Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.misc > #5271 > unrolled thread
| Started by | Rich <rich@example.invalid> |
|---|---|
| First post | 2014-10-09 01:43 +0000 |
| Last post | 2014-10-10 11:51 +0000 |
| Articles | 15 — 9 participants |
Back to article view | Back to comp.misc
The Horror of a 'Secure Golden Key' Rich <rich@example.invalid> - 2014-10-09 01:43 +0000
Re: The Horror of a 'Secure Golden Key' RS Wood <rsw@therandymon.com> - 2014-10-09 14:16 +0000
Re: The Horror of a 'Secure Golden Key' Rich <rich@example.invalid> - 2014-10-09 16:26 +0000
Re: The Horror of a 'Secure Golden Key' Mike Spencer <mds@bogus.nodomain.nowhere> - 2014-10-09 16:01 -0300
Re: The Horror of a 'Secure Golden Key' RS Wood <rsw@therandymon.com> - 2014-10-09 20:11 +0000
Re: The Horror of a 'Secure Golden Key' Huge <Huge@nowhere.much.invalid> - 2014-10-11 09:52 +0000
Re: The Horror of a 'Secure Golden Key' Mike Spencer <mds@bogus.nodomain.nowhere> - 2014-10-11 15:31 -0300
Re: The Horror of a 'Secure Golden Key' polygonum <rmoudndgers@vrod.co.uk> - 2014-10-11 19:48 +0100
Re: The Horror of a 'Secure Golden Key' Mike Spencer <mds@bogus.nodomain.nowhere> - 2014-10-12 00:01 -0300
Re: The Horror of a 'Secure Golden Key' Hils <hils@saynotospam.net> - 2014-10-09 19:34 +0100
Re: The Horror of a 'Secure Golden Key' mm0fmf <none@mailinator.com> - 2014-10-09 21:24 +0100
Re: The Horror of a 'Secure Golden Key' Oregonian Haruspex <bob_davis_retired@yahoo.com> - 2014-10-10 15:43 -0700
Re: The Horror of a 'Secure Golden Key' Rich <rich@example.invalid> - 2014-10-10 00:22 +0000
Re: The Horror of a 'Secure Golden Key' Gordon Henderson <gordon+usenet@drogon.net> - 2014-10-09 17:17 +0000
Re: The Horror of a 'Secure Golden Key' RS Wood <rsw@therandymon.com> - 2014-10-10 11:51 +0000
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2014-10-09 01:43 +0000 |
| Subject | The Horror of a 'Secure Golden Key' |
| Message-ID | <a0d+p8Rxgrc0PmAr3NZGUMzA@dont-email.me> |
https://keybase.io/blog/2014-10-08/the-horror-of-a-secure-golden-key This week, the Washington Post's editorial board, in a widely circulated call for "compromise" on encryption, proposed that while our data should be off-limits to hackers and other bad actors, "perhaps Apple and Google could invent a kind of secure golden key" so that the good guys could get to it if necessary. This theoretical "secure golden key" would protect privacy while allowing privileged access in cases of legal or state-security emergency. Kidnappers and terrorists are exposed, and the rest of us are safe. Sounds nice. But this proposal is nonsense, and, given the sensitivity of the issue, highly dangerous. Here's why. A "golden key" is just another, more pleasant, word for a backdoor - something that allows people access to your data without going through you directly. This backdoor would, by design, allow Apple and Google to view your password-protected files if they received a subpoena or some other government directive. You'd pick your own password for when you needed your data, but the companies would also get one, of their choosing. With it, they could open any of your docs: your photos, your messages, your diary, whatever. ...
[toc] | [next] | [standalone]
| From | RS Wood <rsw@therandymon.com> |
|---|---|
| Date | 2014-10-09 14:16 +0000 |
| Message-ID | <20141009141607.dfc30e20.rsw@therandymon.com> |
| In reply to | #5271 |
On Thu, 09 Oct 2014 01:43:38 +0000 (UTC) Rich <rich@example.invalid> wrote: > A "golden key" is just another, more pleasant, word for a backdoor - > something that allows people access to your data without going through > you directly. This backdoor would, by design, allow Apple and Google to > view your password-protected files if they received a subpoena or some > other government directive. You'd pick your own password for when you > needed your data, but the companies would also get one, of their > choosing. With it, they could open any of your docs: your photos, your > messages, your diary, whatever. I'm reminded of that "magic key" that the TSA transport safety guys have that opens any suitcase lock, in agreement with manufacturers who produce suitcases with locks that open given a special universal key. If memory serves, that key was being mass-produced in Nigeria on industrial scale the day after it was announced. This kind of security isn't security at all. It is also a dangerous first step down the route of acquiescence, which can only lead to more 'urgent, insistent' demands. How 'bout we tell the authorities to buzz off instead?
[toc] | [prev] | [next] | [standalone]
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2014-10-09 16:26 +0000 |
| Message-ID | <m16d08$frv$1@dont-email.me> |
| In reply to | #5275 |
RS Wood <rsw@therandymon.com> wrote: > On Thu, 09 Oct 2014 01:43:38 +0000 (UTC) > Rich <rich@example.invalid> wrote: > > > A "golden key" is just another, more pleasant, word for a > > backdoor - something that allows people access to your data > > without going through you directly. This backdoor would, by > > design, allow Apple and Google to view your password-protected > > files if they received a subpoena or some other government > > directive. You'd pick your own password for when you needed your > > data, but the companies would also get one, of their choosing. > > With it, they could open any of your docs: your photos, your > > messages, your diary, whatever. > I'm reminded of that "magic key" that the TSA transport safety guys > have that opens any suitcase lock, in agreement with manufacturers > who produce suitcases with locks that open given a special universal > key. If memory serves, that key was being mass-produced in Nigeria on > industrial scale the day after it was announced. This kind of > security isn't security at all. > It is also a dangerous first step down the route of acquiescence, > which can only lead to more 'urgent, insistent' demands. How 'bout > we tell the authorities to buzz off instead? I also wonder how many times a "Target data breech", "Home Depot data breech", "X data breech", etc. has to occur before the lemmings begin to wonder: "if all these folks can't keep secrets secret, why do we think the govt. can do any better of a job....". Although, I do suspect the problem is the general lemmingness of the general populace. The "I don't want to think for myself, so please, you do the thinking for me and tell me what to believe" mentality. Which leads to folks like the post editor swallowing, hook line and sinker, the tale that the "golden key" will somehow be magically more secure than all the other items that have not yet proven to be so secure so far. Add pixie dust, and it will "just work"....
[toc] | [prev] | [next] | [standalone]
| From | Mike Spencer <mds@bogus.nodomain.nowhere> |
|---|---|
| Date | 2014-10-09 16:01 -0300 |
| Message-ID | <87r3yhjcef.fsf@bogus.nodomain.nowhere> |
| In reply to | #5277 |
Rich <rich@example.invalid> writes:
> I also wonder how many times a "Target data breech", "Home Depot data
> breech", "X data breech", etc. has to occur before the lemmings begin
> to wonder: "if all these folks can't keep secrets secret, why do we
> think the govt. can do any better of a job....".
>
> Although, I do suspect the problem is the general lemmingness of the
> general populace. The "I don't want to think for myself, so please,
> you do the thinking for me and tell me what to believe" mentality.
> [...]
> Add pixie dust, and it will "just work"....
In defence of T.C. Mits [1], we're having something like a complexity
catastrophe. Understanding what's going on "out there", whether in
digital tech, crypto, banking, law or other domains, really *is* too
hard. Some of it, such as crypto, is intrinsically hard but in
general, it's too hard because there's too much of it and there's too
much underlying detail to be mastered.
I'm inclined to think I have "the hacker naturef [2] (although most of
my hacking has been with tangible objects.) I have a degree in a hard
science; program at an amateur level in 3 languages; have mastered a
difficult craft; have years of experience in a mechanical trade; read
neuroscience, comp sci and math as a hobby. Have an eccentric
lifestyle that allows me to pursue all of that more or less at whim.
And much of what the system, the ubiquitous "they", throws at me is
too hard, to recursively complicated, for me to understand it. I'm in
a position to just forego some things such as credit cards but
T.C. Mits typically isn't.
If you, comp.misc reader, understand fully how your smart phone's apps
may subvert your privacy, do you understand your loop(s) of Henle? If
you're an MD and well up on the kidney, what do you know about the
risks of your car's ABS or of your office's digital medical records?
If you're a wizard (computer) hacker with a master's in biology, do
you fully understand the attack surface presented by the global
financial system and how your humble credit/debit card, GIC or
mortgage may be affected?
And that's assuming that you have an IQ over 100, which, very loosely
speaking, half the Mits don't.
And that doesn't even *mention* such time- and attention-consuming,
quotidian matters as making a living, taking care of a family, dealing
with health problems and so on.
It's easy to scorn the lemming-like behavior of The Geat Unwashed [3]
but I submit that even those brighter, more diligent, more curious,
more literate and numerate than average with more time available than
typical for learning how stuff works, with a more critical and
observant disposition, are confronted daily with the complexity
catastrophe and must accept much of what comes along as pixie dust.
And either do pixie dust or else forego the many products and services
that they can't readily understand with available time and resources.
FWIW, etc. etc.
[1] The Celebrated Man in the Street. Google Lillian Lieber.
[2] See the "jargon file" aka Hacker's Dictionary
[3] Who, today, give nearly fetish-like attention to washing and personal
hygiene products.
--
Mike Spencer Nova Scotia, Canada
[toc] | [prev] | [next] | [standalone]
| From | RS Wood <rsw@therandymon.com> |
|---|---|
| Date | 2014-10-09 20:11 +0000 |
| Message-ID | <m16q5g$9en$1@solani.org> |
| In reply to | #5281 |
On 2014-10-09, Mike Spencer <mds@bogus.nodomain.nowhere> wrote: > And that's assuming that you have an IQ over 100, which, very loosely > speaking, half the Mits don't. Great quote from George Carlin: "Think about how stupid your average person is. Now remember, half the populace is stupider than that." I'm paraphrasing, but it's a clever quip. The quote from Arthur C. Clarke about any sufficiently complex science beginning to resemble magic is also probably germane. It's true that most modern tech is built on so many levels of complexity no one single person can ever possibly understand it all. Imagine, I'm typing this on a Chromebook in a terminal written in javascript! that's shelled into a VPS - a virtual computer running an operaing system! - that communicates over TCP/IP with other users. It's extraordinary. That said, this 'universal key' business can kiss my ass.
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2014-10-11 09:52 +0000 |
| Message-ID | <c9scuoFbh0lU1@mid.individual.net> |
| In reply to | #5281 |
On 2014-10-09, Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
> If you, comp.misc reader, understand fully how your smart phone's apps
> may subvert your privacy, do you understand your loop(s) of Henle? If
> you're an MD and well up on the kidney, what do you know about the
> risks of your car's ABS or of your office's digital medical records?
> If you're a wizard (computer) hacker with a master's in biology, do
> you fully understand the attack surface presented by the global
> financial system and how your humble credit/debit card, GIC or
> mortgage may be affected?
Actually, yes. All of the above. But then, it's taken a whole lifetime,
two degrees (in disparate subjects) and working in several different
industries to acquire that knowledge. And if you'd included (for example)
sports and haute couture, I'd have been screwed.
--
Today is Prickle-Prickle, the 65th day of Bureaucracy in the YOLD 3180
"I do not want people to be agreeable, as it saves me that trouble of
liking them." – Jane Austen
[toc] | [prev] | [next] | [standalone]
| From | Mike Spencer <mds@bogus.nodomain.nowhere> |
|---|---|
| Date | 2014-10-11 15:31 -0300 |
| Message-ID | <87a952e9vg.fsf@bogus.nodomain.nowhere> |
| In reply to | #5298 |
Huge <Huge@nowhere.much.invalid> writes: > On 2014-10-09, Mike Spencer <mds@bogus.nodomain.nowhere> wrote: > >> If you, comp.misc reader, understand fully how your smart phone's apps >> may subvert your privacy, do you understand your loop(s) of Henle? If >> you're an MD and well up on the kidney, what do you know about the >> risks of your car's ABS or of your office's digital medical records? >> If you're a wizard (computer) hacker with a master's in biology, do >> you fully understand the attack surface presented by the global >> financial system and how your humble credit/debit card, GIC or >> mortgage may be affected? > > Actually, yes. All of the above. Genuflect, genuflect. ;-) > But then, it's taken a whole lifetime, two degrees (in disparate > subjects) and working in several different industries to acquire > that knowledge. Just so. I.e., not T.C. Mits. > And if you'd included (for example) sports and haute couture, I'd > have been screwed. Dang. [Adds memo to rhetoric notebook.] grep -i 'stitch count' `locate 'William Gibson\'s _Idoru_'` # :-) ObCompMisc: None of which makes "Secure Golden Key" worth a cvapu bs fuvg. -- Mike Spencer Nova Scotia, Canada
[toc] | [prev] | [next] | [standalone]
| From | polygonum <rmoudndgers@vrod.co.uk> |
|---|---|
| Date | 2014-10-11 19:48 +0100 |
| Message-ID | <c9tcbkFjnplU1@mid.individual.net> |
| In reply to | #5300 |
On 11/10/2014 19:31, Mike Spencer wrote: > Genuflect, genuflect.;-) I think the full(er) version is: Bow your head with great respect And genuflect, genuflect, genuflect! -- Rod
[toc] | [prev] | [next] | [standalone]
| From | Mike Spencer <mds@bogus.nodomain.nowhere> |
|---|---|
| Date | 2014-10-12 00:01 -0300 |
| Message-ID | <87oatic7pe.fsf@bogus.nodomain.nowhere> |
| In reply to | #5301 |
polygonum <rmoudndgers@vrod.co.uk> writes: > On 11/10/2014 19:31, Mike Spencer wrote: > >> Genuflect, genuflect.;-) > > I think the full(er) version is: > > Bow your head with great respect > And genuflect, genuflect, genuflect! Nice to see another musically literate person here! :-o -- Mike Spencer Nova Scotia, Canada
[toc] | [prev] | [next] | [standalone]
| From | Hils <hils@saynotospam.net> |
|---|---|
| Date | 2014-10-09 19:34 +0100 |
| Message-ID | <m16kfa$b9g$2@speranza.aioe.org> |
| In reply to | #5275 |
On 2014-10-09 15:16, RS Wood wrote: > I'm reminded of that "magic key" that the TSA transport safety guys > have that opens any suitcase lock, in agreement with manufacturers who > produce suitcases with locks that open given a special universal key. > If memory serves, that key was being mass-produced in Nigeria on > industrial scale the day after it was announced. This kind of security > isn't security at all. > > It is also a dangerous first step down the route of acquiescence, which > can only lead to more 'urgent, insistent' demands. How 'bout we tell > the authorities to buzz off instead? How could it work without somehow prohibiting stronger forms of encryption?
[toc] | [prev] | [next] | [standalone]
| From | mm0fmf <none@mailinator.com> |
|---|---|
| Date | 2014-10-09 21:24 +0100 |
| Message-ID | <1aCZv.343764$Kk6.45963@fx22.am4> |
| In reply to | #5279 |
On 09/10/2014 19:34, Hils wrote: > How could it work without somehow prohibiting stronger forms of encryption? When encryption is outlawed only the outlaws will have encryption. (Kudos to whoever said that first.)
[toc] | [prev] | [next] | [standalone]
| From | Oregonian Haruspex <bob_davis_retired@yahoo.com> |
|---|---|
| Date | 2014-10-10 15:43 -0700 |
| Message-ID | <m19ndr$d98$1@dont-email.me> |
| In reply to | #5284 |
On 2014-10-09 20:24:25 +0000, mm0fmf said: > On 09/10/2014 19:34, Hils wrote: >> How could it work without somehow prohibiting stronger forms of encryption? > > When encryption is outlawed only the outlaws will have encryption. > (Kudos to whoever said that first.) Also the steganographers. Encryption is out of the bag, there's no way it will be outlawed. At least until the formal, legal, and publicly announced death of the republic. Then, all bets are off. See you at the nearest death camp!
[toc] | [prev] | [next] | [standalone]
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2014-10-10 00:22 +0000 |
| Message-ID | <m178s3$583$1@dont-email.me> |
| In reply to | #5279 |
Hils <hils@saynotospam.net> wrote: > On 2014-10-09 15:16, RS Wood wrote: > > I'm reminded of that "magic key" that the TSA transport safety guys > > have that opens any suitcase lock, in agreement with manufacturers > > who produce suitcases with locks that open given a special > > universal key. If memory serves, that key was being mass-produced > > in Nigeria on industrial scale the day after it was announced. > > This kind of security isn't security at all. > > > > It is also a dangerous first step down the route of acquiescence, > > which can only lead to more 'urgent, insistent' demands. How 'bout > > we tell the authorities to buzz off instead? > How could it work without somehow prohibiting stronger forms of > encryption? That's just the problem. It can not work. It is simply a backdoor, waiting to be exploited.
[toc] | [prev] | [next] | [standalone]
| From | Gordon Henderson <gordon+usenet@drogon.net> |
|---|---|
| Date | 2014-10-09 17:17 +0000 |
| Message-ID | <m16fvr$s92$1@dont-email.me> |
| In reply to | #5271 |
In article <a0d+p8Rxgrc0PmAr3NZGUMzA@dont-email.me>, Rich <rich@example.invalid> wrote: >https://keybase.io/blog/2014-10-08/the-horror-of-a-secure-golden-key > > This week, the Washington Post's editorial board, in a widely circulated > call for "compromise" on encryption, proposed that while our data should > be off-limits to hackers and other bad actors, "perhaps Apple and Google > could invent a kind of secure golden key" so that the good guys could > get to it if necessary. > > This theoretical "secure golden key" would protect privacy while > allowing privileged access in cases of legal or state-security > emergency. Kidnappers and terrorists are exposed, and the rest of us are > safe. Sounds nice. But this proposal is nonsense, and, given the > sensitivity of the issue, highly dangerous. Here's why. > > A "golden key" is just another, more pleasant, word for a backdoor - > something that allows people access to your data without going through > you directly. This backdoor would, by design, allow Apple and Google to > view your password-protected files if they received a subpoena or some > other government directive. You'd pick your own password for when you > needed your data, but the companies would also get one, of their > choosing. With it, they could open any of your docs: your photos, your > messages, your diary, whatever. Have we forgotten about http://en.wikipedia.org/wiki/Clipper_chip already? -Gordon
[toc] | [prev] | [next] | [standalone]
| From | RS Wood <rsw@therandymon.com> |
|---|---|
| Date | 2014-10-10 11:51 +0000 |
| Message-ID | <20141010115135.3463fc11.rsw@therandymon.com> |
| In reply to | #5278 |
On Thu, 9 Oct 2014 17:17:47 +0000 (UTC) Gordon Henderson <gordon+usenet@drogon.net> wrote: > Have we forgotten about http://en.wikipedia.org/wiki/Clipper_chip already? > > -Gordon Actually, in my case, yes, I had forgotten about it. Thanks for the link - that was a good read, and timely as well. I sense we're spiralling in policy, and slowly coming back to the point where something similar will be again introduced, and given a different political and technical environment, potentially even succeed.
[toc] | [prev] | [standalone]
Back to top | Article view | comp.misc
csiph-web