Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

61–70 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#61
post #55
post #37

Earlier quoted context omitted.

No, it's a win because the government is not the only, and in most cases not the worst, threat. Insiders (like Snowden and Manning, ironically) are one of the biggest threats. Being attacked by non-USG outsiders is a major threat ("hackers", state sponsored or not). Your business partners being hacked, or having lax security, is another threat. USG is probably near the bottom of the list of actual threats for most pe…

> Insiders (like Snowden and Manning, ironically) are one of the biggest threats. They're a threat to those who like running a Surveillance State, not to the average citizen.

"They" specifically are... generally, the point is that 'insiders' are probably not motivated the same way but have the same access to data which they could leverage against a target.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#62
post #58
post #17

I treat email in Gmail as publicly accessible, same for almost everything I do on the web casually. My business data lives in Amsterdam (Azure EU West), critical services we use are based in Europe. At least in my case I couldn't care less if the big US companies handed out SSL keys.

If you think that operating in any particular jurisdiction provides you with protection then you are sadly deluded. Your protection lasts just up until the point where protecting you becomes inconvenient. Oddly enough, using the resources of smaller companies provides less protection because they are easier to influence, and basing services outside of the US means that you are completely fair game for the NSA as you…

The NSA itself has exactly zero power outside the USA.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#63
post #35
post #17

I treat email in Gmail as publicly accessible, same for almost everything I do on the web casually. My business data lives in Amsterdam (Azure EU West), critical services we use are based in Europe. At least in my case I couldn't care less if the big US companies handed out SSL keys.

Azure is , as far as I'm aware, still run by Microsoft (a US company).

IIRC it's run by Microsoft Ireland in the EU.

Even then, if the US would be to access EU-hosted data, with no real justification, the EU will not take that kindly. Especially private data.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#64
post #11

There is just so much more to public key crypto than public web SSL/TLS.

This is what I was thinking. This sounds more like certificates are broken than public key crypto. Yes they can come to me for my private key, but that's a different issue, then at least they're coming to me and not going to some intermediary "trusted party".

If certificates are broken then public key crypto is broken, because a trusted third-party certificate is necessary to prevent man-in-the-middle attacks, no?

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#66
post #49

Earlier quoted context omitted.

I don't understand your point. You could probably say the same about your family. The fact that something is not working as well as it should does not mean it's not essential. I mean, would you prefer feudal lords? Because that's what we had before central government, and that's what many corporations would like. Do you want to be ruled by Google? By Walmart?

Do you want to be ruled by Google? By Walmart? Why is the default assumption by Statists that if the government won't rule us, corporations will? A novel concept that people may want to attempt to grasp is that there could be no rulers, and as such, there's no need to make up a fictitious "new ruler".

>A novel concept that people may want to attempt to grasp is that there could be no rulers

It seems to me that the fastest way to evaluate this idea is to look at how an organization is propelled to statehood in the first place. If incentive structures support states, they will exist.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#68
post #6
post #2

Why can't PFS be a solution for this?

PFS and other Deniable encryption ( http://en.wikipedia.org/wiki/Deniable_encryption ) are great for deniability. However, they and everything else can be susceptible to unrelenting rubber-hose "cryptanalysis". ( http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis ) It is said that the goal of cryptography is to make the attacker resort to rubber-hose cryptanalysis, revealing their intentions. In those cases, the…

That can be a bad idea. Consider the case of you having revealed the contents of a truecrypt partition to the feds. You can't actually prove you showed them everything. There may be circumstantial evidence against you or the fed may be misled by some other factor beyond your control... or you may forget passwords or even lose security tokens. With deniable encryption, you may be guaranteeing yourself a treatment of the "rubber hose" with no way to say "stop".

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#69
If they're not careful they're going to endanger what access they have now. If secure communication as we know it ceases to be actually secure people will start (are now) figuring out how to go around points of failure. Meaning, if they push on this too hard they'll lose their ability to listen in on targeted communication because people will have more faith in unsigned than signed keys.

All it takes is one leak of this data to throw the entire idea "gimme your private key" requests into the domain of F###ing horrible ideas.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#70

If they're not careful they're going to endanger what access they have now. If secure communication as we know it ceases to be actually secure people will start (are now) figuring out how to go around points of failure. Meaning, if they push on this too hard they'll lose their ability to listen in on targeted communication because people will have more faith in unsigned than signed keys. All it takes is one leak of t…

Actually, how crazy would it be if the documents that Greenwald is sitting on now bring to light that this is already happening... it would overnight throw software best practices into chaos. I hope he's careful.
Post reply on HN