Then in 15 years, that $1M computation still costs $1000.
In 30 years, it can be done for one dollar.
Is that good or bad? I guess it depends on your threat model and what the data is worth.
Then in 15 years, that $1M computation still costs $1000.
In 30 years, it can be done for one dollar.
Is that good or bad? I guess it depends on your threat model and what the data is worth.
My actual thought was to have the secure enclave emit an encrypted copy of the key with a targeted key strength when presented with a request signed by Apple's key. It would require Apple's participation (or compromising Apple) but still require that the person spend a significant amount of money on the process.
By having it encrypt a key, you can make normal messages much stronger, such that you can't decrypt messages without the device in question (because the key can't be attacked directly, only the weakly encrypted version of the key when the secure enclave shares it). Further, because you can change how strong the SE emitted key is with each revision, you can have new phones always have a 10 year expected safety window (and even turn up the difficulty over time). In the case of a total compromise of Apple's storage, the attacker still has to spend significant funds to compromise any given phone -- so we'll only see targeted attacks. (That is, they might say, crack Bill Gates' phone, but are they really going to spend hundreds of thousands a pop to break the keys of random Starbucks workers? I'm honestly not super worried if Bill Gates has to spend a few thousand extra dollars every few years to protect his billions.)
But we're never going to get to discuss those kinds of scoping and cost-benefit tradeoffs if we don't engage in the process of shaping legislation in an open and honest way.
Full disclosure: I've been working on some similar ideas for a while. I'll be presenting a high-level pitch for the general concept at the USENIX Enigma conference in January [1]. Also hoping to have a full paper to share on https://eprint.iacr.org/ sometime later this month.
> But we're never going to get to discuss those kinds of scoping and cost-benefit tradeoffs if we don't engage in the process of shaping legislation in an open and honest way.
Agreed. And I'll actually take it one step farther. I think it might make sense for tech companies to adopt a very conservative version of this approach even without a government mandate.
Then the next time the DOJ rolls around to demand somebody turn over their private key (a la Lavabit), or to demand that somebody create a custom OS for them (Apple), we can say "No, we already gave you a way in, just pay the million dollars. Now bugger off and leave me alone."