4 ms·
We can also require that the hardware issuer (eg, Apple) stores an encrypted copy of the key (throwing away the key used to encrypt the original key), such that
by SomeStupidPoint 9y ago
We can also require that the hardware issuer (eg, Apple) stores an encrypted copy of the key (throwing away the key used to encrypt the original key), such that it costs $1M (or other amount) to break the encryption and reveal the key.
There's no reason it shouldn't require expense and physical breaking to gain entry, just because it's digital (and I think that this scheme gains legal protection because of such features).
By actually discussing it, instead of hiding behind lies like "there are no security gradients", we can talk about systems where it would require X amount of compute effort to break an encrypted key held in escrow for Y years at Z expense to reveal the key. (I was actually thinking about using a hash chain to timelock the key, since we have a pretty good idea of how hard it is to sequentially hash.)
I don't think most of us are against the government being able to see individual, targeted encrypted drives -- I think we object to the ability to transparently compromise all systems.
- olliej 9y agoApple never has your keys to store. That's kind of the point of end to end encryption. Note that on osx/ios that same e2e encryption protects credit card and password data. Saying company X should store their keys is the same as saying "Company X should paint a giant target on their servers that have to be weakly protected to appease requests from agency Y". The solution to unending breaches of user data is to not be able to decrypt it, that only way to achieve that is to never have the keys.
- crankylinuxuser 9y agoTo be honest, I'm against the "moneyball" solution. Hardware's going to only get: cheaper, faster, better. That $1m price will inexorably come down to the point that skiddie could do it on their phone with AWS. I still stand by the point of having a consortium of opposing interests as a combined group (or supermajority) to override an encryption. I think of it as a strong version of checks and balances. In that case, if members are also hidden, it doesn't matter how many dollars are thrown at the problem. Unless you have peoples' willful intent, the escrow doesn't work.
- cvwright 9y agoLet's work through your $1M example. Assume Moore's Law continues for the foreseeable future, so the price of all computation halves every 18 months (ie, every 1.5 years). Then in 15 years, that $1M computation still costs $1000. In 30 years, it can be done for one dollar. Is that good or bad? I guess it depends on your threat model and what the data is worth.
- SomeStupidPoint 9y agoAt a technical level, that supposes the file you want to decrypt still exists in X years. My actual thought was to have the secure enclave emit an encrypted copy of the key with a targeted key strength when presented with a request signed by Apple's key. It would require Apple's participation (or compromising Apple) but still require that the person spend a significant amount of money on the process. By having it encrypt a key, you can make normal messages much stronger, such that you can't decrypt messages without the device in question (because the key can't be attacked directly, only the weakly encrypted version of the key when the secure enclave shares it). Further, because you can change how strong the SE emitted key is with each revision, you can have new phones always have a 10 year expected safety window (and even turn up the difficulty over time). In the case of a total compromise of Apple's storage, the attacker still has to spend significant funds to compromise any given phone -- so we'll only see targeted attacks. (That is, they might say, crack Bill Gates' phone, but are they really going to spend hundreds of thousands a pop to break the keys of random Starbucks workers? I'm honestly not super worried if Bill Gates has to spend a few thousand extra dollars every few years to protect his billions.) But we're never going to get to discuss those kinds of scoping and cost-benefit tradeoffs if we don't engage in the process of shaping legislation in an open and honest way.
- cvwright 9y agoOh, that's cool. Thanks for sharing. Full disclosure: I've been working on some similar ideas for a while. I'll be presenting a high-level pitch for the general concept at the USENIX Enigma conference in January [1]. Also hoping to have a full paper to share on https://eprint.iacr.org/ https://eprint.iacr.org/ sometime later this month. > But we're never going to get to discuss those kinds of scoping and cost-benefit tradeoffs if we don't engage in the process of shaping legislation in an open and honest way. Agreed. And I'll actually take it one step farther. I think it might make sense for tech companies to adopt a very conservative version of this approach even without a government mandate. Then the next time the DOJ rolls around to demand somebody turn over their private key (a la Lavabit), or to demand that somebody create a custom OS for them (Apple), we can say "No, we already gave you a way in, just pay the million dollars. Now bugger off and leave me alone." [1] https://www.usenix.org/conference/enigma2018/ https://www.usenix.org/conference/enigma2018/
- kelnos 9y agoThis might be unpopular (and is certainly counter to the government's desires), but I am absolutely against breakable encryption of any sort. I am absolutely fine with criminals being able to use strong encryption to make data impossible to ever be read by the government. The bit I take issue with here is that breakable encryption is absolutely necessary for law enforcement to do its job. No. It makes it _easier_ for them to do their job, at the expense of everyone else's security. There are usually other ways to get a conviction other than being able to decrypt a criminal's data. And if in some instances there isn't, I'm ok with that. I value freedom and privacy higher.