Earlier quoted context omitted.
I want to point out, that manufacturing a gun is not "non-trivial". Given blueprints, (publicly available) or a template and accurate enough measures, a lathe, and a mill, anyone can make a firearm or parts for one in their garage. Is there reading involved? Yes. But any argument you make w.r.t. The futility of illegalizing encryption is immediately portable to firearms manufacture.
I mean... manufacturing a working modern firearm in their garage is probably much more achievable to the general population than rolling out any kind of encryption software. Anyone with some basic hands-on competency can make a gun.
Attorney General William P. Barr Delivers Address Conference on Cyber Security
211–220 of 230 posts
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#212Earlier quoted context omitted.
> This includes both how to build a better mousetrap (one that doesn’t have a “backdoor” or significantly weakens the encryption mechanism), and how to solve concerns about abuse of exceptional access. There is a simple way to solve concerns about abuse of "exceptional access": Not to include any "exceptional access" mechanisms. Securely implementing a cryptosystem is a daunting task almost never achieved. Intentiona…
Let’s leave politics and assumptions about me out of it, please. Same point: figure out a technological and procedural solution to the human attack vector. If “security professionals” all agree on ideology or theory that it’s not possible and thus refuse to help solve the problem, then exceptional access solutions generally will be worse off for it. It’s independent of whether they actually are deployed.
There is no solution. If you build in your "exceptional access" exception, then the system is broken by design and no one will use it. That's the end of the discussion, there's nothing more to discuss. You can rube goldberg "solutions" all day long, but in the end you're just figuring out ways to deploy a broken system.
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#213Earlier quoted context omitted.
Well no, here's another inaccessible bit of information: face-to-face conversations where there are no recording devices present. Hence the importance of testimony in a criminal investigation. Should we now require all buildings to, by law, record audio conversations in case such conversations might one day be "needed" by law enforcement? Or perhaps there are other ways to perform targeted wiretaps?
You mean your Google home?
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#214Earlier quoted context omitted.
>In these discussions about the government being able to decrypt stuff, are we, in effect, suggesting that certain math be made illegal? All images are binary. All binary is just a number. We have made many such numbers illegal and even have software that will detect them and report you when you share the number with such number sharing services (dropbox, facebook, etc). So making math illegal sounds entirely possibl…
You are talking about data, so following that logic, what would be made illegal would be implementations not algorithms . Math can be represented in a variety of ways, but the pattern being described is immutable. What A.G. Barr is insinuating is not that we make implementations illegal, but that we make the use of algorithms categorically illegal.
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#215In general, I agree with the government stance that "warrant proof" communication is not in the best interests of US citizens. I believe that there is some precedent and established law that can be built upon to provide a compromise that allows for encryption to remain a strong privacy tool for society but one that does not hinder the state from lawful access. I believe that the US should establish a court similar to…
How often are the people making the arguments from the same political party? This problem extends to pretty much every court, as we currently have 3 branches being gamed by 2 political parties.
This will be one of the fracture lines that break the country.
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#216Earlier quoted context omitted.
I totally get what you are saying, but it is quite the rabbit hole if we determine that 'we can't have any illegal number... everyone should be able to share any number with anyone else' That basically means we have to entirely get rid of copyright, since all data (books, movies, software, corporate secrets, state secrets, etc) are just very large numbers. Do we believe that there should be no restriction on the shar…
We are talking about functions, not data. In that sense, copyright = data, and encryption = functions.
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#217Earlier quoted context omitted.
It's not incredible at all if you understand that all the power in the world is ultimately derived from people with guns.
In case it wasn’t already blatantly obvious, my point is that terrorism in the US is fundamentally associated with “brown” people, and elicits the most immediate and direct attention from governments, whereas mass shootings are almost always committed by white men, and even the worst mass shootings against children elicit no real action. But yes, guns have been regulated in the past — when? After the Black Panther pa…
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#218If the US Government succeeds in requiring a backdoor then so will every other government. Does anyone really think China won’t immediately demand backdoors?
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#219Earlier quoted context omitted.
Let’s leave politics and assumptions about me out of it, please. Same point: figure out a technological and procedural solution to the human attack vector. If “security professionals” all agree on ideology or theory that it’s not possible and thus refuse to help solve the problem, then exceptional access solutions generally will be worse off for it. It’s independent of whether they actually are deployed.
You've missed the point. There is no solution. If you build in your "exceptional access" exception, then the system is broken by design and no one will use it. That's the end of the discussion, there's nothing more to discuss. You can rube goldberg "solutions" all day long, but in the end you're just figuring out ways to deploy a broken system.
Again, simply arguing that “it can’t be done”, which is of course theoretically true if the goal is to have zero additional risk by introducing a third party, isn’t going to stop such systems from being deployed, it will simply reduce the quality of such solutions due to talent refusing to work on the problem.
An idea that comes to mind: third party can’t trivially decrypt the data (maybe it requires substantial computation to decrypt) thus reducing practicality of bulk decryption. Make the exceptional access truly exceptional.
I agree that having a trivial way for governments to access encrypted comms at scale is bad; I don’t agree that governments should be completely locked out, without exception, of all comms deployed at scale by mega tech corporations.
Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security
#220Earlier quoted context omitted.
You've missed the point. There is no solution. If you build in your "exceptional access" exception, then the system is broken by design and no one will use it. That's the end of the discussion, there's nothing more to discuss. You can rube goldberg "solutions" all day long, but in the end you're just figuring out ways to deploy a broken system.
The government has a different idea of what constitutes “broken” in this case. Of course adding a third party introduces additional risks. Two parties versus three parties: All can access the clear info; neither scenario is without risk. The goal is to find a solution that minimizes the risks of providing exceptional access. Again, simply arguing that “it can’t be done”, which is of course theoretically true if the g…
So then you recognize that "exceptional access" mechanisms necessarily weaken a cryptosystem, which are already notoriously difficult to implement securely. This brings us back to your OP, where you complain about people telling you the truth you already recognize, and make two entreaties for assistance from HN:
1. "Perhaps HN would do well to ask how to solve the problem from a technical perspective, given the requirements. This includes both how to build a better mousetrap (one that doesn’t have a “backdoor” or significantly weakens the encryption mechanism) [...]"
2. "[...] and how to solve concerns about abuse of exceptional access."
I understand now that you suffer from severe cognitive dissonance with respect to the first. You just acknowledged that the "weakening issue" with "exceptional access" cannot be solved, yet still argue that it can be solved, presumably with more effort from security professionals.
I already addressed the second: Concerns about abuse of "exceptional access" also cannot be solved, except by avoiding their inclusion in the first place.
Your idea is also a non-starter. Human political masters will set the work parameters, not users (otherwise: Who would choose anything but an infinite amount of work to decrypt their communications?). Users would have no way to verify the work required to decrypt as, again, they cannot verify that communications have or have not been "exceptionally accessed". The work parameters must be updated as technology improves, so there must be a way for human political masters to update work requirements (potentially reducing them). Nobody outside certain SCI or ECI compartments has any idea what kind of cryptanalytic power USG can bring to bear. Maybe, like Skipjack, the proof of work cryptography is subtly weaker than expected in a way that only they know. Maybe the USG will just start allocating $100B/year to routinely use "exceptional access". And certainly, after such a backdoor scheme is deployed, LEO and IC will howl that they cannot access enough plaintext to stop child molesting terrorist superpredators, and anyone who would just think of the children would support reducing or eliminating the burdensome computational obfuscation parameters. Once again: Any such "exceptional access" scheme necessarily reduces security by inserting a critical dependence on trust in humans that cannot be verified and whose compromise has Biblically enormous value to many groups.
> I agree that having a trivial way for governments to access encrypted comms at scale is bad; I don’t agree that governments should be completely locked out, without exception, of all comms deployed at scale by mega tech corporations.
If we agree on the first part, then we should agree on everything that I've written. "Exceptional access" schemes only make sense for unconstitutional dragnet surveillance purposes and are a severe threat to liberty. If a target is known, and is found to be using cryptanalytically impenetrable cryptography, targeted physical surveillance will defeat that cryptography every time. If some impenetrable communications happen between two non-targets, it doesn't matter that those communications cannot be read, because the government doesn't want to read those communications anyway--right? Of course, serious criminals and terrorists--the ones on whom collection is really important for security--are not going to use known-compromised cryptosystems when non-broken ones are already ubiquitous. Therefore this "exceptional access" is only useful on the average citizens; unless, that is, the government is doing dragnet surveillance and attempting to "winnow" out secure communications, something they can only do effectively if they attempt decryption of every "exceptional access-enabled" communication.
Finally, consider your request in the historical context. For the great deal of our history, communications have defaulted to being private (there were no microphones in Lincoln's log cabin) and inaccessible to government agents except through testimony (which cryptography does nothing to prevent). Now your claim is that the government must have the ability to access any communication. But why? Our government and society worked just fine without substantially all communications being recorded and accessible to the government. Such a large shift in the balance of power will, I fear, lead inevitably to tyranny.