Some Encryption Protocols Hard-to-Crack, Leaked NSA Documents Show

執筆者
Robert Lemos
Robert Lemos
Published: Jan 2, 2015
Updated: Feb 2, 2021
2 minute read
encryption protocols
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

While many encryption protocols have been broken—or worked around—by the National Security Agency and other intelligence organizations, Internet users hoping to keep their information and communications private should not be entirely disheartened, according to a presentation Dec. 29 at the Chaos Communications Congress hacking convention.

Based on the information from the archive of leaked Snowden documents, the presentation identified the communications technologies, such as Skype, that the NSA routinely monitors and from which it collects data. Yet other technologies—such as the onion routing protocol used by the TOR network and the Zimmerman Real-Time Protocol (ZRTP) used to encrypt communications by voice over IP service providers, such as Silent Circle—have hobbled the agency’s data collection plans, according to documents allegedly leaked by former NSA contractor Edward Snowden and cited by the two presenters, privacy activist Jacob Appelbaum and documentarian Laura Poitras.

“There have … been some victories for privacy, with certain encryption systems proving to be so robust they have been tried and true standards for more than 20 years,” they stated in an article published in Der Spiegel with other co-authors and based on the same research.

A variety of technologies that security professionals thought were secure have actually been either broken by the NSA or pose only minor hurdles for the company. By attacking the routers used to create VPNs based on the IP Security (IPSEC) protocol, the NSA is able to tap into VPN connections, the presenters and their co-authors stated in the Der Spiegel article. In addition, the agency has little problem accessing communications that are encrypted using the secure HTTP (HTTPS) protocol, the basis for much of the purportedly secure communications on the Web, according to Snowden documents cited in the article.

“The NSA and its allies routinely intercept such connections—by the millions,” the Der Spiegel article stated. “According to an NSA document, the agency intended to crack 10 million intercepted https connections a day by late 2012.”

The documents date back to 2012 but are thought to be an accurate representation of the NSA’s current capabilities.

Advertisement

Many people do not use encryption because “they think the intelligence agency experts are already so many steps ahead of them that they can crack any encryption program,” according to the Der Spiegel article. “This isn’t true. As one document from the Snowden archive shows, the NSA had been unsuccessful in attempts to decrypt several communications protocols, at least as of 2012.”

Robert Lemos

Robert Lemos is an award-winning journalist who has covered information security, cybercrime and technology's impact on society for almost two decades. A former research engineer, he's written for Ars Technica, CNET, eWEEK, MIT Technology Review, Threatpost and ZDNet. He won the prestigious Sigma Delta Chi award from the Society of Professional Journalists in 2003 for his coverage of the Blaster worm and its impact, and the SANS Institute's Top Cybersecurity Journalists in 2010 and 2014.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。