Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Wednesday, September 09, 2015

Preparing Encryption for Quantum Supercomputing

It is an inevitability that cryptographers dread: the arrival of powerful quantum computers that can break the security of the Internet. Although these devices are thought to be a decade or more away, researchers are adamant that preparations must begin now.

Computer-security specialists are meeting in Germany this week to discuss quantum-resistant replacements for today’s cryptographic systems—the protocols used to scramble and protect private information as it traverses the web and other digital networks. Although today’s hackers can, and often do, steal private information by guessing passwords, impersonating authorized users or installing malicious software on computer networks, existing computers are unable to crack standard forms of encryption used to send sensitive data over the Internet.

But on the day that the first large quantum computer comes online, some widespread and crucial encryption methods will be rendered obsolete. Quantum computers exploit laws that govern subatomic particles, so they could easily defeat existing encryption methods.

Tuesday, August 04, 2015

MicroSoft Claims to Have Developed Quantum Computer Proof Encryption

The new quantum-proof version of TLS generates encryption keys using a different mathematical problem that’s believed to be beyond the practical reach of both conventional and quantum computers.

That system was tested by using it to encrypt data moving between two PCs, one taking the role of a Web browser and the other a Web server. The quantum-proof encryption protocol moved data 21 percent more slowly than a version using elliptic curve cryptography, as some websites do today, but the researchers consider that penalty a reasonable one to pay if their idea is polished up for real-world use.

Ari Juels, a professor at Cornell Tech and previously chief scientist at the security company RSA, says it makes sense to prepare our encryption for quantum computers now. Outdated encryption lingering in websites or software already causes security problems, even with the relatively slow progress made on encryption-beating attacks, he says.

However, right now it’s not certain that the math used in Microsoft’s quantum-proof software will always be intractable for either quantum or conventional computers, says Juels. Mathematicians and cryptographers haven’t studied them as intensely as they have RSA or the encryption used today. “We’ve no solid assurance,” he says.

Thursday, January 01, 2015

The NSA Eats VPNs for Breakfast

The National Security Agency’s Office of Target Pursuit (OTP) maintains a team of engineers dedicated to cracking the encrypted traffic of virtual private networks (VPNs) and has developed tools that could potentially uncloak the traffic in the majority of VPNs used to secure traffic passing over the Internet today, according to documents published this week by the German news magazine Der Speigel. A slide deck from a presentation by a member of OTP’s VPN Exploitation Team, dated September 13, 2010, details the process the NSA used at that time to attack VPNs—including tools with names drawn from Star Trek and other bits of popular culture.

OTP’s VPN exploit team had members assigned to branches focused on specific regional teams, as well as a “Cross-Target Support Branch” and a custom development team for building specialized VPN exploits. At the regional level, the VPN team representatives acted as liaisons to analysts, providing information on new VPN attacks and gathering requirements for specific targets to be used in developing new ones.

While some VPN technologies—specifically, those based on the Point-to-Point Protocol (PPTP)—have previously been identified as being vulnerable because of the way they exchange keys at the beginning of a VPN session, others have generally been assumed to be safer from scrutiny. But in 2010, the NSA had already developed tools to attack the most commonly used VPN encryption schemes: Secure Shell (SSH), Internet Protocol Security (IPSec), and Secure Socket Layer (SSL) encryption.

Tuesday, July 01, 2014

Europe & China are Closing in on Quantum Cryptographic Satellite Communications

Europe and China are gaining the upper hand in the race to bounce perfectly secure messages off satellites in low Earth orbit.

One of the great benefits of quantum communication is the ability to send messages from one point in space to another with perfect security. Not so great is the fact that so-called quantum cryptography is limited to distances of around 100 kilometers.

That’s because over longer distances, photons tend to be absorbed by the glass in fiber-optic cables and by the atmosphere when beamed from one location to another. That causes errors that are too great for perfect privacy.

But there is a potential way around this–to send photons to an orbiting spacecraft, which then retransmits the message securely when it is over another part of the planet. That’s possible because the photons traveling straight up only have to negotiate a few tens of kilometers of the atmosphere before reaching space.

So it’s not surprising that governments all over the world are keen on exploiting space-based quantum cryptography. Indeed, last year we reported on a Chinese team that had successfully reflected individual photons off an orbiting satellite, to simulate a satellite sending photons to the ground.

The Chinese team said the demonstration was a crucial step toward space-based quantum cryptography. However, the ability to send single photons from orbit and receive them on the ground is not enough.

A key factor is the error rate in this process. If the error rate is above 11 percent, quantum cryptography does not work.

So an important unanswered question is whether the error rate is small enough.

Today, we get an answer thanks to the work of Giuseppe Vallone at the University of Padova in Italy and a few pals. These guys have bounced polarized photons off a number of different satellites and measured the error rate in the photons that return to Earth.

And they have good news. They clearly show that the error rate can be made smaller than the critical threshold.

Saturday, May 10, 2014

Beyond Cryptography: Hiding Communications


Sometimes encrypting messages isn’t enough, and the very act of sending them must be hidden as well. Now physicists have discovered how to camouflage messages and guarantee that they remain hidden.

The world of cryptography has undergone a quiet revolution in recent years. That’s largely because of the advent of techniques that exploit the laws of quantum mechanics to send messages with perfect privacy. So-called quantum cryptography ensures that an eavesdropper cannot decode a message under guarantee by the laws of physics.

But sometimes perfect privacy isn’t enough. Sometimes the knowledge that a message has been sent is all that an adversary needs. So the question arises of how to hide a message so that an eavesdropper cannot tell whether it has been sent or not.

The discipline, known as steganography or covert communication, is as old as its cryptographic cousin but has received much less attention in recent years. But that changes today thanks to the work of Boulat Bash at the University of Massachusetts in Amherst and a few pals who have worked out how to camouflage messages in a way that is guaranteed mathematically.

And they’ve put their ideas into practice with a proof-of-principle demonstration. “We have built the first operational system that provides mathematically proven covert communication over a physical channel,” they say.

The technique is relatively straightforward, relying on a method of communication known as pulse position modulation. This divides each second (or other unit of time) into a number of time bands which each correspond to a symbol. Alice sends a message to Bob by transmitting pulses during bands that correspond to the required symbol, which Bob then looks up in the order he receives them.

There’s an important caveat, of course. This system requires the sender and receiver to agree on the band structure and the symbols they refer to. And this must be done in advance in secret.

This allows Alice and Bob to send encrypted messages (the length of which depend on the length of the information shared in advance).

The question is how to hide this information. And the answer is in plain view. Bash and co assume that the message is sent using photons and that the environment supplies a certain amount of noise against which their signal is camouflaged. For example, they assume that photon detectors are not perfect and so always produce a certain number of dark counts in which they register a photon without receiving one.

Tuesday, January 07, 2014

OMG! Snowden Reveals ALL on NSA Developing Quantum Computers!!!

In room-size metal boxes ­secure against electromagnetic leaks, the National Security Agency is racing to build a computer that could break nearly every kind of encryption used to protect banking, medical, business and government records around the world.

According to documents provided by former NSA contractor Edward Snowden, the effort to build “a cryptologically useful quantum computer” — a machine exponentially faster than classical computers — is part of a $79.7 million research program titled “Penetrating Hard Targets.” Much of the work is hosted under classified contracts at a laboratory in College Park, Md.

[...]

“It seems improbable that the NSA could be that far ahead of the open world without anybody knowing it,” said Scott Aaronson, an associate professor of electrical engineering and computer science at the Massachusetts Institute of Technology.




Actually, this is about as UNSURPRISING as anything Snowden has revealed.  The NSA, if they are doing their jobs the way they ought, really should be pursuing a quantum computer.  Likewise, they ought to be pursuing quantum cryptography (other side of their job is PROTECTION of American communications).  We know LANL produced a star config quantum encrypted network.  So, why in the world are we shocked the NSA is pursuing a quantum computer???  gah.

Likewise, given the prior knowledge of the Carnivore and ECHELON programs, why are we shocked the NSA has developed more capable skills?!  Naive or more likely false outrage is stupid.  Yes, false outrage.  Everyone spies on everyone and this is the world which spawned STUXNET, the "cyber superpower" which created it ought to be able to get into almost anything.  Thinking otherwise is disingenuous at best.

(PS no clemency.  The turkey, if he were a whistleblower, ought to have just revealed (with evidence) the actions of the NSA against US citizens.  He has revealed more than Manning did and Manning got 35 years)


Thursday, September 05, 2013

So You Think That's Encrypted?

The National Security Agency is winning its long-running secret war on encryption, using supercomputers, technical trickery, court orders and behind-the-scenes persuasion to undermine the major tools protecting the privacy of everyday communications in the Internet age, according to newly disclosed documents.

The agency has circumvented or cracked much of the encryption, or digital scrambling, that guards global commerce and banking systems, protects sensitive data like trade secrets and medical records, and automatically secures the e-mails, Web searches, Internet chats and phone calls of Americans and others around the world, the documents show.

Many users assume — or have been assured by Internet companies — that their data is safe from prying eyes, including those of the government, and the N.S.A. wants to keep it that way. The agency treats its recent successes in deciphering protected information as among its most closely guarded secrets, restricted to those cleared for a highly classified program code-named Bullrun, according to the documents, provided by Edward J. Snowden, the former N.S.A. contractor.

Beginning in 2000, as encryption tools were gradually blanketing the Web, the N.S.A. invested billions of dollars in a clandestine campaign to preserve its ability to eavesdrop. Having lost a public battle in the 1990s to insert its own “back door” in all encryption, it set out to accomplish the same goal by stealth.

The agency, according to the documents and interviews with industry officials, deployed custom-built, superfast computers to break codes, and began collaborating with technology companies in the United States and abroad to build entry points into their products. The documents do not identify which companies have participated.

link.

I have never assumed my information was safe from the determined.  With off the shelf technologies like Bro and the HPC assets plus some really gifted math folks...yeah.  Thinking your data is truly safe is...naive.  You should plan for mitigation, not pure protection.

heh.  Evil meme: What do you want to bet the bitcoin hash really lives in the NSA.