10 ms·
Considering Schneier has been outspoken for decades about the importance of open source cryptography, I asked if he recommends that other people use BestCrypt,
by alyx 11y ago
Considering Schneier has been outspoken for decades about the importance of open source cryptography, I asked if he recommends that other people use BestCrypt, even though it’s proprietary. “I do recommend BestCrypt,” Schneier told me, “because I have met people at the company and I have a good feeling about them. Of course I don’t know for sure; this business is all about trust. But right now, given what I know, I trust them.“
Uhh what?
So following that same logic, if I know people at Microsoft who wrote the code for BitLocker, and I trust them, I should trust BitLocker.
- drzaiusapelord 11y agoI've said it before: Schneier is an empty suit. He knows what buttons to hit in geek culture to get viral traffic, but a lot of what he preaches is questionable and seemingly personal and subjective. If anyone else would have said this they would have been instantly buried.
- nickpsecurity 11y agoHe's far from an empty suit given the diverse work he's done that's arguably good. He does occasionally make spot judgments that seem weak and go in what I believe is the wrong direction at times. Unlike many, I post counterpoints to him each time on his own blog and he makes no attempts to censor/grayout those via moderation. He rarely gets into those debates: we sort them out instead. Yet, he lets it all stand for his crowd to read. Not the typical action of either someone trying to hide their incompetence or an ego-maniac. This attitude of his is why a number of us contributed there for years. Plenty of what we posted also pre-empted the Snowden leaks (incl many TAO attacks). Plenty to learn archived over there.
- jron 11y agoBruce's comment is quite bizarre. Here is a slightly better quote from him in 2013: "Be suspicious of commercial encryption software, especially from large vendors. My guess is that most encryption products from large US companies have NSA-friendly back doors, and many foreign ones probably do as well. It's prudent to assume that foreign products also have foreign-installed backdoors. Closed-source software is easier for the NSA to backdoor than open-source software. Systems relying on master secrets are vulnerable to the NSA, through either legal or more clandestine means." The article would have been far better if they only included Microsoft's answers and ended the piece with the same line: "Whatever you choose, if trusting a proprietary operating system not to be malicious doesn’t fit your threat model, maybe it’s time to switch to Linux."
- dragonwriter 11y ago> So following that same logic, if I know people at Microsoft who wrote the code for BitLocker, and I trust them, I should trust BitLocker. Not entirely unreasonable [0] -- a significant benefit of open-source is that more people have access to the code of the same software you are evaluating, so its more likely that you will be able to find a trusted evaluator (or, if you have the skills to do the evaluation, to do it yourself) -- and that you will likely have more trustworthy evaluators, as well. But, ultimately, yes, its a question of trust in people who are familiar with the code , and what Schneier describes is a not unreasonable basis for personal trust in closed-source code, its just harder to get than a comparable basis for trust in open-source code. [0] The problem in both cases is that there are more people involved that you need to trust, although sufficient trust in and information from the people writing the software could suffice to trust the software.
- Lawtonfogle 11y agoExcept there is absolutely no reason to trust a corporation. Even the most trustworthy can be forced to betray that trust by the powers that be.
- sliverstorm 11y agoWhy doesn't that apply to open source contributors? They can be bought or coerced too. If we are assuming some malevolent entity powerful enough to manipulate the world's largest companies like marionettes, I don't see why we think open source is safe.
- caskance 11y agoBecause if it's open source, I don't need to trust anyone. I'm totally going to review the source code and build the binaries myself. One day. After writing the next chapter of my book.
- michaelmrose 11y agoSafer. Its a matter of degree.
- Lawtonfogle 11y agoThere is little assumption needed to know there is collusions between powerful corporations and government spy agencies. Open source isn't fully trustable either, especially by the vast majority of users who are unable to review the source. But it is better, and we should not let perfect be the enemy of better in this case.
- nickpsecurity 11y agoExactly. The code and executable might not match. As in obfuscated C, the code might be subtly designed to fail. Further, the code might work but be integrated with libraries or deployed on an OS that the enemy knows they can hit. The security case of a given piece of software always depends on the reviewers and knowing you're using what they reviewed. That this is usually lacking in vast majority of software is why we're seeing a ton of vulnerabilities in both commercial and FOSS software.
- derefr 11y agoI think the "good feeling" is supposed to be about their cryptographic experience and expertise. The second point about trust doesn't directly flow from the previous sentence (which would make it sound like he's saying something like "I trust this person sight-unseen"); instead, he's just meaning that cryptography (like any technology) ultimately requires you to trust someone at some point, because you can't audit every line of every piece of software and firmware you're sitting on top of. And because of that, while there can be a point where you know "enough" about a particular codebase's architecture and management to have faith in its stewardship (or enough to not have faith in said stewardship—OpenSSL, for example), you can't really ever know everything there is to know about a codebase now-and-forevermore such that you no longer have to trust anyone about anything.
- jkyle 11y agoSomewhat. But that's a pretty thin link of trust. People change jobs and I doubt the people he knows personally know every line of code either. In the end, he's trusting MS the company as a whole. Generally when I 'trust' open source, it's not a specific person I'm trusting. More so, I "trust" that given the millions of programmers in the world that will look at this code there will be one with similar interests to me that will catch any nefarious bits that slip in. I think these two kinds of trust are categorically different. One providing much more permanence than the other.
- nickpsecurity 11y agoMostly likely it's the kind of intuitive guess-work common for those those who've been reviewing black-boxes for years. You get what technical detail you can [which may be lies]. Past that, the competence, attitude, and priorities of the organization will tell you more about the estimated quality/security of their product than anything else. He apparently saw these were good at BestCrypt. So, if you can't use open-source, then he says use this company that seems more qualified and with better intentions than others (esp Microsoft!). So, he prefers we have or use open-source crypto where we can but recognizes many won't be able to. He gives them the best option he's seen in proprietary sphere for modern Windows boxes. Incidentally, that's the best that can be done outside of reverse engineering. That's how thin our trust baseline is in commercial crypto. It's why I pushed for a paid, open-source model with independent review below: https://www.schneier.com/blog/archives/2014/05/friday_squid_bl_424.html#c6051639 https://www.schneier.com/blog/archives/2014/05/friday_squid_...
- tptacek 11y agoWhat "guesswork"? What "black box"? Microsoft's code is the most comprehensively reverse-engineered in the world. Somehow, between the beginning of the Linux era and, say, 2005 or so, people forgot how to efficiently comprehend large assembly programs. But it's not 2005 anymore; it's fully ten years later. Virtually every software security team in the world has multiple people on staff who know what basic blocks and control flow graphs are. There are credible open-source competitors to IDA, and arguably the best disassembler currently available costs something like $80 and backs assembly out to C. Closed source software imposes meaningful, significant costs. It's reasonable to prefer open-source code, or even to require it. But we cannot reasonably make the excuse that closed-source code is a "black box" anymore.
- nickpsecurity 11y agoThat's all so irrelevant to our discussion I wonder why you bring it up. The point is that a black box takes the kind of effort you describe to review: "meaningful, significant costs" most can't or won't invest using specialist skills or tools most don't have. Are you telling me you fully reverse engineer all the state and code paths in every proprietary offering you consider along with a robust evaluation against known vulnerabilities? Or do you look at their stated claims, prior/current credibility, and perform some basic evaluation? Most of us do the latter for economic reasons and that leaves proprietary software as a black box. As for Microsoft, there's all kinds of people reverse engineering their code with most doing it to write exploits. So far, nobody has shared a link to a bug-for-bug compatible source equivalent for Bitlocker to analyze for cryptography issues. I'd just be taking someone else's word that (a) they R.E.'d it enough to see all potential subversions, (b) they had the skill to spot clever subversions with little context, and (c) they weren't lying to me. Please link to papers showing such a full deconstruction of the Bitlocker code with a hash that we can use to confirm it's the same on our machines. It will boost everyone's confidence in the product. Otherwise, you're talking like it's been rigorously R.E.'d and reviewed while providing zero citations to back that. Meanwhile, the Internet is full of citations on Microsoft's security failures and deceptions. Status quo stands until you deliver proof otherwise.