Showing posts with label PGP. Show all posts
Showing posts with label PGP. Show all posts

20130824

September 1, 2000: A pocket guide to NSA sabotage

The NSA engages in sabotage, much of it against American companies and products. One campaign apparently occurred at about the time when PGP's most serious vulnerability was added. To understand the whole story requires some background.

 In Bruce Schneier's newsletter Crypto-Gram he told us last year about Lew Giles, said to be an NSA saboteur wrecking American privacy products in 1997. Schneier says that according to several sources Giles went from company to company, asking them to destroy the security of their own products, and arranging cover stories to protect them. According to Crypto-Gram sometimes Giles worked directly with engineers, with no managers around. The sabotage was always supposed to look like a mistake. At about the same time, PGP introduced "key recovery" with the hidden flaw recently covered worldwide, including Schneier's own clear description in Slashdot.

Other serious vulnerabilities have been found in the PGP versions released then. For example, just last May PGP was found to generate weak keys on Linux and OpenBSD. The original report in BugTraq says the bug was introduced in version 5.0, released in 1997... http://cryptome.org/nsa-sabotage.htm

20120525

German intelligence agencies can decrypt PGP

The federal government declared that its intelligence agencies generally are able, to decrypt PGP and Secure Shell, at least in part. Used for monitoringapplications would be the German company Utimaco, and Ipoque Trovicor to report members of the Bundestag. But the statements are vague and the PGP encryption is not mathematically decoded.

The federal government claims that the German intelligence services were able to decrypt PGP. This is clear from the response (PDF) to a parliamentary question by members of the small party left the show...

http://translate.google.com/translate?sl=de&tl=en&js=n&prev=_t&hl=en&ie=UTF-8...://www.golem.de/news/bundesregierung-deutsche-geheimdienste-koennen-pgp-entschluesseln-1205-92031.html