4 ms·
You left out b) vendor has the keys stolen or leaked by a disgruntled employee and now the encryption is useless. That's the problem with all these systems, yo
by supergauntlet 7y ago
You left out b) vendor has the keys stolen or leaked by a disgruntled employee and now the encryption is useless.
That's the problem with all these systems, you're increasing the size of the attack surface enormously.
- pcl 7y agoIn practice, this happens frequently. We've seen this happen with TLS certificate authorities and with DRM solutions.
- tialaramex 7y ago> We've seen this happen with TLS certificate authorities Have we? I'm going to assume that you mean CAs in the Web PKI and not just "My friend Bob runs TLS and this has happened to the CA he was running on his Windows 10 laptop". The last CA where we had a really grave problem was DigiNotar, in 2011. It seem _very_ unlikely that the problem at DigiNotar was full key compromise, instead bad guys appear to have penetrated the issuance infrastructure. This means they were able to (and did) issue themselves arbitrary certificates, but it did not give them the actual keys as you've said "happens frequently". Since then we've seen a variety of unacceptable behaviour, including issuing backdated certificates to conceal the (also problematic) choice to continue doing something that was no longer allowed in new certificates, and issuing "test" certificates which would have been trusted by real client software even though their contents were known to be false. All unacceptable, and all having consequences (for example Symantec is no longer a CA) but all far short of "vendor has the keys stolen or leaked by a disgruntled employee".
- jimbob45 7y agoExactly what I was going to say. "The road to hell is paved with good intentions.".
- umvi 7y ago> You left out b) vendor has the keys stolen or leaked by a disgruntled employee and now the encryption is useless. e) If the keys are stolen, issue new keys to all devices The leaked keys are only good for physically compromised devices in the hands of people with access to the scanning electron microscopes, which I daresay is an extremely small attack surface. There is only a small window after the leak in which a device can be stolen, powered down, and compromised. On the other hand, you could mandate that such keys aren't allowed to be stored in databases (physical access only)
- the_watcher 7y agoYou don't always know that keys have been stolen. And an electron scanning microscope is hard to get now, but what about state-sponsored actors spending half a decade developing a pocket-sized tool? The whole point of E2E is that all of these scenarios are literally not possible.
- umvi 7y agoWell, periodically reissue keys then regardless of if you think they've been compromised. Or don't store the private key in a database, store on physical media in a vault that is airgapped and hard to access. Make the read-only-ability of the storage chip more difficult and onerous with each generation like paper currency security. My point it that you could make it so difficult to break E2E for even the most elite hackers that the only realistic way to do it is with a warrant.
- the_watcher 7y agoNot if you're sponsored by a hostile actor with functionally limitless resources. E2E isn't just about stopping legitimate law enforcement from conducting investigations.
- umvi 7y ago> Not if you're sponsored by a hostile actor with functionally limitless resources Like who? Russia? China? Here's how they can compromise my device: 1. Locate me within the USA (easy) 2. Send a spy onto US soil to find me and steal my phone (hard) 3. Send another spy to work for Apple (easy) 4. Spy needs to break into Apple's vault and retrieve airgapped media containing my device's private key without a warrant (super hard) 5. Send both back to the motherland and use scanning electron microscope to complete the process (easy) You really think that is viable? Seems extremely far fetched to me. Can you provide a more realistic scenario?
- kelnos 7y ago