Something that people have apparently not quite connected is that these developments are incremental steps towards and can already be considered within the spectrum of mind reading. The only reason that that a majority of today's people do not recognize the situation as squarely in mind reading territory based on examples from literature and popular culture is that the the technical limitations still retrain governme…
As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
171–180 of 295 posts
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#172Earlier quoted context omitted.
Situations like these probably rarely produce a real "winner". It is going to be an arms race between those favoring personal privacy and those favoring government snooping. Just keep in mind that government operates basically on an unlimited budget and has access to a wide range of harassment opportunities for non compliance in matters like these. This fact alone will keep them at least at a dead level with potentia…
I can think of at least one counterexample, namely the failure of the NSA-promoted key escrow system in 1990s (aka Clipper chip)
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#173Earlier quoted context omitted.
Tepid? The response has been cooler than that.
You apparently missed the fact that the Obama administration had a full scale Democratic congressional revolt on its hands yesterday - a majority of congressional Dems voted to defund the NSA collection of bulk call records under FISA - the White House was seriously afraid the Amash Ammendment would pass - it only failed narrowly - 217 to 205. So in objective terms, the response has been far worse than the administra…
Nobody is guilty.
Nobody did anything wrong.
And money to the program continues to flow.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#174Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#175Please forgive my rudimentary (and possible erroneous understanding. There are three things important to public-key encryption. The public key, the private key (together called the key pair) and a certificate. If I understand it the cert is just to give confidence that you have the correct public key. So the NSA having access to the cert is a non issue as everyone has access to same. That's its purpose in life. Also…
As I understand it, the NSA could insert itself as a so-called "Men in the Middle" (aka MITM Attack). See this SO question for a far better explanation than I could provide: http://stackoverflow.com/questions/14907581/ssl-and-man-in-t...
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#176Something that people have apparently not quite connected is that these developments are incremental steps towards and can already be considered within the spectrum of mind reading. The only reason that that a majority of today's people do not recognize the situation as squarely in mind reading territory based on examples from literature and popular culture is that the the technical limitations still retrain governme…
Precisely, I agree that this is the logical direction in which this is heading. I think there's an implicit but rarely stated understanding - in silicon valley in particular - that there's value beyond traditional monetary capital in collecting and storing personalized information about individuals, groups, and organizations - i.e. security, profiling, recruitment and research value. Background checks for hires, sele…
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#177Earlier quoted context omitted.
What you say is true, but misses an important consideration: yesterday, only tinfoil hats believed they couldn't trust third-party companies with their privacy. Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer. The whole PRISM scheme worked because people supposed the government respected their privacy. Now that it's been proven false, I expect people to us…
Self signed certificates throw up all kinds of nasty "you're taking lots of risks" in browsers (if they're allowed at all). I would not expect that they will be more broadly used than before, particularly since installing a self-signed certificate locally is very hard to do for the average person.
Yes, please do alert users that self-signed certificates are potentially sourced by nefarious organizations. But in most cases, they are used by small companies and individuals to simply encrypted content from trusted servers. So allow them to be permanently trusted.
Perhaps we will see an increase in interest in web-of-trust alternatives?
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#178Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…
> Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. A, the old "let's use technology to solve a political issue" idea. Sadly, it does not work. For one, the government has all the technology available for it too, including dedicated, full-time paid researchers. Second, they can outlaw any of those things at whim.
For example, we could deprecate and eventually disallow TLS ciphersuites that don't provide forward secrecy, just like we did with single-DES, the NULL cipher, and "anonymous" (unauthenticated) encryption modes.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#179Earlier quoted context omitted.
What you say is true, but misses an important consideration: yesterday, only tinfoil hats believed they couldn't trust third-party companies with their privacy. Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer. The whole PRISM scheme worked because people supposed the government respected their privacy. Now that it's been proven false, I expect people to us…
> Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer. I agree with you, but I think you have far too much faith in ordinary Americans. I invented some widely used anti-phishing technology, and I can tell you that spending a few months analyzing actual incidents where otherwise intelligent people did ridiculously unsafe things on the Internet will give you a n…
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#180Earlier quoted context omitted.
What you say is true, but misses an important consideration: yesterday, only tinfoil hats believed they couldn't trust third-party companies with their privacy. Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer. The whole PRISM scheme worked because people supposed the government respected their privacy. Now that it's been proven false, I expect people to us…
> Today, everyone knows that the only way to have privacy is to handle it personally, from their local computer. I agree with you, but I think you have far too much faith in ordinary Americans. I invented some widely used anti-phishing technology, and I can tell you that spending a few months analyzing actual incidents where otherwise intelligent people did ridiculously unsafe things on the Internet will give you a n…
Moreover, even if only the 10% best informed people use PRISM-proof communications, it's a safe bet that NSA's alleged targets (whatever the current definition of "terrorist" might be) are among them, so the argument that they're doing that to catch "terrorists" doesn't hold water anymore.
I believe the tech community is concerned about this, because it threatens the robustness of Internet. Today, nobody in the business can pretend with a straight face that top-level certification authorities are trustworthy; so I expect the next generation of security protocols, the successors of the (transparent and enabled by default) SSL, to treat governments as opponents.
I also believe that companies will change their security patterns, e.g. stop trusting American third parties such as Microsoft if they have competitors with political connections in Washington.