Live data from Hacker News

Times Pulls Article Blaming Encryption in Paris Terror Attack

insidesources.com

271–280 of 312 posts

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#271

> writing messages via in-game functions, like spelling words with dropped items or shooting walls I'm kinda ashamed I haven't thought of that.

It reminded me of the "The Wire"'s Season 5 (I think), where Marlo Stanfield's guys were communicating with each other by sending photos of street maps, which would indicate meetup locations. It now seems easy to catch, but at that time (2008) it was still kind of a new thing to send data (like photos) instead of plain texts.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#272

Earlier quoted context omitted.

The most dangerous terrorists have probably already reverted to couriers with one-time pads. One-time pads are uncrackable, yet they were used extensively before modern cryptography was even invented. They're cumbersome and constrained but very effective. No amount of mass surveillance will alter their efficacy. https://en.wikipedia.org/wiki/One-time_pad

So I read the wiki on the One-time pad and there's something I'm a little stuck on. There's a statement (paraphrasing) that the OTP is immune to cryptanalysis (brute force) because any given key translates to all possible plain-text, and the viable words all have a-priori the same likelihood. The thing I'm stuck on though, isn't it still possible to do semantic analysis on the various permutations. Basically reading…

[deleted]

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#273
post #216

Earlier quoted context omitted.

Not really, because the proposals aren't to go to no encryption but to go to government-backdoored encryption. To an observer you've still just a random stream of bits until someone tries to decrypt it with the backdoor key. Pretty easy to hide in unless we're monitoring every message. And terrorists would be smart - they'd employ non-backdoored encryption, hide that in "legit" communications, and encrypt that with t…

And when the next Snowden publishes the global decryption keys we'll all just update our software together.

Surely you mean "the next Impact Team" (those behind the Ashley-Madison breaches) because Snowden actually went through painstaking lengths to not reveal stuff that would put the public at danger like that.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#274
post #120

Earlier quoted context omitted.

It's even more absurd than that. The premise is that we can have a public worldwide debate that emphasizes how important encryption is to successfully carrying out terrorist attacks, convince the world to give up their privacy for the sake of safety, and after the majority of the protestors have been defeated by public awareness that encryption and terrorism go hand-in-hand, the terrorists will go back to using phone…

My thought is that if we implement a back door policy, the public will have communication links which are much easier to compromise by any party, while terrorists can still easily use encryption and/or steganography to secure their communications. All the back doors accomplish in the end is harming the general public.

It would help conventional law enforcement. Most violent criminals probably don't put enough forethought into their spontaneous attacks to properly avoid notice by the NSA. Unfortunately the NSA doesn't seem to use their resources to secure the nation, and just ignores all the large scale violent crime that goes on daily.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#275
post #262

Earlier quoted context omitted.

So I read the wiki on the One-time pad and there's something I'm a little stuck on. There's a statement (paraphrasing) that the OTP is immune to cryptanalysis (brute force) because any given key translates to all possible plain-text, and the viable words all have a-priori the same likelihood. The thing I'm stuck on though, isn't it still possible to do semantic analysis on the various permutations. Basically reading…

No. What you described will work for a simple substitution cypher, but not for a one time pad. A one time pad is the same length as the message, and permutates every letter independently. Trying all keys will yield every possible plaintext . For example the phrase: "The swallow flies at midnight" May (with a one time pad) be encrypted into "WD4oXOl8yO0QtD4sOf7ip0P7ScIia" (which, incidentally, is indistinguishable fro…

Easy to tell the right sentence because it's the only one capitalized correctly! /s

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#276
post #246

Earlier quoted context omitted.

> I don't think that federal intelligence and law enforcement officials calling for backdoors have fully thought through the consequences I think assuming that level of incompetence is a big claim. It's simply much more likely that the actual plans/goals and the talking points and press releases about the plans/goals are mostly unrelated, as usual. You can infer that those calling for backdoors have decided that call…

> I think assuming that level of incompetence is a big claim. Not really. Have you listened to the average member of Congress lately? Incompetence runs deep throughout all levels of government.

I think largely politicians are very intelligent and competent. What they're not though, is open about their own thoughts. That's not their job. Their job is to reflect what their supporters (financially and votingly) want. If their supporters have wild nonsense ideas, they have to promote those ideas to keep their job. That's why they were elected. We don't choose politicians because they're smart and have good ideas. We choose them because they tell us our own foolish ideas back to us.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#277
post #142

Earlier quoted context omitted.

Encryption is important and is crucial to the security mechanisms that underly the whole internet. I don't think anybody is seriously advocating making encryption illegal. (Which makes your argument pointless.) What does seem being argued for is to mandate adding a 'backdoor' for the government. The counter argument to that is that adding a 'backdoor' makes the encryption pretty much worthless. The weighing of risks…

"Which makes your argument pointless" Of course it doesn't, and that's not what I meant. I didn't mean wholesale outlaw, as in no one would be allowed to use it. Governments can mandate consumer communication technology, for example, like they are trying to do with Apple now. http://betanews.com/2015/11/17/tim-cook-apple-wont-weaken-en...

what could possibly go wrong

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#278
post #262

Earlier quoted context omitted.

So I read the wiki on the One-time pad and there's something I'm a little stuck on. There's a statement (paraphrasing) that the OTP is immune to cryptanalysis (brute force) because any given key translates to all possible plain-text, and the viable words all have a-priori the same likelihood. The thing I'm stuck on though, isn't it still possible to do semantic analysis on the various permutations. Basically reading…

No. What you described will work for a simple substitution cypher, but not for a one time pad. A one time pad is the same length as the message, and permutates every letter independently. Trying all keys will yield every possible plaintext . For example the phrase: "The swallow flies at midnight" May (with a one time pad) be encrypted into "WD4oXOl8yO0QtD4sOf7ip0P7ScIia" (which, incidentally, is indistinguishable fro…

Well-known caveat for people who are familiar with encryption, but it's worth calling out explicitly here:

If you use the same one time pad to encode two or more different messages, then all the sorts of attack proposed here become plausible again.

The security provided by a one time pad relies entirely on the fact that it is only ever used once.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#279
post #20

Earlier quoted context omitted.

Or to put it another way, "If you outlaw encryption, only outlaws will have encryption"

Yes, and that reduces the number of people you need to watch more closely by about 100x.

Watch for what? Random noise? Innocent Looking Traffic? https://www.torproject.org/docs/pluggable-transports.html.en

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#280
I don't know why people are considering these terrorists to be so smart. They arrived at the Stade de France and were naively thinking they'd be able to come inside with explosives tied to them. In January, they didn't even know where the Charlie Hebdo meeting room was, they had to ask for directions and were even sent the wrong way (at first). Really, I'm far from worrying about their communication's encryption as much as I worry about the lax government.
Post reply on HN