Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

81–90 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#81
post #71

Earlier quoted context omitted.

Do you want to be ruled by Google? By Walmart? Why is the default assumption by Statists that if the government won't rule us, corporations will? A novel concept that people may want to attempt to grasp is that there could be no rulers, and as such, there's no need to make up a fictitious "new ruler".

And this will last for approximately five minutes until a new ruler establishes themselves either through resource monopolisation or through pure threat of force. And they will never be short of toadies. Why is the default assumption by libertarians that if the government is brought down, human nature will suddenly, completely change?

My view of libertarianism is that it's not a movement to 'fight government'. It is just a system of views that once productive forces of society achieve certain level, government at least as we know it will become redundant. And there is little 'new ruler' can do to establish himself if people don't need a ruler.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#82
post #62
post #58

Earlier quoted context omitted.

If you think that operating in any particular jurisdiction provides you with protection then you are sadly deluded. Your protection lasts just up until the point where protecting you becomes inconvenient. Oddly enough, using the resources of smaller companies provides less protection because they are easier to influence, and basing services outside of the US means that you are completely fair game for the NSA as you…

The NSA itself has exactly zero power outside the USA.

European snooping agencies seem to be quite happy to cooperate with them, so that argument doesn't really count.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#83
post #36

A logical conclusion to this is that if/when governments start forcing people to supply them with their private keys, they will also start forcing companies producing encryption software to include backdoors. At this point, I'm thankful that we have Free Software. With access to the source code, forcing the insertion of a backdoor is futile, since somebody else will fork and remove it. With Free Software, we'll still…

At this point, I'm thankful that we have Free Software.

Me too, which is why I'm worried about hardware. With enough effort, literally anyone can decide not to trust a binary and check the source. Unfortunately, the same cannot be said for hardware: you can't print your own microchips.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#84
post #64

Earlier quoted context omitted.

This is what I was thinking. This sounds more like certificates are broken than public key crypto. Yes they can come to me for my private key, but that's a different issue, then at least they're coming to me and not going to some intermediary "trusted party".

If certificates are broken then public key crypto is broken, because a trusted third-party certificate is necessary to prevent man-in-the-middle attacks, no?

No. The trust model of HTTPS was always broken from the start. This whole story "only" reinforces the point that key distribution and management is hard, and a central list of certificate authorities is not a good solution.

This story has exactly zero effects if you use some public-key system with different key management.

On the negative side, good systems don't really exist. On the plus side, this story might help push the development of good systems.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#85

Earlier quoted context omitted.

I agree with your sentiment, but want to provide a slight correction about "Free Software": MIT/BSD licensed software while not free in FSF/GPL sense, is still open and widely used and solves the problem we have right now. To avoid confusion with FSF ideals, I'd talk simply about Open Source software.

I think you might be a bit confused. MIT/BSD are fully supported by the FSF and are GPL compliant. They are free software licenses in all aspects.

> MIT/BSD are fully supported by the FSF and are GPL compliant. They are free software licenses in all aspects.

To be clear, GPL compliance is not a prerequisite to being a free software license. There exist many free software licenses which are not technically GPL compliant for various reasons: http://www.gnu.org/licenses/license-list.html#GPLIncompatibl...

However, while freedom does not imply GPL compliance, I do believe GPL compliance implies freedom. I'm not 100% certain of this, but I can't think of a counterexample or how that might not be true.

(I know you probably know this, but I want to make sure others reading your comment do too).

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#86
post #9

Earlier quoted context omitted.

Don't rely on government for anything? What are you talking about? Almost 100% of scientific research and 100% of infrastructure around the world is funded by government. Almost all of education, health and welfare around the world (though less so in the US) is run by government. A lot of people are suspicious of government, but such fundamental disdain toward and alienation from government are peculiar American (and…

Libertarian socialism is more popular in Europe than in America, and they, too, strongly disdain governments.

I think many in Europe have a disdain for governments because our countries have experienced tyranny up close and personal, if not experienced it directly. Many European countries have at some point in fairly recent history have had governments that have gone too far against their own people (Spain, Greece, Turkey, Italy spring to mind for example, but also to a lesser extent France, the UK, East Germany, Poland etc.).

In many European countries there's been a history of oppression and a state controlled press that spouts untruths, which makes people quite skeptical and untrusting of governments. Indeed, some countries still have this or a notionally free press that's hampered through other means.

There's an almost brave new world-like contrast in the US whereby having the illusion of a free press and free democracy has lead many Americans to believe they're free, even though they're supporting things that work against them collectively.

I'm not bashing America, there are many free-thinking Americans (on this site especially) and there are many non-free-thinking Europeans, I'm just trying to highlight some of the differences.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#87
It's a neat argument that the Feds have.

If you send traffic unencrypted: 'You have no expectation of privacy, because you're broadcasting information publicly.'

Turn on encryption: 'Clearly you have something to hide, and deserve additional scrutiny. It's still not a fourth amendment violation because we are just compelling a business to give us your keys'

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#88
post #37
post #25

Earlier quoted context omitted.

Situations like these probably rarely produce a real "winner". It is going to be an arms race between those favoring personal privacy and those favoring government snooping. Just keep in mind that government operates basically on an unlimited budget and has access to a wide range of harassment opportunities for non compliance in matters like these. This fact alone will keep them at least at a dead level with potentia…

No, it's a win because the government is not the only, and in most cases not the worst, threat. Insiders (like Snowden and Manning, ironically) are one of the biggest threats. Being attacked by non-USG outsiders is a major threat ("hackers", state sponsored or not). Your business partners being hacked, or having lax security, is another threat. USG is probably near the bottom of the list of actual threats for most pe…

I always assumed "zombie apocalypse" was code for "civil uprising" anyway.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#89
Technology changes and so does the world, whether we like it or not. The question is always, who will come out on top

I'm not really trying to be snide, but it really is an issue that's been sort of hanging around since the before I was born (1980s), who's going to control the internet and how, and whoever does is probably going to have a lot of power

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#90
post #72

Something that people have apparently not quite connected is that these developments are incremental steps towards and can already be considered within the spectrum of mind reading. The only reason that that a majority of today's people do not recognize the situation as squarely in mind reading territory based on examples from literature and popular culture is that the the technical limitations still retrain governme…

You mean, we have a new paradigm, an unprecedented new perspective and ability, so the first thing we're gonna use it for is to try and kill as many people as we can before they kill us?
Post reply on HN