Live data from Hacker News

Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

rietta.com

121–130 of 139 posts

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#121
post #119

Earlier quoted context omitted.

Of course, that perfection is achieved by shifting all your risk to key distribution. I think of OTPs as a form of time-shifting. Think of it this way: if you and your correspondent have viable OTPs, that implies that, at some point in the past, you securely communicated that OTP. Since it is (at least) the length of a future message, you could have just passed a secure message then. Instead, you passed something tha…

Imagine implementing your amazing solution in real life. I don't see a situation being frequent where you'd know the message weeks or months in advance of when you send it. If we follow your scheme, there's no encryption; we just meet up when we need to communicate. What if we're on opposite sides of the earth? If we had exchanged keys months earlier, this wouldn't be a problem.

I must have explained poorly. I was not proposing "just communicate securely in advance". I was highlighting the problem with OTPs.

The fact that your key material is the same size as the message means all your security is in the key, thus in your key distribution method. Among other problems, this means no rekeying without replicating your original hand-off - you can communicate exactly as many bits as your previously securely exchanged, no more.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#122
post #121

Earlier quoted context omitted.

Imagine implementing your amazing solution in real life. I don't see a situation being frequent where you'd know the message weeks or months in advance of when you send it. If we follow your scheme, there's no encryption; we just meet up when we need to communicate. What if we're on opposite sides of the earth? If we had exchanged keys months earlier, this wouldn't be a problem.

I must have explained poorly. I was not proposing "just communicate securely in advance". I was highlighting the problem with OTPs. The fact that your key material is the same size as the message means all your security is in the key, thus in your key distribution method. Among other problems, this means no rekeying without replicating your original hand-off - you can communicate exactly as many bits as your previous…

> means all of your security is in the key

...erm, isn't that the point?

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#123
post #112
post #46

Earlier quoted context omitted.

The Clintons and Al Gore have their paws all over the Clipper Chip.

It's a grave mistake to demonize a single politician you dislike: if it were that simple, they'd have dropped it as soon as that one person left office. In reality, there's a large community pushing for things which they perceive as making their job easier and that persists across administrations — that started well before Clinton ran for office and certainly didn't end after he left.

You are putting words in my mouth. I demonize no one.

My feelings about them (The Clintons) have indeed declined over the years. I mostly have huge respect for Al Gore. But my personal feelings have absolutely nothing do to with their material involvement with the Clipper Chip. Nor do I care when it started. They all carried the baton of government key escrow which is not something I am going to forget. It is a grave mistake to not hold people accountable for their actions, to not take a stand while the bureaucracy pushes you along with the current.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#124
post #21

Just think of the outrage if the government required master keys to everyone's homes? I know there is a difference, but it's not a huge leap to compare the two. We don't want the government to have such easy access to our homes because we can't trust every government employee not to abuse it. I think the same goes here. No mater what safe guards you put in place it's a scary thought that you simply can't keep the gov…

Government already has master key to anyone's home. They'll just break the door, it can be done easily. Proper encryption is a different beast, you just don't have that option to break the door.

Breaking a door is not the same as having its master key. It's a flaw of the door. Encryption can be broken as well, but everyone has encryption that is better at not breaking than most doors.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#125
post #118

The US Department of Defense arguably runs the most extensive key escrow system in the world. Every DoD employee and many contractors have Common Access Cards (CAC) that contain email encryption keys that are escrowed with DISA.

God I love Starship Troopers. Heinlein was a true patriot.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#126
post #121

Earlier quoted context omitted.

I must have explained poorly. I was not proposing "just communicate securely in advance". I was highlighting the problem with OTPs. The fact that your key material is the same size as the message means all your security is in the key, thus in your key distribution method. Among other problems, this means no rekeying without replicating your original hand-off - you can communicate exactly as many bits as your previous…

> means all of your security is in the key ...erm, isn't that the point?

Speaking of points, I can't tell if you're intentionally missing mine, but either way this is unproductive. If you're sincerely confused, please read up a bit. The Wikipedia page isn't a terrible place to start.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#127

The irony here is that simple one-time-pad solutions (OTP) will continue to be available to securely encrypt the sort of messaging that's of use to terrorists (relatively short infrequent messages), instead it's the general communications (including for banking) that the rest of us perform online that will be made vulnerable. You don't even have to program or use a computer to create these OTP solutions, for limited…

> instead it's the general communications (including for banking) that the rest of us perform online that will be made vulnerable

Hardly ironic at all, since as long as someone stands to gain either money or power from doing so, they will simply do so under guise of the former.

Not ironies, just tactics.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#128
post #126

Earlier quoted context omitted.

> means all of your security is in the key ...erm, isn't that the point?

Speaking of points, I can't tell if you're intentionally missing mine, but either way this is unproductive. If you're sincerely confused, please read up a bit. The Wikipedia page isn't a terrible place to start.

No I mean I understand where OTP falls short, but you're either really bad at conveying your viewpoint, or you're simply plain wrong.

Yes, with OTP you need to exchange keys and this shifts all of the security to key exchange, and while this wouldn't be a problem in other ciphers, it's a problem in OTP because of its other properties and shortfalls.

So at most I feel as though it's a security/convenience tradeoff; a tradeoff that's substantial or even dangerous in certain situations.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#129
post #21

Just think of the outrage if the government required master keys to everyone's homes? I know there is a difference, but it's not a huge leap to compare the two. We don't want the government to have such easy access to our homes because we can't trust every government employee not to abuse it. I think the same goes here. No mater what safe guards you put in place it's a scary thought that you simply can't keep the gov…

I think its not a correct comparison. The reason government doesn't have or need keys to every house, because no matter how many lock you put on your door, government (SWAT team, for example) can break in anyways, if deem necessary. So for this reason alone if they truly want to... every house can be and will be open to them, no matter what. Meanwhile here the locks are based on sophisticated math.. and that math is…

I am reminded of a quote from The Princess Bride: "...you cannot track it, not with a thousand bloodhounds, and you cannot break it, not with a thousand swords." And that just infuriates the prince, to the point where he just has to go destroy something beautiful, out of spite.

People put locks on their homes to keep criminals out. It does not matter if the government can break those locks, until the government itself begins to act like a criminal. At that point, it becomes necessary to build locks that even a government cannot break.

The Snowden alarum showed us all that a portion of the US government has become functionally indistinguishable from an organized crime ring. So, sorry Comey, but perhaps the FBI should focus for a while on investigating and burning out the criminal corruption within its own umbrella organization before we talk about maybe allowing it the power to intrude upon our personal lives at will, in the name of the greater good.

By the house metaphor, law enforcement is more like vampire legends. The vampire has the strength to batter down any door, but if it crosses the threshold without first being invited inside, it loses its power. Except the cop-vampire can also be invited in by a magistrate who issues a warrant.

And perhaps even that is too lenient. Maybe our warrants should be issued by a grand jury. Allowing them to be issued by a sole judge, or panel of judges, seems an invitation to erect secret, rubber-stamp courts like those used for FISA warrants. Maybe your secret keys should be protected by an M-of-N consensus algorithm using about 30 cryptographically-random peers. The government then has to convince a bunch of presumably reasonable strangers that it should be allowed access to your keys. Should be no problem if you're a dangerous criminal, but impossible if the state just wants to sniff around in your dirty drawers.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#130
post #112
post #46

Earlier quoted context omitted.

The Clintons and Al Gore have their paws all over the Clipper Chip.

It's a grave mistake to demonize a single politician you dislike: if it were that simple, they'd have dropped it as soon as that one person left office. In reality, there's a large community pushing for things which they perceive as making their job easier and that persists across administrations — that started well before Clinton ran for office and certainly didn't end after he left.

If you disagree with someone, the right thing to do is to put forward your own side of the argument. It isn't polite to simply disregard what someone says because of your conceptions about where that belief is coming from.
Post reply on HN