4 ms·
So what you're saying is, "golden keys" are no less secure than any other form of encryption. People are repulsed when you call it a back door or a "golden key
by bren2013 12y ago
So what you're saying is, "golden keys" are no less secure than any other form of encryption.
People are repulsed when you call it a back door or a "golden key," but "secure golden keys" are simply key escrows. Escrows are one of the first things you learn to build after asymmetric crypto.
Escrows are well understood, secure, and generally regarded as a good idea. However, "back doors" are scary, sordid, and insecure?
- AnthonyMouse 12y ago> So what you're saying is, "golden keys" are no less secure than any other form of encryption. The encryption is using the usual cryptographic primitives. The problem is that the encryption is not the problem. > Escrows are well understood, secure, and generally regarded as a good idea. They are not. Because they're the same thing as back doors. Using key escrow as a method of e.g. password recovery is a security vulnerability. And at least then you're choosing who you trust and the trusted party doesn't have a nuclear neon target painted on it because the keys in escrow are only for specific parties rather than everybody everywhere. That's really the main issue. It is manifestly unwise to create a system which, if broken, yields the keys to everything. Because it makes the ROI of breaking it so enormous that the quantity and strength of the attackers you attract will overwhelm any imperfect system, and all systems are imperfect.
- bren2013 12y ago> Using key escrow as a method of e.g. password recovery is a security vulnerability. I have no idea what you mean by "security vulnerability" in this case. Key escrows are the primary way asymmetric crypto is used in practice. An escrow recovers the symmetric key a message was encrypted with and you proceed as normal. > the trusted party doesn't have a nuclear neon target painted on it By that logic, government agencies should operate exclusively by typewriter. They don't because crypto primitives are designed to be secure against unrealistically strong adversaries. No crypto paper has ever said, "Our construction is secure in the standard model as long as the ROI is less than epsilon." You can go down the path of "what if there's another Snowden, and it's a snow day in Kentucky...," but you aren't doing cryptography anymore--you're just developing mild paranoia.
- AnthonyMouse 12y ago> I have no idea what you mean by "security vulnerability" in this case. Key escrows are the primary way asymmetric crypto is used in practice. An escrow recovers the symmetric key a message was encrypted with and you proceed as normal. You're using an unusually broad definition of what "key escrow" means. http://en.wikipedia.org/wiki/Key_escrow http://en.wikipedia.org/wiki/Key_escrow And your definition is covering the scenarios that nobody would call a back door, so I'm not sure what point you're trying to make. Giving a third party access to your private information is a security vulnerability unless you can trust the third party, and "you can trust the government" is a statement contrary to evidence. > By that logic, government agencies should operate exclusively by typewriter. They don't because crypto primitives are designed to be secure against unrealistically strong adversaries. No crypto paper has ever said, "Our construction is secure in the standard model as long as the ROI is less than epsilon." Once again, the crypto is not the issue. Nobody is expecting the attacker to solve the discrete logarithm problem. But breaking the cryptosystem is not the only way to obtain the encryption keys. You have a serious security vulnerability if the expected value of the attacker obtaining the secret key is larger than the amount of money required to bribe the relevant government employee(s). Or if the servers the government keeps the keys on are vulnerable to heartbleed/shellshock/whatever at any point after attackers learn of the vulnerability, regardless of the strength of the escrow cryptosystem. > You can go down the path of "what if there's another Snowden, and it's a snow day in Kentucky...," but you aren't doing cryptography anymore--you're just developing mild paranoia. It's not doing cryptography at all. It isn't a cryptographic problem. The strength of the cryptography makes little difference because the cryptography is not the weakest link.
- simonh 12y agoThat's an excellent rebuttal and I agree completely, but there is another issue with the golden key concept. If the key was only ever goign to be kept ina secure vault burried under Fort Knox forever, it woudl probably not constitute a significant vulnerability. That's the picture golden key proponent paint when they describe such a system. The problem is that government agencies have demonstrated very clearly that they will use such a key as often and as liberally as they can get away with. Every time the key is brought out and used, it becomes vulnerable to interception or disclosure to the point where pretending that it is sure to be safe is just completely out of touch with reality.
- Zigurd 12y agoThis many years after Clipper, you are really claiming key escrow as a legal requirement for doing business in the US is a practical idea? You really don't know how many bad outcomes would have arisen from Clipper?
- willvarfar 12y agoSchneier's blog explains his stance on this in great detail consistently over many years. Key escrow is a back door. Schneier has generally moved focus from designing and breaking cryptography (although he was a key contributor to the Skein SHA3 candidate) to the bigger aspects of risk. And trusting the government or any third party is risk. You'll like his blog.