Earlier quoted context omitted.
Lets say I grant everything you say about the danger to every Alice and Bob that a master key exists. The question is, can policies be enacted and systems put into place that provide a commensurate amount of security for the risk the backdoor key poses? It seems plausible that it can be. But this is the conversation that needs to happen, not the boneheaded claim that its "mathematically impossible" to have a secure s…
> The question is, can policies be enacted and systems put into place that provide a commensurate amount of security for the risk the backdoor key poses? It seems plausible that it can be. It's plausible that the government can permanently keep a key to every lock secure against every attacker? That is such a ridiculous claim that just skipping right to "no, that's impossible" is a completely reasonable thing to do.…
DOJ: Strong encryption that we don’t have access to is “unreasonable”
221–230 of 238 posts
Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”
#222Earlier quoted context omitted.
> The question is, can policies be enacted and systems put into place that provide a commensurate amount of security for the risk the backdoor key poses? It seems plausible that it can be. It's plausible that the government can permanently keep a key to every lock secure against every attacker? That is such a ridiculous claim that just skipping right to "no, that's impossible" is a completely reasonable thing to do.…
This is just lazy. A string of bits that only need to be accessed behind closed doors isn't like any of those other things. What's more, that secret room can be secured arbitrarily well.
You can devise a defense against any attack you can think of, but for a trillion dollar prize someone will find an attack you didn't think of.
And that's the problem. You can say the words "secured arbitrarily well" but in practice you've created a room with the keys to the world in it and your first indication that your security was insufficient is an incalculable catastrophe.
It's like creating a button that gives anyone who presses it three wishes but destroys North America. "Don't worry, we'll put some guards around it" doesn't cut it. Some things need to just not exist.
Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”
#223Earlier quoted context omitted.
> This is different than routine shredding because the moment when they become inaccessible is when you refuse, not the moment you encrypted them. If it really had anything to do with when you refuse then you could just proactively refuse as soon as you encrypt so it happens at the same time. And it would imply that if you were killed before being asked to decrypt then the government would have access to the data bec…
The refusal was specific to this situation. The data also becomes inaccessible the moment a person is incapable of producing the password like when they die. When does encrypted data become inaccessible? When you encrypted them or when you forgot the password?
Inaccessible to which party? It becomes inaccessible to anyone without the key immediately and inaccessible to anyone with the key when they forget the key.
Compare the situation where a person commits a document to memory and then destroys it, but writes down some inscrutable clues to help them remember it. You have some gibberish you can't decipher, if you give them the gibberish they can recreate the original document, but it's only by application of information that exists only in their mind.
Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”
#224Earlier quoted context omitted.
DUAL_EC_DRBG is, in principle, equivalent to encrypting the same data with two separate keys, each one being able to recover the plaintext. There are no "two separate levels at the same time" here: the weakest of these two keys determines your security level. With DUAL_EC_DRBG, one of these keys is a static key which, once leaked, can break every message with a small amount of extra effort. The same applies to the re…
I don't see how this is a substantive reply. Yes, once your key is known you no longer have security. That's true regardless of how many keys your scheme employs. Just like in traditional encryption scenarios, your personal key remaining secret is a part of the assumption. That there are now two secret keys doesn't alter the analysis substantially.
It doesn't, and that's the point. There are no "separate levels" of security. The attacker only has to break one of the keys, whichever is the weakest one. The "security level" of the whole system is the "security level" of its least secure part.
Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”
#225Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”
#226The government has demonstrated that they will abuse every power given to them, and even those that weren't. I would not entrust every aspect of my personal information to the very same organizations that indefinitely detains people, including American citizens, without access to a lawyer while commiting acts of torture; and the ones that said the Patriot Act could never be used for domestic surveilance; that lied ab…
> The government has demonstrated that they will abuse every power given to them, and even those that weren't I think this mixes up what is true and what people (myself included) wish was true. Governments don’t have power given to them. Their default state is God-Kings ruling on personal whims. Governments have power taken from them , either by corporations, or by religions, or by other governments — sometimes these…
Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”
#227Earlier quoted context omitted.
> Do we want to protect our citizens? The only answer is yes. This is not the right question. It is the one they use but is not the right one. "Do we want our citizen able to protect themselves" is the right question. And as most government have shown, they really don't want it. They want to be in charge of the protecting. Once you see things from their perspective their position makes more sense.
But it's funny that the US is so adament about being able to defend yourself with guns. But with software it's a debate. And it seems that often, the people for guns are against encryption and vice versa. From a european perspective it's so strange.
Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”
#228Earlier quoted context omitted.
Let's work through your $1M example. Assume Moore's Law continues for the foreseeable future, so the price of all computation halves every 18 months (ie, every 1.5 years). Then in 15 years, that $1M computation still costs $1000. In 30 years, it can be done for one dollar. Is that good or bad? I guess it depends on your threat model and what the data is worth.
At a technical level, that supposes the file you want to decrypt still exists in X years. My actual thought was to have the secure enclave emit an encrypted copy of the key with a targeted key strength when presented with a request signed by Apple's key. It would require Apple's participation (or compromising Apple) but still require that the person spend a significant amount of money on the process. By having it enc…
Full disclosure: I've been working on some similar ideas for a while. I'll be presenting a high-level pitch for the general concept at the USENIX Enigma conference in January [1]. Also hoping to have a full paper to share on https://eprint.iacr.org/ sometime later this month.
> But we're never going to get to discuss those kinds of scoping and cost-benefit tradeoffs if we don't engage in the process of shaping legislation in an open and honest way.
Agreed. And I'll actually take it one step farther. I think it might make sense for tech companies to adopt a very conservative version of this approach even without a government mandate.
Then the next time the DOJ rolls around to demand somebody turn over their private key (a la Lavabit), or to demand that somebody create a custom OS for them (Apple), we can say "No, we already gave you a way in, just pay the million dollars. Now bugger off and leave me alone."
Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”
#229Earlier quoted context omitted.
I don't really think the timeline is meaningful in this case. Having a rule where people cannot be made to decrypt files is just legalizing document shredding with an extra step. To avoid cases where people legitimately forgot their passwords just assume that the police have video evidence of you unlocking the files just before you were arrested. You know the passphrase and the police could prove it beyond reasonable…
> This is different than routine shredding because the moment when they become inaccessible is when you refuse, not the moment you encrypted them. Not true. The moment you encrypted them, they became inaccessible without your consent.