How the NSA Got So Smart So Fast(on.wsj.com)
on.wsj.com
How the NSA Got So Smart So Fast
http://on.wsj.com/11HXT5w
46 comments
Re: #3; can you seriously imagine that they can't take control of an MS-Windows PC, with or without MS's knowledge?
And you forgot a point: can they get an SSL root certificate signed for them, in order to perform MitM attacks on seemingly secured connections? Here again it's a foregone conclusion, several less technically-savvy countries have been caught doing that.
And you forgot a point: can they get an SSL root certificate signed for them, in order to perform MitM attacks on seemingly secured connections? Here again it's a foregone conclusion, several less technically-savvy countries have been caught doing that.
And you forgot a point: can they get an SSL root certificate signed for them, in order to perform MitM attacks on seemingly secured connections?
Yes, that is a good point that I forgot. I tend to assume the answer is "yes".
Yes, that is a good point that I forgot. I tend to assume the answer is "yes".
> Re: #3; can you seriously imagine that they can't take control of an MS-Windows PC, with or without MS's knowledge?
Can they take control of an MS-Windows PC without the cooperation of my router maker and my firewall maker? And what does it cost them to do so for the different makers?
You know? I'm fairly sure they can, after all if some kiddy off the internet can what are the chances they can't. But what's the cost to cover the different profiles? Is there a single point of failure?
Can they take control of an MS-Windows PC without the cooperation of my router maker and my firewall maker? And what does it cost them to do so for the different makers?
You know? I'm fairly sure they can, after all if some kiddy off the internet can what are the chances they can't. But what's the cost to cover the different profiles? Is there a single point of failure?
Shouldn't be hard for the NSA to monitor your web browsing for a few days and then inject a 0-day for whatever browser you're using into an HTTP response from, say, HN, right?
If they've got to rely on the infrastructure provider to know what I've been looking at, then I assume that they don't have infrastructure in place themselves to arbitrarily do HTTP injection in a push button manner. May be wrong though.
What could we do about it if 1. were true? Not much.
For 2. I think it's safe to assume that they know a few tricks that we don't. Probably enough to hasten breaking encryption, but probably not enough to make encryption useless.
For 3. Yes, isn't that obvious?
Here's a recent discovery regarding FPGA's, maybe not the NSA, but it didn't get there by accident. http://www.cl.cam.ac.uk/~sps32/sec_news.html
I suspect that some bugs like this one in Intel networking chips may not be bugs http://blog.krisk.org/2013/02/packets-of-death.html
If it is technically feasible, then it is almost certainly being done.
For 2. I think it's safe to assume that they know a few tricks that we don't. Probably enough to hasten breaking encryption, but probably not enough to make encryption useless.
For 3. Yes, isn't that obvious?
Here's a recent discovery regarding FPGA's, maybe not the NSA, but it didn't get there by accident. http://www.cl.cam.ac.uk/~sps32/sec_news.html
I suspect that some bugs like this one in Intel networking chips may not be bugs http://blog.krisk.org/2013/02/packets-of-death.html
If it is technically feasible, then it is almost certainly being done.
Well, there are some things we could do for 1. - switch to an algorithm not vulnerable to quantum computing, for example. I think NTRU would be an example of this.
I'm sure they can handle number 2 quite easily. The factors of any large prime number are the number itself and 1. What I think you meant, though, is can they factor the product of two large prime numbers (where the original primes are unknown to them). If that can be solved (without quantum computers), then I believe that actually opens up a whole range of solutions to other problems not related to cryptography.
What I think you meant, though, is can they factor the product of two large prime numbers (where the original primes are unknown to them)
D'oh... yes, of course, that's what I meant to say. Sorry, too much on my mind right now!
D'oh... yes, of course, that's what I meant to say. Sorry, too much on my mind right now!
Number 3 is the most likely, along with pushbutton tools that automate attacking and extracting information from endpoint devices. The market among state actors for zero-day exploits is documented, while the other possibilities are out there with other "secret weapon" theories that are predicated on fundamental scientific breakthroughs.
Yeah, I'm not buying that the NSA has some crazy advanced technology that is kept secret.
There are highly skilled and better financed tech companies with huge R&D teams. Why would the NSA be able to outperform them?
It's more likely their power is their access to the latest zero-day exploits via sourcing information - something they are extremely good at.
There are highly skilled and better financed tech companies with huge R&D teams. Why would the NSA be able to outperform them?
It's more likely their power is their access to the latest zero-day exploits via sourcing information - something they are extremely good at.
The NSA knew about differential cryptanalysis more than 10 years before academia and the general public. It's become cool to bash the NSA, but don't make the mistake of underestimating them. (Also, remember that the NSA is far, far larger than the CIA.) They have plenty of smart people working for them--in fact, a bunch of the most prominent researchers/personalities in the security community worked for the NSA in the past.
There are highly skilled and better financed tech companies with huge R&D teams. Why would the NSA be able to outperform them?
More to the point, they don't (presumably) have some secret pipeline of highly talented people. I mean, the pool of graduates in mathematics, statistics, computer science, etc., year in and year out, is available to everyone, NSA, other public sector, other private sector, etc. And while the NSA probably prioritizes hiring brilliant math wonks and what-not, so do wall street hedge fund companies, tech companies, etc. And given that at least some small percentage of "really smart people" would probably refuse to work for the NSA just on ideological grounds, I don't see any reason to believe that they have a monopoly on smart people who can do crypto research and what-not.
As for their financing, however... I don't know. I'm not real big on conspiracy theories, but I don't doubt the existence of secret budgets and "off the books" stuff to fund certain government programs. I mean, just go back to the Iran/Contra affair[1] and you can see that some sneaky stuff does go on, at least on occasion.
[1]: http://en.wikipedia.org/wiki/Iran%E2%80%93Contra_affair
More to the point, they don't (presumably) have some secret pipeline of highly talented people. I mean, the pool of graduates in mathematics, statistics, computer science, etc., year in and year out, is available to everyone, NSA, other public sector, other private sector, etc. And while the NSA probably prioritizes hiring brilliant math wonks and what-not, so do wall street hedge fund companies, tech companies, etc. And given that at least some small percentage of "really smart people" would probably refuse to work for the NSA just on ideological grounds, I don't see any reason to believe that they have a monopoly on smart people who can do crypto research and what-not.
As for their financing, however... I don't know. I'm not real big on conspiracy theories, but I don't doubt the existence of secret budgets and "off the books" stuff to fund certain government programs. I mean, just go back to the Iran/Contra affair[1] and you can see that some sneaky stuff does go on, at least on occasion.
[1]: http://en.wikipedia.org/wiki/Iran%E2%80%93Contra_affair
To add another reference to your point, you must be a US citizen to work for the NSA. That alone limits their supply of the really smart people of the world.
At the same time, at least some small percentage of really smart people would prefer to work for the NSA on ideological grounds.
Absolutely. I'm not suggesting they don't have smart people, just pointing out that they don't have all of the smart people. Or at least that's my presumption.
What tech companies have an R&D budget of $125.6 billion[1] dollars a year? And that's just what's on the books. Who knows what is classified, "for our own good."
[1]Projected US Gov't R&D spending - 2012: http://www.battelle.org/media/press-releases/battelle-r-d-ma...)
[1]Projected US Gov't R&D spending - 2012: http://www.battelle.org/media/press-releases/battelle-r-d-ma...)
"There are...better financed tech companies."
Unlikely. And given the secrecy surrounding their budgets, how could you know for sure? Even if you did, the dollars themselves are only part of the picture. The dynamic surrounding the money also has a big influence on how it can be used. A private company needing to post a profit operates under a set of constraints that are dramatically different from those that govern R&D in the military.
Also, unlike private R&D teams, the military can unilaterally classify and restrict entirely categories of hardware (e.g. GPS units that function over specific altitudes or above certain velocities). And they can seize (in secret) any instances that threaten national security.
That's a set of competitive advantages that the private sector, almost by definition, can never hope to match. Or at least not independently.
Unlikely. And given the secrecy surrounding their budgets, how could you know for sure? Even if you did, the dollars themselves are only part of the picture. The dynamic surrounding the money also has a big influence on how it can be used. A private company needing to post a profit operates under a set of constraints that are dramatically different from those that govern R&D in the military.
Also, unlike private R&D teams, the military can unilaterally classify and restrict entirely categories of hardware (e.g. GPS units that function over specific altitudes or above certain velocities). And they can seize (in secret) any instances that threaten national security.
That's a set of competitive advantages that the private sector, almost by definition, can never hope to match. Or at least not independently.
#3 - recall that the NSA was the contributor of Security Enhanced Linux, which is part of nearly every distro now.
I think the chance of it containing a backdoor is low, though. It's been reviewed by any number of top kernel developers since it was published.
I think the chance of it containing a backdoor is low, though. It's been reviewed by any number of top kernel developers since it was published.
Paywall for me... :(
Most of the top links are just teasers which link to the paywalled story.
Here is a complete (I assume) version. http://finance.yahoo.com/news/nsa-could-smart-fast-235100722...
Here is a complete (I assume) version. http://finance.yahoo.com/news/nsa-could-smart-fast-235100722...
Article behind paywall. Here is link that works: http://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2...
welp if the PLA has a backdoor on my Shenzhen-made electronic goodies, I need an NSA backdoor in order to keep em honest. Also any conversation with "backdoor" could get dirty fast...
I wonder if the NSA will open source their server architecture?
Believe it or not, they do open source some of their stuff, sometimes. See, for example, Accumulo.[1][2]
[1]: http://en.wikipedia.org/wiki/Apache_Accumulo
[2]: http://accumulo.apache.org/
[1]: http://en.wikipedia.org/wiki/Apache_Accumulo
[2]: http://accumulo.apache.org/
Another classic example, SELinux.[1]
[1]: http://en.wikipedia.org/wiki/Security-Enhanced_Linux#Overvie...
[1]: http://en.wikipedia.org/wiki/Security-Enhanced_Linux#Overvie...
SELinux saved my ass years ago, preventing exploitation of an outdated/vulnerable PHP application. Since then, it gets installed on every production server I deploy. Those who simply turn it off because it's a PITA are doing themselves a huge disservice.
Would love to hear details on how it protected you.
An outdated version of a PHP application (which had a public vulnerability) was attacked, allowing arbitrary code execution. The "exploit" attempted to download and execute a remote file via TFTP. Ultimately, a "remote shell" would end up being installed on the server.
SELinux, however, prevented the TFTP transfer from happening. We saw this in the audit logs, investigated, and discovered what had happened (and, of course, updated the PHP application).
If the attack had succeeded, I'm convinced that it eventually would have ended up as a full ("root-level") compromise.
SELinux, however, prevented the TFTP transfer from happening. We saw this in the audit logs, investigated, and discovered what had happened (and, of course, updated the PHP application).
If the attack had succeeded, I'm convinced that it eventually would have ended up as a full ("root-level") compromise.
I believe NSA has a dual mandate. We are hearing a lot lately about their efforts to discover and use intelligence via electronic means, but I believe they are also responsible for providing guidance on how the U.S. can secure its own electronic communications--this is where efforts like SELinux and the guide to securing OS X come from.
Yep, they also participate in the development of various STIGs, including the recently released RHEL 6 STIG.
>but I believe they are also responsible for providing guidance on how the U.S. can secure its own electronic communications
How can anyone find them credible in such a role with such huge glaring conflicts of interests, and their demonstrated lack of trustworthiness?
How can anyone find them credible in such a role with such huge glaring conflicts of interests, and their demonstrated lack of trustworthiness?
We see the same kind of behavior in corporations all the time. "Sony" is both "Columbia Pictures", which wants to put invasive DRM in your TV, and "Sony Electronics", which wants to sell TVs without DRM so more people buy them.
And you can just look at the NSA's guide to securing Red Hat Linux.
http://www.nsa.gov/ia/_files/os/redhat/rhel5-guide-i731.pdf
It's not substantially different than the information you'd find in any other book about security. Anyone is free to review or comment on it. I don't find it plausible that the NSA would hide any tricks in that document so they could track you. At best, they might omit information, such as knowledge of a 0-day exploit.
And you can just look at the NSA's guide to securing Red Hat Linux.
http://www.nsa.gov/ia/_files/os/redhat/rhel5-guide-i731.pdf
It's not substantially different than the information you'd find in any other book about security. Anyone is free to review or comment on it. I don't find it plausible that the NSA would hide any tricks in that document so they could track you. At best, they might omit information, such as knowledge of a 0-day exploit.
I don't consider Sony trustworthy either.
As far as the NSA's published guide you linked, of course it is in the national interest for them to do things like that, and given the nature of a public document it would be foolish for them to put false or misleading information in it. That would be both bad, and comically obvious. I was thinking more along the lines of them promoting or mandating the use of encryption/technology that has weaknesses known only to them.
As far as the NSA's published guide you linked, of course it is in the national interest for them to do things like that, and given the nature of a public document it would be foolish for them to put false or misleading information in it. That would be both bad, and comically obvious. I was thinking more along the lines of them promoting or mandating the use of encryption/technology that has weaknesses known only to them.
They were selected because they are the most credible; as the ones responsible for developing the most advanced cryptanalytic and signals interception capabilities possible they are also the ones best suited to identify attacks against which the U.S. must defend themselves, and provide suitable countermeasures.
For instance, NSA fixed a problem in what became IBM's DES crypto standard before the cryptanalytic community even knew what the attack was. So there's at least evidence that NSA takes that part of their mission goals seriously, and that NSA required the knowledge/skills/abilities of their "other half" in order to properly carry out those duties.
For instance, NSA fixed a problem in what became IBM's DES crypto standard before the cryptanalytic community even knew what the attack was. So there's at least evidence that NSA takes that part of their mission goals seriously, and that NSA required the knowledge/skills/abilities of their "other half" in order to properly carry out those duties.
I would say most competent. I still think that it is a terribly conflicted set of roles, and that they've poisoned their position of trust. They still have the incentive to protect US interests from foreign enemies, including commercial ones as in the IBM example you cited; but, there is no longer any reason to think that those interests are protected from government agents with access.
Well they want to protect US data and get the data of other people...that is not exactly a conflict of interest.
Their trustworthiness on technical matters is a matter of public record--for example, as far as I know, Linux experts independently agree that SELinux is a very secure Linux configuration.
Their trustworthiness on technical matters is a matter of public record--for example, as far as I know, Linux experts independently agree that SELinux is a very secure Linux configuration.
One hand doesn't know what the other hand is doing.
Just because the DOD bombs civilians with drones in far off doesn't mean we should hold the National Park Service in the same light.
Just because the DOD bombs civilians with drones in far off doesn't mean we should hold the National Park Service in the same light.
The National Park Service isn't a division of the DOD.
They're all a part of the US government.
So all US government agencies are in effect one? What am I to make of the GAO constantly finding fraud and waste? A clever subterfuge?
You're totally missing my point.
My orignal response was to someone wondering why the NSA can violate constitutional rights while at the same time open sourcing technologies for enhanced securities. My example of the DOD vs the NPS was to show that entities within the same organizational structure can have opposed goals.
My orignal response was to someone wondering why the NSA can violate constitutional rights while at the same time open sourcing technologies for enhanced securities. My example of the DOD vs the NPS was to show that entities within the same organizational structure can have opposed goals.
1. Do they already have a functional quantum computer, capable of rendering most modern encryption useless?
2. Do they have a mathematical breakthrough that allows them to factor products of large prime numbers multiplied together, far faster than anyone suspects - which would render most / all modern encryption useless?
3. Have they planted backdoors and vulnerabilities in popular, widely distributed hardware / software platforms?
etc.