Showing posts sorted by relevance for query weak encryption. Sort by date Show all posts
Showing posts sorted by relevance for query weak encryption. Sort by date Show all posts

Wednesday, July 31, 2019

Government encryption backdoors are are a seriously bad idea

Attorney General Robert Barr has floated making government backdoors in encryption software mandatory.  I've posted about this before:
The choice for the Fed.Gov is this:  live with crypto that they can't (easily) break, or destroy encryption (and the Internet economy that depends on it).

I know that they want a backdoor that only they know about.  I want a unicorn that farts 93 octane into my gas tank.  And remember: they would ask us in the security community to trust them after the Snowden revelations showing how we can't trust them.
There is an excellent overview from Robert Graham that covers this in some detail:
Cryptographers don't know how slightly weak crypto that's only 99% secure instead of 100% secure, because any small weakness inevitably gets hacked into an enormous gaping hole.

Barr derides our concerns as being only "theory", but it's theory backed up my a lot of experience. It's like asking your doctor to prove that losing weight and exercising will improve your health. Our experience from cryptography is that there is no such things as a little bit weak. We know of no way to implement the government's backdoor in such a way that won't have grave impacts. I might not be able to immediately point out the holes in whatever scheme you have concocted, but that doesn't mean I believe your backdoor scheme doesn't have weaknesses. My decades of experience tells me it's only a matter of time before those weaknesses explode into gapping holes that hackers exploit.
I would add the note that Edward Snowden shows that a secret like this could not possibly remain secret.  What would the Chinese and Russians do with access to this?  Which leads to Graham's policy argument:
China and Russia show us the answer to this question. Both have cracked down on encrypted communications. China mandates devices have a backdoor whereby the government can access anything on a phone, encrypted or not. Russia has cracked down on Telegram, an encrypted messaging app popular in Russia. Both cases have been motivated by their desire to crack down on dissidents.

...

Thus, the debate isn't whether the U.S. government should have this power, but whether governments in general should have this power. If it were only the U.S., we might trust them with backdoors, because the U.S. is a free country and not a totalitarian state. But that's the same as saying that we trust our current government to regulate speech because they'd never restrict political speech the way they do in China and Russia.
Of course, there is a long list of where the US Government has violated many laws and Constitutional mandates.
So now let's go back and revisit what sounds like a reasonable argument that the Fourth Amendment balances privacy and security.

There is no evidence of an imbalance. Crime rates aren't increasing, clearance rates (of solving crimes) aren't decreasing [Note: Graham's post has data to back this up - Borepatch]. Far from "going dark", we live in a Golden Age of Surveillance, were police are able to grab our GPS records, credit card receipts, phone metadata, and other records, often without a warrant. It's impractical to travel anonymously in the United States, as the government gets a copy of plane and train records, and is increasingly blanketing the country with license plate readers to track our cars. If a rebalancing of the "privacy vs. security" equation is needed, it's in favor of privacy.

But we aren't talking about that balance. We are instead balancing "security vs. security". It has become obvious that privacy of security communications is a wholly separate concern from other privacy issues. Even though we rely upon government to provide for public safety, we are in danger from governments that abuse their power to repress citizens. It is every much as important for political dissidents that we protect private communications (with encryption) as we protect their right to public communications (free speech).
There are very few things that make me distrust our Law Enforcement community more than the persistent proposal that we destroy encryption.  The mathematics of cryptography is subtle and really easy to screw up in unpredictable ways.   It's impossible to predict, but it's entirely possible that a backdoor that lets the Government read your email could also let them write emails.  The Russians and the Chinese would have a field day with this once the secret inevitably leaks - allowing them to forge incriminating emails about politicians to undermine trust in our political system or forge bogus financial transactions to wreak havoc with the economy.  Among other things.

Quite frankly, this is a glaring example of why the Swamp needs to be drained.

Thursday, May 21, 2015

The NSA is the reason that we can't have nice things on the Internet

It seems that encryption was deliberately broken by the NSA, and now everyone is getting hip to how to read all your data.
Tens of thousands of HTTPS-protected websites, mail servers, and other widely used Internet services are vulnerable to a new attack that lets eavesdroppers read and modify data passing through encrypted connections, a team of computer scientists has found.

The vulnerability affects an estimated 8.4 percent of the top one million websites and a slightly bigger percentage of mail servers populating the IPv4 address space, the researchers said. The threat stems from a flaw in the transport layer security protocol that websites and mail servers use to establish encrypted connections with end users. The new attack, which its creators have dubbed Logjam, can be exploited against a subset of servers that support the widely used Diffie-Hellman key exchange, which allows two parties that have never met before to negotiate a secret key even though they're communicating over an unsecured, public channel.

The weakness is the result of export restrictions the US government mandated in the 1990s on US developers who wanted their software to be used abroad. The regime was established by the Clinton administration so the FBI and other agencies could break the encryption used by foreign entities. Attackers with the ability to monitor the connection between an end user and a Diffie-Hellman-enabled server that supports the export cipher can inject a special payload into the traffic that downgrades encrypted connections to use extremely weak 512-bit key material. Using precomputed data prepared ahead of time, the attackers can then deduce the encryption key negotiated between the two parties.
NSA was involved in all the discussions on export grade encryption in the 1990s.  Their fingerprints are all over this.

This is still developing but looks like it is very bad indeed.  This would let a Bad Guy get your online banking password, among other things.  The idea that NSA could get a back door in important code and that the back door would remain secret was always pretty dumb.

Keep your eye out for a pop up from your browser saying there's an important security fix.  You absolutely will want this one.  As far as I can tell, Internet Explorer is the only one patched so far.

Tuesday, October 6, 2009

Online Banking: Caveat Emptor

The weak link isn't your bank's web site (which likely has very good security indeed). The weak link isn't the encryption that protects your data between your computer and the bank's web site, which is strong enough to keep even the NSA from cracking it (really).

The weak link? Your computer:

A next-generation Trojan recently discovered pilfering online bank accounts around the world kicks it up a notch by avoiding any behavior that would trigger a fraud alert and forging the victim's bank statement to cover its tracks.

The so-called URLZone Trojan doesn't just dupe users into giving up their online banking credentials like most banking Trojans do: Instead, it calls back to its command and control server for specific instructions on exactly how much to steal from the victim's bank account without raising any suspicion, and to which money mule account to send it the money. Then it forges the victim's on-screen bank statements so the person and bank don't see the unauthorized transaction.

Not surprising - as some parts of the defense gets better, attackers look for softer targets. So what are the softest targets?

1. Windows. This isn't a rant, but it's simply a fact that malware targets Windows. It's not that Mac or Linux isn't vulnerable too, but it (so far) doesn't pay for the Bad Guys to attack them, because there are a lot fewer of them, and they're harder to attack.

2. Internet Explorer 6 and 7. Lousy security. Use Firefox, or Opera, or even Internet Explorer 8 (it's security is a lot better).

Unfortunately, your antivirus scanner has been getting less effective for years - more specifically, the malware has been getting better at avoiding detection for years.

So what do you do? Well, you can give up online banking. You can switch to Mac or Linux. Or you can take your chances. Check your bank statements regularly, and make sure you're on good terms with your banker.