Earlier quoted context omitted.
> but it does give an example of a “working” backdoor setup. I'd argue that it's actually giving the illusion of a working setup - not that the setup actually works.
Well (one of) the arguments has been that it's possible to put in a secure backdoor such that only folks that should have access has access. In this case the government. In China the backdoor as far as I know is only accessible by the government and hasn't been otherwise exposed yet.
Tech firms “can and must” put backdoors in encryption, AG Barr says
111–120 of 130 posts
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#112Earlier quoted context omitted.
It takes a prohibitively long time to knock on 2^256 bricks. The real risks aren't from the crypto; they're from the humans who have access to the back door. Can they be trusted? Can they be compromised? That's not to mention the business damage this would cause. The US is trying to block Huawei products due to back doors. Other countries will block US products if the US government starts requiring back doors.
> It takes a prohibitively long time to knock on 2^256 bricks This assumes you have to knock on 2^256 bricks and not just wiggle the mortar free in one spot. WEP wifi encryption is an example of an implementation failure vs. theoretical time to brute force the encryption.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#113I challenge him to describe what an encryption backdoor actually is. Its like putting a hidden switch behind a brick in a wall. The brick looks the same, but if you take the time to knock on every brick, you'll eventually find the button. Every moderately powerful nations will have someone out there knocking on the bricks.
Ditto larger and more organized criminal organizations.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#114Earlier quoted context omitted.
That's an interesting argument, but only the most extreme interpretation of the 2nd Amendment argues that it covers _all_ munitions. And I'm having trouble finding a contemporary example of someone making this claim. On top of that, we now have years of SCOTUS jurisprudence that "arms" are absolutely subject to _some_ regulations, with the debate focusing on what "some" actually means.
>And I'm having trouble finding a contemporary example of someone making this claim. Maybe you were looking for someone notable, but I'll make it for you right now.
I suppose such an interpretation would have the side effect of making literally any hazardous substance legal to possess.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#115Earlier quoted context omitted.
> It takes a prohibitively long time to knock on 2^256 bricks This assumes you have to knock on 2^256 bricks and not just wiggle the mortar free in one spot. WEP wifi encryption is an example of an implementation failure vs. theoretical time to brute force the encryption.
You're right, but the answer to encryption backdoors can't be "we don't think you'll make good enough backdoors". Even if the backdoor can't be opened by anything other than acquiring the government key, it's still not acceptable.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#116I challenge him to describe what an encryption backdoor actually is. Its like putting a hidden switch behind a brick in a wall. The brick looks the same, but if you take the time to knock on every brick, you'll eventually find the button. Every moderately powerful nations will have someone out there knocking on the bricks.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#117They do not need to hide the backdoor's existences though Just add a 'USGOV BACKDOOR' tab and password/encrypt it or whatever the fuck. It doesn't need to be a real control panel or anything other than trivial options (a grayed-out unchangeable toggle box that says 'Enable backdoor', for instance). I'm not the guy to provide you UI tips. Let users understand it's there without relying on security-through-obscurity. D…
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#118We can have a little test - let's put backdoors on all of law enforcement's encryption usage and see how long it stays safe. I really don't know if people like Barr are arguing in good faith. But then I try to assume incompetence first and malice second.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#119>He also accused tech firms of "dogmatic" posturing, saying lawful backdoor access "can be and must be" done, adding, "We are confident that there are technical solutions that will allow lawful access to encrypted data and communications by law enforcement, without materially weakening the security provided by encryption." This reminds me of the classic article about trisectors https://web.mst.edu/~lmhall/WhatToDoWhe…
"We are confident that there are technical solutions that will allow squaring circles without materially making them not circles." Or drying water, or any number of other impossibilities.
Ice is dry water.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#120Yeah but what's to stop a bad actor simply switching to a provably secure cryptographic system or app? Don't forget there's an arms race going on, where bad actors consistently try to outpace law enforcement by switching to provably secure and private systems. Take for example when 3DES[0] was discovered as insecure and all the criminals switched to AES[1]. And don't forget the old adage: If you outlaw encryption, th…