Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

251–260 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#251
post #36

A logical conclusion to this is that if/when governments start forcing people to supply them with their private keys, they will also start forcing companies producing encryption software to include backdoors. At this point, I'm thankful that we have Free Software. With access to the source code, forcing the insertion of a backdoor is futile, since somebody else will fork and remove it. With Free Software, we'll still…

At this point, I'm thankful that we have Free Software. Me too, which is why I'm worried about hardware. With enough effort, literally anyone can decide not to trust a binary and check the source. Unfortunately, the same cannot be said for hardware: you can't print your own microchips.

Hardware? More than One Billion people are walking around with computers in their pockets running closed source, proprietary, binary blobs. These computers constantly track their owners while being connected to most (if not all) of their private communications services.

Even people running a "fully" open source OS are affected.

Not even the Ubuntu phone will help this problem for which there is no end in site.

This is off topic, but it's high time we open source cellular radio drivers.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#252
post #229

Earlier quoted context omitted.

All forms of public key encryption require proof that Alice or Bob are who they say they are or you can setup a man in the middle attack. Without a public key athority to Safely provide the correct public key your stuck with manual key exchanges which can work, but does not scale. If the government has the public key authority's private key they can spoof them and setup man in the middle attacks easily.

Web of trust. So say I meet someone visiting from the US that I trust, he gets my public key and signs it, and vice versa, then I can guarantee to people who have my pubkey that the one I'm sending them is his one.

Web of trust has massive scaling issues. The most obvious being a rooted devices can quickly compromise the network and your talking about a huge attack surface if your willing to trust more than one link in the chain.

Edit: Realistically if you want secure peer to peer communications your protocalls has to survive when 40+% of peers are compromised and well good luck with that at scale. This seems like a reasonable problem but you also need to be able to revoke certificats.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#253
post #181

Earlier quoted context omitted.

Tens of thousands caring out of a population of 350 million is 0.03% of the population. That's kinda tepid. But should Paula Deen have been fired from Food Network? Crisis of epic proportions!

You might want to consume different sources of news media. The only times I've heard the name "Paula Deen" was in conversation with my parents and grandparents. I'm sure her travails (whatever they are or were) amount to a crisis for some people, but you don't have to pay attention to those people.

Oh. Your parents and grandparents aren't Americans, then?

Look, if you hang with the hipsters who "consume" better media, then sure, you won't have any clue what the vast majority of the public cares about. It's not surveillance. It's whatever mass opiate has been focus-grouped out for the week.

In the meantime, though, that mass opiate is mainlined into every public space in the land on countless television monitors in essentially every place where a person has to spend more than 30 seconds. They've got no time to think about the future - they've got to be outraged about this week's 15-minute hate, or admire this week's baby, or fear this week's terrorist.

You may simply not visit those downscale places. Good on you. But Washington really doesn't care, except to the extent that you earn more money they can extract or possibly build more centralized data processing services they can mine.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#254
post #252

Earlier quoted context omitted.

Web of trust. So say I meet someone visiting from the US that I trust, he gets my public key and signs it, and vice versa, then I can guarantee to people who have my pubkey that the one I'm sending them is his one.

Web of trust has massive scaling issues. The most obvious being a rooted devices can quickly compromise the network and your talking about a huge attack surface if your willing to trust more than one link in the chain. Edit: Realistically if you want secure peer to peer communications your protocalls has to survive when 40+% of peers are compromised and well good luck with that at scale. This seems like a reasonable…

You make it sound like Web of Trust does not include revocation.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#255

Earlier quoted context omitted.

1st off, the last link you have there is a brilliant example of a failure to use Bayesian reasoning. > its perfectly logic you need to get shots against other peoples diseases BUT at the same time those who don't become a danger to you You don't understand herd immunity. It amplifies a weak individual immune boost (say, a 40% effictive vaccine) into a dramatic effect on the actual number of people who get sick. Here'…

Thanks for response, I upvoted you. I wasn't clear in my first post. I am not against major vaccines, the problem is that today by age 8 you have many more shoot than those you had only 20 years ago. I fail to believe life on Earth change soo much that we all need so many more shots to survive. Like with any other business, pharma sees opportunity to oversell and creates tons of unnecessarily shots that your local CS…

> I am not against major vaccines

Oh, good :)

> today by age 8 you have many more shoot than those you had only 20 years ago

There are two factors at play. One is evolution: there's a new flu every year (bacteria and virii can meaningfully evolve in less than a year, even). The other is that we are finding ways to vaccinate against more and more diseases. The diseases always existed, but your odds of catching them were higher then than they are now even if you don't vaccinate yourself because of herd immunity. There are still plenty of diseases we don't know how to vaccinate against, so expect the trend to continue.

> pharma sees opportunity to oversell

Yeah, and the US system is particularly vulnerable to those pressures. There are still protections: you couldn't get a placebo approved, even a well designed one. But single-payer systems are much better at focusing on efficacy. The other side to that is the US gets drugs first and sometimes exclusively. Just because a vaccine falls below the threshold of what the EU is willing to pay doesn't mean it won't save hundreds or thousands of lives in the US. We pay twice as much for health care and this is one of the (very) few extra privileges we enjoy as a result. Best take advantage of it :)

> older man who got a shot and 2 weeks later got sick exactly on something he was getting shot against

I still don't think you grok herd immunity. Vaccines do very little to protect the individual. If you would have gotten sick before the vaccine, you would probably still get sick after the vaccine. But if everyone gets vaccinated, the disease dies away.

It's like a nuclear bomb. Below critical mass, it's just moderately radioactive. Above critical mass, you get a huge explosion. Vaccines keep a disease from getting to critical mass. They don't stop individuals from getting sick very well (they don't stop the radioactivity) but they reduce it just enough to prevent pandemics (nulear explosions).

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#256
post #252

Earlier quoted context omitted.

Web of trust. So say I meet someone visiting from the US that I trust, he gets my public key and signs it, and vice versa, then I can guarantee to people who have my pubkey that the one I'm sending them is his one.

Web of trust has massive scaling issues. The most obvious being a rooted devices can quickly compromise the network and your talking about a huge attack surface if your willing to trust more than one link in the chain. Edit: Realistically if you want secure peer to peer communications your protocalls has to survive when 40+% of peers are compromised and well good luck with that at scale. This seems like a reasonable…

What about some sort of web of trust model that has a notion of confidence. Lets say I have four people; Alice, Bob, Carol, and me. I know both Bob and Carol, but I don't know Alice directly. Since both Bob and Carol vouch for Alice, I can be fairly sure that Alice is Alice. Now lets say that Bob has reason to believe that Alice has been compromised, so he revokes his link to Alice. Now I have am less confident about Alice, because I have one link to Alice instead of two. Or is this how Web of trust works?

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#257
post #129

> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan. No evidence in the article substantiates this bold statement. - "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of…

Agreed. Public-key cryptography is fine. Entrusting third parties to protect your privacy is dying. This is something I have been thinking about a lot lately. Users need to take more responsibility for guarding their own privacy. I think there are a lots of business opportunities here: easy to use tools that keep control entirely in Alice's and Bob's hands and public key cryptography is certainly part of the solution…

The fact that the agencies have to apply pressure to obtain keys proves that the crypto is working.

Therefore, if you have, use and keep secret your own keys, the best-resourced intruders cannot practicably get your data.

Of course, http://xkcd.com/538/

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#258
post #44

Earlier quoted context omitted.

And what if they say "That data was obviously innocuous so there must be another encrypted partition"?

You could try putting something embarassing but not incriminating there (e.g., gay porn or whatever).

Sure, but my point is that plausible deniability always comes paired with plausible accusibability. Hell, the very fact that you had one encrypted partition massively increases the probability that you have more than one. Most people don't even know how to set one up. I think you'd be way better off simply claiming you didn't have one.

One way or another, you're going to be relying on reasonable doubt in the end.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#259
post #44

Earlier quoted context omitted.

And what if they say "That data was obviously innocuous so there must be another encrypted partition"?

You could try putting something embarassing but not incriminating there (e.g., gay porn or whatever).

Aha, obviously you are quite cunning, therefore you knew that I would expect a second partition, so there must be a third partition!

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#260

Earlier quoted context omitted.

> Does the Federal government not understand that this (idiotic) mass scale surveillance is bad for business? Emmm, it's the business interests that ask for those kind of things. You think the politicians operate on a vacuum? The idea is to get a stable climate where the business interests (multinationals and such) can do as they please, and citizens are afraid.

That's objectively false - Google, Microsoft, Yahoo, and Facebook (among others) have all been at pains to distance themselves from NSA data collection precisely because they understand how bad the NSA's behavior is for their business.

PUBLICLY, they have (Yahoo appears to be honestly resisting), Microsoft on the other hand was cracking open Skype before they even had taken the bow off.

From a PR standpoint, whether you are for or against the NSA program, you absolutely have to oppose it as an online multinational business.

Post reply on HN