Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

81–90 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#81

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

Let’s see: Mercedes recently forgot a token in a public repository which grants access to everything . Microsoft forgot its “Golden Key” in the open, allowing all kinds of activation and secure boot shenanigans. Microsoft’s JWT private key is also stolen, making the login page a decoration. Somebody stole Realtek’s driver signing keys for Stuxnet attack. HDMI master key is broken. BluRay master key is broken. DVD CSS…

I've been waiting for those wildvine keys to leak which would finally let me choose what to play my stuff on. But it still hasn't happened. They are getting better at secrecy sadly.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#82

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

[flagged]

I know. We definitely aren't a nation founded on outright treason and insurrection, and thumbing our nose at authority and doing the moral thing isn't in our DNA in any way, shape, or form.

Frustrating that some people think otherwise.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#83

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

At the time, I had a t-shirt that said "this t-shirt is a munition", because it also had on it the RSA public key algorithm encoded as a barcode.

Cane to say the same thing. It sparked a lot of interesting conversations over the years.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#84

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

The guy who founded Crypto AG was really good friends with a guy who became a top dog at the NSA.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#85
Encryption is meaningless with cpu-level side-channel memory key dumps active on most modern platforms. The reality is if you have been targeted for financial or technological reasons, than any government will eventually get what they are after.

One can't take it personally, as all despotic movements also started with sycophantic idealism.

Have a great day, =)

https://xkcd.com/538/

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#86

Now the argument coming from civil society for backdoors is based on CSAM: > Heat Initiative is led by Sarah Gardner, former vice president of external affairs for the nonprofit Thorn, which works to use new technologies to combat child exploitation online and sex trafficking. In 2021, Thorn lauded Apple's plan to develop an iCloud CSAM scanning feature. Gardner said in an email to CEO Tim Cook on Wednesday, August 3…

CSAM is evil, and I personally believe we should execute those who distribute it.

I have an even stronger belief in the right to privacy, and those in the government who want to break it should be executed from their positions (fired and publicly shamed).

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#87

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

At the time, I had a t-shirt that said "this t-shirt is a munition", because it also had on it the RSA public key algorithm encoded as a barcode.

Haha I remember that. OG fist bump!

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#88
post #31

for a long time, the US considered cryptography algos as a munition. Needed some arms license to export. Also, US tried to convince the world only 56 bits of encryption was sufficient. As SSL (I don’t think TLS was a thing back then) was becoming more mainstream, US govt only permitted banks and other entities to use DES [1] to “secure” their communications. Using anything more than 56 bits was considered illegal. ht…

Even now, if you join a discussion on crypto and say something like "Why don't we double the key length" or "Why not stack two encryption algorithms on top of one another because then if either is broken the data is still secure", you'll immediately get a bunch of negative replies from anonymous accounts saying it's unnecessary and that current crypto is plenty secure.

Well, I think that would sevearly inhibit future development. Scaling on bitcoin has been a delicate game of optimizing every bit that gets recorded, but also support future developments that dont even exist yet, there is no undo button either. New signature schemas and clevar cryptography tricks can do quite a bit, but when you slap another layer of cryptography on you will inevitably make things worse in the long run.

Histories biggest bug bounty is sitting on the bitcoin blockchain, if it were even theoretically plausible to crack sha-256 like that then we would probably know, and many have tried.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#89

Earlier quoted context omitted.

[flagged]

Maybe you just have a faulty sarcasm detector?

It's no longer possible to tell. Some of the ideas that avg Americans have on the way just about anything works is frightening.

My favorite lately is that the US was the real bad guy in WWII because we used nukes.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#90
post #31

for a long time, the US considered cryptography algos as a munition. Needed some arms license to export. Also, US tried to convince the world only 56 bits of encryption was sufficient. As SSL (I don’t think TLS was a thing back then) was becoming more mainstream, US govt only permitted banks and other entities to use DES [1] to “secure” their communications. Using anything more than 56 bits was considered illegal. ht…

Even now, if you join a discussion on crypto and say something like "Why don't we double the key length" or "Why not stack two encryption algorithms on top of one another because then if either is broken the data is still secure", you'll immediately get a bunch of negative replies from anonymous accounts saying it's unnecessary and that current crypto is plenty secure.

The best is the claim that multiple encryption makes it weaker or that encryption is the weaker of the two. If that were true we'd break encryption just by encrypting once more with a weaker algo.
Post reply on HN