10 ms·
I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the con
by FakeComments 8y ago
I disagree with the conclusion of absolute security — it won’t happen, and only encourages subversion by people who both need and have a right to access the content.
Instead of pontificating, the tech industry should innovate.
There’s no reason that hashchains can’t be used to timelock the key, and the enclave export it in response to a signed request. Then we can at least force the compromises through the legal system and require effort to reverse the hashchain. That kind of court authorized targeted access removes the incentive (and justification) for other actors to more deeply compromise the system. In turn, this let’s us provide more security, in practice.
What’s not going to sell, and what the tech industry needs to get over is “lulz, it’ll impossible to intercept military or terrorist information because I need absolute privacy for my saucy emails”. I think it’s been empirically demonstrated that won’t happen.
Be part of the solution.
- techntoke 8y agoC'mon everyone, be part of the solution like this person says. The intelligence agencies will never abuse their power. You can trust them. /s
- FakeComments 8y agoThat’s a deep straw man of what I said, to the point of being non-constructive mocking. You’re just being dishonest to claim I suggested trusting the spy agencies. Rather, I pointed out that they have a real mission, and they’re going to spend effort accomplishing it. But their mission isn’t to own every device — it’s to own a select few, probably on the order of hundreds or thousands a year. So, if we create a mechanism by which they can do that without owning every device, we can align our goal of protecting most devices with theirs of owning a few. This in turn increases security for nearly everyone, because powerful agencies no longer have the same motivation to cause harm — and might be persuaded to help. After all, it’s in their interest to prevent large remote compromises — just not a higher priority than maintaining their own access. Further, the best way to actually restrain them is through a change in government policy, which will only happen when the government believes there’s an alternative solution. Perhaps you could try responding to the point?
- pjc50 8y agoI think the underlying point is "which intelligence agencies would be allowed to compromise devices like this"?
- FakeComments 8y agoThe ones courts which governed the relevant company were willing to issue warrants on behalf of — that is, those our regular legal and political systems decide on. For a big multinational like Apple, that’s probably a fair number. But it’s also harder to hide they’re doing that, and let’s us bring pressure on them politically for their political misdeeds. In the end, it’ll be major powers who can — US, Europe, China, etc. My point is that it’s never going to be the case that technologists get to unilaterally decide that for all of society. My proposal is just to bring phones into line with existing warrants: https://news.ycombinator.com/item?id=19036408 https://news.ycombinator.com/item?id=19036408 But by doing so, technologists have the political cover to push back on spy agency excesses and abuses.
- pjc50 8y agoSo you support China being able to hack any phone globally with a warrant in a Chinese court? Isn't that literally what Huawei are accused of facilitating?
- FakeComments 8y agoNo, I support China being able to spend an appreciable amount of time to crack each phone they have physical possession of, following a court order. I never suggested the ability for remote compromise (what Huawei is accused of), and my exact point is that we can create a cost to cracking each phone — in hashing power and time spent — if we compromise on the topic. No such cost exists now, because they achieve access via other means. The combination of requiring physical possession and appreciable hashing time per crack is a two-layered response to mass-surveillance. That’s the whole basis of the compromise I’m proposing: calling their bluff, and enabling warrant cracks as political cover to shut down mass surveillance and cracking as unnecessary.
- nothrabannosir 8y agoThis sounds like a first order objection to a second order concern. In particular: > What’s not going to sell, and what the tech industry needs to get over is “lulz, it’ll impossible to intercept military or terrorist information because I need absolute privacy for my saucy emails” Seems to be an ironic mischaracterisation of the parent’s point, which was precisely that one coubtry’s terrorism is another’s gay rights activist or high ranking foreign official. From the article: In 2017, for instance, the operatives used Karma to hack an iPhone used by Qatar’s Emir Sheikh Tamim bin Hamad al-Thani, as well as the devices of Turkey’s former Deputy Prime Minister Mehmet Şimşek, and Oman’s head of foreign affairs, Yusuf bin Alawi bin Abdullah. It isn’t clear what material was taken from their devices. “Saucy e-mails” is a bit tone deaf :(
- FakeComments 8y ago> Seems to be an ironic mischaracterisation of the parent’s point, which was precisely that one coubtry’s terrorism is another’s gay rights activist or high ranking foreign official. My point was that issues like this should be mediated by courts and existing legal systems, not the unilateral decision of technologists. And that society is going to insist that be the case, hence the most effective way to protect those persecuted minorities is via cooperation and steering how that process happens — not fighting a losing battle. Finally, that the way to increase the effective security is stop fighting ideological battles on the issue, and find a politically workable compromise which still prevents remote exploitation — the main danger of encryption bypasses.
- darkpuma 8y agoWhich courts? Which legal systems? Legal systems and courts of nations who believe political speech is a crime and that alternative lifestyles are capital offenses?
- FakeComments 8y agoThe ones who are capable of compelling the phone company to obey over political pressure from other sources. This is a strict improvement over the current situation, where the answer is “anyone who has money”.
- syn0byte 8y agoWouldn't the police have a "right" to know if a person has any weapons? Detaining everyone and performing a full cavity search for any and all infractions is just the police exercising their "right" to such information. Will you be the first to bend over and spread for the cops "right" to peace of mind? "That it is better 100 guilty Persons should escape than that one innocent Person should suffer, is a Maxim that has been long and generally approved."
- Ntrails 8y ago>"That it is better 100 guilty Persons should escape than that one innocent Person should suffer" is a Maxim that has been long and generally approved. It is not fundamentally true nor universally accepted. Where does the scale tip? All criminal justice systems attempt to minimise the risk - but one some level it is simply the cost of doing business. For all that it is an admirable sentiment, it is limited.
- FakeComments 8y agoUh, my proposed solution required getting a warrant to order a company to produce a device specific message which in turn could be provided via cable to the physical device, which they must also have access to, followed by spending time reversing a hash chain. So yes, the police already have the power to search you for weapons if they have a warrant, and this is bringing the ability to search phones into line with that.
- LeifCarrotson 8y ago> "That it is better 100 guilty Persons should escape than that one innocent Person should suffer, is a Maxim that has been long and generally approved." I wonder if that maxim is still generally approved. It seems like some authoritarians would prefer that 100 innocents would suffer than one guilty person should escape. I suppose it depends how you define "innocent" and "suffer". Under modern law, everyone is guilty of something. And while we might not require suffering in prison, a little suffering of expensive legal fees, invasions of privacy of your digital data/at the border/in the airport, or searches and seizures of property by police in your car are commonplace.
- sobellian 8y agoThe objections to a golden key are irrespective of whatever system permits the golden key access. Your hashchains are completely irrelevant. The courts will use some key to sign their request, and that key will leak. Cryptography reduces message security to key security, nothing more.
- FakeComments 8y agoThat’s why it’s a two stage system: leaking the key only permits forged requests, but an attacker still has to spend the time reversing the hash chain. For each and every phone they want to crack. Apple has also done a reasonable job of holding onto their signing keys, to date.
- jhayward 8y ago> Apple has also done a reasonable job of holding onto their signing keys, to date. How do you know that?
- FakeComments 8y agoBecause whoever has stolen them has been reasonably discreet, and we don’t see compromised Apple things all over the place — which means if they’ve been stolen at all, it’s been by high class attackers. If your goal is to stop the NSA et al stealing a key or owning a device, you’ll be sad. But if your goal is to change the law and redefine the parameters of them owning devices, you might make progress. The political process will insist on a means to access these devices, and they’ll accomplish it by one means or another. By engaging with instead of fighting that, we gain the ability to have a say on what those means are.
- smolder 8y agoIf I want to have a private conversation where the details of what are said are undiscoverable, I believe that's a right that people should have in a "free country", including over the internet, over phone, and so on. The fact is, I can, using some combination of math and secrets, accomplish this. I don't think anyone on earth has the right to collect/record/see the contents of my communications other than me and the other participants, until there's reasonable suspicion of a crime. Covert dragnet snooping is an evil means to any end, and it damages the moral standing of the society that does it.
- zerocrates 8y agoThe trick here is that the authorities will (somewhat reasonably) advertise their need for these tools under the "reasonable suspicion" label: they want the backdoor or whatever it is they need to conduct their surveillance once they do have reasonable suspicion.
- int_19h 8y ago> What’s not going to sell, and what the tech industry needs to get over is “lulz, it’ll impossible to intercept military or terrorist information because I need absolute privacy for my saucy emails”. I think it’s been empirically demonstrated that won’t happen. It's very much the other way. Strong encryption algorithms have been available to the public for a long time now. You can ban using them, but the only way to effectively enforce that ban would be for the government to require that all devices capable of running code from external sources run only code that's signed by that government. Without that, you can ban all you want, but terrorists and others who need that stuff will have it anyway. So the only effect would indeed be no privacy for saucy emails. Of course, intelligence agencies would love that, since it would allow them to have a society-wide dragnet.
- FakeComments 8y agoI disagree with your analysis — the way most people receive encryption, including criminals and terrorists, is through a provider. Regulating their behavior does change the general trend in security. Further, forcing them to implement their own encryption increases the likelihood they make a mistake while also refocusing the NSA et al to those algorithms instead. What we’ve seen is governments subverting encryption and systems repeatedly, in ways they wouldn’t if they had other methods. I’m not trying to accomplish some absolute ideological position, I’m trying to shift the state of affairs to realign incentives for several players. If some people write their own encryption, or the technologists use GPG everywhere, whatever. > allow them to have a society-wide dragnet I don’t think you even read my proposal: the mechanism I proposed makes that impossible, which is in contrast to the current state of affairs, where they subvert the security of the entire system instead of targeted people. Allowing for targeted cracking at a certain level of expense and requiring physical possession of the device in no way enables mass dragnets, and in fact, removes their legal cover by providing alternative means. I’m not saying people can’t invent their own security — just that factory made safes need to not be “unbreakable”, because it just incentivized bad behavior when they discover a flaw and/or subverting the integrity of the factory.
- baybal2 8y ago
- baybal2 8y agoFakeComments, can you tell who you are?