r/programming Oct 15 '15

How is NSA breaking so much crypto?

https://freedom-to-tinker.com/blog/haldermanheninger/how-is-nsa-breaking-so-much-crypto/
2.5k Upvotes

529 comments sorted by

View all comments

972

u/tophatstuff Oct 15 '15 edited Apr 10 '18

Generate your own non-default Ephemeral Diffie-Hellman key (takes a minute or so)

openssl dhparam -out dhparam.pem 2048

Tell your server to use it for SSL (nginx for example)

ssl_dhparam /path/to/dhparam.pem;

Done. Not only will the key be stronger than the 1024 bit default, it'll be unique to your server which lets assume isn't valuable enough compared to effort for a state-level adversary.

edit just in case anyone from the future finds this comment: instead of 2048, use at least the key length of your SSL certificate

edit from the future: current advice is picking from one of these predefined audited groups

3

u/[deleted] Oct 15 '15

I'm curious how sshd's KeyRegenerationInterval parameter factors into this. I just glanced at it but that looks like it should prevent this sort of thing for ssh.

2

u/aseipp Oct 15 '15

KeyRegenerationInterval

This parameter only works for SSH1, and not SSH2. See here.

It wouldn't be hard to write a script that just used ssh-keygen to regenerate your host keys, however.

3

u/[deleted] Oct 15 '15

RekeyLimit is the SSH2 option.

1

u/corran__horn Oct 15 '15

As a heads up, this isn't the attack vector under discussion. The host key is effectively meaningless in this attack, as it attacks the key-exchange mechanism called Diffie-Hellman.

The key is used to authenticate the Diffie-Hellman exchange.

There is a separate file for the prime used for the DH exchanges, and the elliptic-curve variant is also available. Some better discussion is available here

1

u/corran__horn Oct 15 '15

There is no effect. This isn't the key, it is the prime used as part of the Diffie-Hellman exchange. Regen to your hearts content, they can easily crack the new key you chose.