Live data from Hacker News

Pervasive Monitoring Is an Attack

tbray.org

21–29 of 29 posts

Re: Pervasive Monitoring Is an Attack

#21

TFA says "PM is an attack ... and this is a consensus of the IETF". On the other hand, IETF continues to employ NSA employees (like Kevin Igoe, a co-chair of Crypto Research Group under IETF[1] ). So: is it a consensus or not? Does Mr. Igoe consider PM an "attack", even though his own employer does it? I'm having trouble reconciling the two. [1] http://article.gmane.org/gmane.ietf.irtf.cfrg/2337

The IETF considered replacing Igoe. No consensus was reached. People with lots of IETF institutional credibility (ie: that had been instrumental in previous standardization efforts, ones in which no tampering concerns were entertained by anyone) strongly disagreed with his ouster.

Also, from a political perspective, the effort to replace Igoe was hamstrung by the lack of anyone in the universe raising their hand and saying "I'm a respected cryptographer AND I want to punch myself in the face continuously for several years by chairing CFRG".

The less reverence the Internet has for the cryptographic wisdom of the IETF, the better off I think we all are.

Re: Pervasive Monitoring Is an Attack

#22
post #17

TFA says "PM is an attack ... and this is a consensus of the IETF". On the other hand, IETF continues to employ NSA employees (like Kevin Igoe, a co-chair of Crypto Research Group under IETF[1] ). So: is it a consensus or not? Does Mr. Igoe consider PM an "attack", even though his own employer does it? I'm having trouble reconciling the two. [1] http://article.gmane.org/gmane.ietf.irtf.cfrg/2337

> I'm having trouble reconciling the two. Why? It's extremely common for industry/standardization groups like the IETF to come to conclusions that are contrary to the position of one of its members, and it usually doesn't result in said member being expelled or falling on their sword.

Tell that to that Sterling guy who owns the Clippers.

Actually I agree with your statement.

Re: Pervasive Monitoring Is an Attack

#23

> if your ap­pli­ca­tion doesn’t sup­port pri­va­cy, that’s prob­a­bly a bug in your ap­pli­ca­tion. Amateur radio is explicitly not for traffic that needs to remain private. It exists for limited purposes not including routine communication that can be served by other means (e.g. a phone or ordinary internet connection). It is chiefly for education and research/experimentation in radio. It is not for general persona…

IANAL. The ham radio community needs to raise this with the FCC. This section was originally constructed a long time ago (1993?). I'm guessing it's biased this way to stop 1940's era spys from operating.

The regulations prohibit various forms of commercial use, e.g. preventing a cab company from moving its dispatch onto the 2m ham band— a reasonable policy since there is limited spectrum and commercial parties could easily overrun it: but if the traffic is encrypted how is the community management supposed to function?

Personally I'd like to see the regulations adopt special rules for highly directional or low-power limited-range signals in the SHF+ bands where there is plenty of spectrum which basically drops all the content rules beyond requiring cleartext contact information. Without competition for spectrum the balance of interests is different and it would be nice to be able to lawfully backhaul community internet access over some chunks of spectrum up at 3cm. Since no one would likely notice or care you could already use crypto in these places, so it might as well be made permitted.

Re: Pervasive Monitoring Is an Attack

#24

TFA says "PM is an attack ... and this is a consensus of the IETF". On the other hand, IETF continues to employ NSA employees (like Kevin Igoe, a co-chair of Crypto Research Group under IETF[1] ). So: is it a consensus or not? Does Mr. Igoe consider PM an "attack", even though his own employer does it? I'm having trouble reconciling the two. [1] http://article.gmane.org/gmane.ietf.irtf.cfrg/2337

Most blackhats will cheerfully acknowledge that what they are doing is wrong. They just think it isn't very wrong. Everyone does things they know to be wrong. Even very wrong.

Update: Formatting. (can't we get a preview, please?)

Re: Pervasive Monitoring Is an Attack

#25
post #21

TFA says "PM is an attack ... and this is a consensus of the IETF". On the other hand, IETF continues to employ NSA employees (like Kevin Igoe, a co-chair of Crypto Research Group under IETF[1] ). So: is it a consensus or not? Does Mr. Igoe consider PM an "attack", even though his own employer does it? I'm having trouble reconciling the two. [1] http://article.gmane.org/gmane.ietf.irtf.cfrg/2337

The IETF considered replacing Igoe. No consensus was reached. People with lots of IETF institutional credibility (ie: that had been instrumental in previous standardization efforts, ones in which no tampering concerns were entertained by anyone) strongly disagreed with his ouster. Also, from a political perspective, the effort to replace Igoe was hamstrung by the lack of anyone in the universe raising their hand and…

What do you think about IETF-JOSE? I've been using it as sort of a cookbook for signing and encryption. They even have a cookbook: http://datatracker.ietf.org/doc/draft-ietf-jose-cookbook/

Re: Pervasive Monitoring Is an Attack

#26
post #25
post #21

Earlier quoted context omitted.

The IETF considered replacing Igoe. No consensus was reached. People with lots of IETF institutional credibility (ie: that had been instrumental in previous standardization efforts, ones in which no tampering concerns were entertained by anyone) strongly disagreed with his ouster. Also, from a political perspective, the effort to replace Igoe was hamstrung by the lack of anyone in the universe raising their hand and…

What do you think about IETF-JOSE? I've been using it as sort of a cookbook for signing and encryption. They even have a cookbook: http://datatracker.ietf.org/doc/draft-ietf-jose-cookbook/

JOSE includes JSON canonicalization, which scares the crap out of me. If I had the choice, I'd treat JSON as binary --- a whitespace change would, for a signed file, break the signature.

JOSE also includes RSA PKCS1v1.5 signatures, which are deprecated (you should use RSA-PSS, which JOSE also documents).

It includes naive nondeterministic DSA, which should be deprecated in favor of deterministic DSA or something like Ed25519.

It doesn't include details you actually want about curve selection. (Also, P-521?!)

It includes encryption under RSA PKCS1v1.5 (encryption with v1.5 is even worse than signing under it) and AES-CBC, which is disfavored by cryptographers.

(My understanding of JOSE is cursory, at best, so I wouldn't be surprised to be corrected on any of these).

Re: Pervasive Monitoring Is an Attack

#28

> if your ap­pli­ca­tion doesn’t sup­port pri­va­cy, that’s prob­a­bly a bug in your ap­pli­ca­tion. Amateur radio is explicitly not for traffic that needs to remain private. It exists for limited purposes not including routine communication that can be served by other means (e.g. a phone or ordinary internet connection). It is chiefly for education and research/experimentation in radio. It is not for general persona…

IANAL. The ham radio community needs to raise this with the FCC. This section was originally constructed a long time ago (1993?). I'm guessing it's biased this way to stop 1940's era spys from operating.

I’m too lazy to look it up but I would be surprised if many of the founders of the internet where not ham operators. Again I’m being lazy about looking it up but if not specifically in writing at least in spirit I believe one of the purposes of the armature radio program has been to advance wireless communication and technology.

Right now strong encryption and authentication are where most of the efforts in the field seem to be focused. It should be at the forefront of the experimentation being done by amateur radio operators.

Not that I really have an answer to the problem of bandwidth abuse. I completely understand how this would be a problem and have no doubt that it would be abused.

Post reply on HN