6 ms·
Are there any existing cryptographic algorithms which allow for two keys to un-encrypt a piece of cipher text?
by FourierTformed 7y ago
Are there any existing cryptographic algorithms which allow for two keys to un-encrypt a piece of cipher text?
- rubbingalcohol 7y agoPGP
- danShumway 7y agoI can think of setups that would allow this, but I don't understand what the advantage would be over sharing keys. Honest question, if I have a key that can unencrypt all of your data, why is it important that it not literally be your key?
- scarejunba 7y agoBecause then I need a way of giving you my key that doesn’t give the bad guy the key.
- extropy 7y agoIt's useful to have a master key that decrypts everything. For each message that means encrypting for two keys - the recepient and the master key. The obvious drawback being the huge damage when a master key is inevitably leaked.
- deleted 7y ago[deleted]
- michaelmrose 7y agoIts trivial and common to have one or more than one key that unlocks the actual key that is in fact used to decrypt data see LUKS the standard for full disk encryption on Linux for example. This trivially lets you change your passphrase without rewriting all your data on disk. It's also useful for recovering data that the user has forgotten their self set passphrase or wont share it in case of a hostile ex employee. Furthermore one can have multiple passphrases and revoke one if it is known to be compromised. For the governments concept on it see "key escrow" and the clipper chip fiasco https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Clipper_chip Problems are legion and multifaceted. To put it briefly based on past actions no reasonable party would trust the US government to be respectful of their rights and privacy nor even competent enough to keep a secret. It would force the entire world of computer security to be shackled and standardized upon what an incompetent bureaucracy understands and it would be a disaster inside a year. If one recalls a lot of current woes with malware can be traced back to one of their geniuses that took home a hard drive full of tools and lost it all to the bad guys. https://www.nytimes.com/2019/05/25/us/nsa-hacking-tool-baltimore.html https://www.nytimes.com/2019/05/25/us/nsa-hacking-tool-balti... If a golden key that unlocked everything in existence came into being it would be in the hands of state actors within 30 days and everywhere next year. It has always required monumental arrogance and profound lack of foresight to suggest we should backdoor all security for the benefit of the keystone cops and their current fearless leader Sergeant Shultz here. As the iconic tv character used to say "I know nothing. Nothing!!"
- xyzzyz 7y agoGovernment generates a public/private key pair Gpub/Gpriv, and publishes the public part. It also requires the following scheme to be used: if you want encrypt a message M with a key P, you generate random key K, encrypt M with K to obtain Enc_K(M), encrypt K with Gpub to obtain Enc_Gpub(K), and encrypt K with P to obtain Enc_P(K), and then send this triple (Enc_K(M), Enc_Gpub(K), Enc_P(K)). This way, either of the P or Gpriv can be used to decrypt M (you just use it to first decrypt K, and then decrypt M). This scheme is as strong as the scheme used for encryption is, and no cryptography is weakened by its use, except of course a huge negative impact in case Gpriv leaks. With stakes this high though, you could bring likelihood of leak to be very low, and you could modify the scheme to mitigate the impact of the leak. I don't like it as much as anyone else, but unfortunately I think this is viable in practice. Of course, nothing stops you, a hacker, from using non-backdoored encryption, but government is fine with that, as long as Google, Apple, Facebook etc. are forced to use backdoors.
- nybble41 7y ago> Of course, nothing stops you, a hacker, from using non-backdoored encryption, but government is fine with that, as long as Google, Apple, Facebook etc. are forced to use backdoors. Which just goes to show that this isn't actually about catching hardened criminals (who will just use non-backdoored encryption, either alone or layered on top of the compromised channels) but rather about enabling pervasive surveillance of ordinary citizens.
- xyzzyz 7y agoNot necessarily. There is a middle ground between the two: common criminals that simply use the tools that Google, Apple etc create to make security for normal people easy. If it's effortless to enable full end to end encryption on your phone, then not only will your grandpa enjoy benefits of it, but also a cocaine dealer or a burglar trying to fence stolen goods. But yes, I think that there are lower-hanging fruits available for pick up here. I wish we lived in a reality where backdooring encryption was the best available path to reduce crime.
- 7y ago