5 ms·
Never roll your own security if you actually want security, either. What are we supposed to do :).
by bowmessage 5y ago
Never roll your own security if you actually want security, either. What are we supposed to do :).
- robertlagrant 5y agoIt's don't roll your own crypto, not security in general.
- dankent 5y agoIt's definitely a dilemma. I guess the sweet spot would be security systems that are well understood in house but built on existing, well understood and studied standards and theory. A starting point might be to use battle-tested open source systems but subject them to detailed in-house analysis and audit.
- sharklazer 5y agoOh, indeed, unless you're DJB, never roll your own. I mean you should understand what you're doing and why you're doing it, not leave it up to someone else to make decisions for you. Not that you should re-invent the wheel. :-)
- isoprophlex 5y agoUse one time pads
- GuB-42 5y agoOne time pads are really inconvenient and hard to get right. That's why they are almost never used in practice, despite being theoretically perfect. First, you need to generate large amounts of unbiased, true random data. If it is not true randomness, you have a stream cypher, and if you "rolled your own", probably not a good one. They you have to store the one-time pad. It is usually too big to memorize. You have to store in on a device like a USB stick or a book, and guard it well. Then, you have to share the secret, and for that you need a secure channel and that shouldn't rely on encryption, because it would miss the point. Essentially, you need to meet in person, in a secure location. Then, you need to make sure that the one-time pad really is one-time. It should be securely destroyed after each use, preferably on both ends.
- VLM 5y agoIF you want to send arbitrary data. Usually people don't need that. For something like coke smuggling you just need to know its on the way, get ready. So the OTP could be something as lame as "if you get a phone call from some rando who says 'Taste the Feeling'" then the next boat is full of coke, or if not, then the next boat is not full of coke". Actually terrible idea as taste the feeling was a coke company slogan a couple years back, but you get the general idea.
- rtkwe 5y agoYou generally need more information flow than that to successfully coordinate a big logistics move like this though which is where you need arbitrary messages.
- vkou 5y agoMost criminal activity involves communicating arbitrary data. Communicating that a drug boat is coming across a border is a tiny fraction of the communication in a criminal organization. In the scenario you described, planning out the communication protocol itself is an example of communicating arbitrary data... That needs to happen, at every physical hand-off point.
- VLM 5y agoInterestingly, no. I had recently finished reading both books by Robert Mason, who started out flying helicopters for the Army in Vietnam and ended up smuggling literal tons of weed and got caught and did federal time. Pretty interesting autobiography. Anyway my comments fit pretty well with his description contained in his second book. Mr Mason got caught by bad luck. There will always be small timers who do things small timer style who get caught by being verbose and oversharing, and to catch those we'll have "encrypted" smartphones.
- VLM 5y agoIn this situation that would leave you open to network analysis and location analysis, even if no payloads were decryptable. Using enough data warehousing and artificial intelligence, eventually some algorithm would notice that every time some dude gets a phone call, next month the same boat gets a bill for servicing its water intakes, and a month later coke supply increases in .au decreasing the price. Might take a few times, but someone's getting caught. The best part is if they go in shooting on a warrant and kill some random completely uninvolved people, it was all an algorithm's fault and nobody is to blame and I guess we just need more police involvement and surveillance to prevent future tragedies.
- notyourday 5y agoIf you have a way to security distribute one time pads you don't actually need one time pads as you have a way to security distribute the messages as the one time pads are higher than the size of the messages you are distributing.
- isoprophlex 5y agoNevertheless you can distribute your pad once and communicate over clear channels for a long time. You might even schedule regular communications to avoid being caught by traffic metadata analysis.
- gooseus 5y agoRemain insecure in your security or else be completely unsecured.
- anyonecancode 5y agoI always took this as "you're not a domain expert so you'll get it wrong", with the implied corollary that if you actually _are_ a domain expert, then you know what you're doing. IOW, hire bonafide domain experts rather than trying to cheap out.
- Buttons840 5y agoWhy not both? Encrypt your message with your home grown encryption, then send it through standard TLS. Both would have to fail for the message to be revealed. Sometimes when I'm wearing my tinfoil hat I wonder if the advice to avoid rolling your own crypto is a conspiracy. The powers that be want to maintain their backdoors, maybe? Probably not. Of course, it's definitely true that there are more attack vectors out there than an amateur can be aware of.
- petschge 5y agoThe main warning against rolling your own crypto is because you would (or would be tempted to) replace standard crypto with it.
- generalizations 5y agoI also wonder why there's such a pushback against one-time-pads. The common critiques don't seem to be any greater of a risk than the holes we've already encountered (e.g. heartbleed). I think I remember a scifi story that mentioned some character who worked in the one-time-pad shipping business. I guess a spacecraft full of data storage can hold enough random data to last for a long time. Seems like we should at least come up with a proper protocol for it, so we can at least get started with something that's broadly compatible.
- rtkwe 5y agoUnless you’re using a true random number generator that works on a mechanical/electrical process a lot of encryption algorithms are various ways of creating a one-time pad. And they save a lot on space which used to be precious. With a single key much smaller than a megabyte I can encrypt essentially endlessly where for the normal OTP process I need as much random data as there is data to be encrypted which gets unwieldy extremely quickly even with cheap storage.
- nybble41 5y ago> Unless you’re using a true random number generator that works on a mechanical/electrical process… …you're not using a one-time pad. OTP requires the pad to be truly random: at least one bit of unique, never-used-elsewhere entropy for every bit in the message. Merely XORing some plaintext with a pseudo-random stream based on a smaller seed, which as you say is the basis for various other encryption algorithms, is not a one-time pad. The real problem with OTP is key distribution: You need to share pads with everyone you might want to communicate with, one pad per sender/receiver pair, and those pads need to be at least as large as all the message you'll eventually want to exchange. There is no OTP equivalent to public-key cryptography where you only need one private/public keypair per recipient.
- reilly3000 5y agoIf you do roll your own and you’re not a high value target (aka there aren’t a lot of assets they can seize or are a notorious criminal) nobody is going to take the time to bust open your homegrown setup. Security by obscurity is powerful. There is a reason why Wordpress sites get hacked a lot: the exploit has a lot of leverage with 1/4 to 1/3 of the public web using it.
- Andrew_nenakhov 5y agoDo not rely on technical means to solve an administrative problems. Vito Corleone didn't have messenger apps, email or ERP systems, but his enterprise ran like like a clock. So should yours.
- phpnode 5y ago1. That was way before the advent of smart phones and most technological surveillance techniques. 2. It was fictional.
- Andrew_nenakhov 5y ago1. That's it, if you don't use phones for your criminal activities, most modern technological surveillance techniques will not be effective against you. 2. There were a lot of non-fictional organizations that ran just fine without any modern means. Genghis Khan conquered a lot of countries without relying on radio for communications or satellites for reconnaissance. Using a WhatsApp-like chat apps to communicate about criminal activities is very convenient, but opens a new vector of attack against you.