3 ms·
I think it's safe to assume that would be impossible to keep secret. The number of people that would need to be "in on it" is huge. I can vouch personally that
by brainfire 10y ago
I think it's safe to assume that would be impossible to keep secret. The number of people that would need to be "in on it" is huge.
I can vouch personally that at least one civilian department doesn't do this.
- EdHominem 10y agoDo you really have a policy that would survive an NSA-directed evil-sysadmin attack from any of the participants in your chain of trust? As a civilian branch of the government? It's pretty hard to setup a system that would survive an powerful adversary who simply didn't know your passwords, have access to your safes, etc. But to then make that system hardened against a malicious insider with get-of-of-jail card?!
- brainfire 10y agoIt would have to be one of the four people with root. Multiply this by the number of groups that operate a .gov website (it's a lot) compounded by turnover (even more.) And account for the cat-herders needed to organize it and do it every time the private key rotates (no less than yearly for our internet-facing sites.) There are a lot of ways you could do this on a small scale, but you really can't scale up this particular mechanism and keep it secret.
- EdHominem 10y ago> It would have to be one of the four people with root. Or anyone who'd ever gotten access to the computer, or installed a camera near it, etc. The critical part of that answer though, is "one of the". The system fails if any of the individuals is be malicious. A more-robust system would require multiple malicious agents in various organizational silos (security, compliance, management) to fail. > every time the private key rotates Well, if I got in once it probably phones that home for me. > you really can't scale up this particular mechanism and keep it secret Well, it isn't secret. We know the NSA intercepts hardware to muck with it, when needed. Much easier even than planting something in your server room explicitly. Also, they wield NSLs compelling silence and cooperation. It's not like being discovered here or there would stop scare or stop them. It would probably scale pretty well given that this is the extreme; most people just generate keys on the old debian box in the corner.
- brainfire 10y ago> A more-robust system would require multiple malicious agents in various organizational silos (security, compliance, management) to fail. Yes, and at that point the name for it is "policy". These are our own keys after all- nobody would blink an eye if they were supposed to be collected. They're not.
- EdHominem 10y ago> They're not. [keys not collected by another agency] Right. I think you're absolutely correct, now. And I fully expect (hope!) that the NSA will one-day come to you with some more-secure hardware and that you will gladly cooperate because as you say - we are all on the same team. My point is that you can't say what you're saying now. You aren't secure, and you don't have the type of procedures that would ever let you get to more than a 4/10 or so. You don't even see having four independent points of failure as an issue, rather than a benefit. By promising people that the NSA does not have your organization's keys you're providing the less technical with a false picture. And maybe, one day, that might matter. You might trick the next leaker into trusting your org as a way to whistle-blow and cause them to be caught by the NSA before they reach the news. > Yes, and at that point the name for it is "policy". [security procedures] Yeah, and software is just automated policy. If this is a zero, and that's a zero, etc... If the guard in the vault runs a non-exploitable policy (ie no "I'm the boss" backdoors) then you can greatly reduce evil-sysadmin attacks.
- brainfire 10y agoSorry, I'm not going to continue arguing with you. It's clear you don't understand the scope of what you're proposing is happening.
- willstrafach 10y agoStrangely, many tech folks seem to have normalized some very wild fantasies about what the NSA does.