Profile picture
Micah Lee @micahflee
, 7 tweets, 2 min read Read on Twitter
We just published a Snowden document from 2006 about NSA successfully breaking the encryption and spying on VPNs run by Al Jazeera, the Iraqi military, airlines and reservation systems, and other "high potential" targets theintercept.com/2018/08/15/nsa…
VPNs are complicated. There are many protocols, and each can be configured in many ways to make it more or less secure. Exactly which VPNs NSA can crack is a closely-guarded secrets, and the Snowden archive doesn't contain the answer.

But it's clear they can't crack everything.
Analysts that discover VPN traffic can submit it to an NSA tool called VIVIDDREAM to learn whether or not NSA can likely exploit it, all while hiding sensitive info about the exploits *from the analysts themselves* theintercept.com/document/2018/…
There are several other docs in the Snowden archive about NSA's VPN hacking capabilities, and much of this has already been reported years ago, such as NSA's HAMMERSTEIN router malware that can crack some VPNs theintercept.com/2014/03/12/nsa…
In 2015, a group of 14 cryptography researchers published a paper called Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice, along with the Logjam attack. I think it's likely that this is how NSA broke into those "high potential" VPNs weakdh.org
All that said, I think what it takes to run a VPN that NSA can't exploit* is to use good protocol (don't use PPTP, probably avoid IPSec, but OpenVPN seems good) and choose good ciphersuites and other settings. Too many VPNs are simply badly configured
* By "NSA can't exploit", I mean directly using VPN exploits. They can still do things like hack your sysadmin's laptop to get in
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to Micah Lee
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member and get exclusive features!

Premium member ($3.00/month or $30.00/year)

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!