Hacker News new | ask | show | jobs
by antocv 4447 days ago
Uhm, as NSA and other agencies are responsible for "secure" internal comm, they have methods for that. Sometimes they get broken, probably, but thats their mission to find out, and sometimes let the enemy continue thinking their breakin is effective.

Its the same methods as in 1940, that is, classic intel methods.

Security does not just mean strong crypto algorithms.

If you find your enemy has found a flaw in openssl or some other methods which you are using to communicate - the best way forward is to continue using that - keep the enemy thinking its all good information when its in fact worthless, and move to another method for the real secure stuff, such as steganography or pidgeons.

Anyway, there probably isnt much "really highly, this kills the cat"-type of information goin on the internets, I guess one point of NSA would also be to keep highly classified information to a minimum. Think thats one reason why Navy and others have their own networks parallel to the internet. Where much secrets flow - isolate.

1 comments

These are fair points, but I think the GP comment above was referring as much to political economy type espionage.

Say, for example, china wants to spy on a military contractor. Unless the NSA is sharing its secure pigeon network with every US defense contractor (and many of them, large and small) some pretty important US national security assets might be in play. So, perhaps not "state secrets" but things like technology inside of some tactical weapons guidance systems, or similar. The downside for the NSA of sharing any secret-pigeon networks would op-sec goes down as info dispersal goes up.

* Also for companies like a tesla or a space-x who may have purely industrial know how.

Tactical weapons guidance systems, tesla and space-x, I believe those are in the category of "NSA will secure this with a bit more tools than given to the public as recommendations".

It could be methods like increasing security for those companies gmail accounts - on the Google internal network and all, closing all normal backdoors on Tesla employee computers, installing NSAs own intrusion detection system on them and such.

And to top it off, feed any Chinese and Russian hackers misinformation through honeypots and "accidents".

In Sweden for example during cold war it was quite popular to install extra instrumentation on jets and provide "just for the soviets" technical documentation - seed confusion and such.