Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

1–10 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#2
This topic comes up a bunch still. Someone please correct me, but as I understand it anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch.

I know puri.sm[0] takes some steps to try to plug the hole, but haven't read up to see if it's effective or no.

[0] https://puri.sm/learn/intel-me/

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#3
In case anyone is wondering about the context for this 2016 article, it was right after the 2015 San Bernardino attack and the FBI was trying to get into one of the attacker's phones. Apple resisted the request primarily because they wanted a certificate that would allow them to install any rogue firmware/app/OS on any iPhone, not just the attacker's.

https://en.wikipedia.org/wiki/2015_San_Bernardino_attack

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#4

    FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues.
"could exploited by criminals" is sadly a disingenuous claim. A cryptographic backdoor is presumably a "Sealed Box"[1] type construct (KEM + symmetric-cipher-encrypted package). As long as the government can keep a private key secure only they could make use of it.

There are plenty of reasons not to tolerate such a backdoor, but using false claims only provides potential ammunition to the opposition.

[1] https://libsodium.gitbook.io/doc/public-key_cryptography/sea...>

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#5

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

And Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#6

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

It's not a false claim, assuming the feds will keep such a key "secure" is not backed by evidence. Top secret materials are leaked all the time. Private keys from well secured systems are extracted from hacks. The FBI having such a key would make them a very profitable target for the various corps that specialize in hacking for hire. For example, NSO group.

If the power doesn't exist, nobody can exploit it.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#7

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

It's not a false claim, assuming the feds will keep such a key "secure" is not backed by evidence. Top secret materials are leaked all the time. Private keys from well secured systems are extracted from hacks. The FBI having such a key would make them a very profitable target for the various corps that specialize in hacking for hire. For example, NSO group. If the power doesn't exist, nobody can exploit it.

Do military cryptographic keys leak often? Do nuclear codes leak?

The times highly valuable cryptographic keys leaked for various cryptocurrency exchanges it has generally if not always been due to gross negligence.

Such a key would be highly sensitive and it would also require very little traffic to use. You would just need to send the secure system a KEM (I don't doubt they could secure it. Can even split the key into shares and require multiple parties to be present in the secure location.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#8

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

>As long as the government can keep a private key secure only they could make use of it.

Your devices would be secure as long as a private key that happened to be the most valuable intelligence asset in the United States, accessed thousands of times per day, by police spread across the entire nation, was never copied or stolen.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#9

Earlier quoted context omitted.

It's not a false claim, assuming the feds will keep such a key "secure" is not backed by evidence. Top secret materials are leaked all the time. Private keys from well secured systems are extracted from hacks. The FBI having such a key would make them a very profitable target for the various corps that specialize in hacking for hire. For example, NSO group. If the power doesn't exist, nobody can exploit it.

Do military cryptographic keys leak often? Do nuclear codes leak? The times highly valuable cryptographic keys leaked for various cryptocurrency exchanges it has generally if not always been due to gross negligence. Such a key would be highly sensitive and it would also require very little traffic to use. You would just need to send the secure system a KEM ( I don't doubt they could secure it. Can even split the key…

nuclear codes are probably not used as much as phone backdoors. local police wants access too and other governments so I do believe it would leak

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#10

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

And Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?

https://arstechnica.com/security/2023/12/exploit-used-in-mas...

Looks like criminals were using it for four years undetected.

Post reply on HN