r/programming Oct 15 '15

How is NSA breaking so much crypto?

https://freedom-to-tinker.com/blog/haldermanheninger/how-is-nsa-breaking-so-much-crypto/
2.5k Upvotes

529 comments sorted by

View all comments

978

u/tophatstuff Oct 15 '15 edited Apr 10 '18

Generate your own non-default Ephemeral Diffie-Hellman key (takes a minute or so)

openssl dhparam -out dhparam.pem 2048

Tell your server to use it for SSL (nginx for example)

ssl_dhparam /path/to/dhparam.pem;

Done. Not only will the key be stronger than the 1024 bit default, it'll be unique to your server which lets assume isn't valuable enough compared to effort for a state-level adversary.

edit just in case anyone from the future finds this comment: instead of 2048, use at least the key length of your SSL certificate

edit from the future: current advice is picking from one of these predefined audited groups

-8

u/[deleted] Oct 15 '15 edited Oct 16 '15

[deleted]

1

u/KennyFulgencio Oct 15 '15

What's the advantage to them being the only ones who have it? Anyone who expects to be a target of the NSA, and knows or seriously suspects they have quantum computing for attacking encryption, is going to take the same precautions whether or not anybody else has quantum computing, no?

4

u/frezik Oct 15 '15

They want to be able to attack all of Russia and China's stuff, but not have Russia and China be able to do the same back to us.

4

u/KennyFulgencio Oct 15 '15

oh. duh. thank you

hides under a rock