PRISM-Proof Security Considerations
ietf.org
ietf.org
A dozen years after the attacks on the World Trade Centers, it's clear that the terrorists won. The USA cannot be called the "land of the free, home of the brave" anymore. Terrorists know that their tactics work very well, and has made the US vulnerable to even more attacks because of cowardice.
Imagine if the US government had decided _not_ to be terrorized, like the Norwegians did for the 2011 Oslo attacks:
---
And at the political level, the Prime Minister Jens Stoltenberg pledged
to do everything to ensure the country's core values were not undermined.
"The Norwegian response to violence is more democracy, more openness and
greater political participation," he said.
A year later it seems the prime minister has kept his word.
There have been no changes to the law to increase the powers of the police
and security services, terrorism legislation remains the same and there
have been no special provisions made for the trial of suspected terrorists.
On the streets of Oslo, CCTV cameras are still a comparatively
rare sight and the police can only carry weapons after getting special
permission.
Even the gate leading to the parliament building in the heart of Oslo
remains open and unguarded.
"It is still easy to get access to parliament and we hope it will stay
that way, " said Lise Christoffersen, a Labour party MP.
She is convinced people do not want laws passed which would curtail
their basic rights and impinge on their privacy despite the relative
ease with which Breivik was able to plan and carry out his attacks.
---There is a way back to the way the US used to be, but the answer is not something most people will even consider or listen to.
But what you're not doing is giving your own alternative analysis. What is the threat posed by the NSA and what are the attacks that we should think seriously about, and what are the threats we can safely ignore? What can we do about the former?
Kleptography is pretty well defined in the first sentence of its section: Kleptography is persuading the party to be intercepted to use a form of cryptography that the attacker knows they can break. So yes, in some instances it's encouraging the cracked RSA standard, and in others, it means encouraging "weak ECC curves".
You're a highly-regarded member of this site and a very vocal security expert, yet lately you've started dodging security questions you used to freely answer, and you post odd comments that tend to derail security threads. At one time, you regularly had the top comment with a highly insightful technical explanation of how a security concept works. What happened?
EDIT: I responded to your reply. I was hoping you could look at it whenever you have time, because your response seemed to be talking about a different timing attack on a different encryption scheme than what I was talking about.
That would be this Comodo Group: http://en.wikipedia.org/wiki/Comodo_Group#2011_breach_incide...
'The proposal has just one author - Phillip Hallam-Baker of the Comodo Group – which makes it a little unusual as most IETF proposals are the work of several folks in pursuit of a common goal.'
'Sadly the paper is a little light on for actual ideas about how the internet can be PRISM-proofed, offering “a security policy infrastructure and the audit and transparency capabilities to support it” as one item that should be on any hardening effort's to-do list. More use of cryptography is also proposed, so that “two layers of public key exchange using the credentials of the parties to negotiate a temporary key which is in turn used to derive the symmetric session key used for communications”. That regime should, Hallam-Baker suggests, make it harder to snoop on everyday traffic.'
Heavily emphasis on the should on that last sentence.
[1]: http://tools.ietf.org/html/draft-hallambaker-rfctool-01
Of course they are limited in the information they can reveal. They can only reveal as much information as is there to reveal. That in itself is a limit. That is a non-informational, misleading statement.
> ... and easily defeated with relatively simple cryptographic techniques.
While some cryptographic techniques are "relatively simple" to use, those same techniques can be undermined. In the current case, the attacker was involved in developing that technique and/or has the overwhelming power to make the technique worthless (acres of server farms, able to churn on any of it).
The only tecnique to guard data against passive attacks is to destroy the data, all its copies, and all who ever saw the data.
/facepalm