Earlier quoted context omitted.
PFS and other Deniable encryption ( http://en.wikipedia.org/wiki/Deniable_encryption ) are great for deniability. However, they and everything else can be susceptible to unrelenting rubber-hose "cryptanalysis". ( http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis ) It is said that the goal of cryptography is to make the attacker resort to rubber-hose cryptanalysis, revealing their intentions. In those cases, the…
Rubber hoses don't scale.
As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
51–60 of 295 posts
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#52Earlier quoted context omitted.
Don't rely on government for anything? What are you talking about? Almost 100% of scientific research and 100% of infrastructure around the world is funded by government. Almost all of education, health and welfare around the world (though less so in the US) is run by government. A lot of people are suspicious of government, but such fundamental disdain toward and alienation from government are peculiar American (and…
I just meant that in a personal way. That is: if you get into trouble, don't rely on the government to help you, for it is not too much willing to help, and pretty soon will be unable to. If you are in your 20s, no way you should hope the government will pay you pension once you grow old, for example.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#53A logical conclusion to this is that if/when governments start forcing people to supply them with their private keys, they will also start forcing companies producing encryption software to include backdoors. At this point, I'm thankful that we have Free Software. With access to the source code, forcing the insertion of a backdoor is futile, since somebody else will fork and remove it. With Free Software, we'll still…
I agree with your sentiment, but want to provide a slight correction about "Free Software": MIT/BSD licensed software while not free in FSF/GPL sense, is still open and widely used and solves the problem we have right now. To avoid confusion with FSF ideals, I'd talk simply about Open Source software.
MIT/BSD are fully supported by the FSF and are GPL compliant. They are free software licenses in all aspects.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#54Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#55Earlier quoted context omitted.
Situations like these probably rarely produce a real "winner". It is going to be an arms race between those favoring personal privacy and those favoring government snooping. Just keep in mind that government operates basically on an unlimited budget and has access to a wide range of harassment opportunities for non compliance in matters like these. This fact alone will keep them at least at a dead level with potentia…
No, it's a win because the government is not the only, and in most cases not the worst, threat. Insiders (like Snowden and Manning, ironically) are one of the biggest threats. Being attacked by non-USG outsiders is a major threat ("hackers", state sponsored or not). Your business partners being hacked, or having lax security, is another threat. USG is probably near the bottom of the list of actual threats for most pe…
They're a threat to those who like running a Surveillance State, not to the average citizen.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#56Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…
Those things you speak of will be outlawed and you won't be allowed to use them.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#57Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#58I treat email in Gmail as publicly accessible, same for almost everything I do on the web casually. My business data lives in Amsterdam (Azure EU West), critical services we use are based in Europe. At least in my case I couldn't care less if the big US companies handed out SSL keys.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#59Earlier quoted context omitted.
No, it's a win because the government is not the only, and in most cases not the worst, threat. Insiders (like Snowden and Manning, ironically) are one of the biggest threats. Being attacked by non-USG outsiders is a major threat ("hackers", state sponsored or not). Your business partners being hacked, or having lax security, is another threat. USG is probably near the bottom of the list of actual threats for most pe…
> Insiders (like Snowden and Manning, ironically) are one of the biggest threats. They're a threat to those who like running a Surveillance State, not to the average citizen.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#60Earlier quoted context omitted.
/sarcasm -- (to be read in the voice of Sir Humphrey Appleby) I, for one, rely on my government to perform all those vital, but tragically under-appreciated services done selflessly and at great sacrifice, and all for the public good. Our top Whitehall mandarins do so much to pre^H^H^Hdeserve their salaries. The fabulous residences for the ambassadors, senior diplomats and other political appointees -- all those soci…
I don't understand your point. You could probably say the same about your family. The fact that something is not working as well as it should does not mean it's not essential. I mean, would you prefer feudal lords? Because that's what we had before central government, and that's what many corporations would like. Do you want to be ruled by Google? By Walmart?
Why is the default assumption by Statists that if the government won't rule us, corporations will?
A novel concept that people may want to attempt to grasp is that there could be no rulers, and as such, there's no need to make up a fictitious "new ruler".