6 ms·
This is two distinct questions rolled up: Why technically Why politically The technical issues are real and deep but they can, were, and continue to be tackl
by Adaptive 15y ago
This is two distinct questions rolled up:
Why technically
Why politically
The technical issues are real and deep but they can, were, and continue to be tackled. The bigger issue is that successfully addressing and deploying robust encryption solutions is not a political priority (quite the opposite).
Keep well in mind that for many online in the 90s, the assumption was that eventually standards for email encryption, as one example, would become well deployed. The fact that email is today routinely not encrypted (disregard ssl connections for the moment, a whole different barrel of fish) is a demonstration that interested power structures (governments, US primarily) were successful in limiting uptake.
There are real challenges to successful distributed crypto, but the political forces in play had the effect of early work withering on the vine for the most part.
- tptacek 15y agoI hear it all the time, but I think this is a pretty silly sentiment. Nobody wants the entire Internet encrypted more than the giant banks that Redditors believe control the political system. What malign forces do you believe the government is actually wielding to retard adoption of crypto? Who controls how much of the Internet is encrypted? Because the Internet is an end-to-end system design, the two parties most responsible for crypto adoption are your browser vendor (which vigorously supports crypto adoption), and the people who run servers (most of whom vigorously support crypto adoption). The onus is on you to provide evidence to back your silly argument up.
- rdl 15y agoIt was absolutely the case in the 1990s that much of the government actively retarded crypto deployment. The whole ITAR/export control thing (40 bit as a compromise) was a HUGE factor in keeping crypto out by default. Then there was the clipper thing and proposals for key escrow. And, A5 on GSM being weak. Outside of payments, where the government and industry have pushed for strong integrity and authentication (although not really confidentiality), government and big corps have hindered the deployment of crypto. There has been some improvement in the past decade or so, at least in other regulated areas, both in regulation and in industry self-regulation/compliance standards. I think the majority of the reason cryptography isn't more widely deployed is that it's 1) hard to do well and 2) most people writing applications have a hard enough time getting a non-encrypted form working and 3) few people make it a requirement as a customer. However, government has definitely hindered ubiquitous crypto deployment.
- tptacek 15y agoYou are absolutely right that the government had an overt, irrational, and hostile reaction to encryption in the '90s. I dealt with it firsthand writing security code for a Canadian company. But that was the 1990s. The government does not in 2011 believe you are shipping "munitions" when you allow open downoads of software that incidentally encrypts traffic. People do it all the time now. And, to be fair to the government: nobody saw the mainstream Internet coming, and prior to that, crypto basically was a munition. I agree with your (1) (2) and (3) reasons. I just don't see anything the government is doing today, or in the last 10 years or so, to hold back an encrypted Internet. The people I know in government who think about this stuff would dearly like to see a more secure Internet.
- leot 15y agoIt's so trivial for Gmail to do PGP that it was testing email signatures two years ago (http://googlesystem.blogspot.com/2009/02/gmail-tests-pgp-signature-verification.html http://googlesystem.blogspot.com/2009/02/gmail-tests-pgp-sig...) Indeed, Yahoo, Hotmail, and Gmail could get the ball rolling here completely transparently to users and with relative ease, thereby preventing thousands of phishing attacks in the process. If they did, then webmail would suddenly become useful for talking to banks, stockbrokers, foreign dissidents, avoiding craigslist scams, etc. etc.. But not only have Gmail et al not implemented any features like these, but they've not even uttered a peep as to why. Their silence here is conspicuous.
- tptacek 15y agoAs someone who uses PGP on a daily basis: I have zero confidence that e.g. my mom could make any sense of it. It doesn't help that Gmail, a web app, has no secure was of implementing PGP with people's "real" public keys. Apple bakes encrypted email into Mail.app. It has an almost transparent UX. Nobody uses it. Demand is what's holding back encrypted email. Nobody cares about it.
- luser001 15y agoOK, I'll bite. :) I belong the camp which says Gmail's lack of encryption is "conspicuous". Look at Ubuntu: they're constantly improving the user experience of encrypted home directories. In the latest release, this is as simple as checking a box during account creation (it creates the keys under the hood and uses your login password as the passphrase for the data key etc). Also re: gmail has "no secure way". I read the white paper written by your company on the problems with encryption and javascript. AFAIK, if all traffic is exchanged only over SSL, I don't see any reason why encryption can't be done in Gmail in javascript (unless you're going invoke quality of the random number generators of browsers). Here's an UX I can think of: (1) generate key pairs in the background in the browser for all gmail users. (2) transparently use this to encrypt to users within gmail. Start from there. Then add the ability to import keys of contacts.
- 15y ago
- DanBC 15y ago> Nobody wants the entire Internet encrypted more than the giant banks Why is so much bank security nothing more than ridiculous security theatre? I agree they have the money, they have the need, they have enough smart programmers; so why do they fail so hard at security?
- T-hawk 15y ago1) They don't have enough smart programmers. Nobody does, since "enough" means every single one. It only takes one CRUD screen with an SQL injection or buffer overrun exploit to get owned. By definition, a large amount of code must tend towards average quality. 2) Selective perception. We only notice when they fail. On the whole maybe they do do a pretty good job and nobody notices when things aren't wrong. 3) Sometimes it's an insider job. 4) Dumb users; no amount of company security can stop a successful phish or keylogger or whatever. 5) Cost-benefit. Sometimes it really isn't worthwhile to pour as much security as you possibly can at a problem. What if a bank guarded every transaction by having a live operator call the customer at a pre-known number? Sure that's pretty stiff security, and completely impractical in a competitive capitalist marketplace. That's an extreme example but it goes to prove the point. Sometimes it's cheaper just to clean up aftewards. Security is a thorny problem; you can't always just magically have more security by throwing more money at it.
- tptacek 15y agoThese are great points. Regarding #2: most of the banks we've all heard of are huge companies with hundreds of apps. A breach in any of them, even a brochureware app, is reported as if it was a full-blown bank heist. Serious incidents do happen at banks, but when you hear about them, odds are it isn't the retail account management system that broke