3 ms·
The security improvements due to Elephant certainly are not proveable (what in crypto truly is?). I argue that there is meaningful security added by Elephant, c
by xnull 12y ago
The security improvements due to Elephant certainly are not proveable (what in crypto truly is?). I argue that there is meaningful security added by Elephant, clunky though it certainly is - because it does make block modification attacks (which could be used to thwart "Secure Boot") and in that 'poor man's authentication' is better than no man's authentication. Here the perfect very well may be the enemy of the good. Of course I would be happier with something even better.
> Popping up a level further on the stack: I'm rebutting the claim that NSA coerced MSFT into removing Elephant. It was a marginal implementation of a marginal countermeasure that wasn't relevant to NSA.
Not sure whether this is strong enough evidence to be considered a rebuttal. I do not know and will not claim that it was the NSA (or other) coercing MSFT.
> Popping up a level further on the stack: I do not believe that NSA has within the last decade coerced Microsoft into doing anything cryptographic.
Not the NSA key? Not the removal of end-to-end crypto from Skype and then onboarding of Skype to PRISM? Not the SEA hacking of FBI request documents? Not bitlocker keys automatically uploaded to OneDrive, and OneDrive onboarded to PRISM? Not TPM 2.0 support - not Germany's leak of TPM backdoors - not China's following ban of TPM 2.0 and Windows 8.1 - not Microsoft's then downport of TPM 2.0 support to Windows 8?Not the cloud key escrow patent?
"Once a request comes in from a third party (e.g. a user, a business, a legal entity or governmental entity, etc.) to access user's data, the data storage system may send..."
https://www.google.com/patents/US20120321086 https://www.google.com/patents/US20120321086
"MS, working with the FBI, developed a surveillance capability to deal with the new SSL... went live Dec 2012" - Snowden docs
http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPlaceToHide-Documents-Uncompressed.pdf http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl... (30)
You probably think Microsoft did these things without NSA/TLA coercion.
- tptacek 12y ago"What in crypto truly is provable" is where I get off this train.
- xnull 12y agoHey I love (and defend) crypto but ultimately it relies on (sometimes standard) assumptions like the one-way hardness of discrete logarithms. Symmetric systems hardly have underlying information theoretic garuntees - usually symmetric constructs are based on reductions under random oracle models (which have has its own methodological problems). Furthermore implementations are hardly the same as mathematical constructs, which gives rise to side channels. These are not controversial views - they are common knowledge among cryptographers. It is thus an injustice to knock Elephant on 'provability' grounds. The papers for Elephant (and Lion before it) follow standards for peer reviewed work in cryptography. It is a shame you will not reply to any of the examples in the remainder of the comment. But other HN readers will see them.
- tptacek 12y agoTiniest violin playing for the loss of another pointless discussion about NSAKEY. https://www.schneier.com/crypto-gram-9909.html https://www.schneier.com/crypto-gram-9909.html
- xnull 12y agoThe crypto bit is perfectly reasonable in this context as Elephant meets the standards for crypto publication in this regard. You excuse leaks water. Where you can no longer reasonably hold your position is where you got off the train.
- xnull 12y agoYou've downvoted the content rather than replying to it. I'll repeat it again, for the benefit of the larger HN community (and you can get you jollies downvoting again). "MS, working with the FBI, developed a surveillance capability to deal with the new SSL... went live Dec 2012" - Snowden docs http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPlaceToHide-Documents-Uncompressed.pdf http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl... (30) Microsoft stripped security from newly deployed TLS, worked to undermine TPMs, store copies of your Bitlocker keys for law enforcement, hand cloud data to law enforcement and stripped crypto from Skype. They either did this all on their own voluntarily, were encouraged or pressured, or where forced. Choose your demon.
- tptacek 12y agohttps://www.dropbox.com/s/pqy5un1vzcho6a4/Screenshot%202014-11-09%2022.42.47.png?dl=0 https://www.dropbox.com/s/pqy5un1vzcho6a4/Screenshot%202014-... https://www.dropbox.com/s/bswum0iz8ggfheo/Screenshot%202014-11-09%2022.43.16.png?dl=0 https://www.dropbox.com/s/bswum0iz8ggfheo/Screenshot%202014-...