HomeSecurityNew round of leaks about the NSA from Edward Snowden

New round of NSA leaks from Edward Snowden

A new round of NSA from Edward Snowden surfaced online late Sunday. The latest PDFs, published by Der Spiegel, show the Five Eyes cyber alliance of five countries that has been working to surveil other countries. The US, the UK, Australia, Canada and New Zealand – all of whom are believed to be working together to circumvent internet security protocols. 

nsa-happy-dance

The leaked files may be a bit old, since they cover the period from 2010 to 2012, but they offer some interesting details about how spies were trying to break strong online encryption.

An 18-page file (PDF) dated June 13, 2011, for example, provides tantalizing details about "A possible technique for deanonymizing TOR network users.".

The investigation reveals that the spies of Britain's secret service GCHQ believed they could hack Tor.

The document is marked "UK TOP SECRET STRAP1 COMINT" and states:

We will present a technique that can deanonymize the given TOR web-browsing packet times between the client and the security node and the packet times from the exit node that are filtered on a single circuit. The false positive rate seems quite low and so we propose to evolve this technique.

The required data is not currently collected. The following additional data sources are required for this technique to work:

  • The Second-accurate packet connects to the TOR that control packets and is characterized by a unique circuit identifier.
  • Second-accurate packet connection between clients, TOR nodes, and the TOR security node. This data could be obtained using SIGINT [signal information] or by running guard nodes. The SIGINT solution would require up-to-date feeds of TOR consensus documents. TOR IP addresses could then be extracted from the consensus documents for filtering by the SIGINT system.

At the time of writing, JTRIG [Joint Threat Research Intelligence Group] is investigating data collection from exit nodes and ICTR-FSP is experimenting with a data stream from guard nodes.

They ultimately concluded that “a broader audit” was necessary to be able to get better results on the “false positive rate.” They recommended that Brit ghosts should try to deanonymize JTRIG using TOR as a first step.

Another GCHQ slide (PDF) shows why the anonymous network is a nuisance to government surveillance.

gchq

"A lot of 'bad' people use Tor," he says, adding, "Secret Services hide content on the Web that continues to exist!", "It's almost impossible to figure out who's talking to whom," "it's complicated.".

Below the documents mention the attempts to decrypt PGP (which continues to be secure (?)), AES (which is constantly under pressure, but there is no evidence that it has been compromised) and OTR (secure, but its implementation was found to be problematic).

Shared secret keys or passwords are required to achieve a VPN breach before they can decrypt the SSL protocols.

To hack a VPN, on the date of the leaked file release, it was necessary to hack into Reuters, or the victim's computer. The last resort would be a court order that would force the company's system administrator to hand over the SSL private keys.

An NSA slide also states that the SSH service had been successfully compromised by the agents.

ssh-nsa

It has long been known that Skype is owned by the NSA and should clearly not be used by anyone concerned about their security. Similarly, there were no surprises that PPTP is broken.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS