Live data from Hacker News

Rethinking Encryption

lawfareblog.com

111–120 of 125 posts

Re: Rethinking Encryption

#111
post #95

Earlier quoted context omitted.

> Simply put, yes. Feel free to build such services, if you wish. > You are maybe concerned with the technical issues / problems to the service provider. Not just that (though I certainly don't consider it reasonable to expect a service to have thousands of servers in thousands of jurisdictions and deal with thousands of legal systems; frankly, I want services to expose themselves to as few jurisdictions as possible)…

> Feel free to build such services, if you wish. Well, I don't propose or expect companies to volunteer doing this. My point is that EU (for one) should mandate them, and if service providers like FB, etc, don't like them, they could skip the 500m market -- and just be careful not to let the door hit them on their way out... > Not just that (though I certainly don't consider it reasonable to expect a service to have…

> As long as it's your jurisdiction?

No, not at all. I expect it to be the jurisdiction of whoever runs the service. That jurisdiction will necessarily have control over the authors of the service; there's no getting around that. (The authors can try to build the service with themselves as a threat model, which few services do, and even then that may not work.) Unless you want to mandate that people can't use services from outside their country (and enforce that with a country-wide firewall blocking access to the real Internet), then you're never going to get around that.

Also, you seem to be treating "store and use data locally" as a thing that protects the citizens of a country, rather than a thing that threatens the citizens of a country. Many countries want data stored locally so that they can seize it, and want services hosted locally so that they can block those services or make them consistent with the country's propaganda.

Also, you're assuming that data is nicely partitioned by user. For many useful services, it isn't. Just for the simplest case, consider collaboratively-edited works by multiple users.

> There aren't "thousands of jurisdictions and legal systems".

Tell that to states and equivalent sub-jurisdictions within countries. Tell that to many large cities and their local regulations. Thousands is if anything an underestimate.

> there could easily be an infrastructure and common services to deploy to span the globe

That sounds like a great way to introduce security holes and a vastly expanded threat model.

Also, to comment on something you edited into a previous comment:

> (Exceptions could be made for non-democratic countries -- no reason to give control of a service's local data to a dictatorship).

Who gets to decide that? Obviously not the countries themselves. That just leaves the people building the service and the people deciding which services to use; those are the same parties who already get to decide that today.

Re: Rethinking Encryption

#112

Earlier quoted context omitted.

USB stick... I'm sure it'll work out great. What if you have to give it up with a gun to your head? > Hand wavy as heck. Then you meander. Not sure what you're responding to.

The whole point of a one time pad is that it is never used again and destroyed after use. Even the sick fucks in the CIA don't think they can get a key sequence from you with torture or threats after it has already been stomped and put in a microwave.

I thought he meant a series of pads on a USB stick exchanged in advance. If you're trying to get just one message across that's very easily doable as you say, and with many other ways. But if you're trying to establish a real bidirectional communication scheme that doesn't involve meeting at Starbucks every Wednesday ... different story.

Re: Rethinking Encryption

#113
post #46

Earlier quoted context omitted.

A one time pad must be truly random to be secure. A music stream is far from that.

'The Nth 4096 bits from this week's mod(N,100) top video on YouTube' Can you tell me what's wrong with that approach? In my head, it seems reasonable.

You are making two choices here: one out of say 10K and the other out of 100. You'd be lucky to end up with 20 bits of entropy. That can be cracked in a microsecond (exaggerating a bit and/or assuming a distributed data parallel cracking algo on a massive botnet), assuming the data source (youtube) is accessible, and this recipe is known, which it is now since you described it in public.

Re: Rethinking Encryption

#114
post #7

I’m extremely skeptical about ANYTHING put out by this group, and Jim Baker in particular. This guy was general counsel for the FBI at the same time they were abusing FISA warrants to secretly spy on Trump admins. You think they’ll stop at Trump? They’re just getting started. We need to get back to our roots of being extremely careful about our intelligence agencies. I know you’ll initially be turned off by the subje…

Don't post conspiracy theories. Also: the article actually comes out in favour of strong encryption. How does that fit with your worldview?

What are "conspiracy theories"?

Re: Rethinking Encryption

#115
post #102
post #77

Earlier quoted context omitted.

How so? Censorship is explicitly forbidden by the US constitution, and even so it happens (in this case, "in the name of national security" or whatever).

The current interpretation says there are certain reasonable restrictions on the 1st for the public safety. Compelled speech isn't accepted as constitutional. Remember the constitution only really, effectively, says whatever the current Supreme Court says it means. And really I don't think anyone want's the 100% literal 'shall make no law' interpretation of free speech; that would throw out any kind of labeling laws…

is ordering silence and secretly seizing control of the publication technology (ie website) then maintaining a false warrant canary a way around compelled speech ? if so then regular live press-conference/video appearances would be the only practical implementation method. if they say nothing and exit then the canary is dead.

Re: Rethinking Encryption

#116
post #102

Earlier quoted context omitted.

The current interpretation says there are certain reasonable restrictions on the 1st for the public safety. Compelled speech isn't accepted as constitutional. Remember the constitution only really, effectively, says whatever the current Supreme Court says it means. And really I don't think anyone want's the 100% literal 'shall make no law' interpretation of free speech; that would throw out any kind of labeling laws…

is ordering silence and secretly seizing control of the publication technology (ie website) then maintaining a false warrant canary a way around compelled speech ? if so then regular live press-conference/video appearances would be the only practical implementation method. if they say nothing and exit then the canary is dead.

It could be, I'm not a lawyer. That seizure would be something you could fight in court too on two fronts: seizure of property and if the government takes over your means of communication and pretends to be you what separates that from directly compelling speech.

Re: Rethinking Encryption

#117
post #46
post #40

Earlier quoted context omitted.

USB stick? the entertainment industry provides an excellent source for the distribution of 1-time pads, just agree on some particular stream/CD/DVD/etc ("number 27 on this week's top 40") and use the LSBs in some agreed order

A one time pad must be truly random to be secure. A music stream is far from that.

The LSB are pretty close to this (unless it's Cage's 4'33)

Re: Rethinking Encryption

#119
post #37

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court. One thing the US has going for it is tha…

Note: 9/11 is almost two decades in the past

Re: Rethinking Encryption

#120
post #46

Earlier quoted context omitted.

A one time pad must be truly random to be secure. A music stream is far from that.

'The Nth 4096 bits from this week's mod(N,100) top video on YouTube' Can you tell me what's wrong with that approach? In my head, it seems reasonable.

There are recurring patterns in a video or audio stream. More often than not these coincide with recurring patterns in the message, revealing information. For the sake of an example, take some pages of a novel as the one time pad. There will be statistical variations (not all ciphers in the ciphertext come with equal frequency) in the ciphertext, where the combination ocuring most will correspond to an "e" in the plain text and an "e" in the one time pad because both occur most often in English language. You can calculate the probabilities for each combination and thus deduce the plain text provided it is long enough. For a one time pad to be secure it must be truly random or pseudo-random.

As a way out you can agree to a seed to a secure pseudo random algorithm but that's commonly called a password or pre-shared secret. In fact it's more secure to use just the string 'The Nth 4096 bits from this week's mod(N,100) top video on YouTube' as pre-shared secret.

Post reply on HN