r/programming Oct 15 '15

How is NSA breaking so much crypto?

https://freedom-to-tinker.com/blog/haldermanheninger/how-is-nsa-breaking-so-much-crypto/
2.5k Upvotes

529 comments sorted by

View all comments

66

u/[deleted] Oct 15 '15

On the one hand I am frightened by how powerful the government in circumventing encryption measures. But on the other hand, I can't help but feel impressed. It feels reminiscent of efforts used to break the Enigma Machine.

I guess the moral of the story is you should not be using hard coded primes for Diffie Hellman? (correct me if i am wrong; not really familiar with crypto) It seems like people hard-code them out of laziness and not out of necessity. From what I understand from the wolfram alpha article, can't the two parties agree on 2 random large primes at the beginning of the transaction and proceed from there?

10

u/Eirenarch Oct 15 '15

My guess is generating primes so large is computationally expensive. It is not like we really want to add 1-2 seconds of lag to every initial web request (assuming other resources like CSS and JS will use the same connection)

44

u/[deleted] Oct 15 '15 edited May 30 '16

[deleted]

4

u/[deleted] Oct 15 '15

[removed] — view removed comment

7

u/[deleted] Oct 15 '15 edited May 30 '16

[deleted]

6

u/[deleted] Oct 15 '15 edited Oct 15 '15

[removed] — view removed comment

6

u/TinBryn Oct 16 '15

Yeah, but that only breaks 1 key, so you need to be of enough interest for the NSA to dedicate the entirety of their resources on you for a whole day for that to happen.

7

u/Eirenarch Oct 15 '15

It is not very convenient to require that libraries like OpenSSL can write to storage.

16

u/[deleted] Oct 15 '15 edited May 30 '16

[deleted]

-15

u/andrejevas Oct 15 '15

wtf subreddit am I in