Live data from Hacker News

A Few Thoughts on Ray Ozzie’s “Clear” Proposal

blog.cryptographyengineering.com

71–77 of 77 posts

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#71
post #52

Earlier quoted context omitted.

1) regarding BUNCH: the nonces are random and hence there will be as many as there are phones drawn from suitably large n-bit space, but Apple does not need a local copy of the nonces, if the government requests a decryption and Apple agrees, it will decrypt and find the user pass code and the irrelevant nonce. 2) "and force anyone who wanted to look them up to do it physically, in person, with paper" I dont understa…

The idea is that each of the secret keys (not nonces) would be kept on paper in a well observed location, with only the public keys leaving. The building would be operated by whoever is responsible for generating the keys and showing that their keys aren't (hopefully yet) compromised. They could allow the public to observe and perhaps the boxes could be marked with the range of IMEIs/keys contained within. If the cop…

suppose Apple owns the building:

* there is no advantage in having cops come over: either a secret is revealed or it is not. Any information to convince Apple concerning a specific case or phone could just as well be sent over the internet. Allowing them to enter looks like a serious threat vector to me, they could plant things, smuggle things out...

* Either Apple is faithfully reporting each count of the cops unlocking a phone, or it isnt. In the case of requesting over the internet the cops can't bring in devices to look through closed boxes or whatever.

* Is your fear rooted in a perceived sense of insecurity because of the small passcode (4 decimal digits) and the effect that would have on the security of the encrypted(passcode+nonce)? because that is exactly why the random nonce is there, in theory the user could select his own nonce and have it burned in efuse memory, but he would only be able to change the nonce a limited number of times. Then the user can roll as many dice as he wants and xor bits to smithereens ;)

but it all stays crap key escrow, its just a big "Eureka!"-show trial balloon to gauge public acceptance, no?

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#72

Personally I believe real world actions should be the focus of surveillance. The empires are simply trying to cheap out by focusing on surveillance of computer activity. This is the most profound part of Matthew Green's piece in my opinion: "While this mainly concludes my notes about on Ozzie’s proposal, I want to conclude this post with a side note, a response to something I routinely hear from folks in the law enfo…

I've been thinking along somwhat similar lines. Here's an old thing I wrote about it. I'd be curious to know what you think?

"Total Surveillance is the Perfection of Democracy"

For once I disagree with RMS, re: https://www.gnu.org/philosophy/surveillance-vs-democracy.htm...

I believe that it is fundamentally not possible to "roll back" the degree of surveillance in our [global] society in an effective way. Our technology is already converging to a near-total degree of surveillance all on its own. The article itself gives many examples. The end limit will be Vinge's "locator dust" or perhaps something even more ubiquitous and ephemeral. RMS advocates several "band-aid" fixes but seems to miss the logical structure of the paradox of inescapable total surveillance.

Let me attempt to illustrate this paradox. Take this quote from the article:

    "If whistleblowers don't dare reveal crimes and lies, we lose the last shred of effective control over our government and institutions."
(First of all we should reject the underlying premise that "our government and institutions" are only held in check by the fear of the discovery of their "crimes and lies". We can, and should, and must, hold ourselves and our government to a standard of not committing crimes, not telling lies. It is this Procrustean bed of good character that our technology is binding us to, not some dystopian nightmare.)

Certainly the criminally-minded who have inveigled their way into the halls of power should not be permitted to sleep peacefully at night, without concern for discovery. But why assume that ubiquitous surveillance would not touch them? Why would the sensor/processor nets and deep analysis not be useful, and used, for detecting and combating treachery? What "crimes and lies" would be revealed by a whistleblower that would not show up on the intel-feeds?

Or this quote:

    "Everyone must be free to post photos and video recordings occasionally, but the systematic accumulation of such data on the Internet must be limited."
How will this limiting be done? What authority will decide who gets to collect (archive!) what and when? And won't this authority need to see the actions of the accumulators to be able to decide whether they are following the rules?

In effect, doesn't this idea imply some sort of ubiquitous surveillance system to ensure that people are obeying the rules for preventing a ubiquitous surveillance system?

Let's say we set up some rules like the ones RMS is advocating, how do we determine that everyone is following those rules? After all, there is a very good incentive for trying to get a privileged position vis-a-vis these rules. Whoever has the inside edge, whether official spooks, enemy agents, or just criminals, gains an enormous competitive advantage over everyone else.

Someone is going to have that edge, because it's a technological thing, you can't make it go away simply because you don't like it. If the "good guys" tie their own hands (by handicapping their surveillance networks) then we are just handing control to the people who are willing to do what it takes to take it.

You can't unilaterally declare that we (all humanity) will use the kid-friendly "lite" version of the surveillance network because we cannot be sure that everyone is playing by those rules unless we have a "full" version of the surveillance network to check up on everybody!

We can't (I believe) prevent total surveillance but we can certainly control how the data are used, and we can certainly set up systems that allow the data to be used without being abused. The system must be recursive. Whatever form the system takes, it shall necessarily have to be able to detect and correct its own self-abuses.

Total surveillance is the perfection of democracy, not its antithesis.

The true horror of technological omniscience is that it shall force us for once to live according to our own rules. For the first time in history we shall have to do without hypocrisy and privilege. The new equilibrium will not involve tilting at the windmills of ubiquitous sensors and processing power but rather learning what explicit rules we can actually live by, finding, in effect, the real shape of human society.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#73
post #68

Personally I believe real world actions should be the focus of surveillance. The empires are simply trying to cheap out by focusing on surveillance of computer activity. This is the most profound part of Matthew Green's piece in my opinion: "While this mainly concludes my notes about on Ozzie’s proposal, I want to conclude this post with a side note, a response to something I routinely hear from folks in the law enfo…

Regarding your distinction between real and cyber crimes, digital evidence can certainly be relevant in a murder case, e.g. iMessages, location history, search history. Also, the read-only bricking chip tries to allow search but exclude ongoing surveillance, though I don't think it's technically feasible.

"Regarding your distinction between real and cyber crimes, digital evidence can certainly be relevant in a murder case, e.g. iMessages, location history, search history."

But the cameras are supposed to completely cover society, so we don't need the cyber info. Indeed, perhaps the perpetrator has a secret paper diary, written in code, where he writes down his exploits. Who cares? We have signed imagery, of him commiting the crime. Any extra information is useful in the statistical sense (to understand what drives a person to do this or that, or to better prepare citizens on how to prevent falling victim to such and such crime), but should be unnecessary to convict a person. The most relevant are the actions themselves I think.

About location history: the camera system is more reliable than the cell phones since a cell phone may be given to a friend willing to provide an alibi, alternatively GPS spoofing etc.

The major reason these cell phone messages, search history etc are highly relevant is simply because we lack the community camera system.

Another problem is phone evidence is highly irregular: some people are more aware of mass surveillance then others (which is also highly correlated to status in society!) when communicating, some people refuse to have a cell phone on them, ...

When they lack enough evidence, the prosecution is forced to grab at straws (irrespective of guilt or innocence of the defendant), and then the value of computer/phone activity seems very high, especially if boots on the ground or scientifiic investigation of crime scenes is so much more expensive. Then it is easy to view this digital data as highly relevant and reliable.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#74

Personally I believe real world actions should be the focus of surveillance. The empires are simply trying to cheap out by focusing on surveillance of computer activity. This is the most profound part of Matthew Green's piece in my opinion: "While this mainly concludes my notes about on Ozzie’s proposal, I want to conclude this post with a side note, a response to something I routinely hear from folks in the law enfo…

I've been thinking along somwhat similar lines. Here's an old thing I wrote about it. I'd be curious to know what you think? "Total Surveillance is the Perfection of Democracy" For once I disagree with RMS, re: https://www.gnu.org/philosophy/surveillance-vs-democracy.htm... I believe that it is fundamentally not possible to "roll back" the degree of surveillance in our [global] society in an effective way. Our techno…

My proposal stems very much from nearly identical thoughts that you just described!

Just posting to say I have read your comment, and will most certainly edit this comment to reply tomorrow!

I will probably also want to be able to contact you (by some method acceptable for us both, email? IRC?) if I ever rewrite this in a more accessible format, or perhaps to collaborate on this subject?

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#75
post #64

But why? Why give the government such a ripe target for abuse? Why tilt the balance of power even further in its favor?

Many people, especially those outside the tech community, do not view law enforcement as an adversary. In the US, the balance that we have struck is that the government cannot search our property, except upon probable cause (fourth amendment). While I personally don't like it, I think that warrant-based key escrow is reasonable from a policy perspective.

In post-FISA world where a campaign of a presidential candidate was wiretapped under false pretenses, this view of the world is criminally naive.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#76
post #52

Earlier quoted context omitted.

The idea is that each of the secret keys (not nonces) would be kept on paper in a well observed location, with only the public keys leaving. The building would be operated by whoever is responsible for generating the keys and showing that their keys aren't (hopefully yet) compromised. They could allow the public to observe and perhaps the boxes could be marked with the range of IMEIs/keys contained within. If the cop…

suppose Apple owns the building: * there is no advantage in having cops come over: either a secret is revealed or it is not. Any information to convince Apple concerning a specific case or phone could just as well be sent over the internet. Allowing them to enter looks like a serious threat vector to me, they could plant things, smuggle things out... * Either Apple is faithfully reporting each count of the cops unloc…

The real risk is that whatever the key-holder thinks is air-gapped storage isn't and the whole lot is secretly lost to crackers, state sponsored or not... that's a lot harder to do with 1000 tons of paper.

The point is that even a dedicated party trying to keep the keys safe probably can't do it (for any length of time) on digital media.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#77

Earlier quoted context omitted.

I've been thinking along somwhat similar lines. Here's an old thing I wrote about it. I'd be curious to know what you think? "Total Surveillance is the Perfection of Democracy" For once I disagree with RMS, re: https://www.gnu.org/philosophy/surveillance-vs-democracy.htm... I believe that it is fundamentally not possible to "roll back" the degree of surveillance in our [global] society in an effective way. Our techno…

My proposal stems very much from nearly identical thoughts that you just described! Just posting to say I have read your comment, and will most certainly edit this comment to reply tomorrow! I will probably also want to be able to contact you (by some method acceptable for us both, email? IRC?) if I ever rewrite this in a more accessible format, or perhaps to collaborate on this subject?

Cool. :-)

eff oh arr em ay en dot ess aye em oh en at

gmail.com

Post reply on HN