Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

121–130 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#121
post #92

Earlier quoted context omitted.

>> And there is little 'new ruler' can do to establish himself if people don't need a ruler. How charmingly naive! I don't know that people have needed a ruler at many times in history, but there has always been one. A power vacuum almost always results in war, revolution almost always results in war... basically humans like war and leaders. I don't think that will ever go away. We're tribal animals. Even if people d…

Well, if there is little government can do to control (like people using p2p currencies on a massive scale and encrypting their communications), and with production structure not suffering from possibility of monopolism (which we are close to having now), how will the government exercise their control? Of course we will always have some sort of government, but over years, it will become more and more irrelevant, not…

Then the incentive structures have changed to no longer support statehood. See my earlier comment on how to easily figure out the viability of the various forms of anarchism.

"It seems to me that the fastest way to evaluate this idea is to look at how an organization is propelled to statehood in the first place. If incentive structures support states, they will exist."

Since government is the current default, the onus is on you to prove that the incentive structures that select for statehood have changed in a significant way. (Or that they are going to change or could be changed.)

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#122
This article seems to be mostly FUD. Per-session, ephemeral SSL keys are available and are used by at least Google [1], CloudFlare[2], and others.

No keys are stored, no keys can be given to the NSA.

1 - https://www.imperialviolet.org/2011/11/22/forwardsecret.html

2 - http://blog.cloudflare.com/cloudflare-prism-secure-ciphers

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#123
post #118

This kind of thing makes me think the Snowden disclosures actually emboldened the NSA in some ways. Their nightmare scenario occurred, and nothing happened. Nobody even got fired or "resigned". The public's tepid reaction has brought our nightmare scenario to life - we taught secretive government agencies that they can now do anything they want without fear of public backlash. These kinds of requests can now dramatic…

What you say is true, but misses an important consideration: yesterday, only tinfoil hats believed they couldn't trust third-party companies with their privacy. Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer. The whole PRISM scheme worked because people supposed the government respected their privacy. Now that it's been proven false, I expect people to us…

> Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer.

I agree with you, but I think you have far too much faith in ordinary Americans. I invented some widely used anti-phishing technology, and I can tell you that spending a few months analyzing actual incidents where otherwise intelligent people did ridiculously unsafe things on the Internet will give you a new perspective on the tech savvy of the general population. Unless we (the tech community) make strong security both transparent to the user and enabled by default, the feds will be seeing everything they do. Sadly, most of them seem OK with that.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#124
post #71

Earlier quoted context omitted.

And this will last for approximately five minutes until a new ruler establishes themselves either through resource monopolisation or through pure threat of force. And they will never be short of toadies. Why is the default assumption by libertarians that if the government is brought down, human nature will suddenly, completely change?

My view of libertarianism is that it's not a movement to 'fight government'. It is just a system of views that once productive forces of society achieve certain level, government at least as we know it will become redundant. And there is little 'new ruler' can do to establish himself if people don't need a ruler.

>there is little 'new ruler' can do to establish himself if people don't need a ruler.

What about sending his group of followers door to door shooting people who don't acknowledge that he is the leader?

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#125

Earlier quoted context omitted.

Tepid? The response has been cooler than that.

If you're talking about the media, what did you expect? The mainstream media is just a mouthpiece for the government at this point.

Or is it the other way around? I honestly don't know anymore.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#126
Just a thought: For the better half of the 20th century, i.e. after WWII, Europe has been confronted and living with acts of terrorism from numerous sides (Israeli – just after WWII, Palestine, left-wing, right-wing, nationalist, etc, etc) with several severe casualties. Europe's democracies (for the better part at least) stepped back from drastic surveillance measures at will. (Partly because of the example of the Eastern block. Look up: Stasi.) It worked anyway.

So: There is no possible deal of security versus freedom as it has been proposed for the last 12 years or so. Sorry. It does not make sense. There is no proportion between the losses of freedom and identity, the investment, and the reported "less than 50 use cases" for the whole surveillance system. Please stop. Immediately.

Just saying, while we are losing digital identity.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#128

This kind of thing makes me think the Snowden disclosures actually emboldened the NSA in some ways. Their nightmare scenario occurred, and nothing happened. Nobody even got fired or "resigned". The public's tepid reaction has brought our nightmare scenario to life - we taught secretive government agencies that they can now do anything they want without fear of public backlash. These kinds of requests can now dramatic…

It's unfortunate but not surprising how little coverage this whole thing has had. I think as tech savvy individuals we need to do a better job of informing people of these events. The media won't care unless people care.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#129
> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan.

No evidence in the article substantiates this bold statement.

- "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of trust.)

- wiretaps, snooping, etc.: everyone is welcome to grab a copy of the ciphertext, this does not prove that cryptography is futile -- quite the contrary.

- "concerns about the security of widely used cipher algorithms and a range of other associated exploits": vague.

- "it is prudent to at least assume that intelligence agencies around the globe may still be working several steps ahead of public "state of the art" in crypto tech": unfalsifiable.

- "forced the hands of chip manufacturers to include "special goodies" for surveillance purposes": I am willing to fear deliberate plausibly deniable weaknesses on accelerated hardware implementation of crypto primitives, e.g., PRNGs, but it seems very hard to believe that implementations of public-key crypto using general purpose instructions could be somehow identified by the CPU and somehow tampered with in a way which would be non-obvious somehow.

- "when governments really want to target someone, they'll find some way to compromise the associated computers directly -- either through phishing or other malware attacks, or via in-person "black bag" jobs to physically alter systems as they might feel appropriate": humans are the weakest part of cryptosystems, and if they have physical access then they win; nothing new here.

In conclusion:

> I believe it would be fully appropriate for us to be considering alternative methodologies for data protection that are sufficiently outside the existing public-key "box"

Public-key cryptography is a tool. It certainly does not form, in itself, a full "methodology for data protection", but nothing in the article justifies that has lost any usefulness in its current form.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#130
post #68
post #6

Earlier quoted context omitted.

PFS and other Deniable encryption ( http://en.wikipedia.org/wiki/Deniable_encryption ) are great for deniability. However, they and everything else can be susceptible to unrelenting rubber-hose "cryptanalysis". ( http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis ) It is said that the goal of cryptography is to make the attacker resort to rubber-hose cryptanalysis, revealing their intentions. In those cases, the…

That can be a bad idea. Consider the case of you having revealed the contents of a truecrypt partition to the feds. You can't actually prove you showed them everything. There may be circumstantial evidence against you or the fed may be misled by some other factor beyond your control... or you may forget passwords or even lose security tokens. With deniable encryption, you may be guaranteeing yourself a treatment of t…

There is no way to say "stop" anyway, it's up to them if they stop. Look at Guantanamo...
Post reply on HN