Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Export-level Encryption Proves Insufficient

Posted by michael on Fri Jan 18, 2002 09:16 AM
from the forty-bits-is-not-enough dept.
rossjudson writes: "The Independent is running an article about the shoe bomber terrorist. The interesting bit for Slashdot readers is at the bottom -- apparently the 40-bit encryption in the export version of Windows 2000 was cracked by a set of computers using a brute force method. So let's confront the question: Should the US prohibit the export of high-encryption software? Here is a case where the default values (40 bit) clearly helped recover valuable information from a system." There's another article in New Scientist focusing on the encryption issue.
This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2
  • Yeah (Score:3, Insightful)

    by johnburton (21870) <johnb@jbmail.com> on Friday January 18 2002, @09:19AM (#2861741) Homepage
    Yeah because prohibiting the export of this will prevent anyone evil from getting hold of it...
    • Re:Yeah by Shanep (Score:2) Friday January 18 2002, @09:29AM
      • Re:Yeah by gowen (Score:3) Friday January 18 2002, @09:34AM
        • Re:Yeah by Shanep (Score:2) Friday January 18 2002, @11:23AM
          • Re:Yeah by questionlp (Score:2) Friday January 18 2002, @11:53AM
        • Re:Yeah by gowen (Score:1) Friday January 18 2002, @09:58AM
        • 1 reply beneath your current threshold.
      • Re:Yeah by bildstorm (Score:3) Friday January 18 2002, @09:40AM
        • Re:Yeah by plsander (Score:3) Friday January 18 2002, @10:41AM
          • Re:Yeah by lynx_user_abroad (Score:1) Friday January 18 2002, @01:44PM
        • Re:Yeah by Shanep (Score:2) Friday January 18 2002, @11:28AM
        • Re:Yeah by Captain_Jackass (Score:1) Friday January 18 2002, @01:03PM
          • Re:Yeah by eam (Score:1) Wednesday January 23 2002, @11:28AM
        • Re:Yeah by wkw3 (Score:1) Friday January 18 2002, @04:38PM
        • Re:Yeah by DavidTC (Score:1) Saturday January 19 2002, @01:24AM
        • Re:Yeah by Alan Partridge (Score:1) Friday January 18 2002, @11:53AM
          • Re:Yeah by RDskutter (Score:1) Friday January 18 2002, @12:30PM
            • Re:Yeah by Mirus Nex (Score:1) Friday January 18 2002, @05:10PM
              • Re:Yeah by Shanep (Score:2) Sunday January 20 2002, @07:06AM
        • 2 replies beneath your current threshold.
    • Re:Yeah by blibbleblobble (Score:1) Friday January 18 2002, @09:41AM
      • Re:Yeah by ichimunki (Score:3) Friday January 18 2002, @09:58AM
        • Re:Yeah by bonk (Score:1) Friday January 18 2002, @10:16AM
        • Re:Yeah by Discoteck (Score:3) Friday January 18 2002, @10:24AM
          • Re:Yeah by ichimunki (Score:1) Friday January 18 2002, @11:35AM
    • Re:Yeah by Anonymous Coward (Score:1) Friday January 18 2002, @10:17AM
    • Re:Yeah by Ioldanach (Score:2) Friday January 18 2002, @10:20AM
      • Re:Yeah by johnburton (Score:2) Friday January 18 2002, @10:40AM
        • Re:Yeah by jlower (Score:1) Friday January 18 2002, @11:03AM
          • Re:Yeah by MadAhab (Score:2) Friday January 18 2002, @11:25AM
          • Re:Yeah by Mirus Nex (Score:1) Friday January 18 2002, @05:21PM
      • Re:Yeah by Tassach (Score:2) Friday January 18 2002, @11:48AM
      • 1 reply beneath your current threshold.
    • True (Score:5, Insightful)

      by Greyfox (87712) on Friday January 18 2002, @11:36AM (#2862731) Homepage
      When my company started a contract with a software shop in Romania for them to write software for us, corporate policy required all communications to be encrypted. We got PGP and GPG for the various servers, they bought PGP from the PGP International people and our keys were all 1024 bit keys. Nothing to it.

      What the crypto regulations really do is prevent most people in the USA from adopting it. None of the three-letter agencies want everyone encrypting their E-mail or network traffic by default. That simply wouldn't do -- if everyone did it, how would they know who actually has something to hide? So they make it a pain in the ass for software developers to incorporate it into their software and they make it a pain in the ass for most users (Who don't know to go to international sites where you don't have to fill out a form to download the software) to get it.

      The irony is that now they're bitching because the network is so insecure and how a cyber-attack could bring down public utilities and banks and things. Well they're just reaping what they've sown. The network would have tended to cryptographic authentication and tighter security except for the artificial and fundamentally useless restrictions the federal government has put in place.

      [ Parent ]
      • Re:True by RDskutter (Score:1) Friday January 18 2002, @12:40PM
    • Re:Yeah by minard (Score:1) Friday January 18 2002, @11:43AM
    • Re:Yeah by mghiggins (Score:2) Friday January 18 2002, @12:11PM
    • Re:Yeah by johnburton (Score:2) Friday January 18 2002, @09:29AM
      • cheer up by Alien54 (Score:2) Friday January 18 2002, @10:15AM
      • Re:Yeah by Anonymous Coward (Score:1) Friday January 18 2002, @10:27AM
    • 3 replies beneath your current threshold.
  • To really be safe... (Score:5, Funny)

    by wfrp01 (82831) on Friday January 18 2002, @09:20AM (#2861749) Journal
    If you really want to make the world a safer place, please demand that everyone wear helmets all of the time.
  • It doesn't matter because: (Score:5, Insightful)

    by Bonker (243350) on Friday January 18 2002, @09:22AM (#2861759)
    Advanced Math Textbook +
    Computer +
    Low-level programming skills =

    High Grade Encryption... Anywhere in the world.
  • by Hater's Leaving, The (322238) on Friday January 18 2002, @09:22AM (#2861764)
    40 bits is nothing, and has been for decades.
    That limit was /chosen/ to be crackable. And in my book, and in the minds of many others, that pretty much disqualifies it from even being called 'crypto'.

    THL.
  • Why not? (Score:5, Insightful)

    by sql*kitten (1359) on Friday January 18 2002, @09:23AM (#2861770)
    Should the US prohibit the export of high-encryption software?

    Sure, why not? It isn't as if there are any cryptographers [pgpi.org] in any other countries [www.ssh.fi] in the world, is it?

    Legislation is pointless, and even damaging in this case. The cryptography playing field is fairly level. That's not inherently a good or a bad thing; just as al-Queda can encrypt their files, they are equally prevented from intercepting sensitive information by the same technology. If legislation restricts crypto, we will find ourselves in a situation in which the FBI can't crack terrorist comms, yet terrorists can intercept commercial data. Airline security information, oilrig blueprints, whatever.
    • Re:Why not? by Guppy06 (Score:2) Friday January 18 2002, @09:52AM
      • Re:Why not? (Score:4, Insightful)

        by sql*kitten (1359) on Friday January 18 2002, @10:00AM (#2862031)
        We're not talking about restricting domestic encryption here. The issue is specifically about export restrictions.

        You might have a point if US citizens never traveled on non-US airlines. That simply isn't true. Terrorism is a global problem.

        What I see here is an instance where, because of our export restrictions, we WERE able to crack terrorist comms. The old argument of "They won't use handicapped software" doesn't seem to hold as much water as it used to.

        It's very easy to fall into the trap of assuming that al-Queda are stupid. I am not committing sedition by saying they are in all likelihood just as smart as the law enforcers hunting them. With no technology, and (relatively) little money, massively outnumbered and outgunned, Osama and his people are still free. No-one knows where he as, and he is able to communicate with his organization at will.

        Let me give you an analogy. The minimum wage high-school dropout flipping hamburgers doesn't mean that the global fast-food corporation isn't run by Harvard MBAs. The Shoebomber was a pawn in this, nothing more.

        I have some familiarity with cryptography, because of my work, but it's not a life-or-death thing for me. You can bet every terrorist with a computer is googling for "crypto" right now.
        [ Parent ]
        • Re:Why not? by stapedium (Score:1) Friday January 18 2002, @11:24AM
          • Re:Why not? by sql*kitten (Score:2) Friday January 18 2002, @12:06PM
        • Re:Why not? by _ganja_ (Score:2) Friday January 18 2002, @12:29PM
        • 1 reply beneath your current threshold.
      • Re:Why not? by joshsisk (Score:3) Friday January 18 2002, @10:04AM
        • Re:Why not? by Guppy06 (Score:1) Friday January 18 2002, @10:35AM
          • Re:Why not? by joshsisk (Score:1) Friday January 18 2002, @12:10PM
      • Re:Why not? by bnenning (Score:2) Friday January 18 2002, @01:15PM
      • 1 reply beneath your current threshold.
    • Why has no-one bashed Microsoft yet? by cyberformer (Score:2) Friday January 18 2002, @04:30PM
  • well that settles it.. by TechnoVooDooDaddy (Score:1) Friday January 18 2002, @09:24AM
    • Re:well that settles it.. by ptrourke (Score:3) Friday January 18 2002, @09:26AM
    • Re:well that settles it.. by Howie (Score:2) Friday January 18 2002, @09:30AM
    • Re:well that settles it.. by hotgrits (Score:1) Friday January 18 2002, @09:35AM
    • Re:well that settles it.. by MikeyLikesIt! (Score:3) Friday January 18 2002, @09:41AM
    • 40 bits is useless (Score:5, Insightful)

      by Bostik (92589) on Friday January 18 2002, @09:55AM (#2861997)
      [...] this pretty much settles the question for me that 40-bit, even 64-bit just isn't enough.

      Correct. 40-bit keys have no protective value. Remember the article about IBM's crypto chip being broken? (Somebody please provide the link to /. article, I can't at the moment.) In practice, they broke single DES, 56 bits worth of security in a good block cipher. In brute force.

      It took at most 2 days with ~1000 $US worth of gear to find the key. Let's assume that they needed the full 48 hours to get that key broken. Simple math follows:

      48 hours is 48*3600 seconds. It takes this much time to brute-force a 56-bit key. 40 bits is 1/(2^16) times the size of that, hence the time to break a 40-bit key with similar equipment is 48*3600/(2^16) seconds. This is no more than about 2.6 seconds.

      To underline this as clearly as I can: 40-bit keys provide NO security. They may have provided some, at a time - but definetely not for some time now.

      [ Parent ]
    • 2 replies beneath your current threshold.
  • Meaningless by NiftyNews (Score:2) Friday January 18 2002, @09:24AM
  • When Strong Crypto Is Outlawed by joel_archer (Score:2) Friday January 18 2002, @09:24AM
  • Good Idea! by Not2Bryt64 (Score:1) Friday January 18 2002, @09:24AM
    • Re:Good Idea! by agentZ (Score:2) Friday January 18 2002, @09:32AM
      • Re:Good Idea! by NullAndVoid (Score:2) Friday January 18 2002, @09:41AM
      • Re:Good Idea! by whovian (Score:1) Friday January 18 2002, @09:45AM
        • Re:Good Idea! by RazzleFrog (Score:1) Friday January 18 2002, @09:54AM
    • Re:Good Idea! by Geeky (Score:1) Friday January 18 2002, @09:50AM
  • Why YOU should care about crypto freedom. by Frank White (Score:1) Friday January 18 2002, @09:24AM
  • What is a Good Law? by Lilkeeney (Score:2) Friday January 18 2002, @09:25AM
    • 1 reply beneath your current threshold.
  • From the article... by xZAQx (Score:1) Friday January 18 2002, @09:25AM
  • This is news? by Wind_Walker (Score:2) Friday January 18 2002, @09:26AM
    • Re:This is news? by RazzleFrog (Score:1) Friday January 18 2002, @09:58AM
    • The news is the who, not the what. (Score:4, Insightful)

      by fizbin (2046) <martin@snow p l o w . org> on Friday January 18 2002, @10:02AM (#2862054) Homepage
      The only real newsworthy bit I saw in it is that apparently the people who bought the laptop and then decrypted the disk are not govenrment operatives, but "just" people working for the Wall Street Journal. If anything, this says that moderate cryptography knowledge has become routine in corporate America.

      When the NSA can uncover my deepest secrets, that's one thing. When a potential employer can decrypt anything protected with twenty year old technology, I don't worry yet, but talk to me again in my mid-40s. I wonder when some of the early posts to alt.anonymous.* will become decipherable.
      [ Parent ]
    • Re:This is news? by maeka (Score:1) Friday January 18 2002, @01:10PM
  • Of course it should not be export-controlled by Tom7 (Score:2) Friday January 18 2002, @09:27AM
  • Far better tools has been free for a long time by bodin (Score:2) Friday January 18 2002, @09:27AM
    • 1 reply beneath your current threshold.
  • Is this an issue? by epepke (Score:2) Friday January 18 2002, @09:27AM
    • 1 reply beneath your current threshold.
  • No, no, no... by trix_e (Score:2) Friday January 18 2002, @09:28AM
    • 1 reply beneath your current threshold.
  • The US doesn't have a monopoly on encryption by ergo98 (Score:1) Friday January 18 2002, @09:28AM
  • Like I trusted windows encription before by Andy.T.BOFH (Score:1) Friday January 18 2002, @09:28AM
  • It Did A Bad Job by Bartmoss (Score:2) Friday January 18 2002, @09:29AM
  • Anyone can write encryption software by mochan_s (Score:1) Friday January 18 2002, @09:29AM
  • I don't get this... (Score:3, Interesting)

    by blitzrage (185758) on Friday January 18 2002, @09:29AM (#2861822) Homepage
    Why do people think that having a law regarding exporting software/code is going to stop ANYONE from using it? It's just like gun laws in Canada, the only people who are affected are the law abiding citizens who legally use their guns, or have them for decoration. If someone REALLY wants to use 128 bit encryption, they are going to. There is no way around that. Software is so easily obtainable that anyone who has access to a Windows platform can download it and install it. It really is a no brainer.

    Now for this guy who happened to have 40-bit encryption installed by default, he's just a moron then. He obviously didn't know that 40-bit was easily breakable, he didn't care, or didn't take the 10 seconds to download and enable 128 bit on his computer.

    I chalk it up to stupidy on his part for not simply looking for the stronger encryption (it's out there, and easily obtainable).

    Now for the conspiracy theorists: He wasn't ACTUALLY using 40-bit encryption, that's what they want you to think. He was using the full 128-bit encryption, but the NSA can easily crack that level now due to the computer power they have. They simply tell the media it's 40-bit just so that we don't come up and develop something even more powerful which would take them longer to decrypt.
  • as if that would help by koekepeer (Score:1) Friday January 18 2002, @09:30AM
  • Shoe bomber = idiot (Score:3, Interesting)

    by isa-kuruption (317695) <kuruptionNO@SPAMkuruption.net> on Friday January 18 2002, @09:30AM (#2861828) Homepage
    He's obviously a complete idiot for only using 40-bit encryption in the first place. He's an idiot for trying to light the shoes with a match.

    Conclusion: We know the guy is an idiot... what would happen if a SMART person tried this?
  • US blocking export by SomethingOrOther (Score:2) Friday January 18 2002, @09:31AM
    • 1 reply beneath your current threshold.
  • Get with the program... (Score:5, Informative)

    by GiorgioG (225675) on Friday January 18 2002, @09:31AM (#2861835) Homepage
    128-bit Encryption Becomes the Default in Windows 2000 Service Pack 2 (SP2) [microsoft.com]

    The Windows® 2000 operating system was the first Microsoft platform with 128-bit encryption to be shipped internationally after the United States government relaxed its export restrictions for strong encryption in early 2000. Microsoft has obtained the necessary approvals to ship Windows 2000 with strong encryption to all customers worldwide except U.S. embargoed destinations.
  • Export-level Encryption Proves Insufficient by Score0, Overrated (Score:1) Friday January 18 2002, @09:31AM
  • Enforcement is unrealistic by cheekymonkey_68 (Score:1) Friday January 18 2002, @09:32AM
  • by Anonymous Coward on Friday January 18 2002, @09:32AM (#2861846)
    In fact, we should just make terrorism illegal, then people would stop. Because criminals follow the law, right?

    Even though Osama was able to get a bunch of people into US flight schools, he surely wouldn't've been able to go to CompUSA, buy a copy of W2K off the shelf, and somehow get a 5 x 5 x 1/16" piece of plastic outside a country with roughly 10,000 miles of borders and 1500 international flights daily. Nope, no way that coulda happened.
  • Psss, don't tell anyone (Score:4, Interesting)

    by f00zbll (526151) on Friday January 18 2002, @09:33AM (#2861850)
    As the new scientist article stated at the end, "there are other ways." If the government has learned anything from current events is High Tech is useless when dealing with people who only trust those they know. As as the article said, "not using strong encryption just makes it easier" for bad people to exploit businesses.

    Considering how much planning and communication had to take place for 9/11 to happen, we only have a video tape and a few files? Sounds like the low tech method works better for keeping things under raps. Is a computer isn't going to commit suicide if the FBI catches it (well I suppose you could boobie trap it). A terrorist on the otherhand can mislead, or commit suicide. The only thing weak encryption does is make businesses more vulnerable to government snooping and crackers. Plus the government can use things like a warrant to get access. Oh I forgot they hate having to ask judges for warrants and answering questions like "do you have sufficient proof or cause?"

  • Too Many Secrets... by josquint (Score:1) Friday January 18 2002, @09:34AM
  • Of course.... by dfenstrate (Score:2) Friday January 18 2002, @09:34AM
  • Wrong magazine had to Crack a computer. by Mr Krinkle (Score:1) Friday January 18 2002, @09:38AM
  • New slashdot poll (Score:3, Funny)

    by Salsaman (141471) on Friday January 18 2002, @09:38AM (#2861879) Homepage
    What should be the US legal limit on encryption for export ?

    40 bit

    128 bit

    Cowboy Neal with a pen

  • Wrong Question by ebacon (Score:1) Friday January 18 2002, @09:38AM
  • Faulty analysis... (Score:3, Interesting)

    by Fnkmaster (89084) on Friday January 18 2002, @09:42AM (#2861902)
    This is a serious case of faulty analysis, if anybody thinks this is evidence that crypto export restrictions ever were or could be effective. While it is true that forcing the default shipments of much software to 40-bit does make getting strong crypto a _conscious_ decision and require a small, but definite output of effort, to find and download a secure solution (in your country of choice), the people most likely to put forth this effort are those who need it.


    Who needs it? Well, businesses, anybody with information they want to keep private, anybody with information they don't want their bosses or employers to know, anybody who keeps secret information or documents that they don't want wife/children/family/parents to pry into, people with mistresses, and yes, perhaps some really bad people like terrorists.


    The fact that one already acknowledged to be EXTREMELY incompetent terrorist who failed to successfully ignite his shoe bomb (which was packed with high explosive) ALSO failed to properly obtain a high security add-on for his computer is evidence of exactly one thing: his incompetence. Not of the effectiveness of export restrictions. So while I agree that perhaps investigators obtained useful information because he was using weak encryption, and that is fortunate, export restrictions would not prevent a determined, modestly informed criminal or criminal organization from using real crypto (as opposed to 40 bit crippleware).


    You could argue that a really determined criminal could take down a plane too. That's probably true, but we're talking about levels of effort on different orders of magnitude here. One involves 5 minutes and a few clicks on a computer. The other involves serious tactical planning to commit a terrorist act. Conclusion: crypto export restrictions have never protected us from a competent criminal, and they still cause economic harm by restricting free trade of goods that support proper encryption by US companies, giving unfair advantage to foreign companies.

  • Rjindael is from Belgium! by Steve Cox (Score:2) Friday January 18 2002, @09:42AM
  • A STARTLING admission by the Wall Street Journal! by Tsar (Score:2) Friday January 18 2002, @09:43AM
  • conspiracy theorie! (Score:3, Insightful)

    by Juju (1688) on Friday January 18 2002, @09:45AM (#2861919)
    So let me get this straight...

    Two journalist are in Afghanistan, one of their laptop is broken, so they deside to buy anther one.

    So far, so good, I would probably have tried to repair it and ask for replacement, but then, I am not in Afghanistan.

    They buy two computers, another laptop and a desktop. What did they buy the desktop for again?
    And they buy it from people who are looting buildings? I always thought journalist to have low ethics anyway...

    Instead of re-installing the PC, they decide to look at what is on it. Ok, I can understand that, but they must have spent quite some time looking at those files to determine that they were willing to spend five days to crack some of the encrypted files they found.

    In other words, two american journalist pick up a PC (they had no reason to buy), and they happen to find Terrorist secret files on it. Sounds too good to be true. I don't buy it, it's a setup.

    And now they use that to attest of the validity of the export restriction on encryption.

    If the BSA or RIIA is going after me because I have some illegal stuff on my hard disk, I can just claim that I got my PC second hand, and that all this stuff was left there by the terrorists who had the PC first...
  • If only the US would ban export of weapons by Anonymous Coward (Score:2) Friday January 18 2002, @09:47AM
  • 5 days?! by FyRE666 (Score:1) Friday January 18 2002, @09:48AM
    • Re:5 days?! by AnotherBlackHat (Score:2) Friday January 18 2002, @03:09PM
    • 3 replies beneath your current threshold.
  • by eXtro (258933) on Friday January 18 2002, @09:48AM (#2861949) Homepage Journal
    The reason why this guys messages were decrypted through brute force wasn't because of the 40 bit encryption, it was because he didn't understand the difference between good encryption and bad encryption. The encrypting file system under Windows 2000 will only provide protection against casual inspection. Your day to day things are pretty secure, mostly because nobody is interested enough in it to go to the expense of decrypting it. When you try to blow up an airliner people become a bit more interested in the data you've got stored on your computer.

    If this guy was informed about cryptography (not necessarily knowledgable, but informed - sort of like having the equivalent of a financial planner for cryptography) he would've used one of a number of bolt on products to really secure his computer. Some of these products are commercial, others are open source. He may have more difficulty getting (and if he's properly informed - less trust in) the higher grade commercial packages but it'd still be doable. Fly to California, go to Fry's and buy it. If he goes for the source code route its just about impossible to police. You can get it anywhere in the world where there's an internet connection or a mail system (CD ROM or a package of floppies through the mail).

    Saying that 40 bit encryption is an assistance to the CIA/FBI/NSA is only true if you rely on having stupid terrorists, in this case it was obviously true. Suppose they hired the equivalent of a director of IT though, who would come up with approved solutions. Life would become more difficult for the government. Whether the solutions that are proposed are legal or not doesn't matter. You're planning on blowing up aircraft, knocking down buildings and killing people. You won't even bat an eyelash at breaking encryption laws.

    What low grade encryption really helps with is gathering data against ordinary citizens such as the guy who was a bit less than honest about his tax return.

    Also, despite this low grade encryption the attack wasn't stopped. It's only after everybodies eyes were on this guy that his computer was examined and found to have low grade encryption.

  • by mdahlman (306918) on Friday January 18 2002, @09:53AM (#2861979) Homepage
    I've just read 50 posts saying that limiting export strength encryption won't stop any non-US people from using higher encryption. I agree that this makes perfect sense. It's completely logical.

    But everyone seems to conveniently ignore the fact that this group DID rely on the export strength encryption that they had available. They DIDN'T use PGP or any one of the myriad of other options for better encryption. Perhaps the premise that a slashdot reader is familiar with other encryption techniques isn't equivalent to the premise that an Al-Qaida member will be familiar with other encryption techniques.

    Any reasonable and complete argument against limiting export strength encryption at least needs to address this fact. One could argue that it is an unusual case, that it won't be repeated, that you don't care if non-US folks have default access to better encryption, etc.

    But arguing that it will never stop anyone from using better techniques seems silly when presented with this case of a group using exactly the default abilities that they were given in Win2k.
  • I like the independent. by Pat__ (Score:1) Friday January 18 2002, @09:53AM
  • by Kefaa (76147) on Friday January 18 2002, @09:53AM (#2861983)
    "Should the US prohibit the export of high-encryption software? Here is a case where the default values (40 bit) clearly helped recover valuable information from a system."

    If the US could somehow ensure that we were the only ones who provided encryption, this may be an argument on national security bounds. However, we cannot.

    If anything, all of this talk about encryption has provided criminals with the knowledge that we can eventually break in. Even if that were not the case, better encryption is available in any of over a hundred countries, many with little concern for US regulations. I believe 128-bit encryption has been freely available for years, provided by companies outside the US.

    We need freely available encryption of every higher levels to stay ahead of our enemies (and some would argue our friends). Consider it only took five days to break the 40-bit encryption. How long would it take someone to brute force his or her way into a financial institution? Banks, trading firms; electronic merchants, etc. are and or should be constantly upgrading their security and encryption levels.

    Encryption should be viewed like a car. A car has very powerful, valuable, perhaps even essential uses. Unfortunately, people can use cars to rob, kidnap, and murder. Still, we allow and even encourage access to cars because the benefits far outweigh the problems that periodically occur.
  • Fatal assumption: terrorist == stupid by Dix (Score:1) Friday January 18 2002, @09:54AM
  • Hey its M$ by securityman (Score:1) Friday January 18 2002, @09:55AM
    • Re:Hey its M$ by WildBeast (Score:1) Friday January 18 2002, @10:00AM
    • Re:Hey its M$ by AnotherBlackHat (Score:1) Friday January 18 2002, @06:57PM
  • Definately. by supabeast! (Score:2) Friday January 18 2002, @10:00AM
  • So... by nicadic (Score:1) Friday January 18 2002, @10:01AM
    • Re:So... by nicadic (Score:1) Friday January 18 2002, @01:40PM
    • 1 reply beneath your current threshold.
  • What Encryption scheme? by Discoteck (Score:1) Friday January 18 2002, @10:01AM
  • The Question... by L-Wave (Score:1) Friday January 18 2002, @10:02AM
  • Isn't PGP already found throughout the world? by Archie Steel (Score:1) Friday January 18 2002, @10:05AM
  • oh great by austad (Score:2) Friday January 18 2002, @10:07AM
  • More Questions Than Answers by hotgrits (Score:1) Friday January 18 2002, @10:07AM
  • Doesn't make sense by gaj (Score:1) Friday January 18 2002, @10:13AM
  • Interesting question... (Score:3, Insightful)

    by Noryungi (70322) on Friday January 18 2002, @10:17AM (#2862149) Homepage Journal
    A couple of points to be noted:
    • Win2K uses DES, which is notoriously vulnerable to today's raw CPU power and dedicated, custom-built machines. [eff.org]
    • "Export-grade" US crypto is ridiculously vulnerable, and this has been known for years. People who take crypto seriously outside of the US have other sources [pgpi.org] of crypto [gnupg.org].

    Despite this public knowledge, Al Quaeda has been using weak (MS-supplied) crypto to protect sensitive information... that could be discovered within days. Therefore:
    • Al-Quaeda/Bin Laden operatives are not the crime geniuses the US government say they are. As a matter of fact, they appear as pretty incompetent to me.
    • The [CIA | NSA] should have intercepted that data before 9/11 -- or, at the very least, got those machines before the reporters did. They also appear as pretty incompetent to me, and I don't know if that's good news or not...

    Just my US$0.02...
  • Export of strong crypto helps US by Charles Dodgeson (Score:1) Friday January 18 2002, @10:17AM
  • Bear with me... by jgerman (Score:2) Friday January 18 2002, @10:19AM
  • Export BLAH! by ImaLamer (Score:2) Friday January 18 2002, @10:19AM
  • Don't you actually READ anything!?!? by Guppy06 (Score:2) Friday January 18 2002, @10:24AM
  • by Rogerborg (306625) on Friday January 18 2002, @10:24AM (#2862212) Homepage

    There I was, foaming at the mouth and ready to launch into a "how can you be so stupid?" diatribe. How can you keep encryption out of the hands of Bad People by denying it to Good People? In general terms, writing laws aimed at criminals is futile, because the criminals (by definition!) won't care about the law and will use whatever technology or methods they want. Nobody would be stupid or lazy or overconfident enough to use the lame default encryption on an export system, surely?

    And then I read the article.

    The al-Qa'ida machine was indeed running 40 bit encryption. It's hard to credit, but it really does appear that they simply were too stupid or too lazy or overconfident to upgrade the default lame-o-crypt settings. It's astonishing, especially compared to the planning that they put into September 11th, but there it is.

    No, I don't think we should try and ban strong encryption. There are plenty of Good People who can make use of it (think Tibet), and any competent and determined Bad People can get it anyway. But these opponents just demonstrated clearly that while they were determined, they were not competent, and that changes my mind, just a litle.

    I can see an argument for encouraging developers (Microsoft, MacOS and yes, Linux hackers) to supply 40 bit security by default on all consumer systems. Aunt Jemima doesn't need strong encryption, you and I probably don't need it. I wouldn't want strong encryption to be limited, but honest to god, I'd be flattered if anyone ever thought it was worth breaking even 40 bits worth on anything that I produced. I want the option to upgrade to be there, but I feel no particular need to use it, and here's the kicker: the less we kick up a fuss about it - and just quietly download the strong stuff ourselves without demanding that Aunt Jemina have it by default - the better.

    I can't help but think that the more noise we make about the distinctions between low and high encryption, the more likely it is that even stupid, lazy, overconfident terrorists will perk up their ears and ask "Hey! Is this something we should be thinking about? Maybe we should send Achmed out to buy a copy of 'Security For Dummies'." Because they clearly are dummies, and I'm quite happy for them to stay that way, thanks all the same.

  • They used brute force... by tthomas48 (Score:1) Friday January 18 2002, @10:26AM
  • A Terrorist con-trick? by PhatAir (Score:1) Friday January 18 2002, @10:36AM
  • Why not export by Anonymous Coward (Score:1) Friday January 18 2002, @10:41AM
  • DVD CSS by Malc (Score:2) Friday January 18 2002, @10:42AM
  • DMCA anyone? by {*} (Score:1) Friday January 18 2002, @10:43AM
  • Microsoft EFS was broken in 1999 by Anonymous Coward (Score:1) Friday January 18 2002, @10:51AM
  • Various Crypto Strengths.. (Score:3, Funny)

    by dfenstrate (202098) <dfenstrate @ g m a il.com> on Friday January 18 2002, @10:56AM (#2862430)
    128 bit- HaHa, silly mortal! You'll never unlock my secrets before the apocolypse comes!!!
    64 bit- You'll get my secrets when they're no longer of any use! (RC5 anyone?)
    56 bit- Never! Never will you have my secrets. If never means three weeks from now anyway.
    40 bit- You'll have to arm-wrestle me for access.
    32 bit- You'll have to thumbwrestle me for access.
    24 bit- You want access? You'll pry it from my cold, dead... Hey, give that back!!!
    8 bit- What's your favorite color?
    4 bit- Guess my shoe size
    1 bit- Want access?
    0 No
    1 Yes
  • Terrorists have the same user problems we do .... by hmarq (Score:1) Friday January 18 2002, @11:13AM
  • What software did they use? by BLKMGK (Score:2) Friday January 18 2002, @11:17AM
  • Foreign Students in the US by elzubeir (Score:1) Friday January 18 2002, @11:30AM
  • Cracking Windows 2000 VS "getting In" by toby360 (Score:1) Friday January 18 2002, @11:38AM
  • What a bunch of moronic Slashbots by duffbeer703 (Score:2) Friday January 18 2002, @11:39AM
  • why Export crypto = Domestic crypto by SaberTaylor (Score:1) Friday January 18 2002, @11:40AM
  • Lives by SilentChris (Score:2) Friday January 18 2002, @11:51AM
  • Duh! by MrWorf (Score:1) Friday January 18 2002, @11:53AM
  • The Shoe Bomber isn't the only idiot out there... by jparker (Score:1) Friday January 18 2002, @11:56AM
  • Madness... by Catbeller (Score:2) Friday January 18 2002, @11:58AM
  • Cretins by MjDascombe (Score:1) Friday January 18 2002, @11:59AM
  • Okay. by mindstrm (Score:2) Friday January 18 2002, @12:26PM
  • Sure, ban strong encryption by anonymous_wombat (Score:1) Friday January 18 2002, @12:30PM
  • It IS Illegal! by segvio (Score:1) Friday January 18 2002, @12:38PM
  • by nick_davison (217681) on Friday January 18 2002, @12:38PM (#2863163)
    There are a lot of arguments about how a reasonably motivated terrorist can just code their own strong crypto. But that kind of misses the point.

    I would imagine that most decryption is done in bulk, sifting through for the occasional terrorist tidbit. Even if some terrorists do use 128+ bit, it frees up a hell of a lot of resources if the majority of the load is still easily crackable. It also allows the authorities to montior more different sources so now they can add minor suspects rather than having to focus on the major ones.

    So, yes, for the most sophisticated criminals, export laws don't make a difference. For the total bulk work that the NSA etc. do, reducing the number of people with strong crypto makes their lives easier.
  • Not a good way to solve the problem by johnpelster (Score:1) Friday January 18 2002, @01:02PM
  • The Weakest Link by filtersweep (Score:1) Friday January 18 2002, @01:17PM
  • A few points by ToLu the Happy Furby (Score:2) Friday January 18 2002, @01:32PM
  • it won't help one bit by EdIsSoKewl (Score:1) Friday January 18 2002, @01:47PM
  • So we'll import our crypto from overseas... by Zinho (Score:1) Friday January 18 2002, @01:49PM
  • Rule of thumb I use by karlm (Score:1) Friday January 18 2002, @01:50PM
    • Misprint by karlm (Score:1) Friday January 18 2002, @01:53PM
  • Strong crypto is not needed for security by Belly of the Beast (Score:1) Friday January 18 2002, @02:13PM
  • Perhaps the govt has a good (but hidden) reason. by surfcow (Score:1) Friday January 18 2002, @02:49PM
  • That just goes to show you. by ebyrob (Score:1) Friday January 18 2002, @02:54PM
  • This is not very logical... by questforme (Score:1) Friday January 18 2002, @04:29PM
  • Distibuted.net : crack Al Qaeda by karlm (Score:1) Friday January 18 2002, @04:49PM
  • Electronic rights by scotto1973 (Score:1) Friday January 18 2002, @04:59PM
  • Source code? by 3Suns (Score:1) Friday January 18 2002, @05:40PM
  • What about the DMCA? by roman_sez (Score:1) Friday January 18 2002, @05:49PM
  • Did anybody see the decrypted material? by Pussy Is Money (Score:1) Friday January 18 2002, @05:55PM
  • Harumph by TheCabal (Score:1) Friday January 18 2002, @06:39PM
  • Haw Haw by Mark_in_Brazil (Score:1) Friday January 18 2002, @09:42PM
  • excerpts from a recent conversation... by Anonymous Coward (Score:1) Friday January 18 2002, @10:22PM
  • Should 128 || 1024-bit crypto be BANNED? by Dwonis (Score:2) Saturday January 19 2002, @12:24AM
  • This is really, really alarmist. by Wakko Warner (Score:2) Saturday January 19 2002, @04:04AM
  • Re:why usa? by {X-Frog} (Score:1) Friday January 18 2002, @09:31AM
  • Re:But ... the laws have changed already by ComaVN (Score:1) Friday January 18 2002, @09:48AM
    • Re:But ... the laws have changed already by Tipsy McStagger (Score:1) Friday January 18 2002, @09:54AM
    • French version same - here's why (Score:4, Interesting)

      by BLKMGK (34057) <morejunk4me@ho[ ]il.com ['tma' in gap]> on Friday January 18 2002, @10:21AM (#2862177) Homepage
      It used ot be that the French version was horribly cripled. Lotus folks actually compared it to sending mail on a postcard :-)

      Anyway, it was done this way becaue th eFrench did NOT want the US Govt. to have an easier time decrypting the documens than did the French Govt. so they required a really poor encryption be used in Notes. Once the US Govt. dropped it's export restricitons the French Govt. lifted this requirement since this placed us all on a "level" playing field. One of the point revisions of R5 brought nearly all of the versions together except the French I THINK. Due to the extreme crippling they had to do the French may have had their own upgrade or have been forced to reissue certs and IDs - I'm fuzzy on this. I believe if you spend some time on the Notes site you'll find your answer.

      On a plus note - Lotus has determined that 128 just isn't good enough. They mentioned plans to upgrade the crypto at Lotusphere last year but it probably won't be there till RNext goes gold. If there's one product out there that actually seems to care about security and was WAY ahead of the certificate thing it's Notes. And no, they aren't perfect...
      [ Parent ]
  • Re:But ... the laws have changed already by Tipsy McStagger (Score:1) Friday January 18 2002, @09:52AM
  • Re:But ... the laws have changed already by LinuxHam (Score:2) Friday January 18 2002, @09:52AM
  • Re:why usa? by Guppy06 (Score:2) Friday January 18 2002, @10:10AM
  • Re:But ... the laws have changed already by Theodrake (Score:1) Friday January 18 2002, @10:10AM
  • Re:why usa? by {X-Frog} (Score:1) Friday January 18 2002, @10:19AM
  • Re:But ... the laws have changed already by Troed (Score:1) Friday January 18 2002, @11:09AM
  • Re:why usa? by {X-Frog} (Score:1) Monday January 28 2002, @01:27PM
  • 32 replies beneath your current threshold.
(1) | 2