Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

131–140 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#131
post #92

Earlier quoted context omitted.

>> And there is little 'new ruler' can do to establish himself if people don't need a ruler. How charmingly naive! I don't know that people have needed a ruler at many times in history, but there has always been one. A power vacuum almost always results in war, revolution almost always results in war... basically humans like war and leaders. I don't think that will ever go away. We're tribal animals. Even if people d…

Well, if there is little government can do to control (like people using p2p currencies on a massive scale and encrypting their communications), and with production structure not suffering from possibility of monopolism (which we are close to having now), how will the government exercise their control? Of course we will always have some sort of government, but over years, it will become more and more irrelevant, not…

>> people using p2p currencies on a massive scale

I'm not of the faith that says that p2p or crypto currencies are necessarily a good thing. I, personally, think it's a good thing that democratic governments can exert control over fiat currency in order to attempt to mitigate economic disasters. I certainly don't think that the (for example) bitcoin model is a good one.

>> and encrypting their communications

I'm not really sure what this has to do with governments or control. I don't think democratic social order necessarily depends upon being able to surveil everyone, it's just a trap that the current bunch have fallen into.

>> production structure not suffering from possibility of monopolism

I'm not really sure what you mean here either, but it's hard to forsee a state in which monopolies are somehow impossible, or how the lack of them would imply the lack of need for government.

>> how will the government exercise their control?

In much the same way they do now, by the majority of us granting a democratic government a monopoly on the use of force. I'm not sure what bearing the form of currency, or encrypted comms, or even a utopian ideal of monopolistic impossibility have on this.

--edit-- Please do not take this as me saying either that I think the way governments have handled currency is good, or the way they do ... pretty much anything is all totally awesome. Far from it.

--edit 2-- The use of language is interesting here. Correct me if I'm wrong, but you see government as the external imposition of control on to otherwise free citizens? I see it as (at its best) free citizens banding together to achieve collective goals and prevent the worst of human nature overtaking us. The rhetoric and the social measures that come from government in this day and age are pretty abhorrent, but collective defence, roadbuilding, education etc are (to me) vital and useful functions.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#132
post #62
post #58

Earlier quoted context omitted.

If you think that operating in any particular jurisdiction provides you with protection then you are sadly deluded. Your protection lasts just up until the point where protecting you becomes inconvenient. Oddly enough, using the resources of smaller companies provides less protection because they are easier to influence, and basing services outside of the US means that you are completely fair game for the NSA as you…

The NSA itself has exactly zero power outside the USA.

Be careful that you do not equate "power" and "authority". As Canada mentions below, they have top talent, researchers, and likely many exploits. It seems foolish to believe that geographical location of entities on a globally connected network has a nontrivial bearing on whether the NSA can penetrate it.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#133

Earlier quoted context omitted.

I disagree with your usage of the past tense here. This is far from over, and I don't think the public's reaction was tepid.

Tepid? The response has been cooler than that.

You apparently missed the fact that the Obama administration had a full scale Democratic congressional revolt on its hands yesterday - a majority of congressional Dems voted to defund the NSA collection of bulk call records under FISA - the White House was seriously afraid the Amash Ammendment would pass - it only failed narrowly - 217 to 205. So in objective terms, the response has been far worse than the administration expected. And this policy tussle isn't over yet.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#134

Earlier quoted context omitted.

Tepid? The response has been cooler than that.

If you're talking about the media, what did you expect? The mainstream media is just a mouthpiece for the government at this point.

I know that's a popular thing to say, but the mainstream media broke the story. In what way are they a government mouthpiece?

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#135
post #118

This kind of thing makes me think the Snowden disclosures actually emboldened the NSA in some ways. Their nightmare scenario occurred, and nothing happened. Nobody even got fired or "resigned". The public's tepid reaction has brought our nightmare scenario to life - we taught secretive government agencies that they can now do anything they want without fear of public backlash. These kinds of requests can now dramatic…

What you say is true, but misses an important consideration: yesterday, only tinfoil hats believed they couldn't trust third-party companies with their privacy. Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer. The whole PRISM scheme worked because people supposed the government respected their privacy. Now that it's been proven false, I expect people to us…

Self signed certificates throw up all kinds of nasty "you're taking lots of risks" in browsers (if they're allowed at all). I would not expect that they will be more broadly used than before, particularly since installing a self-signed certificate locally is very hard to do for the average person.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#136

Earlier quoted context omitted.

Do you think it was planned by the NSA?

I don't, but then anything is possible. They could have invented Snowden in response to a credible threat from someone else that was planning to leak this or other even more sensitive materials. Anybody making similar disclosures today would have a tough time getting any attention because the Snowden story drew so little public outrage.

The Snowden story got huge traction. It will be the biggest story of 2013.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#137
post #48
post #22

Earlier quoted context omitted.

Any encryption scheme worth using will not be identifiable by a randomness test. Block ciphers like AES are designed specifically to model pseudorandom permutations (or, rather, this was one of their design goals); being able to distinguish them from truly-random data would be a rather frightening result. For more information, see "Is it possible to distinguish a securely-encrypted ciphertext from random noise?" at h…

Well, only two typical use cases will lead to owning a hard drive filled with (pseudo-)random noise: secure deletion or encrypted data. If you used either, you've got something to hide and it's a well-known fact only terrorists and communists do.

Or, radio telescope analysis. I wonder how hard it is to get a terabyte of radio telescope noise. If I had that, how hard would it be to use it to xor with a truecrypt partition.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#138
post #110

It's a neat argument that the Feds have. If you send traffic unencrypted: 'You have no expectation of privacy, because you're broadcasting information publicly.' Turn on encryption: 'Clearly you have something to hide, and deserve additional scrutiny. It's still not a fourth amendment violation because we are just compelling a business to give us your keys'

Right on, Clearly its also ok for the police to search your apartment at any time as well. You don't own your apartment, an apartment corporation does, so its clearly not a 4th amendment violation

Actually laws do protect private domain of a rental. It's the same reason the apartment companies themselves/landlords are not allowed to enter the apartment without your expressed consent.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#139
post #49

Earlier quoted context omitted.

I don't understand your point. You could probably say the same about your family. The fact that something is not working as well as it should does not mean it's not essential. I mean, would you prefer feudal lords? Because that's what we had before central government, and that's what many corporations would like. Do you want to be ruled by Google? By Walmart?

Do you want to be ruled by Google? By Walmart? Why is the default assumption by Statists that if the government won't rule us, corporations will? A novel concept that people may want to attempt to grasp is that there could be no rulers, and as such, there's no need to make up a fictitious "new ruler".

It's the assumption because it's how things have always happened. Do you have an example to the contrary, of any significant group of humans living without rulers for any significant amount of time?

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#140
Really, this article is silly. SSL keys will remain useful for authentication. If you want to make sure nobody's got the master key, just do a double-Diffie-Hellman and you're square...provided the person snooping on the master key isn't trying to use it to MITM you. That's a whole other bear entirely, though.
Post reply on HN