Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

11–20 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#11

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

[flagged]

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#12

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

And Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?

Which backdoor do you mean? I'm not an Apple expert by any means, but I thought they encrypted customer data in a way that even they can't get to it? Wasn't that the crux of this case, that Apple couldn't help the FBI due to security measures, prompting the agency to ask for a backdoor?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#13

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

> As long as the government can keep a private key secure only they could make use of it.

Not disingenuous. Keys are stolen or leaked all the time. And the blast radius of such a master key would be extremely large.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#14

Earlier quoted context omitted.

And Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?

Which backdoor do you mean? I'm not an Apple expert by any means, but I thought they encrypted customer data in a way that even they can't get to it? Wasn't that the crux of this case, that Apple couldn't help the FBI due to security measures, prompting the agency to ask for a backdoor?

What's an update? They can sign and push any code they want remotely.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#15

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

And Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?

Source/reference? I’m not aware of such a backdoor

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#16

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

And Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?

FWIW this is a fair and valid argument. Generally, no one entity should have that much power. Doesn’t really matter if it’s USG or a tech giant.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#17

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

> false claims

As Pauli said, "That's not even wrong". It cannot even meet the basic criteria for truth or falsehood.

It's simply naked hubris.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#19
As this is from 2016 it doesn't include this new fun revelation:

> On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages.

https://en.m.wikipedia.org/wiki/Crypto_AG

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#20

Earlier quoted context omitted.

Which backdoor do you mean? I'm not an Apple expert by any means, but I thought they encrypted customer data in a way that even they can't get to it? Wasn't that the crux of this case, that Apple couldn't help the FBI due to security measures, prompting the agency to ask for a backdoor?

What's an update? They can sign and push any code they want remotely.

IIRC the question is when the phone is totally locked, e.g. if you turn it off then turn it back on and haven't entered the PIN yet. In this state even apple can't get an update to run, the secure hardware won't do it unless you wipe the phone first. And your data is encrypted until you unlock the phone.

In practice though most people are screwed b/c it's all already in icloud.

Post reply on HN