Earlier quoted context omitted.
I don't buy it. These systems are always multiparty. In a single party cryptosystem we can have internal integrity. We know we're not the bad guys and we didn't share the private information with the bad guys, therefore the bad guys don't have the data. Once you're multiparty that goes away, any other party can definitely betray you and then it's game over, your own integrity doesn't matter. Historically NOBUS was ab…
The argument about who the trustworthy "us" is is deeply uninteresting to me. I just care that there's precedent that if you stipulate the existence of such an "us", computer science does allow for NOBUS-y access mechanisms.
Civics is boring, so, let's encrypt something (2024)
61–70 of 74 posts
Re: Civics is boring, so, let's encrypt something (2024)
#62So, if we were to implement what this author is proposing, governments would be allowed to jail people indefinitely simply because they used effectively unbreakable encryption- regardless of whether what they encrypted was illegal (or evidence of a crime)? Because if so, that is absolutely unacceptable in any society that would call itself free.
[dead]
Re: Civics is boring, so, let's encrypt something (2024)
#63Earlier quoted context omitted.
I don't think it's actually irrelevant; there's a reason they did it that way. Getting commit access and being the only one who can even read the code are two very different things. Even if you can modify the code, the less obvious it is that the change is adding a backdoor the less likely someone else is to catch you.
I think it would be so difficult to convince me that a state-level adversary who has obtained persistent access to Netscreen's builds can't hide arbitrary backdoors that it isn't really worth hashing this out. I'm just going to point out again that the Netscreen attack didn't break the "NOBUS" property of Dual EC --- so far as we know, the Dual EC private keys have never leaked.
Re: Civics is boring, so, let's encrypt something (2024)
#64Earlier quoted context omitted.
[dead]
I don't know what country you think that is true in, but citation needed. In the US at least, criminal convictions must be proven "beyond a reasonable doubt", they can't just say that they think there's information there, it must be proven that they already know it's there.
Re: Civics is boring, so, let's encrypt something (2024)
#65Earlier quoted context omitted.
I think it would be so difficult to convince me that a state-level adversary who has obtained persistent access to Netscreen's builds can't hide arbitrary backdoors that it isn't really worth hashing this out. I'm just going to point out again that the Netscreen attack didn't break the "NOBUS" property of Dual EC --- so far as we know, the Dual EC private keys have never leaked.
It seems like you're implying they'd be too good to ever get caught, but... they got caught. The trouble is, making a backdoor less obvious makes it more likely that if they try it 10 times they don't get caught all 10 times, more likely it gets into production before they get caught, more likely that it stays in production for a year instead of a month, etc.
Also, "never getting caught" isn't what NOBUS means.
Re: Civics is boring, so, let's encrypt something (2024)
#66Earlier quoted context omitted.
I don't understand the latter assertion. What's so special about RSA getting compromised?
They're a world-class security organization. If a nation-state actor can get access to their most important keys the hard way, then a nation-state actor has a decent shot at compromising any private key on the planet, if they're willing to put enough money into it.
Re: Civics is boring, so, let's encrypt something (2024)
#67Earlier quoted context omitted.
It seems like you're implying they'd be too good to ever get caught, but... they got caught. The trouble is, making a backdoor less obvious makes it more likely that if they try it 10 times they don't get caught all 10 times, more likely it gets into production before they get caught, more likely that it stays in production for a year instead of a month, etc.
Who got caught? The Juniper hackers? Obviously yes. They're not NSA. Also, "never getting caught" isn't what NOBUS means.
But the Juniper hackers are the NOBUS failure because changing the locks on a backdoor that somebody else had installed is easier than getting one installed yourself.
Re: Civics is boring, so, let's encrypt something (2024)
#68Earlier quoted context omitted.
They're a world-class security organization. If a nation-state actor can get access to their most important keys the hard way, then a nation-state actor has a decent shot at compromising any private key on the planet, if they're willing to put enough money into it.
They were just an enterprise software company. People have weird ideas of what RSA was. They bought the name RSA.
Re: Civics is boring, so, let's encrypt something (2024)
#69Earlier quoted context omitted.
They were just an enterprise software company. People have weird ideas of what RSA was. They bought the name RSA.
They're a large, trusted enterprise software company specializing in security. I'm very comfortable using them as a heuristic for the most secure that a regularly-used private key can possibly be.
Re: Civics is boring, so, let's encrypt something (2024)
#70Earlier quoted context omitted.
Who got caught? The Juniper hackers? Obviously yes. They're not NSA. Also, "never getting caught" isn't what NOBUS means.
I mean, didn't the NSA also get caught by Snowden? They intended it to be a secret. But the Juniper hackers are the NOBUS failure because changing the locks on a backdoor that somebody else had installed is easier than getting one installed yourself.