10 ms·
That's... just not true. And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as prett
by SomeStupidPoint 9y ago
That's... just not true.
And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies?
I mean -- "there is not a gradient"? ...what do you call changing key size?
Ed:
I'd like the people downvoting to explain how changing the keysize isn't a gradient of security. (Hint: You can't, because it is.)
- olliej 9y agoWe change key size because what is secure in terms of key size is literally compute bound. Key strength changes because we predict when a key will /cease being secure/. That said most of the demands made by DoJ aren't for reduced key size, they're for variations of key /escrow/: literally breaking the security model of crypto entirely. So maybe I could be more specific: there is no such thing as an almost secure protocol. The key (ha!) result of this recognition is that all secure protocols have been moving to some variant of ephemeral keys. Specifically to deal with the problem of all static keys eventually becoming insecure.
- SomeStupidPoint 9y ago> Key strength changes because we predict when a key will /cease being secure/. Yes, we use keys up the gradient of security that key size represents as attacks become more powerful. The reason we don't use the more secure keys in the first place isn't that 2048b keys weren't always more secure than 1024b keys -- it's just that we didn't (for most purposes) need to be that secure, and so we choose an appropriate spot on the gradient for our cost-benefit analysis. Pretending that's not a gradient of security is simply dishonest. > That said most of the demands made by DoJ aren't for reduced key size, they're for variations of key /escrow/: literally breaking the security model of crypto entirely. That's missing the plot for the details: the DoJ wants a method by which they can break into digital safes in a manner similar to physical safes. Their proposal is key escrow, but that's partly because technologists didn't suggest a better way when the DoJ simply asked to get it done with little guidance. So they made a specific ask. And it sucks -- because they're not technologists. Everyone knows it, but the DoJ isn't inclined to let people flat out refuse. Pretending that there aren't technical solutions with transparent ruses -- like there aren't gradients of security -- are how we got to lawyers demanding technical features. I don't disagree with you that we should use secure protocols, I'm just saying we need to hold ourselves accountable for honest and strong arguments, not ruses. The one you end on -- that using ephemeral keys is fundamentally a stronger algorithm that doesn't work well with long term taps -- is a strong argument. Much better than things like "there aren't security gradients" -- partly because they're actually true.
- olliej 9y agoNo one came up with a better "solution" than escrow because there is not one. I've spent years of my life working on making it so people don't have to risk their information whenever it touches a computer. Key length is a measure of how long you want the key to be secure. Also note that we tried that once in the past: DES had a deliberately crippled key space. That was resulting in terrible security bugs only a few years ago.
- cvwright 9y ago> No one came up with a better "solution" than escrow because there is not one. I keep seeing this statement being made whenever this topic comes up. Yet I've never seen a formal impossibility result. It's amazing. Cryptographers are the smartest people in the world when it comes to solving most problems. (Just ask them!) But seriously, some of the stuff they can do is like magic. Things that, intuitively, sound like they should be impossible. For example: Zero knowledge proofs? Can do. Oblivious transfer? Sure thing. Fully homomorphic encryption? Coming right up! But then the DOJ says they want some way to investigate the Texas shooter's phone without also getting access to everyone else's data. And suddenly the whole community is like "I dunno man, aren't you just asking me to 'nerd harder'? ¯\_(ツ)_/¯ lololol" It was cute at first, but if we keep it up we're going to start burning through our credibility real soon.
- Jotra7 9y agoSpoken like someone who doesn't understand encryption.
- crankylinuxuser 9y agoTo defend this user's point, I think could be a case made for a key escrow that requires an unlock from different organizations. RSA solved this years ago. We could establish a key escrow that adds a key to your personal key. This extra key would allow unsealing in cases where it would be needed within the law. The extra key could be set up so that it requires X out of Y keys. Each key could be owned by different organizations, like the state govt, FBI, Courts, Nonprofit oversight committees, citizens oversight of police, and such. This could provide a balance of security and privacy, and allow in extreme circumstances a forced break of encryption. (Ideally, it would require many orgs that are normally in opposition to agree. It would not be "state govt", "FBI", "CIA" like the old Clipper Chip.)
- bhhaskin 9y agoI as a private citizen do not want the government to have access to my files. Period. End of story. They have zero right to have access to every aspect of my life. Any "solution" that involves any government the ability to access encrypted files is not encryption, but a lie.
- crankylinuxuser 9y agoAnd that's where I have to disagree. "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized." 4th Amendment, Bill of Rights, US Constitution That's a balance, of between "Get off my lawn", and "I affirm I saw X illegal thing and I swear it in front of a judge, and the judge agreed." Now, I don't trust some bureaucratic department to honor the constitution. And from the sounds of it, neither do you. Which is why I was keeping in mind of having an antagonist based key-holding scheme which would require a multitude of people to unlock before the data would be unsealed. To me, that does re-enable the balance set forth in the Constitution, namely the 4th Amendment to the Bill of Rights.
- 9y ago
- olliej 9y agoI had another comment, but in response to your Ed: comment: key size is not a measure of security. It is a measure of how /long/ we intend the key to be secure. More explicitly: Key size does not exist of the gradient of protocol security. We know how long a key takes to break given current technology and algorithms. We choose a key size to render the time to break infeasible against our prediction of state of the art some amount of time in the future. If there's a gradient, the gradient isn't "how secure it is", its "how long it will remain secure". Hence any policy that endeavours to control the "strength" of encryption through controls over key length is /necessarily/ requiring an insecure key size. It can be put this simply: How small must the key be to allow it to be "good enough" for the DoJ? Would they accept a continuous 5 years on a 10000 gpus? Noting of course that in 18-24 months that key size will now only require 2.5 years, then 1.25, 7 months, 3 months... Of course I'm sure 5 years and millions of dollars will be "unreasonable", so it would need to take less time, and cost less.
- SomeStupidPoint 9y agoSincere question: how do you define "how secure it is" except "how long it will remain secure (under attack)"? Edit: You're also completely eliding that security is probabilistic -- they might just guess our key on the first try. We can only discuss it as the expected amount of computation to figure out our key on average. That expected amount has a gradient along keysize.
- olliej 9y agoA protocol is secure if, and only if, the fastest attack is an attack on the key itself. All of the recent crypto breaks (that not cause by prior key size restrictions req'd by gov agencies) have been protocol flaws, e.g. flaws in the protocol allowed you to derive the key without having to just explore the entire key space. Anything other than deriving the plaintext of encrypted data alone would mean the protocol was insecure. That said, I am coming to agree with you in terms of trying to explain to people who don't write crypto code that saying key size is gradient of security is probably the most sensible thing. I still disagree with you on the actual statement :D
- 9y ago
- thatcat 9y agoI didn't downvote you, but ultimately either someone else can get in or they can't, the fact that keys have varying sizes is tangential to this issue since the size chosen only needs to be one that is sufficient. The fact that I don't know what that value is doesn't change the fact that the outcomes are binary (secure|insecure).
- ketzu 9y agoYour initial assumption seems to be wrong. In cryptography there is one information theoretical secure scheme: The one time pad. But even that relies on circumstances to keep it secure. Without limitations you can not say no one can break it, because obtaining the key material might still be possible. That leaves us with most other schemes. They are computationally secure. This implies that the security of the system depends on the computational power of the attacker. So a system can only be secure for a class of attackers and to a certain extent. If you apply a binary clssification of secure insecure as you proposed it someone can get in", most systems today, if not all, are insecure.
- thatcat 9y ago>most systems today, if not all, are insecure I'd say that's a fair assessment.
- senectus1 9y agoI wish I didn't agree with you but I do. Security is a process not a state. You cant say that something is "secure", there is more secure and less secure. What the politicians are saying is that your individual security is not as important as their responsibility in security policy. Security + Politics = Every shade of grey conceivable and then some not yet conceived.
- SomeStupidPoint 9y agoI don't like it either. But as a practical matter, I think we will do more to protect privacy and security by engaging with the process and honestly addressing their concerns so we can strike a balance between conflicting societal needs than we'll do with hardline stances based on inaccuracies. I think pretty rightly a lot of tech people got told off by the political process for misrepresenting what was possible and how technology worked in an effort to not have to obey social structures. I don't think most of us liked that (I sure didn't!), but we're not going to have everything our way (and especially not by lying or throwing tantrums). I mean, if I were a senator, I'd be thinking "So, they can secure a ledger with floating cryptographic difficulty when they want to make money, but a solution for national security is impossible? Yeah, fuck these guys." There just hasn't been the kind of open, honest discussion around the topic that would satisfy their concerns. And the key to having some of it our way is explaining why that issue is paramount to have our way and honestly engaging in the process to make it happen. Politics is a game of compromise and negotiation -- the government is almost certainly not only willing to concede some of the things on the FBI wishlist if better alternatives are put forward, but actually is interested in doing so. Everyone knows professional investigators ask for too much, but if no one else is putting forward honest suggestions -- what choice do politicians have?
- AnthonyMouse 9y ago> I mean -- "there is not a gradient"? ...what do you call changing key size? It isn't that there are no levels of security, it's that you can't be at two separate levels at the same time. There is no overlap. Mandating 512-bit RSA is useless because the government could break it but so can everybody else. Allowing 4096-bit RSA wouldn't allow the government to break it. There is no middle ground. Mandating something like 1024-bit RSA, which is considered weak but nobody has actually broken it yet, is worse than useless. The FBI probably couldn't break it today and some hackers will probably break it tomorrow, so it would only leave people at risk without providing the government access.
- hackinthebochs 9y ago>It isn't that there are no levels of security, it's that you can't be at two separate levels at the same time. There is no overlap. What do you say to DUAL_EC_DRBG, which seems to be precisely that "separate levels" of security you claim is impossible?
- cesarb 9y agoDUAL_EC_DRBG is, in principle, equivalent to encrypting the same data with two separate keys, each one being able to recover the plaintext. There are no "two separate levels at the same time" here: the weakest of these two keys determines your security level. With DUAL_EC_DRBG, one of these keys is a static key which, once leaked, can break every message with a small amount of extra effort. The same applies to the recently published DUHK attack: once the hardcoded key is known, the whole thing gets broken, showing that the security level was only as strong as the weaker key.
- hackinthebochs 9y agoI don't see how this is a substantive reply. Yes, once your key is known you no longer have security. That's true regardless of how many keys your scheme employs. Just like in traditional encryption scenarios, your personal key remaining secret is a part of the assumption. That there are now two secret keys doesn't alter the analysis substantially.