Earlier quoted context omitted.
Nobody trusts CAs. There is a lot of work being done on layering more trustworthy authentication features on top of the TLS CA system, one good one being TACK: http://tack.io/draft.html The problem with simply abandoning CAs is that it creates a situation in which it's even easier for government sponsored agencies to mass-intercept traffic, at least for a window of time (probably several years), and all that window b…
> Nobody trusts CAs. No. The problem is that pretty much everyone trusts them, at this point in time. That was Peter's point. Sure, there are researchers and engineers who rightfully don't trust CAs. But we don't really matter. The users, the consumers, the parents, the grandparents, the activists do.
A Saudi Arabia Telecom's Surveillance Pitch
31–40 of 115 posts
Re: A Saudi Arabia Telecom's Surveillance Pitch
#32I'm very curious what aspect of Twitter's TLS code makes hard to intercept whereas other websites can be easily intercepted? I'm also very curious about how they intercepted Whatsapp. Does it do something stupid like eval'ing code received over regular HTTP? Quoting the paragraph, in case my paraphrasing is inaccurate: "What’s depressing is that I could have easily helped them intercept basically all of the traffic t…
Re: A Saudi Arabia Telecom's Surveillance Pitch
#33Re: A Saudi Arabia Telecom's Surveillance Pitch
#34This stuff happens more than anyone in infosec wants to admit; it's (ironically) what got me into professional software security to begin with, after being upset by what a commercial network monitoring tool would have allowed us to do to our customers at an ISP I helped run. It's especially funny to see a government sponsored telecom reaching out to Moxie Marlinspike. Also: this isn't like that time a random Microsof…
Governments are in a unique position here. They can always just move up the stack. Can't break the crypto? That's fine. They can just require the mobile phone companies to sell phones with spyware already included.
Re: A Saudi Arabia Telecom's Surveillance Pitch
#35> TextSecure and RedPhone could serve as appropriate secure replacements sadly those are only available for Android.
Re: A Saudi Arabia Telecom's Surveillance Pitch
#36Re: A Saudi Arabia Telecom's Surveillance Pitch
#37This stuff happens more than anyone in infosec wants to admit; it's (ironically) what got me into professional software security to begin with, after being upset by what a commercial network monitoring tool would have allowed us to do to our customers at an ISP I helped run. It's especially funny to see a government sponsored telecom reaching out to Moxie Marlinspike. Also: this isn't like that time a random Microsof…
Like Moxie says, money buys technology, and they will eventually find someone to rig up a workable solution for what they're trying to do. Governments are in a unique position here. They can always just move up the stack. Can't break the crypto? That's fine. They can just require the mobile phone companies to sell phones with spyware already included.
But the economics flip around in Europe, Japan, the US, &c: governments there do have something to lose by surreptitiously backdooring huge numbers of devices, and the odds are good that any efforts to do so will be detected (the state of the art for reverse engineering now includes decapsulation and imaging of electronics packages).
Re: A Saudi Arabia Telecom's Surveillance Pitch
#38Unfortunately, this is the world we live in now. Its only going to get worse, and sooner or later will self-destruct. Bliss.
Re: A Saudi Arabia Telecom's Surveillance Pitch
#39Earlier quoted context omitted.
> Nobody trusts CAs. No. The problem is that pretty much everyone trusts them, at this point in time. That was Peter's point. Sure, there are researchers and engineers who rightfully don't trust CAs. But we don't really matter. The users, the consumers, the parents, the grandparents, the activists do.
What about a crowd-sourced decentralized list of known bad-CAs or certificates known to be used by Government security services? At the very worst, it will raise some warnings and let the user think twice before connecting to that service (which may or may not be annoying), but at best it would shield users from surveillance?
Re: A Saudi Arabia Telecom's Surveillance Pitch
#40I suddenly had a realization why someday in the future everyone is going to want their own personal satellite. Government interception/manipulation (or any other party) would become rather difficult.