Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

141–150 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#141
post #106
post #20

Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…

In terms of hardware safeguards, is it really an improvement when we have to rely on proprietary hardware safeguards that may have government "special features" silently built in, vs open source software that can be inspected by the public?

The point is to make the hardware itself feasible to verify. There are ways to do this arbitrarily well. Traditional HSMs are a very bad choice for "interesting" users for exactly this reason -- look what Crypto AG did to the Iranian Government and others, and other vs proofed commercial devices.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#142

Does the Federal government not understand that this (idiotic) mass scale surveillance is bad for business? All the big American companies generate most of their revenue outside of the US. Majority of the user-bases of the big Silicon Valley tech companies are foreign. This only works if there is a level of trust in the American system and American government. What are they thinking?!?!

> Does the Federal government not understand that this (idiotic) mass scale surveillance is bad for business? Emmm, it's the business interests that ask for those kind of things. You think the politicians operate on a vacuum? The idea is to get a stable climate where the business interests (multinationals and such) can do as they please, and citizens are afraid.

That's objectively false - Google, Microsoft, Yahoo, and Facebook (among others) have all been at pains to distance themselves from NSA data collection precisely because they understand how bad the NSA's behavior is for their business.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#143
post #55
post #37

Earlier quoted context omitted.

No, it's a win because the government is not the only, and in most cases not the worst, threat. Insiders (like Snowden and Manning, ironically) are one of the biggest threats. Being attacked by non-USG outsiders is a major threat ("hackers", state sponsored or not). Your business partners being hacked, or having lax security, is another threat. USG is probably near the bottom of the list of actual threats for most pe…

> Insiders (like Snowden and Manning, ironically) are one of the biggest threats. They're a threat to those who like running a Surveillance State, not to the average citizen.

Insiders are the biggest threat to any organization. Doesn't matter if it is USG and Manning or that Icelandic kid and wiki leaks or whatever. Independent of whether the org is good or evil.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#144
post #40

Earlier quoted context omitted.

I hope it works out similarly to how proliferation of public wi-fi led to increased adoption of https.

Did you know it is illegal to broadcast encrypted signals on HAM radio? Wonder how long it will take for that to come to the internet.

I didn't know that! I used to be a member of FidoNet (pre-internet network that provided e-mail and usenet-like services) back in 1990s and any commercial activity and encryption was similarly prohibited - relay operators were even supposed to read their users' mail and delete any messages that violated the rules.

I don't think there's any chance of this coming to the internet though. There are just too much uses for encryption besides conspiring for terrorist attacks.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#145
post #20

Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…

Just wondering - will older, but still decent hardware, start to become increasingly valuable since the hardware controls don't exist there? Will the value of my circa 2000 Dell PowerEdge take on new life?

I'm looking at ways to do an open source HSM using either trivially auditable/passive components (batteries, wire, wl gore fabric) and old cots components which you could buy from arbitrary sources, or buy a bunch of and inspect destructively.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#146
Articles like this miss the main issue.

Privacy rights should not have to be enforced at the public key encryption level.

Before all the sensationalists start going wild, remember that the NSA almost got defunded very recently. That is where the real frontier of this debate should be.

At best, this episode exposes how vulnerable public key encryption is. But let's not go off the reservation.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#148
post #118

This kind of thing makes me think the Snowden disclosures actually emboldened the NSA in some ways. Their nightmare scenario occurred, and nothing happened. Nobody even got fired or "resigned". The public's tepid reaction has brought our nightmare scenario to life - we taught secretive government agencies that they can now do anything they want without fear of public backlash. These kinds of requests can now dramatic…

What you say is true, but misses an important consideration: yesterday, only tinfoil hats believed they couldn't trust third-party companies with their privacy. Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer. The whole PRISM scheme worked because people supposed the government respected their privacy. Now that it's been proven false, I expect people to us…

Even on your local computer, it's probably a good idea to avoid operating systems that may be compromised by default. Also be careful about installing extra software, including browser plug-ins and addons. I am preaching to the converted though.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#149
post #40

Earlier quoted context omitted.

I hope it works out similarly to how proliferation of public wi-fi led to increased adoption of https.

Did you know it is illegal to broadcast encrypted signals on HAM radio? Wonder how long it will take for that to come to the internet.

Ham radio is a special case, and it is actually the Hams trying to block crypto. There is actually an FCC open rule making issue right now on the issue, and arrl is against it.

The solution is to develop protocols which use crypto but use a public key for now.

Post reply on HN