Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

181–190 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#182

Earlier quoted context omitted.

And Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?

Source/reference? I’m not aware of such a backdoor

How is their update path not considered a backdoor? They can sign and serve you any update that they want.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#183

Earlier quoted context omitted.

Let’s see: Mercedes recently forgot a token in a public repository which grants access to everything . Microsoft forgot its “Golden Key” in the open, allowing all kinds of activation and secure boot shenanigans. Microsoft’s JWT private key is also stolen, making the login page a decoration. Somebody stole Realtek’s driver signing keys for Stuxnet attack. HDMI master key is broken. BluRay master key is broken. DVD CSS…

I've been waiting for those wildvine keys to leak which would finally let me choose what to play my stuff on. But it still hasn't happened. They are getting better at secrecy sadly.

Since Widevine L3 is completely implemented on software, there are tools you can use, but L2 and L1 are have hardware components, and secure enclaves are hard to break. Up to par ones have self-destruction mechanisms which trigger when you bugger them too much.

On the other hand, there are 4K, 10bit HDR + multichannel versions everywhere, so there must be some secret sauce somewhere.

This is not a rabbit hole I want to enter, though.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#184

Earlier quoted context omitted.

Yeah, this lives in the back of my mind too. I run debian on 11th gen intel, but with the non-free blobs included to make life easier. I've been meaning to try it without them, but it's too tempting to just get things 'up' instead of hacking on it.

There's little we can do about it short of running ancient libreboot computers. We'll never be truly free until we have the technology to manufacture free computer chips at home, just like we can make free software at home.

ASML fabs in every basement when? I think riskV is as close to an open source CPU we have at the moment, unfortuantly most riskV cpu's rely on the company having IP that is protected like the CPU layout or the core architecture as of what I understand of modern CPU design.

RISKV has been a great step forward and I'd love to see it succeed but I'm also aware of the lack of open source architecture for GPU's or AI accelerators.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#185
post #86

Now the argument coming from civil society for backdoors is based on CSAM: > Heat Initiative is led by Sarah Gardner, former vice president of external affairs for the nonprofit Thorn, which works to use new technologies to combat child exploitation online and sex trafficking. In 2021, Thorn lauded Apple's plan to develop an iCloud CSAM scanning feature. Gardner said in an email to CEO Tim Cook on Wednesday, August 3…

CSAM is evil, and I personally believe we should execute those who distribute it. I have an even stronger belief in the right to privacy, and those in the government who want to break it should be executed from their positions (fired and publicly shamed).

In some cases artwork where no child was harmed counts as CSAM. Is that execution worthy?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#187

Earlier quoted context omitted.

There's little we can do about it short of running ancient libreboot computers. We'll never be truly free until we have the technology to manufacture free computer chips at home, just like we can make free software at home.

ASML fabs in every basement when? I think riskV is as close to an open source CPU we have at the moment, unfortuantly most riskV cpu's rely on the company having IP that is protected like the CPU layout or the core architecture as of what I understand of modern CPU design. RISKV has been a great step forward and I'd love to see it succeed but I'm also aware of the lack of open source architecture for GPU's or AI acce…

RISC-V* (Reduced Instruction Set Computing, 5th incarnation)

And sure, companies can choose not to share chip designs, but if you want an open-design CPU then you should be checking for that specifically and not just filtering by ISA. There exist such chips already, and I expect they'll catch up with AArch64 chips (in terms of being able to run desktop Linux) in <10 years, given the specs already include SIMD and the high-end chips have clock rates comparable to the oldest Windows-on-ARM laptops, like the 1st-gen Surface.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#188
post #86

Earlier quoted context omitted.

CSAM is evil, and I personally believe we should execute those who distribute it. I have an even stronger belief in the right to privacy, and those in the government who want to break it should be executed from their positions (fired and publicly shamed).

In some cases artwork where no child was harmed counts as CSAM. Is that execution worthy?

Can you give an example? If we're talking about Loli-type stuff, I hate it, but it doesn't harm kids directly, so execution is too harsh.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#189
post #155

Earlier quoted context omitted.

i seem to have vague recollection of a variant of this shirt that had a perl script on it? or was the perl script for decoding the barcode?

Memory claims: It was RSA in Perl, text shape of a dolphin, but it may be wrong.

Picture:

https://commons.wikimedia.org/wiki/File:Munitions_T-shirt_(f...

The code:

http://www.cypherspace.org/adam/shirt/design/

Post reply on HN