Live data from Hacker News

Rethinking Encryption

lawfareblog.com

41–50 of 125 posts

Re: Rethinking Encryption

#41

Earlier quoted context omitted.

All public encryption algorithms have backdoors in their implementation and sometimes (as with Elliptic Curve standards from NIST adopted in the browser) in their spec. You might get lucky if you have a cryptographer design you a custom algorithm but that's mostly security thru obscurity and if a state actor really wanted to defeat it they may just kidnap the cryptographer at gun point and have them reveal how to. Cr…

Although you're right that anything but OTPs give you guarantees and that cryptography is still a black art (with lots of unrealistic conditional proofs), good cryptography can be completely open and will be no less secure if it is published, so there is really no need to kidnap the cryptographer. There is also good reason to assume that if e.g. you make your own Feistel cipher out of existing cryptographic primitive…

>

The key is "your own"

By "public" I don't mean that their spec is "published" but that their implementation is open source and has various 3rd party contributions and dependencies, as is the case with most OSS.

So if you build your own, and it's good against the NSA, they'd come after you if they have to, unless it costs them less to crack it.

I agree ultimately with your assessment that side channel attacks make this whole discussion moot. But my original point was and still is: nothing is secure against a determined and well resourced adversary. So people out there shouldn't get the wrong idea that cryptography is an invisibility cloak or some such

Re: Rethinking Encryption

#42

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

China already got golden keys for Chinese iPhones. Apple handed them iCloud.

I'm not saying you're wrong, but I haven't been able to find a source for this - only mentions of a new datacenter in China. A citation would be nice.

Re: Rethinking Encryption

#43
post #37

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court. One thing the US has going for it is tha…

> 9/11 is almost a decade in the past

I assume you mean two decades?

(unless I'm missing the point and you are referring to some specific fall-out from that event that had particular significance at a point ten years after?)

Re: Rethinking Encryption

#44
post #37

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court. One thing the US has going for it is tha…

A warrant canary is utterly useless as a defense. Any secret legal order to alter IT systems (the specific threat model it is most often suggested for) can logically also include an order to maintain a fake warrant canary.

Re: Rethinking Encryption

#45

Earlier quoted context omitted.

China already got golden keys for Chinese iPhones. Apple handed them iCloud.

I'm not saying you're wrong, but I haven't been able to find a source for this - only mentions of a new datacenter in China. A citation would be nice.

https://support.apple.com/en-us/HT208351

Re: Rethinking Encryption

#46
post #40
post #8

Earlier quoted context omitted.

Uhh.. no. In fact it doesn't. If your goal is to secure the entire internet via SSL or get people to use PGP signed emails in a mass market then the tremendous technical and cultural hurdles in place that create making a 'truly secure' implementation that gets widely accepted a near impossibility. But if you goal is to secure the communication between trained people in a 'terrorist cell' or other small group then tha…

USB stick? the entertainment industry provides an excellent source for the distribution of 1-time pads, just agree on some particular stream/CD/DVD/etc ("number 27 on this week's top 40") and use the LSBs in some agreed order

A one time pad must be truly random to be secure. A music stream is far from that.

Re: Rethinking Encryption

#48
Interesting speech by William Barr:

https://www.c-span.org/video/?464971-3/attorney-general-barr...

"Only two ways to protect society ... 1) Ability to detect and apprehend criminals .. 2) Regiment society as a whole"

"Our ability to protect the public from criminal threats is rapidly deteriorating"

"Status quo is exceptionally dangerous"

Re: Rethinking Encryption

#49

This is all theater to give people a warm-fuzzy about the way things are. Other than cock-blocking ISPs, what's the value in end-to-end encryption when one of those ends is a megacorporation that is A) super-friendly with the state security apparatus, and B) ready, willing, and able to sell you out to the highest bidder? E2E works great against basement-dwelling h4x0rs, not so much against people with actual power. I…

To be clear, E2E from your-own-server to your-own-server is wonderful. E2E from your google/apple/amazon surveillance device to google/apple/amazon servers is turf guarding.

Say I want to block such-and-such domain. With unencrypted DNS, I put a record in my own resolver, and problem solved. With per-app DNS over HTTPS, my infrastructure is out of the loop, and SV has total control.

Re: Rethinking Encryption

#50
> But going dark is broader than encryption; it involves the decreasing ability of the government to conduct effective lawful surveillance for many technical reasons, including but not limited to the widespread adoption of encryption technology.

The 'going dark' boogeyman - how predictable. Only in the mind of a spy agency shill does the rapidly growing number of surveillance cameras, facial recognition, flying surveillance drones with high-resolution cameras over cities, and interception of all communication metadata (if not the content), equate to decreasing ability. They won't be happy until we are stripped of even the last tiny scrap of privacy.

Post reply on HN