// COMPLETE THREAD

Crypto '95: Robert Morris

15 expanded posts ยท every known parent and child

NODE f959ce1eCrypto '95: Robert Morris
Bob Morris (recently retired from NSA) gave a fascinating invited lecture
entitled "Non-cryptographic Ways of Losing Information".  I hope he writes
it up; until then, here are my notes from his presentation.

Two things he said which I found new and fascinating:

- During the early 1950's many major powers were discouraged by the
  tendency of then-modern crypto machines to fail in a way that would send
  plaintext instead of ciphertext, and they went to one time pads for most
  of their high-level enciphered traffic.  Because of key re-use, we were
  regularly and routinely reading pieces of that traffic -- not just
  VENONA, but many systems from various countries.  Sometimes the people
  who prepared OTP's would double their profit by selling them to more
  than one customer.

- By the middle to late 1960's cryptanalysis became less cost effective
  than obtaining the information by other means -- wiretaps and so on.

Morris emphasized and said we should write down these dicta:
-------------------------------------------------------------------------
Never underestimate the attention, risk, money and time that an opponent
will put into reading traffic.

Rule 1 of cryptanalysis: check for plaintext.
-------------------------------------------------------------------------

The real start of modern cryptology should be dated to the Enigma
machines, which typified the new character of the art.  Much has been made
of the errors of the German cipher clerks, but egregious as they were, the
errors made by the British cryptographers were vastly worse, and the
American blunders were worse yet.  German analysts regularly read and used
Atlantic convoy orders throughout the war -- they were transmitted in an
old code.

One must always assume that the enemy has a copy of the machine/algorithm.
A system that relies on keeping the algorithm secret is eventually doomed
to failure, because it will always be discovered by some means or other.

He sees microphones and antennas everywhere: the telephone line cord is
an antenna; if telephone linemen were working on a pole outside his house
he'd call the police an then find out what they were working on.  In an
unspecified country he called Lower Slobbovia (Al Capp, isn't it?) American
troops used encrypted radiophones; when they broke they were taken to local
repair shops to be fixed.  When they got home the US engineers were
interested to see the modifications that had been made.  He mentioned a
few similar instances, including the lovely carved wooden seal given to
the US Embassy in Moscow to decorate their anteroom. [It's now on view at
the National Cryptologic Museum with the transmitter cavity visible.]
Cordless phones have a range of 5 miles or so.  Use of cellular phones is
increasing dramatically, as well as fax and modems.

He discussed the Walker/Whitworth spying case, and said one of his design
criteria is to design systems with Walker in them: it's not good enough to
have a system where everyone must be trusted, but it must also be made
robust against insiders.  This may include going to non-paper systems, so
that there are no paper keys that the Walkers of the world can shop to the
other side.

Threats and risks include: overconfidence, carelessness, eavesdropping and
tapping, theft of floppies and other materials, purchase, theft of key
material, burglary and blackmail.  Much or most loss is due to insiders.

In the future there will be more radio used for ordinary communications.
Americans are unwilling to pay for secure telephones, but that's not the
case in Europe.

-------------------------------------------------------------------------
Reported by:

	Jim Gillogly
	12 Halimath S.R. 1995, 04:33
NODE bca8d0eaNSA says Joe Sixpack won't buy crypto
jim@acm.org:

>- By the middle to late 1960's cryptanalysis became less cost effective
>  than obtaining the information by other means -- wiretaps and so on.

but for some reason, the NSA keeps humming along...? perhaps 
confirming the rule that bureacracies, like bores at parties,
persist long after they are relevant?

>In the future there will be more radio used for ordinary communications.
>Americans are unwilling to pay for secure telephones, but that's not the
>case in Europe.

I object to this highly. the NSA has very little credible understanding
of market forces, IMHO. they are a government agency. they do not
understand marketing or human psychology. Clipper, the closest the
agency has come to creeping out of the darkness of their coffin,
was a total fiasco. the self-destructing director of NSA whats-his-name
who as running for that FBI position or whatever is another example of how 
the inbred spook society has difficulty dealing with anything outside
their artificial reality.

as for the market viability of cryptographic phones, I think this
is duplicity ranging on utter lying that "the US public is not 
willing to pay for secure phones". this is precisely the baseless
rumor and conventional wisdom one would expect the NSA attempt to
spread and use to surreptitiously manipulate the natural market direction.
every phone company would avoid even introducing a phone model
because "after all the public is not willing to pay for encryption".
sure, maybe they won't pay for the very finest encryption money
can buy, but they can get some pretty awesome bang for minor bucks
when it comes to crypto.

the fact is, cryptography is becoming EXTREMELY CHEAP. virtually
all phones are going to have some high power microprocessor inside
that could be used to do semi-decent secure encryption, far better
than *nothing*, the current status quo-- *for free*, virtually, because
the phone is already going to have some serious horsepower. the whole
issue of "signal transformation" is very intrinsic to the existing
phone circuitry anyway.

extremely secure encryption (i.e. that the NSA is not likely to
break at all) is another issue, but again chips are becoming
awfully cheap.

so I say anyone spreading a rumor that "american public doesn't
want encryption or is not willing to pay for it" (esp. in 
cell phones or whatever) is either:

1. intentionally lying
2. rather clueless
3. making an unwarranted and undemonstrated assumption
4. possibly has an axe to grind-- i.e. axeing widespread public
encryption

furthermore, the idea that someone from NSA would say something
like "the U.S. public doesn't want so-and-so" encryption I find
highly repulsive. the NSA's business is based on SUPPRESSING ENCRYPTION.
it would be hard to find a more biased and less credible opinion
anywhere. the NSA has done the very best job of sabotaging the 
natural growth of cyberspace by having its slithering tentacles
lodged into key areas of influence within our government, while
at the same time pretending that  it is actually working in our
own best interest.

--

frankly, I think any anti-encryption sentiment is inherently
unpatriotic. you see, there is far more to be gained from widespread
encryption than is to be lost from it. the NSA in their anal
retentive, freedom-pissing mode will never understand this, or
never apprise the situation unbiasedly, but it appears to me
to be fairly unequivocal that there are tremendous benefits
from the availability of widespread, seamless, invisible 
encryption.

if the NSA released one public report that analyzed the actual
cost benefit ratio to *society* of free encryption, that is the
day I will scrape a smidgeon of respect for this vile, odious,
noxious excuse for a publicly funded institution. but the NSA
will never do this, because 

(1) the NSA can barely stand to address the congress honestly
and openly, and virtually never does even this, and so the
idea of justifying its existence to the actual public that
pays for its spook toys is beyond distasteful to the agency,
it would be sacrilegious!!

(2) they are incapable of an 
unbiased opinion on the issue, in fact they are probably not
even capable of any opinion that is not duplicitous and inherently
self-serving beneath a surface sugar-coating of actual legitimacy, 

(3) they don't want to admit that
their main motive, their raison d'etre, has absolutely nothing to 
do with maximizing overall public welfare-- it has to do with maximizing 
their own budget and maximizing intelligence available to their
omnipresent tentacles.

but thanks, JG, for a look into the dark, squirmy, teeming recesses of 
some perverted spook's mind. I would thoroughly enjoy any other choice
morsels you have to offer about the lies that spooks tell each other to
justify their existence. and the ones that they actually believe are by
far the most entertaining! <g>

--Vlad Nuri
NODE 700918ecRe: NSA says Joe Sixpack won't buy crypto
> but for some reason, the NSA keeps humming along...? perhaps 
> confirming the rule that bureacracies, like bores at parties,
> persist long after they are relevant?

Cryptography is a new science, it may be more effective to break in to an office
than to hack in to their computers, but maybe new discoveries will change that.

> understand marketing or human psychology. Clipper, the closest the
> agency has come to creeping out of the darkness of their coffin,
> was a total fiasco. the self-destructing director of NSA whats-his-name
> who as running for that FBI position or whatever is another example of how 
> the inbred spook society has difficulty dealing with anything outside
> their artificial reality.

I think you are dead wrong.  The NSA has mastered the market psychology.
Who has defined all of the most popular standards? DES, DSS, ElGamal, SHS...
the NSA has had a hand in them all.  DES is by far the most popular cipher,
popular enough that it will takes years and years to switch to something new.
As for the clipper "fiasco,"  I would argue that it was an excellent marketing
move.  The NSA is aware that there is only a very very small percentage of 
society the thinks about crypto, with the internet and what have you it is now
possible for this minority to be heard, the NSA proposes clipper, and so we all
bitch about it because it's only secure against non-government attacks.  Now
the public hears this and resists clipper.  There isn't another product that is
winning support that clipper could have had.  You step back and look at it, and
the public is exactly where they were 5 years ago, no crypto.  
Clipper was a no lose situation for them, if it is adopted only they can read
all transactions made with it, if it isn't adopted, everybody can read all 
transactions, they didn't lose anything. 
They have some top minds working for them, it's been proven that they have been
a few steps ahead of the public for a long time; it's foolish to think they 
don't understand the psychology of the market.  Just as the public starts to 
desire something like public key crypto, they can publish a standard on it
and it is likely to be adopted.
NODE 9e0b6a96Re: NSA says Joe Sixpack won't buy crypto
>> understand marketing or human psychology. Clipper, the closest the
>> agency has come to creeping out of the darkness of their coffin,
>> was a total fiasco. the self-destructing director of NSA whats-his-name
>> who as running for that FBI position or whatever is another example of how 
>> the inbred spook society has difficulty dealing with anything outside
>> their artificial reality.
>
>I think you are dead wrong.  The NSA has mastered the market psychology.
>Who has defined all of the most popular standards? DES, DSS, ElGamal, SHS...
>the NSA has had a hand in them all.  DES is by far the most popular cipher,
>popular enough that it will takes years and years to switch to something new.

no, I think the NSA is very adept at infiltrating and twisting existing
cryptographic market processes to suit their own ends. DES is a good example
of this. it was created by IBM largely, and then "manipulated" by the
NSA. this is well known and understood. the NSA does not work with standards
or markets so much as *interfere* with them. how can you deny this basic
premise embraced by virtually everyone on this list?

>As for the clipper "fiasco,"  I would argue that it was an excellent marketing
>move.  The NSA is aware that there is only a very very small percentage of 
>society the thinks about crypto, with the internet and what have you it is now
>possible for this minority to be heard, the NSA proposes clipper, and so we all
>bitch about it because it's only secure against non-government attacks.  Now
>the public hears this and resists clipper.  There isn't another product that is
>winning support that clipper could have had.  You step back and look at it, and
>the public is exactly where they were 5 years ago, no crypto.  

clearly, the first attempt was to get the public to embrace clipper. lacking
that, they have thwarted natural market progression. I agree they have
done this. but it's like making a pool shot accidentally and saying,
"I meant to do that". the NSA is *not* an agency that has a single clue
about *real* markets. they do have a brilliant ability to leverage their
political coercion skills to the absolute maximum to *manipulate* and
*interfere* and *piss on* newly growing markets. 

the NSA has screwed
up public crypto in uncountable ways. you cannot deny this!! they secretly
visit people doing state-of-the-art research and intimidate them into
silence or going other directions. they visited Mosaic designers to tell
them that the things they were installing in the software were not 
acceptable legally. of course, any other legal arm of the government
would simply sue once the software appeared, but not try to manipulate
the design prior to its release. this is the tactics of an *espionage*
and *intelligence* agency. surprise!!

to say that the NSA understands markets is like saying that thieves
understand how to pick pockets. yeah, that's true, but that's not
quite how I would have put it.

>Clipper was a no lose situation for them, if it is adopted only they can read
>all transactions made with it, if it isn't adopted, everybody can read all 
>transactions, they didn't lose anything. 

huge amounts of cash and credibility have been WASTED on it. the NSA has
lost enormous credibility because of this fiasco. furthermore, the way
they tried to hide behind presidential directives is absolutely repugnant
to anyone who has a belief in the separation of powers within our 
government.

>They have some top minds working for them, 

I know, it's a pity they don't get more respectable and socially
fulfilling jobs at companies, where they can be publicly rewarded
and recognized for their brilliance.

>it's been proven that they have been

k
>a few steps ahead of the public for a long time; it's foolish to think they 
>don't understand the psychology of the market. 

they *do* understand the market, only to the extent that they are trying
to successfully SABOTAGE what would regularly be it's natural growth.
they have been ahead in *theoretical* knowledge, but it was precisely
my *point* that this nebulous eggheadism has demonstrably exploded
when placed in public scrutiny.

do you realize the sheer ability of Microsoft to build software that
succeeds in *markets*? Microsoft doesn't care much about Netscape
because, as one microsoft engineer remarked, "well, it's strange
to talk about market share when you are giving away software for free".
well, the NSA is the absolute *opposite* of Microsoft. they don't
have a *clue* about true market forces. they do however understand
ways in which the government interferes with markets, and they seize
on every one of those mechanisms as their lifeblood for control
and "shadow/invisible oppression".

>Just as the public starts to 
>desire something like public key crypto, they can publish a standard on it
>and it is likely to be adopted.

the NSA is quickly losing relevance. the public *does* desire public
key crypto, and a defacto standard *has* been created, it's called PGP.
if the NSA proposes something in public key areas, it is likely to 
be pissed on by the public as much as Clipper, in many ways because
of the failure of Clipper. clipper in a big sense *was* the NSA's first
step toward public key encryption, and it was widely trounced on.

face it dude, the NSA has shown far less competence in the public arena
than *any* apologist such as yourself can ever demonstrate.
NODE 0a419f35Re: NSA says Joe Sixpack won't buy crypto
> 
> 
> >> understand marketing or human psychology. Clipper, the closest the
> >> agency has come to creeping out of the darkness of their coffin,
> >> was a total fiasco. the self-destructing director of NSA whats-his-name
> >> who as running for that FBI position or whatever is another example of how 
> >> the inbred spook society has difficulty dealing with anything outside
> >> their artificial reality.
> >
> >I think you are dead wrong.  The NSA has mastered the market psychology.
> >Who has defined all of the most popular standards? DES, DSS, ElGamal, SHS...
> >the NSA has had a hand in them all.  DES is by far the most popular cipher,
> >popular enough that it will takes years and years to switch to something new.
> 
> no, I think the NSA is very adept at infiltrating and twisting existing
> cryptographic market processes to suit their own ends. DES is a good example
> of this. it was created by IBM largely, and then "manipulated" by the
> NSA. this is well known and understood. the NSA does not work with standards
> or markets so much as *interfere* with them. how can you deny this basic
> premise embraced by virtually everyone on this list?
> 
The NSA doesn't really bother me all that much, because all they've managed
up to now is to slow things down (by about 3 hrs. in the case of PGPhone).
But what happens when someone who HAS mastered market psychology gets into
the game?

Here's a prediction:  within one year, we will see the advent of Micro$oft's
"Not So Bad Privacy".  It'll be a secret algorithm with either GAK done by
Micro$oft itself, or a flat-out trap door.  ANY communications with a 
Windoze box or network will have to use it, or loose the market.  About the
same time, Justice will suddenly 'loose interest' in its various 
investigations of M$.  Micro$oft will probably give it away for free as part
of the Windows 95.702 upgrade. 

At this point, the NSA's 'speed bump' becomes Micro$oft's 'brick wall'.  And
while some of us will continue to use PGP and other strong crypto, the average
American will have kissed off ALL of her privacy to the tune of "... you make
a grown man cry."

-- 
Jeff Simmons                           jsimmons@goblin.punk.net
NODE 816da225Re: NSA says Joe Sixpack won't buy crypto
On Mon, 4 Sep 1995, Jeff Simmons wrote:

> Date: Mon, 4 Sep 1995 20:48:51 -0700 (PDT)
> From: Jeff Simmons <jsimmons@goblin.punk.net>
> To: cypherpunks@toad.com
> Subject: Re: NSA says Joe Sixpack won't buy crypto
> 
> Here's a prediction:  within one year, we will see the advent of Micro$oft's
> "Not So Bad Privacy".  It'll be a secret algorithm with either GAK done by
> Micro$oft itself, or a flat-out trap door.  ANY communications with a 
> Windoze box or network will have to use it, or loose the market.


It's here already.
It's called "lotus notes."


> About the
> same time, Justice will suddenly 'loose interest' in its various 
> investigations of M$.  Micro$oft will probably give it away for free as part
> of the Windows 95.702 upgrade. 

Wait a few months.  Justice is boring of the investigation even now.

> -- 
> Jeff Simmons                           jsimmons@goblin.punk.net
> 


---
00B9289C28DC0E55 nemo repente fuit turpissimus - potestas scientiae in usu est
E16D5378B81E1C96 quaere verum ad infinitum, loquitur sub rosa    -    wichtig!
*New Key Information*    -    Finger for key revocation and latest key update.
NODE 246ac486Re: NSA says Joe Sixpack won't buy crypto
On Tue, 5 Sep 1995, Black Unicorn wrote:

> On Mon, 4 Sep 1995, Jeff Simmons wrote:
> 
> > 
> > Here's a prediction:  within one year, we will see the advent of Micro$oft's
> > "Not So Bad Privacy".  It'll be a secret algorithm with either GAK done by
> > Micro$oft itself, or a flat-out trap door.  ANY communications with a 
> > Windoze box or network will have to use it, or loose the market.
> 
> 
> It's here already.
> It's called "lotus notes."
> 
> 
> > About the
> > same time, Justice will suddenly 'loose interest' in its various 
> > investigations of M$.  Micro$oft will probably give it away for free as part
> > of the Windows 95.702 upgrade. 
> 
> Wait a few months.  Justice is boring of the investigation even now.

I hope this doesn't mean the Department is switching to Microsoft Word! :-)
(In fact, we're about to go to WP6.0 for Windows.  And the 6.0 is not a 
typo.)


 
> > -- 
> > Jeff Simmons                           jsimmons@goblin.punk.net

EBD
NODE 1d57d98fRe: NSA says Joe Sixpack won't buy crypto
> > 
> > Here's a prediction:  within one year, we will see the advent of Micro$oft's
> > "Not So Bad Privacy".  It'll be a secret algorithm with either GAK done by
> > Micro$oft itself, or a flat-out trap door.  ANY communications with a 
> > Windoze box or network will have to use it, or loose the market.
> 
Black Unicorn wrote:
> 
> It's here already.
> It's called "lotus notes."
> 
So what form of GAK or trap-door does lotus notes contain?

-- 
Jeff Simmons                           jsimmons@goblin.punk.net
NODE f808175aRe: NSA says Joe Sixpack won't buy crypto
On Tue, 5 Sep 1995, Jeff Simmons wrote:

> Date: Tue, 5 Sep 1995 16:00:38 -0700 (PDT)
> From: Jeff Simmons <jsimmons@goblin.punk.net>
> To: cypherpunks@toad.com
> Subject: Re: NSA says Joe Sixpack won't buy crypto
> 
> > > 
> > > Here's a prediction:  within one year, we will see the advent of Micro$oft's
> > > "Not So Bad Privacy".  It'll be a secret algorithm with either GAK done by
> > > Micro$oft itself, or a flat-out trap door.  ANY communications with a 
> > > Windoze box or network will have to use it, or loose the market.
> > 
> Black Unicorn wrote:
> > 
> > It's here already.
> > It's called "lotus notes."
> > 
> So what form of GAK or trap-door does lotus notes contain?

No, it's just been so weak before the current implementation of RC4 (and 
note the export version still has 40 bits) that it might as well be nothing.

> 
> -- 
> Jeff Simmons                           jsimmons@goblin.punk.net
> 

00B9289C28DC0E55 nemo repente fuit turpissimus - potestas scientiae in usu est
E16D5378B81E1C96 quaere verum ad infinitum, loquitur sub rosa    -    wichtig!
*New Key Information*    -    Finger for key revocation and latest key update.
NODE 17bc7fa2Re: NSA says Joe Sixpack won't buy crypto
> no, I think the NSA is very adept at infiltrating and twisting existing
> cryptographic market processes to suit their own ends. DES is a good example
> of this. it was created by IBM largely, and then "manipulated" by the
> NSA. this is well known and understood. the NSA does not work with standards

Well known that the NSA manipulated DES?  How so?  I am willing to believe that
they had a lot of say in it and they probably wanted it weakened, but I think
you'll be very hard pressed to find proof of that.  Based on some of the 
analysis of lucifer, it could be said that IBM weakened the key space to 
because that was a side effect of adding strength to the overall cipher.  
Keyspace is just about the only weakness of DES, I don't think that can be said
about lucifer.

> or markets so much as *interfere* with them. how can you deny this basic
> premise embraced by virtually everyone on this list?

Interference is just noise, the NSA has pretty much pushed the market where they
want it to go.  If you think that is just "interference" then we use the word
differently.  

> clearly, the first attempt was to get the public to embrace clipper. lacking
> that, they have thwarted natural market progression. I agree they have
> done this. but it's like making a pool shot accidentally and saying,
> "I meant to do that". the NSA is *not* an agency that has a single clue
> about *real* markets. they do have a brilliant ability to leverage their
> political coercion skills to the absolute maximum to *manipulate* and
> *interfere* and *piss on* newly growing markets. 

If they are as powerful as we both seem to think (easily "interfering" with 
markets and screwing the public for decades) how can you underestimate them like
that?  If they are actually spying on us, then they know what moves we'll make
and they can always head that off, it's not slop pool.  If they aren't then I
don't know what I'm supposed to hold against them, I don't have to use their
standards unless I wish to export stuff.

> 
> the NSA has screwed
> up public crypto in uncountable ways. you cannot deny this!! they secretly

This is true, they make long term industry standards that are short lived.
DES's keyspace was far too small.  Escrow isn't a great idea (excpet for 
signatures) ITAR is bullshit.

> visit people doing state-of-the-art research and intimidate them into
> silence or going other directions. they visited Mosaic designers to tell
> them that the things they were installing in the software were not 
> acceptable legally. of course, any other legal arm of the government
> would simply sue once the software appeared, but not try to manipulate
> the design prior to its release. this is the tactics of an *espionage*
> and *intelligence* agency. surprise!!

This is all hearsay.  I doubt that the mosaic designers have had any contact 
with the NSA unless they invented a significant new cryptographic technology,
all Netscape/Mosaic have done is implement existing technology.  They even
implemented SSL with the 40bit exportable key size using rc4, which is what 
the law says you are supposed to do.  Any netscape employees want to dispute 
this and tell me about your encounters with the NSA?

> huge amounts of cash and credibility have been WASTED on it. the NSA has
> lost enormous credibility because of this fiasco. furthermore, the way
> they tried to hide behind presidential directives is absolutely repugnant
> to anyone who has a belief in the separation of powers within our 
> government.

They have only lost credibility to the cryptographic community, where they
already had very little credibilty.  This is the point that we all tend to 
overlook.  Joe SixPack, doesn't know much about the NSA or cryptography, when
first told about them he tends to think that they are their to protect him and
doesn't think of them as an enemy.  The biggest accomplishment of the clipper
thing is that nobody (very few at least) are using secure public key crypto
and the few new people to the issue have no idea who to trust now.  If their
job is to listen to tranmitions, then their money was well spent because there
aren't many secure transmitions right now.  and since everybody is scared about
it there aren't likely going to be a lot of secure transmitions real soon.


> do you realize the sheer ability of Microsoft to build software that
> succeeds in *markets*? Microsoft doesn't care much about Netscape
> because, as one microsoft engineer remarked, "well, it's strange
> to talk about market share when you are giving away software for free".
> well, the NSA is the absolute *opposite* of Microsoft. they don't
> have a *clue* about true market forces. they do however understand
> ways in which the government interferes with markets, and they seize
> on every one of those mechanisms as their lifeblood for control
> and "shadow/invisible oppression".

I disagree, the NSA and MS have a lot in common, they both have defined shoddy
standards that we are all using for one part of our life or other.  We will
have to put up with both of them for a long time and both of them are 
anticompetitive.  If market forces were so much more powerful than the NSA can
understand, then why the hell are all the banks in the world depending on DES?

> the NSA is quickly losing relevance. the public *does* desire public
> key crypto, and a defacto standard *has* been created, it's called PGP.
> if the NSA proposes something in public key areas, it is likely to 
> be pissed on by the public as much as Clipper, in many ways because
> of the failure of Clipper. clipper in a big sense *was* the NSA's first
> step toward public key encryption, and it was widely trounced on.

The NSA is only losing relevance with us, how many average folks even know what
clipper was?  We could even disregard the average people and just ask the 
computer users, how many of those 80million windows users know about clipper?
If it is enough for the NSA to "lose relevance" I would think this list with
be many times larger than it is. 

> 
> face it dude, the NSA has shown far less competence in the public arena
> than *any* apologist such as yourself can ever demonstrate.
> 

I take offence at that, I am not an apologist, I'm just trying to show the other
side.  We can't fight the NSA if we are all blind to what they do in the general
public's eyes.  For what it's worth, I can't think of a major commercial product
that uses cryptography that hasn't had the NSA's hands in it; that is pretty 
damn competent if you ask me.
NODE f1bfc6a6Re: NSA says Joe Sixpack won't buy crypto
On Sun, 3 Sep 1995, Vladimir Z. Nuri wrote:

> was a total fiasco. the self-destructing director of NSA whats-his-name
> who as running for that FBI position or whatever is another example of how 
> the inbred spook society has difficulty dealing with anything outside
> their artificial reality.

Give this man a prize.


---
00B9289C28DC0E55 nemo repente fuit turpissimus - potestas scientiae in usu est
E16D5378B81E1C96 quaere verum ad infinitum, loquitur sub rosa    -    wichtig!
*New Key Information*    -    Finger for key revocation and latest key update.
NODE 2231e8a4Re: NSA says Joe Sixpack won't buy crypto
> jim@acm.org (reporting on R. H. Morris' talk at Crypto '95):

> >- By the middle to late 1960's cryptanalysis became less cost effective
> >  than obtaining the information by other means -- wiretaps and so on.

> "Vladimir Z. Nuri" <vznuri@netcom.com> writes:
> but for some reason, the NSA keeps humming along...? perhaps 
> confirming the rule that bureacracies, like bores at parties,
> persist long after they are relevant?

Evidently they have plenty of other sources to deal with... their SIGINT
charter is to read traffic, not necessarily to decrypt traffic.  It does
seem excessive, though, and it will seem even more excessive once more
traffic is encrypted with strong systems and plaintext begins to disappear
from the airwaves and wires.  It bothers me that the gov't appears to
be redefining the role of the intelligence community to be economic spying
rather than the military spying that was (I think) justified during the
Cold War.  Rather than finding ways to justify and maintain current budgets
and bureaucracies, why not just cough up the peace dividend?

> >In the future there will be more radio used for ordinary communications.
> >Americans are unwilling to pay for secure telephones, but that's not the
> >case in Europe.

> I object to this highly. the NSA has very little credible understanding
> of market forces, IMHO. they are a government agency. they do not
...
> as for the market viability of cryptographic phones, I think this
> is duplicity ranging on utter lying that "the US public is not 
> willing to pay for secure phones". this is precisely the baseless

I misstated his point to some extent here.  He was contrasting current
buying practices in the U.S. and in Europe, not predicting the future (i.e.
not exactly what I said above).  In particular, he mentioned GSM in Europe
and its success... of course, that doesn't count as strong encryption with
the keys evidently being no better than 40 bits worth, but it's a lot
better than calling in the clear from your cellular phone.  He indicated
that Europe has embraced GSM and the US has not (yet) embraced anything
equivalent (about which more below).

>                                           Clipper, the closest the
> agency has come to creeping out of the darkness of their coffin,
> was a total fiasco.

Clipper wasn't a fiasco from the gov't's point of view if you look at what
it prevented rather than what it achieved.  By now the DES-based AT&T
encryption box might be the US standard if the Gov't hadn't intervened by
"incentivizing" them around the time of the Clipper roll-out.  It was
ready to go and was already in production when Clipper got rushed up.  As
it is there is now no standard and most traffic is still in clear.  If
this doesn't reflect a credible and <practical> understanding of how the
market works, what would?  Of course this one can't completely be laid at
NSA's door, but it's convenient to think of them as the fount of US crypto
policy decisions.

>              you see, there is far more to be gained from widespread
> encryption than is to be lost from it.

Agreed.

	Jim Gillogly
	Trewesday, 13 Halimath S.R. 1995, 01:26
NODE bc5db01aRe: NSA says Joe Sixpack won't buy crypto
"Just cough up the peace dividend".

There is no ppeace dividend. There is a massive eco-spill of government 
debt;  quite possibly larger than the GNP capacity of the American 
economy to repay anytime in the next century.

The debt will be bankrupted, in some stealthy manner, hidden by masses of 
smoke and mirrors. Nothing new here - it's  about the only thing that 
works. For the mosrt recent examples, read up on FDR's confiscation of 
gold in (?) 1933.  Or read the detrails of the currency changeover 
effected by the occupation authorities in Germany (1947 or 1948).

Alan Horowitz
alanh@infi.net
NODE 8f0d7127Re: NSA says Joe Sixpack won't buy crypto
I'm not sure I see the words "cryptography" or any related to them
here. It might be an interesting topic, but it probably isn't
cypherpunks material.

.pm

Alan Horowitz writes:
> "Just cough up the peace dividend".
> 
> There is no ppeace dividend. There is a massive eco-spill of government 
> debt;  quite possibly larger than the GNP capacity of the American 
> economy to repay anytime in the next century.
> 
> The debt will be bankrupted, in some stealthy manner, hidden by masses of 
> smoke and mirrors. Nothing new here - it's  about the only thing that 
> works. For the mosrt recent examples, read up on FDR's confiscation of 
> gold in (?) 1933.  Or read the detrails of the currency changeover 
> effected by the occupation authorities in Germany (1947 or 1948).
> 
> Alan Horowitz
> alanh@infi.net
> 
>
NODE b8038762Re: NSA says Joe Sixpack won't buy crypto
JG:
>Rather than finding ways to justify and maintain current budgets     
>and bureaucracies, why not just cough up the peace dividend?  

taking money from a bureacracy is like the exact opposite of taking
candy from a baby. but hell, maybe you could get a job as a spook
in their dark tunnels and "show them the light" so to speak. <g>

>I misstated his point to some extent here.  

oh right, any perceived boneheadness on the part of a premiere spook
is surely in the eye of the beholder <g>

>  He indicated
>that Europe has embraced GSM and the US has not (yet) embraced anything
>equivalent (about which more below).

well, thanks for clearing up the assertion but I stand by my rant.
(and BTW, thank you for the wonderful opportunity, one must prize every
opportunity to get one's blood boiling to know one is alive). the
US may very well not have "embraced" any encryption standard because
the NSA is trying to THROW A @#$%^&* WRENCH INTO ANY STANDARD THAT
IS DEVELOPED. that is EXACTLY WHAT CLIPPER WAS AN ATTEMPT TO DO.

y'know that we MAY HAVE WIDESPREAD ENCRYPTION BY NOW if the NSA has
not continually interefered with what is normally a NATURAL PROCESS
of standards creation in the technological community. Clipper is
a black, black mark not only because of what it tried to *introduce*,
but also of what it tried to *replace*.

again, the fact that we do not have widespread encryption in the U.S.
acc. to the NSA reminds me of the anecdote of the murderer going before
the court and stating that he deserved leniency because he was an
orphan. THE NSA HAS TRIED TO MURDER CRYPTO IN THE U.S. and then say,
"gosh!! there's no crypto!! no one has it!! therefore, no one wants it!!
why is everyone so angry when we tried to keep it from everyone when
nobody wants it"? @#$%^&*!!!

again, I suggest that the lack of crypto in the US is due to a 
*political* situation, and nothing else. the NSA of course would like
to deny that, and justify the *political* situation based on something else
(such as that people don't really want encryption or that it is not really
in the nation's best interests)
 
>Clipper wasn't a fiasco from the gov't's point of view if you look at what
>it prevented rather than what it achieved.  By now the DES-based AT&T
>encryption box might be the US standard if the Gov't hadn't intervened by
>"incentivizing" them around the time of the Clipper roll-out. 

exactly. THE MARKET COULD HAVE BEEN MATURING LONG AGO INSTEAD OF 
THROWN INTO CONFUSION.  we could have been on the path to improving 
encryption capability. and Clipper is only the product that we *saw*
in front of the world. did anything in the Clipper announcement talk
about the government collusion with AT&T? it is patently obvious that
the NSA has long worked behind the scenes to try to sabotage crypto,
and that Clipper was only the most desperate instance that we *heard*
about.

of course, when there is widespread crypto the NSA will probably try
to justify its existence based on the widespread crypto in the world,
and take credit for its introduction. "why, after all, Clipper was
a major step in introducing good encryption to the masses".  @#$%^&*

> It was
>rady to go and was already in production when Clipper got rushed up.  As
>it is there is now no standard and most traffic is still in clear.

indeed!! true progress!! the government has accomplished its mission
of sabotaging privacy!! so Clipper is a tremendous success in sowing
fear of the NSA into every American!! in throwing the standards process
into total confusion!!

JG, let me ask you a question. imagine there was some foreign government
agency, say of a totalitarian government, that wanted to prevent the
"spread of cyberspace" around the world. don't you think they could
be quite effective in  killing the Internet as it was growing? it would
be quite trivial to insert agent-provacateurs into all the open 
standards-making Internet conventions. where would we be now if this
happened?

cryptography is very intrinsic to cyberspace, and it would be quite
ubiquitous now if it werent for the reprehensible covert and overt 
NSA wrench-throwing acts. the NSA is sabotaging the natural growth of 
cyberspace, uneqivocally. I hope that every person in the NSA who
reads about Netscape or uses it, the Web, or the Internet,  hangs hi/her
head in shame, that he worked in an agency that helped work *against* the 
reality that created these wonderful embodiments of freedom in 
communication.

>>              you see, there is far more to be gained from widespread
>> encryption than is to be lost from it.
>
>Agreed.

actually, to tell you the truth I don't consider that a given. it is
very well possible that a huge advantage shifts to the terrorists of
the world. it very well may be!! but is anyone actually trying to
unbiasedly *answer* this question with honest research? of course
not. the NSA, the FBI, the whole law enforcement community is in
total CYA mode. we have Freeh actually utter at a press conference,
"would you feel the same about strong encryption if your daughter
was kidnapped by a pedophile?" or whatever his little @#$%^^&*
phrase was....anybody remember that slimy epithet of his?

for god's sake, could someone in the government do a study of 
what would *actually happen* if there was widespread encryption,
instead of letting the NSA's apparent default idea of "apocalypse now!!!" 
rule the whole debate?? the NSA is always talking about "the right
to communcation balanced with the needs of law enforcement", but have
they ever determined what in fact the costs are to society at large?
beyond simply ASSUMING that if a policeman complains that he can't
tap a phone line, that the world is really going to end tomorrow?!?!

has it ever occured to law enforcement agencies that widespread 
encryption may actually make their lives *easier*?? I could see a
situation where this is possible. the police routinely say, "sorry
ma'am we can't do anything because our hands are tied". if the police
and our government were prevented from any intervention into any
area involving cyberspace, perhaps both society and the police would
breath a lot easier!!

--Vlad Nuri