Snowden documents reveal the NSA routinely intercepted SSL/TLS traffic, decrypted VPN connections, struggled with PGP, Truecrypt, Tor, CSpace, OTR, ZRTP in 2012
Inside the NSA's War on Internet Security — US and British intelligence agencies undertake every effort imaginable to crack …
Context & Ripple Effects
The Spiegel report maps the NSA's crypto offensive as of 2012: bulk interception of SSL/TLS was routine and VPN decryption worked, but a short list of tools — PGP, Truecrypt, Tor, CSpace, OTR, ZRTP — held up. That split line between broken and unbroken transport security is the document's real content.
It also fits a pattern the later Snowden disclosures keep confirming: when the math resists, the agencies go around it — exploiting Juniper firewalls at the network edge in 2011, reverse-engineering antivirus products like Kaspersky to harvest exploits, and even turning privacy software itself into a feed for tracking bitcoin users by 2013.
First-order effects
- Anyone relying on SSL/TLS or VPN tunnels in 2012 had their traffic readable to the NSA and its British counterpart, while users of Tor, PGP, Truecrypt, OTR, CSpace and ZRTP were outside the agency's demonstrated reach.
Second-order effects
- The failure list doubles as a target list: the same disclosure trail later shows GCHQ and the NSA shifting to firewalls, antivirus vendors, and repurposed open-source and privacy tooling — attacking implementations and endpoints rather than the ciphers themselves.
Third-order effects
- If the pattern holds, national-security pressure on encryption migrates from cryptanalysis to supply chains and software ecosystems, making vendor security practices — not algorithm strength — the decisive variable for encrypted communications.
The trend: Signals intelligence is shifting from breaking encryption mathematics to compromising the software supply chain and endpoints around it, with each Snowden disclosure revealing another layer of that workaround economy.