6 ms·
Every cryptographic protocol has a weakness in its implementation if not in its spec (and if not in the tool itself then in its various dependencies)
by backdoorsgalore 7y ago
Every cryptographic protocol has a weakness in its implementation if not in its spec (and if not in the tool itself then in its various dependencies)
- senectus1 7y agoAny tool can be used to undo itself... if not directly then by proxy.
- ProfHewitt 7y agoThis is one reason that NIBOR requires that a new virtual machine can always be installed to fix issues with the previous one.
- lazyguy2 7y agoUhh.. no. In fact it doesn't. If your goal is to secure the entire internet via SSL or get people to use PGP signed emails in a mass market then the tremendous technical and cultural hurdles in place that create making a 'truly secure' implementation that gets widely accepted a near impossibility. But if you goal is to secure the communication between trained people in a 'terrorist cell' or other small group then that is pretty easy. It's really as hard as you want it to be. For example any decent programmer could write a program that utilizes a 'One Time Pad' of random data to encrypt communication. A program in a USB flash drive that is filled with randomly generated data and the program is all that would need to be exchanged ahead of time. The biggest challenge involved in that is making absolutely sure that the every section of the one time pad used is only used once and is destroyed afterwards. You don't need to really know anything about encryption or math or protocol details to make something like that work. And if correctly done it'll be impossible to crack. And we are dealing with threats and adversaries that are much more sophisticated then that. Even small terrorist groups are more often then not state-funded one way or another. Foreign threats are sophisticated enough to create their own encryption. Domestic threats and cartels are sophisticated to hire competent programmers to do work for them. Pedophiles are not idiots either. Many of them are talented technical people that will have no problem avoiding government backdoors in commercial software and hardware products. The threats American face via encryption isn't that encryption is too strong. It's that Americans don't use it enough and don't use it properly. I find the idea that Americans are under threat due to lack of backdoors a fallacious one. Legislating that backdoors need to put in place only increases threats. The only thing that laws like that would accomplish is to make it illegal for Americans to be secure. Take away legal ability to have secure software then it means that the only people who will have secure software is criminals. Criminalizing good software is never going to be productive.
- backdoorsgalore 7y agoUSB stick... I'm sure it'll work out great. What if you have to give it up with a gun to your head? << Many of them are talented technical people that will have no problem avoiding government backdoors in commercial software and hardware products >> Hand wavy as heck. Then you meander. Not sure what you're responding to.
- michaelmrose 7y agoIt's trivial to lock the USB stick in such a fashion as to be impossible to decrypt in a practical time frame. Furthermore it's practical to communicate in such a fashion that grabbing one party only grants you access to communication intended for this party. If really paranoid it might only grant you access to communication between compromise and his fellows realizing that he is burned. Maybe nothing at all if you can't successfully coerce and all devices are locked.
- backdoorsgalore 7y agoAll public encryption algorithms have backdoors in their implementation and sometimes (as with Elliptic Curve standards from NIST adopted in the browser) in their spec. You might get lucky if you have a cryptographer design you a custom algorithm but that's mostly security thru obscurity and if a state actor really wanted to defeat it they may just kidnap the cryptographer at gun point and have them reveal how to. Cryptography as a weapon against state actors is NO LESS BRAINLESS than the right to bear arms to protect against the US gov. Just completely useless, if not brain dead.
- adrianN 7y agoEncryption is not trivial to implement right, but it is also not impossible to defend against reasonable threat models. You make claims without giving any proof.
- AdieuToLogic 7y ago> All public encryption algorithms have backdoors in their implementation ... Okay, this is the first time I can recall having ever asked the following: Source? I mean, if you're going to make that type of absolute claim, I must ask for some referenes to support same.