Live data from Hacker News

Government Announces Steps to Restore Confidence on Encryption Standards

bits.blogs.nytimes.com

61–70 of 132 posts

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#61
post #38

This got my heart beating. There is actual rebellion among academics, and a movement to restore trust in both people and tech. This is the NY Times quoting Matt Green of John Hopkins in the article: “I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. Thats pretty strong sentiment. Seems to echo the bitterne…

If I remember correctly back in beginning of 1990s there was a discussion in the US about preventing export of encryption protocols, then it was a discussion about making laws where a suspect is obliged to give up his/her key just like in the UK to agencies, and someone even mentioned making encryption unavailable or forbidden by law for civilians. All in the name of "we wont be able to catch criminals if we cant lis…

The export related discussion you remember was the _end_ of that programme.

http://en.wikipedia.org/wiki/Export_of_cryptography_in_the_U...

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#62
post #10
post #6

When I saw 'new details' (edit: this was referring to an old title), I was hoping that the backdoor in Dual_EC_DRBG was either confirmed or denied ... in reality, there's not much new here. The NYT confirmed that their previous article was talking about Dual_EC_DRBG, but that's what everyone (edit: in the cryptography community) expected anyway [1]. We still don't know the exact story behind Dual_EC_DRBG. Maybe the N…

> that's what everyone expected anyway This one sentence is a _remarkably easy way_ to kill a story for the 99.9% of the world who this is news for. "Everyone" indeed.

Yes, news to me and that it's reported by the New York Times no less, albeit on a blog, makes it less of a conspiracy theory and less controvertible. I'd say it's more like this is news to 99.99999%

Kind of shocking, N.I.S.T and the C.S.E with their pants down.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#63
post #34
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

Thats an interesting concept, I wonder if Russia and China have their own standards/protocols to use? I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.

> I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.

TrueCrypt supports cascaded encryption in XTS mode, see [0]. AES-Twofish-Serpent, combined with a decent password and Whirlpool hash algorithm (it is used for HMAC and for mixing the RNG) should be pretty secure, IMO. Anyhow, we don't have plenty of really good and checked publicly available alternatives for symmetric encryption.

[0] http://www.truecrypt.org/docs/cascades

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#64
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

Your augment makes sense, but somehow you're missing the idea that the government has infinite ways to investigate someone outside of breaking encrypted communication. They actually have people who can break into buildings and install keyloggers, or audio bugs, or interview witnesses, or anything you can imagine.

His argument doesn't make sense because it misses the fact that a government is supposed to represent the people, and therefore it should accept the will of the people.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#65
post #50
post #39

Earlier quoted context omitted.

Sounds ideal, until you realize that building and operating proper encryption is too hard for some of these organizations (PirateBay, FSF). For the rest, they are only mutually hostile on the surface. I am sure when it suits them they will get together and sell all our asses to each other.

You mean like Obama giving a tool to read his email to Putin? Unlikely IMO.

More generally, something along the lines of: "You give us Snowden/limit his asylum claims/etc etc, and we give you favourable trade terms".

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#66
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

"How can any government accept a situation where communications are so secure that none of their agencies can break it?"

Their friends in the business community can rest assured that foreign competitors, criminals, etc. are not able to eavesdrop on their communications. Spies in foreign countries could use a strong cipher without raising any suspicions. These arguments were made in the 90s you know.

"Essentially law enforcement do need to investigate crime."

Only to a point. If the only evidence of a crime is the plaintext of some encrypted message -- no physical evidence, no witnesses, etc. -- then the benefits of strong cryptography vastly outweigh whatever problem there is with letting the crime go unpunished.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#67
post #53

This got my heart beating. There is actual rebellion among academics, and a movement to restore trust in both people and tech. This is the NY Times quoting Matt Green of John Hopkins in the article: “I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. Thats pretty strong sentiment. Seems to echo the bitterne…

“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. That's the understatement of the century. NIST is pissed off. Many of these guys move fluidly back and forth from NSA, and clearly they were kept in the dark.

Nitpicking but why understatement? Feeling betrayed sounds more serious that just pissed off.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#68
post #51
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

I have absolutely no interest in forgetting the idea of secure communications just because governments won't like it. I find it peculiar to see someone call themselves an anarchist yet accept this - unless you're a Proudhonist or other particularly esoteric pre-Bakunin kind that have been out of fashion since the 1870's... A key feature of anarchism all the way back to when Bakunin was expelled from the first Interna…

Great points. I am not an anarchist in theory, but I agree with many of your points on a practical level. Balance of power is critical to maintaining a fair society, which was obviously violated by the NSA's actions, insofar as their power to misuse their information advantage was not appropriately constrained. Please forgive my ignorance on the matter, but what claims have been made regarding innapropriate actions taken based on the NSA's surveillance programs? Inappropriate meaning "decreasing fairness of outcomes in a real sense", not based on the theoretical potential for abuse of an asymmetric information advantage.

I'm a thoroughly pragmatic person. I share all of your concerns about abuse of power (which I see very real cases of everywhere). Yet something in my core believes the ultimate theoretical good may not be ultimate secrecy, but no secrets at all. (Yes, I realize the best path there is not a straight line, if there even exists a practical path).

An honest question for anyone who is passionate about secrecy/anonymity: is it something you inherently value or do you value it because you don't trust other parties to not misuse it? Hypothetically, if that were not possible because their abuse would also be known and they would be held accountable, would that alleviate your concerns?

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#69
I hate all this NSA spying but they do have a point - if they cant read the communications of the bad guys, how are they supposed to catch them before it's too late. Isn't there a way to accomplish both objectives of security and preserving constitutional freedoms?

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#70
post #34

Earlier quoted context omitted.

Thats an interesting concept, I wonder if Russia and China have their own standards/protocols to use? I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.

OpenSSL supports these Russian GOST standards: * md_gost94 message digest algorithm * gost89 symmetric encryption algorithm with 256 bit key * gost94 public key algorithm with 1024 bit public key * gost94cp public key algorithm with 1024 bit public key (CP mode1) * gost2001 public key algorithm based on elliptic curves with 512 bit public key * gost2001cp public key algorithm based on elliptic curves with 512 bit pub…

Should I make a simple script to use gnutls to encrypt a file with AES then openssl using gost89, then 3des ?
Post reply on HN