home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: sci.crypt
- Path: sparky!uunet!shearson.com!snark!pmetzger
- From: pmetzger@snark.shearson.com (Perry E. Metzger)
- Subject: Re: A Copper Balloon
- Message-ID: <1992Nov9.172132.11375@shearson.com>
- Sender: news@shearson.com (News)
- Organization: /usr/local/lib/news/organization
- References: <1992Nov7.142220.1683@guvax.acc.georgetown.edu>
- Date: Mon, 9 Nov 1992 17:21:32 GMT
- Lines: 68
-
- denning@guvax.acc.georgetown.edu writes:
- >I'd like to suggest another possibility, which for want of a
- >better name I'll call the "copper balloon".
- [...]
- >The basic idea is very simple. Use a 3-way Diffie-Hellman public-key
- >exchange protocol to set up a session key for use with say DES
- >encryption. The third party would be the service provider (actually
- >equipment owned by the service provider), which would make the key
- >available to law enforcement if a court order has been received and
- >an intercept activated.
-
- I don't see much of an improvement here, Professor Denning. From what
- I can tell, all that has happened is that "trusted third party" has
- turned into "telephone company", and "private key" has turned into
- "session key".
-
- As a political dissident, I'm pretty certain that the government will
- listen in on my phone conversations and use the information to
- sabotage my activities with or without a court order, given the
- opportunity. They've shown the inclination and capacity to do this
- with others in the past. To you, this is all academic. To me, this is
- a question of whether 10 years from now I end up in an unmarked grave
- somewhere. Please don't tell me that it can't happen here -- thats
- what they always say.
-
- Even ignoring this particular subissue, all the problems we have dealt
- with before, or even worse versions, such as third parties still being
- able to tap the line (after all, people can just spoof the phone
- company part of the transaction), all continue to arise. I can't think
- of a single thing that this scenario improves.
-
- >Assuming that the 3rd party devices were reliably constructed, this
- >would at least superficially provide more protection since no keys
- >would be kept unless a court order were issued.
-
- No, Professor -- no keys will be kept unless someone chooses to record
- them, regardless of a court order. A court order is just a piece of
- paper. The government has shown an inclination to ignore such scraps
- of paper in the past. As has been noted, "confidential informant" is
- often just a euphamism for "illegal wiretap".
-
- Secret communication is supposed to be just that -- secret. If I
- wanted someone else to be able to read it, I'd hand them the key, too.
- It is not the function of a free society to constrain all human
- behavior to make it easy to surveil. The police managed without phone
- taps for the first century and a half of our republic's existance and
- we didn't collapse without them. The next step after compelling people
- to make sure that everything they say on the phone can be tapped is a
- law requiring installation of bugging devices in all homes. After all,
- the police would have so much easier a time if they were there all the
- time, and no one would listen to them without a court order.
-
- As I've noted before, all that is necessary for a police state to
- succeed in our society is that we build an infrastructure for one and
- that someone unscrupulous takes it over. Your scheme is, as with all
- other such schemes, a wonderful tool for a police state to use to
- consolidate its power. For the moment we might have a government that
- shows some scruples about using that power, but when we produce an
- unbeatable system for universal surveilance all that will be necessary
- for a shift to fascism would be a little tiny change in attitude. No
- proposal that requires the disclosure of keys to a third party,
- regardless of how well intentioned the purpose, is acceptable to me.
-
- --
- Perry Metzger pmetzger@shearson.com
- --
- "They can have my RSA key when they pry it from my cold dead fingers."
- Libertarian Party info: Phone 1-800-682-1776, E-Mail 345-5647@mcimail.com
-