a consumer, the main problem is the creepiness factor. Who wants to use incrementally more technology if along with it you get incrementally more surveillance?
These government agencies are obviously dug much deeper in private industry than many expected so I wouldn't put it past them
This is why customer-company relationships and company integrity is becoming increasingly important, and frankly not many US companies are doing well in that regard.
http://www.techspot.com/news/41643-intels-sandy-bridge-proce...
And if this were really an issue, couldn't you just use 4096-bit RSA (unless they have managed to surreptitiously insert a backdoor in it)?
> Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency. The N.S.A. wrote the standard and aggressively pushed it on the international group, privately calling the effort “a challenge in finesse.”
> N.S.A. documents show that the agency maintains an internal database of encryption keys for specific commercial products, called a Key Provisioning Service, which can automatically decode many messages. If the necessary key is not in the collection, a request goes to the separate Key Recovery Service, which tries to obtain it.
1) Site sends public key certificate to browser. 2) Browser verifies certificate against in-browser store. 3) Browser extracts public key from certificate. 4) Browser generates symmetric/private key. 5) Browser encrypts that symmetric key with the site's public key. 6) Browser sends encrypted symmetric key to site. 7) Site decrypts symmetric key with its private key (the one associated with its public key certificate) 8) Site and browser encrypt and decrypt data using the privately shared symmetric key.
If I break the public key algorithm(s) used in SSL, I break all of that. But we think that's tough (as in NP hard).
If I break SSL itself (find flaws in negotiation, etc.) I might be able to break all of that. That's been done a few times (SSL v1.0 is garbage; v2.0 is borked; v3.0 a little broken; only TLS 1.2 is borkless, so far. As far as we know.
If I break the symmetric algorithm(s), then I can get at the data without breaking SSL itself. But we think that's tough, too. As far as we know.
If any of the software used in any of the above is borked, then usable attack vectors may be exist. Or not. We don't know until we find them.
It's a complex box of moving parts with many potential attack vectors, many potential vulnerabilities, etc.
Who really knows if the NSA might have found a multi-vector, multi-vulnerability attack that allows them to get at a lot of encrypted data without having broken all of any one of those things.
It's purest speculation until someone with a sufficient clearance and sufficient need-to-know decides to speak out, and even then it would remain unconfirmed.
So man-in-the-middle attacks are certainly within their capability and fairly hard to detect. As to whether the NSA can passively intercept and decrypt SSL traffic, I don't know, but they may not need to.
People assume CAs should be trusted but it's a huge game of chicken: If the NSA can't break SSL, you have to assume that either SSL is opaque to them, which these revelations seem to contradict, or they have corrupted the CAs.
I don't think this would be particulary hard either. For IE, the NSA can just get MSFT to do it. For Firefox, they can compile from source, and for Chrome, well, they can probably compile from source too, because they probably have access to the build source of Chrome, with or without GOOG mgmt knowledge.
Can anyone come up with a (technical) reason the NSA could not be doing this?
It is not somuch the protocol what matters but the implementations.
Imagine they "rig" all those beatiful hardware RNG. Could you tell the difference?
Are you sure renowned developer X van Y is not an NSA mole?
But it is certainly feasible that if they manage to find cracks in popular-but-old communications protocols that they are able to automatically decrypt them, or use prior key recovery successes to bootstrap fast attacks on new communications from the same host.
What would be interesting is if NSA's own "Suite B" crypto recommendations are susceptible to these risks, as that would potentially represent a rather significant break in the U.S.'s own COMSEC, and COMSEC is one of the things NSA is very specifically tasked with ensuring are safe with no backdoors for anyone to jump through.
The issue to me has always been how and what data they access and store, and how it is used.
I draw the line at collecting everything without specific warrants, regardless of what they do with it, against their charter and the Constitution.
I draw the line at hardware backdoors for equipment that I buy, and insertion of vulnerabilities into encryption standards that I take advantage of. Or I guess I should say that take advantage of me.
Their "breaking" of encryption is a combination of purposefully introducing vulnerabilities into standards, surreptitiously altering software and hardware to give the NSA a backdoor, hacking into private systems and stealing keys, etc etc.
I'm cool with an NSA super computer trying to brute force my VPN traffic to YouTube, I'm not cool with the NSA planting an engineer at a chip fab and changing designs to add a backdoor (a backdoor that could also be exploited by other actors).
1. They obviously can't keep their own secrets, so it's unlikely that they will do any better than keeping yours. Eventually, your data will leak out to non-NSA people.
2. By adding backdoors, they weaken the encryption. This implies that anyone with sufficient skill who goes looking for backdoors may be able to exploit the hole that the NSA opened up. This is a big deal, especially if you have secrets that you need to protect.
When the combined '5 eyes' come out and ban Lenovo / Huawei from being used on any of their secure networks, because of fears of back doors [1], one has to imagine that the same is true of themselves.
The hardware is most likely backdoored as well as firmware, the OS and installed software. I would not trust anything, even open source, because to be perfectly honest, there a very few people who really are smart enough to understand the in depth cryptographic requirements. If there are people, then they probably already work for the NSA or GCHQ.
If you want to plan a terrorist attack or become a politician or business leader who does not want to be blackmailed, don't do anything on the internet apart from share pictures of cute cats.
My advice to any terrorists is to go dark. Speak in private. Write it down pass the note and then burn it. Use old methods like book ciphers. Touch and electronic device and they have you.
Legal note: Of course I'm not advocating 'advising' terrorists, well only the good ones, you know those ones that we call 'freedom fighters'. The ones western governments like to back when it suits their purposes.
[1] http://www.infosecurity-magazine.com/view/33679/lenovo-compu...
If it turns out one way functions actually don't exist, I'll give in and learn to love big brother. Withstanding that, I'll continue considering communications freedom (and all that it implies) as our manifest right and view these types of breaks as implementation errors.
What this sort of article does to me (unlike you, I make no claims to know what the article was 'meant' to do, other than report the news) is make it clear that we need to push back against the NSA _politically_ to win, make what they are doing illegal, change the gag order laws, etc. We aren't going to beat them technologically, but (for those of in the U.S.), it's theoretically a democracy, we can tell them to stop.
I've seen that argument made before, several times, in essays linked to on HN. It's a political problem, not a tech problem, that the NSA can force corporations to install back doors and give the NSA the keys.
You're signing up for a losing game. The myth of Democracy (tm) is another layer of control over individuals.
1. Most people will never have a problem with what the NSA is doing. They support the NSA's goals (tautology, since as you've mentioned, it is responsible to the majority), and if its methods end up causing harm to enough people, they will simply be adjusted to reduce aggregate harm (not to rule out any possible harm). The feedback loop of democracy works on specific actualities, not hypothetical corner cases.
2. The most memetically fit ideas are the simplest ones that elicit the strongest feelings (see: bikeshedding). Outrage peddlers swamp the political reception bandwidth with lowest common denominator controversy - usually judgments on other's lifestyles.
3. Even if there is a widespread preference to reduce the scope of the NSA, the people simply do not have the transmit bandwidth to make this preference clearly known. And they are easily led into squandering their input on the aforementioned manufactured controversy.
4. Elected figures don't actually run the government, the entrenched bureaucracy does at an imperceptible glacial pace. The elected figures run interference by making the majority believe they voted for this shit.
It's a MITM solution that injects fake certificates, i.e. nothing groundbreaking and equivalent to compromised/corrupt CAs (which, as we know, exist and are able and willing to hand out fake intermediate certs etc. to rogue entities). The Whole CA ecosystem is broken and basically snake oil and pretty much everyone knows it.
I predict that in the next 5 to 10 years, many organizations across all industry sectors will drop/reject encrypted packets (SSL, SSH, SFTP, etc) that they cannot decrypt. And the reason they'll give is that it makes them more secure.
The concern I have (as a security technologist) is that most people who use encryption are not bad, however everyone is punished and every packet must now be inspected because a few people use encryption to do bad things. So one day soon, I'm afraid that anyone who uses encryption will be suspect simply because they do and the stronger the encryption, then the more suspect they'll be.
Will it become illegal to do encryption research or use OpenPGP unless you agree to escrow your private key or will everyone be forced to use very weak ciphers? In today's climate (encryption is evil), I see all of these things as very real possibilities.
You can turn it off... but how many admins do? If you want an example of behavior which is completely plausibly-deniable, but which immensely reduces internet security, this is a good one.
The problem is that the NSA apparently used those capabilities on basically everyone, millions of innocent Americans whose activities should be of no interest to intelligence agencies, not just the handful of genuine spooks and terrorists our intelligence agencies are supposed to protect us from. (To international people: Cosmically speaking, you're not less important than we are, but the NSA's first responsibility is to protect and serve the USA, so them spying on innocent Americans is at least as bad as them spying on innocent foreigners.)
And it has been shown that the NSA provided information to ordinary criminal investigations with no links to terrorism or foreign intelligence, having police say "it's a lucky traffic stop," where the government actually knew the drugs were in that car ahead of time due to a decrypted phone call. This makes a mockery of the Fourth Amendment because, when prosecutors/police lie to the courts about the origin of evidence, the courts cannot properly answer the question of whether their methods of gathering evidence violate the defendant's Constitutional protection against unreasonable search and seizure.
In short, this is coming out -- which, as the article said, will weaken those capabilities -- because the NSA went too far outside their mission scope. If they hadn't done those two things, I'd be willing to bet Snowden wouldn't have leaked this data.
The NSA could have made more of an effort to harden American business and infrastructure to attack. They could have spent the money on developing intelligence sources who actually work for opponents instead of US telcos. They could have fixed zero day exploits.
We are rapidly approach a time where oponents will be able to attack completely annonymously. American infrastructure or buisness could be damanaged and know one ever know who or why. If that happens cold war tactics will seem hopelessly naive.
This is the part that truly disgusts me.
Is this the first time we've seen a 5-digit number to describe the number of documents Snowden has? Of course, these are just the ones used for this story...
RSA has issues but as of yet hasn't yielded entirely to cryptanalysis.
As the article says, it's easier to attack the system and try to get the plaintext, or coerce you into giving up your key through legal means.
Edit: adding a link to Wikipedia's article on post-quantum crypto, it's a good place to start understanding how to answer these type of questions:
No, because the difficulty of breaking RSA keys doesn't scale in the same way as symmetric encryption. Integer factorisation is much easier than a brute force search of the keyspace. A 1024-bit RSA key is believed to be roughly equivalent to an 80-bit symmetric key. A 3072 bit key is about as hard to brute force as an 128-bit symmetric key.
(Source: http://www.keylength.com/en/4/ )
In any case, you can choose a public key exponent large enough to still make it a hard problem to crack in a reasonable amount of time. Barring some huge vulnerability in RSA that hasn't been discovered in 30 years of public scrutiny, of course.
And while there are limits to the applicability of Grover's algorithm, you're correct that it effectively cuts the number of bits in any cryptosystem it applies to in half. Which, to my nonexpert eyes, looks to be most of them.
Shor's algorithm is very tasty, but when the real world demonstrations at top research facilities are saying, "yes, we factored 21 into 7x3, but WITH ENTANGLEMENT"[1] it makes me think that scaling to RSA-size prime factors is still a good way off.
Listen, the US government is powerful, but building a full scale quantum crypto decoder ring in complete secrecy _decades_ ahead of everyone else? I just don't think so. Maybe I'm a sheep for not wanting to believe the government so powerful and corrupt, but the whole thing sounds like a tin foil fantasy.
I don't doubt they would if they could, though. And they've done as much as they can with present day tech: supercomputers, mass data collection, penetration of target systems, exploiting SSL's many weaknesses, tapping undersea lines, and legally strong-arming perceived threats into giving up their encryption keys. I just don't think we need to get science fiction involved.
[1] http://www.nature.com/nphoton/journal/vaop/ncurrent/full/nph...
Only a small cadre of trusted contractors were allowed to join Bullrun. It does not appear that Mr. Snowden was among them, but he nonetheless managed to obtain dozens of classified documents referring to the program’s capabilities, methods and sources.
Who knows what other documents other internal hackers could have stolen?
This paragraph interests me the most.
For one, it's clear that their goal is opportunistic decryption; that is, decrypting everything and being able to search through it, rather than targeting known endpoints. This is an important point that a lot of people miss when debating cryptography. While it's fairly likely that the government can find ways to access any communication they want in a targeted manner, as they have so many means to do so (hacking the endpoints, physically breaking in and performing an evil maid attack, etc), widespread encryption is generally good enough to prevent opportunistic data gathering.
The other point I note is that they only mention "web chats and phone calls" in their breakthrough. It doesn't sound like the breakthrough is something that works well for arbitrary SSL connections. The main link I can see between web chats and phone calls is that they are long lived connections, with bursty traffic (HTTP or email protocols, on the other hand, tend to stream a lot of data at once, and then the connection is closed). I'm wondering if there's some kind of traffic or timing analysis vulnerability that they've discovered.
Also interesting is this quote from the Guardian article:
> To help secure an insider advantage, GCHQ also established a Humint Operations Team (HOT). Humint, short for "human intelligence" refers to information gleaned directly from sources or undercover agents. > > This GCHQ team was, according to an internal document, "responsible for identifying, recruiting and running covert agents in the global telecommunications industry."
Various technology companies have been adamant in maintaining that they haven't been been giving the NSA direct access to their data. However, with HUMINT programs like this, you always have to wonder if the NSA has hired anyone within such companies to put backdoors into their systems, without authorization by the company. Obviously, they'd have to be subtle about it (it's hard to install new gigabit fiber pipes to siphon off the data without anyone noticing), but just setting up a way for the NSA to covertly run queries, disguised as some other type of job that would normally run on the system, would probably not be too hard to do.
(it's hard to install new gigabit fiber pipes to siphon
off the data without anyone noticing)
If you have access to manufacturers that can put in back doors for you, I reckon you don't even need your mole to install stuff for you. Instead you just ask your mole to inform you want is going to be installed and then make sure that the company gets backdoored systems when hardware is installed/upgraded/replaced.I'm wondering is datacenter monitoring utilities like the stuff Boundary[0] is working on could be used to identify anomalies in how network hardware is behaving versus how it should be behaving. I know that in my conversations with cliff, they are trying to get their monitoring solution to the point where they can visualize "the circulatory system" of a data system with the goal of spotting things that don't look quite right.
I now want viable open source web-of-trust encryption for the web as soon as possible.
If one government agency has your data then the rest of them do too.
"Among the specific accomplishments for 2013, the NSA expects the program to obtain access to "data flowing through a hub for a major communications provider" and to a "major internet peer-to-peer voice and text communications system". "
That second one is hard to read other than 'skype'.
Why is this not just the same as the other clever ways the smart NSA listens in things (not that I'd like but there's something more)?
Well, the thing about backdoors is they get installed on the outside of everyone's software/chips/machines and then ... someone else, someone with less to loose than the NSA, starts to use them for more crudely nefarious reasons, either criminal activity or spying by other nations.
All of this bears resemblance to the former USSR. Once bureaucracy claimed unlimited political power, the next step was for the "mafiya" to take advantage of the universal silence and surveillance.
That sounds a lot like "the division to provide security advice was providing advice that would make it easier for the NSA to break".
Page 4 of the article was the most interesting.
https://factorable.net/weakkeys12.conference.pdf
https://www.usenix.org/system/files/conference/usenixsecurit...
Is there anything unusual about the cipher options offered by NSA/GCHQ servers? Or any recent changes at The NYTimes or Guardian's servers.
Which isn't to say that backdoors inserted into the binary that aren't in the published source are impossible, only that they need something more subtle than the crude/easily-detectable 'merge backdoor, compile, ship'. Something like a Ken Thompson 'Trusting Trust'[2]-style attack. (Though there are ways of at least having a good chance of detecting even those - see [3]).
(More likely, IMHO, are just deliberately-introduced, plausibly-deniable bugs in the source - think [4]. Yeah, they might be found & reported by an outsider reviewing the source, in which case you thank them, fix it, and introduce another couple somewhere else next week).
[1] http://blogs.kde.org/2013/06/19/really-source-code-software
[2] http://cm.bell-labs.com/who/ken/trust.html
I disagree with this characterization. Surrendering to the NSA would be Google/Facebook/Microsoft's approach of unconditional cooperation. Lavabit's refusal to work with the NSA -- even though apparently the only alternative was shutting down their business or going to jail -- is more along the lines of a scorched earth retreat (destroying your own stuff when you can't hold the line).
I wonder which computer viruses belong to the NSA.
And maybe even ones you have compiled yourself "from scratch":
Wonder if it is referring to the Dual_EC_DRBG RNG.
So I'd say yes, it sounds like that's what they're talking about.
Speaking of which, I'm really quite frustrated how many of these recent reports about the NSA elide the technical details. You have to read between the lines to figure out what's really going on, what weaknesses there really are.
As a matter of security, it would be better to know specifically what vulnerabilities there really are. Merely the announcement of vulnerabilities can allow a dedicated black-hat to find and exploit it; but someone who's trying to secure their system, and isn't following cryptography incredibly closely, won't know what they need to do or change to make their systems more secure against these types of attacks.
There's a reason that the security community advocates for full disclosure (or at least responsible disclosure, if it's possible to selectively disclose to a few vendors so they can do a coordinated release that fixes the vulnerability before it becomes public), in which you completely disclose a vulnerability so people aren't left guessing about it.
Are you? Well please sign up to work for the NSA, learn the technical details, then go public with them. The reason that the NYTimes isn't publishing the technical details is because they DON'T KNOW THEM. (They might not publish them if they did.) They don't know them because Edward Snowden was a system administrator not a cryptography expert and he's releasing memos about the process.
> "Intelligence officials asked The Times and ProPublica not to publish this article, saying that it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read. The news organizations removed some specific facts but decided to publish the article because of the value of a public debate about government actions that weaken the most powerful tools for protecting the privacy of Americans and others."
NYT, the Guardian, etc do have access to these details, but chose not to publish them.
If this story leaves you confused, join the club. I don't understand why the NSA was so insistent about including Dual_EC_DRBG in the standard. It makes no sense as a trap door: It's public, and rather obvious. It makes no sense from an engineering perspective: It's too slow for anyone to willingly use it. And it makes no sense from a backwards-compatibility perspective: Swapping one random-number generator for another is easy.
There really should be no doubt at all that there is corporate espionage and insider trading going on. On one hand, if the NSA approached this with giving helpful 'heads up' when a US-based multinational's overseas factory might be planning to strike, or provide their foreign competitors' private dealings etc etc, they could win brownie points.
But you know it won't stop with screwing around with overseas business. If they are not already, you can bet that internal insider information is going to be traded and sold. You can't trust a rogue, so as long as it is not dismantled they are indirectly if not directly a hostile threat to your ability to conduct business.
The entire thing seems hand-wavy.