D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OT: NSA: Do they or don't they?

 

On Fri, 6 Sep 2013, Philip Hudson wrote:
Dancing around saying clearly whether PGP has been cracked or not. What do you think? Non-tech journo so hard to tell and harder to know whether to rely on his analysis.

https://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html?pagewanted=all

The article doesn't mention PGP, but here is Phil Zimmermann quoted saying that he doesn't believe PGP to have been cracked:

http://wapo.st/1aaRi6r

Obviously, he has a vested interest in saying this. And I don't find his argument that the US government still uses PGP so it can't have been cracked very strong: the NSA and GCHQ are pretty secretive about what they have cracked and I can see why it would be in the former's interest to be able to decrypt government documens.

But Bruce Schneier, who has seen the original documents, has been quoted saying "math is good, code has been subverted".

In other words, (most) algorithms haven't been cracked. Implementations have. That's the more boring version of the story, but even without Schneier's quote would have been the most likely one.

Martijn.

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq