Live data from Hacker News

A Few Thoughts on Ray Ozzie’s “Clear” Proposal

blog.cryptographyengineering.com

21–30 of 77 posts

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#21

CAs seem to be able to keep their private keys safe. Why should phone companies be less competent? They certainly have far more money to devote to it. In any case, Ozzie’s proposal shows that the technological argument has always been more of an attempt to circumvent the political discussion. The tech community loves the idea of subverting the law with technology when it doesn’t suit them. The Federal,Reserve is just…

You haven't addressed the currently imaginary properties required of the secure processor.

CAs also have a revocation story. Fun stuff re-provisioning the keys inside millions of phones.

And then after all that the really bad actors will have illegal phones from China that no one seems to have the private keys for.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#22

CAs seem to be able to keep their private keys safe. Why should phone companies be less competent? They certainly have far more money to devote to it. In any case, Ozzie’s proposal shows that the technological argument has always been more of an attempt to circumvent the political discussion. The tech community loves the idea of subverting the law with technology when it doesn’t suit them. The Federal,Reserve is just…

This is a really nutty comment.

Symantec’s CA is publicly collapsing in slow motion right now, because they neglected their security.

https://security.googleblog.com/2018/03/distrust-of-symantec...

Honestly... your comment feels a bit like observing that terrorism is not a problem a month after 9/11.

CAs screw up, and when they do, it is extraordinarily inconvenient.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#23

CAs seem to be able to keep their private keys safe. Why should phone companies be less competent? They certainly have far more money to devote to it. In any case, Ozzie’s proposal shows that the technological argument has always been more of an attempt to circumvent the political discussion. The tech community loves the idea of subverting the law with technology when it doesn’t suit them. The Federal,Reserve is just…

CAs seem to be able to keep their private keys safe.

You mean, except for the 23 000 that were leaked just this year?

https://arstechnica.com/information-technology/2018/03/23000...

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#24
I don't see anything new in the alleged proposal, this is the same old crypto war. This is "just" key escrow.

One might as well propose to have the manufacturers build in the governments public key (and autobrick phone usage) such that the phone can detect if it is really the government reading the phone.

Another note:

"Ozzie’s proposal relies fundamentally on the ability of manufacturers to secure massive amounts of extremely valuable key material against the strongest and most resourceful attackers on the planet. "

This is not true: the phone encrypts the users passcode against the manufacturers public key. If the government tries to read the phone, it will get the encrypted passcode (useless) and send it to the manufacturer who decrypts the passcode. A single private key is not massive amounts of information. Not that it changes anything about protection needs: wheither its a piece of paper containing the say 4096 bits (512 bytes), or in Matthew Greens misinterpretation billions of 512 bytes (half a terrabyte) on a single HDD, they both have the same value. The whole code base needs similar protection anyway: their bootloaders already are signed by the manufacturer.

All this centralization is bad, leave the crypto genie out of the bottle please...

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#25
We need a new way of thinking about caches of secrets. It comes from this unpleasant truth: all secrets eventually leak. The evidence of the past few years teaches us that even state actors with unlimited resources cannot prevent their secrets from leaking.

A "leak" here happens when a trusted entity loses control of the secret to one or more untrusted and malicious entities. That's just a definition, not a claim that any particular government, company, or person is a trusted entity.

To counter this, we need multiple layers of defense.

One is the business of bricking the phones when the leaked secrets are exploited. That makes it plain that the secret has leaked. It's a valuable layer of defense.

Another is to make the secrets have limited useful lifetimes. Expiration and revocation for TLS certificates is a way to do that. Credit/debit card numbers can be deactivated and replaced rapidly. That's another way to limit the lifetime of a secret. Ozzie's proposal does not include a way to limit secrets' lifetimes. (Social Security numbers are problematic secrets: they too have unlimited lifetimes.)

A third layer is making the secrets have limited utility. If debit cards had daily spending limits, their secret numbers would be less useful than they are today, for example. Day-one exploits are secrets with vast utility, for another example. Ozzie proposes a secret to unlock an entire phone. How about limiting that to, say, the phone's call log or SMS log?

A fourth layer is to keep the caches of secrets as small as possible, so a breach affects as few people as possible. Ozzie proposes the opposite of this.

A fifth layer: holders of caches of secrets must know they are strictly liable for breaches proportional to the damage they do. It must not matter whether the breach was due to negligence, carelessness, espionage, or salt water rusting out the safe after a storm. Large scale key escrow cache systems will never be able to meet this standard: nation states won't honor that liability, nor will they pay private companies enough to cover the insurance for it.

(Strict liability is not unprecedented: workers' compensation and the vaccine injury victims' compensation fund are two reasonably successful examples.)

People, companies, and governments holding secrets necessarily must consider what happens when (not if) they leak, and provide at least some defenses in depth like these.

Ozzie's proposal has weak and incomplete in-depth defenses. That's why it's dangerous.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#26
post #17

I’m not sure the benefit to Apple or other phone manufacturers. This looks like a substantial cost with zero benefit to those others than law enforcement. And substantial new risk for misuse or abuse. What’s Ozzie’s true motivation? Is he looking to start a company running Clear and raking in patent revenue? I get why the governments want this, but not why a citizen would propose this. If it weren’t Ray Ozzie, I woul…

Money. His true motivation is money. Secondary to that is prestige; he "solved" this problem.

Do you personally know him or is this just speculation ?

Because most entrepreneurs aren't running businesses primarily for the money.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#27
He talks about “massive amounts of extremely valuable key material“ needed to be stored for billions of devices.

It’s not like this would be Fort Knox. All that data could be stored on a couple of USB sticks which, really, makes it even scarier. Someone could hold the entire contents in the palm of their hand walk away with everything.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#28
What if someday we get political leadership so awful that, hypothetically, a former CIA chief feels compelled to warn that is is fundamentally dangerous to the nation?

One answer might be that we deserve such an outcome, and there is no reason to insulate encryption from the negative consequences. But is that a good answer?

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#29
Personally I believe real world actions should be the focus of surveillance. The empires are simply trying to cheap out by focusing on surveillance of computer activity.

This is the most profound part of Matthew Green's piece in my opinion:

"While this mainly concludes my notes about on Ozzie’s proposal, I want to conclude this post with a side note, a response to something I routinely hear from folks in the law enforcement community. This is the criticism that cryptographers are a bunch of naysayers who aren’t trying to solve “one of the most fundamental problems of our time”, and are instead just rejecting the problem with lazy claims that it “can’t work”. "

I believe the most fundamental problem is how can we decentralize real world security? I am FOR mass surveillance but AGAINST centralized mass surveillance.

Assume every crook and cranny of the world was covered by community cameras, and the cameras encrypted the streams with treshold cryptography, such that the populace has different parts of the secret, then one needs "enough" citizens agreeing to reveal the contents seen by a specific camera at a specific time. This way its public for all or public for none. Every accident, every murder, ...

Suppose a body is found, then the group decides to reveal the imagery: oh yes, in this case the person was murdered! look the perpetrator is walking out of view to the next camera, then the next,... we can trace him to where he is now. Properly trained citizens (in a now authorized police role) go and arrest the guy. He is now in prison waiting for his trial (also with community cameras, so no broomsticks in prisoner ani). At trial time, if the person denies, or claims to be a different person from the arrested one, we can trace through all the imagery from his commiting a crime to his sitting in court right there and then.

So yes, there is a real conflict between cryptographers and centralized law enforcement. We dont need no spooks!

And the spooks can not decode the camera imagery: a large enough number of citizens (chosen at random by cryptographic sortition) running instance of good citizen client software need to release their part of the shared secret.

EDIT:

So there is broadly speaking 2 kinds of crimes:

* meatspace crimes (murder, negligence, rape, making childporn (automatically rape), ...)

* cyber crimes (copyright, child porn, ...)

I argue that not implementing such a community camera system is a form of negligence in itself.

It does not adress things like copyright infringement, but ... thats not exactly the most popularly supported concept.

Then there is the problem of child porn: fake and real.

I argue that with deepfake any faked child porn will eventually become indiscernible from real child porn.

Which leaves the problem of official child porn recorded by the community cameras used to apprehend perpetrators (since these also sign the imagery to testify authenticity!).

Due too taboo many victims of child abuse didn't realize, or only had doubts that they were suffering abuse, enabling the abuse to continue. Without concrete visual examples for them to explore, to asses if they are or are not suffering child abuse, how can they alert others of their situation? We send these children extremely mixed messages: absolutely tell us if you are being abused, but absolutely never falsely report a person. Merely asking someone else for advice is automatically interpreted as a child reporting child abuse. How can a child asses his or her situation? With abstract questions using words and connotations it does not know?

I believe the number of reported child abuses would go up if we used these community cameras for decentralized mass surveillance.

Also for crime in general (theft, murder, ...), the knowledge that you will with extremely high probability be caught, will decrease a lot of crime. I would not be surprised if the crime rate of "impulsive" crimes (where the criminal was supposedly not able to control his urges) would drop substantially, revealing that in the current system they often get off the hook.

There will still be rude people, getting fines for squeezing women in the ass while drunk. But for any actual crime in general, both victim and perpetrator would know that the victim can simply report this to the group, and that the perpetrator can not escape by lack of evidence. The current lack of evidence constantly discourages people from reporting crimes (as there is risk involved: financial: lawyers, emotional: potential incredulity at police station, ...).

One might think that this will cause criminals to escalate to murder: "if you rob a victim, you should kill her, or else she will report you" but hiding a body will be very hard, and if a person goes missing the friends and relatives will report this, and instead of following the criminal we can follow the missing person from the time and place she was last reported seen!

As long as cryptographers only draw the privacy card, the law enforcement community has a point. As long as the law enforcement community only draws the centralized power card, the cryptographers have a point.

Only when we have decentralized mass surveillance can we have both privacy (as long as you don't commit crimes or go missing) and real law enforcement.

Common FAQ:

What if say a stalker repeatedly reports his ex as "missing"? Cry wolf to many times, or be blocked to report a person missing, and the good citizen client software that the citizens individually run, will refuse to comply.

What if a stalker or group of them repeatedly reports a "murderer" in a celebrities bedroom? we can send a local but randomly selected properly trained (group of) citizen (in police role) to go check the room, if the supposed dead body is not there, no reason to unlock the imagery.

(I will add more as people ask)

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#30
I agree about the security of a centralized vault being a key weakness, but the article omits a few key aspects of Ozzie's proposal:[0]

* A court order is required. It's not up to the tech vendor.

* Physical control of the device is required. No remote exploits.

* Access is enabled only to one device at a time. No mass hacking.

The point of security is to increase the cost to the 'attacker' (here we'll use that word even for legitimate government purposes); there's no perfect security; law enforcement can access data on iPhones already. Also, attackers focus on the weakest (i.e., least expensive) link and there's limited value in increasing the cost beyond the 2nd weakest link.[1] Except for the centralization of key storage and two other issues (see below), Ozzie's proposal might increase the cost to the level of law enforcement's alternative, acquiring a hacking tool. In fact, I've been thinking of something similar (court order, physical access required, notification to user) and might even have posted it to HN at some point.

Using hacking tools is much worse than Ozzie's process: There's no court (or at least it's not as enforceable, because there's no tech company checking for a warrant), no tech company, the user doesn't necessarily know their data has been accessed, remote exploits are possible, and so is mass hacking.

Also remember that private citizens can still encrypt their data at the file level using other tools, though of course most will not.

Here are weaknesses I see:

A) The use of other means of accessing devices would have to be outlawed, or law enforcement will continue to use hacking tools and citizens gain nothing.

B) Solve the centralization problem. Probably, the keys shouldn't be in the hands of the tech giants and should be distributed widely. EDIT: Perhaps require two unrelated parties for access?

C) If these new access tools are built into mobile devices, what happens in countries where people's rights have been taken away? The courts are often ineffective. I suppose the fact that the phones get bricked at least informs the user, and the authorities can use hacking tools anyway, so perhaps nothing is lost.

____________

[0] https://www.wired.com/story/crypto-war-clear-encryption/

[1] If I increase the cost of exploit A to $100,000 and exploit B costs $50,000, attackers will use B. If I increase the cost of A even further, to $200,000, it won't provide much more security - the attackers still will use B.

Post reply on HN