China issues new encryption import control
sanctionsnews.bakermckenzie.com
sanctionsnews.bakermckenzie.com
Added: A bit of searching revealed that this policy has been oversimplified to the point of nonsense in the linked article. A relevant article:
* https://www.hldataprotection.com/files/2019/11/The-Grand-Fin...
This seems to be more about checking to see if imported stuff that might affect national security has any backdoors.
Perhaps there is a rule that prevents someone in China from implementing any algorithm they want to implement with any number of bits they want to use, but that rule would hardly be an "import control", which is what the linked article is about.
Is there any well-defined, well-implemented cipher with a keysize of >256. AFAIR the AES is either 128 or 256.
That seems more (rightfully) careful than draconian..
Also FIPS 140-2 is outdated, please see FIPS 140-3.
While FB have many customers in China (much as Google do), I don't believe that they have any actual data centres, and they certainly don't have any (official) users.
On a side note, my own encryption software is now prohibited in China, but that hardly matters. I don't recall having any customer in China anyway.
A QC large and stable enough to run Grover's Algorithm would be a problem for symmetric keys and hashes smaller than about 192 bits. Most cryptographers recommend 256-bit or larger for a good margin of safety.
Asymmetric crypto is more complex story.
Sure log4j might have been recently patched, but it's not unrealistic to think that a nation-state has access to similar exploits.
This is not an argument for using shitty cryptography, but it is IMHO an argument for being more afraid of the implementation and the human beings using it than the crypto.
Unless we get quantum computers. Then what happens with AES-256?
I guess that's a nit against the post title, but I don't think it really clarifies much.
So they have domestic >256bit ciphers, and this restricts foreign equipment that uses >256bit ciphers. China also has an extensive domestic surveillance system, has lots of weird "national security" regulations (e.g. they use an obfuscated coordinate system for public maps, and IIRC it's illegal to use a GPS receiver for anything resembling mapping), and is also pretty protectionist.
What's the purpose of these regulations? Is it...
1. To further strengthen domestic surveillance by encouraging the use of (possibly compromised) domestic encryption equipment, or...
2. protect domestic industry by making certain technology imports difficult, or encourage foreign entities to buy Chinese technology for interoperability reasons, or...
3. discourage the domestic use of foreign equipment on national security grounds (e.g. foreign backdoors), or use interoperability or market-access concerns to weaken foreign equipment, or...
4. all of the above?
Those are not strong encryption standards. They have dual key escrow such that the government can backdoor the connection with their own key. Those are China made encryption standards for use primarily with government products but they are attempting to also force them on the general public.
> I don't see any clues stating that China forbids encryption technology with a key greater than 256 bits.
That is exactly what this results in, because your choice is either a government backdoored encryption method (which basically means it isn't encrypted at all) or a non-backdoored encryption method that is limited to a key size no greater than 256 bits.
I will note, with this over reliance on dual key escrow. If a foreign government were to steal that key through espionage without China's knowledge, it would let say the US government to backdoor China's own government communications.
Why would a government use key escrow for its own internal encryption (for actual important communications, as opposed to "retail" business functions like running garbage pickup operations)?
So to answer the question, the govt is not using key escrow for its own internal communications. Because it isn’t a monolith, and it’s not internal. The different fiefs need to be watched as much as anyone else.
Because governments (especially dictatorships) are most scared of their own members who can possibly seize power.
Submitted title was "China forbids data encryption using a key greater than 256 bits". Submitters: please follow the site guidelines, which ask "Please use the original title, unless it is misleading or linkbait; don't editorialize."
https://news.ycombinator.com/newsguidelines.html
If you want to say what you think is important about an article, that's fine, but do it by adding a comment to the thread. Then your view will be on a level playing field with everyone else's: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
In cryptanalysis it is normally assumed that the attacker knows the algorithm and encryption parameters aside the key.
I’m not interesting so not an issue for me, but I would also assume that they can break much more than this and wouldn’t actually reveal their limit in such a policy. Kind of like how your boss quadruples your time estimate. If their policy says nothing over 256, then they likely have capability for more.
But I’d expect that usually these pass phrases can be any length as they are all getting beaten out of us when needed.
There are several degrees of interest. Essentially they are interested in everyone trying to hide anything from them and they probably understand people of real danger to them will do their best to look ordinary and mediocre.
> If their policy says nothing over 256, then they likely have capability for more.
Sounds reasonable but breaking 512 obviously is much harder than 256 and will take significant time and resources they don't really want to waste. They will rather force you to reveal the key and only break 512+ if they can't easily reach you physically or identify you in the first place.
The final cyphertext of an encryption system should be indistinguishable from noise - the less random the output looks, the more information an attacker gains.
The output of your 512-bit encryption should therefore look like noise already. Converting noise to noise should therefore result, predictably, in more noise. So I'm going to say "no, you can't tell".
Proper encryption, maximum compression, and random bytes are all indistinguishable, as they have maximum entropy.
I only failed 9th grade three times, so feel free to correct me.
without additional information!
I can prove to you that you're seeing an encrypted message by giving you the decryption key, and I can prove to you that you're seeing compression by giving you the decompression algorithm.
However, there is no way to prove that random bytes are _really_ random.
well of course, because the opposite is true, any string of bytes can by XOR'd to something meaningful.
Instead of auditing the code/file format, it may be less error prone to just re-encrypt the entire file thereby hiding any metadata that the encryption program attaches.
And that is before you get into less than perfect encryption.
Things are banned, implicitly, only if you get caught, so I don't think this is a philosophical argument.
This can be done covertly or overtly, the former being plain old spying, the latter may be as simple as detaining the people involved and seizing computers (especially in China...).
Note that there's a huge difference between "until proven guilty" and "until considered suspect": suddenly obscurity cannot be shrugged off at all, quite the opposite.
Source: https://www.internetsociety.org/deploy360/tls/basics/
IIUC, AES-256 will be fine for the forseeable future, even with quantum computers. However, Curve25519 could fall relatively soon, depending on how rapidly quantum computing advances.
https://www.bankinfosecurity.com/report-china-to-target-encr...
... this is why forward secrecy is so important!
[1] Article does not specify encryption algorithms, so we should assume "any encryption algorithm can be broken" here.
[2] Contemporary SAT (CDCL) solvers accumulate constraints derived from problem being solved and it has been shown (proven, even) to exponentially speed up search process. Resulting algorithm is still exponential (2^O(N)), but exponentially faster than brute force (different constants).
I think this is about being able to target political dissidents for using encryption.
The context was that, although the agency was committed (hmm) to making cybersecurity better for US citizens, and thus helping the cryptography community to improve security, they felt OK exploiting weaknesses, so long as they thought it would be too difficult for others to do so too.
Sorry it's so hand-wavy, I'd love to find the article for my own sake, but busy/hard to google.
"One of the consequences of the second law of thermodynamics is that a certain amount of energy is necessary to represent information. To record a single bit by changing the state of a system requires an amount of energy no less than kT, where T is the absolute temperature of the system and k is the Boltzman constant. (Stick with me; the physics lesson is almost over.)
Given that k = 1.38×10-16 erg/°Kelvin, and that the ambient temperature of the universe is 3.2°Kelvin, an ideal computer running at 3.2°K would consume 4.4×10-16 ergs every time it set or cleared a bit. To run a computer any colder than the cosmic background radiation would require extra energy to run a heat pump.
Now, the annual energy output of our sun is about 1.21×1041 ergs. This is enough to power about 2.7×1056 single bit changes on our ideal computer; enough state changes to put a 187-bit counter through all its values. If we built a Dyson sphere around the sun and captured all its energy for 32 years, without any loss, we could power a computer to count up to 2192. Of course, it wouldn’t have the energy left over to perform any useful calculations with this counter.
But that’s just one star, and a measly one at that. A typical supernova releases something like 1051 ergs. (About a hundred times as much energy would be released in the form of neutrinos, but let them go for now.) If all of this energy could be channeled into a single orgy of computation, a 219-bit counter could be cycled through all of its states.
These numbers have nothing to do with the technology of the devices; they are the maximums that thermodynamics will allow. And they strongly imply that brute-force attacks against 256-bit keys will be infeasible until computers are built from something other than matter and occupy something other than space."[0]
[0]https://www.schneier.com/blog/archives/2009/09/the_doghouse_...
It's worth noting that if those Dyson spheres were quantum computers (and we ignored light-speed delays even within single spheres) you'd only need to count up to 2^128, not 2^256 to brute-force a 256-bit key. Still well outside the realm of possibility for anything smaller than a Dyson sphere.
So 256 can become 128.
What makes you say that, and what new information would indicate when "unlikely" had turned to "likely"?
I don't know. It's seems crazy that an algorithm wouldn't be affected at all by significant numerical increases.
ssh also would need permission?
If you meant "Cisco VPN gateway" then yes, and I wonder if China is actually going to prevent import of cryptography hardware that's known to be broken or backdoored.
Or put differently would 10x even have a noticeable performance / UI wise hit?
To save a click, relevant part from the PDF:
65 软件和信息技术服务业
编号:216501X
技术名称:深度伪造技术
控制要点:笔迹伪造技术、语音伪造技术、图片伪造技术、视频伪造技术、生物特征伪造技术以及其他伪造技术,伪造信息与被伪造信息相似度大于 70%
编号:216502X
技术名称:数据加密技术
控制要点:安全强度高于 256 位加密算法的加密技术
Next HN frontpage news idea: "China bans Deepfake"For anyone not familiar with this, 256-bit ECDSA is considered to have the same security as 3072-bit RSA. A lot of large shops use 2048-bit keys, and GPG folks think 4096 is "unnecessary"[1]. So 3072 is a more-than-decent strength by today's standards.
[1]: https://gnupg.org/faq/gnupg-faq.html#not_a_bad_idea_just_unn...