NODE 3ec584caRe: crypto for porno users
Carl Ellison <cme@clark.net>Fri, 24 Nov 1995 04:04:10 +0800
Hi Jay.
>Date: Thu, 23 Nov 1995 00:17:47 -0800
>From: Jay Campbell <edge@got.net>
>Subject: Re: crypto for porno users
>A law
>enforcement team would be stepping onto shaky ground if they were forced to
>transfer illegal images/etc to a suspected trafficer before getting evidence
>from him. Entrapment is an ugly concept.
We've been hearing about such things (using the mails) for some time. I
don't know how the cops avoided entrapment when they posed as kiddie porn
customers or pedophiles when they were doing the AOL sting.
>>3. Encryption of porn would work against the kind of porn distribution
>> found on the alt.binary.pictures.erotic... newsgroups. Encryption
>> requires that recipients be identified.
>
>Not at all .. a porn distributor could generate a key pair, use part A to
>encode the images, and dessiminate part B thru a variety of outlets -
>publicly posted, sold, passed thru an informal network of like-minded
>netizens...
It's that informal network which is the danger to the pornographer. The
bigger the network, the closer to certainty that it's been infiltrated.
<begin major soap box issue for me>
Strong authentication via crypto does not create a trusted group. Trust is
a human:human decision -- subject to severe flaws, none of which are solved
by crypto. [Can you devise a crypto protocol which will prevent or even
just detect adultery, for example?] With each additional person, there is
a probability of deception. For this informal network of yours, deception
by any one participant constitutes a security failure. If you want to
avoid that, therefore, you need to keep the group *very small*. If it's
that small, then it's not that interesting a target for LE.
<end major soap box issue for me>
>I would argue the exact opposite - strong crypto would tend to minimize the
>effective take, since there's no guarantee that /anything/ on a perp's
>system will be in the clear. I'll let someone else with a better background
>pound on the 'brute force' section.
Ah -- but that's the point I was making. Crypto gives the appearance of
security -- whether it's in the informal network or with file storage.
It's often a bank vault door on a cardboard house. For much of what people
do, especially if there's a large net, it's not rational to expect to
achieve security. But -- if people have done something to achieve
security, they're likely to be fooled into trusting it to be adequate.
Meanwhile, if *everything* on the perp's machine is encrypted, you're
probably in good shape. That means he'll be required to type passwords too
often -- so he'll either pick a small one or have some machinery which
stores the password. Both give cryptanalytic advantages.
This isn't a guarantee that *every* perp will be wide open. Some won't be.
It means that a bunch of perps will be wide open (out of their own
carelessness -- like the breaks into the Enigma net).
The question you need to look at is not the control-freak question which
Freeh seems concerned with:
A) the probability that some one perp will manage to hide his data
but rather the SIGINT question:
B) the expected percentage of perps who will fail to hide their data
Have a good day.
- Carl
+--------------------------------------------------------------------------+
|Carl M. Ellison cme@acm.org http://www.clark.net/pub/cme |
|PGP: E0414C79B5AF36750217BC1A57386478 & 61E2DE7FCB9D7984E9C8048BA63221A2 |
| ``Officer, officer, arrest that man! He's whistling a dirty song.'' |
+---------------------------------------------- Jean Ellison (aka Mother) -+
NODE 27ac3ab9Re: crypto for porno users
"Ed Carp [khijol SysAdmin]" <khijol!erc@uunet.uu.net>Fri, 24 Nov 1995 06:12:43 +0800
-----BEGIN PGP SIGNED MESSAGE-----
> >A law
> >enforcement team would be stepping onto shaky ground if they were forced to
> >transfer illegal images/etc to a suspected trafficer before getting evidence
> >from him. Entrapment is an ugly concept.
>
> We've been hearing about such things (using the mails) for some time. I
> don't know how the cops avoided entrapment when they posed as kiddie porn
> customers or pedophiles when they were doing the AOL sting.
As I recall, the courts have sent the message to the LE community that it's entrapment if they
entice someone into doing something that they normally wouldn't do. If you're a kiddie porn dealer,
and I as a LE officer entice you to sell me some pictures of that cute 8-year-old doing some geezer,
then that's not entrapment. If I, on the other hand, try to pressure you (assuming you are a
law-abiding citizen) into buying such by either misrepresenting the article in question or by
threatening you with dire consequences if you don't buy, etc. - in other words, forcing or enticing
you to do something you normally wouldn't do - *that's* entrapment.
- --
Ed Carp, N7EKG Ed.Carp@linux.org, ecarp@netcom.com
214/993-3935 voicemail/pager
Finger ecarp@netcom.com for PGP 2.5 public key an88744@anon.penet.fi
Q. What's the trouble with writing an MS-DOS program to emulate Clinton?
A. Figuring out what to do with the other 639K of memory.
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
iQCVAwUBMLTsaSS9AwzY9LDxAQHZ9AP/ZmGmWQm/cd+osceg0rLj8ZgrPbsXw3hi
5u4RbAjWlazTKydk6JfgDrpfLn+tFr/KhqWE7Zo7wFcgTJcX39PdhuxyO0gnt+lr
BdCjB+qYSei3/TgsoU5XPkMEj+fp22dT1NIxRdDPujDjE1BEz18knQsihngGsZ6X
Iz8TyBe6SIM=
=dJ0W
-----END PGP SIGNATURE-----
NODE 2aeeeb69Re: crypto for porno users
Moroni <moroni@scranton.com>Sat, 25 Nov 1995 08:04:37 +0800
I wish we could get off the subject of the kiddie porn , it makes me
wonder what people on this list are doing when they are not mailing out
letters. Not to flame ,BUT it is such a serious issue and we all as
adults and approaching adults should not treat it as an academic issue .
It is the most victimizing of all crimes and I think of speak for some of
us when I say that it would be better if we all found a way to get back
to discussing the problems of cryptography as related to we not
pornographers.
Thanks in Advance
moroni
NODE a0b4e218Re: crypto for porno users
"Ed Carp [khijol SysAdmin]" <khijol!erc@cygnus.com>Fri, 24 Nov 1995 06:13:43 +0800
-----BEGIN PGP SIGNED MESSAGE-----
> Strong authentication via crypto does not create a trusted group. Trust is
> a human:human decision -- subject to severe flaws, none of which are solved
> by crypto. [Can you devise a crypto protocol which will prevent or even
> just detect adultery, for example?] With each additional person, there is
> a probability of deception. For this informal network of yours, deception
> by any one participant constitutes a security failure. If you want to
> avoid that, therefore, you need to keep the group *very small*. If it's
> that small, then it's not that interesting a target for LE.
Very true. Authentication, whether strong or weak, merely says that you are who you say you are -
totally different from this "web of trust" I keep hearing about - and that is *it*. Do you trust me
any more now than before I started signing my postings?
> Ah -- but that's the point I was making. Crypto gives the appearance of
> security -- whether it's in the informal network or with file storage.
> It's often a bank vault door on a cardboard house. For much of what people
> do, especially if there's a large net, it's not rational to expect to
> achieve security. But -- if people have done something to achieve
> security, they're likely to be fooled into trusting it to be adequate.
>
> Meanwhile, if *everything* on the perp's machine is encrypted, you're
> probably in good shape. That means he'll be required to type passwords too
> often -- so he'll either pick a small one or have some machinery which
> stores the password. Both give cryptanalytic advantages.
It's well-known that most revelations of encrypted information come from "humint", not from
mathematical finesse with the encryption scheme. I especially love Oracle's idea of security - when
submitting SQL to the Oracle back-end, to automate the process, you feed it your user ID and
password IN THE CLEAR, ON THE COMMAND LINE. Any weenie can run "ps -ef/ps -ax" and pipe it to
grep. The fact that Larry Ellison wont do anything about it seems to me to be idiocy of the first
order, and that Oracle doesn't know what it's doing. It's not even a good database product. Deity
only knows why people keep buying it, although that's rather off-topic ;)
- --
Ed Carp, N7EKG Ed.Carp@linux.org, ecarp@netcom.com
214/993-3935 voicemail/pager
Finger ecarp@netcom.com for PGP 2.5 public key an88744@anon.penet.fi
Q. What's the trouble with writing an MS-DOS program to emulate Clinton?
A. Figuring out what to do with the other 639K of memory.
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
iQCVAwUBMLTuOyS9AwzY9LDxAQEuWAP9EU0LgHHAFQgpR+h2D/u9oZmNR3I2z7Cm
qsEZr0Iy84Cu7fH5vIvy5waDx3OZC+Gc1Z2kFydebxl09rTrY88rYIj0Ezp3Mqjk
25oqSlKoDMJNYC2W6cfhVAx6VBDnuExMi4H/R/8pTUepNSBMyc9z0nG0ivkCbTBz
AQd1jcI3lPU=
=Fvaf
-----END PGP SIGNATURE-----