Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You fail to get my point, why do you think that that the US has has little issue with allowing encryption to be used these days?

How strong is your 'locked' box? It's only a bunch of 1s and 0s.



Maybe because they realize that treating encryption as munitions is totally unenforceable and strong encryption is basically public knowledge at this point? I know everyone has a cousin in the NSA that knows someone who knows someone who knows how to break Triple DES in 3 minutes, but there's no evidence that is actually real. Even if the NSA or whoever is years ahead of the public in math research (they aren't, BTW, these people would make far more money in the private sector) there's still no evidence to the smartest mathematicians and cryptographers that this is the case. The biggest threats to encryption is parallel computing, weak security, and possibly quantum computing in the future, not a backdoor.


Not to be pedantic but Triple DES could be broken relatively easily by the government, which is why it was replaced with AES. I completely agree with what you are saying in the post, I just wanted to bring up that Triple DES is considered insecure.

Sources: http://arxiv.org/ftp/arxiv/papers/1003/1003.4085.pdf http://delivery.acm.org/10.1145/360000/358718/p465-merkle.pd...


Unless the NSA/FBI/whatever is decades ahead in mathematical research from what is common in academia, or has computers that are many orders of magnitude faster than what we have today, well encrypted data is basically random data to anyone who lacks the keys. That's a pretty tough locked box.


"Unless the NSA/FBI/whatever is decades ahead in mathematical research from what is common in academia"

I wouldn't be surprised. Basically 9/10 people that study cryptography in the US end up working for the NSA. Look at the NSA's budget, and then look at how many cryptography professors there are.

However, that said, IF they managed to decrypt AES somehow, they are severely limited in what they can do with that information. Basically anything they do with the decrypted data has to in no way alert anyone that they have that capability.

So that data DEFINITELY can't be used in court, nor for a whole array of other more covert operations.


The NSA has not only got to be decades ahead of the rest of the world, it has to be completely certain that no-one else in the world will make the same discovery for at least another few decades.

It seems unlikely in the extreme that the NSA is both so far ahead of the rest of the world, and so sure that their discoveries will not be replicated for decades.


And who packages that box?


You're veering awfully metaphorical, but it might be relevant to point out that the crypto implementations in wide use today are typically open source, and the algorithms themselves are public, and widely reviewed by independent cryptographers who have no incentive to do anything sinister.


In fact, they have a good incentive not to do sinister things. If they do, and other cryptographers find out, they will lose a lot of standing in the academic community.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: