Why I Wrote PGP (1999)
philzimmermann.com
philzimmermann.com
The government initially claimed that using Clipper would be
voluntary, that no one would be forced to use it instead of
other types of cryptography. But the public reaction against
the Clipper chip was strong, stronger than the government
anticipated. The computer industry monolithically proclaimed
its opposition to using Clipper. FBI director Louis Freeh
responded to a question in a press conference in 1994 by saying
that if Clipper failed to gain public support, and FBI wiretaps
were shut out by non-government-controlled cryptography, his
office would have no choice but to seek legislative
relief. Later, in the aftermath of the Oklahoma City tragedy,
Mr. Freeh testified before the Senate Judiciary Committee that
public availability of strong cryptography must be curtailed by
the government (although no one had suggested that cryptography
was used by the bombers).
Sounds a bit like some of the conversations going on again, today. The last sentence in particular.The NYT seemed to be the source for that claim, and they quietly pulled that story. It's still repeated by media outlets elsewhere.
Not that it would change my opinion that government mandated crypto backdoors are a bad idea if they had.
That was the speculation I heard the other evening on NPR, by someone lobbying to put limits on private citizens' use of strong crypto.
Yes, french HUMINT has heavily infiltrated extremist organizations, and failed to prevent this attack. It does not mean that it was the use of encryption that allowed ISIS/extremist organizations to execute this attack on french soil.
The french secret service approach is fundamentally different from the US, as they historically rely less on SIGINT.
I am not sure where I read it, but in presume the number of prevented attack is in the thousands.
Then why don't we have thousands of prosecuted and convicted terrorists in our jails?
But I get your point. I need to check that article back then.
But they still happily installed only-now-legal "black boxes" at major providers to siphon data, don't you worry.
EDIT:
http://interviews.slashdot.org/story/01/09/24/162236/philip-...
I posted that link on another comment. But it addresses this one to some extent, he also mentions that the terrorist use of encryption was a significant issue in the 1990s. Still can't find the source for my original comment.
[0] http://kotaku.com/reporting-error-leads-to-speculation-that-...
This still rings very true to this day.
It would be really good if the NSAs of the world would just accept this and stop doing evil in their desperate attempt to survive.
Meta-data also bypasses codes, as you point out, by revealing the network of communication (who-with-who, when, and how often). So whether the communication/interaction is recorded and understandable or not becomes less important. In the case that it is recorded and understandable, excellent, even more intel. If it's not, they still have some material to work with.
At home, it turns out that it is pretty much impossible to stop a handful of people who have access to weapons, want to do as much damage as possible, and don't fear death. Increasing the surveillance on regular citizens will not change that.
The NSA, at least on the margin, does not care about convictions. Their mandate has nothing to do with law enforcement.
You're right that metadata is often much more operationally important than the message. But the DEA-style parallel-construction corruption is a hobby business for the NSA.
In the old days (Groupwise?) I found PGP easy to implement and use. Today I find it nearly impossible. Apparently I am not alone.
http://www.gaudior.net/alma/johnny.pdf
I have found S/MIME a bit easier to implement, but still much harder.
Is it a conspiracy to keep people from using crypto?
The problem now is the increasing number of centralised services, Google doesn't want to be storing encrypted emails within Gmail, because the content cannot be analysed for advertising purposes. And the same goes for other free email providers. It's still possible, but it is increasingly difficult.
That's why prz is doing Silent Circle now. VoIP crypto is actually easier, since you can rely on the fact that it's very difficult to convincingly forge someone's voice. Tie that to the crypto verification (via SAS) and it's easy for anyone to have a secure channel they're confident is actually secure.
Today I find it fairly difficult to implement with modern email systems and devices. Apparently I am not alone.
http://www.gaudior.net/alma/johnny.pdf
I have found S/MIME to be barely implementable. What can we do together to make it easier to use email encryption?
Has nobody told them that in reality, the problem is not encryption. Its poor foreign policy as well as poor international relations.
Thats my two cents for what its worth. Im no expert on foreign policy though although I do understand that the clear agenda in it is peace.
I know there are plenty of legitimate uses, but especially for the services that essentially bill themselves as secure and untraceable, you have to know at a certain point you've designed and built technology that is actively being used to hurt innocent people. For me it would be difficult to quantify if the amount of good is worth the all the bad people in the world.
anonymous money anonymous communication anonymous residence anonymous weapons
etc
Maybe we should make hands illegal since they do illegal things and you can only use your hand with a license from the smart-over-lord-government, right?
Or less dramatically, all technology and all constructions from home improvements to particle accelerators to hairspray to encrypted internet should pass review from the government and people can only work on what the government approves and use things they have licenses for.
--
Do you want to apply your same argument to car manufacturers? Cars can be used by kidnappers, bank robbers, rapists and murderers to flee crime scenes. So car manufacturers should stop producing cars because all of the good they are used for (visiting loved ones in the hospital, visiting your kids baseball game, going to work) isn't worth the carnage caused by the "bad people"?
It is so easy to do basic crypto if you're a terrorist - to them, whether xMessenger.app has it is a marginal usability difference. Giving terrorists a marginal usability difference, to many, is okay in exchange for securing the bulk of innocent communications from overreaching governments.
Zimmerman's response to being described as "overwhelmed with feelings of guilt" in article following 9/11 and the possibility that his encryption tools had been used by the plotters.
I wonder if anyone believes that the world would be better today if we didn't have airplanes, even if they are sometimes used to hurt innocent people.
[1] https://en.wikipedia.org/wiki/Alberto_Santos-Dumont#Death
[2] http://global.britannica.com/biography/Alberto-Santos-Dumont
That's a dangerous assumption in any situation (it's never a good idea to assume your opponent is stupid). We do not have a monopoly on mathematics; you never know who has read [1]الكتاب المختصر في حساب الجبر والمقابلة.
> I wonder how the people who wrote crypto software and provide secure messaging services feel about terrorists and other bad people using their products
Are you going to ask shoemakers the same question? I'm sure most terrorist prefer the advantage of durable shoes when fighting. While I don't have any numbers, I suspect durable shoes have helped more terrorists than encryption.
...
The problem is you're anthropomorphizing technology. Each new technology is neither good nor evil (or neutral). I'll let Feynman explain:
I think a power to do something is of value. Whether the result is a good
thing or a bad thing depends on how it is used, but the power is a value.
Once in Hawaii I was taken to see a Buddhist temple. In the temple a
man said, “I am going to tell you something that you will never forget.”
And then he said, “To every man is given the key to the gates of heaven.
The same key opens the gates of hell.”
And so it is with science. In a way it is a key to the gates of heaven,
and the same key opens the gates of hell, and we do not have any
instructions as to which is which gate. Shall we throw away the key
and never have a way to enter the gates of heaven? Or shall we struggle
with the problem of which is the best way to use the key? That is,
of course, a very serious question, but I think that we cannot deny
the value of the key to the gates of heaven.”
Encryption is just a tool, and like every tool that has ever been made it will occasionally be used jby bad people doing bad things.We keep learning more and more science and technology, and I don't think it is truly possible to stop that trend. I suggest we start finding ways to live with each other in the presence of technologies like encryption, because he problem is only going to get worse. We, as a species, are going to have a serious problem if we haven't learned that lesson by the time someone invents a way to make nuclear weapons with common household parts... or some unknown technology that is even worse.
[1] https://en.wikipedia.org/wiki/The_Compendious_Book_on_Calcul...
Bad people are people. They will do the exact same things that people in general do. They will use the exact same services that people in general use.
You know what has objectively led to much more innocent people being hurt than crypto? The Internet. Why aren't you out there guilt tripping all people who work on it?
So you basically get to choose: we stop all tools from being freely available and we open up all our communications to criminals and governments alike or we will have to take the good with the bad.
The people who wrote crypto software (and the people who built TOR and who operate anonymous proxy servers, VPN services and so on, built bitcoin, the internet, your browser and your mail client) all realize their work is 'dual use' and there is absolutely nothing that you can do about it so just let it go and accept it.
That same hammer that can pound in a nail in the hands of a carpenter (skilled or not) can be used to bludgeon someone to death. Should we ban hammers? How should the person who invented the hammer feel?
A tool I invented is used by some pretty bad people. I don't like it much. But I recognize that that same tool is also used for good, and that those good uses are probably the majority of them. It used to bother me, but I got over it, now I do think longer and harder about if there is any possible bad use of the stuff I make that I can make harder by designing the stuff I build in a different way. It doesn't always work out and people are pretty clever about finding alternate uses.