Bruce123 Posted September 6, 2013 Posted September 6, 2013 (edited) Recent leaks from the NSA talk about them having made a "breakthrough in 2010", making "vast amounts of data newly exploitable". Journalists assume it relates to cracking SSL (e.g. HTTPS), but does anyone care to speculate on exactly what that the breakthrough was? The online press seem reluctant to speculate. My guess is that they have got hold of one or more of the 'master' secret key(s) used by the main root certification authorities (i.e. a secret key used to sign the certs for the intermediary authorities who then provide/sign certs for companies like Google etc.). My browser has around 25 of these root certificates installed (from the likes of VeriSign etc.) This will enable them to produce fake certificates, but this by itself won't let them eavesdrop on traffic 'passively'. They would have to initiate an 'active' Man in the Middle Attack for each SSL session, whereby the session is decrypted-> recorded/analysed -> re-encrypted using a fake certificate, on-the-fly. Which I guess is feasible, but perhaps a little processor intensive for millions of sessions (e.g. when passing through a major Internet hub). Or have they cracked SSL in a more fundamental way? If they have not then re-issuing of the root certs would render this breakthrough obsolete. If they did obtain the master secret keys from the root CAs (rather than breaking SSL), how did they do this? By hacking into their systems? By brute force on the public keys available in the root certs (would take too long surely)? Or have they discovered an efficient way to factorise primes (as in fundamentally breaking RSA/SSL)? Some kind of leap forward in quantum computing? No harm in speculating.. Thanks, Bruce. Edited September 6, 2013 by Bruce123
kevin_lane Posted September 6, 2013 Posted September 6, 2013 But the thing is if they have broken them then surely they would have to tell them because what happened to the data protection act
Bruce123 Posted September 6, 2013 Author Posted September 6, 2013 I think GCHQ thinks the DPA doesn't apply to them (or it actually doesn't apply to them - I know there is an exception in the Act for prevention and detection of crime). Similar for NSA and the USA DPA act I imagine.
Arthur Posted September 6, 2013 Posted September 6, 2013 If they did obtain the master secret keys from the root CAs (rather than breaking SSL), how did they do this? Some sort of blunt instrument? http://imgs.xkcd.com/comics/security.png
Bruce123 Posted September 6, 2013 Author Posted September 6, 2013 The obvious/simple solution is often the right one... But I image they'd prefer the carrot to the stick.. less questions asked. IT Bod with the Ferrari in the car park might raise a few eyebrows though. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now