Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

271–280 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#271
post #264

Earlier quoted context omitted.

> No evidence in the article substantiates this bold statement. The implication is simple and frightening -- classify it as munitions and making illegal to possess. Remember that Constitution also allows one to have arms. Well arms in 1700s was rifle and that was a top weapon whether for government infantry or dissenting militants. What happened, you can still own arms but you can't own ICBMs, air-2-surface missiles,…

The implication is simple and frightening -- classify it as munitions and making illegal to possess. You know we went through this in the 1990s and PGP was de classified as a munition, yes? http://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_in... Before taking the claims at face value it's good to do a bit of background research. Also, I generally find anything where every paragraph consists only of a single s…

Exactly that was my point. It was only 20 year ago. It was declassified as munition it can be reclassified as munitions pretty easily as well.

> Before taking the claims at face value it's good to do a bit of background research.

It also good to read and understand the whole comment before replying. I didn't say it is illegal (in US, it is in other countries) I said it is not an unreasonably hard step to take.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#272

This kind of thing makes me think the Snowden disclosures actually emboldened the NSA in some ways. Their nightmare scenario occurred, and nothing happened. Nobody even got fired or "resigned". The public's tepid reaction has brought our nightmare scenario to life - we taught secretive government agencies that they can now do anything they want without fear of public backlash. These kinds of requests can now dramatic…

You can call it boldness, but at this point I'm not sure how you'd distinguish it from an extinction burst[1], or "getting while the getting's still good."

1. http://youarenotsosmart.com/2010/07/07/extinction-burst/

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#273
The whole cert structure has always been a house of cards. As evidenced last year, e.g, with the Turkish provider ...

Since I first looked through the original Netscape, I've never had -any- reason to put so much trust in the hands of these Blue-Ribbon names. Or any ISP, for that matter. If US intelligence goes through with this, then only end-to-end (which has been deliberately stalled off and roadblocked and stonewalled for decades) will be left.

At that point we'll find out just how much power we've left to defend the privacy of our communications, our relationships, our finances and our movements. The Cryptocat guy may yet become a legend... or someone like him.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#274
post #252

Earlier quoted context omitted.

Web of trust has massive scaling issues. The most obvious being a rooted devices can quickly compromise the network and your talking about a huge attack surface if your willing to trust more than one link in the chain. Edit: Realistically if you want secure peer to peer communications your protocalls has to survive when 40+% of peers are compromised and well good luck with that at scale. This seems like a reasonable…

What about some sort of web of trust model that has a notion of confidence. Lets say I have four people; Alice, Bob, Carol, and me. I know both Bob and Carol, but I don't know Alice directly. Since both Bob and Carol vouch for Alice, I can be fairly sure that Alice is Alice. Now lets say that Bob has reason to believe that Alice has been compromised, so he revokes his link to Alice. Now I have am less confident about…

This is how bitcoin works. The network will adopt whatever the majority agree on in terms what transactions happened. As a result, you can't man-in-the-middle bitcoin and it remains secure even without centralized key signers, because you can increase your confidence by confirming a transaction with as many nodes as you want. This is how you validate a local block chain - you connect to enough other bitcoin clients in the swarm such that at some confidence threshold you agree your chain is the correct one. The usual number is 8 independent connections in the bitcoin network (both for blockchain verification and confirmation of transaction acceptance) because the probability of getting 8 bad actors agreeing to the same fraudulent transaction is mathematically demonstrated to be sufficiently low.

Note: that is (besides the 51% attack vector) the primary reason the bigger parts of the crypto scene won't call bitcoin truly secure. Because there is still a risk of insecurity, it is just abysmally small, and disrupting one node doesn't mean the degradation of the web of trust because as long as the majority still agrees on the correct state of affairs (and as a false block chain diverges it becomes more expensive to maintain that public facing fork to disrupt other clients).

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#275
post #129

> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan. No evidence in the article substantiates this bold statement. - "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of…

You are totally nitpicking on semantics. Obviously the general concept of public key encryption is not at risk.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#276
post #271

Earlier quoted context omitted.

The implication is simple and frightening -- classify it as munitions and making illegal to possess. You know we went through this in the 1990s and PGP was de classified as a munition, yes? http://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_in... Before taking the claims at face value it's good to do a bit of background research. Also, I generally find anything where every paragraph consists only of a single s…

Exactly that was my point. It was only 20 year ago. It was declassified as munition it can be reclassified as munitions pretty easily as well. > Before taking the claims at face value it's good to do a bit of background research. It also good to read and understand the whole comment before replying. I didn't say it is illegal (in US, it is in other countries) I said it is not an unreasonably hard step to take.

I read your whole comment, I just don't agree with you. It would be wholly impractical to reclassify PGP as munitions considering its ubiquitous availability. It got declassified in the first place because there was strong legal precedent supporting the publication of the algorithm in book form. I think your fears are unreasonable.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#277
post #219

Earlier quoted context omitted.

I don't know what would have to happen for you to consider the response substantial. Would citizens need to be forming militias and actively marching in the streets? That's just not how people react anymore. Tens of thousands of people called their congresspeople on a day's notice to express their support for the Amash Amendement. That amendment lost by only 12 votes. A large majority of people polled think that the…

A few tens of k's is remarkable. There's a fallacy of thinking "people aren't doing anything about it, therefore they don't care". In fact, people don't "do something" because they estimate, rightly or wrongly, that they can't do anything that would make a difference. Millions worldwide protested the current US wars when they were getting started, but they went ahead on schedule. What, exactly, can citizens do to eff…

I find it sad, but that is the conclusion I came to, as well.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#278
post #270
post #173

Earlier quoted context omitted.

But still, everything continues as usual. Nobody is guilty. Nobody did anything wrong. And money to the program continues to flow.

>Nobody is guilty. >Nobody did anything wrong. True and true. If I am not mistaken, What we've witnessed from James Clapper and General Alexander, it is legal for representatives from our federal surveillance agencies to openly lie in a Congressional oversight hearing. This of course, if fact, is insane, and will only lead into extralegal catastrophe. Learn to read and reread `Clapperspeak'. When you look for it and…

I think many of us in the United States saw this coming when the current administration stated they would not be addressing the previous administration's law breaking.

The law is now "in your face" optional, depending on how much money and/or power is involved. Power has always had undue influence, it is just flagrant now.

From what I read, this is fairly common among many countries, so I take it as part of the "human condition."

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#279
post #129

> Public-key cryptography as we know it today may be rapidly approaching the end of its useful lifespan. No evidence in the article substantiates this bold statement. - "pressuring major Internet firms to provide their "master" SSL keys for government surveillance purposes": this demonstrates a weakness of centralized public-key infrastructures, it does not follow that public-key cryptography is doomed. (See: web of…

You are totally nitpicking on semantics. Obviously the general concept of public key encryption is not at risk.

"As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption"

Obviously.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#280
post #209
post #177

Earlier quoted context omitted.

And looping back to the tin-foil hatters, many of us have called into question why all browsers have, over time, decreased their support for self-signed certificates. There are modes wherein Firefox will not even offer the "proceed anyway" option [1]. Conspiracy theories abound, but the browsers' marginalization of self-signed certificates has always struck me as devious. Yes, please do alert users that self-signed c…

I don't see it follows. If anything, self-signed certs just make it easier for the NSA (or anyone else) to capture your traffic. Organizations should probably set up their own CA instead.

That's what we meant. IIRC you can't even use a self-signed certificate directly for authentication: you have to create your own self-signed root CA, then use it to sign you authentication certificate.

The point is, if what you do interest the US government, it can compel Verisign and the likes to betray your trust, so you shouldn't trust them. And what emerges progressively is that the threshold beyond which you're deemed "interesting" by US administrations is way lower than long believed.

If you're a company doing international business, you want to secure your strategic communications with your own root CA, not with that of a company who can't say no to the government.

Post reply on HN