Live data from Hacker News

More Encryption Is Not the Solution

queue.acm.org

61–70 of 88 posts

Re: More Encryption Is Not the Solution

#62
post #36
post #18

Encryption can be circumvented. It's hard, but doable for a state, when it targets one high-value suspect. But if everything is encrypted, they can't go "big data" on it and collect everything about everyone: if proper encryption is generalized, spying doesn't scale anymore. Big companies' ability to break the encryption between them an you is irrelevant: if they're the legitimate receiver of the communication, they…

I think the take-away from this article is that the political/legal environment is part of implementation detail you need to consider when considering a "private" communication mechanism. No crypto-system is truly secure unless BOTH sides can be trusted. If either one is even remotely possible to compromise, then that will happen . In the case where one of those parties is well-known and has something to lose, you ca…

Of course we have a form of Clipper through such agreements. Lotus Notes had a secret key escrow mechanism that was discovered in the '90s. It is very unlikely that Notes was the only supposedly secure product with secret arrangements with law enforcement and/or intelligence services, and it is even less likely that the pace and intensity of such arrangements has declined since then.

On the other hand, Edward Snowden thinks he can secure information effectively from attempts to crack it. He probably had practical knowledge of the day-to-day capabilities of the NSA when he worked there. There is no reason that most everything that you and I store and transmit can't be equally well-protected.

Re: More Encryption Is Not the Solution

#63
post #54
post #27

Earlier quoted context omitted.

It's like hygiene. A few hundred years back people weren't washing their hands and health was very bad. As soon as we understood the germ theory of disease, we learned hygiene and now we are much better. With encryption and privacy it will be the same. People will need to learn new skills. Unfortunately, what we need to do is as cumbersome as a surgeon prepping for operation - it takes too much care to make sure you…

And if there's a backdoor on your hardware then they have access to all your plaintext before encryption ... I can imagine a day when face to face communication gets really popular, even critical for some people.

I wonder if one day, 3d printing will be cheap enough so that one could go to the local hackerspace, Print print out chips, assemble the board/internal devices and be sure to be free from hardware backdoors?

Re: More Encryption Is Not the Solution

#64
post #31

Earlier quoted context omitted.

> a well-thought-out weakness can easily be worth [a lot] Indeed, but my point is, in addition to be worth a lot, it's difficult to implement, and it's very fragile. Every time they use it, they gamble its secrecy, hence its effectiveness. So they won't use it for petty reasons, only for genuine national security matters. The problem isn't that NSA works on ensuring national security: it's that the scope of what they…

The problem isn't NSA. It's the President(s) and Congress who define the scope. Call me naive, but I think that most of the folks at NSA, even many of the leaders, are patriots who believe that they are protecting their country.

If you believe that politicians control the bureaucracy rather than the other way around, then I respectfully disagree.

Bureaucrats have expertize, inertia, the ability to sabotage many things, long term stable positions, and care about how things actually are, rather than how they look to the average voter. In many cases, including this one IMO, politicians have the appearance of control, but very little actual latitude in practice.

If you want a cruel but funny illustration of this, may I suggest that you read [http://www.amazon.com/The-Complete-Yes-Minister-ebook/dp/B00...] or watch [http://www.amazon.com/Open-Government/dp/B0015KOTY2] Yes Minister? It compellingly illustrate how an administration can manipulate a politician, what they call the "house training" of a minister.

Re: More Encryption Is Not the Solution

#65
post #36

Earlier quoted context omitted.

I think the take-away from this article is that the political/legal environment is part of implementation detail you need to consider when considering a "private" communication mechanism. No crypto-system is truly secure unless BOTH sides can be trusted. If either one is even remotely possible to compromise, then that will happen . In the case where one of those parties is well-known and has something to lose, you ca…

> Have YOU inspected your CPU/Firmware/OS/Applications for backdoors? Even with the full source code? this is absolutely spot on, especially the firmware. nobody talks about it and the attack surface is huge. just to be explicit, hardware backdoors exist as well :)

Completely agree. Anybody recall the TPM? Security is pretty much turtles all the way down.

Encryption isn't going to help stop a guy with a stick from beating the information out of you. A functional state, however, can help prevent such things from happening.

Re: More Encryption Is Not the Solution

#66
post #59

Earlier quoted context omitted.

The most surefire way isn't in trusting those who betrayed the trust. It's in making their efforts to spy on us futile.

TFA just explained why this is not a "surefire" way. Not to mention that the last 40 years not much progress has been made in this direction (if any). Also: the other proposition also helps putting a better government in place. The "technological" solution, even if it worked, it would only solve the very specific problem of privacy. Not the much more important problem of a government that betrayed the trust of the pe…

Not the much more important problem of a government that betrayed the trust of the people.

We've built a system that makes sure liars and demagogues get into office. Until people are on board with putting an end to such a system of elections, the only way to change the political landscape will be to circumvent it.

Re: More Encryption Is Not the Solution

#67
I have seen more bad things happening from politics than from encryption. Politics, in just about any nation, is the never ending cancer of "making deals". The never-ending tit for tat, the compromise. We need NO compromise. I'm in my 60's now, and have seen the internet been born. Actually I contributed to that birth while working at Arpa. Privacy, no matter how I look at it, is ABSOLUTE. Also for criminals, and yes, even for terrorists. Humans have the natural expectation of privacy. That's probably difficult to absorb for many reading this medium. Every human being has the ultimate right to be in charge of his or her own mind. Politics conflicts with privacy, all the time. Politics established the rule of law, and, did so by and at the convenience of those with the loudest noise and the toughest axes. Since none of us is capable, willing or able to put the politicians out of (our) business, we can only find resolve in taking care ourselves, and thus deploy encryption. And we do have good quality crypto. And it is even free. Can it be broken? Over time, yes. But complexity, volume and speed can make that a fairly long trajectory. Can it be broken by quantum-cryptanalysis? Probably yes, but even that is more than 30 years away to be in infant stage. The real problem is the endpoint security. Well, work on it, make it better, improve it. Don't just stand there and accept God knows who to run away with YOUR thoughts, ideas, inventions, preferences or problems. And by all means, please do NOT think that government, any government, is the only one looking at your data. There is an entire commercial world busy with your stuff without you knowing about it. ---RTF PS: and yes, this is anonymous. My students would probably scaffold that I'm a weakling :)

Re: More Encryption Is Not the Solution

#68
post #26

Encryption is not absolutely safe because it relies on trusting in who's at the other end, but it surely is much better than using clear net. We can still trust a few entities, right? We need to collectively scrutinize and make informed guesses about who to trust. At the moment I set up TOR and use Starpage.COM instead of Google. Auto-delete cookies after closing the tabs and actively remove ads and tracking JS from…

That's a good idea, but it falls down the first time someone in the crowd starts downloading cp. Instead of having one, or a few, people being traced to their IP and investigated for cp, you now have 1,000 people under suspicion. You can protect users by ensuring that the box doesn't log any information about them, but then the box's admin is the one being held responsible.

'cp' above apparently means child porn.

I read it wondering 'If at first they come for cp, what about mv? rm?'

Re: More Encryption Is Not the Solution

#70
This silly defeatism is killing you guys.

Just use bloody SIP or any other cryptographically-sound protocol; maintain trust with people and their personal endpoints, rather than companies which are obviously under enormous state pressure(the threat of violence and imprisonment, and the rape included with that, for life) to give up the goodies.

We have other issues, including the pervasive use of proprietary software trading convenience over the pragmatic requirement of not having industrial or governmental espionage committed against you.

Intel is under grave pressure to inject these bugs into their CPUs, and even a well-audited system such as OpenBSD is not modular enough to prevent remote exploitation through network stacks(see the last two remote vulnerabilities), but laziness leaves them on monolithic kernels.

Even if the systems worked correctly, proprietary firmware in PCIe devices like network cards and graphics cards allows them to directly access memory on the bus, generally with very little protection, and often enough with none at all.

You guys are buying all of this crap, supporting the people who subjugate and bend.

You paid them knowingly to do all of this crap(in addition to raping, killing, and enslaving hundreds of millions or billions in other countries), and you continue to today.

If you want this stuff to stop happening, you need to simply stop knowingly supporting these things, and playing dumb when you learn the specifics.

Post reply on HN