Live data from Hacker News

Government Announces Steps to Restore Confidence on Encryption Standards

bits.blogs.nytimes.com

31–40 of 132 posts

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#31
post #16

I suspect that NIST is just another government organization trying to do their jobs, and I don't think it's fair that their name got dragged through the mud. The truth is that the NSA practically co-opted NIST's decision-making strategy. I have confidence in NIST. Sadly, I don't have confidence in the NSA to not muddy up the process.

I'm not sure you can separate those. If NIST is being systematically interfered with by the NSA, how can you have confidence in them?

+1 I don't get it, don't they get paid at NIST? Do they have moral values and ethics? Or it's okay to say "Hey NSA pressed us really hard to backdoor you all. So yes we did it, but we didn't really want to", they are not judged for their initial intentions, they are judged for their wrongdoings. The NSA could say that (was said many times actually) the data retention in the end of the day is to protect America against terrorism. Problem is no one believes them.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#32
The cynic in me says "of course they want us to trust their flawed encryption standards, otherwise there's no point back-dooring them in the first place." I suspect, however, that this has more to do with high-profile businesses complaining about the damage that's been done to them in the last few weeks.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#33
This got my heart beating. There is actual rebellion among academics, and a movement to restore trust in both people and tech. This is the NY Times quoting Matt Green of John Hopkins in the article:

“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday.

Thats pretty strong sentiment. Seems to echo the bitterness of Rogaway: http://www.cs.ucdavis.edu/~rogaway/politics/surveillance.pdf

This is an important question of our times, and the cryptography experts should speak up like this. They have the credibility, and the ear of the people and media.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#34
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

Thats an interesting concept, I wonder if Russia and China have their own standards/protocols to use?

I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#35
Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following:

How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this.

Such a situation is fine for "us", and great for government, in that it means they them selves can communicate with confidence. But to expect government to accept a situation where there is zero way they can snoop or investigate is asking a lot. Its a huge risk to government. So, I think we have to forget that idea completely, as attractive as it is to the likes of me.

As others have said, its procedural or legal, not technical. What is needed is a rock solid frame work and set of rules that properly limit how the snooping is done. What is needed is a universal bill of online or electronic rights. Not just for the USA, but something that can apply to any country and government. I'd suggest it should be developed by an international group, UN backed, and made part of being a member. Or could it be something that has to be agreed to as part of acquiring IP addresses or domain names. Dunno, but tie it in some how.

Ok, I'm not sure that works totally as I have set it out, Im no lawyer, and others may well want to modify it, but we need something international as the internet is international. We all need protection, not just Americans. We need a base level to work from. Something we can all accept as reasonable, workable and enforceable. Most of all, we need confidence in using communications and those regulating it.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#36
post #5

The weird bit is the NYT did it on their own website instead of Ars. It's also super classy of Ars to cite a second report by the NYT then link to their own summary of that article too! http://bits.blogs.nytimes.com/2013/09/10/government-announce...

Mike Masnick calls it a complete non-response from NIST, regarding the real issue/accusation: http://www.techdirt.com/articles/20130910/12371124473/nists-...

When was Mike Masnick last happy about anything?

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#37
Every standards body that is even remotely financed by governments or companies is a lie. (http://www.ecma-international.org/publications/standards/Ecm...)

Committees rulings are a lie. (http://www.textbookleague.org/103feyn.htm)

Even the most seemingly reasonable regulations are a lie. (http://www.amazon.com/The-Truth-About-Drug-Companies/dp/0375...)

The sooner people realize there's no other option other than a direct democracy since governments and companies are untrustworthy, the better.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#38

This got my heart beating. There is actual rebellion among academics, and a movement to restore trust in both people and tech. This is the NY Times quoting Matt Green of John Hopkins in the article: “I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. Thats pretty strong sentiment. Seems to echo the bitterne…

If I remember correctly back in beginning of 1990s there was a discussion in the US about preventing export of encryption protocols, then it was a discussion about making laws where a suspect is obliged to give up his/her key just like in the UK to agencies, and someone even mentioned making encryption unavailable or forbidden by law for civilians. All in the name of "we wont be able to catch criminals if we cant listen in on communications". Up to that point in time, encryption and secure communications was reserved for agencies and those in power, it was not for the plebians. See for example how it went for PGP.

I guess a route that US agencies took is to "we will recommend good standards for you, because you know we also need security, but you shouldnt know all those standards and implementations will be compromised so we still retain the ability to spy on you while you wont be able to spy on us and if you do then you're a traitor".

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#39
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

Sounds ideal, until you realize that building and operating proper encryption is too hard for some of these organizations (PirateBay, FSF). For the rest, they are only mutually hostile on the surface. I am sure when it suits them they will get together and sell all our asses to each other.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#40
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

Why not use ISO, they are doing a fine job on the C standard without the help of NIST.
Post reply on HN