3 ms·
I'd love to see what a detailed version of security policies and infrastructure look like in a world of backdoor-less strong encryption from Schneier, the EFF,
by Futurebot 10y ago
I'd love to see what a detailed version of security policies and infrastructure look like in a world of backdoor-less strong encryption from Schneier, the EFF, the Hopkins crew, etc. Something that can be used to persuade, or at least influence policymakers by allowing them to see that another way is possible, one that allows security services to do their job in a way that allows them to feel that their work isn't futile, while simultaneously respecting privacy rights.
I think the need for strong encryption and no backdoors (which as Schneier himself has explained in the past, are always a double-edged sword) are very important and I support them, but that those on the side of it who also have in-depth knowledge about the finer details don't deign to articulate just what exactly the policy looks like without resorting to just a list of what we shouldn't do and vague allusions to "just go old-school" or "utilize human assets more."
A coherently articulated, normative counterfactual security platform would be a better place to argue from.
It's a cousin to the negative liberty arguments: they only list what not to do to in order to avoid hurting people, rather than what we can do to help them (positive liberty.)
Maybe we could frame the question as "If we let the EFF and Bruce Schneier redesign the United States security apparatus from scratch, what would it look like?"
We already have excellent critiques, and are good at articulating "what's bad," but far too little on "what would a good system look like that strikes the 'right' balance?"
- nickpsecurity 10y agoA combo of per-customer authentication at packet-level, DDOS monitoring, and rate limiting (or termination) of specific connection upon DDOS or malicious activity. That by itself would stop a lot of these right at the Tier 3 ISP level. Trickle those suckers down to dialup speeds with a notice telling them their computer is being used in a crime with a link to helpful ways on dealing with it (or support number). Far as design, they could put cheap knockoff of an INFOSEC guard in their modems with CPU's resistant to code injection. Include accelerators for networking functions and/or some DDOS detection (esp low-layer flooding) right at that device. https://en.wikipedia.org/wiki/Guard_(information_security) https://en.wikipedia.org/wiki/Guard_(information_security)