6 ms·
There is a subfield of cryptography called kleptography, which studies the "secure golden keys" talked about. The DUAL_EC_DRBG is a great example of how "golde
by bren2013 12y ago
There is a subfield of cryptography called kleptography, which studies the "secure golden keys" talked about.
The DUAL_EC_DRBG is a great example of how "golden keys" can be implemented securely, because the underlying problem is the same one that a lot of elliptic curve cryptosystems rely on.
Only the NSA could predict the output of the generator with the same level of security as ECDH or ECDSA.
- rcxdude 12y ago>Only the NSA could predict the output of the generator with the same level of security as ECDH or ECDSA. Only the NSA could generate the key initially. After that, who knows who will get access to it? You still have the same fundamental problem as with all backdoors, you've just eliminated one that most of them have (the fact that they're crap enough that you don't even need the back-door key to access them).
- pluma 12y agoIOW, it's not a technical problem, it's a social one. "The NSA" isn't a person. If "the NSA" has access to a backdoor that means there are possibly hundreds of people who have access to that backdoor, every single one being a mere human being. It's not a secure golden key in a glass box with the label "in case of emergency break glass". It's a note on a shared whiteboard in an open plan office.
- saganus 12y ago>Only the NSA could predict the output of the generator with the same level of security as ECDH or ECDSA. How do we know, and be sure that this is true?
- saganus 12y agoI don't know why I got downvoted and I love how people don't give the slightest explanation.
- srcmap 12y agoHow real is this issue? Isn't is true that today, I can easily clone iPhone's data by declaring I loss my phone and need to buy a new one and recover everything from iCloud? Isn't it just trivial for someone to "recover" your data by pretent to be you by court order, NSL or other means?
- tonyplee 12y agoI agree! Just listen to "Security Now" popcast from Steve Gibson. Steve's thought on how safe the data in cloud storage is by asking a question: "How easy is it for me to recover the data from your cloud service if I loss/forgot my password?" On iDevice, it is NOT that hard for the phone owner to do it. It is trivial for any government agencies fake the owner's phone #, txt Msg, email to recover or reset the iCould password.
- bren2013 12y ago> How do we know, and be sure that this is true? Predicting the generator's output reduces to solving the discrete logarithm on elliptic curves, which is incredibly hard unless you chose the private key. Just like in any asymmetric crypto scheme, given only the public key, it's very difficult to find the private key. (Actually doing it requires knowledge of how the generator works. I promise you it is easy given the private key, but you can go into its internals if you don't believe me.) > Isn't it just trivial for someone to "recover" your data by pretent to be you by court order, NSL or other means? Without a "golden key," somebody would have to ask you. With the "golden key," somebody would have to ask the organization in charge OR you.
- AnthonyMouse 12y ago> The DUAL_EC_DRBG is a great example of how "golden keys" can be implemented securely, because the underlying problem is the same one that a lot of elliptic curve cryptosystems rely on. I think it was Schneier who described encryption algorithms as being like a single fence post which is a thousand miles high. The vulnerability is not the encryption algorithm. The attacker is not going to break the encryption, the attacker is going to get access to the key. The ways attackers might do that have very little to do with cryptography. Espionage, corruption, social engineering, bureaucratic incompetence, completely unrelated vulnerabilities in government networks, etc.
- bren2013 12y agoSo what you're saying is, "golden keys" are no less secure than any other form of encryption. People are repulsed when you call it a back door or a "golden key," but "secure golden keys" are simply key escrows. Escrows are one of the first things you learn to build after asymmetric crypto. Escrows are well understood, secure, and generally regarded as a good idea. However, "back doors" are scary, sordid, and insecure?
- AnthonyMouse 12y ago> So what you're saying is, "golden keys" are no less secure than any other form of encryption. The encryption is using the usual cryptographic primitives. The problem is that the encryption is not the problem. > Escrows are well understood, secure, and generally regarded as a good idea. They are not. Because they're the same thing as back doors. Using key escrow as a method of e.g. password recovery is a security vulnerability. And at least then you're choosing who you trust and the trusted party doesn't have a nuclear neon target painted on it because the keys in escrow are only for specific parties rather than everybody everywhere. That's really the main issue. It is manifestly unwise to create a system which, if broken, yields the keys to everything. Because it makes the ROI of breaking it so enormous that the quantity and strength of the attackers you attract will overwhelm any imperfect system, and all systems are imperfect.
- 12y ago
- acqq 12y agoNot only NSA, everybody who gets to have a key could predict the output of the generator. In order for a key to be used, and those that promote it always want to use it, there would be enough copies of that key that very soon it would leak. Your assumption that ""golden keys" can be implemented securely" is wrong. The only secure golden keys are those not used. Which means, in order for such keys to be really secure they mustn't be created.
- NoMoreNicksLeft 12y ago> The DUAL_EC_DRBG is a great example of how "golden keys" can be implemented securely, Edward Snowden proved how this is far from secure. There are people from the NSA, who if they wanted to spy on a girlfriend, could walk out with those keys. The underlying problem is that you're no longer relying on technological security and mathematical certainty, but rather on human security and the capriciousness of people who earn $65,000/year to keep secrets. There's no security at all there.