news.volyx.in

A brief history of the U.S. trying to add backdoors into encrypted data (2016) (atlasobscura.com)

550 points by whatever3 · 927 days ago · 193 comments on HN

Article summary

The US government has a history of attempting to add backdoors to encrypted data, with examples including the NSA's promotion of Clipper chips in the 1990s and the discovery of a backdoor in the Dual_EC_DRBG algorithm. These efforts have been met with resistance from cybersecurity experts and the tech industry. The article highlights the ongoing battle between government officials and the tech industry over access to consumer data. The government's efforts to add backdoors have been largely unsuccessful due to the opposition from experts and the industry.

Main themes

  • encryption backdoors
  • government surveillance
  • cybersecurity risks
  • tech industry resistance
  • Intel ME and AMD PSP
  • cryptographic key security
  • open-source vs closed-source firmware
  • update paths and security

What commenters say

  • The existence of security coprocessors like Intel ME is not necessarily a security hole, but rather a potential vulnerability that can be addressed through firmware updates.
  • The use of closed-source firmware and hardware can make it difficult to detect and prevent backdoors.
  • Some argue that trusting a SoC manufacturer is inevitable, and that backdoors can be implemented in a variety of ways, making it difficult to completely prevent them.
  • Others argue that the update path used by companies like Apple can be considered a backdoor, as it allows them to push updates without user consent.
  • The security of cryptographic keys and backdoors is a concern, with some arguing that they can be leaked or exploited, while others believe that they can be secured with proper protocols.
  • There is a debate about the likelihood of cryptographic keys leaking, with some citing examples of leaked nuclear codes and others arguing that such keys can be secured with proper measures.
  • The use of open-source firmware and hardware can help to prevent backdoors, but it is not a guarantee.
  • Some argue that the benefits of backdoors for law enforcement outweigh the potential risks, while others believe that the risks to consumer privacy and security are too great.