Posting Freak
Posts: 854
Threads: 71
Joined: 2008-07
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
Job: Software Dev.
Basically, the Obama administration is preparing a bill that would require all encrypted internet communication to have back doors allowing the government to decrypt it. Here's the article.
Quote:- Communications services that encrypt messages must have a way to unscramble them.
- Foreign-based providers that do business inside the United States must install a domestic office capable of performing intercepts.
- Developers of software that enables peer-to-peer communication must redesign their service to allow interception.
Encryption that can be decrypted by a third party is no encryption. If the government can decrypt it, so can anyone else. Do you like managing your bank account or credit card online or making purchases securely on Amazon? Too bad.
Posting Freak
Posts: 9,907
Threads: 379
Joined: 2010-02
First the COICA, and now this?
Hahaha
Posting Freak
Posts: 1,269
Threads: 42
Joined: 2008-08
This is concerning to say the least. As I mentioned in the Schwarzenegger VS. EMA case thread, it surely seems the government is approaching internet control from different angles. All these precedents they try and set leave the possibility of constant monitoring of your internet use and putting anything you do into a file that could be used against you in for example background checks when trying to get a job. Sure it isn't likely, but again, close to "thought police".
And yeah, I know that case I mentioned has nothing to do with the internet as it stands now, but as games move mainstream into online only content, it is a direction they could go.
Posting Freak
Posts: 6,070
Threads: 229
Joined: 2008-07
hahahaohwow.jpg
Obama, gtfo. Now.
Your systems still get h4x0red by other entities, what makes you think this will ever work?
Test Mushroom
Posts: 10,045
Threads: 1,506
Joined: 2008-06
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
IGN: GuavaCowboy
Server: Zenith
Level: 10x
Job: Jett
Guild: L>
Uhhh, the way you wrote the definition of the article is fearmongering to say the least.
The government wants the ability to decrypt/descramble communications if given a court order allowing them to do so. This means, for instance, if Skype can help the government catch criminals, Skype must give the government the decryption keys that they can use to decrypt the packets. The government knowing how to decrypt it will reduce the security of it - that much is uncontested. The more people that know how to decrypt something, the more vulnerable that something is.
The internet will stay decentralized.
Encryption can continue as usual.
Already the government can subpoena that an ISP release who is behind certain IP addresses, release your e-mails to the FBI, and release search history and chat logs to courts who request them. Why is this the nail in the coffin? Why will this kill the internet more than anything else the government has already done? As much as I love strong encryption, I don't see how this is a bad thing or how it overextends the government's ability to do its investigative work.
Posting Freak
Posts: 2,426
Threads: 88
Joined: 2009-06
I don't really see real criminals leaving super important information, or even any insignificant information to help point of the criminal, on the internet.
"Google records indicated that this man searched "how to build a bomb in the back of my car. He's the guy, plain evidence for anyone to see."
I think they're overstepping their bounds a little to be honest. It's one thing to target individuals, and another to ask websites to give away a wall of defense.
Posting Freak
Posts: 854
Threads: 71
Joined: 2008-07
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
Job: Software Dev.
@Fiel:
Quote:Developers of software that enables peer-to-peer communication must redesign their service to allow interception.
It depends on what the law would consider to be "peer-to-peer communication". I can only assume that it means communication that goes from Alice to Bob without passing through the provider of some service, because the other points focus on an architecture where there's a middleman. That definition would include things like SSH and HTTPS. I'd like to see some assurance that that isn't the case. And if that definition does NOT include things like SSH and HTTPS, that's a loophole that makes the law essentially useless.
Posting Freak
Posts: 6,070
Threads: 229
Joined: 2008-07
Spaz Wrote:Alice to Bob
Read the book from Bruce Schneier?
Posting Freak
Posts: 854
Threads: 71
Joined: 2008-07
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
Job: Software Dev.
KajitiSouls Wrote:Read the book from Bruce Schneier? Every cryptography example EVER uses Alice and Bob.
Posting Freak
Posts: 6,070
Threads: 229
Joined: 2008-07
Hmm. Afaik, a lot of cryptography examples seem to come after that one book he wrote. Don't quote me on this though.
While Paul is correct that the original post is fearmongering, I'm still don't trust letting software have backdoors. I think the damage potential is larger than what it might prevent.
Posting Freak
Posts: 4,163
Threads: 357
Joined: 2009-11
Gender: Male
Sexual Orientation: Straight
Country Flag: finland
IGN: Helsinki
Server: MYBCKN
Level: 220
Job: Aran
Guild: Friends
Guild Alliance: Unbreakable
Government=US?
I don't think other countries will allow this. Just new way to spy on people/other countries. Heck, still waiting for Wikileaks to totally reveal the conspiracy of US to the world.
Posting Freak
Posts: 1,544
Threads: 22
Joined: 2010-11
Fiel Wrote:Uhhh, the way you wrote the definition of the article is fearmongering to say the least.
The government wants the ability to decrypt/descramble communications if given a court order allowing them to do so. This means, for instance, if Skype can help the government catch criminals, Skype must give the government the decryption keys that they can use to decrypt the packets. The government knowing how to decrypt it will reduce the security of it - that much is uncontested. The more people that know how to decrypt something, the more vulnerable that something is.
The internet will stay decentralized.
Encryption can continue as usual.
Already the government can subpoena that an ISP release who is behind certain IP addresses, release your e-mails to the FBI, and release search history and chat logs to courts who request them. Why is this the nail in the coffin? Why will this kill the internet more than anything else the government has already done? As much as I love strong encryption, I don't see how this is a bad thing or how it overextends the government's ability to do its investigative work.
As an anarchist (it's an ideal, get off my back polipapayas), i have to agree with feil. Especially the bit about this being kinda heavy on the fearmongering.
Test Mushroom
Posts: 10,045
Threads: 1,506
Joined: 2008-06
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
IGN: GuavaCowboy
Server: Zenith
Level: 10x
Job: Jett
Guild: L>
2010-11-15, 05:17 AM
(This post was last modified: 2010-11-15, 08:15 AM by Fiel.)
Spaz Wrote:It depends on what the law would consider to be "peer-to-peer communication". I can only assume that it means communication that goes from Alice to Bob without passing through the provider of some service, because the other points focus on an architecture where there's a middleman. That definition would include things like SSH and HTTPS. I'd like to see some assurance that that isn't the case. And if that definition does NOT include things like SSH and HTTPS, that's a loophole that makes the law essentially useless.
This is what I like about the internet, though. It's easy to work around things like this.
Suppose Alice and Bob want to set up a channel on a peer to peer network on Skype to chat together. Alice sends a message to Bob, but that message gets bounced through Skype. Skype then connects Alice to Eve to Bob. Since Alice and Bob are not directly connected to each other, Alice can be aware of her own internet connections and destroy the call. It's too easy to discover Eve's presence. Alice and Bob can then move to a different network or create their own P2P communication that does not rely on government laws and the possibility of connecting with Eve.
Allowing one connection to be different from another due to these laws would create something different in the communication which allows for detection. A person could write a piece of code notifying Alice that she's actually connected through Eve, then communicate that awareness to Bob. Or Bob could have it as well. It doesn't matter.
This assumes, however, that Alice knows exactly how to route to Bob and is aware of how to protect her own security. This isn't always true.
Also, since you can funnel any kind of communication through SSH tunneling, it becomes hard to detect where a person is truly calling from. You could detect a person through the account name, but accounts are easily disposable.
Posting Freak
Posts: 1,167
Threads: 94
Joined: 2008-07
Gender: Female
Sexual Orientation: Straight
Country Flag: newzealand
Spaz Wrote:Every cryptography example EVER uses Alice and Bob.
Slightly off topic, but does anybody have any idea why this is?
I first thought it was my math professor and then it started coming up in my other courses that mentioned crypto too!
Is it just because they wanted one person with a name starting with A, and another with B, and we have to be fair to each gender? But why didn't Andrew/ Brenda get chosen for example?
Randm question, but it's one of those things I wonder a lot about when bored in class o_o
Posting Freak
Posts: 10,920
Threads: 288
Joined: 2009-07
Typically when the USA tries to make anything easier it makes it twice as hard and 25 years longer.
Posting Freak
Posts: 854
Threads: 71
Joined: 2008-07
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
Job: Software Dev.
Heidi Wrote:Slightly off topic, but does anybody have any idea why this is?
I first thought it was my math professor and then it started coming up in my other courses that mentioned crypto too!
Is it just because they wanted one person with a name starting with A, and another with B, and we have to be fair to each gender? But why didn't Andrew/ Brenda get chosen for example?
Randm question, but it's one of those things I wonder a lot about when bored in class o_o
Let me wikipedia that for you
Posting Freak
Posts: 1,167
Threads: 94
Joined: 2008-07
Gender: Female
Sexual Orientation: Straight
Country Flag: newzealand
Spaz Wrote:Let me wikipedia that for you
You're not suppoed to say that! *strangles Grag*
Anyway, wow. I didn't realise there was a whole alphabet. Scientists and Engineers are such crazy people. I don't think the man in the middle in my security course was Chuck though... was something else starting with C. I'd have to look at my notes to remember though.
And wow there is a lot of random things on wikipedia o_o
DustBunny Wrote:Typically when the USA tries to make anything easier it makes it twice as hard and 25 years longer.
For something like this, that'd actually be a good thing.
Posting Freak
Posts: 2,466
Threads: 182
Joined: 2009-06
Gender: Male
Country Flag: California
IGN: Enfris
Server: Reboot GMS
Level: 173
Job: Evan
Guild: Forever alone.jpg
Guild Alliance: Forever alone.jpg
I don't like the potential dangers of this. Smarty poops that knows how the government gets the 'good stuff' will be willing to do the same thing. Therefore, more and more people will know it, because its most likely for that smarty poop to release a tutorial to the other smarty poops, and then the tutorial dumbs down to the general public, therefore they can understand how to get the "good stuff".
|