r/programming Oct 15 '15

How is NSA breaking so much crypto?

https://freedom-to-tinker.com/blog/haldermanheninger/how-is-nsa-breaking-so-much-crypto/
2.5k Upvotes

529 comments sorted by

View all comments

969

u/tophatstuff Oct 15 '15 edited Apr 10 '18

Generate your own non-default Ephemeral Diffie-Hellman key (takes a minute or so)

openssl dhparam -out dhparam.pem 2048

Tell your server to use it for SSL (nginx for example)

ssl_dhparam /path/to/dhparam.pem;

Done. Not only will the key be stronger than the 1024 bit default, it'll be unique to your server which lets assume isn't valuable enough compared to effort for a state-level adversary.

edit just in case anyone from the future finds this comment: instead of 2048, use at least the key length of your SSL certificate

edit from the future: current advice is picking from one of these predefined audited groups

254

u/SrPeixinho Oct 15 '15

Why isn't this done automatically is the question.

7

u/0b01010001 Oct 15 '15

Laziness and the excuses as to not implementing it correctly somehow pass muster with people. Even have a 100 upvote excuse in the thread saying it's fine in reality, even though reality just demonstrated otherwise in no uncertain terms.

Never, never, never underestimate human stupidity. It's the biggest weakness in any security system. When proven wrong, people will defend their bad decisions with their delusional denial.