[117460] in Cypherpunks
Subject: Re: Project: Hardening Crypto Against Big Brother's "BlackBag" Intrusions
daemon@ATHENA.MIT.EDU (Peter Gutmann)
Fri Sep 3 14:44:11 1999
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: cypherpunks@cyberpass.net
X-Charge-To: pgut001
Date: Sat, 4 Sep 1999 06:25:08 (NZST)
Message-ID: <93638310801189@cs26.cs.auckland.ac.nz>
Reply-To: pgut001@cs.auckland.ac.nz (Peter Gutmann)
Sunder <sunder@brainlink.com> writes:
>A simple {datalink layer} sniffer whether implemented in hardware or software
>will be able to gain access to both the encrypted and freshly plaintexted
>streams. A keyboard sniffer will still be able to get at your typed emails,
>and a video sniffer will still be able to read what you read.
Sure, that's possible, but I think most users will probably notice the
appearance of the extra T1 labelled "NSA use only" which is used to carry all
this data out of their office/house/whatever. The point of a black bag job is
to get in, plant/remove something, and get out again as quickly as possible
without leaving any traces. By using a crypto box, you're forcing the bad
guys to spend hours tearing the place apart looking for whatever it is they
need to compromise before they can even start trying to compromise it and/or
requiring the establishment of a secure, undetectable high-bandwidth channel
to get plaintext data out if they can't compromise the crypto box itself. I
don't think anyone below the company management level has any illusions about
the true security of a Windows box, and Unix boxen often aren't that much
better, by putting the crypto in a physically separate environment your're
getting something which requires an attacker to actually go to the hardware
and physically attack it, rather than having your security compromised when
you read your mail or view a web page located on the other side of the planet.
>You still need to harden the host machine somewhat. Now to make things
>hardware bug resitant, you could force yet another layer of encryption
>between the PC and the device, so off the shelf spookware hardware sniffers
>won't work, but if you cannot prevent hardware attacks, you can't ensure that
>your OS is truly secure.
If an attack of this level is a real concern to an organisation then I suspect
they need a lot more help than any kind of crypto can ever give them (massive
physical/personnell security, TEMPEST protection, all the stuff the we'd-have-
to-kill-you-afterwards crowd specialise in).
Peter.