TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The NSA's Cryptographic Capabilities

91 点作者 silenteh超过 11 年前

6 条评论

devx超过 11 年前
After the new revelations every site who&#x27;s using SSL should be using Perfect Forward Secrecy with it, too. Right now, only a few known companies like Google (only for the search engine probably), DuckDuckGo, and Ixquick&#x2F;Startpage are using it.<p>Considering NSA is collecting as many keys as possible, let&#x27;s at least make their job exponentially harder by encrypting every session and every message with a new key with PFS. It&#x27;s the <i>least</i> these companies can do, if they&#x27;re serious about their users&#x27; privacy.<p>Also, as Bruce is saying - use 3072 bit or even 4096 bit RSA keys (or better alternatives) and AES-256 as soon as possible (hopefully within a year).
评论 #6340410 未加载
einhverfr超过 11 年前
The idea that we can break public key encryption and go back to shared secrets doesn&#x27;t solve the problem for which public key encryption is the answer, namely sharing the secrets. Schneier&#x27;s piece would be a little more helpful if this were considered. Going back to simple shared secrets means that one cannot securely engage in something like ecommerce, and so breaking public key encryption would totally break the way we use encryption today.
shin_lao超过 11 年前
<i>Certainly the fact that the NSA is pushing elliptic-curve cryptography is some indication that it can break them more easily.</i><p>There are valid and sane reasons to dismiss RSA. Keys are becoming larger and larger for example.<p>What Bruce doesn&#x27;t say is that the NSA made modifications to DES S-Boxes so that it can RESIST differential cryptanalysis better.<p>But overall I agree, I think the <i>&quot;Also, we are investing in groundbreaking cryptanalytic capabilities to defeat adversarial cryptography and exploit internet traffic.&quot;</i> is just vulgarization for the people voting budget.<p>It doesn&#x27;t matter if you break the crypto or the implementation as long as you provide intelligence.
评论 #6340392 未加载
raheemm超过 11 年前
On a different note, considering the popular myth that government by default is incompetent, this is a remarkable degree of competence, surpassing even the private sector.
评论 #6340503 未加载
评论 #6340478 未加载
评论 #6340683 未加载
评论 #6340469 未加载
MrBra超过 11 年前
&gt; I think it extraordinarily unlikely that the NSA has built a quantum computer capable of performing the magnitude of calculation necessary to do this, but it&#x27;s possible.<p>.<p>I think, that from the very first moment a quantum computer could be built (given an extraordinary amount of resources) NSA set this to their highest priority, and tried to do so, given what this system could provide them, so I am pretty sure that by now they have already some prototype working and growing.<p>Or do you think they&#x27;re saving money? Or not trying to draw all possible funds to this cause considering how much appeal its computations could exercise for exampe for US foreign economy?
wjnc超过 11 年前
One point that is made more often is: &quot;It&#x27;s very probable that the NSA has newer techniques that remain undiscovered in academia.&quot;<p>How does one go around maintaining such an omerta?<p>Most cryptographic math is not that hard that it requires a team to remember. So anyone working in this field at NSA could (if true) become professor by working out that math in academia after his&#x2F;her career at NSA. Or is there such strong commitment to secrecy that not one former NSA cryptographer would try to follow that route?
评论 #6340294 未加载
评论 #6340630 未加载
评论 #6340268 未加载