Live data from Hacker News

Rethinking Encryption

lawfareblog.com

61–70 of 125 posts

Re: Rethinking Encryption

#61
post #37

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court. One thing the US has going for it is tha…

>Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back.

Yeah, that's not exactly the case...

Re: Rethinking Encryption

#62
post #45

Earlier quoted context omitted.

I'm not saying you're wrong, but I haven't been able to find a source for this - only mentions of a new datacenter in China. A citation would be nice.

https://support.apple.com/en-us/HT208351

Well, China issues aside, that should be the case in every country -- such services should be local, governed by local laws, and not giving a free-pass to foreign countries/governments (foreign as to the users of the service) to enforce their laws/surveillance.

E.g. I would like the EU iCloud to be hosted in EU.

Re: Rethinking Encryption

#64
post #59

> But going dark is broader than encryption; it involves the decreasing ability of the government to conduct effective lawful surveillance That wasn't an ability of government in 1900 or 1800, so why should we worry that this new-fangled ability has been decreasing lately? Who said it should be an ability for government, and much more, an eternal one, and not a temporary accidental capability due to a few technical d…

While I agree with you, I can also appreciate that intelligence/law enforcement agencies are not keen to go back to the alternatives. HUMINT is a nasty (in the moral sense), dangerous, and expensive enterprise. Would you rather train for a few years, then live a fake life with the constant threat of gruesome death, lying to everyone you know - possibly even your fake wife and kids or rather just tap a few phones/emails?

It's no wonder that most agencies have pretty much entirely dropped their expertise on this as soon as the alternative showed up. I don't think they are geared up to get back into that game.

Re: Rethinking Encryption

#65
post #37

Earlier quoted context omitted.

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court. One thing the US has going for it is tha…

A warrant canary is utterly useless as a defense. Any secret legal order to alter IT systems (the specific threat model it is most often suggested for) can logically also include an order to maintain a fake warrant canary.

Part of the theory of a warrant canary is that compelled speech (and in particular a compelled lie) may be easier to challenge than suppressed speech. While that isn't definitive, there's some jurisprudence to back that theory. If you have a warrant canary, you should be prepared to challenge any such order in court and use that as the defense.

Re: Rethinking Encryption

#66
post #19

I'm confused at the assumption that you can prevent serious organized criminals from having access to strong cryptography simply by backdooring common communications apps. The genie is out of the bottle: Powerful criminal enterprises will have no difficulty hiring people to build overlay tools that they can run inside their backdoored comms that will provide adequate (at least, if not effectively unbreakable) cryptog…

The NIBOR (Nothing Is Beyond Our Reach) proposal addresses the issue of cryptography inside backdoored devices by installing a virtual machine underneath.

As discussed in following article, NIBOR also combats steganography: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3425957

Re: Rethinking Encryption

#67
post #59

> But going dark is broader than encryption; it involves the decreasing ability of the government to conduct effective lawful surveillance That wasn't an ability of government in 1900 or 1800, so why should we worry that this new-fangled ability has been decreasing lately? Who said it should be an ability for government, and much more, an eternal one, and not a temporary accidental capability due to a few technical d…

While I agree with you, I can also appreciate that intelligence/law enforcement agencies are not keen to go back to the alternatives. HUMINT is a nasty (in the moral sense), dangerous, and expensive enterprise. Would you rather train for a few years, then live a fake life with the constant threat of gruesome death, lying to everyone you know - possibly even your fake wife and kids or rather just tap a few phones/emai…

>HUMINT is a nasty (in the moral sense), dangerous, and expensive enterprise.

Which they use all the time still, so that's not a real difference. It's not xor with digital surveillance.

Besides what you describe (double life, death, etc) would be a problem for the spy, not the general population. I could not care less about the spies.

But I wasn't talking about spying as much, but for government / police / etc surveillance. Where if they have to deploy humans to spy on some drug dealers or suspected murderer or whatever, is fine. And the fact that they're humans, makes it more costly to mass deploy (and thus serves as a natural check and balance).

Re: Rethinking Encryption

#68

Despite the length of this article, I see no plan for the obvious rebuttal of terrorists: if you make whatsapp or some other app not end to end encrypted, the terrorists will make their own app. Its not difficult to generate your own symmetric key and use openssl to encrypt and decrypt information sent with that key. Sure, you can force apple to reveal the contents of the hard drive, but whats the difference if apple…

A new virtual machine underneath can see what every app is doing.

Re: Rethinking Encryption

#69
post #62
post #45

Earlier quoted context omitted.

https://support.apple.com/en-us/HT208351

Well, China issues aside, that should be the case in every country -- such services should be local, governed by local laws, and not giving a free-pass to foreign countries/governments (foreign as to the users of the service) to enforce their laws/surveillance. E.g. I would like the EU iCloud to be hosted in EU.

> that should be the case in every country -- such services should be local, governed by local laws

So a cloud service that's available worldwide should store and process data locally in every country (or perhaps even every sub-jurisdiction of every country) just so that that jurisdiction can serve warrants to it and others cannot? Or worse, people in multiple countries should have to use different services and hope those services interoperate with each other, just so that they can "shop local"?

The Internet does not and should not work that way. If we're going to go to the trouble of building interoperable, federated services, it should be to put them in the control of individual users, not in the control of governments.

Re: Rethinking Encryption

#70

Earlier quoted context omitted.

Every cryptographic protocol has a weakness in its implementation if not in its spec (and if not in the tool itself then in its various dependencies)

Any tool can be used to undo itself... if not directly then by proxy.

This is one reason that NIBOR requires that a new virtual machine can always be installed to fix issues with the previous one.
Post reply on HN