Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

eridani

(51,907 posts)
Thu Oct 10, 2013, 03:17 AM Oct 2013

The NSA is Making Us All Less Safe

https://www.eff.org/deeplinks/2013/10/nsa-making-us-less-safe

By weakening encryption, the NSA allows others to more easily break it. By installing backdoors and other vulnerabilities in systems, the NSA exposes them to other malicious hackers—whether they are foreign governments or criminals. As security expert Bruce Schneier explained, “It’s sheer folly to believe that only the NSA can exploit the vulnerabilities they create.”

The New York Times presented internal NSA documents with some specifics. They are written in bureaucratese, but we have some basic translations:

•“Insert vulnerabilities into commercial encryption systems, IT systems, networks and endpoint communications devices used by targets”— Sabotage our systems by inserting backdoors and otherwise weakening them if there’s a chance that a “target” might also use them.

•"actively engages US and foreign IT industries to covertly influence and/or overtly leverage their commercial products' designs" — Secretly infiltrate companies to conduct this sabotage, or work with companies to build in weaknesses to their systems, or coerce them into going along with it in secret.

•“Shape the worldwide commercial cryptography marketplace to make it more tractable to advanced cryptanalytic capabilities being developed by NSA/CSS — Ensure that the global market only has compromised systems, so that people don’t have access to the safest technology.

•"These design changes make the systems in question exploitable through Sigint collection … with foreknowledge of the modification. To the consumer and other adversaries, however, the systems' security remains intact." — Make sure no one knows that the systems have been compromised.

•“influence policies, standards and specifications for commercial public key technologies” — Make sure that the standards that everyone relies on have vulnerabilities that are hidden from users.
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
The NSA is Making Us All Less Safe (Original Post) eridani Oct 2013 OP
My server logs have hits every day from defacto7 Oct 2013 #1
What in the world are you talking about? JDPriestly Oct 2013 #3
Geek pickup lines. Spitfire of ATJ Oct 2013 #4
What the NSA scripkiddies don't know might hurt their corporate masters. Zorra Oct 2013 #2
K&R DeSwiss Oct 2013 #5
Law enforcement has always sought to break coding/encryption schemes. randome Oct 2013 #6
Glad to see that at least some people on the internet know more than-- eridani Oct 2013 #7

defacto7

(13,485 posts)
1. My server logs have hits every day from
Thu Oct 10, 2013, 03:47 AM
Oct 2013

the FBI and other nondescript US gov IPs redressed from anonymous proxies. They're out there.

Stay close to your AES256 and IDEA encryption algorithms and never let your certs go below an rsa:2048 on your CAs. I use 4096 -AES256 myself of all my certs. Other encryption methods are around that are nice to work with on general data, take your pick, and don't touch MD5 with a long stick.

 

randome

(34,845 posts)
6. Law enforcement has always sought to break coding/encryption schemes.
Thu Oct 10, 2013, 07:15 AM
Oct 2013

Online child pornographers try to hide behind encryption. So does organized crime.

I doubt we would want them to feel safe.

I also laugh at the idea that there are 'back doors' to circuits and encryption schemes. There are thousands of smart IT people -smarter than are employed at the NSA- who would know of such things.

This is another 'let's all panic' article.
[hr][font color="blue"][center]I'm always right. When I'm wrong I admit it.
So then I'm right about being wrong.
[/center][/font][hr]

eridani

(51,907 posts)
7. Glad to see that at least some people on the internet know more than--
Thu Oct 10, 2013, 12:47 PM
Oct 2013

--professional computer people.

Latest Discussions»General Discussion»The NSA is Making Us All ...