5 ms·
The USG reserves the use of backdoor-free software and strong encryption for itself, so I'm not sure that this is a worry with regard to the recent data breach.
by themeek 11y ago
The USG reserves the use of backdoor-free software and strong encryption for itself, so I'm not sure that this is a worry with regard to the recent data breach.
The FBI means that consumers and foreign markets should not have encryption or backdoor-free software. I understand that this is a double standard, but we need to be clear that the double standard doesn't have to do with this most recent breach.
- mc808 11y agoIt is relevant in the general sense that it would only be a matter of time before a "massive data breach" included the keys/procedures to open some or all of the backdoors.
- themeek 11y agoI see. This has already been done. During Operation Aurora the Chinese hacked into the FBI backdoor built into GMail by Google and used it to gather information about intelligence operations being performed by the United States against Chinese nationals and also used it to perform surveillance of their own against their terrorist and dissident watch lists. There are probably more examples. I do not know of a single database that has 'all the keys' to the all software and encryption back doors. If such a thing existed it would be a very valuable target. Somehow, though, I imagine that there isn't such a centralized database.
- yellowapple 11y agoThere isn't such a centralized database yet. With NSA surveillance and FBI calls for backdoors, that is quickly changing as various three-letter-agencies gobble up all the data they physically can and in the process make themselves easy and obvious targets.
- themeek 11y agoThis seems sort of speculative to me - at least too speculative to base (important) policy on. The way the US government would be likely to handle this situation is that they would recognize the threat and mandate that no such single database be created or that one be separated were it to exist. I don't know that they would change their mind about backdooring products and services when they can mitigate the scenario and address concerns a much easier way.
- Splendor 11y agoThat's interesting. I'm unfamiliar with Operation Aurora. Can you recommend a good source for more information?
- themeek 11y agoEven the Wikipedia article is pretty good. Honestly I would recommend Googling around for it. There's bound to be declassified aspects to the attacks you can trace down if you are dogged, but it's likely you'll find everything you want with standard internet search.
- packetslave 11y agoDuring Operation Aurora the Chinese hacked into the FBI backdoor built into GMail by Google and used it to gather information about intelligence operations being performed by the United States against Chinese nationals [citation needed]
- deleted 11y ago[deleted]
- themeek 11y ago"operation aurora fbi backdoor" https://www.google.com/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=operation%20aurora%20fbi%20backdoor https://www.google.com/webhp?sourceid=chrome-instant&ion=1&e...
- meowface 11y agoHmm, I don't think you're totally right. >Former government officials with knowledge of the breach said attackers successfully accessed a database that flagged Gmail accounts marked for court-ordered wiretaps. To me it sounds like Gmail was compromised, and during the compromise, the attackers identified a database containing information that was of great intelligence value to them. This database does not appear to have been the vector that allowed the attackers to get in, nor was it a "backdoor". I suspect the attackers also had access to many, many other databases. It's certainly possible the primary intended goal of the breach was to access this information (for counter-intelligence purposes), but it's not how they actually got in, nor did it help them get in.
- themeek 11y agoContinue to read. You will find that this was the target of the operation. It was not the vector that allowed them to get in (not soley). It is usually the case that a successful breach gives very wide access, so I would suspect this as well. I think you'll find that on the whole I am right. That the system was there for US intelligence and the Chinese were there for counter-espionage and that the backdoor allowed the Chinese used the system to access email information that they would have had to compromise a different way to get - thus their getting access through a back door.
- mc808 11y agoI doubt there could be such a database today, but I'm thinking in terms of a scenario where all "secure" communications channels available to the public are required to choose from some list of compromised encryption standards. Perhaps each company would maintain its own keys at first, but after a few cases of being unable to comply with court orders because someone lost the keys, the obvious next step would be a central registry.
- themeek 11y agoI understand this. Such a database would definitely be a juicy target. Concentrating backdoor keys and information is unwise. I'm not sure we want to base policy on something speculative like that. Agreed that conversations should be had - both about widespead backdoors and about centralizing the keys to these backdoors - if the scenario ever comes to pass. In the meantime we can't say that the backdooring contributed to this Chinese attributed breach.
- mc808 11y agoI don't see anyone claiming a backdoor contributed to this breach in particular. It's just a bit ironic (and convenient, frankly) that the news would break on the same day an FBI official calls to further weaken U.S. digital security under the extremely dubious assumption that the U.S. government, now and forever, would be the only power capable of exploiting those weaknesses.
- themeek 11y agoIt is ironic in a certain sense. Comments here unfortunately were and are linking the two in a causal way rather than just pointing out the double standard. The point of these backdoor programs is that there is an asymmetry in how the vulnerabilities can be exploited. The point being that the calculus has been done - right now the benefit to national security (the place of the US in the 'world pecking order' - it's ability to project power and protect its strategic interests) is greater than its detriment to national security. Now, it absolutely does weaken 'personal security'. Broken encryption, backdoors, weak protocols, federated auth, these things decrease the digital security of companies and persons. As a person not involved in performing the calculus of national security (again global strategic interests) it is easy to see these programs as merely a threat with no obvious gain. Those concerned with national security and global competition see this as a small price to pay to wield a large amount of global influence. This is a good way to understand why the FBI will say things that seem so plainly wrong to the HN crowd. I happen to agree with the HN folk wisdom - that the national security apparatus is there to protect our democracy not the other way around - but to really engage with the issue its important to understand what the 'other side' is arguing more fully. This is a very complicated space. Very important policy scholars (Sunstein) even recommends reinterpreting free speech to mean something closer to what we've historically criticized China for. Going forward we need as much informed debate as possible. The national security apparatus isn't going to listen to the public if the public can't understand the issues they grapple with and engage it charitably. I hope I didn't rant too long.
- higherpurpose 11y agoBut the government will use this as yet another excuse to pass more cyber surveillance laws. Also, with the FBI promoting an anti-encryption culture and the NSA promoting an anti-security culture in terms of what laws politicians should pass, it's only a matter of time before that culture spills into the government's own agencies, too. For instance, politicians can be brainwashed so much by the NSA/FBI that encryption is some "dark sorcery that only terrorists and child pornographers use" to the point where they'll start voting against bills that aim to secure government's websites and so on.
- themeek 11y agoIt's likely that scare tactics and politics will use whatever justification they can to achieve their goals - including politicization of large media events.
- Zigurd 11y agoThat's not really how it has worked. CAs can't be trusted because, in part, the USG wants to corrupt them as needed. Encryption systems get weakened because the NSA wants to be able to break them. Vulns don't get reported. Etc. It isn't a "double standard." The tech industry well has been poisoned in the same of surveillance.
- themeek 11y agoThis is right, but it doesn't address my comment. Did this play a role in the breach? Almost certainly it did not.
- yellowapple 11y agoNo, but it means that breaches like this will be even more dangerous to the American public, since now such breaches will have the potential of exposing access to "secure" backdoors and the wealth of surveillance data various LEAs have accumulated.
- themeek 11y agoThere's other threads here were people suggest this. It seems pretty speculative to me that there's some large database with all of the mandated software backdoors and keys to get access to. And if it existed, I don't know that it would be such a large threat. Certainly security bugs and professionals inside of industry are targeted by hackers already. Given everything else, I don't know how large an issue this is (compared to say, hacking nuclear defense systems, energy grid, military C2C, etc). It would be interesting to see whether this is considered a threat scenario by the USG.
- yellowapple 11y ago> It seems pretty speculative to me that there's some large database with all of the mandated software backdoors and keys to get access to. You overestimate the competence of government agencies. > Given everything else, I don't know how large an issue this is A significantly large issue, seeing as it puts the safety of the vast majority of Americans at risk by exposing their personal information (everything from banking information to patient records to their precise movements). > It would be interesting to see whether this is considered a threat scenario by the USG. If it's not, then I've lost any sliver of confidence in the Feds that I might have had previously.
- swsieber 11y agoBut it does. It's harder to have good security when all the normal solutions suck - they've all been poisoned. Its like when somebody told it's bad to be the most ambitious person in the room - it takes more effort to stand out than to blend in. If your the most ambitious one, merely being the in that state has a dampening effe.
- themeekforgotpw 11y agoI'm not sure I get the analogy to being the most ambitious person in the room. I think you mean that relative to intelligence agencies (not just US intelligence) and the most elite hacking groups domestic computers are products are not up to snuff? I'm not sure that top intelligence agencies backdooring products has really made that gap so much worse. I sorry I don't think I fully understood your point.