1. Insecure systems: government can get in, but so can hackers.
2. Secure systems: hackers can't get in, but neither can government.
It's a binary choice. Like being pregnant. You are, or you are not. There is no try.
1. Insecure systems: government can get in, but so can hackers.
2. Secure systems: hackers can't get in, but neither can government.
It's a binary choice. Like being pregnant. You are, or you are not. There is no try.
So your choices are:
1. Only the user has their key
2. Someone else has the user's key
If a company, law enforcement, or anybody else has a trove of everyone's keys, that trove will be extremely valuable to hackers, organized crime, domestic and foreign intelligence, etc, and it will be stolen. Whether we'll know it's been stolen is another question.
If we accept that mechanisms in common use, like warrantful search of physical belongings under the Fourth Amendment of the US Constitution, are legitimate and rightful functions of government, then warrantful key disclosure is a logical compromise that protects the individual's privacy, except when the government compels them with good cause to reveal information. Balancing this with protections against self-incrimination is one complication that's currently playing out.
- hardware key storage, iphone/TPM style
- mechanism for the manufacturer to authorise key release from a device
- important 1: this process should be irreversibly tamper-evident, such as IC "fuses" or one-time PROM. This should be permanently visible in the UI, so it cannot be applied invisibly.
- important 2: an obligation on the state to pay for replacement devices which have been compromised in the previous step but not used in court. This is to prevent it being routineised.
If nobody but me has the device encryption key, and my device is stolen, I can be sure that nobody will have access to whatever data it contains. If anybody else has the device encryption key, however, and the device is stolen, I can no longer know whether anybody else had access to the data, no matter how much tamper evidence the device has.
Brilliantly awful.
You realize, of course, that, of your two choices, the DOJ would probably choose the former (i.e. general insecurity).
Again, any government backdoor = security failure and there is no way around this.
What was interesting about Dual_EC_DRBG was that the default points served as sort of a secret master key to generator state leakage. It was harder than usual for another party to gain illicit access, leaving the vulnerability largely in the hands of the NSA.
It was some pretty interesting math, harder for unintended (by the NSA) people to take advantage of, and still, of course, a crippling vulnerability.
At this point, I'd be hard pressed to trust the NSA with anything security related, as they have demonstrated different priorities.
Or it gets left on a USB key in a taxi
Or it gets left on an un-scrubbed laptop that's put up for government auction.
Or any of the other which-ways that humans get around policy limitations that don't have technical barriers, or socially-engineered to get around the technical barriers.
The more important the key, the more sought after it will be by hackers, especially one which could theoretically decrypt an entire countries communications. It's only a matter of time.
[1] https://boingboing.net/2015/08/21/make-your-own-tsa-universa...
Now if you mandate everyone use a government key or escrow their key with the government there's now a single place to attack. Also this place is affected by government whims, staff pay freezes, cutbacks, layoffs. All you need is one disgruntled employee or contractor with access and you now have access to _everything_.
This isn’t some hypothetical scenario either http://time.com/106319/heres-what-chinese-hackers-actually-s...