Earlier quoted context omitted.
Why does going to your parties make someone not incompetent? In any case his competence is moot, the man is a demagogue and as such should be avoided and ignored.
Read his book: http://www.skatingonstilts.com/
Former NSA lawyer: the cyberwar is between tech firms and the US government
41–50 of 79 posts
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#42I've known Stewart Baker, the ex-NSA GC quoted in the linked article, for about 15 years--not incredibly well, but well enough that he'd show up at parties I held in my home when I was living in D.C. before moving to the SF bay area. Stewart is extremely smart, should not be underestimated, and HN comments in this thread calling him "incompetent" reflect badly on the person making the comment. He's likely the single…
Why does going to your parties make someone not incompetent? In any case his competence is moot, the man is a demagogue and as such should be avoided and ignored.
I read this as Declan saying that he and Baker were sufficiently acquainted for him to form a judgement of Baker's competence, with "he'd show up at parties I held" being to clarify the degree of their acquaintance. He's not claiming that they two things are causally connected.
And ignoring demagogues is not necessarily a good idea.
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#43I've known Stewart Baker, the ex-NSA GC quoted in the linked article, for about 15 years--not incredibly well, but well enough that he'd show up at parties I held in my home when I was living in D.C. before moving to the SF bay area. Stewart is extremely smart, should not be underestimated, and HN comments in this thread calling him "incompetent" reflect badly on the person making the comment. He's likely the single…
That someone is smart does not mean that whatever he says is true.
In fact some of the smartest people on earth use their intelligence to fool and mislead other people.
It is not very smart on this man when he talks about blackberry: "look were blackberry is today". Blackberry in fact did help governments with their encryptions keys.
In particular,people that worked for the NSA need to develop a habit of lying to everyone as a morning routine.
We know that while the CIA and the NSA were crying loud about how encryption was making them "blind", they were in fact spying on more Americans and non Americans than ever.
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#44Earlier quoted context omitted.
Why would these use cases need end to end encryption?
I'm sorry if I wasn't clear. I wasn't meaning to limit my argument to data in transit - I was also including data at rest. To answer your question though, end-to-end encryption of data in transit will obviously interfere with an employer's ability to log transactions. I think Mr. Baker's arguments were more directed at the recent ubiquitous iPhone encryption controversy (in fact, after doing a quick search, he made a…
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#45"The crypto wars have about as much to do with the outcome of security as the Soviet-Finnish war of 1939 had to do with the outcome of WW2."
I've seen it argued that the Soviet-Finnish (AKA the "Winter War") actually had quite a large impact on the outcome of WW2:
- The difficulties the Soviets had in fighting the Finns made them re-organize their command structure of the Red Army, re-instating traditional rank structures and reducing the role of political officers
- It led Hitler to believe that the Soviets would be easy to defeat, underestimating both the size and quality of Soviet forces
So you could argue that if the Soviet-Finnish hadn't happened then Hitler might not have been quite so keen to invade the Soviet Union when he did and might have encountered a more poorly organized Red Army when he did.
NB The Finns put up an incredible defence of their country against apparently overwhelming attacks, including Simo Häyhä who as a sniper had 505 combat kills.
Perhaps we should be concluding that a small, skilled and highly motivated defence can blunt the attack of even the most powerful of enemies?
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#46I've known Stewart Baker, the ex-NSA GC quoted in the linked article, for about 15 years--not incredibly well, but well enough that he'd show up at parties I held in my home when I was living in D.C. before moving to the SF bay area. Stewart is extremely smart, should not be underestimated, and HN comments in this thread calling him "incompetent" reflect badly on the person making the comment. He's likely the single…
> Stewart is extremely smart, should not be underestimated, and HN comments in this thread calling him "incompetent" reflect badly on the person making the comment. Incompetent may be the wrong word. What people (including you) are getting at is that his arguments are unpersuasive upon examination. It's all just fear mongering. There are two plausible explanations for this. The first is that he doesn't see the holes…
In other words, you aren't supposed to present both sides of the argument, you're supposed to present your side alone. It's up to your adversary to find the faults in your arguments - if there are any.
Stewart Baker, being a former lawyer, might simply be arguing in this tradition.
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#47Earlier quoted context omitted.
What Baker is trying to express is that companies like Apple could be shooting themselves in the foot with corporate sales if the data sitting on devices they're manufacturing can't be handed over when counsel tells you that there's a valid warrant. If Apple says the data on the phones is completely secure and not even the cops can get to it, then that means IT can't get to it when directed to, either. Management mig…
Apple and Google are merely absolving themselves of being involved in the legal matters of others. The third-party doctrine basically forces third-parties to be legally culpable for discovery. Google and Apple don't want to be legally responsible anymore, so they've pushed the responsibility for complying with counsel to the end-user. i.e. instead of law enforcement going to Google and Apple and saying "I have a lega…
Which is entirely the wrong way to conduct a criminal investigation. How effective can the police really be when they have to go to suspect and say "We've got enough evidence to suspect you of a crime and get a warrant, but not enough to convict. Can you please hand over all evidence that would further incriminate you?"
> It's not like Google and Apple are taking away the government's ability to issue warrants.
No, but they're making the warrants useless.
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#48Earlier quoted context omitted.
What Baker is trying to express is that companies like Apple could be shooting themselves in the foot with corporate sales if the data sitting on devices they're manufacturing can't be handed over when counsel tells you that there's a valid warrant. If Apple says the data on the phones is completely secure and not even the cops can get to it, then that means IT can't get to it when directed to, either. Management mig…
If as a company, you aren't managing your devices, (trivial to do at low cost via MDM) there is no difference between encrypted/unencrypted -- you're reliant on the custodian of the phone to do the right thing when turning over the device. Baker wants the US to have the same access to data that Saudi Arabian or Indian law requires, except in those countries there is actual law requiring this. NSA/et al prefers "gentl…
Precisely - and companies aren't going to want to purchase phones that they can't manage. Of course, this might be a moot point; I've never seen a company-issued iPhone before, so maybe Apple doesn't even want to be in that market (I might just be hanging around the wrong people, though).
> NSA/et al prefers [...]
While encrypting data while it's transiting the internet might have an effect on the NSA, encrypting data stored locally (like with the iPhone encryption debacle) won't affect them at all. When was the last time the NSA had your phone in its possession? It will affect criminal investigations. I think Apple would have stirred up a lot less controversy if they had marketed their encryption as protecting the data on your lost phone from criminals instead of marketing it as protecting it from the cops.
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#49Earlier quoted context omitted.
I'm sorry if I wasn't clear. I wasn't meaning to limit my argument to data in transit - I was also including data at rest. To answer your question though, end-to-end encryption of data in transit will obviously interfere with an employer's ability to log transactions. I think Mr. Baker's arguments were more directed at the recent ubiquitous iPhone encryption controversy (in fact, after doing a quick search, he made a…
Unless that data is at rest somewhere outside an organization's control, that still does not require end to end Enron with key escrow/recovery.
> end to end Enron
I think you meant "end to end encryption". I'm guessing you're typing that on iPhone :)
Re: Former NSA lawyer: the cyberwar is between tech firms and the US government
#501) If these measures are effective and stop them doing what they perceive to be their job, they'd have to protest.
2) If they had access to the information by other means, they'd have to protest anyway, otherwise you'd be able to conclude we're in situation 1
My guess it's a bit of both, and they're mostly just losing their ability to mass surveil against low priority targets (e.g. populations), since cracking the encryption for absolutely all connections would be too much work.