Live data from Hacker News

Rethinking Encryption

lawfareblog.com

31–40 of 125 posts

Re: Rethinking Encryption

#31

Earlier quoted context omitted.

It's trivial to lock the USB stick in such a fashion as to be impossible to decrypt in a practical time frame. Furthermore it's practical to communicate in such a fashion that grabbing one party only grants you access to communication intended for this party. If really paranoid it might only grant you access to communication between compromise and his fellows realizing that he is burned. Maybe nothing at all if you c…

All public encryption algorithms have backdoors in their implementation and sometimes (as with Elliptic Curve standards from NIST adopted in the browser) in their spec. You might get lucky if you have a cryptographer design you a custom algorithm but that's mostly security thru obscurity and if a state actor really wanted to defeat it they may just kidnap the cryptographer at gun point and have them reveal how to. Cr…

> All public encryption algorithms have backdoors in their implementation ...

Okay, this is the first time I can recall having ever asked the following:

Source?

I mean, if you're going to make that type of absolute claim, I must ask for some referenes to support same.

Re: Rethinking Encryption

#32

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

China already got golden keys for Chinese iPhones. Apple handed them iCloud.

Re: Rethinking Encryption

#34

Earlier quoted context omitted.

USB stick... I'm sure it'll work out great. What if you have to give it up with a gun to your head? > Hand wavy as heck. Then you meander. Not sure what you're responding to.

It's trivial to lock the USB stick in such a fashion as to be impossible to decrypt in a practical time frame. Furthermore it's practical to communicate in such a fashion that grabbing one party only grants you access to communication intended for this party. If really paranoid it might only grant you access to communication between compromise and his fellows realizing that he is burned. Maybe nothing at all if you c…

> It's trivial to lock the USB stick in such a fashion as to be impossible to decrypt in a practical time frame.

That is definitely not true if your adversary has the ability to control the endpoint and might even reflash the firmware of your USB stick.

If you use OTPs in such a threat scenario it's safest to use old school easy-to-burn paper OTPs with manual encoding/decoding.

Re: Rethinking Encryption

#35

Earlier quoted context omitted.

It's trivial to lock the USB stick in such a fashion as to be impossible to decrypt in a practical time frame. Furthermore it's practical to communicate in such a fashion that grabbing one party only grants you access to communication intended for this party. If really paranoid it might only grant you access to communication between compromise and his fellows realizing that he is burned. Maybe nothing at all if you c…

All public encryption algorithms have backdoors in their implementation and sometimes (as with Elliptic Curve standards from NIST adopted in the browser) in their spec. You might get lucky if you have a cryptographer design you a custom algorithm but that's mostly security thru obscurity and if a state actor really wanted to defeat it they may just kidnap the cryptographer at gun point and have them reveal how to. Cr…

Although you're right that anything but OTPs give you guarantees and that cryptography is still a black art (with lots of unrealistic conditional proofs), good cryptography can be completely open and will be no less secure if it is published, so there is really no need to kidnap the cryptographer.

There is also good reason to assume that if e.g. you make your own Feistel cipher out of existing cryptographic primitives without caring too much about performance, then it will be secure enough against state actors.

Nowadays side channel attacks seem to be the rule, and there is no way to secure the endpoints without developing the whole technology in-house - which is essentially impossible even for organized crime. So the whole discussion is essentially moot, the FBI can buy 0-day exploits on the black market or develop their own like everyone else.

Re: Rethinking Encryption

#37

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court.

One thing the US has going for it is that unlike some countries, is that companies are more scared of their customers than the government.

Re: Rethinking Encryption

#38
post #3

"Going dark" is a good thing... it limits the state's ability to abuse its enormous power (which is already routinely abused, as any student of FBI history or current events should know). However, "going dark" is not what's happening. Only recently had government has this much power to examine, catalog, and track the masses. Instead of debating the ethics of encryption (and trying to outlaw math), we should be debati…

The problem was the fact that the Internet, in its romantic period, "went light" first. "Going dark" is just a return to the balance once knowledge critical mass was reached about the scale of the "went light" event.

Re: Rethinking Encryption

#39
post #37

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court. One thing the US has going for it is tha…

Every three or four months Cisco or Juniper get caught having introduced a new backdoor. Hardcoded admin passwords, full system access backdoors following a specific port knocking sequence, you name it. Sure, some companies have started pushing back but the companies that produce critical network infrastructure can't be trusted.

Re: Rethinking Encryption

#40
post #8

Earlier quoted context omitted.

Every cryptographic protocol has a weakness in its implementation if not in its spec (and if not in the tool itself then in its various dependencies)

Uhh.. no. In fact it doesn't. If your goal is to secure the entire internet via SSL or get people to use PGP signed emails in a mass market then the tremendous technical and cultural hurdles in place that create making a 'truly secure' implementation that gets widely accepted a near impossibility. But if you goal is to secure the communication between trained people in a 'terrorist cell' or other small group then tha…

USB stick? the entertainment industry provides an excellent source for the distribution of 1-time pads, just agree on some particular stream/CD/DVD/etc ("number 27 on this week's top 40") and use the LSBs in some agreed order
Post reply on HN