The second crypto war and the future of the Internet
agenda.weforum.org
agenda.weforum.org
That is incorrect and dangerous advice to give users.
As has been discussed before, as long as Apple controls the public key exchange process, they have the capability to intercept and decrypt your messages if they wish, or are compelled to do so.
[1] At least by an adversary with sufficient resources, leverage, and impunity (NSA, GCHQ, etc.)
This war really has little to do with find the way into a named person's communications; it has much more to do with finding the names of people whose communications they want to see.
For that, iMessage is devastating (assuming it is implemented and behaves as marketed, a pretty big assumption).
This is completely false. Use good cryptography properly, and make sure your system isn't hackable. PGP + Tails is a popular combination for Glenn Greenwald and others like him.
There are just too many layers of abstraction to exploit to say a system isn't hackable.
And in a lot of countries you are automatically jailed for not handing over your encryption keys when asked.
Not automatically jailed, but can be jailed when they want the key and not turned over.
That said, iMessage in design and even implementation is utterly amazing compared to the normal quality of such systems from big companies. It is by far the most secure large-scale easy to use communications system available today. I think WhatsApp/Moxie-enhanced will probably surpass it when available, but that's an add-on application. iMessage is an out of the box default.
I don't know what is more stunning; the blatant racism, or the fact that nobody seems to care about it.
It loses auth for whatever reason (a bug? an os update?), has me sign in again, and then a "new device" message with my desktop name pops up on all of my mobile devices. I really have no way of telling if it is a reauth from my desktop or a third party that happened to know my desktop name.
https://en.wikipedia.org/wiki/Warrant_canary
That's a really interesting concept thanks for bringing it to my attention.
If anyone's interested here's the first article I found discussing Apple removing their warrant canary:
https://gigaom.com/2014/09/18/apples-warrant-canary-disappea...
In the '90s, you could distribute code for PGP in a book, and effectively circumvent regulation. Now, you can ban encryption apps in the walled garden and effectively shut down an entire genre of computation.
But it's also quite hard to tell if an open source application is secure. Do you have time to audit thousands of lines of impenetrable C/C++/Java/Go/etc. code? The rash of OpenSSL bugs we've had recently shows that "Linus's law" really doesn't work -- the fact that the code can be audited openly doesn't mean anyone is going to spend the time to actually do it. People are busy.
It comes down to the question of "how paranoid are you?"
If I were highly paranoid I'd take a defense in depth strategy -- layer multiple cryptosystems, possibly on multiple OSes/platforms, etc. But that level of paranoia comes at a price of course, both in setup time and overhead.
iMessage is pretty good for every day use. PGP is probably better since you have greater transparency, but is less convenient. SSH and SSL are also pretty good for every day use. But I would trust none of those things to protect me from the NSA or a very well funded criminal adversary.
When an exploit in closed source software is publicized, we have to take their word for it that it gets fixed.
This would be expensive ( in time and effort spent), but is possible for some things.
With things like crypto though, AFAIK most crypto is based on certain assumptions which seem to be true, even after a high degree of investigation, but for which a proof has not been found. In these cases, it would not be feasible to prove the program to be "secure", but one could prove that the program correctly implements the algorithm.
But then there's also timing attacks and the like, and I don't know that there are tools for proving things about the running time of a program, so as to prove that the running time doesn't leak information?
But for some things, one can trust a program to be correct if it contains a proof that it is correct, and you agree with what correct is being chosen to mean.
Sure you can build functionally good software, like PGP, but making something work is only maybe 25% of the way to delivering a product. The other 75% of the work is in getting the user experience right, packaging, supporting all the different platforms, etc. Walled gardens are winning because they deliver orders of magnitude better UX than open systems, and that's because they have a revenue model that can allow them to pay people to do the immense amount of work required to polish things to that extent.
https://www.crowdsupply.com/purism/librem-laptop (successfully met its funding goals)
https://www.crowdsupply.com/kosagi/novena-open-laptop (arguably more niche and yet it grossed an incredible 305%)
http://ccc.de/ (not all revenue models need to produce hardware)
Creating really beautiful UX is a brutal slog through the tar pits of hell. The amount of testing, testing, testing, testing, TESTING and endless revision that's required to iron out every little nit-picky detail of a user's interaction with a product is immensely time consuming and expensive. You need top-tier designers working for years with large teams of testers, beta users, etc.
For example: I could not imagine fielding a competent turn-by-turn directions app for a phone for less than $10-$15 million in funding, minimum. Then you'd need millions a year minimum in recurrent revenue to finance the endless polish and nit-picky improvements that would be required year over year to keep it competitive with the alternatives.
Tiny details matter. For example, when you start turn-by-turn directions on Google's Maps app for Android, it doesn't say anything right away if you're already going along the correct route. It's silent until it's time to turn. This caused me to assume something was wrong with it or my volume was down. Almost made me throw my phone out the window.
Think about what a tiny detail that is. Google with all it's funding and team didn't catch that. Apple got it right. Their Maps app starts talking immediately, letting you know it's working.
It's a new age -- the age of overall user experience. Features are now a commodity. They don't matter all that much. Getting something working is only step one of ten. The other nine steps are to get it working well.
The thing that makes UX really hard compared with features and capabilities is that there's no straightforwardly "right" answer that can be discerned Platonically in isolation.
UX is a matter of taste and people, not algorithms and code. It's not something that responds to the kinds of Moore's Law efficiency gains that can be achieved in the CS realm -- it requires the irreducibly expensive commodity of human time and effort.
The fact that this kind of time and effort investment is irreducibly expensive is why huge mega-corporations like Apple and Google have such an intrinsic advantage in this department. It's easy to understand why they dominate the mobile space -- when you're interacting with a mobile device, your appetite for poor UX is quite a bit lower than when you're sitting at a desktop.
They really don't. All it takes is one designer with good taste, or a developer frustrated with the status quo. Sure, big companies have the resources to do a lot of in-house testing and iteration, but that does not suddenly create taste.
> easy to understand why they dominate the mobile space
The reason for the current duopoly in mobile OSes has less to do with pure UX, and more to do with successful jockeying for market position across a multitude of factors (yes, including UX). WebOS? Windows Phone? Both arguably had/have superior UX, but still lost in the market.
Anyway, the OS vendor is irrelevant in this context, notwithstanding app investment due to market position. One can have horrible app UX on iOS, or terrific app UX on Android -- and Android is really not that great overall, especially with older and/or lower-end devices.
Moreover, there are plenty of successful third-party apps, regardless of platform, most of which haven't invested millions and years into UX.
However, large companies like Apple can deliver an entire suite of software to users that has high quality, consistent UX.
This means consumers who aren't used to technology only have to learn a lot of things once. On the other hand, people who've grown up using Apple products already have an idea how to use new ones.
Individuals and small organizations can create some amazing things but large corporations definitely have some intrinsic advantages, especially when it comes to larger projects.
>[...] for the first time in history, anyone could encode and exchange a message that no law enforcement agency had the technical ability to intercept and decode.
Here's one famous counterexample: https://en.wikipedia.org/wiki/One-time_pad
People have always been able to communicate secrets. I don't underestimate the value of doing it conveniently, and obviously many people have been caught by lazily talking on a wiretapped phone, but the crypto war is only a war on convenience. There can't possibly be an effective war on communicating secrets unless people just give up trying. If governments want to fight it, they should at least be honest and say they're fighting convenient crypto, not crypto in general. They're fighting crypto that average people can access easily, crypto that makes everyday privacy achievable, not crypto used by coordinated criminals. At least it would make more sense and could lead to a reasonable debate.
As with guns, the criminals will simply ignore the law. Anti-crypto legislation will be aimed squarely at We The People.
The great thing about code is that there's usually a way to change the rules. The scary part is that it leads to an endless arms race.
The name is steganography, and has been used since ancient times.
The best way to ensure the secrecy of a message is to prevent the adversary from learning the existence of the message. Second best is to provide a bunch of big dumb decoys for the real message to hide.
I don't see how Apple could avoid that - the government already uses secret legal means to make them do things they don't want to and prevent them from telling anyone. This is no different.
Then I go to their website [1], and see that unfortunately they forgot to add this annotation in the description of their product [2].
Could anyone tell them please :)?
[0] https://agenda.weforum.org/wp-content/uploads/2015/01/prince...
Meaning, it's still not end to end, which is what you would expect when you hear SSL. Where are they upfront about that?
https://bournetocode.com/projects/8-CS-Cryptography/
If there is a second crypto war, I want my students to have a little bit of a head start.
This is the best relic from the past war. We may need a new one soon...
RC4 is so trivial that several people (including myself) were able to write implementations that fit in a single tweet.
If you can memorize a hashing algorithm, then you can use the hash to verify larger pieces of software that you can't memorize.
So large, complex crypto doesn't ever need to be memorized - all you need is an easy to memorize hashing algorithm.
The real criminals of course would use any number of other systems (say those based in other countries) which would not be collected in the dragnet. It would only be the average citizen who suffers.
The best answer here is: the government should obey the laws and not spy on citizens, and maybe then the citizens won't seek refuge.
Also, does anyone else realize that they are essentially expecting to have no limitations? They want to, not only be able to essentially have access to your person at any time ... which is understandable to a certain extent ... under authority of a legal and proper warrant; but they now also want to be able to monitor and track every single thing you do and are at all times for future recall. Essentially, they are wanting to be able to reference the experience of your life, approaching your memory.
So what stops the government from reading your memories, once that technology is fine tuned? We are seriously on a precipice here, because humanity's political and civil society has not caught up to the exponential advances in technology.
The last time such a mismatch existed it resulted in WWI and WWII. Before we emerged, mumbling .... "WTF, just happened"
Why not? By the same logic, tables at all restaurants should be bugged.
Before technology, when people met the only way to know what they were saying was to be there. The world survived that.
And the only underestimation happening here is the politicians'. If the cryptopocalypse were to happen tomorrow (i.e. David Cameron's fantasy), modernity would end as we know it. Financial markets wouldn't so much collapse as cease to exist. Hungarians recently took to the streets over a tax on data; what would happen if e-commerce became impossible? Imagine the impact on the rule of law if 10% of the economy disappeared overnight. Encryption isn't a threat to LE, it's the only thing protecting them from a nightmare.
Strong encryption on the wire (in transit) also renews the focus on the end points. The data are plaintext in memory on the devices. If the end points can be compromised, the data access problem is solved. Lot's of people are writing exploits (both good and bad guys) to do that.
When you combine network metadata with local device data, you've got a pretty complete picture.
Services such as CounterMail, Tutanota and ProtonMail are taking user-friendly (abeit weaker and proprietary) approaches. DarkMail may eventually be a fundamental solution, but may be too ambitious.
The third is end-point security. It's crucial to use full-disk encryption, and to avoid being exploited. That involves both software and wetware hardening.
But even that's inadequate. It's essential to compartmentalize unconformable information in separate and isolated compartments. Isolation comprises all aspects: devices, network and Internet connectivity, communication partners, and so on.
I believe using this in conjunction with some garbage recipients (with a secret key thrown out immediately after the creation of a public key) will randomize metadata quite well for OpenPGP.
EDIT: clarified option switch is for GnuPG