4 ms·
Really? It seems to me like it's key to pro-mass-surveillance people's support for the "collect it all" approach - and for key escrow schemes in particular. A
by jdp23 10y ago
Really? It seems to me like it's key to pro-mass-surveillance people's support for the "collect it all" approach - and for key escrow schemes in particular. And it ties into the VEP discussions as well.
- tptacek 10y agoI don't know what our beliefs about key escrow have to do with the reality that NSA's "impenetrability" isn't part of the prevailing narrative. Among experts, the gauge on NSA is trending strongly towards "clownshoes".
- pdeuchler 10y agoThese points are not mutually exclusive. Most on hacker news or security twitter or slashdot or whatever would agree that the NSA has serious vulnerabilities and have terrible policies/practices, but the narrative being pushed to the average american via the usual channels is most assuredly that the NSA is infallible (or that it's only fallible due to pesky things like privacy). This article is on Reuters, which means it wasn't meant for people who know what elliptic curves are, it was meant for people who still call Comcast to restart their router. Given that, I think it's safe to say there's a distinct narrative being pushed here where it's heavily implied that leakers are the main threat to the NSA's security.
- tptacek 10y agoI didn't say they were mutually exclusive; that is also a rebuttal to an argument nobody is making. I'm saying they're orthogonal to the question of who's responsible for leaking these NSA tools.
- pdeuchler 10y agoI think this subthread is pretty clearly about the predominant narrative concerning the NSA and how this article plays into that (regardless of who actually is "leaking" it), I was responding to the discussion around your statement of: > "The NSA is impenetrable" is not and was not the prevailing narrative, to say the least.
- pvnick 10y ago> Among experts, the gauge on NSA is trending strongly towards "clownshoes". Really? That's interesting (and funny!). Can you elaborate? What in particular regarding NSA points towards clownshoes?
- jdp23 10y agoThe ''reality'' is that proponents of key escrow solution (and the "collect it all") approach have consistently made the assumption that intelligence agencies are able to protect the keys and data. The impenetrability is so deeply a part of their narrative that it's not even discussed. The cost/benefit analyses are very different if you assume that adversaries are likely to get access to any information our government collects.
- tptacek 10y agoI'm not interested in your reasons for opposing key escrow, if only because I think key escrow is stupid also, as does literally every expert I have ever talked to in my career. Our opinions about key escrow have nothing to do with whether Russia hacked an NSA staging server, or another leaker inside NSA is behind the leak.
- jdp23 10y agoI don't really know how to respond to this. Paraphrasing this conversation so far: tptacek: "The NSA is impenetrable" is not and was not the prevailing narrative, to say the least." me: I disagree; it's part of the narrative that pro-surveillance people use to support things like "collect it all" and key escrow tptacek: I don't understand what our beliefs about key escrow have to do with the narrative me: explains again what you're missing about how this relates to the pro-key-escrow (and more generally pro-mass-surveillance) narrative tptacek: everybody agrees key escrow is stupid, and our opinions about key escrow have nothing to do with things that you weren't discussing like where the leak came from me: hmm ... It's almost like you're trying not to hear what I'm saying. OK, one more try. If all the experts you talk to are against key escrow, why do pro-mass-surveillance folks keep proposing it? They see the tradeoffs differently. And why's that? One reason is that the stories they tell about why it's a net positive have the underlying assumption that there's not a significant risk of they keys being compromised. Conversely and when opponents of key escrow tell stories about the potential downsides if the keys are compromised, proponents downplay this as a risk.
- reinhardt 10y ago
- jdp23 10y agoOh look, here's Nicholas Weaver on Lawfare making a very similar point about vulnerability disclosures: "How is NSA changing the equities process now that "someone stealing the NSA's tools" has to be explicitly included in the threat model? Previously, equities calculations generally relied on the probability that someone else might independently discover and exploit a vulnerability. How does this calculation change when the NSA's own tools might be stolen, without detection? Is there a policy on what to do when the NSA knows that their tools are compromised?" https://lawfareblog.com/nick-asks-nsa-shadow-brokers-and-leaking-ship https://lawfareblog.com/nick-asks-nsa-shadow-brokers-and-lea...