NODE 9ed8bc3dRe: monkey-wrenching GAK
tcmay@got.net (Timothy C. May)Fri, 20 Sep 1996 07:55:01 +0800
At 4:46 PM 9/19/96, Ray Arachelian wrote:
>Another thing you can do: generate huge key pairs all day long and submit
>them to the NSA. If enough people do this, they will be flooded and
>overworked, of course they may ignore them, etc, or make it hard to do
>so, but if everyone generates a 4K key every hour or two and discards it,
>but gives the key pair to the NSA anyway, they will run out of storage
>space, or at least it will make it much much harder for them to figgure
>out which key you are using for conversation X.
Ah, but what about the _fee_ for registering a key? You really didn't think
this would be free, did you?
(It costs money to register cars, guns, etc., so why would it be "free" to
register a key?)
Besides being a revenue enhancement tool, charging a fee stops this sort of
flooding attack.
(Note: One of my biggest objections to GAK, besides the political/civil
rights issue, is what it does to systems which generate lots and lots of
keys on an ad hoc, continuing basis. GAK, if enforced, puts a major speed
bump in the way and increases costs, possibly making certain kinds of
systems infeasible.)
--Tim May
We got computers, we're tapping phone lines, I know that that ain't allowed.
---------:---------:---------:---------:---------:---------:---------:----
Timothy C. May | Crypto Anarchy: encryption, digital money,
tcmay@got.net 408-728-0152 | anonymous networks, digital pseudonyms, zero
W.A.S.T.E.: Corralitos, CA | knowledge, reputations, information markets,
Higher Power: 2^1,257,787-1 | black markets, collapse of governments.
"National borders aren't even speed bumps on the information superhighway."
NODE cba891f1Re: monkey-wrenching GAK
Adam Back <aba@dcs.ex.ac.uk>Sat, 21 Sep 1996 06:06:10 +0800
Tim May <tcmay@got.net> writes on cpunks:
> Ray Arachellian <sunder@brainlink.com> writes:
> >Another thing you can do: generate huge key pairs all day long and submit
> >them to the NSA. If enough people do this, they will be flooded and
> >overworked [...]
>
> Ah, but what about the _fee_ for registering a key? You really didn't think
> this would be free, did you?
I agree. With the aim of enforcing True Names, this might also get
tied to an internet drivers license (and your fingerprints (the
physical kind), social security number etc, much like car DLs (from
the other thread)).
> (Note: One of my biggest objections to GAK, besides the political/civil
> rights issue, is what it does to systems which generate lots and lots of
> keys on an ad hoc, continuing basis.
Yeah, kind of wrecks all the current uses of forward secrecy, DH in IP
link level encryption; temporary RSA keys, and DH used by SSL, and so
on.
The fact that these things are currently in world wide use on a large
scale presents the US law enforcement with problems. They'd need to
"unpublish", and recall a *lot* of software. Some of the non-US folks
might not be so keen to do a GAK enabling downgrade.
Adam
--
exported RSA today? --> http://www.dcs.ex.ac.uk/~aba/rsa/
#!/bin/perl -sp0777i<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<j]dsj
$/=unpack('H*',$_);$_=`echo 16dio\U$k"SK$/SM$n\EsN0p[lN*1
lK[d2%Sa2/d0$^Ixp"|dc`;s/\W//g;$_=pack('H*',/((..)*)$/)