8 ms·
I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc
by turnip123942 9y ago
I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc.
This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
- slashcom 9y agoI worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
- betenoire 9y agoHumor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
- bajsejohannes 9y agoHow would you practically do that? Send all those encrypted hard drives to NSA to be decrypted? Publish the backdoor, effectively rendering that encryption scheme broken?
- asdfgadsfgasfdg 9y agoJust ask the NSA to send you the un-encrypted files - they probably have them in their database anyway.
- H1Supreme 9y agoThen encryption wouldn't be doing what it's set out to do.
- ajmurmann 9y agoSo developers of ransomware would build backdoors into their ransomware because the law requires them to?
- thomnottom 9y agoAssuming that the criminal opts to use the encryption with an NSA backdoor and the victim is able to schedule time at their local NSA Genius Bar to recover their data.
- TehCorwiz 9y agoWouldn't the attackers just use a crypto scheme that didn't have a backdoor?
- winkeltripel 9y agoThe logic is that encryption without a backdoor already exists, and no law can stop a criminal writing a virus from using that.
- pjc50 9y agoWho has the keys to the backdoor? How do you force the ransomware authors not to use the good encryption?
- rickdg 9y agoIt's either turtles all the way down (backdoor of the backdoor of the backdoor..) or you always strive for secure software.
- pwagland 9y agoWell, the bigger problem would be ensuring that the criminals used known broken encryption. The only advantage is that many of these attacks are copy-cat, so if you released the source code for a broken ransomware implementation, it will probably get used more or less verbatim… as has been shown in the past. (https://threatpost.com/bitcrypt-ransomware-deploying-weak-crypto/104448/ https://threatpost.com/bitcrypt-ransomware-deploying-weak-cr..., https://www.utkusen.com/blog/destroying-the-encryption-of-hidden-tear-ransomware.html https://www.utkusen.com/blog/destroying-the-encryption-of-hi...) Anyone who actually knows what they are doing, and are prepared to break the law, would just use AES. All of those law-abiding institutions would be forced to use a weak encryption scheme. Sure, it might help stop script kiddies, but it won't help to stop professionals, and professionals are the ones that you have to worry about, since they end up hosing 45,000+ installations in a day.
- jacquesm 9y agoIf they don't just replace your data outright with noise.
- squeaky-clean 9y ago> if encryption had a backdoor This is the flaw in the logic. "Encryption" can't have a backdoor any more than math can have a back door. Specific types of encryption can. But there's nothing to stop a malicious user from using a non-backdoored encryption algorithm or inventing their own.
- kmonsen 9y agoYeah, I don't think ransomware is going to use the US approved algorithm. What they are doing is already illegal.
- stevefeinstein 9y agoThe logic is sound in theory. But in practice if the government can't protect its exploits, they mot likely can't protect their keys to the backdoor.
- merpnderp 9y agoWhy would ransomers use encryption with a back door? It's not like you can force them to only use the crackable math.
- SimbaOnSteroids 9y agoWhy would the people reaping the rewards of ransomware use encryption that has backdoors if backdoorless encryption already exists.
- djsumdog 9y ago...Because criminals are going to use state-sanctioned encryption software with mandated backdoors? Even if everything off the shelf and open source has some built-in escrow unlocking keys compiled in, hackers are just going to find those code paths and remove them. Encryption works because of certain mathematical principals and laws. Backdoors will only let governments look at legitimately encrypted data and not anything made by criminals who know how technology works. There's a bigger question here: what if the NSA or CIA or some other intelligence/defence organisation discovers a solution to solve some of these hard problems in polynomial time .. and then doesn't release that information so they can use it to spy. In that situation you're going even further: you have agents who are literally holding back scientific research that could change the entire field of mathematics and human understanding, research that could advance number theory by orders of magnitude (a jump equal to that of going from the first flight Kitty Hawk to the Saturn 5 rocket), for limited political gain.
- betenoire 9y agoThat makes sense... So "If encryption had a backdoor" is meaningless. It's really "If a given encryption implementation had a back door" and no one is making the criminals use certain algorithms. thanks
- mtgx 9y agoOnly if the bad guys use the NSA-backdoored encryption.
- maerF0x0 9y agoTo be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.
- Radle 9y agoIt makes no difference whether they created the security holes by moles in the developers company or whether they simply withheld the information. They put human lives at risk by doing it.
- ctrl-j 9y ago> ... it's not the NSA's fault that software has faults. But every time they ask for there to be legally mandated backdoors - they need to be reminded of these incidents. The NSA actively wants there to be "faults" like these. They just only want the "good" guys to have access to them.
- maerF0x0 9y agoI definitely agree wrt intentional exploits ("backdoors") to be added. To me this news highlights the need for fundamentally safe software. Just like we might have safety laws in the automotive or airline industry.
- winkeltripel 9y agoIf the NHS has been significantly crippled by this, and the NSA is partly at fault, could the NHS successfully sue the NSA in the UK? (edit: my logic and phrasing was really bad)
- sbov 9y agoAt least in the US, there is limited ability to sue foreign sovereigns in our courts - not sure if that's the case in the UK too. Beyond that, I doubt this is a rabbit hole any government, much less the UK - which has a fairly imperialistic past - wants to go down. Glass houses and all.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- jps359 9y agoalso that it is very unethical for the US government to find some vulnerability in android/windows/whatever and not report it
- bdamm 9y agoIs it particularly unethical? Many governments around the world are discovering 0-days in commonly deployed products and not revealing that to the vendor, but instead using it as a weapon for navigating computer networks. Revealing the vulnerability would place the US Govt at a distinct disadvantage.
- tgragnato 9y agoThis is an argument that highlights the difference between attack and defence in cyber: attack is easier than defence, an is the most chosen path because of this reason. Your point is actually valid, but that doesn't mean I have the intention to pardon the NSA for having compromised the network of my university, the same network I used each and every single day during my studies (and no, I am not a terrorist, nor I know anyone involved in terrorism, child pornography, or what-else they had in mind). Sorry to say, but "anyone is doing it", is not an excuse or a reason for doing something. If instead of exploiting half of the world, they had dedicated their experience in making their (and everyone else) infrastructure safer (by sharing security conscious design concepts, considerations with software developers and hardware manufacturers), now we probably would not have had massive botnets, exploitations and leaks (least but not least the political consequences of perpetrating and sustaining this kind of decisions). Where is the point when maintaining the supremacy of one's country over the others through deceit, intrigue, and espionage costs too much in terms of negative outcomes? For me that line, US and many others included, has been passed a long time ago. But that's just my humble opinion. Each one is free to draw conclusions through his own point of view.
- appleflaxen 9y agothe entirety of your argument seems to be "it's not unethical because other countries do it", which is not compelling when you consider other forms of unethical behavior using this defense.
- sergior 9y agoProblem is that people (politician) wanting to push it through simply don't care. They just want to have access and they think there are agencies that can deal with potential consequences. It is frankly all about the money - they want to have ability to access sensitive data and therefore be more attractive to people willing to pay the bribe.
- davesque 9y agoIf I understand correctly, there were no backdoors used here. Only zero-days. If the NSA is guilty of anything, they're guilty of not informing system designers of exploitable vulnerabilities. But then the argument becomes entirely ideological and naive since we all know the NSA's mission is almost entirely counter to that outcome. Edit: Apparently, not zero days. Vulnerabilities were patched months ago. I think the point still stands, which is that this outcome really has little to do with debate over encryption backdoors. 2nd Edit: On second thought, there is an argument that, if a backdoor were in place that only government agencies had access to, the means to access it could be leaked just as easily and in a similar manner to the way that information about these vulnerabilities was leaked. Then, we'd really be fucked since a backdoor could likely not be "fixed" with a simple patch (it might be fundamental to the design of a system). Considering this, I'll have to walk back my earlier statement and agree that the topic of backdoors is quite relevant here.
- sbov 9y agoNo zero days were used. This was patched in March.
- uxp 9y ago> Only zero-days. The exploits released by Wikileaks' Vault 7 dump went public months ago. They're as much a 0-day as JFK's assassination was just a few days ago.
- deleted 9y ago[deleted]
- willstrafach 9y agoSmall correction: Nearly everything in WikiLeaks Vault 7 material was already patched (With the exception of something Cisco related which has since been patched I believe). The Vault 7 content was from CIA. This issue is apparently based on a more recent leak by the Shadow Brokers, containing content from NSA and some other DoD elements who worked on offensive cyber operations.
- matt_wulfeck 9y ago
- dgregd 9y ago> This shows that no agency is immune from leaks That's well known for a long time. During cold war a lot of Russian weapons were based on the US designs. There is a TV series, Americans, which shows how to manipulate people and steal secrets. Even atomic bomb secrets were stolen (by Klaus Fuchs and others). So I guess a lot of people in military complex make a lot of money on these exploits, PRISM and other projects. And they just don't care about whole society.
- usefulcat 9y ago> That's well known for a long time. But the implications of it are not. Otherwise, no one (including heads of TLAs) could continue to claim that gov't backdoors are a good idea without being widely perceived as an idiot.
- hkmurakami 9y agoIf you explicitly ask someone with the form "are there are organizations that are infalliable to leaks?" they're likely to say "no of course not. Humans make errors" But if you phrase it to something like "Can the government be trusted with backdoors to protect us from terrorists and Chinese hackers", then suddenly public sentiment will change dramatically.
- _asummers 9y agoTo quote Göring, > Göring: Oh, that is all well and good, but, voice or no voice, the people can always be brought to the bidding of the leaders. That is easy. All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger. It works the same way in any country. Patriotism is both a wonderful and terrible thing, and it is made worse by fearing the "other". Any time people create a boogeyman (China, Mexico, Muslims, what have you), be on the lookout for what the true motivations are.
- kartan 9y ago> Patriotism is both a wonderful and terrible thing I found that hypothesis widely accepted, without so much for it. Patriotism fuses core values like freedom or solidarity with a flag. That's why it is easier to pervert. Patriotism tells people that because there are people born in the same line limits that you, you should be proud of what they do, and you should help them first. Patriotism distorts history. > "Fourteen thousand years ago, Sweden was still covered by a thick ice cap." https://sweden.se/society/history-of-sweden/ https://sweden.se/society/history-of-sweden/ Bullshit. Sweden didn't exist 14000 years ago. All history is learned as if the current countries were an inevitable result thousands of years ago. World history, human history, gets displaced to be able to build a national sentiment. > "The colonial history of the United States covers the history of European settlements from the start of colonization until their incorporation into the United States of America" https://en.wikipedia.org/wiki/Colonial_history_of_the_United_States https://en.wikipedia.org/wiki/Colonial_history_of_the_United... Again, we get that feeling of pre-determination. As if those people weren't free to choose their future as if they weren't individuals but just a means to create a country. Patriotism narrows the mindset of populations. I don't see that usefulness. Anything that people does for patriotism will be better done for freedom, equality, fraternity, etc. Why is patriotism a wonderful thing? What arguments am I missing?
- jsz0 9y agoI agree with this but there is a good argument to be made that well engineered backdoors are better than intelligence agencies hoarding undisclosed exploits.
- charonn0 9y agoIs there? I can't think of one.
- HeavyStorm 9y agoAnd it follows that anything that can create such harm CAN and eventually will "leak" or fall into the wrong hands. Maybe one day, as a species, we'll learn not to create this kind of devices. (sorry if the message seems too exaggerated)
- linkregister 9y agoYou are right but I'm not pleased that your comment has hijacked all discussion on this article. (Not that it's your fault, it's somewhat germane to the overall issue of government, I'm just whining)