Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

151–160 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#151
Please forgive my rudimentary (and possible erroneous understanding. There are three things important to public-key encryption. The public key, the private key (together called the key pair) and a certificate. If I understand it the cert is just to give confidence that you have the correct public key. So the NSA having access to the cert is a non issue as everyone has access to same. That's its purpose in life. Also the public key is publicly available or the system wouldn't work. The only sensitive things are the private keys. Is this right so far? If I want to encrypt a message to someone I need to use that person's public key. I use the cert to make sure I have the right one. Now the message can only be decrypted with the private key. So how can the NSA decrypt such a message? They would need the private key. The ISP doesn't have it. Even if they have the private key don't they need a pass phrase to use it?

Not sure how the above applies to https or to ssh. Still, in both cases I don't think access to the cert breaks things. Indeed access to it and the public keys are essential to it working at all. (I guess one can operate without the cert too if you trust the source.)

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#152
post #72

Something that people have apparently not quite connected is that these developments are incremental steps towards and can already be considered within the spectrum of mind reading. The only reason that that a majority of today's people do not recognize the situation as squarely in mind reading territory based on examples from literature and popular culture is that the the technical limitations still retrain governme…

Precisely, I agree that this is the logical direction in which this is heading.

I think there's an implicit but rarely stated understanding - in silicon valley in particular - that there's value beyond traditional monetary capital in collecting and storing personalized information about individuals, groups, and organizations - i.e. security, profiling, recruitment and research value.

Background checks for hires, selection and identification of possible good candidates for roles, psychological profiles, etc could all - theoretically - be extracted given enough information. For now it is - allegedly - being used purely to identify and track bad elements, but these dubious 'values' exist in the data regardless (and, notably, also for attackers).

Knowing the intent of individuals and what they plan to do would clearly be massively valuable as well - PKD 'pre-crime' springs to mind, and I think Eric Schmidt was strongly signalling to the world that Google is hunting this value aggressively during this 2010 interview:

http://www.businessinsider.com/eric-schmidt-we-know-where-yo...

As connectivity spreads and devices become closer to our biological selves, this is only going to become more accurate - and thus more powerful and controlling for anyone with the ability to use and see the data.

The real questions I have are: how accurate are these predictions really (is Google anywhere near as advanced as their public statements would have us believe?), and how many organized criminals / terrorists will in their right minds continue to use these services, extrapolating, as they must, about these directions as well. With the current silicon valley mindset, the technologies to support all this infrastructure will be pursued even if for reasons of pure capital - they all align perfectly with valid use cases in the advertising, sales and marketing realms. (see: intent analysis)

I think there is a dream of purely computerized security based on 'enough' global buy-in to US-based services, aligned with sufficient communications interception. For example, if 70% of the world uses US services for communications, perhaps that is enough to identify suspicious holes/gaps/anomalies in social networks - as well as simpler patterns of criminal behaviour within the covered communications - and thus anticipate problems.

But whether this is near a reality, and whether the ones who suffer on aggregate are {citizens/residents} or {organized crime, terrorists} I think is very unclear without transparent statistics on coverage / actual crime preventions / etc. I would guess that the NSA, GCHQ, Facebook, Google et al are not there yet, but what they have done is create an arms race where if they do not follow-through, others elsewhere may do - and thus it has become a matter of national security (in terms of supremacy of the allies) after all.

Frankly I would question given the financial crisis whether they are even hunting the right targets, but direction is presumably still set from a political and defence angle as opposed to overall public good.

Given that other nations are likely now following in these same footsteps, I think it is extremely important that the US sets good precedents, because others will take their lead. And to make a parallel with the cold war, it seems like resolution of this kind of arms race would need co-ordination and agreement with other international spy agencies - after all, the volumes and value of the data/analysis they are storing is presumably as potentially destabilizing to international safety as nuclear stockpiling is.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#153
post #122

This article seems to be mostly FUD. Per-session, ephemeral SSL keys are available and are used by at least Google [1], CloudFlare[2], and others. No keys are stored, no keys can be given to the NSA. 1 - https://www.imperialviolet.org/2011/11/22/forwardsecret.html 2 - http://blog.cloudflare.com/cloudflare-prism-secure-ciphers

That's only true in a pure eavesdropping scenario. The keys would still allow MITM attacks.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#154
post #129

> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan. No evidence in the article substantiates this bold statement. - "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of…

[deleted]

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#155
post #23

Earlier quoted context omitted.

'such fundamental disdain toward and alienation from government are peculiar American' This. If you're so unshakably convinced that a government full of people you vote for every four years is never going to work in your interests, you have serious problems.

I wish you counted the officials you voted for and compared it to the number of governmental bureaucrats, agents, and other persons that are assigned , never elected, and often stay at their offices as elected officials change. The number of non-elected officials is vastly larger than the few thousand elected officials people vote for. Not that governments (and other bureaucratic bodies) never work in your interests.…

Many implementations of democracy have this problem, most prominent example of course the US.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#156
post #23

Earlier quoted context omitted.

'such fundamental disdain toward and alienation from government are peculiar American' This. If you're so unshakably convinced that a government full of people you vote for every four years is never going to work in your interests, you have serious problems.

I wish you counted the officials you voted for and compared it to the number of governmental bureaucrats, agents, and other persons that are assigned , never elected, and often stay at their offices as elected officials change. The number of non-elected officials is vastly larger than the few thousand elected officials people vote for. Not that governments (and other bureaucratic bodies) never work in your interests.…

Many implementations of democracy have this problem, most prominent example of course the US.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#157
post #36

A logical conclusion to this is that if/when governments start forcing people to supply them with their private keys, they will also start forcing companies producing encryption software to include backdoors. At this point, I'm thankful that we have Free Software. With access to the source code, forcing the insertion of a backdoor is futile, since somebody else will fork and remove it. With Free Software, we'll still…

But wasn't there an issue with the random seeds (and them possibly being corrupted) even in Free Software?

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#158
post #154
post #129

> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan. No evidence in the article substantiates this bold statement. - "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of…

[deleted]

which time?

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#159
All this increased digital surveillance comes at a time when the US Post Office is under artificial financial pressure. Just last night the news reported a plan to eliminate direct delivery to the door in favor of some sort of community mail box facilities. Interesting coincidence that physical letters (whose contents are still protected by federal statute) are being discouraged while unprotected content is being collected.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#160

Earlier quoted context omitted.

The thing is, for all its supposed power, government is really bad at marketing. People tend to see only what they don't like about government while simultaneously enjoying the benefits from various services that are provided by the government. As in those "get the government out of my medicare" signs that were seen in the US. (Cue the "blah blah markets can do it blah blah" responses - no, I'm sorry, but even econom…

> while simultaneously enjoying the benefits from various services that are provided by the government. Using these services because there's no practical way not to is just the reality of our system. Taking a few scraps from your masters to survive does not mean you agree with your chains.

I'm curious, what's your ideal political arrangement? How do you propose we provide for transportation infrastructure, medical services, police, fire departments, etc? I'm not convinced that abolishment of the state is possible or even ideal, but I'm open to discussion.
Post reply on HN