https://theintercept.com/2015/11/15/exploiting-emotions-abou...
https://theintercept.com/2015/11/15/exploiting-emotions-abou...
>Pakistan secretly captures Bin Laden by bribing tribesmen. The US finds out by bribing Pakistani officials. Further bribes with foreign aid money get other Pakistani officials to issue a stand down order. The SEALS swoop in unopposed but somehow still lose a helicopter. They kill a captive Bin Laden as part of a deal to avoid exposing Saudi support for Al Qaeda. The media gets fed a cover story about the compound being a command center. Some doctor guy becomes a scapegoat and vaccination programs are derailed in all of Pakistan. The CIA fabricates documents from the compound and flirts with claiming credit for "enhanced interrogation" technique in the matter.
If you don't like that story then sure by all means stick with Story A: The CIA does brilliant investigative work. The commander-in-chief makes a gutsy call. The SEALs storm in and kill the bad guy in a firefight. He is buried at sea with full rituals. The 2012 presidential campaign starts a few days afterwards.
If you support Story A, then this would certainly make sense:
>It's like they simply forgot about the biggest reason it took so long to find Osama bin Laden: he was so security-concerned that he used couriers and relays (which, counter to the broad narrative about the terrorist shift to security, actually cannot be decrypted)
##EDIT
Claims comes from a previous HN article about the Killing of Bin Laden: https://news.ycombinator.com/item?id=9520984
The thing I'm stuck on though, isn't it still possible to do semantic analysis on the various permutations. Basically reading permutations for cogent statements? So do some sort of a-posteriori analysis
Infeasible for a human to do, but assuming one could construct a significantly advanced parser (non-trivial of course), wouldn't it be possible to brute force still? What am I missing?
"The swallow flies at midnight"
May (with a one time pad) be encrypted into
"WD4oXOl8yO0QtD4sOf7ip0P7ScIia"
(which, incidentally, is indistinguishable from random noise)
If you just bruteforced that by xor'ing every character with every other possible character you could derive every possible message of that length, such as:
"garfield hate lasagna someday"
"men are cats why even bother?"
"pocket knives go to space yay"
etc ad infinitum
No measure of semantic analysis will help you here!
If you use the same one time pad to encode two or more different messages, then all the sorts of attack proposed here become plausible again.
The security provided by a one time pad relies entirely on the fact that it is only ever used once.
Computerphile recently showed how this was done.
Imagine a one time pad made for encoding numbers that used a "MOD 10" operation on each digit.
Then imagine the key is:
6926560279774
And the message is: 0000000000000
The output is: 6926560279774
Alternative messages: 1234567890123 -> 7150027069897
1111111111111 -> 7037671370885
In all cases, the patterns that you can discern may be from my message and may be from the key. As an analyst, you can't tell.If this were English letters rather than numbers, and you know 'e' is very common, you still can't get anywhere because each 'e' is encoded with a unique character from the key.
With public key crypto it's a lot more likely that something might be broken. But then again if you somehow solve the problem of swapping secret keys/OTPs with everyone you want to talk to, you don't need public key crypto.
Yes, measured data and unmarked compressed data have this same property, as do actual random data. But is does not look like 9 nines of false positive rate are a concern to those people.
If you include stenography, yes, it's certainly not easily recognizable. I don't think good stenography can be recognized at all, but that's not my area and I've got people contradict me at this (without further info), thus I'm not sure.
There is no truth being asserted in the premise causing the conclusion to be true. It's fairly clear that it was a statement from an original source, that source being trustworthy is where we would find (or not find) the information which would show the conclusion to be true, not the premise of the 'fantasy.'
"$noun did $verb which resulted in $result and $result is $something interest which begs the question $question."
The government would just have the private keys so they could decrypt traffic easily.
Someone posted a photo of master keys and Internet was, as usual, the Internet.
And terrorists would be smart - they'd employ non-backdoored encryption, hide that in "legit" communications, and encrypt that with the proper back-doored government encryption. They'd appear to be a totally normal snapchat user, or whatever.
If we actually meant to give up all encryption, card-kiddies would destroy civilization in three weeks.
...Unless you're intercepting and sniffing everything that's unencrypted. Then we're back to square one.
I think you're straw-manning their position here.
The opponents of encryption aren't claiming terrorists will start using unencrypted communication, they're advocating for legally-mandated "back doors" to be built into supposedly-secure communication systems.
Terrorisms won't use legally-mandated software for they illegal operations.
All the back doors accomplish in the end is harming the general public.
http://www.friendmosaic.com/images/example-mosaic.jpg
and it's pretty easy to see that this avenue of thought --- that we will put our efforts toward finding a way to ban encryption --- is totally ridiculous.
So imagine if Apple, upon condition of selling iPhones within China, must provide the Chinese government with a backdoor through Apple's encryption. Do you know how many federal employees use Apple technology? Including the President himself, who totes an iPad everywhere?
I don't think that federal intelligence and law enforcement officials calling for backdoors have fully thought through the consequences.
I think assuming that level of incompetence is a big claim.
It's simply much more likely that the actual plans/goals and the talking points and press releases about the plans/goals are mostly unrelated, as usual. You can infer that those calling for backdoors have decided that calling for backdoors is the best thing to say, inferring anything more requires more information.
Not really. Have you listened to the average member of Congress lately? Incompetence runs deep throughout all levels of government.
Instead, look at it this way: everyone has their area of responsibility. The head of the CIA is charged with providing the best possible situational awareness for the U.S. government. He's going to make proposals and requests that will help him do that.
He's not charged with balancing all possible consequences from his requests, and he's not going to do so.
But ... that seems like quite a level of incompetence for someone trusted with the position of Head of the CIA?
By which I mean, not charging him with that responsibility is a mistake (in gov structure), but him actually not doing so is his own incompetence, is it not?
How is calling for a really bad idea because it's the best thing to say different from the level of incompetence you say is too big to assume?
edit: "not going to happen" could be read as "not going to be effective." I wouldn't actually be surprised if the US ended up passing some law restricting crypto to an approved list of backdoored schemes (surprised: no, dismayed: yes), forcing people into hiding their crypto in deniable ways. What some people don't seem to grasp is that no matter how much you outlaw certain math operations, whether or not the end users comply with those laws is ultimately up to them, and the terrorists simply won't comply.
To a man with a hammer, everything looks like a nail. To a man who only has words, everything looks like a soapbox.
I get that some of the controversy lately is about how well they stick to their mandate, but that doesn't change what the mandate is.
The NSA is part of the Department of Defense charged with foreign signals intelligence for national security purposes, its not a law enforcement agency. (And many of the tools it uses would be flagrantly unconstitutional if used for domestic law enforcement.)
Generally, blurring of the military and law enforcement roles is not a healthy thing; it may be good for order, but rarely for liberty.
It sounds impossible, of course, but that's just because we're not sure where these guys put their goals; some may be fighting for lack of another purpose in their life, while others may be motivated by personal loss or a thorough belief in the violent interpretation of Islam.
So what we really need to do is find a common thread among all the terrorists, and pull on it.
Read pretty much anything Amnesty International publishes, or even the right history books and you'll have all the evidence you ever need as to why privacy is important even when you think it isn't.
Once bad things start happening it's too late to change your mind. They already have what they need.
http://www.news.com.au/world/europe/islamic-state-tweeted-of...
It may indeed be that this kind of signals intelligence isn't actually helpful, but I don't think this is a very good argument either way. If there was a massive disruption of planned terrorist attacks, it is not useless just because there wasn't a complete elimination of terrorist attacks.
http://www.nytimes.com/2008/12/09/world/asia/09mumbai.html?_...
The issue the security forces _did_ have was in identifying where the calls were originating. The actual content was not encrypted though.