Intercepting Predator Video
schneier.com
schneier.com
Poppycock! At least encrypt the stream going up to and coming down from the satellite! If lots of people have to see it, redistribute it afterwards. The uplink/downlink encryption is the exact same key management problem as the command signal! Hell, why not use the same key. The video signal going up to and back from the satellite is hanging out there, accessible from the majority of earth's surface. But encrypt it and beam the encrypted signal to those "comfortable military bases." Then you can re-encrypt it for distribution, and completely change the key management problem to suit your needs. (Essentially make it into two key management problems. Divide and conquer.)
I usually like what Bruce has to say, but this blog post wasn't well thought out.
EDIT: Upon re-reading, Bruce's point is that it's the NSA's bureaucratic requirements that make it too cumbersome for an encrypted feed to be easily made available. So it's just easier for them to leave it unencrypted. I still say poppycock. If they were really being clever, they could "leave out encryption," but still obfuscate matters. (Both from the signal standpoint and from the bureaucratic standpoint.)
Even something like a "new compression algorithm" would probably be enough to flummox the Russian software program. If it were unique to the drones, then the sat-download program authors would have no economic incentive to implement it. (And some "representatives" of our interests could have talks with them about it if they happen to implement it anyway.) This isn't strong crypto, but it would at least raise the bar.
EDIT: To those with poor reading comprehension: the tactic is a bit of "divide and conquer." (Colloquially, not algorithmically.) Divide the "key management" problem into two: "Sat up/down link" and "distribute to allies." The "Sat up/down link" is the exact same key management problem as for the control link. Also, if you solve that key management problem by just using obscure compression, then you can distribute the video using ordinary website access controls on establishing streams. Not strong crypto, not uber-secure, but still better than what's there now.
For the operational requirements of the predator, nothing was better than all. They'd prefer an intermediate option, but it isn't available until procedures change.
Encrypt the uplink/downlink to protect it against satellite eavesdropping, worry about the distribution to users separately. Uplink/downlink video keys need to be distributed to the same folks who need the control link keys.
Sorry, unless you mean something else, you are just wrong. Encrypting a video link drone->sat->base and leaving out the allies is the exact same key management problem that they are solving with the control link encryption. Basically, leave out drone->sat->allies and solve that another way.
Do you see the difference?
Geez, how many times do I have to go over that?
- communication between two parties, one of which is physically secure with plenty of time in advance to agree on keys.
- delivering keys to arbitrary receivers on arbitrary points of the world, potentially under combat or other severely adverse conditions with very limited advance warning.
Are you sure you have the right definition of what 'key management' is? Isn't it easier to just admit Bruce Schneier actually _had_ thought out his post and you, not so much?
You still have to solve the rest, but that is at least an improvement.
Your passive-agressive link to Wikipedia -- what is your point in this? What exactly in the article did I miss?
Which is the entire problem.
You seem to be of the mis-conception that the video goes back to base and then is redistributed. AFAIK this is not the case :) Also, importantly, these signals are being intercepted as they are transmitted to the troops on the ground :)
Thanks for starkly admitting your reading comprehension problem. My proposal is for the video to be encrypted all the way back to the base then redistributed.
Now please go back and edit your responses to me to correct this incomprehension of my position.
Arrrgh, don't they cover reading comprehension in schools anymore? Thank you.
EDIT: Anyone would find this frustrating:
Me: "They are already doing X. That would be the same as Y. I propose they do Y."
cl: "No it doesn't"
Me: "X = Y (paraphrase)"
cl: "No it doesn't"
Me: "X = Y (2nd paraphrase)"
cl1: "Okay it does, but that doesn't solve the problem."
cl2: "Oh, I thought you said they were already doing Y."
sigh
Please, stick to the facts, and if people mis-understand you then restate your point more clearly and addressing the misunderstanding. If you're right, most times they'll apologise and everything is great. If you're wrong then you don't look like a complete asshole.
As I say, I'm not addressing the technical points - I probably don't have the background, and it's Christmas, so I certainly don't have the time. I'm not down-voting you because I can't judge the technical merits, but I'd ask you to be more considerate in your tone. It's one of the things that makes HN so much more pleasant than most other fora.
Please.
Congrats. Brilliant troll, and you made me look like the bad guy.
Congratulations, you've solved the easy problem. When you've solved the hard problem, then you'll have a valid counter-point to the article.
Now, do you make valid points about the difficulty of key management for the 2nd problem? Yes. But mainly I have been expounding on the equivalence of the 1st part. I am correct about that. Have been this whole thread. You just admitted it. Thanks.
Now on to the rest. The military already faces a key management for other communications. They just need to do it with enough bandwidth to support video feeds to take care of the 2nd part. Certainly, they already do such key management for other communications. Will it be trivial to implement? No. But is just putting things up on a satellite in view of the whole globe? I think not.
Also, if you send it out again you will still have a key management problem if the data is encrypted.
I do agree with the premise that if there is crypto it doesn't have to be strong as the enemy do not have a proper analytic capacity. While I also know that the current US defence chief wants gear to fight the war on his hands right now and down the track, but you'd think that they might have considered that crypto would be a good idea at some point and at least had some plans on how to incorporate it. At the moment it just looks like the US military were caught with their pants down.
So, by obfuscating with a "new compression algorithm" you can also actually do compression and save yourself a little bandwidth. This also gets you over bureaucratic hurdles. "By introducing this algorithm, we are save X gigabytes per whatever."
Between "key management is hard, lets go unencrypted", and underestimation of locals, I'd much more buy into the echo chamber that said "towelheads are dumbasses who couldn't find sand in their own damn desert" much more than anything else.
Just as I may want to share how much money I have in the bank to a business asociate to prove I have the assest to make a deal.
I'd do this by showing him/her the bank account information on screen, but I don't want to give him/her the transit, bank acount number and password to access said bank account.
The only relevant issue is "what effect does the compromise have on the usefulness of the intelligence gathered by the UAV?" For a variety of reasons I would say this causes only a very small amount of degradation in the usefulness or lifespan of the intelligence. Do I think it should be fixed? Yeah. Do I think it's the most life-saving use of engineering resources? No. Do I think all the arm-waving is going to cost more than the solution? Definitely.
If a UAV was flying over areas of the world that I know well it's highly likely that I'd be able to identify the locations that it was looking at, and send out warnings/orders accordingly. Also I could perform reconnaissance on the typical flight paths of the UAVs, and plan accordingly.
Probably a major risk in the world of 24 hour news and P2P networks is the possibility of recording and later re-broadcasting closeup video of what happens when UAVs misidentify their targets and hit civilian populations. This could result in some public relations catastrophes for the UAV operators. If the military are happy for this information to be broadcast unencrypted they should also prepare themselves for said footage to appear on YouTube or TV news.
In WW2 it was only a few top commanders who worked with Ultra (afaik), and it wasn't anywhere as regular as broadcast video. I guess the main difference here is the number of users is that much greater and in Schneier's opinion the value of the information is that much lesser.
Not really. Think how widely these keys would have to be spread to have any use. The drones are often used for immediate intervention: i.e. if needed they are launched to provide forward intelligence to units on the ground.
That kind of key management is a nightmare: especially when you think other nationalities/agencies/services might require the feed instantly too.
It would be a perfect setup to have encryption and key management - and I expect that technically a structure could be set up to do it securely. But one important feature of battlefields is that they get extremely confused and disorganised - it would break down at key moments, and regularly. The key to battlefield tech is always simpicity. So it's a tradeoff; one that doesn't seem to have worked out badly so far.
Today's wars are more psychological than ever. The enemy probably watches and gets scared by video of their locations being watched and blown up. They might even think twice after seeing things from our perspective.
There are also a spook-side theories. This could be a subtle poke in the ribs to say the insurgents could be doing this, and General Atomics embarrassed itself into a needed round of funding.
http://news.ycombinator.com/item?id=1000464
and here:
Every source has reported that the military has been aware of the possibility the video feed might be intercepted by an adversary since operations in Bosnia well over a decade ago. It's basic common sense that the designers must have considered such a possibility as well - after all, they made the control link encrypted.
Judging by how this is playing out in the media so far that does not seem to look too good for those that built this system.
In short, outsiders jump to conclusions based on their, almost certainly wrong, hasty assumptions. Insiders may not appreciate that their extensive technically detailed justifications for their current procedures are utterly useless in the face of ignorant casual public armchair analysis.
Now, whether or not the experts are justified in their position is an entirely different topic, but it's quite easy to see why they may not have anticipated the PR fallout from this problem.