![]() |
| (This is only a parody of the NSA logo.) |
I am no expert. Certainly I am not qualified to comment on the technological underpinnings at risk here, and I'm not going to try to speculate on the consequences to business and diplomacy; there are plenty of qualified people engaging in just such speculation. In my case, encrypted documents have impacted me about as minimally as possible: though all my clients used what was available to them, no one spent much time thinking about it.
Now we learn that one of the ultimate US government security agencies has been secretly undermining the entire structure on which secure storage and transmission of documents is based. How does that make us all feel?
Welcome to 1984... thirty years late.
Here is Mr. Green's summary of the NSA's activity:
If you haven't read the NYT or Guardian stories, you probably should. The TL;DR is that the NSA has been doing some very bad things. At a combined cost of $250 million per year, they include:Your government and your tax dollars at work. Have a nice day!
All of these programs go by different code names, but the NSA's decryption program goes by the name 'Bullrun' so that's what I'll use here.
- Tampering with national standards (NIST is specifically mentioned) to promote weak, or otherwise vulnerable cryptography.
- Influencing standards committees to weaken protocols.
- Working with hardware and software vendors to weaken encryption and random number generators.
- Attacking the encryption used by 'the next generation of 4G phones'.
- Obtaining cleartext access to 'a major internet peer-to-peer voice and text communications system' (Skype?)
- Identifying and cracking vulnerable keys.
- Establishing a Human Intelligence division to infiltrate the global telecommunications industry.
- And worst of all (to me): somehow decrypting SSL connections.
(H/T TarheelDem on FDL.)



























