If anyone's interested in learning more of how you can use the private key of a server to monitor all communications: see, for example, US Pat. 7,543,051 It describes a way to passively/non-intrusively ("invisible to the server") capture and analyze all network traffic using a cable-tap. Bottom of column 8: "In order to accomplish decryption in a timely manner the secure traffic decryption unit needs the private key…
As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
261–270 of 295 posts
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#262Please forgive my rudimentary (and possible erroneous understanding. There are three things important to public-key encryption. The public key, the private key (together called the key pair) and a certificate. If I understand it the cert is just to give confidence that you have the correct public key. So the NSA having access to the cert is a non issue as everyone has access to same. That's its purpose in life. Also…
Your understanding of keys is about right. It is the OP article that your are not understanding. You ask "so how can the NSA decrypt such a message?" That's what the article is telling you: Either by 1) getting the private key from the corporation you are communicating with, or by 2) cracking the cryptography. Most people don't encrypt every email, they just use https to their email server. You say you're not sure ab…
The original article seemed to be a bit political and so I bailed on it. Perhaps I'm getting lazy in my old age.
Thanks for confirming my understanding about asymmetric keys. I forget how the pass phrase fits into this. Is it required in order to use the private key? Also the article and you use the term "master key". What is that? Is that just another term for private key?
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#263Earlier quoted context omitted.
Agreed. Public-key cryptography is fine. Entrusting third parties to protect your privacy is dying. This is something I have been thinking about a lot lately. Users need to take more responsibility for guarding their own privacy. I think there are a lots of business opportunities here: easy to use tools that keep control entirely in Alice's and Bob's hands and public key cryptography is certainly part of the solution…
The fact that the agencies have to apply pressure to obtain keys proves that the crypto is working. Therefore, if you have, use and keep secret your own keys, the best-resourced intruders cannot practicably get your data. Of course, http://xkcd.com/538/
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#264> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan. No evidence in the article substantiates this bold statement. - "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of…
The implication is simple and frightening -- classify it as munitions and making illegal to possess.
Remember that Constitution also allows one to have arms. Well arms in 1700s was rifle and that was a top weapon whether for government infantry or dissenting militants. What happened, you can still own arms but you can't own ICBMs, air-2-surface missiles, attack helicopters, nuclear devices etc. So as you can see just because something seems so inalienable, it can still be easily taken (not saying use of public crypto is a Constitutional right, just making a comparison between obvious rights easily stripped away).
Not only that, many country do make it illegal to have crypto software. It is not an outlandish proposition.
It won't take much to drum up support. Just need 3-4 high profile cases of: terrorists or child molesters using PGP and Joe Sixpack would be pretty easily convinced to call his representative and ask him to vote to make such "enabling tools" illegal.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#265Earlier quoted context omitted.
Agreed. Public-key cryptography is fine. Entrusting third parties to protect your privacy is dying. This is something I have been thinking about a lot lately. Users need to take more responsibility for guarding their own privacy. I think there are a lots of business opportunities here: easy to use tools that keep control entirely in Alice's and Bob's hands and public key cryptography is certainly part of the solution…
I've been thinking quite a lot about that exact thing as well. There must be a way to build great commercial tools that are also truly secure. I'd love to discuss further. Contact info in my profile.
> I've been thinking quite a lot about that exact thing as well. There must be a way to build great commercial tools that are also truly secure. I'd love to discuss further. Contact info in my profile.
'state', to solicit this collaboration, would it not be prudent to init a new HN account under a different name?
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#266This kind of thing makes me think the Snowden disclosures actually emboldened the NSA in some ways. Their nightmare scenario occurred, and nothing happened. Nobody even got fired or "resigned". The public's tepid reaction has brought our nightmare scenario to life - we taught secretive government agencies that they can now do anything they want without fear of public backlash. These kinds of requests can now dramatic…
I disagree with your usage of the past tense here. This is far from over, and I don't think the public's reaction was tepid.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#267Earlier quoted context omitted.
I don't, but then anything is possible. They could have invented Snowden in response to a credible threat from someone else that was planning to leak this or other even more sensitive materials. Anybody making similar disclosures today would have a tough time getting any attention because the Snowden story drew so little public outrage.
The Snowden story got huge traction. It will be the biggest story of 2013.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#268> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan. No evidence in the article substantiates this bold statement. - "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of…
> No evidence in the article substantiates this bold statement. The implication is simple and frightening -- classify it as munitions and making illegal to possess. Remember that Constitution also allows one to have arms. Well arms in 1700s was rifle and that was a top weapon whether for government infantry or dissenting militants. What happened, you can still own arms but you can't own ICBMs, air-2-surface missiles,…
You know we went through this in the 1990s and PGP was declassified as a munition, yes? http://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_in...
Before taking the claims at face value it's good to do a bit of background research. Also, I generally find anything where every paragraph consists only of a single sentence can safely be ignored.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#269Earlier quoted context omitted.
The Snowden story got huge traction. It will be the biggest story of 2013.
Zimmerman story was bigger, I'd say. Maybe Paula Deen too.
Snowden has gotten a lot more international coverage.
Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption
#270Earlier quoted context omitted.
You apparently missed the fact that the Obama administration had a full scale Democratic congressional revolt on its hands yesterday - a majority of congressional Dems voted to defund the NSA collection of bulk call records under FISA - the White House was seriously afraid the Amash Ammendment would pass - it only failed narrowly - 217 to 205. So in objective terms, the response has been far worse than the administra…
But still, everything continues as usual. Nobody is guilty. Nobody did anything wrong. And money to the program continues to flow.
>Nobody did anything wrong.
True and true. If I am not mistaken, What we've witnessed from James Clapper and General Alexander, it is legal for representatives from our federal surveillance agencies to openly lie in a Congressional oversight hearing.
This of course, if fact, is insane, and will only lead into extralegal catastrophe. Learn to read and reread `Clapperspeak'. When you look for it and know a little context, we see how entrenched and truthfully revealing it is:
"And Ye Shall Know the Truth, and the Truth Shall Make You Free"
- John 8:32, and the entrances of NSA, Fort Meade, Maryland, and the CIA HQ, Langley, VA
"Arbeit macht frei"
-Auschwitz, and the entrances of other Nazi slave labor camps during World War II