Legal Controls on Extreme End-To-End Encryption
circleid.com
circleid.com
Who's writing this? Who is "Anthony Rutkowski, Principal, Netmagic Associates LLC"? Hoovers has some basic company information.[1] The company address is a tract house in Auburn, VA. There's a self-provided bio available:
(Anthony Rutkowski) has over 45 years of experience in Industry and regulatory affairs with focus on global cybersecurity, lawful interception, retained data, identity management and network forensics. Anthony has held key positions at VeriSign, SAIC, General Magic. Sprint International and GE. Additionally, he has held important posts and positions at FCC, ITU, ETSI, and OASIS.[2] So this is a guy from the wiretapping (er, "lawful intercept") industry.
But that organizational identification is deceptive. Yaana lists him as their "Executive VP of Standards & Regulatory Affairs". What's Yaana? Outsourced Big Brother. "Yaana is a leading global provider of a wide range of intelligent compliance solutions including lawful interception, accurate data retention, big-data search & disclosure, advanced security and application specific analytics."[3]
"Middlebox Security Protocol" is also a new phrase. That's listed as a work item at the European Telecommunications Standards Institute. (Not the IETF).[3] The proposer is listed as "RUTKOWSK". Hmm. No version is available for download. The summary is "Specify protocols to enable trusted, secure communication sessions between network endpoints and one or more middleboxes between them using encryption."
This seems to be plugging something called mcTLS.[4] Here's the actual paper.[5] It's a halfway reasonable idea for allowing middleboxes to work with encrypted streams, without giving them full access to the content. But it has built-in back doors, for "performance". See section 3.6 of[5]. It's also really complicated, and if done wrong, breaks end to end security. That may be Rutkowski's plan.
[1] http://www.hoovers.com/company-information/cs/company-profil...
[2] https://www.yaanatech.com/author/tony/
[3] https://www.yaanatech.com/about-us/
[4] https://portal.etsi.org/webapp/WorkProgram/Report_WorkItem.a...
[1] https://www.yaanatech.com/products/deepprobe-packet-inspecti...
It's one thing if the bank refuses to let the FBI into one of the lockboxes they use. It's another thing entirely if the bank says, "We don't have a key. Nothing we can do to help you." The latter is E2E encryption.
There's is simply encryption that works, and encryption that doesn't work.
With other types of encryption the math works (to various degrees) towards making brute-force decryption so time consuming that either the message would be worthless once it is decrypted, or the time horizon is otherwise beyond what is feasible. However, what math gives, math can also take away. Advances in cryptanalysis algorithms or sideband attacks could expose the message at any given point in the future. There may even be known attacks by three-letter agencies or other adversaries.
However, with a one time pad, given that the pad was truly randomly generated, was not exposed during distribution and is destroyed on each side upon encryption/decryption, the plaintext can NEVER be known.
Without an attacker with a time machine, the procedure is 100% airtight.
Not only will we deny others access to our secret content, we will render the metadata we create useless for any investigative purpose.
ÜUEE2EE is the future.
Sounds more like a geezer who's upset that browsers show warnings on his website rather than someone who knows what he's talking about.
>However, this balance seems unsatisfactory to encryption zealots who are hellbent on leading an extremist vanguard toward some nirvana of ultimate e2e encryption.
2. Utter blindness to the danger of making numbers and algorithms into contraband. As in despotic regimes, we would then have government chasing down users of prohibited software and ultimately the possessors of prohibited knowledge.
One thought I'll responsibly disclose to official authorities though, so network managers can efficiently manage on their networks, is: "Was this dude about to cry?"
Do we have an infinite, free supply of perfect moments and of smart, eloquent people?
hell no.
Thus we better have evidence at hand for when the stars align and we get those circumstances, lest they go wasted.