Live data from Hacker News

Attorney General William P. Barr Delivers Address Conference on Cyber Security

justice.gov

221–230 of 230 posts

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#221
post #212

Earlier quoted context omitted.

You've missed the point. There is no solution. If you build in your "exceptional access" exception, then the system is broken by design and no one will use it. That's the end of the discussion, there's nothing more to discuss. You can rube goldberg "solutions" all day long, but in the end you're just figuring out ways to deploy a broken system.

The government has a different idea of what constitutes “broken” in this case. Of course adding a third party introduces additional risks. Two parties versus three parties: All can access the clear info; neither scenario is without risk. The goal is to find a solution that minimizes the risks of providing exceptional access. Again, simply arguing that “it can’t be done”, which is of course theoretically true if the g…

You're describing a broken and unusable cryptosystem. What you believe requires "substantial computation" to break today requires a consumer GPU tomorrow.

There is no minimizing the risk. Your concept is broken. It does not -- and cannot -- provide security of any use. And I don't care what the government thinks about it.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#222

Earlier quoted context omitted.

In case it wasn’t already blatantly obvious, my point is that terrorism in the US is fundamentally associated with “brown” people, and elicits the most immediate and direct attention from governments, whereas mass shootings are almost always committed by white men, and even the worst mass shootings against children elicit no real action. But yes, guns have been regulated in the past — when? After the Black Panther pa…

Different motives: mentally ill vs spiritual belief. and there are plenty of initiatives to ban guns after terrorist actions done by whites. not sure what your point is.

I just stated my point with perfect clarity. And no, gun control has been legislated almost entirely in response to perceived violence from communities of color.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#223
post #221

Earlier quoted context omitted.

The government has a different idea of what constitutes “broken” in this case. Of course adding a third party introduces additional risks. Two parties versus three parties: All can access the clear info; neither scenario is without risk. The goal is to find a solution that minimizes the risks of providing exceptional access. Again, simply arguing that “it can’t be done”, which is of course theoretically true if the g…

You're describing a broken and unusable cryptosystem. What you believe requires "substantial computation" to break today requires a consumer GPU tomorrow. There is no minimizing the risk. Your concept is broken. It does not -- and cannot -- provide security of any use. And I don't care what the government thinks about it.

Pre quantum algos have this shortcoming built in

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#224

Earlier quoted context omitted.

The government has a different idea of what constitutes “broken” in this case. Of course adding a third party introduces additional risks. Two parties versus three parties: All can access the clear info; neither scenario is without risk. The goal is to find a solution that minimizes the risks of providing exceptional access. Again, simply arguing that “it can’t be done”, which is of course theoretically true if the g…

> [...] arguing that “it can’t be done”, which is of course theoretically true if the goal is to have zero additional risk by introducing a third party [...] So then you recognize that "exceptional access" mechanisms necessarily weaken a cryptosystem, which are already notoriously difficult to implement securely. This brings us back to your OP, where you complain about people telling you the truth you already recogni…

It’s a trade off. There’s no cognitive dissonance, just refusal to work towards better compromises. Lovely argument, though. Euphemistically it’s clear you’re very passionate about this issue. Maybe my hacker news throwaway should’ve been called cryptopassion

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#225
post #221

Earlier quoted context omitted.

You're describing a broken and unusable cryptosystem. What you believe requires "substantial computation" to break today requires a consumer GPU tomorrow. There is no minimizing the risk. Your concept is broken. It does not -- and cannot -- provide security of any use. And I don't care what the government thinks about it.

Pre quantum algos have this shortcoming built in

Word salad.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#226

Earlier quoted context omitted.

> [...] arguing that “it can’t be done”, which is of course theoretically true if the goal is to have zero additional risk by introducing a third party [...] So then you recognize that "exceptional access" mechanisms necessarily weaken a cryptosystem, which are already notoriously difficult to implement securely. This brings us back to your OP, where you complain about people telling you the truth you already recogni…

It’s a trade off. There’s no cognitive dissonance, just refusal to work towards better compromises. Lovely argument, though. Euphemistically it’s clear you’re very passionate about this issue. Maybe my hacker news throwaway should’ve been called cryptopassion

There is no compromise. There is either security, or there is not. You want the not, because you prioritize government access to all communications over privacy.

The rest of the world disagrees with you.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#227
post #221

Earlier quoted context omitted.

The government has a different idea of what constitutes “broken” in this case. Of course adding a third party introduces additional risks. Two parties versus three parties: All can access the clear info; neither scenario is without risk. The goal is to find a solution that minimizes the risks of providing exceptional access. Again, simply arguing that “it can’t be done”, which is of course theoretically true if the g…

You're describing a broken and unusable cryptosystem. What you believe requires "substantial computation" to break today requires a consumer GPU tomorrow. There is no minimizing the risk. Your concept is broken. It does not -- and cannot -- provide security of any use. And I don't care what the government thinks about it.

[deleted]

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#228
post #221

Earlier quoted context omitted.

The government has a different idea of what constitutes “broken” in this case. Of course adding a third party introduces additional risks. Two parties versus three parties: All can access the clear info; neither scenario is without risk. The goal is to find a solution that minimizes the risks of providing exceptional access. Again, simply arguing that “it can’t be done”, which is of course theoretically true if the g…

You're describing a broken and unusable cryptosystem. What you believe requires "substantial computation" to break today requires a consumer GPU tomorrow. There is no minimizing the risk. Your concept is broken. It does not -- and cannot -- provide security of any use. And I don't care what the government thinks about it.

It’s just a brainstorming idea. There would be a key as well - the idea would require both the key and substantial computational power for exceptional access

Brainstorming ideas are meant to be thrown out. Attacking the idea respectfully is fine. It’s to help inspire other ideas.

Of course there’s a trade off involved. But whether it’s two party encryption or three party encryption with exceptional access none is perfectly secure anyway. There is major conflation of political ideologies with hardline technical viewpoints going on

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#229
post #226

Earlier quoted context omitted.

It’s a trade off. There’s no cognitive dissonance, just refusal to work towards better compromises. Lovely argument, though. Euphemistically it’s clear you’re very passionate about this issue. Maybe my hacker news throwaway should’ve been called cryptopassion

There is no compromise. There is either security, or there is not. You want the not, because you prioritize government access to all communications over privacy. The rest of the world disagrees with you.

No, not true. Crypto isn’t perfect as is, and involves levels of security.

Two party crypto has two parties who could leak the data. Two party with exceptional access has three. Current crypto is susceptible to brute force via shor’s and quantum

The rest of the world absolutely does not agree with you. It’s just that a lot of people here live in a bubble.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#230
post #226

Earlier quoted context omitted.

There is no compromise. There is either security, or there is not. You want the not, because you prioritize government access to all communications over privacy. The rest of the world disagrees with you.

No, not true. Crypto isn’t perfect as is, and involves levels of security. Two party crypto has two parties who could leak the data. Two party with exceptional access has three. Current crypto is susceptible to brute force via shor’s and quantum The rest of the world absolutely does not agree with you. It’s just that a lot of people here live in a bubble.

Current crypto is possibly subject to attack due to implementation defects. You're throwing out word salad that you clearly don't understand on this subject -- but hey, let's take your statement as fact for a hypothetical second.

Since as you say, "Current crypto is susceptible to brute force via shor’s and quantum", then there's no need for backdooring algorithms, since they're all already broken.

I mean, none of that is accurate, but given your argument you're asking for something you don't need because you already have it.

Post reply on HN