{"id":4408,"date":"2013-06-20T14:56:09","date_gmt":"2013-06-20T18:56:09","guid":{"rendered":"http:\/\/www.starkeith.net\/coredump\/?p=4408"},"modified":"2013-06-21T18:00:48","modified_gmt":"2013-06-21T22:00:48","slug":"a-renewed-case-for-encryption","status":"publish","type":"post","link":"https:\/\/www.starkeith.net\/coredump\/2013\/06\/20\/a-renewed-case-for-encryption\/","title":{"rendered":"A (Renewed) Case for Encryption"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"4410\" data-permalink=\"https:\/\/www.starkeith.net\/coredump\/2013\/06\/20\/a-renewed-case-for-encryption\/gpg\/\" data-orig-file=\"https:\/\/www.starkeith.net\/coredump\/wp-content\/uploads\/\/2013\/06\/gpg.png\" data-orig-size=\"128,128\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"gpg\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/www.starkeith.net\/coredump\/wp-content\/uploads\/\/2013\/06\/gpg.png\" class=\"alignright size-full wp-image-4410\" alt=\"gpg encryption\" src=\"http:\/\/www.starkeith.net\/coredump\/wp-content\/uploads\/\/2013\/06\/gpg.png\" width=\"128\" height=\"128\" \/>I kind of hoped that this NSA\/PRISM\/wholesale government surveillance business would re-energize people into actually getting back into using encryption, and perhaps even trying to solve the problem of getting more people to actually use it.<\/p>\n<p>One of the big problems with encryption &#8211; for example, email encryption using public key cryptography (PGP or GnuPG) &#8211; has been just getting enough people to start using it. With the way public key encryption works, you need to use encryption, AND the person you&#8217;re sending it to needs to use encryption, too.<\/p>\n<p>In addition, there&#8217;s also the further complication of signing one another&#8217;s keys and assigning trust levels and so on&#8230; it&#8217;s just a bit too complicated and technical for your average user.<\/p>\n<p>However, <em>it doesn&#8217;t have to be complicated<\/em>, and given what we&#8217;ve learned recently, it seems to me <em>it really shouldn&#8217;t be &#8211;<\/em> and that it is in all of our best interests to make it be as simple and easy as possible.<\/p>\n<p>People have been harping on about the importance of encryption for ages, but widespread adoption has mostly been limited to SSL (for webmail &amp; other web apps &amp; services). This sort of encryption prevents a 3rd party from intercepting your communication with Google or Microsoft or Facebook or your bank or whatever, but none of that matters if your data is just going to be handed over to the government by the company on the other end anyway!<\/p>\n<p>SSL encrypts your connection and your data during <em>transmission<\/em>, but the actual <em>contents<\/em> of your data are unencrypted at either end, and vulnerable to interception. It&#8217;s a good first step, but it isn&#8217;t enough &#8211; not anymore.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"4416\" data-permalink=\"https:\/\/www.starkeith.net\/coredump\/2013\/06\/20\/a-renewed-case-for-encryption\/password\/\" data-orig-file=\"https:\/\/www.starkeith.net\/coredump\/wp-content\/uploads\/\/2013\/06\/password.png\" data-orig-size=\"128,128\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"password\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/www.starkeith.net\/coredump\/wp-content\/uploads\/\/2013\/06\/password.png\" class=\"alignleft size-full wp-image-4416\" alt=\"password\" src=\"http:\/\/www.starkeith.net\/coredump\/wp-content\/uploads\/\/2013\/06\/password.png\" width=\"128\" height=\"128\" \/>On the other hand, actually encrypting the <em>contents<\/em> of your communications &#8211; the email, the files, etc. &#8211; means that even if they are stored on a server (as your email is, for example), they are still encrypted &#8211; and most importantly, <em>the server doesn&#8217;t have the decryption key<\/em> &#8211;\u00a0 only the recipient does.<\/p>\n<p>What this would means in practice is that it would <strong>prevent the wholesale collection of data.\u00a0<\/strong> If the government wanted the contents of someone&#8217;s communications, they would need to go after that individual; they wouldn&#8217;t be able to just pull it out of a big database.<\/p>\n<p>Since going after an individual takes effort and requires a subpoena or at least a court order of some sort, there&#8217;s protection built-in. Plus, now the government&#8217;s attempts to access your data would be limited in scope to one person at a time, and they can&#8217;t be done in secret &#8211; or, at least, they&#8217;d be <em>less<\/em> secretive.<\/p>\n<p>The government may still collect other data about you, of course &#8211; encryption is not a cure-all. It may still collect &#8220;metadata&#8221; about you &#8211; times and dates and such &#8211; but at least the <strong><em>content<\/em><\/strong> of your data remains secure until specifically subpoenaed.<\/p>\n<p>As a side note, the NSA has repeatedly said that this is what it does anyway, as part of an attempt to justify why we shouldn&#8217;t be worried about this &#8211; but because everything the NSA does is secret, we have no way to be sure that this is actually the case. All we have to go on is the NSA saying &#8220;trust us, we won&#8217;t read your email without a court order (that you aren&#8217;t allowed to see).&#8221; Doesn&#8217;t exactly inspire a lot of trust, now does it? Especially given the track record we&#8217;re dealing with.<\/p>\n<p>Perhaps if our government had a long &amp; strong history of being trustworthy, of being transparent with its behavior, of standing up for individual rights and privacy, and severely limiting the collection and access of people&#8217;s data to only what is explicitly needed for specific cases and actions, this whole wholesale surveillance thing wouldn&#8217;t be such an issue.<\/p>\n<p>But sadly, this is not the case &#8211; our government has shown, again and again, that it <strong>cannot be trusted<\/strong> in this regard, and that <strong>when given the opportunity, it will make a grab for as much power as it possibly can get.<\/strong><\/p>\n<p>Given the recent revelations on exactly how much power (and, by extension, data) our government has grabbed as of late, making actual content encryption available, widespread, and easy to use seems like an absolute no-brainer.<\/p>\n<p><span style=\"font-size: smaller;\">Icons courtesy of the <a href=\"http:\/\/www.everaldo.com\/crystal\/\">Crystal Icon Set<\/a>.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I kind of hoped that this NSA\/PRISM\/wholesale government surveillance business would re-energize people into actually getting back into using encryption &#8211; but sadly it doesn&#8217;t seem that way. Content encryption &#8211; as opposed to just endpoint encryption, like SSL &#8211; is important, and especially so in light of this kind of wholesale government surveillance.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"webmentions_disabled_pings":false,"webmentions_disabled":false,"_jetpack_memberships_contains_paid_content":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":3,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"","footnotes":"","jetpack_post_was_ever_published":false},"categories":[203,5],"tags":[344,192,342,348,19,343,347,345,67,346],"class_list":["post-4408","post","type-post","status-publish","format-standard","hentry","category-internet-technology","category-technology","tag-cryptography","tag-email","tag-encryption","tag-gnupg","tag-government","tag-nsa","tag-pgp","tag-prism","tag-privacy","tag-spying","entry"],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pimUj-196","jetpack-related-posts":[{"id":846,"url":"https:\/\/www.starkeith.net\/coredump\/2007\/02\/13\/truecrypt\/","url_meta":{"origin":4408,"position":0},"title":"TrueCrypt","author":"Keith Survell","date":"February 13, 2007","format":false,"excerpt":"I think this is GREAT software. The ability to make encrypted disks anywhere on your computer (or USB memory device) is a boon to security nuts like me. And the encryption that's available from this software is very, very good. (As an added bonus, it's open source - so you\u2026","rel":"","context":"In &quot;tech&quot;","block_context":{"text":"tech","link":"https:\/\/www.starkeith.net\/coredump\/category\/technology\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1101,"url":"https:\/\/www.starkeith.net\/coredump\/2008\/05\/08\/online-identity-anonymity\/","url_meta":{"origin":4408,"position":1},"title":"Online Identity\/Anonymity","author":"Keith Survell","date":"May 8, 2008","format":false,"excerpt":"This story over on Slashdot about how the Washington Post's online executive editor Jim Brady is arguing against anonymity sparked quite a lively little debate. The problem isn't really anonymity - it's identity. They don't want to know who a particular person is, they just want to somehow stop that\u2026","rel":"","context":"In &quot;society&quot;","block_context":{"text":"society","link":"https:\/\/www.starkeith.net\/coredump\/category\/society\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1231,"url":"https:\/\/www.starkeith.net\/coredump\/2008\/07\/25\/news-from-the-not-to-distant-future\/","url_meta":{"origin":4408,"position":2},"title":"News from the Not-To-Distant Future","author":"Keith Survell","date":"July 25, 2008","format":false,"excerpt":"From a Slashdot comment on the story \"Big Six UK ISPs Capitulate To Music Industry\": BBC News April 2nd 2010 ISPs have detected a massive spike in encrypted activity on the internet. Indecipherable \"SSL\" packets have increased in volume massively in recent months. This trend is seen as \"disturbing\" in\u2026","rel":"","context":"In &quot;society&quot;","block_context":{"text":"society","link":"https:\/\/www.starkeith.net\/coredump\/category\/society\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":2572,"url":"https:\/\/www.starkeith.net\/coredump\/2009\/05\/20\/the-etiquette-of-e-mail-signatures\/","url_meta":{"origin":4408,"position":3},"title":"The Etiquette of E-Mail Signatures","author":"Keith Survell","date":"May 20, 2009","format":false,"excerpt":"Email signatures - are they still important? And is yours one of those obnoxiously long ones?","rel":"","context":"In &quot;Internet&quot;","block_context":{"text":"Internet","link":"https:\/\/www.starkeith.net\/coredump\/category\/technology\/internet-technology\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1879,"url":"https:\/\/www.starkeith.net\/coredump\/2009\/04\/07\/what-happened-to-an-open-and-transparent-government\/","url_meta":{"origin":4408,"position":4},"title":"What Happened to an \u201cOpen and Transparent\u201d Government?","author":"Keith Survell","date":"April 7, 2009","format":false,"excerpt":"A government which is above the law is not a government - it is a tyranny.","rel":"","context":"In &quot;My Opinion&quot;","block_context":{"text":"My Opinion","link":"https:\/\/www.starkeith.net\/coredump\/category\/personal\/my-opinion\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1760,"url":"https:\/\/www.starkeith.net\/coredump\/2009\/01\/26\/open-government\/","url_meta":{"origin":4408,"position":5},"title":"Open Government","author":"Keith Survell","date":"January 26, 2009","format":false,"excerpt":"Oh, yells yeah: A democracy requires accountability, and accountability requires transparency. [...] The Freedom of Information Act should be administered with a clear\u00a0presumption:\u00a0In the face of doubt, openness prevails.\u00a0The\u00a0Government should not keep information confidential merely because public officials might be embarrassed by disclosure, because errors and failures might be revealed,\u2026","rel":"","context":"In &quot;politics&quot;","block_context":{"text":"politics","link":"https:\/\/www.starkeith.net\/coredump\/category\/politics\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/posts\/4408","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/comments?post=4408"}],"version-history":[{"count":0,"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/posts\/4408\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/media?parent=4408"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/categories?post=4408"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.starkeith.net\/coredump\/wp-json\/wp\/v2\/tags?post=4408"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}