Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

201–210 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#201

This kind of thing makes me think the Snowden disclosures actually emboldened the NSA in some ways. Their nightmare scenario occurred, and nothing happened. Nobody even got fired or "resigned". The public's tepid reaction has brought our nightmare scenario to life - we taught secretive government agencies that they can now do anything they want without fear of public backlash. These kinds of requests can now dramatic…

Like with everything else than maybe virus outbreak, most changes takes time to affect entire community, economy or a country. Rome wasn't built in a day, so the Rome Empire didn't collapse in a day neither. Take me as an example. I am 8 years in US, married to US citizen. Green Card holder now and couple years ago our plan was for me to become a US Citizen and us to raise our kids on US soil. Not anymore. With all t…

With all the outcoming gov scandals, with government forcing you to vaccine your kids...

All other points aside for a moment: the government should force each and every parent to vaccinate their children. Herd immunity is a key factor in protecting most of the population from many awful diseases, and herd immunity is only effective if the vast majority are vaccinated. There's no credible evidence that vaccination causes autism or any other malady.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#202
post #129

> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan. No evidence in the article substantiates this bold statement. - "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of…

Public-key cryptography is a tool.

Yeah, I believe the author mistakenly conflated public-key cryptography with the public-key infrastructure (PKI). One is a technology and the other is a set of policies built around a trust model. While the technology remains sound, our confidence in the policies may be weakening. To prepare for this, we may need to look at alternative trust models such as web of trust.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#203

Earlier quoted context omitted.

Like with everything else than maybe virus outbreak, most changes takes time to affect entire community, economy or a country. Rome wasn't built in a day, so the Rome Empire didn't collapse in a day neither. Take me as an example. I am 8 years in US, married to US citizen. Green Card holder now and couple years ago our plan was for me to become a US Citizen and us to raise our kids on US soil. Not anymore. With all t…

With all the outcoming gov scandals, with government forcing you to vaccine your kids... All other points aside for a moment: the government should force each and every parent to vaccinate their children. Herd immunity is a key factor in protecting most of the population from many awful diseases, and herd immunity is only effective if the vast majority are vaccinated. There's no credible evidence that vaccination cau…

Yes vaccination is NOT a billion dollar business, vaccines do not kill people, and its perfectly logic you need to get shots against other peoples diseases BUT at the same time those who don't become a danger to you, yes.

http://money.cnn.com/magazines/moneymag/moneymag_archive/199...

http://articles.mercola.com/sites/articles/archive/2008/03/1...

http://vaccinedangers.com/

http://www.mercola.com/article/vaccines/neurological_damage....

http://vactruth.com/2013/02/23/17-examples-of-vaccine-failur...

I could go on and on here like the vaccines business is create problem & offer solution infinite loop, but I hope you can do a research on your own.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#204

Earlier quoted context omitted.

With all the outcoming gov scandals, with government forcing you to vaccine your kids... All other points aside for a moment: the government should force each and every parent to vaccinate their children. Herd immunity is a key factor in protecting most of the population from many awful diseases, and herd immunity is only effective if the vast majority are vaccinated. There's no credible evidence that vaccination cau…

Yes vaccination is NOT a billion dollar business, vaccines do not kill people, and its perfectly logic you need to get shots against other peoples diseases BUT at the same time those who don't become a danger to you, yes. http://money.cnn.com/magazines/moneymag/moneymag_archive/199... http://articles.mercola.com/sites/articles/archive/2008/03/1... http://vaccinedangers.com/ http://www.mercola.com/article/vaccines/neu…

If you don't feel like putting in a serious effort into presenting your argument, then I see no reason why anyone should take it seriously.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#205
post #20

Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…

> Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. A, the old "let's use technology to solve a political issue" idea. Sadly, it does not work. For one, the government has all the technology available for it too, including dedicated, full-time paid researchers. Second, they can outlaw any of those things at whim.

These criticisms of technological solutions always miss the obvious: both approaches complement each other.

If I send my aunt a letter, I am assured that unless there is a warrant, my letter to her will not be read by my government. She doesn't live in my country though, and her country gives no such assurances. More-so, even if it did, I would have no particular reason to trust her government. On that note, what if I don't trust my government?

Instead of sending her a regular letter, thanks to technology I have the option of mailing her a message encrypted with her PGP public key. Now I have to trust that my government will not beat me with a wrench or compromise my computer to gain access to the pre-encrypted letter (if I posses it), I have to trust her government to not beat her with a wrench or break into her computer, and I have to trust our governments to not outlaw PGP.

So which is preferable, finding political solutions to the "my aunt and I are being beaten with wrenches" problem, or finding political solutions to the "my letters are secretly being read without our knowledge" problem? I assert the former is preferable. Beating people with wrenches is a far more extreme action, it is easier to trust governments not to do something that is more extreme.

All of the problems with technical solutions are ultimately political problems. You can either abandon all technical solutions and only go for political solutions, or you can find political solutions to the shortcomings to technical solutions. Technical and political solutions complement each other, providing assurances that the other cannot. Both need to be pursued.

Don't want the government to read your mail? Encrypt it. Don't want your government to ban that? Lobby your position.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#206
post #110

Earlier quoted context omitted.

Right on, Clearly its also ok for the police to search your apartment at any time as well. You don't own your apartment, an apartment corporation does, so its clearly not a 4th amendment violation

Actually laws do protect private domain of a rental. It's the same reason the apartment companies themselves/landlords are not allowed to enter the apartment without your expressed consent.

They don't need consent, they just need to give notice.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#207

Earlier quoted context omitted.

Like with everything else than maybe virus outbreak, most changes takes time to affect entire community, economy or a country. Rome wasn't built in a day, so the Rome Empire didn't collapse in a day neither. Take me as an example. I am 8 years in US, married to US citizen. Green Card holder now and couple years ago our plan was for me to become a US Citizen and us to raise our kids on US soil. Not anymore. With all t…

Thanks for your perspective. I wonder which hot-button you pushed that caused the downvotes? My suspicion would be vaccination, but I'm not ruling out the gun-illustration (the word "drawing" is ambiguous in this case) or Bengazi...

Indeed, the downvotes seem bizarre to me. This response just looks like somebody sharing their experience in the matter in a coherent way. It could also be someone who doesn't want attention drawn away from their post.

Anyhow, I'm in Canada right now, and am in the next few years probably looking to change careers. I have good contacts with several top-tier tech companies in the US, and also with the auto industry and big oil. I've never really had much of a desire to live in the US, but now more than ever I'm finding myself looking to other potentially less lucrative positions just because of my distaste, much like the post above.

It really doesn't feel like a good time to be living in the US as a foreigner with an engineering degree, a very foreign sounding name and very liberal views. :-/

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#208
post #134

Earlier quoted context omitted.

If you're talking about the media, what did you expect? The mainstream media is just a mouthpiece for the government at this point.

I know that's a popular thing to say, but the mainstream media broke the story . In what way are they a government mouthpiece?

The media didn't break anything. Snowden gave them the story, which they have mostly ignored in favor of hit pieces against him as a traitor and a coward.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#209
post #177

Earlier quoted context omitted.

Self signed certificates throw up all kinds of nasty "you're taking lots of risks" in browsers (if they're allowed at all). I would not expect that they will be more broadly used than before, particularly since installing a self-signed certificate locally is very hard to do for the average person.

And looping back to the tin-foil hatters, many of us have called into question why all browsers have, over time, decreased their support for self-signed certificates. There are modes wherein Firefox will not even offer the "proceed anyway" option [1]. Conspiracy theories abound, but the browsers' marginalization of self-signed certificates has always struck me as devious. Yes, please do alert users that self-signed c…

I don't see it follows. If anything, self-signed certs just make it easier for the NSA (or anyone else) to capture your traffic. Organizations should probably set up their own CA instead.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#210

Earlier quoted context omitted.

> Aware and concerned tech-heads are trying to protect a drunken fool (the public) from a hungry bear (whoever it is that actually runs the intelligence networks). What self-important, self-aggrandizing bullshit.

Your comment leaves much to be desired.

And an attitude of comparing the public to drunken fools doesn't?
Post reply on HN