Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

51–60 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#51
post #26
post #6

Earlier quoted context omitted.

PFS and other Deniable encryption ( http://en.wikipedia.org/wiki/Deniable_encryption ) are great for deniability. However, they and everything else can be susceptible to unrelenting rubber-hose "cryptanalysis". ( http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis ) It is said that the goal of cryptography is to make the attacker resort to rubber-hose cryptanalysis, revealing their intentions. In those cases, the…

Rubber hoses don't scale.

Tell that to Stalin

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#52
post #9

Earlier quoted context omitted.

Don't rely on government for anything? What are you talking about? Almost 100% of scientific research and 100% of infrastructure around the world is funded by government. Almost all of education, health and welfare around the world (though less so in the US) is run by government. A lot of people are suspicious of government, but such fundamental disdain toward and alienation from government are peculiar American (and…

I just meant that in a personal way. That is: if you get into trouble, don't rely on the government to help you, for it is not too much willing to help, and pretty soon will be unable to. If you are in your 20s, no way you should hope the government will pay you pension once you grow old, for example.

I see. In that case, if you're in your 20s maybe you should try to get into politics and change government so that it would work better.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#53
post #36

A logical conclusion to this is that if/when governments start forcing people to supply them with their private keys, they will also start forcing companies producing encryption software to include backdoors. At this point, I'm thankful that we have Free Software. With access to the source code, forcing the insertion of a backdoor is futile, since somebody else will fork and remove it. With Free Software, we'll still…

I agree with your sentiment, but want to provide a slight correction about "Free Software": MIT/BSD licensed software while not free in FSF/GPL sense, is still open and widely used and solves the problem we have right now. To avoid confusion with FSF ideals, I'd talk simply about Open Source software.

I think you might be a bit confused.

MIT/BSD are fully supported by the FSF and are GPL compliant. They are free software licenses in all aspects.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#54
post #20

Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…

I've recently begun designing such security systems(a few weeks ago). They are quite ugly at the moment and would require entirely new approaches to systems design. I can only hope that more people begin to think like this as it is the best possible evolution in security past things like RSA encryption IMO.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#55
post #37
post #25

Earlier quoted context omitted.

Situations like these probably rarely produce a real "winner". It is going to be an arms race between those favoring personal privacy and those favoring government snooping. Just keep in mind that government operates basically on an unlimited budget and has access to a wide range of harassment opportunities for non compliance in matters like these. This fact alone will keep them at least at a dead level with potentia…

No, it's a win because the government is not the only, and in most cases not the worst, threat. Insiders (like Snowden and Manning, ironically) are one of the biggest threats. Being attacked by non-USG outsiders is a major threat ("hackers", state sponsored or not). Your business partners being hacked, or having lax security, is another threat. USG is probably near the bottom of the list of actual threats for most pe…

> Insiders (like Snowden and Manning, ironically) are one of the biggest threats.

They're a threat to those who like running a Surveillance State, not to the average citizen.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#56
post #50
post #20

Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…

Those things you speak of will be outlawed and you won't be allowed to use them.

Harsh. dvmmh made a joke a few days ago and got downvoted to oblivion. But I think this comment is a good one: we do not live in a libertarian paradise. The government is comfortable using its powers, including physical violence under the law, to keep people from doing things it does not want them to do.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#57
As Feds hire contractors to do this work, the work will leak out of the contractors hands into the hands of those with money, such as foreign organized identity thieves. It's not just about hiding furry porn from the "Murican Gubmint," but about protecting our financial info from foreign thieves.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#58
post #17

I treat email in Gmail as publicly accessible, same for almost everything I do on the web casually. My business data lives in Amsterdam (Azure EU West), critical services we use are based in Europe. At least in my case I couldn't care less if the big US companies handed out SSL keys.

If you think that operating in any particular jurisdiction provides you with protection then you are sadly deluded. Your protection lasts just up until the point where protecting you becomes inconvenient. Oddly enough, using the resources of smaller companies provides less protection because they are easier to influence, and basing services outside of the US means that you are completely fair game for the NSA as you lack even the nominal protection that the (waxing and waning, but currently too damn weak for my mind) domestic/foreign distinction offers in terms of US SIGINT.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#59
post #55
post #37

Earlier quoted context omitted.

No, it's a win because the government is not the only, and in most cases not the worst, threat. Insiders (like Snowden and Manning, ironically) are one of the biggest threats. Being attacked by non-USG outsiders is a major threat ("hackers", state sponsored or not). Your business partners being hacked, or having lax security, is another threat. USG is probably near the bottom of the list of actual threats for most pe…

> Insiders (like Snowden and Manning, ironically) are one of the biggest threats. They're a threat to those who like running a Surveillance State, not to the average citizen.

Whistleblowers are a help to the average citizen, yes, but perhaps the parent poster meant "insiders with their own motives", which might not be benevolent.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#60
post #49

Earlier quoted context omitted.

/sarcasm -- (to be read in the voice of Sir Humphrey Appleby) I, for one, rely on my government to perform all those vital, but tragically under-appreciated services done selflessly and at great sacrifice, and all for the public good. Our top Whitehall mandarins do so much to pre^H^H^Hdeserve their salaries. The fabulous residences for the ambassadors, senior diplomats and other political appointees -- all those soci…

I don't understand your point. You could probably say the same about your family. The fact that something is not working as well as it should does not mean it's not essential. I mean, would you prefer feudal lords? Because that's what we had before central government, and that's what many corporations would like. Do you want to be ruled by Google? By Walmart?

Do you want to be ruled by Google? By Walmart?

Why is the default assumption by Statists that if the government won't rule us, corporations will?

A novel concept that people may want to attempt to grasp is that there could be no rulers, and as such, there's no need to make up a fictitious "new ruler".

Post reply on HN