// COMPLETE THREAD

Crisis Overload (re Electronic Racketeering)

8 expanded posts ยท every known parent and child

NODE ed8fe69bCrisis Overload (re Electronic Racketeering)
Folks, I'm not going to exhort you to fight this latest travesty, to send
angry letters to your senators and representatives.

Every couple of months there's been a new legislative attack on what were
once basic American freedoms. (Sorry to focus on America. I'm sure you
folks in the liberty-loving paradises of, say, Germany, are gloating over
our hand-wringing.)

We're losing the war. We can send in donations to the NRA and EFF, offer
our support to the ACLU and EPIC, but the tide just keeps rolling in,
washing away our efforts. The full-time lawmakers in D.C. can proliferate
new repressive laws much faster than we can fight them.

Our focus on this list has been on crypto, and crypto is finally coming
under the massive assault we knew would come from the earliest rumblings
several years ago about "key escrow." Clipper was the warning shot, the
current "War on the Internet" (fed by scare stories and hysteria) is part
of the propaganda war, and now this bipartisan bill to expand the RICO Act
to include any non-GAK implementation of crypto is the nail in the coffin.

No wonder Stu Baker and Ron Lee were so smug at the last CFP.

Ordinary lobbying is probably a lost cause. The EFF tried to "work with"
the government (Administration, Congress) on the Digital Telephony Bill,
and got rolled (in the opinion of many, even in the governing circles of
EFF).

This latest assault is probably unstoppable. The co-sponsorship by Sen.
Leahy, once seen as an ally of the EFF (recall the attempts to get the
Leahy alternative to Exon adopted), and the enthusiastic support of
Republicans, Democrats, and the intelligence community means that GAK is
coming.

Oh, and the use of RICO and "conspiracy" in such a central way fulfills
Whit Diffie's prediction of a few years ago that the main way crypto will
be controlled is through such laws, by spreading fear, uncertainty, and
doubt amongst users and corporations. Make the corporations so paranoid
that they'll crack down on employees, adopt GAK methods, and freeze out the
"street corner user" of crypto.

(If the only users of PGP and other non-GAK tools are fringe groups and
underground communities, then the main goals will have been achieved. The
public use of PGP will have been squelched, the public use of anonymous
cash will have been suppressed, and the social control goals will have been
achieved. )

I think it's time to abandon all lobbying efforts...they don't appear to be
working, and the government is proliferating new laws faster than we can
fight them.

The only hope is to more rapidly deploy crypto, to reach the "point of no
return." Optimistically, we may already be there (the views expressed by
many of us). Pessimistically, the application of RICO laws and civil
forfeiture could put any of us who advocate crypto use and evasion of the
new laws into a precarious position.

This is enough to say for now.

Suffice it to say I view the latest Grassley proposed legislation to be the
culmination of the past several years worth of anti-liberty legislation. A
much bigger threat than Clipper.

In fact, it's what many of us saw implicit in Clipper.

--Tim May

..........................................................................
Timothy C. May         | Crypto Anarchy: encryption, digital money,
tcmay@sensemedia.net   | anonymous networks, digital pseudonyms, zero
408-728-0152           | knowledge, reputations, information markets,
Corralitos, CA         | black markets, collapse of governments.
Higher Power: 2^756839 | Public Key: PGP and MailSafe available.
"National borders are just speed bumps on the information superhighway."
NODE d348f815Re: Crisis Overload (re Electronic Racketeering)
On Thu, 13 Jul 1995, Timothy C. May wrote:

> I think it's time to abandon all lobbying efforts...they don't appear to be
> working, and the government is proliferating new laws faster than we can
> fight them.
> 
> The only hope is to more rapidly deploy crypto, to reach the "point of no
> return." Optimistically, we may already be there (the views expressed by
> many of us). Pessimistically, the application of RICO laws and civil
> forfeiture could put any of us who advocate crypto use and evasion of the
> new laws into a precarious position.

Unfortunately, a system of social engineering needs to be adopted to get 
massive use of cryptography started.  This means, and I advocated this 
from the day I entered this forum, that programs such as PGP need to be 
redesigned so that the a user friendly . . . so user friendly that any 
Joe Moron can figure out not only how to use them, but also how it helps 
them and how it is "good" for them.  This means that we need simplified 
key management easy enough for the point-and-click masses to utilize.  
This means that common mailing programs, From Elm and Pine to AOLs and 
Computer$erve's mailers need to have TRANSPARENT signing of mail messages 
and near-transparent encryption of messages.  This means that we need to 
stop lobbying the governemtn (they dont' listen) and start lobbying Big 
Business, like IBM, MicroSoft, Apple, etc, to start including encryption 
hooks in their software.  And if PGP is a problem, International PGP 
might be an option.  And if there are problems with patent infringements 
and that kind of crap, then we (the concerned people of the global 
network) need to develop a free encrytion scheme that can do everything 
PGP can do and still be legal.

Unfortuately, all I can do is stand on the sidelines and cheer, because I 
am not a programmer; I'm a user and a teacher.

We've seen the enemy, that the are the 535 senators and representatives 
in D.C., and the staff in the White House.  It's time to shore up our 
allies and enter the battle witht he best weapons we have; information 
and popular use.

> In fact, it's what many of us saw implicit in Clipper.

Yup.  We all saw it with clipper.  We were all called paranoid.

Guess so...

____        Robert A. Hayden      <=> Cthulhu Matata
\  /__          -=-=-=-=-         <=>          -=-=-=-=-
 \/  /  Finger for Geek Code Info <=> hayden@krypton.mankato.msus.edu
   \/   Finger for PGP Public Key <=> http://att2.cs.mankato.msus.edu/~hayden
NODE be9bf524Re: Crisis Overload (re Electronic Racketeering)
"Robert A. Hayden" writes:
> We've seen the enemy, that the are the 535 senators and representatives 
> in D.C., and the staff in the White House.  It's time to shore up our 
> allies and enter the battle witht he best weapons we have; information 
> and popular use.

As unpleasant as the congress is, it isn't the enemy. The governmental
forces desiring control are not the same as the congress.

Congressmen are by and large harried and ignorant people. They have no
idea what any of this is about. We have the choice of letting Louis
Freeh do all the educating, or having a white shoe Washington PR firm
do some of the educating, too. I favor the latter approach.

This is not to say that we shouldn't be widely deploying crypto -- we
should. (Of course, offshore sites will always have crypto available,
but...) 

This is also not to say that Congress doesn't pass very bad laws.

However, I very, very strongly urge that we not assume that nothing
can be done. Just winning a couple years time could totally alter the
landscape.

Perry
NODE 49355ccfRe: Crisis Overload (re Electronic Racketeering)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                          SANDY SANDFORT
 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

C'punks,

On Thu, 13 Jul 1995, Perry E. Metzger wrote:

> As unpleasant as the congress is, it isn't the enemy. The governmental
> forces desiring control are not the same as the congress.

I'm not so sure.  Both politicos and bureaucrats go into their
respective lines of work for many reasons.  One of the main 
reasons--in my opinion--is a lust to control others.  Being the 
"others," we should resist this tendancy.  This begins with the
realization that most of them *are* the enemy and acting 
accordingly.

> This is not to say that we shouldn't be widely deploying crypto -- we
> should. (Of course, offshore sites will always have crypto available,
> but...) 

Yes, what we really need is easy, drop-in, point-and-click PGP
for the computer neophytes.  And we need to give it away to
all of them.  I wish I know how to accomplish all that.

My "wish list" also includes a fantasy in which someone 
(hopefully, a Cypherpunk) cracks some NSA developed, secret
algorithm, crypto system, preferably causing some sycophantic
company or organization to lose a bundle.  Ah, dreams.


 S a n d y

P.S.  My 84 year old mother went in to buy a refrigerator 
      from Sears or Monkey Wards or whomever.  She picked 
      out a top-of-the-line Tappan.  However, when she was 
      getting ready to pay, the salesperson began to ask
      her a series of questions which included her age and
      social security number.  My mom said, "Just stop
      right there.  If you want to ask all this personal 
      information, I'll just buy it somewhere else."  The
      stopped asking questions and took her check.  

      I think Nancy Reagan had a good idea there.  Just 
      say `NO'.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
NODE eb1cafb3Re: Crisis Overload (re Electronic Racketeering)
On Thu, 13 Jul 1995, Sandy Sandfort wrote:

> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>                           SANDY SANDFORT
>  . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
> 
> C'punks,
> 
> On Thu, 13 Jul 1995, Perry E. Metzger wrote:
> 
> > As unpleasant as the congress is, it isn't the enemy. The governmental
> > forces desiring control are not the same as the congress.
> 
> I'm not so sure.  Both politicos and bureaucrats go into their
> respective lines of work for many reasons.  One of the main 
> reasons--in my opinion--is a lust to control others.  Being the 
> "others," we should resist this tendancy.  This begins with the
> realization that most of them *are* the enemy and acting 
> accordingly.
> 

Well, now, I wouldn't say THAT....

There are those of us intent enough of defending our rights as to go so 
far as to make an effort of getting to where we can do so more easily.  
While I know I was shouted down over NYET, the group does know where I 
stand on the issue of, for instance, free crypto or the Exon Hustler 
Protection Act.  I intend to run for JP in '98, and (assuming our 
electoral system, if not our Constition is still intact) higher office 
later.  If I win, you can bet your keyring passwords that _I_ will make 
sure that my juries are aware of FIJAs position papers.

There are others--including one John Tello, a member of the Texas State 
Republican Executive Committee, who almost single handedly got a unanimous 
resolution out of the TX SREC calling for an end of our 60-year emergency 
and a recision of various related acts.

Bluntly, if you are bellyaching but _not_ involved with an organized 
political structure that is capable of influencing legislation, then I 
blame YOU for this legislation.  I am, have, and/or shall have lobbied every 
Congressman with whom I can claim a minimal connection.  And I've done 
the work so that this is a non-trivial list.

Direct mail is useful.  But until you've worked to get someone elected, 
you are just one more voice in the roar.  The '96 campaigns are shaping 
up.  (I'm already putting the word out for '98...)  This is the time to 
find people who share our views, and work so that they win their 
primaries--or maybe don't even have to fight one.  Or maybe its time 
_you_ ran.


Nathan

Crypto-Christo-punk
NODE e54cc27aRe: Crisis Overload (re Electronic Racketeering)
> massive use of cryptography started.  This means, and I advocated this 
> from the day I entered this forum, that programs such as PGP need to be 
> redesigned so that the a user friendly . . . so user friendly that any 
> Joe Moron can figure out not only how to use them, but also how it helps 
> them and how it is "good" for them.  This means that we need simplified 
> key management easy enough for the point-and-click masses to utilize.  
> This means that common mailing programs, From Elm and Pine to AOLs and 
> Computer$erve's mailers need to have TRANSPARENT signing of mail messages 
> and near-transparent encryption of messages.  This means that we need to 

I agree.  If you forgive me for again taking the opportunity to
advertise SSH, one goal was to make it as simple to use as possible.
To get all the benefits of encryption and most benefits of improved
authentication, the users need to know absolutely nothing in addition
to what they need to know with rlogin.  Plus, there are many
convenient features, such as automatic X11 forwarding (encrypted;
DISPLAY is set to point to a fake display), command exit status is
returned properly, etc.

Of course, rlogin and rsh are much less important applications for the
general public than e-mail.  I think the currently the most critical
problem areas are exactly e-mail and interactive messaging programs
(like irc, rwrite etc).

Most mail (at least on the internet) is currently propagated
automatically from the sending host to the receiving host.  A fairly
simple, 90% of the benefit at 10% of the effort solution could be to
have sendmail (or equivalent) encrypt all communications that go
through the network.  This would make electronic mass surveillance and
scanning difficult.  It is much more expensive (and dangerous
publicity-wise) to read messages by breaking into a computer system.
This kind of system could be installed without the user even being
aware that something like that is in use.  It is not a perfect
solution - some sites will not support encryption, and some messages
might get sent without it.  Still, the bulk of the messages would be
encrypted, and any really sensitive data could be additionally PGP (or
similar) encrypted.  The procotol and implementation would have to be
well made and established as internet standards.

    Tatu Ylonen <ylo@cs.hut.fi>

For more information about SSH, see http://www.cs.hut.fi/ssh.
NODE b0b4ee1eRe: Crisis Overload (re Electronic Racketeering)
One motivation behind SSH is trying to make it a de-facto standard
replacement for rlogin and rsh.  That would make it very hard to
replace.  It provides important benefits in authentication and
protection against intruders - and as a side effect it provides hard
to break encryption for anyone.  Plus, it was created and is primarily
distributed *outside* the United States, in a country where none of
the algorithms are patented.  It can thus be openly available for
anyone, and is not limited by US export restrictions.  It currently
includes two algorithms that I know to be patented: RSA and IDEA.
IDEA can be eliminated from it without breaking compability if it
turns out necessary (and, several sources say that non-commercial use
of IDEA is permitted).  RSA is not patented anywhere but in the US,
and there it may be possible for most people to get away by using
RSAREF.

There is more information at http://www.cs.hut.fi/ssh.  The RFC
describes the protocol.

The current list of distribution sites includes:
   ftp.funet.fi:/pub/unix/security
   ftp.unit.no:/pub/unix/security 
   ftp.net.ohio-state.edu:/pub/security/ssh 
   ftp.kiae.su:/unix/crypto 
   ftp.cs.hut.fi/pub/ssh 

More sites are welcome.

    Tatu Ylonen <ylo@cs.hut.fi>
NODE fcbbb266Crisis Overload (re Electronic Racketeering)
Date: Fri, 14 Jul 1995 01:15:04 +0300
   From: Tatu Ylonen <ylo@cs.hut.fi>
   to break encryption for anyone.  Plus, it was created and is primarily
   distributed *outside* the United States, in a country where none of
   the algorithms are patented.  It can thus be openly available for

Well, I think it's nice that people outside the U.S. will have access
to encryption; it appears, however, that those of us in the U.S. writing
such software may end up having to forego payment and credit, until
Blacknet is very strong...

Phil