Live data from Hacker News

A Few Thoughts on Ray Ozzie’s “Clear” Proposal

blog.cryptographyengineering.com

51–60 of 77 posts

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#51
post #48

Earlier quoted context omitted.

impressive calculation for the per phone case! but as I wrote, its not necessary in Ozzie's scheme: Apple only needs to store the single private key. All the phones contain the same public key corresponding to it. All phones encrypt the user passcode to the same public key. When a user tries to unlock his own phone with his correct passcode, the phone encrypts his passcode and arrives at thee same encrypted key, unlo…

Totally agree that they only _need_ a single secure key and a BUNCH of insecure nonces. However, if I was forced to keep a key in escrow and wanted it to be secure I'd put a uniquely generated (lots of lava lamps?) key for every one on paper and force anyone who wanted to look them up to do it physically, in person, with paper. Out go the digital public keys, in stay the paper private keys in a well observed building…

1) regarding BUNCH: the nonces are random and hence there will be as many as there are phones drawn from suitably large n-bit space, but Apple does not need a local copy of the nonces, if the government requests a decryption and Apple agrees, it will decrypt and find the user pass code and the irrelevant nonce.

2) "and force anyone who wanted to look them up to do it physically, in person, with paper" I dont understand your proposal? If the government wants to decrypt a phone, they should come to Apple in person with what paper? How do you insure that everyone knows when a phone is audited? (Ozzie's proposal or what we read of it in the article does not adress insuring the populace finds out whenever a phone is decrypted). In your scenario the well observed building is operated by Apple or by the populace?

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#52
post #48

Earlier quoted context omitted.

Totally agree that they only _need_ a single secure key and a BUNCH of insecure nonces. However, if I was forced to keep a key in escrow and wanted it to be secure I'd put a uniquely generated (lots of lava lamps?) key for every one on paper and force anyone who wanted to look them up to do it physically, in person, with paper. Out go the digital public keys, in stay the paper private keys in a well observed building…

1) regarding BUNCH: the nonces are random and hence there will be as many as there are phones drawn from suitably large n-bit space, but Apple does not need a local copy of the nonces, if the government requests a decryption and Apple agrees, it will decrypt and find the user pass code and the irrelevant nonce. 2) "and force anyone who wanted to look them up to do it physically, in person, with paper" I dont understa…

The idea is that each of the secret keys (not nonces) would be kept on paper in a well observed location, with only the public keys leaving. The building would be operated by whoever is responsible for generating the keys and showing that their keys aren't (hopefully yet) compromised. They could allow the public to observe and perhaps the boxes could be marked with the range of IMEIs/keys contained within. If the cops want to go in and get a key out of a box, they can get a warrant to do it but everyone can know which few hundred thousand phones have been compromised.

It doesn't completely prevent malfeasance... it just makes it a PITA.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#53
post #17

I’m not sure the benefit to Apple or other phone manufacturers. This looks like a substantial cost with zero benefit to those others than law enforcement. And substantial new risk for misuse or abuse. What’s Ozzie’s true motivation? Is he looking to start a company running Clear and raking in patent revenue? I get why the governments want this, but not why a citizen would propose this. If it weren’t Ray Ozzie, I woul…

Money. His true motivation is money. Secondary to that is prestige; he "solved" this problem.

You might be right, but you’re guessing. I’m pretty pro-crypto. I’m an anarchist. I am generally oriented towards non-governmental solutions to everything, including violence.

But even me, even with that bias, I still worry quite often about what evil can lurk behind cryptographic structures, and what effect wide availability of strong crypto will have on that.

I don’t know that it will be positive or negative... my gut says positive, but I worry. And so it’s not crazy to me to think Ozzie might be legitimately worried about people’s safety.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#54

Earlier quoted context omitted.

Really, I don't think it's sensible to even frame it that way. Should she have the right to control where this picture of her naked is being used? Yes. Is the picture evidence of sexual abuse? No. Is the picture evidence of other human right abuses? Yes. Why should it matter whether it "is child porn"?

"Should she have the right to control where this picture of her naked is being used? Yes." This is the hard question, I argue the group should not give her the right to censor this image. Imagine she had the power to censor that image, then she might be bribed into censoring it. I think taxpayers have a right to know what happens with their money. I think the next generations have the right to know what happened, and…

> This is the hard question, I argue the group should not give her the right to censor this image.

Sacrificing people's dignity for the supposed common good it very much not a road I am willing to go down. If we are willing to sacrifice an individual's dignity, there is nothing left worth sacrificing it for.

Mind you that this is distinct from limited use for the purposes of prosecution.

> Imagine she had the power to censor that image, then she might be bribed into censoring it.

Yeah, and then imagine I could strip you of your human rights because I value a common good higher than your human rights. Also, no matter what the law, you cannot completely prevent that people will try to put pressure on other people. The solution is not to disregard the individual's dignity, but to create incentives that counter attempts to silence those who suffer. Create an environment where people will come to the conclusion that allowing their picture to be used is the thing they should do, all things considered.

As for your idea of "democratized mass surveillance", I guess it's a nice thought experiment, but not something that could realistically be implemented in a way that would actually be fundamentally better than what we have today. For one, the checks and balances we have today are a sort-of implementation of the same fundamental idea of decentralizing power, but also, total democratization is not a guarantee for humanistic outcomes: Witch hunts, oppression of minorities, and genocides are in a way highly democratic. The problem with the oppression of homosexuals, say, was not that the abuses were a secret, but that the majority opinion was that it was the right thing to do, and such mass surveillance would only have helped with it.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#55
Can anyone explain why the government wouldn't just mandate that they be given all the keys from the start? Why would they put up with Apple as a middleman who could potentially refuse their requests?

Also, this key escrow scheme is near impossible to scale to more than one government. Now we need a way to authenticate government agents, good luck with that.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#56
Bricking the phone works against law enforcement by only allowing raw access to the data. Even if Clear worked correctly, law enforcement couldn't open apps and see the data in the correct context. They'd have raw data files full of indexes, hashes, and cached data. Worse, apps would start to encrypt data on the client specifically to avoid Clear.

The only significant change between plain key escrow and Clear (bricking the phone) would defeat the usefulness of Clear.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#58

Earlier quoted context omitted.

Well, I believe you that you didn't intend that message. But I think the way you put it still reveals how you think/thought about it, and you are almost certainly not alone with that, that seems to be an expression of a sort-of societal consensus--which is actually why I found it disturbing. Noone would ever even get the idea of putting murder into the "cyber crime" category, but somehow that seems to be a natural th…

The real proble is that I classified subjects, instead of counts of crimes: It should read: * meatspace (a count of murder, a count of rape, ...) * cyberspace (a count of distributing murder films, a count of distributing rape films, ...) The reason nobody thinks of "actual" snuff murder films in cybercrime category, is because we are heavily bombarded with images of people dying: soldiers getting shot in the news ar…

Nah, that's just another effect of the same underlying cause:

Sexuality is something that religions have very restrictive rules about, and anything that doesn't fit within the bounds of those rules is considered immoral. Which is why homosexuals were and still are oppressed, and which is also why pedophiles are oppressed essentially just like homosexuals once were. Being a pedophile is widely considered to be a moral failing, just like homosexuality once was (and by some still is). This taboo leads to people not rationally looking at the actual facts of the situation, not considering the actual consequences of what is happening, instead anything that is in any way associated with pedophilia is seen as equally objectionable, which in turn leads to a general lack of distinction.

"Child porn" is just a generic label for "terrible immoral stuff done by immoral people involving the idea of sexual practices involving children" in the public discourse, and a terrible label at that, given that it either tries to use a negative view of pornography to evoke an emotional reaction to an essentially unrelated topic, or trivializes the experience of abuse victims whose agony is documented by suggesting that it's in some way similar to consenting adults producing erotic works for the pleasure of other consenting adults to look at. It's a bit like using the label "child horror movies" for snuff videos depicting children.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#59

Personally I believe real world actions should be the focus of surveillance. The empires are simply trying to cheap out by focusing on surveillance of computer activity. This is the most profound part of Matthew Green's piece in my opinion: "While this mainly concludes my notes about on Ozzie’s proposal, I want to conclude this post with a side note, a response to something I routinely hear from folks in the law enfo…

[deleted]

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#60
Just a nitpick. Matthew Green uses the analogy of signing keys being leaked often as evidence that Ozzi’s proposed system would be similarly not secure. This is a weak analogy: signing private keys are often leaked because their use case requires them to be “online” in some fashion (code must be signed with the private key so it can be verified with the public key). Similarly, CAs must use private keys operationally (to sign customer CSRs), increasing the risk of key compromise.

In Ozzi’s proposal, the private key never actually has to exist outside the environment it was created in, only the public key does. As pointed out in other comments, LE would not need access to the private key, either, they could simply submit the encrypted passcode to the manufacturer, who would then decrypt it on their behalf using the private key.

Post reply on HN