How the NSA Breaks Crypto at Scale
Cohney asked how the NSA decrypts traffic at scale. Three theories: brute force with a billion-dollar data center, hardware implants, or AI. AES-128 is too strong for brute force. Implants explain targeted attacks, not mass interception. The real answer is a mix. The NSA influences standards and certification to embed weaknesses before products ship. That allows passive decryption of TLS handshakes across millions of devices.
The ANX9.31 Random Number Generator and Hardcoded Keys
The FIPS-approved ANX9.31 RNG used a timestamp as entropy and a block cipher key. The standard did not specify that the key must be dynamic. Cohney reviewed all 300 CMVP certificates and found 12 devices with hardcoded keys. One was FortiOS v4, which used the test vector key from the standard. With that key, an attacker can invert the RNG output, guess the 2^28 timestamp, and decrypt TLS traffic. The brute force took 2^25 operations.
Counter DRBG and Side Channel Attacks
The successor Counter DRBG replaced the timestamp with an incrementing counter and made additional entropy optional. Most manufacturers skipped the entropy. The design allowed generating many output blocks under the same key before refreshing. Cohney used a side channel attack to recover the AES key during that phase. He then extracted long-term client ECDSA secrets from FortiOS v5. The attack worked because FIPS 140-2 did not require side-channel hardening.
Dual EC DRBG and the Juniper ScreenOS Backdoor
Dual EC DRBG was standardized despite known distinguishing attacks. Snowden slides confirmed the NSA influenced standards. Juniper’s ScreenOS used Dual EC chained with ANX9.31. An unauthorized actor changed the curve points, exposing raw Dual EC output. Over multiple patches, the ANX9.31 chaining was removed, making the backdoor viable. Cohney demonstrated the attack on a purchased device. Public reporting attributed the code changes to a Chinese state-sponsored group.
Pre-Supply Chain Operations
Cohney defined a “pre-supply chain operation” (PSYCHO) as corrupting the design, standardization, and certification stages before a product is built. Techniques include binding regulations that force fragile implementations, mandating design flaws (e.g., 56-bit DES keys), choosing weak parameters (Dual EC), and excluding side channels from threat models. Examples include Simon/Spec ciphers, export-grade cryptography, the Logjam attack on Diffie-Hellman groups, and the TETRA radio encryption flaw.
Q&A
What RNG design would you recommend today? Use CPU instructions for entropy, then run through a cryptographic RNG like HMAC DRBG with additional jitter sources. ▶ 53:58
Notable Quotes
standardization is not security Shaanan Cohney · ▶ 47:33
certification is not an audit Shaanan Cohney · ▶ 48:13
nobody but us back door Shaanan Cohney · ▶ 32:38
pre-supply chain operation Shaanan Cohney · ▶ 36:34
Key Takeaways
- Standardization does not guarantee security; broken standards plus broken implementations enable real attacks.
- Certification programs like CMVP are not audits and miss side-channel vulnerabilities.
- State-level adversaries target the design phase, not just the supply chain, to achieve mass decryption.
About the Speaker(s)
Dr. Shaanan Cohney is the Deputy Head of the School of Computing and Information Systems at the University of Melbourne. His research uses computer science techniques to address public policy problems. He won a 2016 Pwnie for Best Cryptographic Attack and multiple best paper awards. He has worked as a fellow for Senator Ron Wyden and at the FTC. He has a history of getting into the right sorts of trouble.