Earlier quoted context omitted.
Is it? NIST has been putting backdoors in recommended encryption standards. USA State Department also classifies strong cryptography as a munition. As far as I know we don't do similar things in Europe (yet?), but I could be wrong.
Europe has dual-use tech export controls - http://www.wassenaar.org/ They're as meaningless as the American versions, only randomly ensnaring companies that sell to a doubleplus ungood entity. They don't do anything to stem the flow of crypto information or open source software to all parts of the globe. And that NIST thing happened possibly once. It's not a common ongoing occurrence.
European Union dedicated questionnaire on the Encryption of Data
101–110 of 113 posts
Re: European Union dedicated questionnaire on the Encryption of Data
#102Earlier quoted context omitted.
Like jbg said in another comment here, the legal system doesn't work that way, where the prosecution can claim you did stuff and you have to disprove the claim. The burden of proof is on the prosecution.
So you are agreeing with me that this tactic of plausible deniability with multiple encryption keys works then? Which is it? Does encryption allow you to hide from the law, or can innocent people just be proclaimed that they are hiding something and that they have to give up keys that don't exist? It is one or the other, because encryption plus multiple keys makes you 'indistinguishable' from an innocent person who t…
The tactic might work, but how well it would work would depend on what other evidence was presented that you do have another encrypted area. For example, if they analyse the partition you gave them the key to and show that it hasn't been booted in 18 months; they cross-reference the cached DHCP leases with the times you were known to have been online using that machine and find discrepancies; they might even have secretly imaged your disk a month earlier and show that a large amount of supposedly free space has changed content in the meantime.
(Maybe they even have you recorded telling someone that you have a second encrypted area on the machine.)
If there's no such evidence, then it ought to be pretty hard to convict you.
Re: European Union dedicated questionnaire on the Encryption of Data
#103Earlier quoted context omitted.
Europe has dual-use tech export controls - http://www.wassenaar.org/ They're as meaningless as the American versions, only randomly ensnaring companies that sell to a doubleplus ungood entity. They don't do anything to stem the flow of crypto information or open source software to all parts of the globe. And that NIST thing happened possibly once. It's not a common ongoing occurrence.
DES is also believed to contain a backdoor. And even if it only happened once, I still don't see how "Europe is farther down this path than the US is currently".
http://www.theverge.com/2016/11/23/13718768/uk-surveillance-...
They've actually had a law requiring you to decrypt on demand since 2007:
http://arstechnica.com/tech-policy/2007/10/uk-can-now-demand...
Nothing like that in the US at all. So, further down the path. France and Germany want similar laws.
http://www.reuters.com/article/europe-attacks-france-germany...
And other countries are joining in the call:
https://www.geektime.com/2016/11/26/5-eu-states-demand-bette...
Re: European Union dedicated questionnaire on the Encryption of Data
#104Earlier quoted context omitted.
Is it? NIST has been putting backdoors in recommended encryption standards. USA State Department also classifies strong cryptography as a munition. As far as I know we don't do similar things in Europe (yet?), but I could be wrong.
Europe has dual-use tech export controls - http://www.wassenaar.org/ They're as meaningless as the American versions, only randomly ensnaring companies that sell to a doubleplus ungood entity. They don't do anything to stem the flow of crypto information or open source software to all parts of the globe. And that NIST thing happened possibly once. It's not a common ongoing occurrence.
(So yes, to the broader point that all the Wassenaar countries implement very similar restrictions).
Re: European Union dedicated questionnaire on the Encryption of Data
#105Earlier quoted context omitted.
Europe has dual-use tech export controls - http://www.wassenaar.org/ They're as meaningless as the American versions, only randomly ensnaring companies that sell to a doubleplus ungood entity. They don't do anything to stem the flow of crypto information or open source software to all parts of the globe. And that NIST thing happened possibly once. It's not a common ongoing occurrence.
DES is also believed to contain a backdoor. And even if it only happened once, I still don't see how "Europe is farther down this path than the US is currently".
DES was weakened in a much more prosaic manner: the effective key size was reduced to 56 bits.
Re: European Union dedicated questionnaire on the Encryption of Data
#106I think this shows the state of our intel community. They've been focused on wide-net operations. If a target is high enough of an asset, why not go the easiest route of installing booby-trapped login screens, hardware keyloggers and what not? It's the easiest and most effective way to spy on someone (I'm sure they already do this.) This is all a ploy to spy on citizens. Period.
Re: European Union dedicated questionnaire on the Encryption of Data
#107Earlier quoted context omitted.
Europe has dual-use tech export controls - http://www.wassenaar.org/ They're as meaningless as the American versions, only randomly ensnaring companies that sell to a doubleplus ungood entity. They don't do anything to stem the flow of crypto information or open source software to all parts of the globe. And that NIST thing happened possibly once. It's not a common ongoing occurrence.
You quote that like Wassenaar is somehow a different thing to the US restrictions, but the US is a member of Wassenaar and ITAR is the USs implementation of it. (So yes, to the broader point that all the Wassenaar countries implement very similar restrictions).
And, of course, the US's treatment of cryptography as munitions predates Wassenaar (the PGP case was previous to it, for instance), not sure about how everyone in Europe handled it prior to the agreement.
Re: European Union dedicated questionnaire on the Encryption of Data
#108Earlier quoted context omitted.
DES is also believed to contain a backdoor. And even if it only happened once, I still don't see how "Europe is farther down this path than the US is currently".
So England is going to just have all this fun by itself? http://www.theverge.com/2016/11/23/13718768/uk-surveillance-... They've actually had a law requiring you to decrypt on demand since 2007: http://arstechnica.com/tech-policy/2007/10/uk-can-now-demand... Nothing like that in the US at all. So, further down the path. France and Germany want similar laws. http://www.reuters.com/article/europe-attacks-france-germany…
Re: European Union dedicated questionnaire on the Encryption of Data
#109Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…
Backdoors and weakened encryption means that there is no encryption going on at all. If any government official can get any information that means anyone can get that information as many of the people who break this stuff don't work for governments and governments are least technically capable actors. So it means there is effectively no encryption all if encryption is weakened or backdoored.
Nonetheless, given your context of "there is no encryption going on at all" I argue does not necessarily hold for a backdoor - or at least not at the outset and if done properly. If the govt backdoor is a key for which huge amount of care is taken to protect and take the extreme example of the govt encrypting the only copy of the key and firing it off in one direction into space - there is a backdoor but this is not necessarily equivalent to "no encryption at all".
Re: European Union dedicated questionnaire on the Encryption of Data
#110Earlier quoted context omitted.
So which department shown on https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/BSI/Orga... has an offensive role? The BND/BSI split as implemented in Germany is relatively unique precisely to separate offensive and defensive concerns. The biggest issue IMHO is that they both report to the same federal office.
Here's some (german) background info on the role. The BSI assisted the BKA in creating a trojan, but tried to hide it from the public: https://netzpolitik.org/2015/geheime-kommunikation-bsi-progr...
I suspect something similar happened here: BKA and some contractors build the trojan software. BVerfG requires that these tools are limited in their impact, and lawyers would also have a field day in court with any case where the software was used, if it can be shown to create security issues and so the BKA requests a security audit from the BSI (that's part of their charter) and gets it. That might have meant some code (in form of patches) flows back, but given that it's the BSI we're talking about, I doubt it.
Unfortunately the BSI is chartered to do security reviews for federal software, so they can't simply refuse. Meanwhile BSI officials are paranoid because they know (from the SINA/ISP surveillance FUD) what public reception of such a job looks like and tries to do PR management (and fails, which surprises probably no-one).