[117460] in Cypherpunks

home help back first fref pref prev next nref lref last post

Subject: Re: Project: Hardening Crypto Against Big Brother's "BlackBag" Intrusions

daemon@ATHENA.MIT.EDU (Peter Gutmann)
Fri Sep 3 14:44:11 1999

From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: cypherpunks@cyberpass.net
X-Charge-To: pgut001
Date: Sat, 4 Sep 1999 06:25:08 (NZST)
Message-ID: <93638310801189@cs26.cs.auckland.ac.nz>
Reply-To: pgut001@cs.auckland.ac.nz (Peter Gutmann)

Sunder <sunder@brainlink.com> writes:

>A simple {datalink layer} sniffer whether implemented in hardware or software
>will be able to gain access to both the encrypted and freshly plaintexted
>streams.  A keyboard sniffer will still be able to get at your typed emails,
>and a video sniffer will still be able to read what you read.

Sure, that's possible, but I think most users will probably notice the 
appearance of the extra T1 labelled "NSA use only" which is used to carry all
this data out of their office/house/whatever.  The point of a black bag job is
to get in, plant/remove something, and get out again as quickly as possible
without leaving any traces.  By using a crypto box, you're forcing the bad 
guys to spend hours tearing the place apart looking for whatever it is they 
need to compromise before they can even start trying to compromise it and/or 
requiring the establishment of a secure, undetectable high-bandwidth channel 
to get plaintext data out if they can't compromise the crypto box itself.  I 
don't think anyone below the company management level has any illusions about 
the true security of a Windows box, and Unix boxen often aren't that much 
better, by putting the crypto in a physically separate environment your're 
getting something which requires an attacker to actually go to the hardware 
and physically attack it, rather than having your security compromised when 
you read your mail or view a web page located on the other side of the planet.

>You still need to harden the host machine somewhat.  Now to make things
>hardware bug resitant, you could force yet another layer of encryption 
>between the PC and the device, so off the shelf spookware hardware sniffers 
>won't work, but if you cannot prevent hardware attacks, you can't ensure that 
>your OS is truly secure.

If an attack of this level is a real concern to an organisation then I suspect
they need a lot more help than any kind of crypto can ever give them (massive
physical/personnell security, TEMPEST protection, all the stuff the we'd-have-
to-kill-you-afterwards crowd specialise in).

Peter.


home help back first fref pref prev next nref lref last post