Live data from Hacker News

NSA-proof encryption exists. Why doesn’t anyone use it?

washingtonpost.com

101–110 of 138 posts

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#101

Earlier quoted context omitted.

Would it be possible to improve the resolution of optical imagery using a synthetic aperture?

Beyond my knowledge, sorry.

Yes, much finer optical resolution is possible if you use multiple instruments separated by a controlled interval.

In radioastronomy, there are arrays of dishes that use this technique. There are good pictures in the Wikipedia article. [0]

One military implementation was a connected three-satellite constellation, built by the US Navy for scanning the surface of the world's oceans. [1]

But those tools work in (relatively) long wavelengths.

I have never heard of free-flight multi-aperature interferometry that works in optical or near-optical wavelengths.

.

[0] "Very-long-baseline interferometry" https://en.wikipedia.org/wiki/Very-long-baseline_interferome...

[0] "How VLBI Works" https://en.wikipedia.org/wiki/Very-long-baseline_interferome...

[1] "White Cloud | PARCAE | NOSS" https://en.wikipedia.org/wiki/Naval_Ocean_Surveillance_Syste...

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#102
post #56

> NSA-proof encryption exists. Yup. Except it's not that easy. Let's say that you're using OTR to provide very strong end-to-end encryption for a conversation between yourself and a buddy, Bob. Maybe he's in a hostile area, and you're worried that if his government sniffs his traffic, that he could be executed for speaking to Americans. Data in transit that is intercepted, if configured correctly, is almost certainly…

Remember that post a little while ago about how most logical fallacies aren't actually logical fallacies? Here, you are committing an actual logical fallacy. It's called "shifting the goalposts." The article is in response to a dragnet surveillance program, where everyone's communications are watched and presumably datamined. It's very easy to do this, because nothing is encrypted, and everyone uses services that exp…

The least of it is to not be the lowest-hanging fruit.

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#103

Earlier quoted context omitted.

The resolution of a lens at a given wavelength is determined by its diameter (Rayleigh function). We know how big the launch vehicles are, so we can estimate the largest size a spy satellite's mirror could be, and we can use that to compute the maximum resolution a satellite could have; it turns out to be something around 5-10 cm. In order to resolve a newspaper from near-earth orbit, you'd need a lens bigger than th…

Would it be possible to improve the resolution of optical imagery using a synthetic aperture?

Yes, aperture synthesis is possible with optical wavelengths. I don't know how practical it would be to actually use with spy satellites, or how much of an improvement they could see with it.

Keep in mind that there are a lot of people that track satellites, even spy satellites, as a hobby. I haven't heard of anyone discovering two or more satellites orbiting in the sort of tight formation you would expect would be required for this.

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#104

Earlier quoted context omitted.

That's for distant stars though, isn't it? I mean, just with Google Maps you can see the mirrors on a car. Newsprint isn't that much of a step up.

While it's true that the stars are very distant, the only atmosphere that the light passes through is same atmosphere the satellites have to peer through (resulting in the same amount of distortion)

Hm, but with angles, distance matters to right? Bending light 10 degrees will mean a much bigger difference light-years away than a couple hundred miles away. That said, I could easily be missing something...

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#105
post #77

Earlier quoted context omitted.

Key escrow services?

See: Clipper.

I'm familiar. There's a big difference between "optional key escrow with a service I have chosen to trust" and "mandatory key escrow" though. Most importantly with regard to the ease of mass surveillance.

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#106
post #51

Earlier quoted context omitted.

Google Maps uses aerial photography from planes for the high-resolution layers of their maps, not satellite imagery.

Huh, interesting! I never knew that. So then I'll need to ask my father about what he was told again. Maybe something got misinterpreted along the way.

It probably was that you can see newsprint, not read it.

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#107
post #52

I have a question that perhaps a cryptography expert could answer for me. My father told me when he was young, he visited Oak Ridge National Labs on a trip, and while there, they told him they had satellites that could read the print on a newspaper. At the time, it wasn't classified information; it was just something that nobody knew. Approximately 15-20 years later, satellites with that capability became well-known.…

Assume that over some time frame a crypto solution (the entire system matters as it's very easy to use encryption insecurely) will be compromised. You are essentially buying yourself time. So the question is how much time do you need to buy yourself. Ok, so even if you select a key length of something very large which depends not only on bytes of the key but also the encryption algorithm as well. For a 4096 bit key t…

I don't know why you're saying Elliptic Curve is not widely available, here is an Elliptic Curve Diffie-Hellman implementation guide from the NSA itself: http://www.nsa.gov/ia/_files/SuiteB_Implementer_G-113808.pdf

Those patents are quite questionable anyway: https://en.wikipedia.org/wiki/ECC_patents

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#108

> NSA-proof encryption exists. Yup. Except it's not that easy. Let's say that you're using OTR to provide very strong end-to-end encryption for a conversation between yourself and a buddy, Bob. Maybe he's in a hostile area, and you're worried that if his government sniffs his traffic, that he could be executed for speaking to Americans. Data in transit that is intercepted, if configured correctly, is almost certainly…

Just because a determined thief will smash your window is no reason not to lock your doors.

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#109

> NSA-proof encryption exists. Yup. Except it's not that easy. Let's say that you're using OTR to provide very strong end-to-end encryption for a conversation between yourself and a buddy, Bob. Maybe he's in a hostile area, and you're worried that if his government sniffs his traffic, that he could be executed for speaking to Americans. Data in transit that is intercepted, if configured correctly, is almost certainly…

> The passphrase can be brute-forced significantly more easily than breaking the encryption itself. Furthermore, as xkcd so accurately pointed out, a hostile government will throw you in prison (or, worse, hit you repeatedly with a wrench) until you divulge your passphrase and data.

Not to detract from the point of your post, but for anyone interested, that's what TrueCrypt's 'plausible deniability' feature [1] is for. It can be used to create a hidden volume on your hard drive with a different password from your main volume, so if you're ever forced to give up the disk passphrase by a government agency or anyone else, you can give them the password to the hidden volume, and (in theory) you'll appear to be fully cooperating. It is impossible (short of cracking the main volume passphrase through brute force) to prove, given only the passphrase to the hidden volume, that the main volume exists. Ideally, you'd probably want to put something "embarrassing" but legal on the hidden volume (e.g., gay porn), to make the "plausible deniability" for using full disk encryption more "plausible".

[1] http://www.truecrypt.org/docs/?s=plausible-deniability

Re: NSA-proof encryption exists. Why doesn’t anyone use it?

#110
post #66

I just posted this question the other day. Let me explain some of my travails trying to use PGP with Thunderbird: The install of T-Bird wasn't too bad The install of OpenPGP was not easy but I managed it. The instructions on the site were not all that clear and for an out-of-date version, but YouTube helped out a lot. My mom, the business owners, or a computer science teacher at Central High School simply do not have…

It's even worse than you think, because several of the things you said in there don't actually make sense. It sounds like you possibly didn't manage to get the message encrypted at all, just signed.

And how you exchange public keys matters a great deal -- if you just send them over email, you haven't actually achieved any meaningful security.

So yes. The entire process is a usability nightmare.

Post reply on HN