Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

121–130 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#121

Earlier quoted context omitted.

Even now, if you join a discussion on crypto and say something like "Why don't we double the key length" or "Why not stack two encryption algorithms on top of one another because then if either is broken the data is still secure", you'll immediately get a bunch of negative replies from anonymous accounts saying it's unnecessary and that current crypto is plenty secure.

two encryption algorithms will mean needing two completely unrelated , unique passwords. this can be impractical and increase odds of being locked out forever

no it doesn't mean that at all

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#122

Earlier quoted context omitted.

Even now, if you join a discussion on crypto and say something like "Why don't we double the key length" or "Why not stack two encryption algorithms on top of one another because then if either is broken the data is still secure", you'll immediately get a bunch of negative replies from anonymous accounts saying it's unnecessary and that current crypto is plenty secure.

The best is the claim that multiple encryption makes it weaker or that encryption is the weaker of the two. If that were true we'd break encryption just by encrypting once more with a weaker algo.

The invalidity of that claim is a bit more nuanced. Having an inner, less secure algorithm may expose timing attacks and the like. There are feasible scenarios where layered encryption (with an inner weak algo and outer strong algo) can be less secure than just the outer strong algorithm on its own.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#123

FBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could e…

Let’s see: Mercedes recently forgot a token in a public repository which grants access to everything . Microsoft forgot its “Golden Key” in the open, allowing all kinds of activation and secure boot shenanigans. Microsoft’s JWT private key is also stolen, making the login page a decoration. Somebody stole Realtek’s driver signing keys for Stuxnet attack. HDMI master key is broken. BluRay master key is broken. DVD CSS…

It's apparently now trivial to brute force the private key used for Windows XP-era Microsoft Product Activation, as another example. (that's where UMSKT and the like get their private keys from)

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#124

Earlier quoted context omitted.

Yep. I use Chinese brand phones because if they're snooping all my shit, they're much further away from me than my own government and not likely to have sharing arrangements.

Wouldn’t Chinese branded phones be a higher priority target by foreign agencies in the first place?

It's likely an additional data point in some kind of 'suspicious' rating.

I think I hit quite a few of those 'suspicious' check-boxes that law enforcement would consider important, whilst actually technically knowledgeable people wouldn't even blink at them. Refer: https://news.ycombinator.com/item?id=39050898

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#125

One of my favorite comics about cryptography. https://xkcd.com/538/ Government routinely posits a desperate need for backdoors in crypto and crypto secured products, but almost universally they get the data they want without needing a manufacturer provided backdoor. So why they insist on continuing to do that is beyond me. It's almost security theater. If they really want your protected information they will be able…

>Ultimately it will take strict legislation and compliance measurement along with penalties to protect the government from overstepping the bounds they promise not to step over already, let alone new ones.

They will find ways to not comply, often blatantly. They have no scruples.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#126
post #91

As this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG

> The company had about 230 employees, had offices in Abidjan, Abu Dhabi, Buenos Aires, Kuala Lumpur, Muscat, Selsdon and Steinhausen, and did business throughout the world. That's a... really strange list of office locations, especially considering the relatively small number of employees. > The owners of Crypto AG were unknown, supposedly even to the managers of the firm, and they held their ownership through beare…

Via lawyer / legal representative if I had to hazard a guess.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#127
post #93

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

I never understood the story about the book-printed PGP source code. Isn't source code protected speech under the first amendment anyway, regardless of the form in which it is transmitted? All kinds of media receive first amendment protection, including things like monetary donations, corporate speech, art, etc. I've never heard of there being a requirement for the printed form. Did the interpretation of the first am…

The book was published in 1995 [1,2]. Free speech protection for source code under US law wasn't decided until 1996, in Bernstein v. United States [3].

[1] https://en.wikipedia.org/wiki/Phil_Zimmermann#Arms_Export_Co...

[2] https://www.eff.org/deeplinks/2015/04/remembering-case-estab...

[3] https://en.wikipedia.org/wiki/Bernstein_v._United_States

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#128
post #95

Earlier quoted context omitted.

> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Then what is it based on, if it happens across different devices and different IP addresses? I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't conta…

Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)

This honestly seems kinda fun. If one was really dedicated: buy new device with cash; purchased and used outside city of residence; don’t drive there, non-electric bike or walk; only use device to connect to the website from public wifi; never connect to own wifi; don’t use same VPN service as usual. Not sure if I missed anything. Probably did.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#129
post #104
post #99

Earlier quoted context omitted.

The idea was to make it blatantly clear that it's not a "munition".

Why would that matter, if source code is protected speech anyway? And why is it more "clear" with a printed book vs. an emailed text file?

Legally speaking, it didn't really matter. But symbolically, having the feds argue that a book constitutes "munitions" would be bad optics for them in a way that is more understandable to the average American, compared to more legal arcane arguments about software having 1A protections.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#130
post #95

Earlier quoted context omitted.

> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Then what is it based on, if it happens across different devices and different IP addresses? I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't conta…

Yeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)

It’s just Akamai being overzealous against bots.

It could simply be you read more pages and it may have triggered anti-scraping rules.

I cannot access many .gov websites either, and maybe it was after 5 pages or so.

Post reply on HN