4 ms·
> they should also not have no clue at all. Over an over again, politicians are asking for backdoors. To me it just proves that they don't understand the very b
by dataflow 2y ago
> they should also not have no clue at all. Over an over again, politicians are asking for backdoors. To me it just proves that they don't understand the very basic of how encryption works.
Unless you're claiming that it's literally impossible to construct a cipher with multiple decryption keys, I don't see how you're implying that asking for a backdoor "proves they don't understand the very basics of how encryption works".
Their stance differs from yours due to their values being different from yours, not due to inferior literacy.
- whatshisface 2y agoIt is impossible to construct a cypher with just one key, such that the good guys (spanning several allied nations, dozens of government agencies, perhaps even local police) can use the key, but bad guys (spanning several opposing nations, dozens of intelligence agencies, thousands of hacker groups, tens of thousands of individual cyber-criminals around the world) cannot. We are talking about every single person who can buy a copy of a piece of paper carried out of HQ being able to read all of your personal and professional correspondence: no doubt a possibility.
- dataflow 2y agoYou're missing my point completely. These folks very well understand that bad people can steal keys. Stolen keys have been a thing since antiquity. It's not rocket science they don't understand. Every single key in history has had a risk of theft and this is no exception. The truth is a lot of them understand this just like you. But unlike you, they are willing to accept this risk. You aren't. That's fine. You have a value disagreement -- you don't think the risk is worth it, and they think it is. Which is why you make arguments about the merits of the issue, instead of attacking the other side on their basic literacy. Just because you disagree on values that doesn't mean the other side is stupid or illiterate about the basics. This isn't about politeness either, it's actively counterproductive to your own cause: insulting people and showing that you lack a basic understanding of their position is a sure-fire way to make sure they dig their heels in and continue to oppose you regardless of the merits of the situation. i.e. it's a grest strategy for losing in the end.
- whatshisface 2y agoI don't believe that France is actually willing to accept that every opposing intelligence agency will obtain the key...
- dataflow 2y agoMaybe they don't think it's as likely as you think. Or maybe they think the time horizon is long enough that it is worth it. Whatever it is, I assure you they are not too stupid to realize this is a possibility. They just differ on either the degree of the risk, or on the value they get in return. In which case, logic dictates that if you believe the actual risk is higher than they would tolerate, to find a way to convince them of that.
- whatshisface 2y agoThat's a matter of facts rather than values. The "impossible promise" is that a private company can keep a kilobyte of data out of the hands of every spy agency on Earth for any length of time.
- immibis 2y agoWhy does this concern apply to the French intelligence agency but not, say, the code signing certificate for Whatsapp?
- whatshisface 2y agoOn one level it does apply to certificates. On another level, pushing a compromised update to every phone in Europe (to gain access equivalent to having a copy of the backdoor) would be noticed by the publisher, and the binary difference would quickly be found by security researchers.
- AshamedCaptain 2y agoAnd yet the immense majority of the population accept & use messaging platforms operated by "not France" where the operator would be able to obtain everyone's key with a couple clicks. (Yes, this includes Apple's).
- throw0101b 2y ago> It is impossible to construct a cypher with just one key […] Technical nit: I (mis?)remember reading in a cryptography book (by Schneier?) that the NSA has at least one algorithm where the decryption key is different than the encryption key, but my search-fu finds no references to it online. The application would be for devices in 'hostile territory' where there was a risk of capture of the unit and so you didn't want the other side to be able to alter data/firmware since the cipher that is available is decrypt only. However, see perhaps: * https://crypto.stanford.edu/~dabo/abstracts/traitors.html https://crypto.stanford.edu/~dabo/abstracts/traitors.html * https://crypto.stackexchange.com/questions/39397/one-encryption-many-decryption-keys https://crypto.stackexchange.com/questions/39397/one-encrypt... Also, see n-of-m algorithms: * https://en.wikipedia.org/wiki/Shamir%27s_secret_sharing https://en.wikipedia.org/wiki/Shamir%27s_secret_sharing
- adgjlsfhk1 2y agothe problem with backdoored encryption isn't making a cypher with multiple decryption keys. It's keeping secret that's worth billions of dollars and shared among 10s of thousands of people. The difference between backdoored encryption and no encryption is whether the backdoor is known to the public. There is a coherent set of values that lead to saying "no encryption", but not one for "only backdoored encryption".
- tshaddox 2y ago> There is a coherent set of values that lead to saying "no encryption", but not one for "only backdoored encryption". While I oppose building backdoors, I don't really agree with this claim. There's nothing incoherent about developing a threat model.
- whatshisface 2y agoI think some threat models, like one that doesn't include hackers, are not coherent relative to reality.
- tshaddox 2y agoA threat model can include hackers while not taking every action that could prevent every conceivable attack from a hacker.
- adgjlsfhk1 2y agoYour government isn't the only one out there. If your government can have a backdoor, so can every other government. If the US, EU, Russia, and China all have backdoors to everything, who are you keeping it secret from?
- cmonreally123 2y agoThe powers that can't pay? If the US, EU, Russia, China all have nukes to everything...
- 2y ago
- palata 2y agoI upvoted because I don't think you should be censored, but I kindly disagree :-). To me (and I think that's the position of cryptography-aware people), requesting a backdoor is a risk so high that it makes absolutely no sense. Of course, they understand that if an adversary gets access to the backdoor, then it's game over. And of course, they believe that it's possible to prevent the adversary from accessing the backdoor. But that's my whole point: their believing this means that they don't understand the problem.