Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

11–20 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#12
post #6
post #2

Why can't PFS be a solution for this?

PFS and other Deniable encryption ( http://en.wikipedia.org/wiki/Deniable_encryption ) are great for deniability. However, they and everything else can be susceptible to unrelenting rubber-hose "cryptanalysis". ( http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis ) It is said that the goal of cryptography is to make the attacker resort to rubber-hose cryptanalysis, revealing their intentions. In those cases, the…

Just to be clear, PFS does not necessarily equal repudiability.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#14
post #9
post #5

Broad solution to all this is building your lives in business in a way government can have a minimal control of. Just do what it requires and keep everything else encrypted and anonymized. And don't rely on government for anything, for we are heading for a world of global government failure: people and institutions are going to ignore and circumvent them all, and make them dysfunctional. In a way, that will be like c…

Don't rely on government for anything? What are you talking about? Almost 100% of scientific research and 100% of infrastructure around the world is funded by government. Almost all of education, health and welfare around the world (though less so in the US) is run by government. A lot of people are suspicious of government, but such fundamental disdain toward and alienation from government are peculiar American (and…

'such fundamental disdain toward and alienation from government are peculiar American'

This. If you're so unshakably convinced that a government full of people you vote for every four years is never going to work in your interests, you have serious problems.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#15

The only thing I get really spooked over, is that eventually it gets to a point where the government starts demanding passphrases for hard drives with no hidden encrypted partition. Am I being paranoid? Someone sensible please dilute my paranoia.

Realistically paranoid, I think.

Best plan may be to create a small encrypted partition, and put some data on it, so you can give them the passphrase when asked.

Don't forget the passphrase!

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#16
post #2

Why can't PFS be a solution for this?

PFS protects you if feds get google keys now to not be able to decipher what you told google 3 months ago. But if they have the current keys nothing can protect you.

Wouldn't that mean Google would have to build a system to automatically send each key, for every session, for every user, to the NSA?

That would be an insane scenario.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#17
I treat email in Gmail as publicly accessible, same for almost everything I do on the web casually.

My business data lives in Amsterdam (Azure EU West), critical services we use are based in Europe. At least in my case I couldn't care less if the big US companies handed out SSL keys.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#18
post #9
post #5

Broad solution to all this is building your lives in business in a way government can have a minimal control of. Just do what it requires and keep everything else encrypted and anonymized. And don't rely on government for anything, for we are heading for a world of global government failure: people and institutions are going to ignore and circumvent them all, and make them dysfunctional. In a way, that will be like c…

Don't rely on government for anything? What are you talking about? Almost 100% of scientific research and 100% of infrastructure around the world is funded by government. Almost all of education, health and welfare around the world (though less so in the US) is run by government. A lot of people are suspicious of government, but such fundamental disdain toward and alienation from government are peculiar American (and…

Libertarian socialism is more popular in Europe than in America, and they, too, strongly disdain governments.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#19
post #9
post #5

Broad solution to all this is building your lives in business in a way government can have a minimal control of. Just do what it requires and keep everything else encrypted and anonymized. And don't rely on government for anything, for we are heading for a world of global government failure: people and institutions are going to ignore and circumvent them all, and make them dysfunctional. In a way, that will be like c…

Don't rely on government for anything? What are you talking about? Almost 100% of scientific research and 100% of infrastructure around the world is funded by government. Almost all of education, health and welfare around the world (though less so in the US) is run by government. A lot of people are suspicious of government, but such fundamental disdain toward and alienation from government are peculiar American (and…

All of these are taxpayer funded.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#20
Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun.

Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical security, it will improve security and trust for end users. Rather than "trust us", it will be "trust us, because...".

Post reply on HN