Jump to content

Recommended Posts

Posted (edited)

Recent leaks from the NSA talk about them having made a "breakthrough in 2010", making "vast amounts of data newly exploitable".

 

Journalists assume it relates to cracking SSL (e.g. HTTPS), but does anyone care to speculate on exactly what that the breakthrough was? The online press seem reluctant to speculate.

 

My guess is that they have got hold of one or more of the 'master' secret key(s) used by the main root certification authorities (i.e. a secret key used to sign the certs for the intermediary authorities who then provide/sign certs for companies like Google etc.). My browser has around 25 of these root certificates installed (from the likes of VeriSign etc.)

 

This will enable them to produce fake certificates, but this by itself won't let them eavesdrop on traffic 'passively'. They would have to initiate an 'active' Man in the Middle Attack for each SSL session, whereby the session is decrypted-> recorded/analysed -> re-encrypted using a fake certificate, on-the-fly. Which I guess is feasible, but perhaps a little processor intensive for millions of sessions (e.g. when passing through a major Internet hub).

 

Or have they cracked SSL in a more fundamental way? If they have not then re-issuing of the root certs would render this breakthrough obsolete.

 

If they did obtain the master secret keys from the root CAs (rather than breaking SSL), how did they do this? By hacking into their systems? By brute force on the public keys available in the root certs (would take too long surely)?

 

Or have they discovered an efficient way to factorise primes (as in fundamentally breaking RSA/SSL)? Some kind of leap forward in quantum computing?

 

No harm in speculating.. :cool:

 

Thanks,

 

Bruce.

Edited by Bruce123
Posted
I think GCHQ thinks the DPA doesn't apply to them (or it actually doesn't apply to them - I know there is an exception in the Act for prevention and detection of crime). Similar for NSA and the USA DPA act I imagine.
Posted
The obvious/simple solution is often the right one... But I image they'd prefer the carrot to the stick.. less questions asked. IT Bod with the Ferrari in the car park might raise a few eyebrows though.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...