Live data from Hacker News

More Encryption Is Not the Solution

queue.acm.org

21–30 of 88 posts

Re: More Encryption Is Not the Solution

#21
This viewpoint became very popular recently and it strikes me as odd. Does the author always leave his house unlocked because there is a law against theft? "Your" nation state over which you presumably have some degree of political control is absolutely not the only adversary. There are foreign states, there are cybercrime gangs etc.

Also, while politics sometimes trumps cryptography, the opposite happens just as often. All the police force is useless if they don't know where to point their guns (see Silk Road)

Re: More Encryption Is Not the Solution

#22
post #12
post #10

This author reaches pretty far. The NSA paid Microsoft to acquire Skype? You can't just materialize multiple billions of dollars on a public company's income statement.

You can indeed. The figures are very large and you cannot view item level detail in the financials, only general concepts. The NSA may be propping up the Azure division or one of countless others through backroom deals over this type of thing.

In addition to selling extra-high priced items to NSA/Military/Government, the Government could allow the company tax breaks it wouldn't get otherwise.

Tax rules for a company of the size of Microsoft are not simple. It's not impossible to hide stuff.

Re: More Encryption Is Not the Solution

#23
post #7

Because we are technical people, it's very tempting to think of a technical solution to the problem. This author is right on the money though. Against a state level actor there is little hope of securing your own person and effects, and thus, your technical solution.

I agree that a political solution is strongly preferable, but I'm not sure if that's ever going to happen. The only reason that the NSA can listen in on your Facebook, Google, Skype (etc) activity is because: 1. These communication tools are operated by a company under American jurisdiction, that can therefore be strong-armed into cooperation 2. These communication tools store your data unencrypted 3. The world outsi…

If our communication tools were decentralized, encrypted and open source, then the NSA would have had a much harder job listening in.

It makes eavesdropping without a warrant harder. However, in some countries the refusal to turn over a private key to the police is already a crime [1]. I don't find it hard to imagine that governments would seek to require that private keys are handed to the government or that they would reintroduce a Clipper-like chip. Especially if it becomes harder to wiretap via Facebook et al.

I agree that a political solution is strongly preferable, but I'm not sure if that's ever going to happen.

I am not sure. I think that under sufficient political pressure, it could happen in Europe. Perhaps with the wrong motivation (weakening the position of US companies), but some influential politicians (e.g. Neelie Kroes) have been very critical of Prism. Of course, we don't know that much of the breadth of data collection of EU security agencies...

[1] http://www.schneier.com/blog/archives/2007/10/uk_police_can_...

[2] http://www.zdnet.com/prism-fallout-could-cost-us-cloud-indus...

Re: More Encryption Is Not the Solution

#24
post #18

Encryption can be circumvented. It's hard, but doable for a state, when it targets one high-value suspect. But if everything is encrypted, they can't go "big data" on it and collect everything about everyone: if proper encryption is generalized, spying doesn't scale anymore. Big companies' ability to break the encryption between them an you is irrelevant: if they're the legitimate receiver of the communication, they…

Half the article is talking about scalable attacks on encryption. For example: "To an intelligence agency, a well-thought-out weakness can easily be worth a cover identity and five years of salary to a top-notch programmer. Anybody who puts in five good years on an open source project can get away with inserting a patch that 'on further inspection might not be optimal.'"

I agree we should continue this arms race but I'm a little less confident than I was before reading this article.

It's true they can't reveal exploits in court, but that matters less and less. If they decide they don't like you there are all sorts of other ways they can screw with you.

Re: More Encryption Is Not the Solution

#25

"if a nation-state decides that somebody should not have privacy, then it will use whatever means available to prevent that privacy." One thing a lot of these discussions miss is that the entire point of doing privacy and anonymity correctly is that you are never on a list of people that any particular nation state wants to deny privacy to. That your True Name (to borrow the idea from Vinge’s story of the same name)…

I really admire your sober and well thought out proposal.

Implementing what you suggest is just such a lot of work. Certainly too much for me, when I weight up the odds I'll fall foul of Big Brother ( as an Oz living in London. Burma, Saudi, etc have clear problems )

I believe that if one comes on the radar of Big Brother, it is for boring mundane reasons like they don't like your politics, they don't like someone you communicate with or you're a lawyer representing someone they don't like.

There are clearly edge cases with serious consequences, such as a police chief fancies your wife and uses privilege to mess with you. But these are rare thank G-d, and one probably has a heads up that this is occurring.

In this context of very low probability consequences, how can I justify all the effort ??

Re: More Encryption Is Not the Solution

#26
Encryption is not absolutely safe because it relies on trusting in who's at the other end, but it surely is much better than using clear net. We can still trust a few entities, right? We need to collectively scrutinize and make informed guesses about who to trust.

At the moment I set up TOR and use Starpage.COM instead of Google. Auto-delete cookies after closing the tabs and actively remove ads and tracking JS from web pages with the help of a few browser extensions. It's not perfect, but it's above average for the moment.

You know how we could become anonymous? Just pipe the traffic of 1000 people through the same box, mix their searches and pages loaded in the same stream. Then send them on the clear net - they can't trace back who requested what. Hiding in the crowd, in plain sight.

Re: More Encryption Is Not the Solution

#27

"if a nation-state decides that somebody should not have privacy, then it will use whatever means available to prevent that privacy." One thing a lot of these discussions miss is that the entire point of doing privacy and anonymity correctly is that you are never on a list of people that any particular nation state wants to deny privacy to. That your True Name (to borrow the idea from Vinge’s story of the same name)…

It's like hygiene. A few hundred years back people weren't washing their hands and health was very bad. As soon as we understood the germ theory of disease, we learned hygiene and now we are much better.

With encryption and privacy it will be the same. People will need to learn new skills.

Unfortunately, what we need to do is as cumbersome as a surgeon prepping for operation - it takes too much care to make sure you don't mix things up. You never login into your Gmail on Tor, don't refer to your reddit user name on Gmail, etc.

Unless you already did, in which case you're toast. They already have years of data on your views and interests.

Could we make a browser extension that would compare all you do and force privacy for you? For example, if you mistakenly mention your anonymous identity in your official mail, to catch it before sending. It should have a list of forbidden things - keywords, user names, etc - and send watch people not to mix the pots. Take care to separate cookies between anonymous mode and public mode. I am sure such an extension would go 99% of the way to making your private online life private again.

I envision a whole suite of apps - browser, mail, messaging, file sharing - written with this goal in mind - to separately manage identities - private and public - based on the content of communication. Like spam filters, but applied to all our data leaks.

Re: More Encryption Is Not the Solution

#28
post #24
post #18

Encryption can be circumvented. It's hard, but doable for a state, when it targets one high-value suspect. But if everything is encrypted, they can't go "big data" on it and collect everything about everyone: if proper encryption is generalized, spying doesn't scale anymore. Big companies' ability to break the encryption between them an you is irrelevant: if they're the legitimate receiver of the communication, they…

Half the article is talking about scalable attacks on encryption. For example: "To an intelligence agency, a well-thought-out weakness can easily be worth a cover identity and five years of salary to a top-notch programmer. Anybody who puts in five good years on an open source project can get away with inserting a patch that 'on further inspection might not be optimal.'" I agree we should continue this arms race but…

"To an intelligence agency, a well-thought-out weakness can easily be worth a cover identity and five years of salary to a top-notch programmer. Anybody who puts in five good years on an open source project can get away with inserting a patch that 'on further inspection might not be optimal.'"

Suddenly, Dijkstra's insistence on developing the proof together with the program and providing it to any interested person doesn't seem to be the ridiculous idea that some people consider it to be, does it?

Re: More Encryption Is Not the Solution

#29
More Encryption is not the final solution to the problem. I fully agree here. However, encryption should be the default for all communication. It provides a certain degree of privacy after all. Yes, there are weaknesses in some of the tools used. That can always happen. As the technical crowd, we should fix those weaknesses instead of screaming "encryption is useless".

I for one don't feel like making it easy for the NSA, a foreign agency in my case, to spy on me. I owe it to my privacy to at least try and protect it.

The political change that is necessary is out of my reach in the case of PRISM, as I am not from the US. I can only hope that the American public will realize how bad this really is and act accordingly. After all, this is still a democracy and it will be until all privacy has been taken away completely.

Re: More Encryption Is Not the Solution

#30
post #25

"if a nation-state decides that somebody should not have privacy, then it will use whatever means available to prevent that privacy." One thing a lot of these discussions miss is that the entire point of doing privacy and anonymity correctly is that you are never on a list of people that any particular nation state wants to deny privacy to. That your True Name (to borrow the idea from Vinge’s story of the same name)…

I really admire your sober and well thought out proposal. Implementing what you suggest is just such a lot of work. Certainly too much for me, when I weight up the odds I'll fall foul of Big Brother ( as an Oz living in London. Burma, Saudi, etc have clear problems ) I believe that if one comes on the radar of Big Brother, it is for boring mundane reasons like they don't like your politics, they don't like someone yo…

At least using PGP or GPG for your emails isn't much effort. These tools are very easy to integrate into all of the common mail clients and some web services. The only "hard" part is to get your communication partners to use them as well.
Post reply on HN