On CBS MoneyWatch: 5 Great Jobs for Lousy Times
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 3 of 17:
Next »
« Previous
re: back doors
"In fact, I think the government would take steps to do exactly the opposite, and force designers to build in more "back doors" that would allow them easy access to PC data. After all, that's what they did with telecom and network hardware and service providers."

Well, the thing about software encryption is that the algorithms can be easily developed in foreign countries. With companies already off shoring so they can get cheap labor, why not do the same for software?

Also, another twist on having a "back door" is that the government uses the same encryption for their own stuff as everybody else does. If there's a back door, they risk that somebody outside the government could steal it and make it public. So if they place a back door on their own encryption, they're putting their own documents at risk if the back door key gets stolen.

In addition, the encryption we have looks like it's going to last a long time. It'll likely be 100+ years before we have computers powerful enough to break current standards, assuming computing power doubles every two years. So there's not really a need for new types of encryption.

It's doubtful the government would require a certain type of encryption by law - and even if they did, it's entirely possible to encrypt the information using a different algorithm before it reaches any type of government mandated encryption, so it would still be encrypted even after they use their back door key.

So the government would not just have to mandate their own encryption: They'd have to mandate that it be the only type of encryption people could use. Otherwise, people can just wrap it in their own encryption before passing it to the mandated encryption, negating the effectiveness of a back door.

Frankly, though, I don't see such a scenario happening. I haven't seen our congress or our president express much interest in encryption; they've got bigger things on their minds. Technology in general tends to be a footnote rather than a big issue with our government.

They're actually more lenient than they used to be with encryption. Encryption used to be considered a form of ammunition and was controlled as such. Now that's no longer the case. Of course, that was all before 9/11, so I don't know which way they lean now.

I wouldn't worry about it - you can always wrap it in your own encryption before you pass it to theirs . . .

"As you say, it would be a simple matter to modify the firmware to overwrite memory during shutdowns and startups, but there is no incentive for companies to do this."

Actually, they don't even need to do that: They simply need to leverage TPM, which never gives away its keys. With TPM, the keys are never stored in physical memory and are therefore not vulnerable to this type of attack.
Posted by: CobraA1   Posted on: 02/21/08 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Supercooled memory?  Eriamjh | 02/21/08
Millions at stake in corporate espionage ...  terry flores | 02/21/08
re: back doors  CobraA1 | 02/21/08
Clearing memory at reboot would not work.  ye | 02/22/08
RE: Supercooled memory?  bfilipiak@... | 02/22/08
A few things to note  CobraA1 | 02/21/08
Careful there  georgeou | 02/21/08
hdiutil was simply used to show successful crack  terry flores | 02/21/08
RE: (Images: How to bypass FileVault, BitLocker security)  d1g1tal_ph3r3t | 02/21/08
RE: (Images: How to bypass FileVault, BitLocker security)  riverab0@... | 02/22/08
Addition  riverab0@... | 02/22/08
Cox  CassidyJames | 02/22/08
I would like to see this tried with Firmware locked  duane@... | 02/22/08
Info still unencrypted in RAM...  robert.rohr@... | 02/22/08
Bit Locker  cobra96ds@... | 02/25/08
Encyption Law  benjaminwright75205 | 02/22/08
This is freaky  John Musbach | 02/24/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More