Live data from Hacker News

Government Announces Steps to Restore Confidence on Encryption Standards

bits.blogs.nytimes.com

111–120 of 132 posts

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#111
post #34
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

Thats an interesting concept, I wonder if Russia and China have their own standards/protocols to use? I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.

None of this helps you if the random number generated that created your key is compromised.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#112
post #31

Earlier quoted context omitted.

I'm not sure you can separate those. If NIST is being systematically interfered with by the NSA, how can you have confidence in them?

+1 I don't get it, don't they get paid at NIST? Do they have moral values and ethics? Or it's okay to say " Hey NSA pressed us really hard to backdoor you all. So yes we did it, but we didn't really want to ", they are not judged for their initial intentions, they are judged for their wrongdoings. The NSA could say that (was said many times actually) the data retention in the end of the day is to protect America agai…

You seem to be assuming there's something NIST could have done about it. Based on what I've read, that doesn't seem to be the case. It seems like the NSA squeezed everyone else out so that they were the only ones calling the shots.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#113
post #89

This got my heart beating. There is actual rebellion among academics, and a movement to restore trust in both people and tech. This is the NY Times quoting Matt Green of John Hopkins in the article: “I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. Thats pretty strong sentiment. Seems to echo the bitterne…

Yes, Prof. Green posted a critical post about the NSA, and then JHU asked him to remove the post from their servers[1]. I'm stunned; academic freedom is evidently an illusion in some parts of the US. How deeply have our academic institutions been co-opted by the intelligence community? 1. JHU then had a dean apologize, but it was almost certainly only a reaction to the negative publicity that ensued: https://twitter.…

The apology was also removed.

With the NSA committing industrial espionage and able to do insider trading in order to fund its operations off the books I am sure they can also most generously "donate" money to Universities.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#114
post #111
post #34

Earlier quoted context omitted.

Thats an interesting concept, I wonder if Russia and China have their own standards/protocols to use? I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.

None of this helps you if the random number generated that created your key is compromised.

Even if you use different random number generators?

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#115
NIST should break ties with the NSA.

That's probably not possible/going to happen but that's what would happen with any other organisation severely breaching confidence like this.

Those are, however, the sort of big actions they need to show to have a chance at regaining trust.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#116
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

> How can any government accept a situation where communications are so secure that none of their agencies can break it?

Chief George Earle: Sensors all over the city can zero in on anyone at any time. I can't even conceive of what police officers did before it was developed.

John Spartan: We worked. This fascist crap makes me want to puke.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#117
post #79

Earlier quoted context omitted.

"How can any government accept a situation where communications are so secure that none of their agencies can break it?" In my opinion, the 4th amendment says the government needs a good reason and a warrant, and then we all agree they can read my gmail. We don't have to agree they can store, search, and use everyone's gmail for fighting crime, terrorism, or gaining economic advantage over other nations. Forget inter…

Even if they have a warrant, they can't read a well-encrypted email. What do they do then?

The get a warrant to put a key logger on your machine and get it that way.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#118
post #53

Earlier quoted context omitted.

“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. That's the understatement of the century. NIST is pissed off. Many of these guys move fluidly back and forth from NSA, and clearly they were kept in the dark.

" Many of these guys move fluidly back and forth from NSA... " This isn't regarded as a problem?

Part of the NSA's job is securing the United States cyber infrastructure, and the people tasked in that job take it just as seriously as the collection part. They sponsored SELinux, and their security guides are quite good:

http://www.nsa.gov/ia/mitigation_guidance/security_configura...

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#119
post #116
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

> How can any government accept a situation where communications are so secure that none of their agencies can break it? Chief George Earle: Sensors all over the city can zero in on anyone at any time. I can't even conceive of what police officers did before it was developed. John Spartan: We worked. This fascist crap makes me want to puke.

I'm currently living in Canada, and for a while people would say "Oh, you're from the London UK, I heard they have mass surveillance there and more cameras than people[1]". The worst to judge were Americans I met.

Well, it seems those manually watched cameras were the least of our worries.

[1] http://www.theguardian.com/uk/2011/mar/02/cctv-cameras-watch...

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#120
post #80
post #79

Earlier quoted context omitted.

Even if they have a warrant, they can't read a well-encrypted email. What do they do then?

They put you in prison until you hand over the keys. In the UK this is under RIPA. In the US there's probably some law they can kludge to fit - contempt of court or some-such.

What happens in situations like this if you use a hidden volume within an encrypted file using something like Truecrypt, which allows plausible deniability? You've supplied the "password" but the real meaty stuff is still hidden away...

http://www.truecrypt.org/docs/hidden-volume#Y0

Post reply on HN