NODE 1759c8b3"Key Escrow" --- the very idea
Mike_Spreitzer.PARC@xerox.comThu, 21 Jul 94 16:49:59 PDT
(1) I'm not an anarchist. Does that make me out of place here? I'm willing to
live with some amount of government, as long as us owners stand a chance of
controlling or overthrowing it. My biggest problem with Capstone is that it
changes the balance of power too much.
(2) I think crimes can be committed in cyberspace. Substantially, if not
entirely, in cyberspace. Maybe not so many now. But I think it's
intellectually dishonest of us who understand the growing importance of
cyberspace to claim there won't be any social contracts there that could be
violated. I accept the terms of the 4th ammendment: search and siezure allowed
when due process followed. "Key escrow" is an attempt to implement the
cyberspatial analog of search.
(3) The Feds must know they can't prevent modestly well funded, educated, and
motivated folks from using unbreakable cryptography amongst themselves. The
argument for doing key escrow anyway is that by installing a breakable
infrastructure, they'll make enough investigations cheaper and more effective
to be worth it. Note that's a comparison of their money and success rate
against our privacy; no wonder they got it so wrong.
(4) If you accept points (1) and (2) above, you're left wanting a way to
implement searches in cyberspace when due process is followed. I hope
anarchists won't be the only people opposing changing the balance of power
greatly in the government's favor (by poorly designed key escrow). What are
the rest of us left to answer with? Perhaps a much better key escrow design.
One that integrates the search with the due process in a cryptographically
strong way; one that can't be subverted by a few people in a few organizations.
For example, who says an escrowed key must have only two parts? Why not a
whole lot of parts, distributed to a whole lot of people/organizations? If
there are only 1000 legal wiretaps in a year, and they're already fairly
expensive, we can add a fair amount to the cost before it gets significant.
And again, remember where we're weighing money against freedom. It may be that
we just have to spend more to stay a reasonably free society. Also, it's worth
debating just how strong the protections have to be. Will we need them to be
stronger than those against physical searches? How few people does it take to
subvert the current protections against illegal searches? Do we feel that
needs to be changed? How much are we willing to spend on it?
NODE c4abd2c8Re: "Key Escrow" --- the very idea
"Perry E. Metzger" <perry@imsi.com>Fri, 22 Jul 94 05:39:01 PDT
Mike_Spreitzer.PARC@xerox.com says:
> (1) I'm not an anarchist. Does that make me out of place here?
No. This is not a list for anarchists. There are some prominent people
here that happen to be anarchists -- others are socialists,
conventional liberals, conventional conservatives, and every other
stripe. Hell, even the 700 Club folks hate key escrow.
Perry
NODE 05e3109aRe: "Key Escrow" --- the very idea
Carl Ellison <cme@tis.com>Fri, 22 Jul 94 06:04:19 PDT
if you really want to propose an escrow system we can live with,
I would demand that it include:
1. unambiguous ID of the person being tapped in the LEAF-equivalent
2. multiple escrow agencies, at least one of which is the NSA HQ
(for its superior physical security)
3. watchdogs as escrow agents (e.g., ACLU, Rep & Dem parties, CPSR,
EFF, NYTimes, ...) with authorization to look for abuses of
authority and to refuse to release keys in such cases and to
publicize such cases as well as bringing them to the attention
of law enforcement for prosecution.
4. user-generated escrow keys, to reduce the chance of anyone having a
backdoor way to get the whole escrow key database.
NODE c0c05172Re: "Key Escrow" --- the very idea
adwestro@ouray.Denver.Colorado.EDU (Alan Westrope)Fri, 22 Jul 94 06:27:17 PDT
> if you really want to propose an escrow system we can live with,
> I would demand that it include:
[...]
Sorry, but there is NO escrow system I can live with -- I don't
care if John Gilmore is selected to head the escrow agency.
Alan Westrope <awestrop@nyx.cs.du.edu>
__________/|-, <adwestro@ouray.denver.colorado.edu>
(_) \|-' finger for pgp 2.6 public key
PGP fingerprint: D6 89 74 03 77 C8 2D 43 7C CA 6D 57 29 25 69 23
NODE 86c7a82aRe: "Key Escrow" --- the very idea
"Perry E. Metzger" <perry@imsi.com>Fri, 22 Jul 94 06:52:53 PDT
Carl Ellison says:
> if you really want to propose an escrow system we can live with,
> I would demand that it include:
I cannot conceive of an escrow system I could live with. I respect
some of the people broaching the concept, but I object to the very
idea. I will no more escrow my communications than I will agree to
speak only next to the microphones.
Perry
NODE c933c075Stalling the crypto legislation for 2-3 more years
tcmay@netcom.com (Timothy C. May)Fri, 22 Jul 94 13:16:03 PDT
> Carl Ellison says:
> > if you really want to propose an escrow system we can live with,
> > I would demand that it include:
>
> I cannot conceive of an escrow system I could live with. I respect
> some of the people broaching the concept, but I object to the very
> idea. I will no more escrow my communications than I will agree to
> speak only next to the microphones.
>
> Perry
I echo Perry's concern. I hope that the "community" will not get
caught up in a game of "help us make key escrow better" and thus get
co-opted (as we used to call it) into the system.
I'm sure Carl and others are just exploring the intellectual ideas
involved, especially as we exchanged personal mail over this topic
a few minutes ago, but there is still the danger that all the various
ideas will result in this co-opting.
In my opinion, the worse danger comes from having the Washington
crypto-lobbyists co-opted into a system they can "live with" (as in
"we can live with this"). The Administration has probably concluded
that they failed to get "buy-ins" from the various influential
lobbying groups prior to dropping Clipper on us like a bombshell on
that fateful April day in 1993.
I'd hate to see EFF, CPSR, and EPIC all "brought into the tent" on
this one, having seen how Kapor and others got so enthralled by the
Digital Superduperhighway that a bad idea got pushed along more than a
little bit by them.
But it may be inevitable. We "rejectionists," who reject crypto
legislation of nearly any sort, are very poor negotiating partners, as
we have nothing to deliver, nothing to make deals with.
But like I said in a recent message, we have a stronger hand to play:
the widespread deployment of many crypto systems, making regulation of
crypto effectively impossible. We may already be at this point, given
the "cryptodiversity" (after "biodiversity") of multiple programs,
multiple platforms, and many communications paths. And in 2-3 more
years, we'll surely be there.
If we can stall and sabotage until then, we should be home free.
--Tim May
(Sorry for using so many buzz phrases, like "buy ins" and "inside the
tent"; these are used as shorthand for the bureaucratic mind-set,
which has a whole glossary of these phrases.)
--
..........................................................................
Timothy C. May | Crypto Anarchy: encryption, digital money,
tcmay@netcom.com | anonymous networks, digital pseudonyms, zero
408-688-5409 | knowledge, reputations, information markets,
W.A.S.T.E.: Aptos, CA | black markets, collapse of governments.
Higher Power: 2^859433 | Public Key: PGP and MailSafe available.
"National borders are just speed bumps on the information superhighway."
NODE 411d4624Re: Stalling the crypto legislation for 2-3 more years
Dave Banisar <tc@phantom.com>Sun, 24 Jul 94 07:43:33 PDT
>
> I'd hate to see EFF, CPSR, and EPIC all "brought into the tent" on
> this one, having seen how Kapor and others got so enthralled by the
> Digital Superduperhighway that a bad idea got pushed along more than a
> little bit by them.
>
I cant speak for the other organizations mentioned but I can guarantee
that EPIC is not in the least bit interested in supporting key escrow
systems. For a privacy advocate to determine to best way to do key escrow
is like a death penalty opponent choosing between gas or electricity.
I'd keep my eyes out for of the other players tho....
NODE 73134cb5Re: "Key Escrow" --- the very idea
Berzerk <berzerk@xmission.xmission.com>Fri, 22 Jul 94 09:28:09 PDT
On Fri, 22 Jul 1994, Carl Ellison wrote:
> if you really want to propose an escrow system we can live with,
> I would demand that it include:
> 1. unambiguous ID of the person being tapped in the LEAF-equivalent
WHAT!
Why in the hell would you want to do that. Just identify the piece of
equipment that is sending it. Let the wiretap guys sort throught it like
they do now.
Berzerk.
NODE 0a041c78Re: "Key Escrow" --- the very idea
Carl Ellison <cme@tis.com>Fri, 22 Jul 94 11:17:39 PDT
>Date: Fri, 22 Jul 1994 10:27:30 -0600 (MDT)
>From: Berzerk <berzerk@xmission.xmission.com>
>Subject: Re: "Key Escrow" --- the very idea
>On Fri, 22 Jul 1994, Carl Ellison wrote:
>> if you really want to propose an escrow system we can live with,
>> I would demand that it include:
>> 1. unambiguous ID of the person being tapped in the LEAF-equivalent
>WHAT!
>
>Why in the hell would you want to do that. Just identify the piece of
>equipment that is sending it. Let the wiretap guys sort throught it like
>they do now.
1. I'm not a fan of key registration
2. If it were forced down my throat, I want to make sure that
the escrow agents can form a list of people being tapped so that
they can detect abuses and possibly notify those tapped that
they've been compromised. They can't do that without either an
ID of the equipment owner or some communciations/routing path
which can map from equipment ID to my addr/phone/e-mail (to
notify me).
In other words, I want to see this hypothetical escrow agent
(or one of the many) as someone protecting my rights against the
interests of a tapping agency.
- Carl
NODE fee2884dRe: "Key Escrow" --- the very idea
Berzerk <berzerk@xmission.xmission.com>Sat, 23 Jul 94 16:04:29 PDT
On Fri, 22 Jul 1994, Carl Ellison wrote:
> 1. I'm not a fan of key registration
Good, but DONT make comprimises that screw the other guy.
> 2. If it were forced down my throat, I want to make sure that
> the escrow agents can form a list of people being tapped so that
Ok, so what you are saying is you don't want your phone taped just
because your coworker is under investigation. This is a reasonable
objcetive, but...
> they can detect abuses and possibly notify those tapped that
> they've been compromised. They can't do that without either an
Wait a second, they would notify those that have been victimized? Are
you serious? Do you have one case in the history of the united states
where they have done this? I think it is better to keep it out of their
hands totally, and it would be beter to identify the person doing the
taping, not the person being taped.
> ID of the equipment owner or some communciations/routing path
> which can map from equipment ID to my addr/phone/e-mail (to
> notify me).
Ok, so you would, if you had to register your key, also demand that all
communication devices be registered also? I don't like this idea, I have
a right to communicate and I don't need the governments permision to use
the phone. I think you are selling away everything with this proposal.
> In other words, I want to see this hypothetical escrow agent
> (or one of the many) as someone protecting my rights against the
> interests of a tapping agency.
I fail to see how you identifying yourself every time you have to use a
pay-phone could possibly lead to a protection of your rights.
Berzerk.
NODE 4ee47eefRe: "Key Escrow" --- the very idea
Ben Goren <ben@Tux.Music.ASU.Edu>Fri, 22 Jul 94 09:46:56 PDT
On Fri, 22 Jul 1994, Carl Ellison wrote:
> if you really want to propose an escrow system we can live with,
> I would demand that it include:
>
> [four "features" deleted]
And just who is going to pay for this system? And why should they? And
why should anybody else use it when there're so many other alternatives?
Heck, for that matter, how are you going to get all users of Norton
Encrypt to escrow their DES keys? After all, they might have the disarm
codes for their homebuilt nuke encrypted with that.
Just say NO to key escrow.
b&
--
Ben.Goren@asu.edu, Arizona State University School of Music
net.proselytizing (write for info): We won! Clipper is dead!
But be sure to oppose escrowed keys. Stamp out spamming.
Finger ben@tux.music.asu.edu for PGP 2.3a public key.
NODE a7704f96Re: "Key Escrow" --- the very idea
Peter Murphy <pkm@maths.uq.oz.au>Fri, 22 Jul 94 22:17:14 PDT
Carl Ellison wrote:
>
> if you really want to propose an escrow system we can live with,
> I would demand that it include:
>
> 1. unambiguous ID of the person being tapped in the LEAF-equivalent
> 2. multiple escrow agencies, at least one of which is the NSA HQ
> (for its superior physical security)
> 3. watchdogs as escrow agents (e.g., ACLU, Rep & Dem parties, CPSR,
> EFF, NYTimes, ...) with authorization to look for abuses of
> authority and to refuse to release keys in such cases and to
> publicize such cases as well as bringing them to the attention
> of law enforcement for prosecution.
> 4. user-generated escrow keys, to reduce the chance of anyone having a
> backdoor way to get the whole escrow key database.
>
I think you missed one important condition:
5. Make it optional, with no strings attached. Furthermore, make the
system designed so that the "default" option is no key escrow. In
other words, the government would have to get permission for key
escrow.
Condition 5 would of course not apply to government employees. Nor would it
apply to the office communication equipment inside the more "paranoid" business
associations. Of course, it would be the company, not government, who would
hold the keys, and of course the company should have the choice in deciding
whether key escrow is really necessary.
Of course, with this extra condition, key escrow seems fairly pointless. :-)
But I don't mind. It's not as if I'm exactly looking forward to it Down
Under.
Peter Murphy.
NODE f2a90bfbRe: "Key Escrow" --- the very idea
Aron Freed <s009amf@discover.wright.edu>Wed, 27 Jul 94 09:22:42 PDT
On Fri, 22 Jul 1994, Carl Ellison wrote:
> if you really want to propose an escrow system we can live with,
> I would demand that it include:
>
> 1. unambiguous ID of the person being tapped in the LEAF-equivalent
> 2. multiple escrow agencies, at least one of which is the NSA HQ
> (for its superior physical security)
> 3. watchdogs as escrow agents (e.g., ACLU, Rep & Dem parties, CPSR,
> EFF, NYTimes, ...) with authorization to look for abuses of
> authority and to refuse to release keys in such cases and to
> publicize such cases as well as bringing them to the attention
> of law enforcement for prosecution.
In theory this would be nice, but it just takes a gun to someone's head
to say hand it over... Would you risk your life for other people... And
once they kill you, it's a matter of searching through the records for
it. It's not that safe. I rather my private key not be in escrow at all...
> 4. user-generated escrow keys, to reduce the chance of anyone having a
> backdoor way to get the whole escrow key database.
>
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
-=- YABBS - telnet phred.pc.cc.cmu.edu 8888 -=-
-=- -=-
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
NODE 85a2d17eRe: "Key Escrow" --- the very idea
tcmay@netcom.com (Timothy C. May)Thu, 21 Jul 94 18:00:33 PDT
Mike_Spreitzer writes:
> (1) I'm not an anarchist. Does that make me out of place here? I'm willing to
Yes, you are out of place. We took a vote a while back and the
anarchists won by 173 votes. The detailed rules of discourse we
adopted can be found at the csua.berkeley.edu site.
> (2) I think crimes can be committed in cyberspace. Substantially, if not
> entirely, in cyberspace. Maybe not so many now. But I think it's
I know of no one who disagrees. Of course crimes can be committed in
cyberspace, whatever one's definition may be of crime. From forwarding
copyrighted material to posting GIFs of children being raped to
contracting for hits on one's enemies. (Personally, I treat very few
things as being criminal, and thus see few things in cyberspace that
could possibly be criminal.)
> intellectually dishonest of us who understand the growing importance of
> cyberspace to claim there won't be any social contracts there that could be
> violated. I accept the terms of the 4th ammendment: search and siezure allowed
> when due process followed. "Key escrow" is an attempt to implement the
> cyberspatial analog of search.
Nope. "Key escrow" is far broader. It is telling people they must
"escrow" their house keys with the cops, just in case the cops have a
need to enter.
It is the requirement that all photographs be "escrowed" with the
cops, just in case some dirty pictures need to be looked at. It is the
requirement that diaries and journals be written in "approved
languages," in case authorities need or want to read them.
(By the way, your tacit assumption, that key escrow will become
mandatory, is probably accurate, but is in fact not the Administration's
proposal. They claim it will forever remain voluntary, though they are
then silent on just how this will help with the criminals they seek to
catch this way.)
The remaining points I'll leave for others to critique.
Mandatory key escrow is like telling people they have to use special
curtains that can be made transparent if the cops think they need to
aim their cameras in our houses.
Not exactly what I have in mind for my future.
--Tim May
--
..........................................................................
Timothy C. May | Crypto Anarchy: encryption, digital money,
tcmay@netcom.com | anonymous networks, digital pseudonyms, zero
408-688-5409 | knowledge, reputations, information markets,
W.A.S.T.E.: Aptos, CA | black markets, collapse of governments.
Higher Power: 2^859433 | Public Key: PGP and MailSafe available.
"National borders are just speed bumps on the information superhighway."
NODE 3fa6503cRe: "Key Escrow" --- the very idea
Mike_Spreitzer.PARC@xerox.comFri, 22 Jul 94 07:50:28 PDT
> > "Key escrow" is an attempt to implement the
> > cyberspatial analog of search.
> Nope. "Key escrow" is far broader...
The result is certainly broader. Arguably too broad. I was simply trying to
say that someone with the narrower motive of trying to implement warranted
searches in cyberspace might reach for key escrow as a solution. Mainly for
lack of a narrower mechansim.
As I tried to say in paragraph (3), I don't think key escrow has to be
mandatory to have some value (whether it's enough to make it worthwhile is the
essence of the debate). Nor do I think there's any point in outlawing
unbreakable cryptography --- your worst outlaws would use it anyway. Also,
outlawing it would be more intrusive than required to implement warranted
searches --- aren't there some relationships (doctor/patient, lawyer/client,
priest/churchgoer) that the courts recognize as sacrosanct? The only arguable
strategy, I think, would be for society to say "we're going to subsidize the
escrowed key infrastructure so that it will be enough cheaper and more
available that most criminals will opt for it for most usage" --- and rely on
the power of human stupidity to make it pay off. This requires a comparison of
the cost of that public subsidy against the law enforcement payoff (and a
design for the distribution of who pays how much of that subsidy). And depends
on being able to make a price and/or availability difference that's
significant. And while Heinlein warns against underestimating the power of
human stupidity, I must say I wonder how long we could expect that most
criminals will remain insufficiently funded, educated, or motivated to avoid
using the escrowed key infrastructure for incriminating activities. I'm not
sure how to evaluate any of these.
NODE ac360a34Re: "Key Escrow" --- the very idea
Rick Busdiecker <rfb@lehman.com>Thu, 21 Jul 94 18:56:26 PDT
Date: Thu, 21 Jul 1994 16:49:01 PDT
From: Mike_Spreitzer.PARC@xerox.com
I accept the terms of the 4th ammendment [sic]: search and siezure
allowed when due process followed.
The 4th amendment:
The right of the people to be secure in their persons, houses,
papers, and effects, against unreasonable searches and seizures,
shall not be violated; and no warrants shall issue, but upon
probable cause, supported by oath or affirmation, and
particularly describing the place to be searched and the persons
or things to be seized.
One problem with what you've said is that the fourth amendment is not
phrased in the sense in which you refer to it. Specifically, it
proscribes unreasonable searches and seizures. It does not require
the people to actively facilitate the government in `reasonable'
searches and seizures. Essentially, you've turned the 4th amendment
on its head in your effort to rationalize key escrow.
In any case, it's a purely academic question given the dissociation of
the `Bill of Rights' from reality.
Rick
NODE 57a59a9eRe: "Key Escrow" --- the very idea
Mike_Spreitzer.PARC@xerox.comThu, 21 Jul 94 21:35:56 PDT
I'm sorry, I guess my wording was too sloppy. I mean the interpretation you
claim is correct.
NODE 761f2866Re: "Key Escrow" --- the very idea
solman@MIT.EDUThu, 21 Jul 94 19:37:26 PDT
> (1) I'm not an anarchist. Does that make me out of place here? I'm
> willing to live with some amount of government, as long as us owners
> stand a chance of controlling or overthrowing it. My biggest problem
> with Capstone is that it changes the balance of power too much.
Simple solution for people like you: Secret split your key into eight pieces,
such that six or seven are required to reconstruct it. Create a mechanism
whereby people can anonymously distribute their keys. Have the govenment
escrow keep just the names of the people with the other pieces. Periodically
require everybody to prove that they still have the same piece by sending
hashes. When the government wants your key it presents a warrant to the people
holding your pieces.
But I find this sort of system to be silly. its only purpose is to eavesdrop
in on my conversations. Why would I want somebody doing that? I like my
privacy so I'd rather not participate.
> (2) I think crimes can be committed in cyberspace. Substantially, if not
> entirely, in cyberspace. Maybe not so many now. But I think it's
> intellectually dishonest of us who understand the growing importance of
> cyberspace to claim there won't be any social contracts there that could be
> violated. I accept the terms of the 4th ammendment: search and siezure
> allowed when due process followed. "Key escrow" is an attempt to implement
> the cyberspatial analog of search.
This is total bullshit. In the physical world, the ideal set up would
clearly be one in which each individual negotiated with each other
individual what the contract between them would be. "I don't want to
die and you don't want to die, so lets both agree not to kill each other
and put some money towards a system of police that guarantees this.
I want property rights so I can enjoy the fruits of my labor..."
This scenario is, of course, absurd. It takes time to negotiate things like
this. Negotiations also require the possibility of no agreement, allowing
the parties to re-examine the strength of their respective positions before
going back to the table. The cost of conducting these negotiations in the
physical world is enourmous.
The cost of conducting these negotiations in the real world is negligible.
People who like their freedom can negotiate on their own. The stupid and
the insecure can purchase agents from other people that do the same thing.
LAWS CAN EASILY BE MADE OPTIONAL IN CYBERSPACE WHILE STILL MAINTAINING
THEIR EFFECTIVENESS. Enforcement of a law is a natural part of the agreement
to participate in it. There is absolutely no reason why one set of laws with
one set of enforcers needs to be adopted simply because the transactional
cost is negligible and the results of non-agreement can be determined
nearly instantaneously. I will be introducing the paleolithic analog of
an information society in the next few weeks. You had better believe that
by the time the information superhighway takes off, complex systems that
enforce complex rules will be available to those who want them.
> (3) The Feds must know they can't prevent modestly well funded, educated, and
> motivated folks from using unbreakable cryptography amongst themselves. The
> argument for doing key escrow anyway is that by installing a breakable
> infrastructure, they'll make enough investigations cheaper and more effective
> to be worth it. Note that's a comparison of their money and success rate
> against our privacy; no wonder they got it so wrong.
It absurd to think that the Feds can control anything in cyberspace without
some sort of physical world police state. Its just not feasible, entropy
is dominant.
JWS
NODE 970197eaRe: "Key Escrow" --- the very idea
Mike_Spreitzer.PARC@xerox.comFri, 22 Jul 94 08:29:06 PDT
Eight pieces seems too few to me. It's too easy for gov't agencies to "lean
on" eight individuals or organizations (someone else suggested "watchdog"
groups as fragment holding agencies, but that doesn't seem very good. Groups
can change over time, respond to pressure. Putting a lot of fragments in a few
hands seems fairly fundamentally flawed). I'd rather see thousands. That way,
if Richard Nixon II launched a secret intimidation campaign against a group of
enemies (e.g., the Democrats, or the Republicans, or the Libertarians, or the
ACLU, or Sierra Club, or people opposed to the Haitian operation, or ...) ---
well, it couldn't be secret, because a lot of people would have to know about
it. This also requires that key fragment holders know what their fragments are
for (the current Capstone architecture associates keys with devices, not
people; whether that should be so is another discussion). Of course, this also
diminishes the secrecy of the wiretap: if a wiretap is warranted on The
Godfather's office phone, what are the odds that someone the FBI doesn't know
is working (indirectly) for him will hold a fragment? Maybe that's just a
price that has to be paid.
What incentive can be given to the fragment holders to get them to take strong
measures to protect the secrecy of those fragments? Also, if a key is split
into N fragments, and there are k keys per capita (how many telephones do we
have today per capita?), each person needs to hold kN fragments (even more if
we restrict holders to, say, adult citizens). Can we expect everybody to spend
what it takes to hold kN fragments securely?
I've also wondered about another way to protect against abuse. There's been
some discussion on this list about cryptographically strong time locks: a way
to reveal something at a predetermined time in the future. I didn't follow it
closely at the time, and don't know how feasible they are (in general, or for
this application). But if they could be implemented, how about requiring the
fact of a wiretap to be published M months after it's started? Again, I mean
in a cryptographically strong way: you couldn't get the key you need for the
wiretap without committing to revealing, M months hence, the fact that you've
done so.
I've also tried to pursue the analogy to current mechanisms with regard to
physical searches. This analogy breaks down in a fairly important way:
physical searches generally reveal to the searchee the fact that they've taken
place; this means Nixon can't conduct a secret campaign against a group of
people --- they'd notice they're all subjects. But a good feature of the
current system that *could* be carried over to cyberspace is that the physical
privacy of my house is under the jurisdiction of a local court --- and the
physical privacy of *your* house is under the jurisdiction of a *different*
court. We don't have just a few "escrow agencies" that protect everybody; we
have lots of agencies, each of which protects a small fraction of us. This
also works against being able to keep widespread abuse secret.
NODE 70d29198Re: "Key Escrow" --- the very idea
solman@MIT.EDUFri, 22 Jul 94 08:38:08 PDT
> Eight pieces seems too few to me. It's too easy for gov't agencies to "lean
> on" eight individuals or organizations (someone else suggested "watchdog"
> groups as fragment holding agencies, but that doesn't seem very good. Groups
> can change over time, respond to pressure. Putting a lot of fragments in a
> few hands seems fairly fundamentally flawed). I'd rather see thousands.
The point here is that if the evil government wants to go busting in on
your conversations without a warrant, it can't. Even if they cheated and
looked in the escrow for the names of you secret holders, they'd have to
show them a warrant. The government couldn't try pressuring that many people
before one of them blabbed and that would lose those folks doing the
pressuring their jobs and quite probably result in prison time and political
ramifications.
I still don't like the idea of escrows because it assumes that I have
something to hide, but if you have to do an escrow, I thing eight people
is fine.
JWS
NODE 9fbd2b9dRe: "Key Escrow" --- the very idea
ebrandt@muddcs.cs.hmc.edu (Eli Brandt)Fri, 22 Jul 94 15:21:08 PDT
> The point here is that if the evil government wants to go busting in on
> your conversations without a warrant, it can't.
Not through the front door. But if the system is anything like the
present proposal, there's a lot of room for the key-generating entity
to undetectably keep the keyspace to 40 bits, or whatever it can
comfortably crack.
Eli ebrandt@hmc.edu
NODE 7fef9427Re: "Key Escrow" --- the very idea
Berzerk <berzerk@xmission.xmission.com>Fri, 22 Jul 94 09:33:09 PDT
On Fri, 22 Jul 1994 Mike_Spreitzer.PARC@xerox.com wrote:
> Eight pieces seems too few to me. It's too easy for gov't agencies to "lean
> on" eight individuals or organizations (someone else suggested "watchdog"
> groups as fragment holding agencies, but that doesn't seem very good. Groups
> can change over time, respond to pressure. Putting a lot of fragments in a few
> hands seems fairly fundamentally flawed). I'd rather see thousands. That way,
NO, what you really need to do is tackle the issue of the government
rounding up keys in mass, and instituting an orwellian system of spying.
To do this, simply make it legal for the escrow agencies to distroy their
database as a whole, in fact, make it a REQUIREMENT that they distroy
their database if necessary and enact measures to protect it from abuse.
Berzerk.
NODE ee3fa5b7Re: "Key Escrow" --- the very idea
Mike_Spreitzer.PARC@xerox.comFri, 22 Jul 94 08:52:37 PDT
> ...The cost of conducting these negotiations in the
> physical world is enourmous.
>
> The cost of conducting these negotiations in the real world is negligible...
Is "the real world" a typo? I suspect you mean something like "in cyberspace".
I'm not familiar with the line of reasoning you're referring to here. I suspect
it's a large topic. Does it rest on the assumption that cyberspace and the physical
world are largely disjoint? I think they're not. Activities in cyberspace often
"are about" or "have influence on" the real world. Sometimes vice versa.
Doesn't this mean laws can't be divided into those about the physical world
vs. those about cyberspace, but must in fact be about both?
NODE f3ad7776Re: "Key Escrow" --- the very idea
solman@MIT.EDUFri, 22 Jul 94 09:43:15 PDT
> > ...The cost of conducting these negotiations in the
> > physical world is enourmous.
> >
> > The cost of conducting these negotiations in the real world is
negligible...
>
> Is "the real world" a typo? I suspect you mean something like "in
> cyberspace".
:) It is most certainly a typo.
> I'm not familiar with the line of reasoning you're referring to here. I
> suspect it's a large topic. Does it rest on the assumption that cyberspace
> and the physical world are largely disjoint?
> I think they're not. Activities in cyberspace often
> "are about" or "have influence on" the real world. Sometimes vice versa.
> Doesn't this mean laws can't be divided into those about the physical world
> vs. those about cyberspace, but must in fact be about both?
You are entirely missing my point. The superior efficiency of cyberspace,
its low transaction costs, have created possibilities there that can not
exist in the physical realm.
In both realms people have different wants and desires. Because they interact
with each other, the actions of one individual can have an impact upon the
actions of other individuals. Without any form of social agreement, there
would be no security, no certainty about anything. This can be highly
inefficient. There is no point in starting a big project today, if there
is a high probability that somebody will kill you tomorrow. There is no
point in doing something that other people would find useful if there is
no mechanism for you to exchange it with them for services that you find
useful.
To circumvent this inefficiency, individuals enter into contracts with one
another. A and B might agree not to kill each other. In exchange for giving
up this element of their freedom, they get security. Security has value.
It enables them to undertake long term projects that might otherwise not have
been possible. But a contract like this is not useful without some mechanism
of enforcement, so A and B have to agree to pay for some sort of policeman.
This policeman would receive compensation for enforcing the contract between
A and B.
HERE IS THE DIFFERENCE BETWEEN THE PHYSICAL WORLD AND CYBERSPACE.
In the physical realm, in order for a contract like this to work, large
numbers of people have to be bound to it. This is true for the following
reasons:
A) The number of people bound under the contract must be large enough to make
it unlikely that the policeman can control them or break his contract.
B) Negotiating a contract like this takes alot of time. The compensation for
the policeman has to be determined. The mechanisms for disciplining murderers
(and determining guilt) have to be determined. The mechanisms for enforcing
the contract between the police and the people have to be determined. The
mechanisms for determining how much each person will be required to pay have
to be determined.
This is an extraordinarily inefficient procedure in the physical world. To
deal with this inefficiency we have developed laws. Laws specify that all
sentient individuals within a given area have to agree to a specific contract.
There is no contract negotiation, there is just a contract that automatically
applies and because a substantial majority of the individuals within a given
locality respect the laws, this system works. In fact legal systems are highly
inefficient artifacts in the physical world.
In cyberspace, the two motivations for extending contracts to all
participants (i.e. having uniform laws) are no longer present. Point A
is no longer true. You don't need to have an enforcing policeman whose
power is balanced by the large number of people he protects, cryptography
can take the policeman's place as the contract enforcer. Point B is no
longer valid because the entire negotiation process can be automated by
computer with negligible transaction costs.
Without any motivation for laws, individuals can get their security through
personal contracts with other individuals. If you don't want to worry about
fraud, subscribe to a fraud protection agency that you like. Any individual
agent that wants to make you an offer will have to first be approved by the
fraud protection agency. In exchange for this approval, the agent will pay
the protection agency money and then pass along that cost to consumers that
required the approval. Alternatively, the agent can agree not to violate the
rules of the FPA, and give the FPA a deposit. If the agent screws up, victims
of fraud could collect recompense via the method of adjudication specified
by the FPA. If the agent isn't willing to agree to the fules of the FPA,
then the user and that agent just won't do business. There can be thousands
upon thousands of FPAs in a scheme like this and individual FPAs can offer
all sorts of protection plans.
In the real world a system like this could never be implemented, the cost
of administering it would be too great. How could stores know what standard
of honesty was required for each individual customer if different customers
lived under different laws? The store has to be notified of the specific
rules governing a specific customer. The store has to pay a tiny amount
to the FPA. It has to be verified that this amount is collected. The store
must then alter its sales strategy for the customer.
This would clearly no work in the real world. If I wanted to buy a
watermelon slush outside of the Kendal T (something I am about to do)
it would cost me about $200 in transaction costs beyond the $1 for the
slush. This is where the difference lies. It simply becomes feasible to
have individually tailored social contracts once you enter cyberspace.
Individuals with incompatible social contracts simply can't communicate
with one another. You get absolute freedom AND absolute security.
JWS