Re: HTTP is just fine

Ben Bucksch <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Hey Chris, thanks for your balanced stance. That's how I know you :)

Chris Hofmann wrote on 26.11.2015 04:04:
> taking action to fix the leaky pipes of the internet just enough to make
> progress on stampping out surveillance, and future risks of increasing
> surveillance.

The thing is: There is no technical solution against governments.
GSM has crypto. And built-in backdoors. And the crypto is weak.

TLS is weak crypto, because it relies on a third party (actually 
hundreds of third parties) to vet my communication partner. That's 
inherently insecure, and I think it was deliberate. It plays into the 
hands of governments. At the time when SSL was invented, the government 
still had to approve crypto exports (I'm sure you still vividly remember 
the time, Chris :) ), and made sure they didn't have any problem with 
surveillance. Since then, the NSA made a little progress on one or two 
fronts.

The NSA hacked Google data centers (see e.g. Google Analytics), hacked 
Linux, hacked ISPs, telcos and core routers. Dell and Lenovo added root 
keys to their computers and allowed all traffic to be intercepted.

If none of that works, they'll just pass more legislation.

Assuming that TLS will lock out the NSA is simply not taking history 
into account.

Ben
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.