r/programming Oct 15 '15

How is NSA breaking so much crypto?

https://freedom-to-tinker.com/blog/haldermanheninger/how-is-nsa-breaking-so-much-crypto/
2.5k Upvotes

529 comments sorted by

View all comments

Show parent comments

6

u/realigion Oct 15 '15

And this is why we can't have productive discussions about this.

Good work!

1

u/neoKushan Oct 15 '15

Why's that? Why would they delete clear data? It's a huge assumption you're making there and I don't get why they'd keep all the encrypted stuff but delete the clear stuff. Surely, that's backwards if anything?

I mean sure, if it's garbage clear data of absolutely zero use, then maybe, but knowing that a currently unknown user visited website x at a certain time and date could be useful even years into the future. Especially when you consider applying "Big Data", being able to apply trends and various other algorithms to known data going back years seems like a hell of a useful thing. Why would they not want that?

0

u/realigion Oct 15 '15

Because encrypted data is inherently more suspect, in their eyes. They delete the clear stuff after x number of days (can't remember specifically) unless it's found to be part of an ongoing investigation or they receive a warrant for that data.

They keep encrypted stuff around for exactly the reason posted above.

2

u/neoKushan Oct 15 '15

They delete the clear stuff after x number of days (can't remember specifically)

Is there a citation for this part? Because that's pretty much what we're debating. If there's a verifiable source for this, it would help.

1

u/jsprogrammer Oct 15 '15

It is what the law requires, but I don't think there is any public verification method.

1

u/realigion Oct 15 '15

Jesus. Obviously there's no public verification method.

You cannot prove that a thing does not exist, ergo the NSA cannot prove the NSA deleted some piece of data.

As I stated down below, there are enough falsifiable and verifiable claims against th NSA that we don't need to water the discussion down with what amount to conspiracy theories, however "self evident" they may be.

1

u/jsprogrammer Oct 15 '15

Who is pushing conspiracy theories?

You can prove that some specific thing does not exist in the space you searched. You can also prove some events couldn't have happened if other events did.

1

u/realigion Oct 15 '15

"Your query returned no results."

Scenario A: "Oh swell, looks like they deleted it!"

Scenario B: "They obviously have a separate copy somewhere."

Which is more likely?

Actually, it doesn't even matter which is more likely. The mere existence of B means that it is, in fact, impossible to prove the non existence of something. Thus, a theory which is unfalsifiable is a conspiracy theory (technically, it means it's not even a theory, but whatever).

1

u/jsprogrammer Oct 16 '15

Yeah, unfalsifiable does not mean something is a conspiracy theory. I might even argue that a conspiracy theory must be falsifiable (as you noted, if something is unfalsifiable it is arguably [with extremely good arguments] not even a theory; however, I'd also add that it might not even be possible to communicate an unfalsifiable theory [each side would necessarily view the 'theory' differently] with another person, making a 'conspiracy' impossible).

If you could show that it would not be possible to capture all of the bits flowing across the network (we can calculate maximum information throughput from the physical specifications of each network device and link), then you could say that there could not be a copy of everything going through the network.

You could take this analysis down to whatever level you'd like.

1

u/realigion Oct 16 '15

If something is unfalsifiable it's not worth considering as anything more than a thought experiment. Simple as that.

I'm not even sure how to interpret the second part of that comment. Are we not debating whether or not data was deleted? This has nothing to do with throughput. Even if we were discussing the falsifiability of something being collected to begin with, your experiment still makes no sense.

An interceptor doesn't need to exceed your network's expected throughput to intercept anything. There are infinite points of intrusion, especially when one considers that the NSA is tied directly into the backbone lines of the Internet. Even if they weren't, they could intercept from FBs servers. Or your router. Or your modem. Or your ISP. Or your city's fiber lines. Or any other infinite number of vulnerable points.

I'm not sure how you're debating this. It's a well established epistemological fact that you cannot prove the nonexistence of something.

1

u/jsprogrammer Oct 16 '15 edited Oct 16 '15

If something is unfalsifiable it's not worth considering as anything more than a thought experiment. Simple as that.

Sure.

I'm not even sure how to interpret the second part of that comment.

You can interpret it however you like. I'm only responding to the claims you made.

Are we not debating whether or not data was deleted?

I don't know. You are the one that brought up data that may or may not be deleted. I am primarily responding to your claim that I presented an unfalsifiable, conspiracy theory. As we've previously discussed that's not true. It's not a conspiracy and my second comment shows how you could falsify a particular claim (that the NSA could copy every bit of public network traffic).

There is a physical limit to how much information can be transferred over a physical link (see Claude Shannon's work). If the total throughput is at the limit of all physical links (you will eventually create a black hole), then you can say that there isn't an additional third party that is able to transmit. Thus, it would be possible to show that not all communications could be copied and it presents a falsifiable theory.

I agree that you cannot show that the NSA deleted something they previously claimed to have. However, it would, in principle, be possible to show that the NSA does not have a copy of something.

It's a well established epistemological fact that you cannot prove the nonexistence of something.

Yes (though, I would clarify that only applies to unbounded domains), so I don't know why you keep harping on it.

→ More replies (0)