Kiss goodbye to privacy forever when brain-implanted comms gear becomes the norm – guru Whit Diffie
- Reference: 1621294443
- News link: https://www.theregister.co.uk/2021/05/17/rsa_cryptography_privacy/
- Source link:
One of the experts even warned we're a generation away from totally destroying our privacy with brain-connected communications devices.
RSA encryption
That aforementioned mathematical technique was documented in a non-peer-reviewed [1]paper by respected German cryptographer Claus-Peter Schnorr that emerged in March and has undergone revisions since. He claimed he had devised a method to find the prime factors p and q of an RSA modulus n far faster than rival algorithms, boasting in one draft: "This destroys the RSA cryptosystem."
Reader, [2]it [3]will [4]not .
Speaking at the RSA Conference's [5]Crytographers' Panel , Rivest said he'd contacted Schnorr and others as soon as he heard about the paper, pointed out some possible issues, and reckons we'll have to wait "until the dust settles" on whether the technique works as stated.
[6]
[7]
[8]
"I tend to be skeptical and the proof is in the pudding when it comes to factoring – I want to see numbers get factored," Rivest said. "Factoring has a very important property that you can demonstrate that you can factor without needing to reveal how. You can factor some of the [9]challenge numbers and give people notice if it works."
Shamir added that, while Schnorr's proposed technique does seem to speed up the factorization of numbers, it appears the speed increase is less than what the paper promises, and wouldn't be effective against the large primes in use today by cryptosystems like RSA.
NFT == NBD
Another thing that drew fire was [10]NFTs , which Rivest said were "a bit like homeopathic medicine" in that there's not really a lot to them: the blockchain tokens merely point to somewhere you can download images and other files, rather than contain the actual media. Shamir was more upbeat: "Certainly it's not harmful. Some people collect coins, some people collect stamps, some people collect NFTs. If they want to pay money for this, it's fine with me."
[11]Blessed are the cryptographers, labeling them criminal enablers is just foolish
[12]University duo thought it would be cool to sneak bad code into Linux as an experiment. Of course, it absolutely backfired
[13]Googlers show off AI that can help developers protect crypto code from key-slurping side-channel attacks
[14]Got $50k spare? Then you can crack SHA-1 – so OpenSSH is deprecating flawed hashing algo in a 'near-future release'
Quantum money grab
Both were skeptical of quantum computers defeating encryption though the most trenchant criticism of the technology came from Prof Ross Anderson of England's University of Cambridge.
Physicists saw the pile of money poured into researching encryption and wanted the same for quantum mechanics, he said, adding it was a way "for number theorists to get their shovels into the military budget." The research has been useful for developing quantum sensing devices, though he was "entirely unimpressed" with such systems' cryptographic skills and doubted they would ever work as decryption engines.
AI too easy to hoodwink
He was similarly unimpressed with machine-learning-powered computer security tools, saying they should be easy to confuse and defeat, judging by his research on natural-language processing systems. Such systems have to be very finely tuned to work properly, and introducing certain data and variables can often "send then haywire." An adversary could find ways to feed bad packets into an AI network scanner, say, to either fool it into allowing malicious traffic through – or denying all traffic, shutting down connectivity. We've [15]written a lot about [16]these sorts of [17]scenarios .
Rivest agreed, reminding us that complexity is the enemy of security, and such AI systems were very complex indeed.
Carmela Troncoso, head of the head of the Security and Privacy Engineering Laboratory at École Polytechnique Fédérale de Lausanne in Switzerland, also agreed, pointing out that not only was resilience an issue but questioning whether it was possible to build a machine-learning system that was explainable, fair, and privacy preserving as well.
Privacy will be a myth
This last factor was also on Whitfield Diffie's mind. The industry guru, co-creator of the Diffie–Hellman key exchange, appeared in a Q&A at the end of the panel session and predicted that privacy, as we know it, will be gone in a generation when communications devices implanted in people's bodies become the norm.
I saw no way that human freedom could stand against improving communications
"For a long time I've been saying that I saw no way that human freedom could stand against improving communications," he opined.
"And I doubt we're a decade from a bunch of early adopters getting communicators put in their head and you won't have to force people to get them because you won't be competitive without it. The freedom we now enjoy will become very hard to come by and we'll think 'oh gosh, back in those days when we actually had privacy'".
[18]
As to what Diffie thought was the biggest security threat, his answer was simple: "Companies." ®
Get our [19]Tech Resources
[1] https://eprint.iacr.org/2021/232
[2] https://www.cryptomathic.com/news-events/blog/rsa-is-not-destroyed-but-do-remain-vigilant-and-be-crypto-agile
[3] https://crypto.stackexchange.com/a/88590
[4] https://twitter.com/inf_0_/status/1367376526300172288
[5] https://www.rsaconference.com/usa/agenda/session/the-cryptographers-panel
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YKM72ucV@iefDawMCck21AAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKM72ucV@iefDawMCck21AAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKM72ucV@iefDawMCck21AAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://en.wikipedia.org/wiki/RSA_Factoring_Challenge
[10] https://www.theregister.com/2021/05/04/what_is_nft/
[11] https://www.theregister.com/2021/05/12/blessed_are_the_cryptographers/
[12] https://www.theregister.com/2021/04/21/minnesota_linux_kernel_flaws_update/
[13] https://www.theregister.com/2020/08/11/ai_side_channel/
[14] https://www.theregister.com/2020/05/28/openssh_deprecating_sha1/
[15] https://www.theregister.com/2021/05/05/ai_backdoors/
[16] https://www.theregister.com/2021/05/05/microsoft_ai_security/
[17] https://www.theregister.com/2021/03/05/openai_writing_attack/
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKM72ucV@iefDawMCck21AAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[19] https://whitepapers.theregister.com/
Anybody remember "The Presidents Analyst" and TPC (The Phone Company)?
Who remembers the Forbin Project* and doesn't forget Colossi?
Carmela Troncoso, head of the head of the Security and Privacy Engineering Laboratory at École Polytechnique Fédérale de Lausanne in Switzerland, also agreed, pointing out that not only was resilience an issue but questioning whether it was possible to build a machine-learning system that was explainable, fair, and privacy preserving as well.
Does that more than suggest, and who would disagree, that it is certainly possible to build a machine-learning system that was/is unexplainable [for fantastic stealth], unfair [for overwhelming advantage] and privacy busting [for no hidden dirty secrets to bugger up the machine learning].
Resilience then would not be an issue to worry oneself unnecessarily about.
And get used to what's on Whitfield Diffie's mind as shared in the four paragraphs under the sub-title, Privacy will be a myth for that boat sailed away ages ago and where it docked on its travels revealed for delivery all manner of exotic wares and erotic fare to trade and free enslaved populations with.
Whatever happened to Hugo de Garis? He seemed to know what he was talking about, and what we are here also talking about is not greatly dissimilar.
Hugo de Garis is a retired researcher in the sub-field of artificial intelligence known as evolvable hardware. He became known in the 1990s for his research on the use of genetic algorithms to evolve artificial neural networks using three-dimensional cellular automata inside field programmable gate arrays. ...... [1]https://en.wikipedia.org/wiki/Hugo_de_Garis
* ....... If of a nervous and/or anxious disposition, beware.
[1] https://en.wikipedia.org/wiki/Hugo_de_Garis
"you won't be competitive without it"
So many bad decisions are driven by that fear, real or not, especially if you use a broad definition of competition.
It certainly impacts personal privacy as we can see not just in a future brain interface but in the present day, with people turning their lives over to Google or Facebook or Apple.
Beyond privacy, we see it all the time in IT with companies grasping for the next big thing without regard for the consequences. It's why beancounters win with their fears of the next quarter. It's why consultants who say they can tell the future trump in-house experts who understand the present. It's what keeps Gartner, with their Curve and Magic Quadrant, in business.
And it seems unstoppable.