Live data from Hacker News

Obama Encryption Policy Rejects Laws Mandating Backdoors

eff.org

61–70 of 78 posts

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#61
post #23

Earlier quoted context omitted.

Because breaking encryption breaks it for everyone. If the cops can get your data, so can a hacker. There is simply no way to compromise. You either are encrypted, in which case nobody but you can decrypt your data, or you're not encrypted at all. Remember the "TSA locks" we're all required to use on our luggage at the airport? Nobody but the government was supposed to be able to unlock them. But now anyone who wants…

I'm not arguing to break encryption. And neither is the white house. They want ways around this stuff- ways that don't break encryption, but if the information is available, then the ability to get to it if necessary. Backdoors don't work because yeah, it breaks the whole system. But not everything is encrypted with these companies, that's just plain.

The White House is pressuring companies to not implement end to end encryption (see, for example, iMessage). Anything short of end to end encryption is considered broken by many people for communications between two parties.

The only way the government can get the equivalent of a wire tap is if there is no end to end encryption. What police do not want is to need to go back to pre-telephone detective work where they need to determine the location at which the parties will communicate (with modern communications there are of course at least two locations) and compromise that location to spy on the supposed criminals.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#62
post #40

Earlier quoted context omitted.

I don't understand why respect would be part of this, or loyalty, patriotism, or whatever. Do you really think the best strategy to defend against an adversary is to shame them into behaving? This is about what's cryptographically possible and what isn't. I don't frankly care if anyone respects my privacy, what I want is the ability to shut adversaries out, period, using math. This decision means companies can say 'n…

Well, being realistic, we have three avenues out of our totalitarian mess we find ourselves deeply in: 1. Political (use money, shame, votes, and threats, praying that these things still work to effect change) 2. Technological (use encryption, praying technological solutions are implemented evenly and properly and that there are no back doors) 3. Violence 1 and 2 are the workable strategies, and they only work when p…

I don't think shame is an effective tactic, because it has no real "stick" component. People will always do what they can.

The only way to stop someone from doing something is to make them unable to do it. That's not solved through shame or appeal to emotion, because the people doing the bad things aren't going to express emotions.

Keep trying to shame them, and you'll simply fail. We need to build something they can't break.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#63
post #23

Earlier quoted context omitted.

Because breaking encryption breaks it for everyone. If the cops can get your data, so can a hacker. There is simply no way to compromise. You either are encrypted, in which case nobody but you can decrypt your data, or you're not encrypted at all. Remember the "TSA locks" we're all required to use on our luggage at the airport? Nobody but the government was supposed to be able to unlock them. But now anyone who wants…

What if there was a way to give only the US government access to the data? For example, somehow have a shared encryption scheme where the user holds a decryption key to decrypt her data, but the government and the company can somehow use their keys in conjunction to decrypt the data as well. (This means company must be complicit in releasing the data, so they have the opportunity to verify/fight the warrant.) If some…

I think the general opinion from the 'cryptowars' in the 90s is that there is no such scheme that does't cripple the actual security of encryption.

Key escrow came up back then though I don't think it included needing multiple keys in order to decrypt - not sure if that's mathematically possible or if there's another reason that never came up. I suppose to the government that's not much different than still needing to compel individuals for the key.

Your point about companies is interesting since things like iMessage could be MITM currently anyway to get unencrypted content for government requests. I think most people don't necessarily trust the company behavior here though and given the government's recently revealed behavior with National Security Letters and secret, massive, unwarranted data collection I don't think they should get a pass. I'd rather side on the power structure unable to collect some of the information even if they're unable to investigate.

I think fundamentally introducing multiple ways to get keys takes a secure system and makes it insecure - the access no longer rests on one individual's knowledge. In general I think that's a bad idea - it also doesn't prevent people who want to actually encrypt their information from doing so (it just harms the regular public and dumber criminals).

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#64
post #2

Deceptive title, unintentionally. FTA: "Instead, the Post reports, the “administration will continue trying to persuade companies that have moved to encrypt their customers’ data to create a way for the government to still peer into people’s data when needed for criminal or terrorism investigations.” While eschewing attempts to legislatively mandate that tech companies build backdoors into their services, the preside…

Umm, I hate to be too nit picky, but the headline isn't deceptive.

"Obama Encryption Policy Rejects Laws Mandating Backdoors"

The Obama administration is rejecting mandated backdoors. That's what the headline says and it's completely correct.

The rest of your comment is correct; they aren't rejecting backdoors, just rejecting making them mandatory.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#65
post #44
post #27

Earlier quoted context omitted.

Crypto is all or nothing. You can't have "backdoors" into crypto algorithms that are secret only to the government. It is literally impossible. Someone will find those backdoors, and now all information that has been encrypted is wide open. So you are either advocating for the complete destruction of ecommerce and online privacy, or you are advocating for unfettered access to cryptography software. Which do you choos…

> Crypto is all or nothing. You can't have "backdoors" into crypto algorithms that are secret only to the government. It is literally impossible. You don't backdoor the algorithm. You backdoor the use of the algorithm--except it is more of a front door than a back door. For instance, when the device encrypts data with a symmetric cipher, encrypt a copy of the symmetric key via a public key cipher using the FBI's publ…

Are you also going to make all other forms of encryption illegal? If not, I'll just pre-encrypt the message with an actually secure mechanism before sending it through the backdoored system.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#66
post #28

Earlier quoted context omitted.

I'd say: first throw out the ability for NSA to spy without letting the persons concerned speak about it. Then we can talk about 'warrants in the case of probable cause'. US as a country has lost a lot of goodwill and trust. And don't forget: - number of deaths from acts of domestic terrorism: 36 - number of deaths–homicide, suicide, and accidental–caused by firearms: 316,545 (in a decade, link: http://magazine.good.…

You think this stuff is just anti-terrorism? The whole reason I even MENTIONED the idea of a warrant is specifically for normal policework. It's the same as searching someone's house after a murder's taken place- just now, instead of reading their files, it's all in a secure place in their computer. Having a reasonable way to read that stuff(WITHOUT USING A BACKDOOR. I don't want weaker crypto just for this- but busi…

Why is it considered different from a physical safe? The government already has the ability and laws to compel citizens to provide access, why should it be any different with encryption?

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#67
post #58
post #49

Earlier quoted context omitted.

Note: That kind of leak is extremely rare, so if that turns out to be the biggest weakness in this system then I think it has achieved my goal of showing that the only options are not completely secure and wide open. If we are using the secret sharing variant, then it means that during the time between the leak and the time the device manufacturers push out an update to replace that key and re-encrypt the appropriate…

Not all that rare (see: OPM leak, any of the other leaks that happen daily) especially with such an incredibly high value target. If it's a symmetric key style system, then wouldn't all previously encrypted communications be vulnerable if they've been recorded someplace? Email, ecommerce, server logs, everything.

Leaks in general aren't rare. Leaks of high value private keys are very rare.

Offhand the only ones I remember are D-Link's leak of a code signing key this year and AMI's leak of a BIOS signing key a couple years ago. I've probably forgotten some.

Keys of this value are generally not stored online, and are often split using a secret sharing system among several people.

It's not hard to set up a system where all of the decryption of the encrypted symmetrical keys of seized phones takes place on a computer that has no network connection and no interface to the outside world other than CD-RW discs [1].

Of course just because there are ways to manage the private key and its use in such system that are arbitrarily safe that doesn't mean that the FBI would actually handle their key properly. If they do lose control of it, it would be bad.

My point, though, was just to illustrate that it is not the case that providing warrant access requires putting in a backdoor that completely opens up the system to anyone who knows about the backdoor and then hoping to keep knowledge of the backdoor hidden.

Also note I'm only trying to design this for data stored on phones and tablets, not for communication systems or servers.

[1] Thumb drives would be more convenient, but they contain electronics and interface via a port that is very hackable.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#68

Earlier quoted context omitted.

You think this stuff is just anti-terrorism? The whole reason I even MENTIONED the idea of a warrant is specifically for normal policework. It's the same as searching someone's house after a murder's taken place- just now, instead of reading their files, it's all in a secure place in their computer. Having a reasonable way to read that stuff(WITHOUT USING A BACKDOOR. I don't want weaker crypto just for this- but busi…

Why is it considered different from a physical safe? The government already has the ability and laws to compel citizens to provide access, why should it be any different with encryption?

It shouldn't be any different. In fact there have been court cases in which individuals have been compelled to provide decryption keys for encrypted disks.

The difference here is that the government wants vastly more access in the digital world than they have in the analog world. It's like asking all safe makers to include a secret combination, unknown to the safe's owner, that can also be used to unlock the safe.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#69
post #35

> the administration will continue trying to persuade companies that have moved to encrypt their customers’ data to create a way for the government to still peer into people’s data If you are one of these companies that are informally cooperating with the government on this, please state so publicly, in the signup process and by message to current users, so that we can avoid using your services now, or at least when…

Well put. We tried to take a very privacy-protective stand when building Recent News (https://recent.io) because of the amount of personalization we do. This warrant canary is part of our privacy policy:

As of [date], we have not received any legal process or demand from any federal, state, or local government that includes a gag order. We have received no National Security Letters, civil subpoenas, search warrants, Foreign Intelligence Surveillance Act orders, grand jury subpoenas, or any other form of compulsory process accompanied by a gag order.

As of [date], we have received no legal orders requiring us to monitor users' future activities or to modify our service.

If we do receive any form of compulsory process from any government entity, we will do our best to ensure that our users' legal rights and privacy rights under the Fourth Amendment to the U.S. Constitution are protected. That includes challenging overly broad orders in court.

It is still valid, I'm happy to say, for [date] values of today.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#70

Earlier quoted context omitted.

What if there was a way to give only the US government access to the data? For example, somehow have a shared encryption scheme where the user holds a decryption key to decrypt her data, but the government and the company can somehow use their keys in conjunction to decrypt the data as well. (This means company must be complicit in releasing the data, so they have the opportunity to verify/fight the warrant.) If some…

I think the general opinion from the 'cryptowars' in the 90s is that there is no such scheme that does't cripple the actual security of encryption. Key escrow came up back then though I don't think it included needing multiple keys in order to decrypt - not sure if that's mathematically possible or if there's another reason that never came up. I suppose to the government that's not much different than still needing t…

> needing multiple keys in order to decrypt - not sure if that's mathematically possible

As a matter of interest Shamirs Secret Sharing algorithm (https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing) is quite nice in that respect. The "secret" would be the decryption key. Using Shamirs Secret Sharing algorithm you could split the key into two so you would need both parts in order to work out the decryption key. The government could have a part. The company could have another. Only when both were combined could anyone work out the decryption key.

This would mean neither the company nor the government could decrypt messages until they work together - and therefore reduce the risk of hackers and rogue employees. It wouldn't break the encryption with dangerous backdoors but would allow the authorities to quickly gain access when needed for a specific investigation.

I doubt anyone would ever implement anything like that since it would be (slightly more) complex and you would have to trust that the decryption parts are valid. But I thought I would just mention it in case anyone else might find that algorithm as interesting as I do.

Post reply on HN