CIA Director John Brennan Pretends Foreign Cryptography Doesn't Exist
schneier.com
schneier.com
Presumably Brennan refers to the big players, Apple, Google, Microsoft, Facebook, Intel (ME) et al. These companies are delivering crypto and/or hardware for the masses and could be subverted maybe with small short term effect.
Of course, the terrorists will switch. And Mr. Brennan knows that. This is the revealing part: It's about mass surveillance of people who are not terrorists by any means.
From the logo of the former Information Awareness Office (under the pyramid-with-eye, of course):
scientia est potentiaIt's a tradeoff, if you really believe that the government are motivated solely for your protection then of course you would allow them unlimited access into your personal life (as long as it was invisible to you, via your phone/computer, why would you care? They only use that information to help you. Think Doctor and seeing you naked, you trust that they don't care about seeing you naked, they just want to help you.)
If you're the director of the CIA maybe you really believe that the government having unlimited invasion of privacy is the correct way to keep everyone safe.
Now we could argue if the CIA works for the well being of the majority of US citizens, or to defend the obscure interests of some minority. And discuss the historical role of the CIA "fighting terrorism".
There are also the conspiracy type reasons but I think it's just a jobs program for white upper middle class men.
Also, the current obsession with machine learning is amplifying the problem. It's easy to misuse data analysis (e.g. overfitting the model until it says what you want it to say). Data is seen as valuable on it's own even if it isn't useful "now". This produces an effect similar to tulip-mania where everybody wants as much data as possible even if it isn't currently useful.
Finally, add in bad incentives where failure is rewarded with more contracts. As Mudge (Peiter Zatko) gave a very good description[1] of this problem which he called "game theory is a bitch". The solution is to make retaining data toxic with liability.
2) Control. This level of surveillance is key in the primary purpose of dissident control. This is why they are harping so much on "lone-wolf radicals" who are "radicalised by the internet". Because they want to say wolf so loud and so much that nobody has the chance to remind them about the constitution. This is also part of why you will see a huge increase in bad legislation written and passed by corrupted good ol boy house/senate. The internet is a threat to the global order due to it's decentralized nature and it's encouragement of anarchistic freedom of thought. The oligarchy are moving against the internet.
3) Fall-guys. The more sinister, grander chessboard for the supranational oligarchs is one of de-legitimizing American power and principles. I'll let you digest the details of this.
Always remember where the Company got it's start. Wall Street international lawyers. I'm pretty sure McCarthy, despite his unconstitutional antics, was actually on to something... but he just didn't aim high-enough in the chain. Corruption in the three-letters is top down.
http://www.maebrussell.com/Prouty/Harry%20Truman%27s%20CIA%2...
If massive financial fraud, corruption and widening inequality continue to get worse, there is going to be a lot of unrest in the western developed nations.
There's only so much shit people can take, so much of their shit that can be taken from them before they realise their entire financial system and wars waged are a giant ponzi scheme set up to suck resources from the many up to the few.
This shit happens in cycles. The upper echelons of society know this is coming again.
Well, combine that with knowing almost everything about everybody, and you can use the threat of charges or actually having them charged to deal with dissidents.
I once knew a gun rights' activist in the US. He has friends who were targeted this way by the Federal gov't. It's not just a theoretical thing.
Not only terrorists will switch. Everyone who has the option will switch. This is just another nail in the coffin for US technology companies.
I'm pretty sure that when this gets through, the non-US companies will be bought en-masse by US companies, like Microsoft did with Skype.
This might be difficult. With iOS, Android or Windows you have to trust the OS Vendor. I assume especially on iOS it might be difficult to supply any meaningful encryption at all if Apple decides to not supporting it.
There is a small but growing market for strong encryption. US companies will find themselves losing some amount of market share due to encryption restrictions. We already saw this once with the previous crypto wars. The U.S. thought that they could corner the market on good crypto and instead ended up losing a good portion of the market. The U.S. lost that war and they can totally lose this one for the same reason. We don't have a monopoly on good crypto in the U.S. and if they have their way we'll end up with only bad crypto.
What are the other nails in your opinion? To me it seems that the Silicon Valley is doing quite well.
There are Amazon employees who could be ordered by the US of A to break German law and extract data from customers at the Frankfurt site. In my judgment, the chance of their being prosecuted in Germany would be indistinguishable from 100%, so the real question is, has Amazon set up its organization such that people who are safely in the US can access such data.
I wonder if they already separate privileges between regions so one rogue employee can't take down all of their regions.
I'm glad I'm not the only one having that opinion about MS's acquisition of Skype. There's this article from July 2012, after the MS acquisition and before the Snowden leaks: https://www.washingtonpost.com/business/economy/skype-makes-...
> The FBI, whose officials have complained to Congress about the “going dark” problem, issued a statement Wednesday night saying it couldn’t comment on a particular company or service but that surveillance of conversations “requires review and approval by a court. It is used only in national security matters and to combat the most serious crimes.”
and most importantly
> But changes allowing police surveillance of online chats had been made since late last year, a knowledgeable industry official said Wednesday.
As an anecdote, just wanted to add that I live in an Eastern European country which has started to at least try to put up a fight against endemic corruption, with the help of some Western countries (i.e. the American and the UK ambassadors issuing worrying statements from time to time saying "corruption is bad" and meeting the head of the Anti-Corruption body).
Anyway, in a couple of anti-corruption cases investigated by our local anti-corruption prosecutors there were mentions of the authorities having access to the corrupt people's Skype conversations. Now, our NSA-like structure is no way as powerful as the real NSA, computationally speaking, so I don't see them breaking Skype's built-in encoding all by themselves, unless given that information on a silver plate by our friends from across the Atlantic Ocean. In exchange, we might help them with keeping nasty terrorists locked in an improptu prison, because that's how friends help each other out. (http://www.independent.co.uk/news/world/europe/inside-romani...)
Sounds like an "exit strategy" - TrueCrypt might even be an example of this.
The data shows you're wrong: lack of encryption does not prevent a significant number of people from using a product.
I'm mostly repeating what I said in https://news.ycombinator.com/item?id=10580829. Further down I had several links supporting the claim that even people who have a lot to gain from encryption will often not use it if it's not enabled by default.
I doubt that. I agree with you that many use unencrypted products though, so you have a point. However in almost all events I can remember the people committing terrorist acts where already known to at least some agencies. The agencies already drown in false positives. There is no indication that this will change. This strengthens my point: it is not about terrorists.
If even that level of prior knowledge is being ignored to push for yet more data (and more false positives) it becomes really hard to believe that this request is being made on the level.
They start cary about privacy if a picture of them naked is exposed or if somebody "pirate" their social accounts, then they will ask for someone to blame, and then go back to business as usual.
You can't expect the average population to be proactive on this.
I don't think technologists who ask users to do complicated things or blame them when things go wrong care about privacy Especially when large tech companies make bank by not standardizing things that should be fundamental rights in communication. To me a lot of this (but not everything) is banker level arrogance similar to pension funds or housing markets where "people should have known we were selling them crap".
But it's also that people value most things over privacy. To me, valuing the hability to express yourself on facebook over freedom is not a good bet. Just like valuing the hability to smoke over your health is not a good one.
I do understand why people do it. I have my share of similar self-destructive behaviours.
Still it's commun that important things like ecology, freedom, health are discarded over confort, convenience and quick rewards.
And privacy falls exactly in that category.
There are plenty of us that do care about it. Sure, they didn't have to do it, they still would have had plenty of users - but they chose to do it.
WhatsApp did it because they could do it in a way that was beneficial to them coupled quite likely with internal ideological reasons to roll it out. It's a positive spin that can be spun in the tech and non-tech media and could be coupled to improve their reputation as long as it's being run with the overall privacy / encryption debate stories. It also future proofs their platform that when they do come under direct fire they don't have to be seen as reactive.
To have a good grasp of what matters to the public, remember that Apple once did a whole ad campaing over the fact that the new iPhone could copy/paste. We mocked it. And the joke is on us, cause it worked briantly. This is what people cares about, and more over, this is what people knows about.
This isn't just a consumer encryption problem, this is the infosec community's fight in a nutshell. To put it simply: risk is invisible.
This is why projects such as the EFF's scorecard ( https://www.eff.org/secure-messaging-scorecard ) are incredibly important, possibly more-so than the actual code various applications implement. Because without public awareness there is no incentive for companies to implement non-trivial encryption features.
To look at it another way, we're fighting a public health battle here and we should borrow the lessons they've learned. You don't eradicate Dracunculiasis by assigning a doctor to look over every person's shoulder -- you educate people that {behavior} causes {invisible thing} causes {problem}. And once people know why, they're empowered to help themselves.
- if the problem take another form, they won't act;
- if the solution needs to be adapted, they won't do it;
- when the problem doesn't exist anymore, or your understanding of the problem is very different and you realize you fought the wrong battle, it will be impossible to realocate the ressource to it. Worst, you will get discriminated if you do.
All in all, education is good, but as long as people don't generally care about the way the world works, no matter the specifi subject, it will be fighting a never ending battle.
Sending a GnuPG encrypted email on the other hand is way too much to ask for the layperson.
Getting the message sent and successfully received is of more importance. It's better if its also encrypted. It's best if the messaging and encryption work together, seamlessly.
Maybe the NSA wants terrorists to switch, since it would make them stand out from the crowd, creating a much smaller pool of people (terrorists and crypto geeks) to watch.
I've got a side project about 10% complete that's a "stegonographic social overlay network". Fully client side JS steganographic encoding of images that are then uploaded to a choice of social media sites, and then subscribed to like RSS feeds. I think it's a cool concept.
Surely, just knowing which accounts are posting "suspicious" communications is valuable enough in and of itself.
But there's a lot of practical issues here. If you just add noise then it may raise suspicion merely by there being more noise than expected. So you may need to "move the existing noise around" or remove the existing noise which gets more problematic to do without leaving artifacts. And of course most of the noise may actually be following some patterns that means that the added/substituted noise must also correctly follow as not not raise suspicion.
[0] F. Beato, I. Ion, S. Capkun, M. Langheinrich, and B. P. (2013). For Some Eyes Only: Protecting Online Information Sharing. In ACM Conference on Data and Application Security and Privacy.
http://www.securitytube.net/video/14656?utm_source=feedburne...
He makes the point I was referring to at 12:53. The question starts about 11:45.
Calling it a crypto war is missing the point and the solution; in fact, the link you provide shows that the focus on crypto was a mistake.
I remember wanting an RSA t-shirt at the time (A t-shirt with the RSA algorithm on it, which is/was considered "munitions" - and not for export).
When do people turn to "companies" for encryption instead of using publicly available libraries or applications?
If end-to-end crypto is going to become the norm, it needs to be supported by the clients people have chosen to use - not by some obscure (to Joe Q. Average) app.
Brennan obviously knows this - it doesn't matter all that much if .01% of the web population use a client outside US control if the remaining 99.99% do use crippled, US-controlled apps.
Heck, it would probably save them lots of time, as being among the .01% would immediately flag you as a crank, terrorist or both.
I suppose SSH doesn't exist, and isn't from Finland either.
It is irrelevant if your cipher is sound and for all intents and purposes unbreakable if you, say, leave the key vulnerable to some side-channel attack.
> Obama and his secretary of state, John Kerry, have said that they don't use terms like "Islamic extremism" or "radical Islam" because they believe doing so would grant undeserved religious legitimacy to terrorist movements such as the Islamic State. Citing Islam as a factor risks framing counterterrorism as a war between the West and Islam, they have said.
> "They are not religious leaders -- they're terrorists," Obama said in February. "And we are not at war with Islam. We are at war with people who have perverted Islam."
http://www.nbcnews.com/storyline/orlando-nightclub-massacre/...
"The government is totally inept and can't be trusted, but if we granted it all these absurd powers to interpose it between a man and his religious beliefs, it won't at all be abused."