Earlier quoted context omitted.
Nobody trusts CAs. There is a lot of work being done on layering more trustworthy authentication features on top of the TLS CA system, one good one being TACK: http://tack.io/draft.html The problem with simply abandoning CAs is that it creates a situation in which it's even easier for government sponsored agencies to mass-intercept traffic, at least for a window of time (probably several years), and all that window b…
> Nobody trusts CAs. No. The problem is that pretty much everyone trusts them, at this point in time. That was Peter's point. Sure, there are researchers and engineers who rightfully don't trust CAs. But we don't really matter. The users, the consumers, the parents, the grandparents, the activists do.
A Saudi Arabia Telecom's Surveillance Pitch
11–20 of 115 posts
Re: A Saudi Arabia Telecom's Surveillance Pitch
#12Quoting the paragraph, in case my paraphrasing is inaccurate: "What’s depressing is that I could have easily helped them intercept basically all of the traffic they were interested in (except for Twitter – I helped write that TLS code, and I think we did it well). They later told me they’d already gotten a WhatsApp interception prototype working, and were surprised by how easy it was. The bar for most of these apps is pretty low."
Re: A Saudi Arabia Telecom's Surveillance Pitch
#13Earlier quoted context omitted.
> Nobody trusts CAs. No. The problem is that pretty much everyone trusts them, at this point in time. That was Peter's point. Sure, there are researchers and engineers who rightfully don't trust CAs. But we don't really matter. The users, the consumers, the parents, the grandparents, the activists do.
I am not sure what the point of this comment is. What conclusion do you come to as a result of this "everyone trusts CA" belief that is different from mine?
In fact I think that so many people trust CAs that if someone provides a more secure alternative it should look like an evolution of CAs so it doesn't piss off people who have been trusting CAs all this time.
Re: A Saudi Arabia Telecom's Surveillance Pitch
#14Government interception/manipulation (or any other party) would become rather difficult.
Re: A Saudi Arabia Telecom's Surveillance Pitch
#15> TextSecure and RedPhone could serve as appropriate secure replacements sadly those are only available for Android.
Without jailbreaking or a dev cert, you can't ensure that an app you install from the App Store on iOS isn't backdoored anyway.
I'm an iOS devotee but even I'm going to buy a second phone specifically to support sideloading of crypto software for secure communications. My phone's primary function is to communicate (despite all the smartphone value-adds) and secure and private communications are a pipe-dream on iOS.
iMessage is great (and end-to-end encrypted) but if I can't control the list of keys to which it encrypts, it's only as secure as Apple (and presumably the DoJ by extension) allows it to be.
Re: A Saudi Arabia Telecom's Surveillance Pitch
#16There needs to be an RFC for Postcard Key Encryption - send each other public keys on hand-written postcards to single-use P.O. boxes to avoid mitm of the initial key exchange. I don't understand why anyone trusts CAs any more.
Nobody trusts CAs. There is a lot of work being done on layering more trustworthy authentication features on top of the TLS CA system, one good one being TACK: http://tack.io/draft.html The problem with simply abandoning CAs is that it creates a situation in which it's even easier for government sponsored agencies to mass-intercept traffic, at least for a window of time (probably several years), and all that window b…
Hundreds of millions of consumers use devices that implicitly trust CAs today.
You're usually spot on, but in this case you're dead wrong. Most humans that use the internet use devices that trust CAs absolutely - which is exactly why they're being subverted for government interception.
Re: A Saudi Arabia Telecom's Surveillance Pitch
#17Earlier quoted context omitted.
Nobody trusts CAs. There is a lot of work being done on layering more trustworthy authentication features on top of the TLS CA system, one good one being TACK: http://tack.io/draft.html The problem with simply abandoning CAs is that it creates a situation in which it's even easier for government sponsored agencies to mass-intercept traffic, at least for a window of time (probably several years), and all that window b…
> Nobody trusts CAs. Hundreds of millions of consumers use devices that implicitly trust CAs today. You're usually spot on, but in this case you're dead wrong. Most humans that use the internet use devices that trust CAs absolutely - which is exactly why they're being subverted for government interception.
The distinction between these two vantage points isn't particularly relevant to my point; at least, I don't think it is.
Re: A Saudi Arabia Telecom's Surveillance Pitch
#18Re: A Saudi Arabia Telecom's Surveillance Pitch
#19> TextSecure and RedPhone could serve as appropriate secure replacements sadly those are only available for Android.
...and, under these sorts of regimes, will likely get blocked should they gain any sort of real traction anyway. (Moxie's post is clear that they want to intercept, and block what they can't.) Without jailbreaking or a dev cert, you can't ensure that an app you install from the App Store on iOS isn't backdoored anyway. I'm an iOS devotee but even I'm going to buy a second phone specifically to support sideloading of…
Re: A Saudi Arabia Telecom's Surveillance Pitch
#20There needs to be an RFC for Postcard Key Encryption - send each other public keys on hand-written postcards to single-use P.O. boxes to avoid mitm of the initial key exchange. I don't understand why anyone trusts CAs any more.