{"id":7803,"date":"2013-09-09T10:22:12","date_gmt":"2013-09-09T15:22:12","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=7803"},"modified":"2015-03-10T19:10:18","modified_gmt":"2015-03-10T23:10:18","slug":"subverting-the-ipsec-standards-process","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2013\/09\/09\/subverting-the-ipsec-standards-process\/","title":{"rendered":"Subverting the IPSec Standards Process"},"content":{"rendered":"<p><a href=\"http:\/\/www.mail-archive.com\/cryptography@metzdowd.com\/msg12325.html\">John Gilmore<\/a> (via <a href=\"https:\/\/twitter.com\/timoreilly\/status\/376747045996212224\">Tim O&rsquo;Reilly<\/a>):<\/p>\r\n<blockquote cite=\"http:\/\/www.mail-archive.com\/cryptography@metzdowd.com\/msg12325.html\">\r\n<p>Every once in a while, someone not an NSA employee, but who had longstanding ties to NSA, would make a suggestion that reduced privacy or security, but which seemed to make sense when viewed by people who didn&rsquo;t know much about crypto.  For example, using the same IV (initialization vector) throughout a session, rather than making a new one for each packet.  Or, retaining a way to for this encryption protocol to specify that no encryption is to be applied.<\/p>\r\n<p>The resulting standard was incredibly complicated&mdash;so complex that every real cryptographer who tried to analyze it threw up their hands and said, &ldquo;We can&rsquo;t even begin to evaluate its security unless you simplify it radically&rdquo;. [&#8230;] That simplification never happened.<\/p>\r\n<p>The IPSEC standards also mandated support for the &ldquo;null&rdquo; encryption option (plaintext hiding in supposedly-encrypted packets), for 56-bit Single DES, and for the use of a 768-bit Diffie-Hellman group, all of which are insecure and each of which renders the protocol subject to downgrade attacks.<\/p>\r\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>John Gilmore (via Tim O&rsquo;Reilly): Every once in a while, someone not an NSA employee, but who had longstanding ties to NSA, would make a suggestion that reduced privacy or security, but which seemed to make sense when viewed by people who didn&rsquo;t know much about crypto. For example, using the same IV (initialization vector) [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"","apple_news_api_id":"","apple_news_api_modified_at":"","apple_news_api_revision":"","apple_news_api_share_url":"","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[705,476,48],"class_list":["post-7803","post","type-post","status-publish","format-standard","hentry","category-technology","tag-nsa","tag-networking","tag-security"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=7803"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7803\/revisions"}],"predecessor-version":[{"id":10754,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7803\/revisions\/10754"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=7803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=7803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=7803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}