Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
rietta.com
rietta.com
You don't even have to program or use a computer to create these OTP solutions, for limited messages you could just flip a coin to create the OTP if necessary (although there are lots of more automated solutions available as well.)
Airgapped computers at both ends provide another way 'round restrictions for more sophisticated actors. Their backdoors won't be accessible (remotely.)
So taking away secure encryption from the rest of us is just security theatre; a destructive, narcissistic legislative exercise designed to make it look like the pompous powerful doing something when they're doing nothing of any real use while creating terrible risks.
This is why, I think, legislators have consistently ignoring logic and math from professionals such as the OP - they don't care. They know perfectly well they're pissing into the wind doing nothing useful; that it's all theatre; they just think the fallout is going to land on someone else's pants after they're out of office. But tech works (and fails) faster than that.
[Counterargument: if everything else is breakable, securely encrypted messages really stand out. One answer: But very short messages (in an unknown format) aren't generally breakable, anyway, and that's the likely case.]
Simplistic interpretations are the bane of security engineering, especially where human factors are involved.
I think of OTPs as a form of time-shifting. Think of it this way: if you and your correspondent have viable OTPs, that implies that, at some point in the past, you securely communicated that OTP. Since it is (at least) the length of a future message, you could have just passed a secure message then. Instead, you passed something that enables passing a secure message now.
I don't see a situation being frequent where you'd know the message weeks or months in advance of when you send it. If we follow your scheme, there's no encryption; we just meet up when we need to communicate. What if we're on opposite sides of the earth? If we had exchanged keys months earlier, this wouldn't be a problem.
The fact that your key material is the same size as the message means all your security is in the key, thus in your key distribution method. Among other problems, this means no rekeying without replicating your original hand-off - you can communicate exactly as many bits as your previously securely exchanged, no more.
...erm, isn't that the point?
Yes, with OTP you need to exchange keys and this shifts all of the security to key exchange, and while this wouldn't be a problem in other ciphers, it's a problem in OTP because of its other properties and shortfalls.
So at most I feel as though it's a security/convenience tradeoff; a tradeoff that's substantial or even dangerous in certain situations.
Hell, in most cases they wouldn't be detectable!
With so much random data flying around today, you could encode short messages in just about anything. comments on reddit or hn or one of the alternatives, image metadata, etc...
If you are looking to hide data on the scale of kilobytes, your options are basically unlimited.
Edit: On a 5 Mbps video stream, that could give you 5-50 kbps bandwidth.
The likelihood for a criminal to use a one time pad is extremely low. The likelihood of them having an encrypted cell phone with useful information is much higher. It would be tough to argue that a law against cell phone encryption wouldn't be effective for this purpose.
More valid criticism is its disproportionate impact on lawful uses.
Maybe that's the case right now, but how can you be so confident that these actors won't switch to OTP if such a law is enacted?
Encryption wasn't mainstream at all back then and, more crucially, digital surveillance was still in its infancy. The most popular chat app in the world right now implements full E2E encryption. Go back 10 years and having a "chat" consisted of sending your friends SMS messages.
Sure, there might be exceptions for high-level criminal conspiracies. But most crime isn't of that kind. For terrorist, I imagine there is a large spectrum of covert abilities.
How are you so confident that this was what happened? Do you have some concrete data and/or stats to back this statement? What if most criminals are using something like Signal? Besides, I personally wouldn't trust WhatsApp if I were partaking in illicit activities.
I think you're gravely underestimating the intelligence range and tech knowledge of 'criminals'.
Even more importantly, it's a power grab of the powerful (which mostly translates into "the rich", and vice versa) aiming to further dominate and manipulate the remaining population ("the 99%") in order to secure and increase their dominant situation.
> The Hampton's aren't a defensible position.
It's going to be no different for "crypto" solutions.
*Part of the FBI's job was to harrass anyone they considered a dissident or counter to their view of what US citizen should be or how they should behave. I doubt they changed at all. It's already documented and well known one of their favorite tactics was to break into people's homes while they're sleeping, or away, move things around... mess with their belongings or persons, etc... Expect it to be the same for crypto solutions "post quantum", if not already "pre quantum".
It seems increasingly apparent that recruitment and radicalisation are done in the open. After all, political speech is free speech.
Then people either self-radicalise (go on a murder spree without coordinating action with a larger group; e.g. many mass shooters), or they meet up in person. Lots of radicalised people go to the Middle East where they can't be surveilled by western security forces.
There's remarkably little evidence that terrorists are making routine use of strong encryption.
Even if they were, we Americans have a fundamental right to strong encryption, protected under the Second, Ninth & Tenth Amendments to the Constitution. I'd go further still, and argue that everyone in the world (who's not a prisoner or otherwise unfree) has a right to strong encryption.
If true, more reason to let the rest of us bank safely with it. There are ISIS manuals, and advice to use the best of the apps available.
Citizens lose.
Hardly ironic at all, since as long as someone stands to gain either money or power from doing so, they will simply do so under guise of the former.
Not ironies, just tactics.
I think it's a good analogy.
https://www.wired.com/2015/09/lockpickers-3-d-print-tsa-lugg...
The reason government doesn't have or need keys to every house, because no matter how many lock you put on your door, government (SWAT team, for example) can break in anyways, if deem necessary.
So for this reason alone if they truly want to... every house can be and will be open to them, no matter what.
Meanwhile here the locks are based on sophisticated math.. and that math is smarter or more complicated than the largest compute power they can get hold of.. hence make your virtual locks unbreakable. I think that's the whole issue they have here.
People put locks on their homes to keep criminals out. It does not matter if the government can break those locks, until the government itself begins to act like a criminal. At that point, it becomes necessary to build locks that even a government cannot break.
The Snowden alarum showed us all that a portion of the US government has become functionally indistinguishable from an organized crime ring. So, sorry Comey, but perhaps the FBI should focus for a while on investigating and burning out the criminal corruption within its own umbrella organization before we talk about maybe allowing it the power to intrude upon our personal lives at will, in the name of the greater good.
By the house metaphor, law enforcement is more like vampire legends. The vampire has the strength to batter down any door, but if it crosses the threshold without first being invited inside, it loses its power. Except the cop-vampire can also be invited in by a magistrate who issues a warrant.
And perhaps even that is too lenient. Maybe our warrants should be issued by a grand jury. Allowing them to be issued by a sole judge, or panel of judges, seems an invitation to erect secret, rubber-stamp courts like those used for FISA warrants. Maybe your secret keys should be protected by an M-of-N consensus algorithm using about 30 cryptographically-random peers. The government then has to convince a bunch of presumably reasonable strangers that it should be allowed access to your keys. Should be no problem if you're a dangerous criminal, but impossible if the state just wants to sniff around in your dirty drawers.
The government can already enter anybody's home upon receiving a warrant to do so. If you don't let them in, they can bust through a door or tear down a wall. We trust the government not to do this without court oversight. We trust courts to provide good and honest oversight. It is far from a perfect system, but we set up lots of human-level checks and balances to keep power distributed enough that this basically works.
The problem with strong encryption is that this is impossible. Even if there is a very good reason signed off by an honest court, it is impossible to get in. This breaks that human-level checks-and-balances system. What replaces it?
That is a lot more out in the open than a "back door". When the government bashes through the door at least it's in plain site and the house owner knows it's happening. But with encryption how would you know if the government has used their access?
Personally, I find that suggestion repugnant.
We also require people to document their finances to accurately tax them. You're presumed 'guilty until proven innocent' in the sense that you're taxed on income unless you can document that it's untaxable(a business expense). There are penalties for failing to document things. What's wrong with requiring you to document your private keys, along with your receipts?
If you sell apples under the name "Loving Apples", you have to pay your state government to register that name. You can be fined for not registering your name, and your bank or other financial provider will want to see the government approval document. You could have the government maintain a central registry of all private keys, and make it a crime to encrypt a document with a key not documented in a state agency.
If you receive a document that is encrypted, you may be further required to tell the government who gave it to you, to ensure compliance with the encryption law; similar to how giving someone money requires you to tell the government about the transaction for compliance with tax law.
Which direction of the implication you take is a matter of preference. People who agree with giving the government full power(and trust them not to abuse it) or who agree with not giving the government any of this power are both logically consistent with my argument.
I'm only attempting to rule out people who are okay with all of the existing documentation requirements, but balk at documenting their encryption keys.
What if a hacker plants "secret encrypted documents" on your computer, and then the government demands that you produce a key for them? This situation has allegedly already played out with child porn[0], and planting drugs is not unheard of by unscrupulous police officers[1]. Essentially, you're back at the issue GP describes - we don't trust government employees with this much power over our lives.
[0] - https://www.nytimes.com/2016/12/09/world/europe/vladimir-put...
[1] - https://www.innocenceproject.org/leaked-documents-show-alaba...
That's exactly what my (UK) government has done.
It's a horrific idea.
If your personal escrow key is government mandated, and well-protected, that prevents the issue of you forgetting passwords (Estonia already has something like this). It also fully ensures that the government accessing escrowed keys requires you being informed.
I still don't support this plan, but it is the best thing I've seen.
Clearly the solution is to require every paper shredder to be equipped with a camera to scan documents and upload them to cloud.gov before shredding. Of course, nobody would be authorized to look at the data without a warrant, and we should trust that nobody working for the government would ever break this law.
Imagine if the government busted down a quarter of all doors in the country - that's a lot of industrial-scale police work, and it's very visible to all citizens. On the other hand, the government can tap half of all phones in the country, or intercept half of all emails sent by US residents, and we're not even legally allowed to know it happened, so we can't even argue against it in a public court of law.
Atomic-grade offense requires atomic-grade defense. We will have un-breakable encryption, or we will be crushed by secret intelligence agencies with immense power and no public accountability. It's a whole new game.
Anyway, I'm not too worried, strong encryption is open source and widely available already (even if not used in nearly all the circumstances it should be yet). This cat isn't going back in the bag.
The first, as others have mentioned, is how easy it is to use an escrowed key without detection. The second is the fact that strong encryption remains available. This means you need to outlaw strong encryption, at which point steganography comes up to hide the encryption. Finally, key-escrow is a massive increase of the attack surface of encryption. It's almost as if the government mandates we all use TSA locks on our doors.
Another line of argument is to emphasize the extent that our digital economy and national security rely on strong encryption. If you outlaw it, then all of our online banking and shopping, corporate and government secrets, and more are vulnerable to hackers and foreign governments. And just as the conservative gun advocacy argument goes, outlawing it won't necessarily take encryption out of the hands of criminals, only law-abiding citizens.
Black bag operations have always existed, and will always exist, despite legislation or other rule-making to the contrary.
The 'because terrorism' excuse falls a bit flat with me.
Thought experiment: how hard would it be for a terrorist organization with access to 100's of millions of dollars (eg. ISIS) to come up with a secure communications scheme? One time pad. A reasonable cipher that hasn't had any 'help' during development. Even run an encrypted channel over a backdoored product. I'm sure many of us could come up with something in a day (with decryption over an airgap). How about a hostile government with multi-billion dollar budgets (and who have been using OTP already for decades).
Is this about terrorists, or is this about citizens? My bet is on the latter.
https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Crypto_Wars
My feelings about them (The Clintons) have indeed declined over the years. I mostly have huge respect for Al Gore. But my personal feelings have absolutely nothing do to with their material involvement with the Clipper Chip. Nor do I care when it started. They all carried the baton of government key escrow which is not something I am going to forget. It is a grave mistake to not hold people accountable for their actions, to not take a stand while the bureaucracy pushes you along with the current.
My point was simply that while, yes, Bill Clinton ultimately owns his official actions, it's naive to ignore the massive weight of the entire U.S. intelligence apparatus, especially coming off of the Cold War footing, on a subject where he was hearing from a lot of experts in government and business saying this was a good move.
When presenting the work, I had a chance to ask ordinary people, and they all pretty much agreed that the government should be able to "break" encryption with a warrant.
This is a scary prospect, and I feel that educating citizens as well as the government is important.
In theory, being able to break encryption with a warrant is exactly the right scenario.
In practice, if you an break it with a warrant, someone else can break it without a warrant and can do so without your knowledge.
[1] https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
Our hardware on the other hand... is probably backdoored already.
It's unrealistic to think that if there is a means for access by the government, that foreign enemies and criminal organizations won't be able to access it, too, and cause havoc.
Right now they want to un-insure 24mil people, re-introduce the whole pre-existing condition scam.
you really think a ruling class that has no qualms being "pro-life" while denying young mothers healthcare will care about your nerd bullshit?
Probabaly the ones supportive of backdoors are as you said, simply "trusting" of the current leader they voted for but would immediately oppose the same policy coming from a Democrat.
...which is the exact impulse and logic that should push all partisans to distrust government power to snoop on communications. There will always be someone in charge somewhere that you don't trust.
They didn't realize that one day they would need the second amendment to protect their right to such "weapons".
-- this post is a poor paraphrase of a comic I saw once.
Edit: turns out it's a relevant xkcd™ https://m.xkcd.com/504/
Regardless, I derive emotional sustenance from your optimism.
Tim Cook's "software equivalent of cancer" is an example of an effective dumbed down take on it, but it need not be the last one. The more ways the point can be re-worded concisely so that lay people will understand it, the better.
I think one of RSA argued this, basically "Do you really think the government will want to review and approve everything on the app store?"
Forcing big players to divulge data, making accused people decrypt their devices -- those are things the government could do. Encryption per se isn't in any danger.
But the arguments against this aren't that difficult... so I have to guess it's the evil. Power corrupts.
https://www.schneier.com/blog/archives/2017/03/new_paper_on_...
repetition error.
> The cybersecurity threats that face our nation are very important to my wife and I.
"to my wife and me"
I went to the store.
My wife and I went to the store.
They loved me.
They loved my wife and me.
I recall from my early public education that my peers and I were all taught incorrectly. They told me and my classmates to use "I" rather than "me" in all compound nouns, rather than to use the correct pronoun. This is burned in my memory. It happened. Don't try to gaslight it. At least one teacher taught every last one of their students the wrong grammar.
For instance, this would be correct. "She and I [1] went to the theater, and the ticket-agent told her and me [2] that matinee prices ended at 4 PM." Countless fools would put "her and I" in position [2], sparking a righteous, impotent rage in my soul.
Also, it's "I know we English speakers can't speak...". Try taking out the descriptive. "I know us can't speak..." versus "I know we can't speak..." Select the correct pronoun, then put the descriptor back in.
but please, for the love of god, proofread your writing!
Joking aside, unfortunately it takes deep problems to motivate people/the US to change. It'll swing this way, and there will be dramatic consequences. Only then will things swing back the other way.
It's too bad there isn't any balance here -- it does make sense in many situations that the police/courts should be able to gain access to information. But encryption doesn't care about the situation. Encryption doesn't care who you are. Encryption has no contextual morales of its own.
If data had physical weight, where things that were important we're really hard to steal, then it'd function like the real world. But data does not, and it's too easy to download gigs of data one should never have access to. It's very difficult to gain a middle ground as suggested by Pelosi. I don't know if she understands that.
My HN "bio" isn't a blog post. I dont start my communication that way.
Also, data does have "weight". The more data that you move, the more obvious the movement is. And the more you obfuscate the connection, the less bandwidth you have.
But yes, Pelosi is clueless.
Joking aside, I guess you're saying that leading with credentials in an article is unnecessary if that article is relatively short and you've got a bio blurb at the bottom of the page?
Also, I think it's reasonable these days to write hardcopy letters that look more like websites -- multiple columns, a bio section, etc. Don't restrict yourself to obsolete and arbitrary etiquette.
Empirical is no more, we're at ginger.io now. Haven't bothered updating various bits.