3 ms·
> Using key escrow as a method of e.g. password recovery is a security vulnerability. I have no idea what you mean by "security vulnerability" in this case. K
by bren2013 12y ago
> Using key escrow as a method of e.g. password recovery is a security vulnerability.
I have no idea what you mean by "security vulnerability" in this case. Key escrows are the primary way asymmetric crypto is used in practice. An escrow recovers the symmetric key a message was encrypted with and you proceed as normal.
> the trusted party doesn't have a nuclear neon target painted on it
By that logic, government agencies should operate exclusively by typewriter. They don't because crypto primitives are designed to be secure against unrealistically strong adversaries. No crypto paper has ever said, "Our construction is secure in the standard model as long as the ROI is less than epsilon."
You can go down the path of "what if there's another Snowden, and it's a snow day in Kentucky...," but you aren't doing cryptography anymore--you're just developing mild paranoia.
- AnthonyMouse 12y ago> I have no idea what you mean by "security vulnerability" in this case. Key escrows are the primary way asymmetric crypto is used in practice. An escrow recovers the symmetric key a message was encrypted with and you proceed as normal. You're using an unusually broad definition of what "key escrow" means. http://en.wikipedia.org/wiki/Key_escrow http://en.wikipedia.org/wiki/Key_escrow And your definition is covering the scenarios that nobody would call a back door, so I'm not sure what point you're trying to make. Giving a third party access to your private information is a security vulnerability unless you can trust the third party, and "you can trust the government" is a statement contrary to evidence. > By that logic, government agencies should operate exclusively by typewriter. They don't because crypto primitives are designed to be secure against unrealistically strong adversaries. No crypto paper has ever said, "Our construction is secure in the standard model as long as the ROI is less than epsilon." Once again, the crypto is not the issue. Nobody is expecting the attacker to solve the discrete logarithm problem. But breaking the cryptosystem is not the only way to obtain the encryption keys. You have a serious security vulnerability if the expected value of the attacker obtaining the secret key is larger than the amount of money required to bribe the relevant government employee(s). Or if the servers the government keeps the keys on are vulnerable to heartbleed/shellshock/whatever at any point after attackers learn of the vulnerability, regardless of the strength of the escrow cryptosystem. > You can go down the path of "what if there's another Snowden, and it's a snow day in Kentucky...," but you aren't doing cryptography anymore--you're just developing mild paranoia. It's not doing cryptography at all. It isn't a cryptographic problem. The strength of the cryptography makes little difference because the cryptography is not the weakest link.
- simonh 12y agoThat's an excellent rebuttal and I agree completely, but there is another issue with the golden key concept. If the key was only ever goign to be kept ina secure vault burried under Fort Knox forever, it woudl probably not constitute a significant vulnerability. That's the picture golden key proponent paint when they describe such a system. The problem is that government agencies have demonstrated very clearly that they will use such a key as often and as liberally as they can get away with. Every time the key is brought out and used, it becomes vulnerable to interception or disclosure to the point where pretending that it is sure to be safe is just completely out of touch with reality.
- freshhawk 12y ago> If the key was only ever going to be kept in a secure vault buried under Fort Knox forever, it would probably not constitute a significant vulnerability I think that's the main point when people disagree about this kind of thing. One side says "but theoretically our fort knox vault solution would be secure" and the other side says "What I just heard you say is 'If I sprinkle magic pixie dust around this intentional vulnerability and ignore it then it would be secure' and that's ridiculous, a group of humans would not almost certainly not act securely around that vault because they never have". Of course the "other side" is right, but people don't think that way naturally so this kind of proposal/argument keeps coming up.
- SixSigma 12y agoEvery crypto system and physical security includes a caveat that states ROI < epsilon.