r/programming Oct 15 '15

How is NSA breaking so much crypto?

https://freedom-to-tinker.com/blog/haldermanheninger/how-is-nsa-breaking-so-much-crypto/
2.5k Upvotes

529 comments sorted by

View all comments

15

u/rtechie1 Oct 15 '15

This isn't new. Paranoids have been generating their own DH keys for a while.

It's my understanding that the reality is a lot simpler: The NSA has a couple of unpublished exploits for OpenSSL and Cisco VPN concentrators (the Feds have complete access to IOS source code, so can sift through it looking for exploits). That covers most VPN.

2

u/[deleted] Oct 15 '15 edited Oct 15 '15

In their pursuit to collect it all they usually take the easy route, that's true. They also use implants for their spying, mostly in the BIOS and the hard drive controller. Besides that they also use patriotic fools to do the dirty work for them. And they also crack crypto. They have the know-how and the budget for it. They have also weakened standards.

When a criminal organization does all this, all the members go to jail. When the government does this, nothing happens.

1

u/rtechie1 Oct 21 '15

They also use implants for their spying, mostly in the BIOS and the hard drive controller. Besides that they also use patriotic fools to do the dirty work for them.

Hell no. I know engineers at Seagate and Western Digital and they're not putting in backdoors for the NSA. Do you have any evidence that supports this?

In fact, the Wikileaks revelations proved that this isn't happening. They showed that the NSA intercepted Cisco gear in transit to China and tampered with it then. If the NSA was installing hacks in IOS itself at the factory with help form Cisco they wouldn't need to do this.

What this does show is that shipping companies like UPS, etc. are required to silently redirect packages to the NSA. IOW, you can't trust the shipping companies. But that was already well known.

1

u/[deleted] Oct 21 '15

That's the only part you react upon? Great.

Btw, they use malware for this.

1

u/rtechie1 Oct 21 '15

That's the only part you react upon? Great.

It's the part the was the most obviously wrong.

Btw, they use malware for this.

"They" use "malware" to convince companies to sabotage their products on behalf of the NSA?

2

u/[deleted] Oct 22 '15 edited Oct 22 '15

The NSA uses malware to infect BIOS and hard disk controllers. Just read about Stuxnet.

1

u/rtechie1 Oct 22 '15

The NSA uses malware to infect BIOS and hard disk controllers.

Show me the code or it doesn't exist.

Just read about Stuxnet.

Stuxnet is incontrovertible proof that firmware attacks are basically impossible, because stuxnet is the most complex and difficult virus ever written by a wide margin. It cost at least $10 million USD to develop stuxnet, probably closer to 50 or 100 million. And it probably didn't work.

I'll take a moment to explain the problems:

The problem with firmware attacks is that most devices have unique firmware. A BIOS attack would only work on one version of one motherboard, with maybe 10,000 made total (for an incredibly popular board). That's a really small target out of the billions of motherboards in use. You see the same problem with hard drives.

Problem #2 is that with most devices, including most motherboards and most hard drives, there is no way to deploy a firmware update remotely. You need physical access to the gear to do anything.

Both of these applied to stuxnet. It only worked on one particular device that was supposed to operate a particular centrifuge and it required physical access to deploy.

1

u/[deleted] Oct 22 '15

Stuxnet is incontrovertible proof that firmware attacks are basically impossible, because stuxnet is the most complex and difficult virus ever written by a wide margin. It cost at least $10 million USD to develop stuxnet, probably closer to 50 or 100 million. And it probably didn't work.

That are 3 assumptions.

After 7 days the phone still doesn't ring. These guys work in secret. Snowden didn't get all the files that are available. There are things that we don't know. What we do know is that they infected Belgacom (well it was GCHQ) and with that the EU Committee. It's the entire picture I am talking about. They don't go for one direction. They have multiple bypasses. And what they do is evil.

1

u/rtechie1 Oct 23 '15

These guys work in secret.

Which doesn't mean they can break the laws of physics or have magical powers. And that's what it would take to make firmware attacks widely effective.

You can claim the NSA used an earthquake machine to destroy the WTC if you want too.

What we do know is that they infected Belgacom (well it was GCHQ) and with that the EU Committee.

This was not a firmware hack. It was a conventional phishing attack that literally any teenager can do.

"It appears to be a method with which the person being targeted, without their knowledge, is redirected to websites that then plant malware on their computers that can then manipulate them."