6 ms·
IMHO second answer does not hold water. If you will end up in situation where you are tortured they will torture you until you will you say how to add the backd
by daliusd 2y ago
IMHO second answer does not hold water. If you will end up in situation where you are tortured they will torture you until you will you say how to add the backdoor.
- tptacek 2y agoHis point is that he can't backdoor it: you can read the code before you install it. I'd go further, and say that this is true of anything end-to-end encrypted, open-source or not, because it's not 2002 anymore and reversing ordinary client software is table stakes. (I'd still rather run something open source, ceteris paribus).
- inopinatus 2y agoFeeding the paranoia above is that cperciva would verifiably be the smartest person in the room. A canny torturer would respond to this bringing in djb as the primary instrument of torture. "First one to break or weaken scrypt or 8-round salsa20 gains their freedom". The loser is forced to give talks at AWS marketing conferences for the rest of their natural
- h0l0cube 2y ago> A canny torturer A canny torturer would read the Smart People on a public forum red-teaming cperciva's mind.
- cperciva 2y agoReversing ordinary client software is table stakes, sure. I'm not so sure about reversing client software which has a deliberately hidden backdoor. (You can hide a backdoor in source code too, of course, but I think it's easier to hide one in a binary because you could e.g. ensure that a buffer overflow overwrites cryptographic keys, where a C compiler would have the freedom to change the memory layout.)
- tptacek 2y agoWe can just disagree here for now, since we agree directionally, and I think people should use Tarsnap.
- dragonwriter 2y agoNot being able to "backdoor it" (presuming this means "exploit a backdoor the torturer presumes you have already put into it") does not prevent you from getting tortured to backdoor it. All it does is, should that occur, prevent you from giving the torturer what they want to end the torture. OTOH, convincing the torturer by, among other means, public statements in advance that you have failed to consider this anhd believe that not having that ability prevents torture, and that for this reason you do not have it, might prevent torture. But that's a big gamble on potential future torturers believing your public statements of motivation.
- tptacek 2y agoTarsnap is software you compile and install yourself. He literally can't backdoor existing installations of it.
- dragonwriter 2y agoExploitable but obscured backdoors in software distributed in form that is compiled and installed by downstream users is not impossible, though sufficient auditing may make it improbable.
- voxic11 2y agoHe probably should have said that if it's what he meant. In his answer he implies that he could in fact back door it but chooses not to because of the liability.
- willsoon 2y agoNo, he won't, because there is no back door. Or yes, because his torturer-contractor thinks there is. Either way, the last part of your sentence doesn't hold water.
- cperciva 2y agoI could be coerced into adding a back door in future versions of Tarsnap, yes. But I can't be coerced into adding a backdoor into past versions of Tarsnap, because I don't have a time machine.
- fragmede 2y agoCoerce you into sending something like "All users must upgrade to client version xyz because of a backdoor discovered by the NSA in the encryption used in older clients. I'm not allowed to tell you what it is, however, rest assured, the latest versions do not have this vulnerability." (but do have a backdoor that I've been tortured into adding). And then wait for a scheduled backup with the backdoored client. Though XZ says that's impossible, so I won't lose sleep over that scenario.
- cperciva 2y agoI am confident that if I sent a message like that, the top application security and cryptography experts in the world would collectively descend on the Tarsnap source code to figure out what changed.
- vizzah 2y agoColin, have you thought to decrease storage pricing, it hasn't been reviewed for ~10 years and Tarsnap costs are currently very prohibitive.. :(
- aftbit 2y agoAgreed. Honestly, I really wish the Tarsnap server was open source. I imagine it has not been released as such because that would probably hurt the business a lot, especially given that the costs per GB are currently approximately 50 times more than I would pay for simple object storage on B2. I built our company's first backup solution on Tarsnap, but when I projected out what deploying that to our entire fleet would cost, I rebuilt on Restic. We currently pay something like $250/mo for our backups, as opposed to the approximately $12,500/mo they would cost on Tarsnap.
- whs 2y agoIt could be designed that doing so will generate some alarm to other people. For example, the backdoor do not exists and it has to be developed, so the attacker has to keep them hostage for some period of time and loved ones may report a missing person. The software then might have to be signed with a key that generate alert to the whole engineering team, which someone else in the company may investigate the unauthorized release as cyberattack. Perhaps the release signing key is physically stored in the office (eg. Yubikey) which also require the attacker to perform a heist in the office. Surely some three letters organization probably could pull that off, but it add risk to their operation that the operation could be leaked.
- cperciva 2y agoSurely some three letters organization probably could pull that off, but it add risk to their operation that the operation could be leaked. This is basically a point I've made in a few of my talks about security and cryptography: The point of cryptography isn't to guarantee that your data is safe; it's to raise the cost of an attack to the point where a potential attacker decides not to attack. In particular, there's usually a human involved somewhere (sending or receiving information, or both) and humans are squishy and fragile; but torturing people attracts far more adverse attention than torturing data.
- kstenerud 2y agoOr, you know, hire ANOTHER software engineer to add the backdoor. Probably cheaper and less hassle and less illegal. In either case, you'd have to fool the internet army, who are watching the source code of projects such as this like a hawk.