Live data from Hacker News

Government Announces Steps to Restore Confidence on Encryption Standards

bits.blogs.nytimes.com

41–50 of 132 posts

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#41
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

"How can any government accept a situation where communications are so secure that none of their agencies can break it?"

In my opinion, the 4th amendment says the government needs a good reason and a warrant, and then we all agree they can read my gmail. We don't have to agree they can store, search, and use everyone's gmail for fighting crime, terrorism, or gaining economic advantage over other nations.

Forget international committees. Smash the hard drives with my phone data in them that spooks can read at will.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#42
post #28

Want to know how to get a secure encryption standard? Do not develop it with the government involved, especially not the US government.

That doesn't ensure a lack of foul play. Even none government-employed developers could be turned into "agents" to insert code. Whether they're bought off or even just have strong patriotic motivations to begin with, you still need a stricter review process to ensure that no one country nor organisation has significant input nor control over the code.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#43
post #30

Earlier quoted context omitted.

America's conscience. In exile in Brazil.

Can you imagine the guy actually living in the USA? He would be annihilated by now.

That's hugely speculative. Just because his car's brakes might fail, it doesn't mean it wasn't an accident.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#44

You lost me at: "Government Announces Steps to Restore Confidence"

Trust is a fickle thing, but one thing that I have learned is that one vital element to building trust is to refrain from announcing your intention of doing so. Even having a "plan to build trust" is questionable - if you need to make such a plan, most likely you have already lost any chance of succeeding.

People must build trust entirely by themselves. If they don't build it themselves, it's not trust. It's persuasion.

And the willingness to be persuaded has been eliminated rather thoroughly, lately.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#45
post #37

Every standards body that is even remotely financed by governments or companies is a lie. ( http://www.ecma-international.org/publications/standards/Ecm... ) Committees rulings are a lie. ( http://www.textbookleague.org/103feyn.htm ) Even the most seemingly reasonable regulations are a lie. ( http://www.amazon.com/The-Truth-About-Drug-Companies/dp/0375... ) The sooner people realize there's no other option other than…

Who gets to vote in a direct democracy? My parents don't know anything cryptography, and are likely to base their decision on others, or even worse, a news source.

Right there, our parents outnumber us 2:1. Why should I trust the rest of America, who largely gets their information from media companies designed to optimize for ratings, on matters pertaining to cryptography?

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#46
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

Your augment makes sense, but somehow you're missing the idea that the government has infinite ways to investigate someone outside of breaking encrypted communication. They actually have people who can break into buildings and install keyloggers, or audio bugs, or interview witnesses, or anything you can imagine.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#47
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

Huh? There are lots of limitations on the power of government (and law enforcement). Why is it "asking a lot" for them to accept that?

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#48
post #34
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

Thats an interesting concept, I wonder if Russia and China have their own standards/protocols to use? I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.

OpenSSL supports these Russian GOST standards:

* md_gost94 message digest algorithm

* gost89 symmetric encryption algorithm with 256 bit key

* gost94 public key algorithm with 1024 bit public key

* gost94cp public key algorithm with 1024 bit public key (CP mode1)

* gost2001 public key algorithm based on elliptic curves with 512 bit public key

* gost2001cp public key algorithm based on elliptic curves with 512 bit public key (CP mode1)

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#49
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

Alan, Is it OK for government only to have the means to do targeted surveillance while dragnet surveillance is not possible? It seems technically possible(probably, that's where blackberry is at. There are a few technical means that might achieve that[1]) and it does fit needing to issue a warrant to do so.

Btw such a strong and capable regulatory framework that is always on, seems useful in regulating corporations and politicians, and if exists it should scare the hell out of them. I could see why they prefer it this way, with. Surveillance staying hidden in the shadows.

[1]one way to do this is strong encryption but medium endpoint security.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#50
post #39
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

Sounds ideal, until you realize that building and operating proper encryption is too hard for some of these organizations (PirateBay, FSF). For the rest, they are only mutually hostile on the surface. I am sure when it suits them they will get together and sell all our asses to each other.

You mean like Obama giving a tool to read his email to Putin? Unlikely IMO.
Post reply on HN