The more taxes we will all have to pay. :)
"I used to wonder when the cyberpunk future was going to get here. Then I realized we're living in it"
So, they will keep it until they can figure out its content ? Fine, so why make it easy on them by giving them plain content from minute 0 ?
I don't see why would anyone able to encrypt his/her data not to.
The problem is not about them keeping encrypted data but about them labeling you as a potential bad guy once you have encrypted data.
"Deine papiere bitte" on the streets is not that far away. Actually what we have today is worse, self-censorship and suspension of rights.
Yup. It is practically here, license plate scanners, NSA metadata with location, constant surveillance. The only thing missing is automatic enforcement of the many petty crimes we commit each day (but you will be threatened with them if the gov't needs you to inform against someone, or simply wants you to plead guilty to some crime).
We already have this. Red light cameras.
Does it dawn on anyone else that our government has and will continue to have turned on its own people. Let that sink in for a couple seconds. The the majority of the legislature instituted it and the executive has been executing it with impunity.
It is already bad enough just based on principle as to what is being done to the rest of the world, but our own government has turned on its own people. Just like Europe didn't quite understand what it was getting into, let's say late ~1910 and again in ~1930, because what was to come was so beyond their experience and comprehension; we are making the same mistake and not quite comprehending the ramifications and consequences that will wash over us.
No one wants to acknowledge it, but the enemy is within. Tyranny is spreading the way it does and will not be apparent until it is too late.
Not encrypting to stay secure is just plain fucking stupid. If you don't encrypt they can read your shit anyways. Plus "reasonably believed to contain secret meaning" in all likelihood means "whatever the fuck we want".
As someone else already noted: There's strength in numbers. Let's just encrypt everything and have those fuckers deal with humongous amounts of data, most of which will be completely useless. Shit, if you're inclined to do so let some piece of software run all day that just produces encrypted gibberish and sends it off to random recipients.
edit: yeah, I was talking out my ass, get over it. I still think it's imprudent to assume that encrypted files may never be compromised in the future.
Edit: It would probably just be easier at that point to ban encryption going forward.
You couldn't even increment every position of a 256-bit key using the energy our Sun could provide, let alone brute force 256-bit AES.
> Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on. Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it.
You probably don't need to use 3 cyphers. Just make sure you're storing your private key somewhere safe.
s/Moore's Law/technological advance and\/or advances in cryptanalysis/
Just so you know; the reasoning behind huge NSA camp they are building in Utah is not because huge camps are cool, but because someone at decisions level was presented with average number of data an average citizen of us soil digest per day, and that number was overwhelming.
So, if we all encrypt everything, 2 things gonna happen:
Either they will ask to quadruple their funding and build 10 more Utah-type camps "because we need more storage and CPU resources to catch those pesky terrorist", or
The problem will be so huge for the government that it will ban usage of PGP/encrypting. The light version of banning would be, for example: extra tax if you encrypt your data. I can see it easily reasoned: terrorist use PGP encryption so the government uses lots of resources (that equals to money) to crack those down so in order to keep their operation running they need extra money. Of course if you do not use PGP you don't have to pay that tax. If you do use PGP, you are required to pay it. Simple checkbox on your tax form. Now, if they every catch you with some encrypted files that they can reasonably say belongs to you (just like the can/cannot tell the child porn files belong to you [they can always upload them themselves]), you will be charge with a severe fine or imprisonment up to 25 years for aiding terrorist [by not supporting NSA Encryption Unit financially -- remember Bush motto? you not with us, you with terrorist].
So, long story short. Just pissing them off and encrypting everything will not fix the issue. It will just give them more reasons to ask for more funding. And they will get them.
Does a system like that exist? A constant stream of random bytes, some of it real information, most of it not. Only those intended to be the recipient know where to look.
I agree, this may not be true in practice.
[Presumably, NSA is not collecting all sources of random data?]
I wanted to like this proposal, but then I realized these encrypted spams have to be sent somewhere. Any ethical target would be too easy for "the bad guys" to filter. Oh well.
My public key is here: http://sho.ch/alexgraul.publickey and on the gpg keyserver, where's yours?
but maybe this is a different thing conceptually i think i would call that a stamp or a seal ..sort of like a wax imprint of a key
Seriously, the are few situations where someone's actually going to want to post their private key to the internet - at least if they understand what it is - so what are we imaging that they're doing with it that they need to know about it in the first place?
You're probably going to want them to have a backup, but you can have them make a backup without having them understand the difference - you just have your program back up a folder structure that the private key is hidden somewhere in and only make the public one obvious. Make them aware that if they don't backup they won't be able to access their emails - should the worst happen - but don't tell them why. Someone with a push-button understanding of computer... they just don't really need to know why.
... -sigh-
I almost wonder whether it wouldn't be easier to market public-private key crypto as a packaged solution. Buy an encrypted email address kind of thing. Send people a physical token they mentally associate with that email address and tell them not to lose it.
GPG has a sucky API and crazy CLI. It's a stack of eggs that everyone is scared to improve.
People don't even try to understand the bare basics of PKI or even security because they are fundamental lazy and not required too. No one expects them to understand the math, just the few processes required for basic usage. If you can understand the arcane rules of baseball, or how to drive a stick, or solder, or field strip a pistol or basic cooking, you can learn how to "use" encryption.
Consider https. That is very easy to use, because the user doesn't have to do anything to use it. The user doesn't need to know anything about encryption.
Doesn't this mean that many users will just click through any errors, thus making https less secure than it could be?
Consider the evolution of warnings. Padlocks were shown in different states and colours, then pop-up dialogue boxes appeared, and now Chrome has an entire red screen with a suitably stern warning.
You're right that https is the easiest form of PKI for users to understand. And they still get it wrong. And that's for encryption that could make a difference to their lives - people could steal their money or their products or whatnot.
Allow me to be the first. (Check your email.)
In all seriousness, I agree that it's a social problem. I think we (in the tech industry) can do a better job of making the tools easier to use. If we really want to make something like PGP take off, we'll have to provide easy tools that integrate with people's email clients and provide dead simple tutorials of how to get started.
I am talking about something like a Chrome/Firefox extension, which creates a GPG key pair for you, uploads the public to some central server and encrypts stuff like the text in your hotmail, gmail, yahoo mail, etc, after you press "send" and before the text is sent to google.
Then, at the other side, the a user with the same extension opens the new message and as soon as it appears, the extension detects that it is an encrypted message, reads the id of the sender and decrypts the message.
There are lots of details which makes this difficult to implement... but that would be the only way to make the vast majority of people use public key encryption.
The only problem was that the system was compromised in order to comply with US requests.
http://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_p...
Good concept, but anything you rely on someone else doing can always be compromised.
Someday I'll even meet someone real in person and be able to get it signed!
Btw. It's time to upgrade the DSA signing key to longer RSA key. Soon GnuPG should have ECC support allowing much shorter keys.
I don't have one. I, a software developer, have no idea how to get one. And if that's the case, what hope does anyone else have?
Nice plugin though, installed.
We affect the 95%.
The solution could be a distributed CA system like http://convergence.io/
My understanding was that having a CA's private key just enables someone to issue new child keys for that CA. That vulnerability could be addressed with certificate pinning.
However, they absolutely can mount a MITM with the CA root.
EDIT: Further, if they can compel a master key then they can also compel a copy of all the private keys the CA generates.
So you essentially have to go off the usual grid to run your own email service... then you have to get all your contacts onboard with using it.
I have a client that uses zixmail - webmail that is https and just sends notifications to your plain-old-text email, then you login and read and reply to your email over https. Ironically, it is a gov't agency that makes us use it.. I wonder if they snoop on their own encrypted, vendor-provided secure email?
The only problem is that a lavabit email is generally viewed as an anonymous (burner) email, so half the services I want to register to just kick the email back as not being "legitimate" enough.
For human to human emails it's great.
Running a mail server is off-grid these days? Can't you just use pgp encryption and it doesn't matter where your email is stored.
The vast majority of people are not able to run a mail server. Of the ones that do some should not be doing it because they're not clueful enough to keep it secure and out of blocklists.
> Can't you just use pgp encryption and it doesn't matter where your email is stored.
Most people get freaked out by context menus and right-clicking. You're smart; you're surrounded by smart people; you're surrounded by people who know computers. I think you might be unaware of just how bad most people are with computers.
If they can't get the data in transit, they'll go for the sources and destinations. Legally mandated keyloggers, anyone? An 'adversary' as markedly omnipresent as the NSA has had no problems [1][2][3] with intruding upon infrastructure, and I doubt your pesky little Win8 tablet or your pretty little Linux box would be able to withstand even a fraction of what the NSA could set up as a push-button intrusion system.
A click of a button, and you're compromised.
If you mess with the bull, you'll get the horns.
[1] http://rt.com/news/snowden-nsa-china-hack-120/ [2] http://venturebeat.com/2013/06/12/nsa-global-surveillance/ [3] http://www.wired.com/threatlevel/2013/06/snowden-says-nsa-ha...
And strength in numbers is not the only reason to do this. The more people expect that their Internet communications are private by default, the more outrageous it will seem to the general public that encrypted data is an exception to whatever rules there are against storing and targeting data from U.S. citizens. "Encrypt everything by default" is a good policy for changing social attitudes, not just a technological measure to defeat an unconstitutional practice.
We do have a choice here, and our collective decisions will be what shape our future and our future government. Without a concerted effort we're doomed to slip ever closer to a dystopian future of zero privacy and ever present suspicion of everyone.