Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.misc > #5271 > unrolled thread

The Horror of a 'Secure Golden Key'

Started byRich <rich@example.invalid>
First post2014-10-09 01:43 +0000
Last post2014-10-10 11:51 +0000
Articles 15 — 9 participants

Back to article view | Back to comp.misc


Contents

  The Horror of a 'Secure Golden Key' Rich <rich@example.invalid> - 2014-10-09 01:43 +0000
    Re: The Horror of a 'Secure Golden Key' RS Wood <rsw@therandymon.com> - 2014-10-09 14:16 +0000
      Re: The Horror of a 'Secure Golden Key' Rich <rich@example.invalid> - 2014-10-09 16:26 +0000
        Re: The Horror of a 'Secure Golden Key' Mike Spencer <mds@bogus.nodomain.nowhere> - 2014-10-09 16:01 -0300
          Re: The Horror of a 'Secure Golden Key' RS Wood <rsw@therandymon.com> - 2014-10-09 20:11 +0000
          Re: The Horror of a 'Secure Golden Key' Huge <Huge@nowhere.much.invalid> - 2014-10-11 09:52 +0000
            Re: The Horror of a 'Secure Golden Key' Mike Spencer <mds@bogus.nodomain.nowhere> - 2014-10-11 15:31 -0300
              Re: The Horror of a 'Secure Golden Key' polygonum <rmoudndgers@vrod.co.uk> - 2014-10-11 19:48 +0100
                Re: The Horror of a 'Secure Golden Key' Mike Spencer <mds@bogus.nodomain.nowhere> - 2014-10-12 00:01 -0300
      Re: The Horror of a 'Secure Golden Key' Hils <hils@saynotospam.net> - 2014-10-09 19:34 +0100
        Re: The Horror of a 'Secure Golden Key' mm0fmf <none@mailinator.com> - 2014-10-09 21:24 +0100
          Re: The Horror of a 'Secure Golden Key' Oregonian Haruspex <bob_davis_retired@yahoo.com> - 2014-10-10 15:43 -0700
        Re: The Horror of a 'Secure Golden Key' Rich <rich@example.invalid> - 2014-10-10 00:22 +0000
    Re: The Horror of a 'Secure Golden Key' Gordon Henderson <gordon+usenet@drogon.net> - 2014-10-09 17:17 +0000
      Re: The Horror of a 'Secure Golden Key' RS Wood <rsw@therandymon.com> - 2014-10-10 11:51 +0000

#5271 — The Horror of a 'Secure Golden Key'

FromRich <rich@example.invalid>
Date2014-10-09 01:43 +0000
SubjectThe Horror of a 'Secure Golden Key'
Message-ID<a0d+p8Rxgrc0PmAr3NZGUMzA@dont-email.me>
https://keybase.io/blog/2014-10-08/the-horror-of-a-secure-golden-key

   This week, the Washington Post's editorial board, in a widely circulated
   call for "compromise" on encryption, proposed that while our data should
   be off-limits to hackers and other bad actors, "perhaps Apple and Google
   could invent a kind of secure golden key" so that the good guys could
   get to it if necessary.

   This theoretical "secure golden key" would protect privacy while
   allowing privileged access in cases of legal or state-security
   emergency. Kidnappers and terrorists are exposed, and the rest of us are
   safe. Sounds nice. But this proposal is nonsense, and, given the
   sensitivity of the issue, highly dangerous. Here's why.

   A "golden key" is just another, more pleasant, word for a backdoor -
   something that allows people access to your data without going through
   you directly. This backdoor would, by design, allow Apple and Google to
   view your password-protected files if they received a subpoena or some
   other government directive. You'd pick your own password for when you
   needed your data, but the companies would also get one, of their
   choosing. With it, they could open any of your docs: your photos, your
   messages, your diary, whatever.

   ...

[toc] | [next] | [standalone]


#5275

FromRS Wood <rsw@therandymon.com>
Date2014-10-09 14:16 +0000
Message-ID<20141009141607.dfc30e20.rsw@therandymon.com>
In reply to#5271
On Thu, 09 Oct 2014 01:43:38 +0000 (UTC)
Rich <rich@example.invalid> wrote:
 
>    A "golden key" is just another, more pleasant, word for a backdoor -
>    something that allows people access to your data without going through
>    you directly. This backdoor would, by design, allow Apple and Google to
>    view your password-protected files if they received a subpoena or some
>    other government directive. You'd pick your own password for when you
>    needed your data, but the companies would also get one, of their
>    choosing. With it, they could open any of your docs: your photos, your
>    messages, your diary, whatever.

I'm reminded of that "magic key" that the TSA transport safety guys
have that opens any suitcase lock, in agreement with manufacturers who
produce suitcases with locks that open given a special universal key.
If memory serves, that key was being mass-produced in Nigeria on
industrial scale the day after it was announced.  This kind of security
isn't security at all.

It is also a dangerous first step down the route of acquiescence, which
can only lead to more 'urgent, insistent' demands.  How 'bout we tell
the authorities to buzz off instead?

[toc] | [prev] | [next] | [standalone]


#5277

FromRich <rich@example.invalid>
Date2014-10-09 16:26 +0000
Message-ID<m16d08$frv$1@dont-email.me>
In reply to#5275
RS Wood <rsw@therandymon.com> wrote:
> On Thu, 09 Oct 2014 01:43:38 +0000 (UTC)
> Rich <rich@example.invalid> wrote:
>  
> >    A "golden key" is just another, more pleasant, word for a
> >    backdoor - something that allows people access to your data
> >    without going through you directly. This backdoor would, by
> >    design, allow Apple and Google to view your password-protected
> >    files if they received a subpoena or some other government
> >    directive. You'd pick your own password for when you needed your
> >    data, but the companies would also get one, of their choosing.
> >    With it, they could open any of your docs: your photos, your
> >    messages, your diary, whatever.

> I'm reminded of that "magic key" that the TSA transport safety guys
> have that opens any suitcase lock, in agreement with manufacturers
> who produce suitcases with locks that open given a special universal
> key. If memory serves, that key was being mass-produced in Nigeria on
> industrial scale the day after it was announced.  This kind of
> security isn't security at all.

> It is also a dangerous first step down the route of acquiescence,
> which can only lead to more 'urgent, insistent' demands.  How 'bout
> we tell the authorities to buzz off instead?

I also wonder how many times a "Target data breech", "Home Depot data
breech", "X data breech", etc. has to occur before the lemmings begin
to wonder: "if all these folks can't keep secrets secret, why do we
think the govt. can do any better of a job....".

Although, I do suspect the problem is the general lemmingness of the
general populace.  The "I don't want to think for myself, so please,
you do the thinking for me and tell me what to believe" mentality.

Which leads to folks like the post editor swallowing, hook line and
sinker, the tale that the "golden key" will somehow be magically more
secure than all the other items that have not yet proven to be so
secure so far.

Add pixie dust, and it will "just work"....

[toc] | [prev] | [next] | [standalone]


#5281

FromMike Spencer <mds@bogus.nodomain.nowhere>
Date2014-10-09 16:01 -0300
Message-ID<87r3yhjcef.fsf@bogus.nodomain.nowhere>
In reply to#5277
Rich <rich@example.invalid> writes:

> I also wonder how many times a "Target data breech", "Home Depot data
> breech", "X data breech", etc. has to occur before the lemmings begin
> to wonder: "if all these folks can't keep secrets secret, why do we
> think the govt. can do any better of a job....".
> 
> Although, I do suspect the problem is the general lemmingness of the
> general populace.  The "I don't want to think for myself, so please,
> you do the thinking for me and tell me what to believe" mentality.
> [...]
> Add pixie dust, and it will "just work"....

In defence of T.C. Mits [1], we're having something like a complexity
catastrophe.  Understanding what's going on "out there", whether in
digital tech, crypto, banking, law or other domains, really *is* too
hard.  Some of it, such as crypto, is intrinsically hard but in
general, it's too hard because there's too much of it and there's too
much underlying detail to be mastered.

I'm inclined to think I have "the hacker naturef [2] (although most of
my hacking has been with tangible objects.)  I have a degree in a hard
science; program at an amateur level in 3 languages; have mastered a
difficult craft; have years of experience in a mechanical trade; read
neuroscience, comp sci and math as a hobby.  Have an eccentric
lifestyle that allows me to pursue all of that more or less at whim.

And much of what the system, the ubiquitous "they", throws at me is
too hard, to recursively complicated, for me to understand it.  I'm in
a position to just forego some things such as credit cards but
T.C. Mits typically isn't.

If you, comp.misc reader, understand fully how your smart phone's apps
may subvert your privacy, do you understand your loop(s) of Henle?  If
you're an MD and well up on the kidney, what do you know about the
risks of your car's ABS or of your office's digital medical records?
If you're a wizard (computer) hacker with a master's in biology, do
you fully understand the attack surface presented by the global
financial system and how your humble credit/debit card, GIC or
mortgage may be affected?

And that's assuming that you have an IQ over 100, which, very loosely
speaking, half the Mits don't.

And that doesn't even *mention* such time- and attention-consuming,
quotidian matters as making a living, taking care of a family, dealing
with health problems and so on.

It's easy to scorn the lemming-like behavior of The Geat Unwashed [3]
but I submit that even those brighter, more diligent, more curious,
more literate and numerate than average with more time available than
typical for learning how stuff works, with a more critical and
observant disposition, are confronted daily with the complexity
catastrophe and must accept much of what comes along as pixie dust.
And either do pixie dust or else forego the many products and services
that they can't readily understand with available time and resources.

FWIW, etc. etc.

[1] The Celebrated Man in the Street. Google Lillian Lieber.

[2] See the "jargon file" aka Hacker's Dictionary

[3] Who, today, give nearly fetish-like attention to washing and personal
    hygiene products.
-- 
Mike Spencer                  Nova Scotia, Canada

[toc] | [prev] | [next] | [standalone]


#5282

FromRS Wood <rsw@therandymon.com>
Date2014-10-09 20:11 +0000
Message-ID<m16q5g$9en$1@solani.org>
In reply to#5281
On 2014-10-09, Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
> And that's assuming that you have an IQ over 100, which, very loosely
> speaking, half the Mits don't.

Great quote from George Carlin: "Think about how stupid your average
person is.  Now remember, half the populace is stupider than that."  

I'm paraphrasing, but it's a clever quip.  The quote from Arthur C.
Clarke about any sufficiently complex science beginning to resemble
magic is also probably germane.

It's true that most modern tech is built on so many levels of complexity
no one single person can ever possibly understand it all.  Imagine, I'm
typing this on a Chromebook in a terminal written in javascript! that's
shelled into a VPS - a virtual computer running an operaing system! -
that communicates over TCP/IP with other users.  It's extraordinary.

That said, this 'universal key' business can kiss my ass.

[toc] | [prev] | [next] | [standalone]


#5298

FromHuge <Huge@nowhere.much.invalid>
Date2014-10-11 09:52 +0000
Message-ID<c9scuoFbh0lU1@mid.individual.net>
In reply to#5281
On 2014-10-09, Mike Spencer <mds@bogus.nodomain.nowhere> wrote:

> If you, comp.misc reader, understand fully how your smart phone's apps
> may subvert your privacy, do you understand your loop(s) of Henle?  If
> you're an MD and well up on the kidney, what do you know about the
> risks of your car's ABS or of your office's digital medical records?
> If you're a wizard (computer) hacker with a master's in biology, do
> you fully understand the attack surface presented by the global
> financial system and how your humble credit/debit card, GIC or
> mortgage may be affected?

Actually, yes. All of the above. But then, it's taken a whole lifetime,
two degrees (in disparate subjects) and working in several different
industries to acquire that knowledge. And if you'd included (for example)
sports and haute couture, I'd have been screwed.

-- 
Today is Prickle-Prickle, the 65th day of Bureaucracy in the YOLD 3180
"I do not want people to be agreeable, as it saves me that trouble of
                       liking them." – Jane Austen

[toc] | [prev] | [next] | [standalone]


#5300

FromMike Spencer <mds@bogus.nodomain.nowhere>
Date2014-10-11 15:31 -0300
Message-ID<87a952e9vg.fsf@bogus.nodomain.nowhere>
In reply to#5298
Huge <Huge@nowhere.much.invalid> writes:

> On 2014-10-09, Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
> 
>> If you, comp.misc reader, understand fully how your smart phone's apps
>> may subvert your privacy, do you understand your loop(s) of Henle?  If
>> you're an MD and well up on the kidney, what do you know about the
>> risks of your car's ABS or of your office's digital medical records?
>> If you're a wizard (computer) hacker with a master's in biology, do
>> you fully understand the attack surface presented by the global
>> financial system and how your humble credit/debit card, GIC or
>> mortgage may be affected?
> 
> Actually, yes. All of the above.

Genuflect, genuflect. ;-)

> But then, it's taken a whole lifetime, two degrees (in disparate
> subjects) and working in several different industries to acquire
> that knowledge.

Just so.  I.e., not T.C. Mits.

> And if you'd included (for example) sports and haute couture, I'd
> have been screwed.

Dang. [Adds memo to rhetoric notebook.]

grep -i 'stitch count'  `locate 'William Gibson\'s _Idoru_'`  # :-)

ObCompMisc: 

None of which makes "Secure Golden Key" worth a cvapu bs fuvg.

-- 
Mike Spencer                  Nova Scotia, Canada

[toc] | [prev] | [next] | [standalone]


#5301

Frompolygonum <rmoudndgers@vrod.co.uk>
Date2014-10-11 19:48 +0100
Message-ID<c9tcbkFjnplU1@mid.individual.net>
In reply to#5300
On 11/10/2014 19:31, Mike Spencer wrote:
> Genuflect, genuflect.;-)

I think the full(er) version is:

Bow your head with great respect
And genuflect, genuflect, genuflect!

-- 
Rod

[toc] | [prev] | [next] | [standalone]


#5305

FromMike Spencer <mds@bogus.nodomain.nowhere>
Date2014-10-12 00:01 -0300
Message-ID<87oatic7pe.fsf@bogus.nodomain.nowhere>
In reply to#5301
polygonum <rmoudndgers@vrod.co.uk> writes:

> On 11/10/2014 19:31, Mike Spencer wrote:
>
>> Genuflect, genuflect.;-)
> 
> I think the full(er) version is:
> 
> Bow your head with great respect
> And genuflect, genuflect, genuflect!

Nice to see another musically literate person here!  :-o

-- 
Mike Spencer                  Nova Scotia, Canada

[toc] | [prev] | [next] | [standalone]


#5279

FromHils <hils@saynotospam.net>
Date2014-10-09 19:34 +0100
Message-ID<m16kfa$b9g$2@speranza.aioe.org>
In reply to#5275
On 2014-10-09 15:16, RS Wood wrote:
> I'm reminded of that "magic key" that the TSA transport safety guys
> have that opens any suitcase lock, in agreement with manufacturers who
> produce suitcases with locks that open given a special universal key.
> If memory serves, that key was being mass-produced in Nigeria on
> industrial scale the day after it was announced.  This kind of security
> isn't security at all.
> 
> It is also a dangerous first step down the route of acquiescence, which
> can only lead to more 'urgent, insistent' demands.  How 'bout we tell
> the authorities to buzz off instead?

How could it work without somehow prohibiting stronger forms of encryption?

[toc] | [prev] | [next] | [standalone]


#5284

Frommm0fmf <none@mailinator.com>
Date2014-10-09 21:24 +0100
Message-ID<1aCZv.343764$Kk6.45963@fx22.am4>
In reply to#5279
On 09/10/2014 19:34, Hils wrote:
> How could it work without somehow prohibiting stronger forms of encryption?

When encryption is outlawed only the outlaws will have encryption. 
(Kudos to whoever said that first.)

[toc] | [prev] | [next] | [standalone]


#5294

FromOregonian Haruspex <bob_davis_retired@yahoo.com>
Date2014-10-10 15:43 -0700
Message-ID<m19ndr$d98$1@dont-email.me>
In reply to#5284
On 2014-10-09 20:24:25 +0000, mm0fmf said:

> On 09/10/2014 19:34, Hils wrote:
>> How could it work without somehow prohibiting stronger forms of encryption?
> 
> When encryption is outlawed only the outlaws will have encryption. 
> (Kudos to whoever said that first.)

Also the steganographers.  Encryption is out of the bag, there's no way 
it will be outlawed.  At least until the formal, legal, and publicly 
announced death of the republic.  Then, all bets are off.  See you at 
the nearest death camp!

[toc] | [prev] | [next] | [standalone]


#5288

FromRich <rich@example.invalid>
Date2014-10-10 00:22 +0000
Message-ID<m178s3$583$1@dont-email.me>
In reply to#5279
Hils <hils@saynotospam.net> wrote:
> On 2014-10-09 15:16, RS Wood wrote:
> > I'm reminded of that "magic key" that the TSA transport safety guys
> > have that opens any suitcase lock, in agreement with manufacturers
> > who produce suitcases with locks that open given a special
> > universal key. If memory serves, that key was being mass-produced
> > in Nigeria on industrial scale the day after it was announced. 
> > This kind of security isn't security at all.
> > 
> > It is also a dangerous first step down the route of acquiescence,
> > which can only lead to more 'urgent, insistent' demands.  How 'bout
> > we tell the authorities to buzz off instead?

> How could it work without somehow prohibiting stronger forms of
> encryption?

That's just the problem.  It can not work.  It is simply a backdoor,
waiting to be exploited.

[toc] | [prev] | [next] | [standalone]


#5278

FromGordon Henderson <gordon+usenet@drogon.net>
Date2014-10-09 17:17 +0000
Message-ID<m16fvr$s92$1@dont-email.me>
In reply to#5271
In article <a0d+p8Rxgrc0PmAr3NZGUMzA@dont-email.me>,
Rich  <rich@example.invalid> wrote:
>https://keybase.io/blog/2014-10-08/the-horror-of-a-secure-golden-key
>
>   This week, the Washington Post's editorial board, in a widely circulated
>   call for "compromise" on encryption, proposed that while our data should
>   be off-limits to hackers and other bad actors, "perhaps Apple and Google
>   could invent a kind of secure golden key" so that the good guys could
>   get to it if necessary.
>
>   This theoretical "secure golden key" would protect privacy while
>   allowing privileged access in cases of legal or state-security
>   emergency. Kidnappers and terrorists are exposed, and the rest of us are
>   safe. Sounds nice. But this proposal is nonsense, and, given the
>   sensitivity of the issue, highly dangerous. Here's why.
>
>   A "golden key" is just another, more pleasant, word for a backdoor -
>   something that allows people access to your data without going through
>   you directly. This backdoor would, by design, allow Apple and Google to
>   view your password-protected files if they received a subpoena or some
>   other government directive. You'd pick your own password for when you
>   needed your data, but the companies would also get one, of their
>   choosing. With it, they could open any of your docs: your photos, your
>   messages, your diary, whatever.

Have we forgotten about http://en.wikipedia.org/wiki/Clipper_chip already?

-Gordon

[toc] | [prev] | [next] | [standalone]


#5291

FromRS Wood <rsw@therandymon.com>
Date2014-10-10 11:51 +0000
Message-ID<20141010115135.3463fc11.rsw@therandymon.com>
In reply to#5278
On Thu, 9 Oct 2014 17:17:47 +0000 (UTC)
Gordon Henderson <gordon+usenet@drogon.net> wrote:
 
> Have we forgotten about http://en.wikipedia.org/wiki/Clipper_chip already?
> 
> -Gordon

Actually, in my case, yes, I had forgotten about it.  Thanks for the
link - that was a good read, and timely as well.  I sense we're
spiralling in policy, and slowly coming back to the point where
something similar will be again introduced, and given a different
political and technical environment, potentially even succeed.

[toc] | [prev] | [standalone]


Back to top | Article view | comp.misc


csiph-web