And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies?
I mean -- "there is not a gradient"? ...what do you call changing key size?
Ed:
I'd like the people downvoting to explain how changing the keysize isn't a gradient of security. (Hint: You can't, because it is.)
key size is not a measure of security. It is a measure of how /long/ we intend the key to be secure.
More explicitly: Key size does not exist of the gradient of protocol security. We know how long a key takes to break given current technology and algorithms. We choose a key size to render the time to break infeasible against our prediction of state of the art some amount of time in the future. If there's a gradient, the gradient isn't "how secure it is", its "how long it will remain secure".
Hence any policy that endeavours to control the "strength" of encryption through controls over key length is /necessarily/ requiring an insecure key size.
It can be put this simply: How small must the key be to allow it to be "good enough" for the DoJ? Would they accept a continuous 5 years on a 10000 gpus? Noting of course that in 18-24 months that key size will now only require 2.5 years, then 1.25, 7 months, 3 months...
Of course I'm sure 5 years and millions of dollars will be "unreasonable", so it would need to take less time, and cost less.
The problem with what others have posited as "money based encryption" easily scales up with AWS, Azure, GCE, and private clouds. Even individuals can buy a large cloud for 1h for cheap and crack with rainbow tables or such.
But for a real safe, I can go get a thermic lance. It nicely cuts inside most safes. Or I can use a bunch of liquid nitrogen and freeze-shatter it.
These vastly speed up even dumb attacks against the passwords. (Not even keys.)
Edit:
You're also completely eliding that security is probabilistic -- they might just guess our key on the first try. We can only discuss it as the expected amount of computation to figure out our key on average. That expected amount has a gradient along keysize.
Anything other than deriving the plaintext of encrypted data alone would mean the protocol was insecure.
That said, I am coming to agree with you in terms of trying to explain to people who don't write crypto code that saying key size is gradient of security is probably the most sensible thing.
I still disagree with you on the actual statement :D
That said most of the demands made by DoJ aren't for reduced key size, they're for variations of key /escrow/: literally breaking the security model of crypto entirely.
So maybe I could be more specific: there is no such thing as an almost secure protocol.
The key (ha!) result of this recognition is that all secure protocols have been moving to some variant of ephemeral keys. Specifically to deal with the problem of all static keys eventually becoming insecure.
Yes, we use keys up the gradient of security that key size represents as attacks become more powerful. The reason we don't use the more secure keys in the first place isn't that 2048b keys weren't always more secure than 1024b keys -- it's just that we didn't (for most purposes) need to be that secure, and so we choose an appropriate spot on the gradient for our cost-benefit analysis.
Pretending that's not a gradient of security is simply dishonest.
> That said most of the demands made by DoJ aren't for reduced key size, they're for variations of key /escrow/: literally breaking the security model of crypto entirely.
That's missing the plot for the details: the DoJ wants a method by which they can break into digital safes in a manner similar to physical safes. Their proposal is key escrow, but that's partly because technologists didn't suggest a better way when the DoJ simply asked to get it done with little guidance. So they made a specific ask. And it sucks -- because they're not technologists. Everyone knows it, but the DoJ isn't inclined to let people flat out refuse.
Pretending that there aren't technical solutions with transparent ruses -- like there aren't gradients of security -- are how we got to lawyers demanding technical features.
I don't disagree with you that we should use secure protocols, I'm just saying we need to hold ourselves accountable for honest and strong arguments, not ruses.
The one you end on -- that using ephemeral keys is fundamentally a stronger algorithm that doesn't work well with long term taps -- is a strong argument. Much better than things like "there aren't security gradients" -- partly because they're actually true.
I've spent years of my life working on making it so people don't have to risk their information whenever it touches a computer.
Key length is a measure of how long you want the key to be secure. Also note that we tried that once in the past: DES had a deliberately crippled key space. That was resulting in terrible security bugs only a few years ago.
I keep seeing this statement being made whenever this topic comes up. Yet I've never seen a formal impossibility result.
It's amazing. Cryptographers are the smartest people in the world when it comes to solving most problems. (Just ask them!)
But seriously, some of the stuff they can do is like magic. Things that, intuitively, sound like they should be impossible. For example:
Zero knowledge proofs? Can do.
Oblivious transfer? Sure thing.
Fully homomorphic encryption? Coming right up!
But then the DOJ says they want some way to investigate the Texas shooter's phone without also getting access to everyone else's data. And suddenly the whole community is like "I dunno man, aren't you just asking me to 'nerd harder'? ¯\_(ツ)_/¯ lololol"
It was cute at first, but if we keep it up we're going to start burning through our credibility real soon.
It isn't that there are no levels of security, it's that you can't be at two separate levels at the same time. There is no overlap.
Mandating 512-bit RSA is useless because the government could break it but so can everybody else. Allowing 4096-bit RSA wouldn't allow the government to break it.
There is no middle ground. Mandating something like 1024-bit RSA, which is considered weak but nobody has actually broken it yet, is worse than useless. The FBI probably couldn't break it today and some hackers will probably break it tomorrow, so it would only leave people at risk without providing the government access.
What do you say to DUAL_EC_DRBG, which seems to be precisely that "separate levels" of security you claim is impossible?
The same applies to the recently published DUHK attack: once the hardcoded key is known, the whole thing gets broken, showing that the security level was only as strong as the weaker key.
Just like in traditional encryption scenarios, your personal key remaining secret is a part of the assumption. That there are now two secret keys doesn't alter the analysis substantially.
Of course it does. At best it doubles the risk of key compromise, but it's really much worse than that.
A master key isn't like a normal key. If you compromise Alice and Bob's key, you can spy on Alice and Bob, but not Alice and Carol and definitely not Carol and Dan.
The existence of a master key is a massive security risk. Alice and Bob's key is worth say $5000. The value of stealing it generally isn't worth the effort. Nobody sends Mossad to spy on every plain old Alice and Bob.
A master key for everything is worth trillions of dollars. Every government and crime family would throw everything they have at stealing it, and many of them would succeed. Spetsnaz units and foreign intelligence operatives would fall out of the sky. Crime bosses would pay multi-million dollar bribes and still turn a huge profit.
And from there it would leak.
It's a completely different level of risk. Orders of magnitude worse. And it implies a prohibition on forward secrecy. So when it leaks, Armageddon.
It's plausible that the government can permanently keep a key to every lock secure against every attacker?
That is such a ridiculous claim that just skipping right to "no, that's impossible" is a completely reasonable thing to do. But we can do the analysis if you really want to.
Look at the other things the government has tried really hard to protect. Nuclear secrets? Nope.
https://en.wikipedia.org/wiki/Atomic_spies
The government has actually lost hydrogen bombs on multiple separate occasions. Not the secrets, the actual live thermonuclear weapons. The things that one of which can turn all of D.C. into radioactive glass.
What about all the sensitive information about the people with security clearances?
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
Incredibly dangerous biological materials ("arguably the most deadly disease ever to affect mankind")?
https://www.npr.org/2014/07/08/329884145/in-a-lab-store-room...
Classified information in general? The list of violations is too long to even enumerate.
And this is what happens when the thing they're supposed to be protecting doesn't have incomprehensibly large commercial value on the black market.
There is no question that they are not capable of doing this.
You can devise a defense against any attack you can think of, but for a trillion dollar prize someone will find an attack you didn't think of.
And that's the problem. You can say the words "secured arbitrarily well" but in practice you've created a room with the keys to the world in it and your first indication that your security was insufficient is an incalculable catastrophe.
It's like creating a button that gives anyone who presses it three wishes but destroys North America. "Don't worry, we'll put some guards around it" doesn't cut it. Some things need to just not exist.
It doesn't, and that's the point. There are no "separate levels" of security. The attacker only has to break one of the keys, whichever is the weakest one. The "security level" of the whole system is the "security level" of its least secure part.
Security is a process not a state. You cant say that something is "secure", there is more secure and less secure. What the politicians are saying is that your individual security is not as important as their responsibility in security policy.
Security + Politics = Every shade of grey conceivable and then some not yet conceived.
But as a practical matter, I think we will do more to protect privacy and security by engaging with the process and honestly addressing their concerns so we can strike a balance between conflicting societal needs than we'll do with hardline stances based on inaccuracies.
I think pretty rightly a lot of tech people got told off by the political process for misrepresenting what was possible and how technology worked in an effort to not have to obey social structures. I don't think most of us liked that (I sure didn't!), but we're not going to have everything our way (and especially not by lying or throwing tantrums). I mean, if I were a senator, I'd be thinking "So, they can secure a ledger with floating cryptographic difficulty when they want to make money, but a solution for national security is impossible? Yeah, fuck these guys." There just hasn't been the kind of open, honest discussion around the topic that would satisfy their concerns.
And the key to having some of it our way is explaining why that issue is paramount to have our way and honestly engaging in the process to make it happen. Politics is a game of compromise and negotiation -- the government is almost certainly not only willing to concede some of the things on the FBI wishlist if better alternatives are put forward, but actually is interested in doing so.
Everyone knows professional investigators ask for too much, but if no one else is putting forward honest suggestions -- what choice do politicians have?
The extra key could be set up so that it requires X out of Y keys. Each key could be owned by different organizations, like the state govt, FBI, Courts, Nonprofit oversight committees, citizens oversight of police, and such. This could provide a balance of security and privacy, and allow in extreme circumstances a forced break of encryption.
(Ideally, it would require many orgs that are normally in opposition to agree. It would not be "state govt", "FBI", "CIA" like the old Clipper Chip.)
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized." 4th Amendment, Bill of Rights, US Constitution
That's a balance, of between "Get off my lawn", and "I affirm I saw X illegal thing and I swear it in front of a judge, and the judge agreed."
Now, I don't trust some bureaucratic department to honor the constitution. And from the sounds of it, neither do you. Which is why I was keeping in mind of having an antagonist based key-holding scheme which would require a multitude of people to unlock before the data would be unsealed. To me, that does re-enable the balance set forth in the Constitution, namely the 4th Amendment to the Bill of Rights.
What should be considered part of one's mind is not clear, but what is clear is that whatever the mind is, no one should be able to pry without consent.
Not commenting on what the constitution actually means, just saying what I think it should mean.
At some point we will have devices actually embedded in our bodies collecting every thought. Should those not be considered part of us and thus protected under the 5th amendment?
There's no reason it shouldn't require expense and physical breaking to gain entry, just because it's digital (and I think that this scheme gains legal protection because of such features).
By actually discussing it, instead of hiding behind lies like "there are no security gradients", we can talk about systems where it would require X amount of compute effort to break an encrypted key held in escrow for Y years at Z expense to reveal the key. (I was actually thinking about using a hash chain to timelock the key, since we have a pretty good idea of how hard it is to sequentially hash.)
I don't think most of us are against the government being able to see individual, targeted encrypted drives -- I think we object to the ability to transparently compromise all systems.
I still stand by the point of having a consortium of opposing interests as a combined group (or supermajority) to override an encryption. I think of it as a strong version of checks and balances.
In that case, if members are also hidden, it doesn't matter how many dollars are thrown at the problem. Unless you have peoples' willful intent, the escrow doesn't work.
Then in 15 years, that $1M computation still costs $1000.
In 30 years, it can be done for one dollar.
Is that good or bad? I guess it depends on your threat model and what the data is worth.
My actual thought was to have the secure enclave emit an encrypted copy of the key with a targeted key strength when presented with a request signed by Apple's key. It would require Apple's participation (or compromising Apple) but still require that the person spend a significant amount of money on the process.
By having it encrypt a key, you can make normal messages much stronger, such that you can't decrypt messages without the device in question (because the key can't be attacked directly, only the weakly encrypted version of the key when the secure enclave shares it). Further, because you can change how strong the SE emitted key is with each revision, you can have new phones always have a 10 year expected safety window (and even turn up the difficulty over time). In the case of a total compromise of Apple's storage, the attacker still has to spend significant funds to compromise any given phone -- so we'll only see targeted attacks. (That is, they might say, crack Bill Gates' phone, but are they really going to spend hundreds of thousands a pop to break the keys of random Starbucks workers? I'm honestly not super worried if Bill Gates has to spend a few thousand extra dollars every few years to protect his billions.)
But we're never going to get to discuss those kinds of scoping and cost-benefit tradeoffs if we don't engage in the process of shaping legislation in an open and honest way.
Full disclosure: I've been working on some similar ideas for a while. I'll be presenting a high-level pitch for the general concept at the USENIX Enigma conference in January [1]. Also hoping to have a full paper to share on https://eprint.iacr.org/ sometime later this month.
> But we're never going to get to discuss those kinds of scoping and cost-benefit tradeoffs if we don't engage in the process of shaping legislation in an open and honest way.
Agreed. And I'll actually take it one step farther. I think it might make sense for tech companies to adopt a very conservative version of this approach even without a government mandate.
Then the next time the DOJ rolls around to demand somebody turn over their private key (a la Lavabit), or to demand that somebody create a custom OS for them (Apple), we can say "No, we already gave you a way in, just pay the million dollars. Now bugger off and leave me alone."
That's kind of the point of end to end encryption. Note that on osx/ios that same e2e encryption protects credit card and password data.
Saying company X should store their keys is the same as saying "Company X should paint a giant target on their servers that have to be weakly protected to appease requests from agency Y". The solution to unending breaches of user data is to not be able to decrypt it, that only way to achieve that is to never have the keys.
The bit I take issue with here is that breakable encryption is absolutely necessary for law enforcement to do its job. No. It makes it _easier_ for them to do their job, at the expense of everyone else's security. There are usually other ways to get a conviction other than being able to decrypt a criminal's data. And if in some instances there isn't, I'm ok with that. I value freedom and privacy higher.
In cryptography there is one information theoretical secure scheme: The one time pad. But even that relies on circumstances to keep it secure. Without limitations you can not say no one can break it, because obtaining the key material might still be possible.
That leaves us with most other schemes. They are computationally secure. This implies that the security of the system depends on the computational power of the attacker. So a system can only be secure for a class of attackers and to a certain extent.
If you apply a binary clssification of secure insecure as you proposed it someone can get in", most systems today, if not all, are insecure.
I'd say that's a fair assessment.
You may think you're taking a strong stance for privacy and freedom. But anyone who isn't already in your corner, and sees reality through similarly myopic lenses, will only be put off by such blatantly obvious falsehoods.
Technologist tend to follow some variation of the "law of the jungle": disagree with the FED's policies? Create a currency that follows no policy except the one dictated by its algorithm! In this endeavor, they commit two mistakes:
(a) Confusing what is with what ought: the inability to do something, sometimes almost true (monetary policy for bitcoin), sometimes obviously false (two-key encryption), is used as an argument to shut down debate.
(b) The refusal to meaningfully engage with any argument that is not narrowly about tech. They believe any such arguments aren't "objective", and that they can sidestep it with technology. Yet this fails to see that of course every algorithm or other technology is the child of ideology by just another name.
In doing so, technologists usurp powers that aren't theirs: if the gold standard is the better monetary policy, you're supposed convince enough people to get Rand Paul elected president. Yes, politics is deeply frustrating, because everyone is just wrong, all the time. But it's still a much better decision-making process than five techbros in china noticing their hashrate has made them king.