3 ms·
USB stick... I'm sure it'll work out great. What if you have to give it up with a gun to your head? << Many of them are talented technical people that will hav
by backdoorsgalore 7y ago
USB stick... I'm sure it'll work out great. What if you have to give it up with a gun to your head?
<<
Many of them are talented technical people that will have no problem avoiding government backdoors in commercial software and hardware products
>>
Hand wavy as heck.
Then you meander. Not sure what you're responding to.
- michaelmrose 7y agoIt's trivial to lock the USB stick in such a fashion as to be impossible to decrypt in a practical time frame. Furthermore it's practical to communicate in such a fashion that grabbing one party only grants you access to communication intended for this party. If really paranoid it might only grant you access to communication between compromise and his fellows realizing that he is burned. Maybe nothing at all if you can't successfully coerce and all devices are locked.
- backdoorsgalore 7y agoAll public encryption algorithms have backdoors in their implementation and sometimes (as with Elliptic Curve standards from NIST adopted in the browser) in their spec. You might get lucky if you have a cryptographer design you a custom algorithm but that's mostly security thru obscurity and if a state actor really wanted to defeat it they may just kidnap the cryptographer at gun point and have them reveal how to. Cryptography as a weapon against state actors is NO LESS BRAINLESS than the right to bear arms to protect against the US gov. Just completely useless, if not brain dead.
- adrianN 7y agoEncryption is not trivial to implement right, but it is also not impossible to defend against reasonable threat models. You make claims without giving any proof.
- AdieuToLogic 7y ago> All public encryption algorithms have backdoors in their implementation ... Okay, this is the first time I can recall having ever asked the following: Source? I mean, if you're going to make that type of absolute claim, I must ask for some referenes to support same.
- jonathanstrange 7y agoAlthough you're right that anything but OTPs give you guarantees and that cryptography is still a black art (with lots of unrealistic conditional proofs), good cryptography can be completely open and will be no less secure if it is published, so there is really no need to kidnap the cryptographer. There is also good reason to assume that if e.g. you make your own Feistel cipher out of existing cryptographic primitives without caring too much about performance, then it will be secure enough against state actors. Nowadays side channel attacks seem to be the rule, and there is no way to secure the endpoints without developing the whole technology in-house - which is essentially impossible even for organized crime. So the whole discussion is essentially moot, the FBI can buy 0-day exploits on the black market or develop their own like everyone else.
- backdoorsgalore 7y ago<< There is also good reason to assume that if e.g. you make your own Feistel cipher out of existing cryptographic primitives without caring too much about performance, then it will be secure enough against state actors. >> The key is "your own" By "public" I don't mean that their spec is "published" but that their implementation is open source and has various 3rd party contributions and dependencies, as is the case with most OSS. So if you build your own, and it's good against the NSA, they'd come after you if they have to, unless it costs them less to crack it. I agree ultimately with your assessment that side channel attacks make this whole discussion moot. But my original point was and still is: nothing is secure against a determined and well resourced adversary. So people out there shouldn't get the wrong idea that cryptography is an invisibility cloak or some such
- necovek 7y agoIf this was the case, there would be no push in government sectors to diminish cryptography and provide backdoors. Or perhaps they are double-bluffing us? ;-)
- backdoorsgalore 7y agoThe "government" is not one coherent entity. Also, its primary goal is the oppression, intimidation and subjugation of the masses, not logical thinking.
- authoritarian 7y ago>All public encryption algorithms have backdoors in their implementation and sometimes (as with Elliptic Curve standards from NIST adopted in the browser) in their spec Lets see your proofs demonstrating this
- jonathanstrange 7y ago> It's trivial to lock the USB stick in such a fashion as to be impossible to decrypt in a practical time frame. That is definitely not true if your adversary has the ability to control the endpoint and might even reflash the firmware of your USB stick. If you use OTPs in such a threat scenario it's safest to use old school easy-to-burn paper OTPs with manual encoding/decoding.
- Nasrudith 7y agoThe whole point of a one time pad is that it is never used again and destroyed after use. Even the sick fucks in the CIA don't think they can get a key sequence from you with torture or threats after it has already been stomped and put in a microwave.
- backdoorsgalore 7y agoI thought he meant a series of pads on a USB stick exchanged in advance. If you're trying to get just one message across that's very easily doable as you say, and with many other ways. But if you're trying to establish a real bidirectional communication scheme that doesn't involve meeting at Starbucks every Wednesday ... different story.