Live data from Hacker News

Government Announces Steps to Restore Confidence on Encryption Standards

bits.blogs.nytimes.com

91–100 of 132 posts

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#94

It's too fucking late. Government, we don't trust you anymore. You're not a part of us. For once, I'm ashamed of being an American.

Well, that's silly. All of our "Freedom!"-loving allies seem to be in on this. UK, Australia, Sweden, etc. This article mentions that the standards process was being run by Canada, and the Canadians were "finessed" by the NSA. Canada? Really?

And, of course, the non-"Freedom!" countries do this also.

The only difference between the US and all the other countries is the amount of smarts, work, and money the US is putting into subverting privacy. Some of the other countries just seem to be along for the ride.

Of course, as Warren Buffet once said, "You’re looking for three things in a person: intelligence, energy, and integrity. And if they don’t have the last one, don’t even bother with the first two." Because if they don't have integrity, the last thing you want is for them to be smart and driven.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#95
post #14

Earlier quoted context omitted.

I suppose that was a bit presumptuous of me. My apologies. The whole spiel has made several rounds on HN, though [1], and Ars reported again on the matter about a week ago [2]. But I do acknowledge that doesn't necessarily mean much... not everyone has the time (or the inclination!) to follow such matters. [1] https://www.hnsearch.com/search#request/all&q=dual_ec_drbg&s... [2] http://arstechnica.com/security/2013/09/…

"The whole spiel has made several rounds on HN, though [1]" If you look at this discussions, HN commenters were very skeptical this was an NSA backdoor. The speculative possibility isn't news; the fact very much is. https://news.ycombinator.com/item?id=4580434

That's the thing, though: this article doesn't say that the NSA did generate the Dual_EC_DRBG constants with a backdoor in mind. It just says that internal memos suggest and appear to confirm that they did.

That is, the article isn't really anything new.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#96
post #69

I hate all this NSA spying but they do have a point - if they cant read the communications of the bad guys, how are they supposed to catch them before it's too late. Isn't there a way to accomplish both objectives of security and preserving constitutional freedoms?

Yes but it relies on an informed electorate holding mostly honest elected officials to account while said officials hold the tools of state to account. In other words no.

The justice dept caught a bunch of mafiosos without violating the rights of everyone else. Why? Because judges oversaw the handing out of search and wire-tapping warrants. A balance was found between security and liberty. Unfortunately, what is happening now is that we are lead to believe it is one or the other. And it's made worse when the debate gets trapped in the "right vs left", "conservative vs liberal" context.

Seems to me that the judicial system needs to get more involved in this. Congressional oversight of NSA, TSA, DOD, etc has not really worked.

There is also a role for technology to play. Out of millions of calls, billions of emails, how do you flag that one bad guy? The implicit assumption in such a problem is that you collect the data on everyone so that you can look for patterns of bad guy behavior. But is there another way?

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#98
post #34
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

Thats an interesting concept, I wonder if Russia and China have their own standards/protocols to use? I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.

Counterintuitively, sequentially applying additional crypto doesn't necessarily improve security; in theory, it may actually damage it.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#100
post #53

Earlier quoted context omitted.

“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. That's the understatement of the century. NIST is pissed off. Many of these guys move fluidly back and forth from NSA, and clearly they were kept in the dark.

Nitpicking but why understatement? Feeling betrayed sounds more serious that just pissed off.

The actual words I wanted to use wouldn't be appropriate in daily conversation. The most accurate substitutes would be incensed, enraged, livid.

"Feeling betrayed" implies skulking about with a sad expression. In reality, from what I hear, I imagine it's more like senior NIST officials roaming the halls at Fort Meade looking for somebody at whom to scream strings of obscenities.

Post reply on HN