If you look at the incentives for Apple in this scenario: It's best for them if we all think their phones are secure. And it's also best for them if they dont piss off LEO. So the rational thing for them to do, is convince us all they have strongly encrypted their phones, while continuing to provide some type of back door, but hiding it well. Parallel contruction etc etc
I can't think of any reason why its "best" for Apple to keep LEO happy. LEO don't pay them anything and actively increase the difficulty they face running their business as well as reduce the trust the people who do pay them (ie their customers) have for their products, actively hurting their business. The big fear is that pissing off LEO will result in harmful regulation, and, while that is certainly possible, histo…
Why Apple's iPhone encryption won't stop NSA
51–60 of 71 posts
Re: Why Apple's iPhone encryption won't stop NSA
#52Earlier quoted context omitted.
Yup. The reality is that you can't defeat the NSA unless you are able to design and fab your own silicon without any third party involvement, are able to write and audit your own crypto code with zero bugs, and are able to physically protect yourself from being "encouraged" to reveal your passphrases. It's not worth seriously trying to defeat an organisation as well funded/staffed/connected as NSA from obtaining your…
And if you're that important of a target, they're eventually just going to pick you up physically, black-bag style, from nearly anywhere on earth if they can. The NSA is the US military after all, there's really nowhere on earth that someone is entirely safe if they want you (maybe under direct protection by Beijing or Moscow).
This argument is bolstered by the fact that Snowden (hardly an ignorant party) sought precisely the protection you mention.
Re: Why Apple's iPhone encryption won't stop NSA
#53I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…
We could make passive observation (beamsplitters) useless by opportunistically encrypting all traffic with unauthenticated DH to derive a key. This would do nothing against an active observer, but it would raise the cost of interception significantly.
Re: Why Apple's iPhone encryption won't stop NSA
#54Earlier quoted context omitted.
We could make passive observation (beamsplitters) useless by opportunistically encrypting all traffic with unauthenticated DH to derive a key. This would do nothing against an active observer, but it would raise the cost of interception significantly.
There's a fine line between significantly and marginally in the case of a massively well funded organization like the NSA. Unauthed HD is so damn trivial to MiTM that accepting it as the status quo might just as likely force our government to invest a couple extra billions in MiTM equipment next year as it would be likely to protect the masses from the over reaching hand of mass surveillance. Who's to say they don't…
Oh, but we could know. And we should know.
This is a good example of good vs perfect and boolean cost. You are right that we currently don't know how prevalent these attacks are and if they are employed on big scale. But it is possible to know and would make a good research topic and/or a way for the community to raise the bar and know more about the state of Internet.
Yes do MITM on unauth DH is easy. But that does not say anything about the actual application traffic flowing through the connection. A successful, _undetected_ attack must also know and subvert the application traffic to keep the illusion alive.
We could do second level authentication, out-of-band authentication etc at application level to make it possible to detect the MITM. If we do this measurement on large scale and continuously we can find out who and where these attacks are in fact occuring.
IMHO one of the best network security research projects lately is the Spoiled Onions:
http://www.cs.kau.se/philwint/spoiled_onions/
This project aims at monitoring Tor for bad nodes and use out-of-band mechanisms to find things like MITM attacks. Very cool and relevant.
Re: Why Apple's iPhone encryption won't stop NSA
#55If you look at the incentives for Apple in this scenario: It's best for them if we all think their phones are secure. And it's also best for them if they dont piss off LEO. So the rational thing for them to do, is convince us all they have strongly encrypted their phones, while continuing to provide some type of back door, but hiding it well. Parallel contruction etc etc
That's a terrible idea. Because when the day comes that a security researcher finds the flaw (and they will find the flaw) Apple has to admit that they lied to their customers. And that's a very bad business practice. The enhanced encryption is Apple's way of saying that it's not their problem if LE has a beef with you. It removes Apple from the equation. If LE starts knocking at their they can say that there is noth…
in something as sophisticated as an iphone there are lots of places for vulnerabilities to be hidden from view.
Re: Why Apple's iPhone encryption won't stop NSA
#56I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…
Re: Why Apple's iPhone encryption won't stop NSA
#57I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…
> I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA) Great point and one that I think typical computer savvy users already do. It is in the security-expert-fantasy-world that the perfect quickly becomes the enemy of the good. For example, using SSL to send sensitive data li…
With 'special email software' do you mean not-webmail? Outlook is still around in many companies, where your colleagues are already connected. IIRC there's a PGP plugin.
Re: Why Apple's iPhone encryption won't stop NSA
#58Re: Why Apple's iPhone encryption won't stop NSA
#59I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…
But the NSA has unlimited funds, created by the tax payers they spy on. So why not make it easy, save us all a lot of money . It so crazy that we are talking about people that require the consent of their governed... On second though maybe outside of our bubble they have that consent and we have to bow to that majority.
Re: Why Apple's iPhone encryption won't stop NSA
#60Although I agree with the premise -- a sufficiently dedicated attacker can defeat many mechanisms you can come up with to protect your data -- many of the points that the author makes seem to be based on either incorrect or implausible assumptions. For instance, the claim that modern cell protocols can be "silently" MITMed is not really true; the current known attack to spoof a GSM tower, I believe, is limited to usi…
> I think the crux of the matter is that this crypto scheme is not designed to stop the NSA I think the NSA has so many tools available when it comes to hack into people's data, it doesn't really matter how you secure yourself, there are many ways for the NSA to spy on people if they really want to. Right now I don't think anyone can really pretend to secure their data from the NSA. It might make it harder for them,…