Live data from Hacker News

Times Pulls Article Blaming Encryption in Paris Terror Attack

insidesources.com

281–290 of 312 posts

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#281

I don't know why people are considering these terrorists to be so smart. They arrived at the Stade de France and were naively thinking they'd be able to come inside with explosives tied to them. In January, they didn't even know where the Charlie Hebdo meeting room was, they had to ask for directions and were even sent the wrong way (at first). Really, I'm far from worrying about their communication's encryption as m…

> as much as I worry about the lax government

You mean the same governments that are already collecting everyone's private communications and swabbing babies for bomb residue at airports under the guise of stopping these types of things? It's not a lack of effort or resources that should be concerning, it's the sheer incompetence.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#282

Earlier quoted context omitted.

This is always the part of the anti-Snowden case that baffled me. Those who seem to think that he alerted terrorists to the most secure means of communication seem to assume that, prior to the Snowden leaks, they were communicating by yelling really loudly across the NSA buildings. It's like they simply forgot about the biggest reason it took so long to find Osama bin Laden: he was so security-concerned that he used…

I understand what you're saying, and I agree. But I think it might be a little disingenuous to use Osama Bin Laden's crypto practices as an example. I believe this is the more interesting story of what really happened with Bin Laden? >Pakistan secretly captures Bin Laden by bribing tribesmen. The US finds out by bribing Pakistani officials. Further bribes with foreign aid money get other Pakistani officials to issue…

I was just using it as an example of it long being on the mind of terrorists that they need to take extreme precautions to avoid their electronics being compromised. Snowden didn't alert them to the concept of decryption. Sorry if I implied anything more.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#283
post #252

Earlier quoted context omitted.

I understand what you're saying, and I agree. But I think it might be a little disingenuous to use Osama Bin Laden's crypto practices as an example. I believe this is the more interesting story of what really happened with Bin Laden? >Pakistan secretly captures Bin Laden by bribing tribesmen. The US finds out by bribing Pakistani officials. Further bribes with foreign aid money get other Pakistani officials to issue…

The other 'wild' claim I heard was that his compound was actually a prison, built especially to house him. Again no proof, but an interesting idea none the less.

To be fair, an ultra-secure compound that the owner/resident of doesn't ever leave for fear of his own safety can be indistinguishable from a luxury prison in terms of outcome, even if it wasn't intended that way.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#284

Earlier quoted context omitted.

This is always the part of the anti-Snowden case that baffled me. Those who seem to think that he alerted terrorists to the most secure means of communication seem to assume that, prior to the Snowden leaks, they were communicating by yelling really loudly across the NSA buildings. It's like they simply forgot about the biggest reason it took so long to find Osama bin Laden: he was so security-concerned that he used…

The most dangerous terrorists have probably already reverted to couriers with one-time pads. One-time pads are uncrackable, yet they were used extensively before modern cryptography was even invented. They're cumbersome and constrained but very effective. No amount of mass surveillance will alter their efficacy. https://en.wikipedia.org/wiki/One-time_pad

It doesn't seem very likely that anyone has broken a modern symmetric cipher like AES or ChaCha. If not, a small random key is just as good as a one time pad, and you can reuse it for as many messages as you want. The bigger risks are that you reveal the key or that your hardware is evil, but OTPs don't save you from either of those.

With public key crypto it's a lot more likely that something might be broken. But then again if you somehow solve the problem of swapping secret keys/OTPs with everyone you want to talk to, you don't need public key crypto.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#285
post #281

I don't know why people are considering these terrorists to be so smart. They arrived at the Stade de France and were naively thinking they'd be able to come inside with explosives tied to them. In January, they didn't even know where the Charlie Hebdo meeting room was, they had to ask for directions and were even sent the wrong way (at first). Really, I'm far from worrying about their communication's encryption as m…

> as much as I worry about the lax government You mean the same governments that are already collecting everyone's private communications and swabbing babies for bomb residue at airports under the guise of stopping these types of things? It's not a lack of effort or resources that should be concerning, it's the sheer incompetence.

No, the point I was trying to make has nothing to do with communication. Molenbeek has been known to host radicalized Islamists for twenty years, I've heard on French TV this weekend. Encrypted communication or not, as long as governments sleep on such facts, we will see further attacks.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#286

Earlier quoted context omitted.

It does, it looks random (hight entropy). Yes, measured data and unmarked compressed data have this same property, as do actual random data. But is does not look like 9 nines of false positive rate are a concern to those people.

You can set the entropy to any amount you want. You need to consider encryption methods that put in at least a bit of effort to hide themselves. It could select random phrases and pretend to be a spambot.

Well, where's the boundary between cryptography that hides itself and stenography? Is there one?

If you include stenography, yes, it's certainly not easily recognizable. I don't think good stenography can be recognized at all, but that's not my area and I've got people contradict me at this (without further info), thus I'm not sure.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#287
post #278
post #262

Earlier quoted context omitted.

No. What you described will work for a simple substitution cypher, but not for a one time pad. A one time pad is the same length as the message, and permutates every letter independently. Trying all keys will yield every possible plaintext . For example the phrase: "The swallow flies at midnight" May (with a one time pad) be encrypted into "WD4oXOl8yO0QtD4sOf7ip0P7ScIia" (which, incidentally, is indistinguishable fro…

Well-known caveat for people who are familiar with encryption, but it's worth calling out explicitly here: If you use the same one time pad to encode two or more different messages, then all the sorts of attack proposed here become plausible again. The security provided by a one time pad relies entirely on the fact that it is only ever used once.

I'd like to add this scenario actually happened during the Cold War. Soviets were reusing one time pads and the US army decrypted some of the messages, among other things this lead to discovery of Soviet spies targeting the US nuclear weapon program https://en.wikipedia.org/wiki/Venona_project

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#288

Earlier quoted context omitted.

> I don't think that federal intelligence and law enforcement officials calling for backdoors have fully thought through the consequences I think assuming that level of incompetence is a big claim. It's simply much more likely that the actual plans/goals and the talking points and press releases about the plans/goals are mostly unrelated, as usual. You can infer that those calling for backdoors have decided that call…

> You can infer that those calling for backdoors have decided that calling for backdoors is the best thing to say, inferring anything more requires more information. How is calling for a really bad idea because it's the best thing to say different from the level of incompetence you say is too big to assume?

It sounds like the implication is that the politicians are smart enough to know that the backdoors are ultimately not going to happen but that calling for them is a way to appease voters who haven't followed this through to its logical conclusion.

edit: "not going to happen" could be read as "not going to be effective." I wouldn't actually be surprised if the US ended up passing some law restricting crypto to an approved list of backdoored schemes (surprised: no, dismayed: yes), forcing people into hiding their crypto in deniable ways. What some people don't seem to grasp is that no matter how much you outlaw certain math operations, whether or not the end users comply with those laws is ultimately up to them, and the terrorists simply won't comply.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#289
post #173
post #161

Earlier quoted context omitted.

I don't fully understand this line of thinking. To me, it's like saying "The belief that seat belts save lives might come as a surprise to these people who died in automobile accidents while wearing seat belts." It may indeed be that this kind of signals intelligence isn't actually helpful, but I don't think this is a very good argument either way. If there was a massive disruption of planned terrorist attacks, it is…

Exactly. Same reason you have locks on your doors even though they are easy to defeat. Tech types want to believe that the government is always overreaching and everything is a slippery slope to some other loss of freedom. Mixed in with a bit of overcooked paranoia thinking the government has enough time and energy to track down everyone and whatever laws they are breaking by reading their emails.

Bad analogy. The sites I help run are often receiving 10k attacks per minute with fuzzers and known exploits. The internet provides anonymity unlike some guy standing at your front door. I have yet to have an army of bad guys trying to pick my lock 10k time per minute on my house. Backdoors into things are economy is based on SSL etc. are just plain irresponsible.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#290

I encourage open thought rather than mob attacks on unpopular opinions. Anyone have a link to the original article?

A quick search of this thread reveals: https://news.ycombinator.com/item?id=10580586 https://web.archive.org/web/20151115191248/http://www.nytime...

I don't really see anything too terrible about the article.
Post reply on HN