Live data from Hacker News

As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

lauren.vortex.com

41–50 of 295 posts

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#41
If anyone's interested in learning more of how you can use the private key of a server to monitor all communications: see, for example, US Pat. 7,543,051

It describes a way to passively/non-intrusively ("invisible to the server") capture and analyze all network traffic using a cable-tap.

Bottom of column 8: "In order to accomplish decryption in a timely manner the secure traffic decryption unit needs the private key of the server. Usually providing the server's private key to another device would be considered a security flaw, since private keys are not meant to be communicated to any other party. But since it may be assumed that usually the server's owner or operator will use the present invention to monitor his/her own server, providing the server's private key to the secure traffic decryption unit does not pose significant security risks."

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#42

If anyone's interested in learning more of how you can use the private key of a server to monitor all communications: see, for example, US Pat. 7,543,051 It describes a way to passively/non-intrusively ("invisible to the server") capture and analyze all network traffic using a cable-tap. Bottom of column 8: "In order to accomplish decryption in a timely manner the secure traffic decryption unit needs the private key…

https://docs.google.com/viewer?url=patentimages.storage.goog...

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#43
post #25
post #20

Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…

Situations like these probably rarely produce a real "winner". It is going to be an arms race between those favoring personal privacy and those favoring government snooping. Just keep in mind that government operates basically on an unlimited budget and has access to a wide range of harassment opportunities for non compliance in matters like these. This fact alone will keep them at least at a dead level with potentia…

I can think of at least one counterexample, namely the failure of the NSA-promoted key escrow system in 1990s (aka Clipper chip)

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#44

Earlier quoted context omitted.

Realistically paranoid, I think. Best plan may be to create a small encrypted partition, and put some data on it, so you can give them the passphrase when asked. Don't forget the passphrase!

And what if they say "That data was obviously innocuous so there must be another encrypted partition"?

You could try putting something embarassing but not incriminating there (e.g., gay porn or whatever).

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#45
post #9

Earlier quoted context omitted.

Don't rely on government for anything? What are you talking about? Almost 100% of scientific research and 100% of infrastructure around the world is funded by government. Almost all of education, health and welfare around the world (though less so in the US) is run by government. A lot of people are suspicious of government, but such fundamental disdain toward and alienation from government are peculiar American (and…

'such fundamental disdain toward and alienation from government are peculiar American' This. If you're so unshakably convinced that a government full of people you vote for every four years is never going to work in your interests, you have serious problems.

I think it's rather the other way. The historical record shows that they hardly ever do what I would have preferred. One problem is that the referents for "you" and "your" don't always match during the sentence:

"If you [1] are so unshakably convinced that a government full of people you [2] vote for every four years is never going to work in your [3] interests, you [4] have serious problems."

1. the person reading this

2. the majority of voters in your country, which the person reading this is only likely to be a part of about 50% of the time at best, in the US

3. the person reading this

4. the person reading this

Looking at just US presidential elections, people who vote straight Republican or Democrat will have been in the majority at least some of the time, but someone voting their conscience without regard to party has a fair chance of having been in the minority most of the time.

Another problem is that voting gives an individual neither control over nor responsibility for anything that the elect do. Look at all the Bush voters outraged about what happened during that administration (either Bush, actually), and all the Obama voters currently outraged about current administration activities.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#46
post #36

A logical conclusion to this is that if/when governments start forcing people to supply them with their private keys, they will also start forcing companies producing encryption software to include backdoors. At this point, I'm thankful that we have Free Software. With access to the source code, forcing the insertion of a backdoor is futile, since somebody else will fork and remove it. With Free Software, we'll still…

I agree with your sentiment, but want to provide a slight correction about "Free Software": MIT/BSD licensed software while not free in FSF/GPL sense, is still open and widely used and solves the problem we have right now. To avoid confusion with FSF ideals, I'd talk simply about Open Source software.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#48
post #22
post #6

Earlier quoted context omitted.

PFS and other Deniable encryption ( http://en.wikipedia.org/wiki/Deniable_encryption ) are great for deniability. However, they and everything else can be susceptible to unrelenting rubber-hose "cryptanalysis". ( http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis ) It is said that the goal of cryptography is to make the attacker resort to rubber-hose cryptanalysis, revealing their intentions. In those cases, the…

Any encryption scheme worth using will not be identifiable by a randomness test. Block ciphers like AES are designed specifically to model pseudorandom permutations (or, rather, this was one of their design goals); being able to distinguish them from truly-random data would be a rather frightening result. For more information, see "Is it possible to distinguish a securely-encrypted ciphertext from random noise?" at h…

Well, only two typical use cases will lead to owning a hard drive filled with (pseudo-)random noise: secure deletion or encrypted data. If you used either, you've got something to hide and it's a well-known fact only terrorists and communists do.

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#49
post #9

Earlier quoted context omitted.

Don't rely on government for anything? What are you talking about? Almost 100% of scientific research and 100% of infrastructure around the world is funded by government. Almost all of education, health and welfare around the world (though less so in the US) is run by government. A lot of people are suspicious of government, but such fundamental disdain toward and alienation from government are peculiar American (and…

/sarcasm -- (to be read in the voice of Sir Humphrey Appleby) I, for one, rely on my government to perform all those vital, but tragically under-appreciated services done selflessly and at great sacrifice, and all for the public good. Our top Whitehall mandarins do so much to pre^H^H^Hdeserve their salaries. The fabulous residences for the ambassadors, senior diplomats and other political appointees -- all those soci…

I don't understand your point. You could probably say the same about your family. The fact that something is not working as well as it should does not mean it's not essential. I mean, would you prefer feudal lords? Because that's what we had before central government, and that's what many corporations would like. Do you want to be ruled by Google? By Walmart?

Re: As Feds Demand the Keys, Preparing for the Death of Public-Key Encryption

#50
post #20

Sounds like not "the death of public key encryption" but the golden age of building technical controls into hardware/software which cannot be subverted by the operator, even in the face of a state agent with a gun. Assuming the right tech is developed and deployed, this is going to be far better for everyone in a few years. Yes, it will be shitty for a year or two, but by 2020, if we actually have real technical secu…

Those things you speak of will be outlawed and you won't be allowed to use them.
Post reply on HN