4 ms·
While I agree that its horrible for agencies to be doing this, I must also say - if it is breakable, then it is not good enough. We shouldn't have to worry abo
by binarymax 13y ago
While I agree that its horrible for agencies to be doing this, I must also say - if it is breakable, then it is not good enough. We shouldn't have to worry about whether someone can break encryption or not. We shouldn't have to guard the guards. The factors of morality and ethics and trust needs to be removed from the equation entirely, because there will always be parties that are not moral, ethical, or trustworthy. This is happening at a good time in history. There are people who are doing what they can to make sure it doesn't happen again. We've only had the internet for 30 years. Lets patch it now.
- Nursie 13y ago>>if it is breakable, then it is not good enough. And if the agencies are steering people towards crypto they know is broken but the public do not?
- binarymax 13y agoOf course there will always be entities who try to break the system - either through technical, political, or social means. Fortunately the existing agencies who had enough power to do this have lost their credibility, so I doubt they will be steering people back anytime soon. I am not sure if what I said above is even possible, but I hope it is. Trying to remove the side effects of humanity from something created by humans is not an easy task.
- venomsnake 13y agoThen the agencies are endangering their own countries. It is simple math - the world produces much more geniuses that NSA employs (or GRU or anyone). If you deliberately introduce weakness someone will find it. And the entity may not be friendly. The problem comes because the win of the cold war somewhat skewed the western view of their own capabilities. When NSA had adversaries that they deemed worthy - they took the effort to strengthen everyone's communications. Right now while looking at the others with disdain and (wrongly) refocused the efforts on terrorism - they prefer weak networks.
- masklinn 13y agoThe title is somewhat unclear, but the issue TBL has is not the cracking itself — as he notes this is a risk and race the internet normally faces — but the deliberate weakening and introduction of flaws into cryptosystems for the purpose of later snooping: > it's naive to imagine that if you introduce a weakness into a system, you will be the only one to use it. A lot of the IT industry feels that's a betrayal. [...] The two governments have elevated the fight against organised hacker gangs and militarised cyber-attacks from states such as China to the rank of a top national security priority. Yet at the same time their spying branches have actively aided cybercriminals by weakening encryption. and the effect this has on users through lowered confidence in the privacy of exchanged information.
- logfromblammo 13y agoThere is no free lunch. Securing your communications against every possible attack has a cost. If the cost is so high that even the intended recipient cannot pay it, that may be as bad or worse than transmitting in the clear. It will always be an arms race between defenders and attackers, because the cost of everything changes over time. You will always have to worry about some genius getting struck by a satori that makes your entire encryption scheme worthless. The problem is akin to someone in the shipbuilding business worrying about the discovery of a beam that can reduce the strength of a 1-cm thick steel plate to 1-cm thick toilet paper--and the effect is not attenuated by normal matter. The inventor could build a facility in the hinterlands that could instantly and tracelessly sink any steel ship, anywhere in the world. That is what encryption designers are up against. TBL is upset because intel agencies have been quietly quashing non-vulnerable schemes and/or actively promoting vulnerable ones, paying no heed to the possibility that their enemies might also have some geniuses, or that their own geniuses' ideas might replicate and leak outside of their info-fortress.