Live data from Hacker News

A Few Thoughts on Ray Ozzie’s “Clear” Proposal

blog.cryptographyengineering.com

41–50 of 77 posts

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#41

Earlier quoted context omitted.

Perhaps a miscommunication? Suppose we talk about vehicles, and I could classify them by color (red, green, ...), or by type (cars, planes, ...) What is a good or bad classification? What is disturbing you? the mere topic? We can't improve prevention of a problem without talking about the problem. EDIT: Note, I have added making child porn to meat space crime (even though that is obvious) specifically for you Would y…

EDIT: Would you consider the "Napalm Girl" [0] to be child porn? Or evidence of the atrocities of the use of napalm in the Vietnam war? Did it eventually contribute to the end of public support for the war? https://en.wikipedia.org/wiki/Phan_Thi_Kim_Phuc

Really, I don't think it's sensible to even frame it that way.

Should she have the right to control where this picture of her naked is being used? Yes.

Is the picture evidence of sexual abuse? No.

Is the picture evidence of other human right abuses? Yes.

Why should it matter whether it "is child porn"?

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#42

Earlier quoted context omitted.

> What is disturbing you? the mere topic? The fact that you seem to consider the act of looking at the resulting pictures to be the primary crime even though that is more or less victim-less, rather than the sexual abuse that children are subjected to in order to produce the pictures, which very obviously is not a "cyber" anything, while you at the same time put murder into the category of "meatspace crime", if, foll…

Yes I see what you mean, but that was never the intended message, note the ellipsis! So just to be clear, I think it is obvious you, me and nearly everybody regards the making of childporn as a crime, without making any statement on how we regard the crimeness of watching child porn.

Well, I believe you that you didn't intend that message. But I think the way you put it still reveals how you think/thought about it, and you are almost certainly not alone with that, that seems to be an expression of a sort-of societal consensus--which is actually why I found it disturbing. Noone would ever even get the idea of putting murder into the "cyber crime" category, but somehow that seems to be a natural thing to do for sexual child abuse for many people.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#43

Earlier quoted context omitted.

EDIT: Would you consider the "Napalm Girl" [0] to be child porn? Or evidence of the atrocities of the use of napalm in the Vietnam war? Did it eventually contribute to the end of public support for the war? https://en.wikipedia.org/wiki/Phan_Thi_Kim_Phuc

Really, I don't think it's sensible to even frame it that way. Should she have the right to control where this picture of her naked is being used? Yes. Is the picture evidence of sexual abuse? No. Is the picture evidence of other human right abuses? Yes. Why should it matter whether it "is child porn"?

"Should she have the right to control where this picture of her naked is being used? Yes."

This is the hard question, I argue the group should not give her the right to censor this image.

Imagine she had the power to censor that image, then she might be bribed into censoring it. I think taxpayers have a right to know what happens with their money.

I think the next generations have the right to know what happened, and learn from the mistakes of the generations before.

Imagine such an image of a person abusing a child, encrypted and signed by community cameras and later decrypted to apprehend the perpetrator. I still think a lot of valuable information (for prevention) can be found: did the perpetrator make some kind of promises? or use fear? how exactly do they lure a child into that situation? how can we prepare children better to recognize such situations? etc...

Then there is also political activism, to the extent that conspiracies or power abuses arise, if the only way to politically imprison a person undetected is to prevent the "evidence" to be presented to the public, then we provide them with this loophole of censorship...

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#44

Earlier quoted context omitted.

Yes I see what you mean, but that was never the intended message, note the ellipsis! So just to be clear, I think it is obvious you, me and nearly everybody regards the making of childporn as a crime, without making any statement on how we regard the crimeness of watching child porn.

Well, I believe you that you didn't intend that message. But I think the way you put it still reveals how you think/thought about it, and you are almost certainly not alone with that, that seems to be an expression of a sort-of societal consensus--which is actually why I found it disturbing. Noone would ever even get the idea of putting murder into the "cyber crime" category, but somehow that seems to be a natural th…

The real proble is that I classified subjects, instead of counts of crimes:

It should read:

* meatspace (a count of murder, a count of rape, ...)

* cyberspace (a count of distributing murder films, a count of distributing rape films, ...)

The reason nobody thinks of "actual" snuff murder films in cybercrime category, is because we are heavily bombarded with images of people dying: soldiers getting shot in the news are not considered snuff, cops and robbers shooting each other in movies are not considered snuff. But naked children are not that regular in news or movies (perhaps french/european movies, but thats just nudity in general not specifically children).

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#45

Earlier quoted context omitted.

Really, I don't think it's sensible to even frame it that way. Should she have the right to control where this picture of her naked is being used? Yes. Is the picture evidence of sexual abuse? No. Is the picture evidence of other human right abuses? Yes. Why should it matter whether it "is child porn"?

"Should she have the right to control where this picture of her naked is being used? Yes." This is the hard question, I argue the group should not give her the right to censor this image. Imagine she had the power to censor that image, then she might be bribed into censoring it. I think taxpayers have a right to know what happens with their money. I think the next generations have the right to know what happened, and…

Imagine we could all simply watch who how and when the double spy & daughter in Britain were possibly poisoned if so.

If they were, we can try to catch them if they are still on soil, or else publicly verifiably convince people elsewhere of what happened, and then continue with higher priorities like Grenfell Tower and how to prevent such events (where many more actually died, and never even worked for the Russians, never consented to the higher risk job of being a spy)

If it didn't happen, we can again focus on our real problems.

It would also generate unity within the community of citizens, instead of this constant contrarianism and doubt.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#46
The work I did on mobile encryption was framed thusly:

- Deriving a key for all devices from a single key creates a single, catastrophic failure mode for the solution where all devices become vulnerable together. As soon as customers figure this out, nobody serious will adopt it because they can't afford to accept that known risk exposure.

- We're assuming that the HSM we're using doesn't have a bias in its key generation RNG to limit the real key space, because if I were an intel agency, that's probably the first lever I would pull.

- The entropy of the additional derivation components we can source from the individual device to locally diversify keys is really limited, and some really smart people are going to be reversing our code. Apple (and unrelated, in my own work, I never worked for anyone affiliated with them) relied on limiting number of attempts in hardware (effectively) to mitigate this risk.

Personally, I think the Ozzie proposal is a red herring to give the feds rhetorical leverage by providing their side with something few people understand, but can get behind politically because it's sufficiently complex as to be "our" magic vs. "their" magic. This is to drown out technical objections and make the problem a political one where they can use their leverage.

As The author (Green) notes, we can design some pretty crazy things, and if the feds came out and said, "build us a ubiquitous surveillance apparatus, or at least give us complete sovereign and executive control of all electronic information." that is technically solvable problem, but in the US, legally intractable. So instead, they want those effective powers without the overt mandate.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#47
post #37

I don't see anything new in the alleged proposal, this is the same old crypto war. This is "just" key escrow. One might as well propose to have the manufacturers build in the governments public key (and autobrick phone usage) such that the phone can detect if it is really the government reading the phone. Another note: "Ozzie’s proposal relies fundamentally on the ability of manufacturers to secure massive amounts of…

I do prefer the idea of storing it on paper... at least it's a little easier to lock up. Even a big camera will only take a few thousand pictures before it fills up, and physical access is a lot easier to enforce. If we make 2 billion phones a year (Apple itself is just over 200M) and you have a line printer running full blast (66 lines = 1page per sec) you could do Apple with one printer... and the world in 10. It w…

impressive calculation for the per phone case!

but as I wrote, its not necessary in Ozzie's scheme: Apple only needs to store the single private key. All the phones contain the same public key corresponding to it. All phones encrypt the user passcode to the same public key. When a user tries to unlock his own phone with his correct passcode, the phone encrypts his passcode and arrives at thee same encrypted key, unlocking the phone. When the government seizes the phone, with a special device they have the phone show the encrypted pass code, dump the encrypted GB's of encrypted phone contents, and burn an irreversible efuse in the processor disabling it. They send the encrypted passcode to Apple, who verifies its the government indeed. Apple uses its single private key to decrypt the user passcode. Apple sends this pass code to the government. The government can decrypt the image.

In the proposal there is no need for a massive database of key material. It's nonsense.

(in practice Apple would use treshold crypography, so that at least k out of n private keys each belonging to specially trained and screened employees are necessary to decrypt)

(in practice each phone has a hardcoded random nonce in efuses and instead of encrypting the user passcode, it encrypts [passcode+nonce], otherwise the government could just bruteforce 10^4 encryptions to the public key)

I am only saying that this can be done efficiently, not saying that I agree with the desirability of key escrow. This idea of key escrow is as old as cryptography.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#48
post #37

Earlier quoted context omitted.

I do prefer the idea of storing it on paper... at least it's a little easier to lock up. Even a big camera will only take a few thousand pictures before it fills up, and physical access is a lot easier to enforce. If we make 2 billion phones a year (Apple itself is just over 200M) and you have a line printer running full blast (66 lines = 1page per sec) you could do Apple with one printer... and the world in 10. It w…

impressive calculation for the per phone case! but as I wrote, its not necessary in Ozzie's scheme: Apple only needs to store the single private key. All the phones contain the same public key corresponding to it. All phones encrypt the user passcode to the same public key. When a user tries to unlock his own phone with his correct passcode, the phone encrypts his passcode and arrives at thee same encrypted key, unlo…

Totally agree that they only _need_ a single secure key and a BUNCH of insecure nonces. However, if I was forced to keep a key in escrow and wanted it to be secure I'd put a uniquely generated (lots of lava lamps?) key for every one on paper and force anyone who wanted to look them up to do it physically, in person, with paper. Out go the digital public keys, in stay the paper private keys in a well observed building full of a zillion boxes of paper. Most insecure part is still the key generator.

If the feds want to audit, they can... but everyone will see it on video, what boxes they opened, and what pages they (could have) looked at.

I'd hire some magicians for pen testing too.

edit: pi*10^7 sec in a year is a useful approximation

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#49
Extremely exceptional access only, in cases where thousands of people's lives could be at stake or millions. Since we can't create a fully unbreakable software/hardware security systems anyway, if ever, companies can use technology + psychology. Unintentionally create an extremely difficult to find bug that requires extremely talented engineers and large hardware resources to break, then unintentionally share it with at most discreet way probably just verbally to very few trusted 3rd parties. And it is not officially approved by the top management or even knows about it. We don't live in a perfect world and we don't have a perfect solution. JUST COMMENTS, NOT A SUGGESTION!

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#50

We need a new way of thinking about caches of secrets. It comes from this unpleasant truth: all secrets eventually leak. The evidence of the past few years teaches us that even state actors with unlimited resources cannot prevent their secrets from leaking. A "leak" here happens when a trusted entity loses control of the secret to one or more untrusted and malicious entities. That's just a definition, not a claim tha…

What if the proposal is changed so that the keys do not need to be kept forever? What if Apple is allowed (or even required) to publicize the private key(s) after, say, 10 years?
Post reply on HN