Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Fax
Telephone
Pen & paper
snail mail
Announcement
Collapse
No announcement yet.
What would you do?: Assume all Public Key Exchange models in use failed overnight.
Collapse
X
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Originally posted by astcell View PostI'm old enough to remember when credit cards not only had no magnetic strip, but the numbers on the cards were TYPED on it, not raised. Yes the world got along fine with couriers, registered mail, pencil and paper. More F2F meets and having to fly to another continent just to utter 5 words. Yup that was my world growing up.
I'd keep listing suggestions, but the best ones are sitting in my WTSHTF plan.
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Originally posted by renderman View Post
This is what I would fear more than any attack or sudden catastrophic event. Because a real failure of any system can be fixed. A wire breaks, you replace it. A server fails, you switch to the backup. The backup fails, you pray to spongebob.
xor
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
My interpretation of the question revolved around the idea that one morning someone announces "We have a box that can break all common PKI based crypto" ala "Sneakers"
While not necessarily breaking the functions currently in place (money could still be transfered, cryptomail sent) but suddenly the mass assumption that it can't be broken in a reasonable time being crushed.
This is what I would fear more than any attack or sudden catastrophic event. Because a real failure of any system can be fixed. A wire breaks, you replace it. A server fails, you switch to the backup. The backup fails, you pray to spongebob.
The bits, bytes, metal, plastic, silicon, and even math that make up such 'secure' systems are built upon the basis of something much smaller and intangible; TRUST
If such a box or decryption system suddenly hit the world, that trust is broken. If that trust is broken, you cannot be reasonably sure that the incoming bank withdrawal request is real. You cannot trust the orders coming from higher up in command. Your not going to take the risk if that trust is broken.
Terrorism, asteroids, global warming, nuclear proliferation. These don't scare me. What does scare me is natural human reactions to fundamental changes in their base psychology. Things like alien life being proven. Religious nuts in general being proven wrong and then attempting to 'make it right'. Humans don't do well with change. To suddenly pull a rug out from a high level of trust (i.e. banking, chain of command) usually doesn't end well
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Originally posted by renderman View PostI assume this topic came about because of the recent announcement of 2 separate groups both making leaps in quantum computing...
.
Just MHO, that perhaps for a short term period the attacker may have a slight edge, but it would be short lived at best.
thx-1138Last edited by xor; September 16, 2007, 13:57.
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Originally posted by xor View PostA better question to ask would be what would happen if an EMP device were detonated over the US.
Using formula from Physics, you can compute the effective force and field strength of a magnetic field given a distance in addition to strength. Like Gravity, the force of field strength relies on the strength of a charge, but the distance is much more important, since the distance is an inverse square applied to any change in charge/field.
So, double the charge, and double the distance, you halve the effective strength to the new distance. Because of this, the effective radius for any EMP bomb is very limited, and addition of more "power" to generate a strong field faces diminishing returns.
A single bomb over the US would not be enough-- even if the power source was nuclear. Many, many EMP would be needed, and then you would have to consider additional power requirements to push the EMI through shielded spaces, and underground storage systems.
Even without an attack a solar flare from the sun directed at the planet could be absolutely catastrophic. In fact it has already happened in the past and will happen again.
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Originally posted by Schuyler View PostI cannot imagine that situation happening without incurring a very specific loss of life in both the immediate and in the following days and weeks. I'd imagine we would be responding as much to the loss of our infrastructure as we would to the loss of life.
As far as going to war at that point, it would depend on how protected our military electronics were. Personally I would have the military on alert and on our shores at that point. National defense first and foremost. I know a lot of people would rather see us marching to war to do something about it, but I think it would be ignorant not to expect more after an event like that. If there was good, verified, actionable intelligence saying "yes, there is more, and it's going to come from X" I'd see if we couldn't get an ally in the area (Say Isreal, if it's the middle east) to launch a preemptive counterstrike to whatever worse was about to come.
thx-1138
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Originally posted by renderman View PostI assume this topic came about because of the recent announcement of 2 separate groups both making leaps in quantum computing...
Much of present high-speed crypto (done on computers today) that use Public Key, or Public Key exchange, rely on very basic assumptions. Many non-public key-exchange are not necessarily at risk. For example, a vernam (Simple XOR, OTP, no key reuse, *) cipher with non-reused "keys" exchanged in an implied secure manner allow for what is considered by many to be one of the most "secure" (from attack by only watching the data stream, not physical security, eavesdropping, etc.)
As DT mentioned, cases where there are *only* secret keys (such as pre-shared secret keys in VPNs) are often considered to not be at *new* risk to attacks (specific) to PKI, by matter of definition and key secrecy.
I wanted to have the problem be generic enough, so as to not be limited to just the spaces where fundamental assumptions required for present Public Key systems are being attacked, but also include spaces that I've not considered, or that might develop in the future.
I think that what would change depends on the type of person on an individual level, and at what level of society on a mass level
On an individual level you'd find credit cards and most common commerce functions would be suspect and you'd see something akin to the old 'run on the bank'.
In a smaller bubble beyond socio-economic meltdown, I would see alot of communication remain the same. Most people recieve email in plain text and few if any average home users use crypto beyond banking/commerce functions.
It's an interesting question to think about because it's a very real one that may occur. I personally tend to be a pessimist and assume the worst will occur. Society tends not to deal with paradigm shifts too well and things would get very ugly very quickly.At least it would'nt be boring.....
Originally posted by Schuyler View PostI'd stop clicking on the red box.
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Originally posted by xor View PostA better question to ask would be what would happen if an EMP device were detonated over the US. An attack of our infrastructure and technology not killing people directly mite not merit a direct military response. Can you really justify killing people over the destruction of critical electronic infrastructure.
As far as going to war at that point, it would depend on how protected our military electronics were. Personally I would have the military on alert and on our shores at that point. National defense first and foremost. I know a lot of people would rather see us marching to war to do something about it, but I think it would be ignorant not to expect more after an event like that. If there was good, verified, actionable intelligence saying "yes, there is more, and it's going to come from X" I'd see if we couldn't get an ally in the area (Say Isreal, if it's the middle east) to launch a preemptive counterstrike to whatever worse was about to come.
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
A better question to ask would be what would happen if an EMP device were detonated over the US. An attack of our infrastructure and technology not killing people directly mite not merit a direct military response. Can you really justify killing people over the destruction of critical electronic infrastructure.
Imagine one day we are part of a global village; suddenly and without warning we are reduced to getting news from our neighbor. No TV, cars, radios, computers, the US goes dark. All unprotected electronics destroyed.
Could you justify war at this point or would you first have to put the country back together which could take a decade or more?
Even without an attack a solar flare from the sun directed at the planet could be absolutely catastrophic. In fact it has already happened in the past and will happen again.
thx-1138
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
I'd stop clicking on the red box.
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
I assume this topic came about because of the recent announcement of 2 separate groups both making leaps in quantum computing...
I think that what would change depends on the type of person on an individual level, and at what level of society on a mass level
On an individual level you'd find credit cards and most common commerce functions would be suspect and you'd see something akin to the old 'run on the bank'.
Large segments of society would grind to a halt as suddenly large banking transactions cannot be verified nor trusted because of the inevitable number of jackasses who would begin to screw with things or just create enough noise in the system to create chaos.
In a smaller bubble beyond socio-economic meltdown, I would see alot of communication remain the same. Most people recieve email in plain text and few if any average home users use crypto beyond banking/commerce functions.
I think that for those of us who use crypto as much as we can (I like un-necessary crypto) our trust would not be immediately broken however our paranoia and suspicion would increase and new communication would be vetted very closely. Habits would change and less un-necessary communications would occur.
It's an interesting question to think about because it's a very real one that may occur. I personally tend to be a pessimist and assume the worst will occur. Society tends not to deal with paradigm shifts too well and things would get very ugly very quickly.
At least it would'nt be boring.....
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Originally posted by xor View PostPersonally I don't claim to be an expert in this subject or even educated. But since we are just talking I'll give it a try.
Even a forum member who is a luddite, that uses carrier pigeons to another human as a forum proxy can reply. Maybe they would say, "The only thing that I would do differently is say,'I told you so!nyah nyah!'"
I personally don't see how this could happen, please elaborate on the possibilities. Though this is an extremely analogy and no doubt a stretch it's sort of like saying what would happen if all the windows boxes one day suddenly didn't boot(wishful thinking). We would all learn MAC OSX, LINUX or FREEBSD.
Even if a new model was found, which appeared to "solve" the present catastrophe, the implementations using the broken models would still exist in live systems, and perhaps exist in firmware, only upgradeable by physical replacement. The only thing a new model would change would be how long the catastrophe would last.
Leave a comment:
-
Re: What would you do?: Assume all Public Key Exchange models in use failed overnight
Personally I don't claim to be an expert in this subject or even educated. But since we are just talking I'll give it a try.
Initially and most likely life would go on in an insecure way until new secure models could be developed or existing alternatives could be implemented. Most crypto is so complicated the average person still would not be able to do anything with it. Data would only be insecure/accessible to a few. It would be a tremendous blow and set back to the perception of trust by the people of internet commerce. As reliant as we are on technology and the fact the most people don't secure anything unless it's done for them again life would go on. The internet has too much going for it for a little thing like trust to get in the way. The internet is an unstoppable juggernaut, short of a solar flare, gamma ray burst, an EMP weapon detonated over the US, nuclear holocaust, the Taliban sacking Washington DC, or us exhausting all energy in the world the internet will be with us insecure or secure for the foreseeable future.
There was a guy in the wireless village at defcon that was pushing a box that performed realtime decryption of ssl webpages. Just cause it can be done doesn't mean he has my banking info or is reading my mail.
I personally don't see how this could happen, please elaborate on the possibilities. Though this is an extreme analogy and no doubt a stretch it's sort of like saying what would happen if all the windows boxes one day suddenly didn't boot(wishful thinking). We would all learn MAC OSX, LINUX or FREEBSD.
xorLast edited by xor; September 15, 2007, 18:59.
Leave a comment:
Leave a comment: