7 ms·
Talk about the power of inertia when attempting to change consumer behaviors. Also, we still haven't had an easy to use open tool set to make usage of Public K
by devy 6y ago
Talk about the power of inertia when attempting to change consumer behaviors.
Also, we still haven't had an easy to use open tool set to make usage of Public Key Cryptography friendly to average Joes. No, GnuPG doesn't count - it's hard to use and cumbersome to configure it securely. You need to be a cryptographer or a mathematician to pick the right parameters in order to stay current and secure. Definitely not friendly even to most programmers.
- AmericanChopper 6y agoThe problem isn’t the tools. It’s that there is no such thing as an operable PKI. The best PKI (by far) is the CA system, and the CA system is not a good PKI. It has so many holes, and the PKI evangelists don’t like it anyway, because it uses trusted authorities. The only other examples of remotely useful PKIs in existence are things like Signal/WhatsApp... and those are even worse PKIs, because TOFU PKIs are in practice authenticationless PKIs.
- bleepblorp 6y agoI think most of the PKI trust issue, at least with regard to financial transactions, could be solved with government involvement. Governments could sign, or issue, PKI keys when they issue identity documents and business licenses. There's much less room for impersonation fraud if the keys used by businesses and people to identify themselves electronically are tied to their foundational identity documents. Obviously, using government-controlled PKI for communications would be unwise, but there's very little risk to using government PKI for financial transactions as governments already have warrantless access to this data.
- AmericanChopper 6y agoI think a government controlled PKI authority, especially one that required real identity authentication, would possibly be the solution that would make the least number of people happy.
- dnautics 6y agowithout even broaching conspiracy theories or secret organizations it's not like government has a stellar track record of dealing with data it promises will be kept secret and single-purpose (for example SSNs).
- nradov 6y agoThe government never promised to keep SSNs secret.
- GoblinSlayer 6y agoWell, in PKI a CA doesn't keep much secret data. SSN is a symmetric shared secret, not PKI.
- bleepblorp 6y agoWhy? Even if you don't have to show government ID for every financial transaction, you need to show government ID (and, often, a lot more government paperwork) to open a financial account that can be used to make transactions. Your ability to move money is entirely predicated on the banks knowing who you are by linking your accounts to a tombstone government identity document. Using PKI controlled by government to authenticate identity for transactions doesn't give government any more control over your affairs than it already has. All it does is add one more layer of authentication to the transaction process by allowing all parties involved to verify that their counterparty is the legal entity they claim to be.
- GoblinSlayer 6y agoI'm afraid if the government ID becomes ubiquitous, there's a danger of abuse that all systems will require it for everything and I doubt government will certify pseudonymous IDs. I'd say have banks as independent CAs, one or several keys per bank.
- nradov 6y agoThere would be huge room for impersonation fraud even with a government run PKI. Hackers would steal private keys from individuals and businesses using the same malware and phishing attacks that they use today for stealing credit card numbers.
- tialaramex 6y agoThe important difference is that credit card details are a shared "secret". You can't use your credit card number and CVV with Amazon without giving those numbers to Amazon, which is the exact same thing a crook would try to trick you into doing. Whereas the whole point of a public key system is that nobody needs your private key. So we don't need to provide individuals and businesses with a way to give their private key to somebody else. The only reason you'd give your private key to somebody else is because you want them to seamlessly impersonate you forever, so there's no need to make it any easier than, for example, giving your kidney to somebody else. Concrete example: A WebAuthn/ U2F "Security Key" offers no way to get the Private Keys out. If you want to "steal" the credentials used to get into my GitHub your best bet is to somehow trick me into physically packaging up the USB authenticator itself and sending that to you by FedEx or something. Or maybe you could try putting a knife to my throat or something?
- pteraspidomorph 6y agoThat system is already in place in several european countries. https://en.wikipedia.org/wiki/National_identity_cards_in_the_European_Economic_Area#Electronic_identity_cards https://en.wikipedia.org/wiki/National_identity_cards_in_the...
- corty 6y agoWith lots of BS like EIDAS remote "signatures". I wouldn't necessarily trust this for anything important.
- tW4r 6y agoWhat are the downsides of EIDAS? They’re widely accepted and used in my home country and I personally have a great experience, although I wish there was a way I could generate my own private key and or at least acquire it so I could script my own solutions rather than depending on third party providers
- corty 6y agoMost of EIDAS is quite fine, but there are really stupid ideas in there. Remote signatures are signatures where the key user is not the key owner. The key is located with some service provider who signs with the user's key on request. The security of this is as useless as it sounds, but for many situations here in Germany it is the only option because there are no officially accredited providers for signature card certificates anymore. Therefore it is all the bother of digital signatures with the insecurity of analogue signature stamps...
- tW4r 6y agoOh yes that is exactly what I meant by not having access to the keys, I use one of such services myself. I do however consider them a bit more secure than signature stamps as should the provider become compromised, their upstream certificate would be revoked, to my understanding this would invalidate all of the signatures. The same as any CA
- fanf2 6y agoChip and PIN cards are based on a PKI with the payment networks acting as CAs. Used by millions of people every day. https://www.cryptomathic.com/hubfs/docs/cryptomathic_white_paper-emv_key_management.pdf https://www.cryptomathic.com/hubfs/docs/cryptomathic_white_p...
- AmericanChopper 6y agoThat only works because it’s hidden from the user, and can only work on highly regulated approved devices. Try giving a user a private key for making CNP transactions, and all you will have achieved is replicating the user experience of bitcoin.
- boomlinde 6y ago> Try giving a user a private key for making CNP transactions, I have that! > and all you will have achieved is replicating the user experience of bitcoin. I've never used bitcoin or any other cryptocurrency. What's the user experience like?
- GoblinSlayer 6y agoYou just have the target wallet address and the "send" button, zero bullshit, like paper money.
- gooseberry 6y ago> zero bullshit lol
- seized 6y agoExcept for drawing the rest of the owl... Getting a wallet, the knowledge of keeping it secure, transferring real money to crypto, knowing which crypto system to choose/use.... There's a lot of layers of "bullshit" before you get to "Just hit send".
- michaelt 6y ago
- astura 6y agoThe US DoD has a perfectly useful and operable PKI infrastructure https://www.cac.mil/Common-Access-Card/CAC-Security/ https://www.cac.mil/Common-Access-Card/CAC-Security/
- torgian 6y agoHaha, the “CAC” as we liked to call it. It is a pretty secure system I think, but government procedures make it a pain to work with.
- jacobwilliamroy 6y agoYes it's very close. The only reason it will fail for private citizens is the device needs to be easily auditable for correctness. The auditing process needs to be at least simple enough that children in public schools can be taught how to assess their PKI dongle to make sure it's real and trustworthy.
- tialaramex 6y agoI'm guessing "the CA system" refers to the Web PKI†. Any Public Key Infrastructure has a Certificate Authority role, so attempting to distinguish the Web PKI by the existence of this role makes no sense. This also makes your next sentence nonsense, anyone advocating for PKI is advocating for a technology that has trusted authorities, that's how it works, it's as though you claimed computer evangelists don't like mathematics because it uses symbol manipulation. And then it makes your next sentence nonsense, something like Signal isn't a PKI, it has no CA role, who "Janet" is on Signal is only a matter for you and Janet. Signal also isn't purely TOFU, you can insist on manually verifying every identity just as you can on SSH. But even though I believe the Web PKI is the only successful public PKI there are plenty of other PKIs in use that are successful in a narrower sphere, and we're already in a discussion thread about such a sphere, the global banking system. † The Web PKI isn't strictly just a PKI for the World Wide Web, it's actually a PKI for TLS services on the Public Internet. But it exists only because Netscape built SSL, and in practice its oversight is from the major browser vendors (most notably Mozilla but of course also Microsoft, Apple and Google). There was once a good chance the only TLS client implementation you had with any useful PKI enforcement was your web browser, today it's likely other tools on your system also do this... but always relying on the Web PKI.
- TheSpiceIsLife 6y agoIt does not have to be perfect, just better than existing payment card numbers, for that specific use case anyway. And also just as simple to use.
- vmception 6y agoOne thing we’ve been able to leverage with cryptocurrency is that the “wallets“ have standardized some public-private key cryptography. So some aspects of our products dont “need a blockchain for this” but the proliferation of standardized signing tools and size of the niche has made it extremely viable to cater to that market. PGP had 30 years to get anywhere, and all we have are some pretty bad, cumbersome businesses releasing poorly integrated signing software on modern OS’ that even privacy advocates can barely tolerate for their email and other messages. People want to try to say the same thing about cryptocurrency over half of a decade or a whole decade but they’ll just have to wait for the Ivy league business school case studies to start coming out about the rest of us that have already figured this out for business. Turns out changing consumer behavior isn’t hard when there are economic incentives to do so that benefit the consumer.
- ineedasername 6y agoThe more abstract the benefits are to consumers, the more even a little friction becomes hard to overcome when changing behaviors.
- deleted 6y ago[deleted]
- ahnick 6y agoIMHO, Keybase is the best example of a friendly tool for public key cryptography. It's really a shame that Zoom acquired them. I still think their stitching together a secure identity based on the aggregation of people's social media accounts is a great approach. Maybe that idea will be incorporated into other tools eventually.