cypherpunks-legacy
Threads by month
- ----- 2026 -----
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2004 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2003 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2002 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2001 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2000 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1999 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1998 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1997 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1996 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1995 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1994 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1993 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1992 -----
- December
- November
- October
- September
- 130025 discussions
FORWARDED MESSAGE
=++=++=++=++=++=++=++=++=++=++=++=++=++=++=++=++=++=++=++=++=++=++=+=
In this message, we introduce binding cryptography, a new proposal for
establishing an information security infrastructure that does not
hamper law enforcement. We present an alternative that can give
law-enforcement agencies access to session keys, without users having
to deposit private keys. Unilateral fraud in this scheme is easily
detectible. We outline the proposal below, and announce two articles
which will describe the proposal in more detail and which will provide
the legal and the technical context.
The text is also available at
http://cwis.kub.nl/~frw/people/koops/binding.htm.
9 October 1996
Eric Verheul, everheul(a)ngi.nl
Bert-Jaap Koops, koops(a)kub.nl
Henk van Tilborg, henkvt(a)win.tue.nl
-------------------------------------------
(c) 1996 Eric Verheul, Bert-Jaap Koops, Henk van Tilborg
This message may only be redistributed in its entirety and with
inclusion of the copyright notice. Credit if quoting.
_Binding Cryptography, a fraud-detectible alternative to key-escrow
proposals_
_1. Introduction_
Information security, and so cryptography, is essential in today's
information society. A robust (information) security infrastructure
must be set up, including a Key Management Infrastructure. However,
the unconditional use of encryption by criminals poses a threat to law
enforcement, a problem that is hard to solve. Consequently,
governments have two tasks. The first is stimulating the establishment
of a security structure that protects their citizens, but which does
not aid criminals. The second task is coping with the use of
encryption by criminals outside of this framework. We think that
encryption outside of the framework (e.g., PGP) should not be outlawed
- but it need not be mainstream either. It is crucial that any such
established security structure is widely accepted and trusted, as this
will lower the demand for encryption outside of this framework, and so
will make the second goal easier to achieve (or, at least, not more
difficult). The establishment of such a widely accepted and trusted
security structure is now the challenge that (US) IT businesses face
if they want to participate in the recent CLIPPER IV initiative.
_2. Binding cryptography_
In a series of two articles, we address the establishment of an
information security infrastructure. Several proposals have been made
by governments and others to establish such an infrastructure, but a
satisfactory overall solution remains yet to be found. In the
non-technical article [VKT], we review several technical proposals and
a few government initiatives, focusing on key-escrow proposals. We
present a series of criteria that acceptable solutions should meet,
and note that all proposals so far fail to meet many of these
criteria. We argued that the establishment of a worldwide security
infrastructure can not be achieved without strong cooperation of
governments. In fact, governments themselves should take up the
challenge of establishing a security infrastructure, based on
public-key encryption, which does not hamper law enforcement. We offer
a new solution to achieve this: "binding data", which also improves
upon current proposals. It has the advantage that it helps the
establishment of a strong security infrastructure which discourages
abuse for criminal or subversive purposes by making unilateral abuse
easily detectible. It allows a straightforward monitoring of
compliance with law-enforcement regulations, without users having to
deposit ("escrow") keys beforehand. Thus, an information security
infrastructure can be established, which does not worsen the crypto
problem for law enforcement.
Metaphorically speaking, our solution consists of equipping public-key
encryption systems used for confidentiality with a (car) governor (a
speed-limiting device). The specifications of this governor are rather
general, and so many systems can probably be equipped with them. It is
inspired by the proposal of Bellare and Rivest [BR], in which users'
encrypted messages consist of three components:
1. the (actual) message encrypted with any symmetric system, using a random session
key;
2. the session key encrypted with the public key(s) of the addressee(s);
3. the session key encrypted with the public key of a Trusted Retrieval Party (TRP).
In effect, the TRP is treated as a virtual addressee, although the
message is not sent to it. When a law-enforcement agency is conducting
a lawful intercept and strikes upon an enciphered message, they take
the third information component to the TRP. If shown an appropriate
warrant, the TRP decrypts the information component and hands over the
session key, so that the law-enforcement agency has access to the
message. Observe that users are not obliged to escrow their (master)
keys, they only give access to the (temporary) session keys used in
the communication. The concept of "virtual escrow" has been the base
of several escrow products (AT&T Crypto, RSA Secure, TIS Commercial
Key Escrow).
The main drawback of this concept is that it offers no possibility, at
least for others than the TRP, to check whether the third component
actually contains the (right) session key; moreover, the TRP will only
discover fraud after a lawful wiretap. This renders the solution
almost entirely unenforceable.
Therefore, we propose a binding alternative, which adds a fourth
component to the encrypted message:
4. binding data.
The idea is that any third party, e.g., a network or service provider,
who has access to components 2, 3 and 4 (but not to any additional
secret information) can:
a. check whether the session keys in components 2 and 3 coincide;
b. not determine any information on the actual session key.
In this way, fraud is easily detectible: a sender that attempts to
virtually address a session key to the TRP (component 3) that is
different from the real one he uses on the message (or just nonsense)
will be discovered by anyone checking the binding data. If such
checking happens regularly, fraud can be properly discouraged and
punished. The binding concept supports the virtual addressing of
session keys to several TRPs (or none for that matter), for instance,
one to a TRP in the country of the sender and one in the country of
the addressee. The solution therefore offers the same advantage for
worldwide usability as the Royal Holloway [Holl] concept. We also
remark that the concept supports the use of controllable key splitting
in the sense of Micali [Mica] as well: a sender can split the session
key and virtually address all the shares separately to the addressee
and various TRPs using the binding concept. Moreover, the number of
shares and the TRPs can - in principle - be chosen freely by each
user. Finally we remark that the time-boundedness conditon (the
enforceability of the timelimits of a warrant) can be fulfilled by
additionally demanding that encrypted information (or all components)
be timestamped and signed by the sender; a condition that can be
publicly verified by any third party (e.g., monitor) as well.
A PKI that incorporates binding data hence has the following four
players:
- Users, i.e., governments, businesses, and citizens,
- TTPs offering trusted services (e.g., time-stamping and certification of
public keys),
- TRPs aiding law-enforcement agencies with decrypting legally intercepted messages,
- Monitors, monitoring communications encrypted via the PKI on compliance with
binding regulations. For instance, these could be network operators or (Internet) service
providers.
In [VKT], we explain how we envision the framework in which the
binding concept could present a security tool in the information
society. We think the concept is flexible enough (e.g., in the choice
of TRPs) to be incorporated into almost any national crypto policy, on
both the domestic and foreign use of cryptography.
In a mathematical paper [VT], Verheul and Van Tilborg propose a
technical construction for binding data for an important public-key
encryption system: ElGamal. This construction is compatible with
Desmedt's [DESM] traceable variant of ElGamal. The construction is
based on the techniques used in zero knowledge proofs. We expect that
these constructions can be improved and that various other public-key
encryption systems can be equipped with binding data. We present this
as a challenge to the cryptographic research community.
An outline of the mathematical construction of binding ElGamal can be
found at http://cwis.kub.nl/~frw/people/koops/bindtech.htm.
_3. References_
[BR]
M. Bellare, R.L. Rivest, "Translucent Cryptography. An Alternative to
Key Escrow, and its Implementation via Fractional Oblivious Transfer",
see http://theory.lcs.mit.edu/~rivest
[Desm]
Y. Desmedt, "Securing Traceability of Ciphertexts - Towards a Secure
Key Escrow System", Advances in Cryptology - EUROCRYPT'95 Proceedings,
Springer-Verlag, 1995, pp.147-157.
[Holl]
N. Jefferies, C. Mitchell, M. Walker, "A Proposed Architecture for
Trusted Third Party Services", Royal Holloway, University of London,
see http://platon.cs.rhbnc.ac.uk
[Mica]
S. Micali, "Fair Public-key Cryptosystems'", Advances in Cryptology -
CRYPTO '92 Proceedings, Springer-Verlag, 1993, pp. 113-138.
[VKT]
E. Verheul, B.J. Koops, H.C.A. van Tilborg, "Binding Cryptography. A
fraud-detectible alternative to key-escrow solutions", Computer Law
and Security Report, January-February 1997, to appear. [*]
[VT]
E. Verheul, H.C.A. van Tilborg, "Binding ElGamal. A fraud-detectible
alternative to key-escrow solutions", will be submitted to
Eurocrypt97.
[*] For the Computer Law and Security Report, send subscription
enquiries, orders and payments to:
Pam Purvey
The Oxford Fulfilment Centre
PO Box 800, Kidlington
Oxford 0X5 1DX UK
Tel: +44 1865 843373
Fax: +44 1865 843940
For the United States:
Elsevier Advanced Technology
Fulfilment (enquiries)
660 White Plains Road, Tarrytown
New York, NY 10591-5153
USA
Tel: 914 333 2458
---------------------------------------------------------------------
Bert-Jaap Koops tel +31 13 466 8101
Center for Law, Administration and facs +31 13 466 8149
Informatization, Tilburg University e-mail E.J.Koops(a)kub.nl
--------------------------------------------------
Postbus 90153 | This world's just mad enough to have been made |
5000 LE Tilburg | by the Being his beings into being prayed. |
The Netherlands | (Howard Nemerov) |
---------------------------------------------------------------------
http://cwis.kub.nl/~frw/people/koops/bertjaap.htm
---------------------------------------------------------------------
--
" The way to combat noxious ideas is with other ideas.
The way to combat falsehoods is with truth. "
-- Justice William O. Douglas, 1958
2
1
As I got sidetracked and it has been awhile, I am reposting the entire
summary along with the second half, which I just finished.
Typos are all mine.
:
The American Bar Association Standing Committee on Law and
National Security - Law Enforcement and Intelligence Conference -
Debrief
The ABA's Standing Committee on Law and National Security is one
of the more successful Committees to come out of the ABA. It's
conferences and early morning breakfast briefings and lectures
are attended by some of the leading experts in the fields of
National Security, Law Enforcement, and Intelligence and no small
number of the beltway power elite.
I'm not sure if many people outside the legal community
understand the degree to which attorney's have impacted and
thrived in both the law enforcement and the intelligence
communities. In fact many, if not most, CIA case officers and
station chiefs, as well as field operatives, are attorneys or
have law degrees. Other intelligence organizations are no
different. It should come as little surprise then if a committee
of the ABA should happen to attract a surprising amount of
intelligence professionals.
This conference was no exception. Spooks, Feds, Legislators, and
even a few Kooks were in attendance. Members of the British,
American, Canadian, and German intelligence communities were in
attendance. A colleague and I attended the majority of the
conference and except where noted the reflections below are a
summary of our collective notes and thoughts on the subject
matter discussed. I'm taking a broad view of relevance to
cypherpunks, but I will omit that which seems clearly not of
direct or somewhat indirect interest.
Part One:
A Changed World for Law Enforcement and Intelligence in the 21st
Century
Thursday, September 19
7:45 AM Registration and Continental Breakfast
8:15 AM Welcome Remarks
Paul Schott Stevens
Chair
ABA Standing Committee on Law and National Security
8:30 AM I. An Overview of a Changing World.
*The Traditional Relationship of Law Enforcement, Foreign
Intelligence and National Security (1945-1995):
*How Have Other nations Balanced Legal and National Security
Requirements and Responded to a Changed World.
*The Changed Threats to U.S. National Security- New Problems and
Priorities
Elizabeth R. Rindskopf
Bryan Cave
Former General Counsel, Central Intelligence Agency
Member, Standing Committee on Law and National Security
Ms. Rindskopf outlined the three classic "periods" of
intelligence community and mission development in U.S. history
and set the stage for the discussions to follow.
Interesting subjects she did touch on included section 715 of the
Senate intelligence bill. The section allows the law enforcement
community to request assistance from foreign intelligence in
collection efforts on foreigners outside of the United States.
The BNC and BCCI scandals were discussed as a backdrop of the
hazards of law enforcement and intelligence separation.
Zoe Baird
Senior Vice President and General Counsel
Atena Life and Casualty Company
Member, Standing Committee on Law and National Security.
Ms. Baird discussed the dangers presented by globalization and
new technologies. She highlighted the point that crime
globalization often follows corporate globalization and the
manner in which a single individual's ability to cause harm has
increased in scope (The NYNEX Hack). Also interesting was her
discussion of the manner in which the more organized elements of
criminal activity worked to take advantage of the very open
society in the United States (Fund raising, publications,
anonymous communications).
Those activities once merely violations of criminal law are, she
argued, now increasingly national security concerns and that
national security events impact elections in very dramatic and
direct ways (Atlanta and Israel bombings as examples).
Crime, she pointed out, gets about an 80% response in the polls,
where as "National Security and Foreign Policy" get perhaps a 3%
response. Merging these elements together serves an
administration. She also pointed out the trend toward making
these issues generally more accessible to the public.
(Specifically by use of language. "Transnational threats"- which
was a term of art for non-state terrorism and organized crime-
becomes "Global Crime" or "Global Lawlessness."
Ms. Baird ended by asking how the firewalls between Law
Enforcement and Intelligence could be rebuilt with these new
considerations in mind.
I considered her a balanced cynic. She managed to get across
some very realpolitik notions without much murmuring from the
(limited) civil libertarian crowd.
David Bickford
Former Legal Adviser to the British Intelligence Services (MI5-
MI6)
Mr. Bickford has in past served as a conduit between British
Intelligence services and the United States. He is well known
and respected among the American and European Intelligence
communities. Knowing Mr. Bickford I can also say that he pays a
great deal of attention to who his audience is and speaks to
their interests with disarming accuracy. His discussion is
important because it is a good insight into what the policy
makers in the United States are looking at.
He began by highlighting the new international nature of crime.
No longer is it confined to power blocs. "Multi-jurisdictional
illegality" is increasingly a concern. New highspeed
communications channels are a contributor and organized crime
groups are possessed of extremely advanced administration
abilities. They are leaner and meaner because they use
computers, encryption, communications, and use up less resources
in administration. The ability to make the organization smaller
also makes it harder to penetrate. In this environment,
international cooperation is essential. He called for more
active and expansive extraterritorial jurisdiction for certain
crimes, and lamented his own country's lack of enthusiasm for
this concept though they are slowly "coming around."
His solutions included the labeling of organizations, even when
they are not geographically based, as "illegal international
organizations" and using all means to combat them. He envisions
a wide cooperation by the G7 to accomplish this, leaving such
organizations with no safe haven. Sanctions regimes formerly
employed only as against "rogue states" and countries in disfavor
should be employed to destroy these illegal international
organizations wherever they are. He indicated that the other G7
states should build on the recent Clinton Executive Order which
seizes the assets of such organizations which may be located in
the jurisdictions of the G7. He called for measures to deny
these assets access to the major securities and international
finance markets and proposed that only organizations like the NSA
could confront and complete these tasks. Intelligence, he
argued, is the only organization that can keep up with
international crime and as a result there should be developed
court processes to introduce intelligence into criminal cases
while protecting the more sensitive information (sources and
methods) as irrelevant. "Evil men" have taken an "early lead."
$500 billion a year comes out of the United States alone in money
laundering. 400 billion in assets is attributed to drug cartels,
80% of which are Cali Cartel assets. There are over 250
international Russian criminal organizations currently operating.
Mr. Phillip Heymann
James Barr Ames Professor and Director,
Center for Criminal Justice
Harvard Law School
Member: Standing Committee on Law and National Security
[Didn't find his comments particularly relevant]
II. Political Challenges in the World Environment
*Breakup of the U.S.S.R.
*Loss of National Sovereignty and Control by Nation States
*Erosion of National Legal Systems
Military Threats at the Subnational Level:
The Terrorism Dilemma
(This looked very much like the section given to the Soviet
Analysts, who no longer have much of a job to do).
Mr. Morton H. Halperin
Senior Fellow
Council on Foreign Relations
Former Special Assistant to the President and
Senior Director for Democracy, National Security Council
[Canceled]
Mr. Peter Rodman
Director, National Security Programs
Nixon Center for Peace and Freedom
and Former Deputy Assistant to the President for National
Security Affairs
Mr. Rodman discussed the new "trans-national areas." Terrorism,
corruption, economic and criminal activity. He discussed the
side effects of collapsing empires (the rise of organized crime
to enforce property and contract rights that cannot be enforced
by the government, the shift of power to the local from the
regional and executive areas) and discussed, in this context, the
importance of avoiding petty squabbles over issues like trade and
the like because they threaten the more important strategic
cooperation that will be necessary to battle global and
transnational criminal activity.
Ms. Jessica E. Stern
Consultant
Lawrence Livermore National Laboraory and
Former Director, Russian, Uklrainian and Eursian Affairs,
National Security Council
Ms. Stern discussed the severe proliferation problems presented
by a weak Russia, particularly the weakening of MPCA (Material
Protection Control and Accounting).
11:15 AM III. Technical and Practical Changes in the Relevant
World Environment
*Global Technologies Emerge
*"Equal Access" to Advanced Technology by State and Private
Actors
* Change in Size, Type and Location of National Security Threats:
Challenge for Modern Intelligence and Law Enforcement
Stewart Baker
Steptoe and Johnson
Former General Counsel, National Security Agency
Member, Standing Committee on Law and National Security
Mr. Baker's remarks were brief, but he discussed the evening of
the odds with respect to government and private organizations
caused by technology.
Admiral William O.. Studeman
United States Navy (retired)
Former Acting Director of Central Intelligence
Admiral Studeman discussed "Information Warfare," pointing out
specifically that advanced societies were more vulnerable because
of their financial, banking and revenue system's dependence on
computer. Power, air traffic control, public safety and media
were also mentioned in passing.
Admiral Studeman went on to call for more intense secrecy in law
enforcement (not intelligence) as to collection methods and new
technology. He called passionately for funding for the DigiTel
program as well as a "key escrow" policy.
Anthony Oettiger
Chairman, Program on Information Resources Policy
Harvard University
Mr. Oettinger was perhaps the only moderate speaker in the
conference. He discussed Executive Order 13010 (establishing the
Critical Infrastructure Protection organization) and called for
more private sector input in policy making (Banks, markets,
businesses want to make their own security arrangements, and are
not very interested in paying much attention to the suits at
their door who claim 'Hi, we're from the government, we are here
to help.'
He pointed out the difference between the movements in Airline
Security (which is drifting from privately maintained, to
publicly maintained) and Internet security (which is doing the
reverse).
He called for reasoned response to the new threats which did not
commit expensive intelligence and law enforcement resources to
combat the single hacker. Proper threat assessing is important,
and intelligence should be used to pinpoint the weak points.
Walter Pincus
National Security Affairs Reporter
The Washington Post
Mr. Pincus asked if (a lovely analogy to chicken little and
osterages with their heads in the sand). His most interesting
remarks regarded the wisdom of dedicating such substantial
resources to repell non-strategic efforts to disrupt networks.
(Hackers, lone gunmen, etc.) He questioned. Doesn't, afterall,
a strategic attack require much more preperation? Should we
really allow the personality of e.g., Louis Freeh, who has the
capital dazzled from his glow, to direct these resources?
12:30 PM Luncheon
John Deutche
Director, Central Intelligence Agency
[Cancelled in the wake of the investigation into alleged CIA drug
connections in California]
Part Two:
The Implications of a Changed World for a Set of Critical
Decisions
2:00 PM IV. Protections Against New High Tech Dangers; Problems
of Encryption, Information Warfare and Computer Theft
Stewart Baker:
Mr. Baker, considering what his position once was, was surprisingly
mellow. There wasn't much warning for law enforcement, he commented.
Cryptography lends itself to criminal activity and subversive warfare.
It's hard to reherse attacks because you have to do it on real live
systems.
For defenses, he suggests the following:
1. Monitor and protect government systems.
2. Launch attacks, both on our systems and on others. (!)
3. Take note that attacks on private systems are the most worrisome.
(Financial institutions, exchanges, utilities)
There is a manifest mistrust between government and private sector
business. Private parties are unlikely to accept help from government.
The liklihood of government systems being adopted is slim.
Banks, for example, make high security expenditures and the choice of
system is best left up to them. (!)
There are, however, market failures in the private sector.
1. No one in the private sector bothers to protect against a simutanious
attack on power and telephone service. This is HIGHLY unlikely to happen
by chance, but by design it is almost certain to happen in an attack.
2. Reporting of incidents. Incidents are rarely if ever reported by
private sector interests. (Flight of funds on reporting, bank runs, lost
of customers all make reporting incidents difficult to justify).
Collection or REQUIRED disclosure, Mr. Baker argues, is required.
3. Some minimum recovery mechanism is required. There is no independent
information system for private sector interests because there is very
little financial incentive to build one. How will the civilian system be
recovered after an attack?
Lee Bollinger
Provost
Dartmouth College
Mr. Bollinger discussed 1st Amendment issues. He had, however, a strange
take on the way they should be broken down. Namely:
Pro Crypto: ITAR as prior restraint. Yes the 1st Amendment is painful
sometimes. So what? This is the cost of a freedom of speech culture.
Anti Crypto: This is a foreign affaris matter. Courts are not fit to make
analysis here. This is not the pentagon. It is "Technical" data and
therefore outside 1st Amendment scope.
Kate Martin
Director, Center for National Security Studies.
The Center for National Security Studies used to be a section of the
ACLU, but has since broken off and gone its own way.
Ms. Martin pointed out that the FBI shouldn't WANT to get involved in the
sources and methods problems that taking intelligence information would
present. The confrontation clause will present problems for the FBI if it
gets information which fall under intelligence "Sources and methods" and
then tries to use it in court. (Greymail - Where the defense calls for
sensitive records necessary to the defense and if they get a ruling in
favor of the discovery, the government either has to make national
security documents public or drop the charges).
She also pointed out that in the current draft of the anti-terrorist bill,
the FBI can "task" the CIA to make collections abroad. The CIA could then
break into a foreign residence, and look for evidence, find evidence
implicating a previously unknown American citizen in e.g., drug smuggling.
The FBI could prosecute the evidence, which was obtained without warrant
and would constitute illegal search in the United States, and the U.S.
Citizen would have, under current 4th amendment standards, NO STANDING to
move for exclusion of the evidence found by the CIA.
Howard Shapiro
General Counsel
Federal Bureau of Investigation
Mr. Shapiro was quite slippery. He spent most of his time dodging Ms.
Martin's barbs by indicating that the FBI tended to err in favor of
applying the constitution even in extraterratorial cases (Achille(?) Laro,
where the terrorists were read their rights even though outside of U.S.
Territorial Jursidiction) and the the FBI would respect limits even if not
required to. Rather weak argument, quite well presented.
Suzanne Spaulding
General Counsel
U.S. Senate Select Committee on Intelligence
[Not Present - Ms. Spaulding was doing markup on the new Intel Bill (Since
signed) at the time, though she arrived later]
4:45 Adjournment
6:30 Reception and Dinner
Speaker Ernest R. May
Charles Warren Professor of History
The John F. Kennedy School of Government
Harvard University
[My associate and I were forced to miss this session]
Friday, September 20, 1996
8:00 AM Continental Breakfast
8:30 Overview
Philip B. Heymann
8:40 VI. New Uses for Intelligence as a Necessary Arm of U.S. Policy
Presentation:
R. James Woolsey
Shea & Gardner
Former Director of Central Intelligence
Mr. Woolsey made some very interesting comments. He called rather
passionately for "Key Escrow," more potent funding for "DigiTel" but also
suggested that perhaps the dictator that was using modern encryption
"might not be hiding as much as he thinks he is."
10:15 AM VII. Law Enforcement and Intelligence
* Can Intelligence Technical Capabilities Better Support Law Enforcement
Objectives: What are the Legal and Practical Limits?
* Should Covert Action and Technical Intelligence Gathering be Available
to Law Enforcement?
* Rethinking Jurisdicitonal Lines, Roles and Responsibilites: Are New
Structures Required?
* The Law Enforcement and Intelligence Relationship; Past, Present and
Future.
* Can Common Standards be Achieved for Collection and Oversight?
Moderator: The Honorable John H. Shenefield
Morgan, Lewis & Bockius
(Introductions and short statements only)
Presentations:
Mark M. Richard
Deputy Assistant Attorney General
Criminal Division
U.S. Department of Justice
Mostly discussion of anti-drug efforts but a few interesting comments:
Internet banking is on the radar screen and there may soon be an
entirely seperate department of DoJ which addresses internet banking
crime. DoJ is clearly leading the effort here. Intelligence agencies
less so.
Jeffrey H. Smith
General Counsel
Central Intelligence Agency
(Soon to return to Arnold and Porter)
A few rather vague quesitons came up about anonymous transactions and
internet came up. The Attorney general "is putting together structures to
attack that." Rather ominous.
Michael A. Vatis
Associate Deputy Attorney General
Office of the Deputy Attorney General
U.S. Department of Justice
Vatis is a young shining star in Justice, a Gorelick protege and likely to
be the most dangerous individual to cypherpunks in the coming years if he
stays with justice. Vatis understands remailers, encryption, PGP, even
mentioned "mixmaster" and so forth specificlly. He is sly, knows just
when to shut up and is probably the front man on the DoJ attempt to attack
remailers and anonymous communications in general. He is a real problem
for cypherpunks and the party is clearly over.
Jonathan M. Winer
Deputy Assistant Secretary of State for International Narcotics and Law
Enforcement Affaris
Winer's points of interest to the list were money laundering related. The
tactic, he indicated, is to get foreign governments to adopt legislation
to make money launderers move elsewhere. (The carrot and the stick
approach is used). He did acknowledge the need for money laundering in
the intelligence community, and urged, vaguely, for cooperation as money
launding regulation "is an increasingly important priority."
He discussed, vaguely, the CIA "tasking" issues brough up by Ms. Martin.
11:45 AM Luncheon
Speaker:
Jamie S. Gorelick
Deputy Attorney General of the United States
Ms. Gorelick most tooted everyone's horn for the increasing cooperation
that between the various communities.
-end-
--
I hate lightning - finger for public key - Vote Monarchist
unicorn(a)schloss.li
2
1
Why?
Date: 20th October 1996.
The purpose of life,... is not to be found. I have been pursuing
this
thought and question to many of the people I have met in the past few
weeks.
Sad enough to report that I have found no answers or clues that if anyone
ever
know what it is or could be. One thing for sure is material and physical
objects are close to replacing the purpose, the real purpose if there is
one.
I am still quizzed on how there is a purpose in which we all strive to
attain.
There must an objective somewhere which clearly states,"You, whatname
whatage,
will have to do this, do that."
Somehow, in the pursuit for the answer I have strained my physical
and emotional self. I have realised what I am doing and that I am actually
directionless, like all the people I know. Doing things for the sake of
doing.
Clearly, I think television or rather, the mass media in general has caused
the gradual eradication of purpose in life for many people. What do you
want?
What do I want? Sure enough, we do not ask ourselves that question once too
often, but spending more time pondering about it, it really makes no sense
in what we do having corellation to what we want. What is it actually that
we
seek in life?
Which brings us back to the time when we thought we had a purpose.
Could you recall the times when you really wanted something? Or someone?
Why?
Simply because we didn't have it. It's a mass media driven, pointless race
to
own something, which actually doesn't make much sense. I am not sure why
all
of us are acting the way we are. In trying to understand it, I began to
question why I would want to know. Why do I want to know? So that I could
talk
about it? Write a book? Be famous and rich? Be respected? Now, take a
minute
off and think of what you just read. It's from the media to the people. The
people made the media. People are driving people nuts. Is this what we
want?
Once you shrink the big picture, you realise that nothing makes any sense
anyway. And what is "making sense"?
What do we gain from realising all this which makes us act and live
the way we are? We get to past our time. Since we were born, we had nothing
except time. Shitloads of it, excuse me. So we start doing things. Things
that
actually do not mean much to us but, "heck, I've got all the time in my
life"
So, it starts to generate a sort of hype, "hey, he's doing something, maybe
I
should too." Then another fella comes in, "Well I've got nothing to do,
maybe
I should tell others what these two guys are doing" So the snowball gets
rolling. The moment it stops, if it ever stops, I guess we go crazy. Now
what
is crazy? Understanding why we actually have no reason of being here? I'm
not
going to start on religion, if you're getting my rift here.
So here we are, pretending that we love this and like doing that.
Okay, I admit somethings are fun but 90% of the time you realise, "gee,
what
is it that I want?" If everyone were to ask the same question at the same
time,
then we'd all be crazy or something, whatever. The problem is, there's five
billion people and each one not voicing what they think would hold
themselves
back by saying "Now, if I say that, these guys would think I'm nuts, and
my..."
Some do get to express, and once they express it, they are lost in the
world
of understanding, they realise that we all have no reasons, logical or
whatsoever, to be where we are doing what we think we need to do. Now these
guys are labeled "nuts" and grouped together. See how happy they are in
"Cuckoo's Nest". Okay, so the interns are a little pain in the ass. But
look
at yourself! We are basically doing things of no relevance. Question what
you
do with "So?" You are bound to realise what you have probably tried to hide
all your life. That we are all alone. That we are all meaningless. That we
are
all trying to hide from each other what we fear.
No, this is not a scam. And sorry, I don't have the solution.
I guess we are the same.
In the dark we are alone, in the bright we skin and hide.
rednax(a)tm.net.my
http://www.asiapac.net/~rednax
"I have seen little angels turn bad
But that's just because they have grown
Likewise the problems I currently access
They are small matters full blown"
3
2
Anyone got a good IP spoofer that can spoof the whole domain? The only
shit I can find is those shitty ones that spoof the first part of the
IDENTD which is possible to do in mIRC if you use it. Oh yeah, it has to
be for Win95. Yes I know that no one likes win95 but I dont have a
choice....I'll tell about that later.
1
0
"Alexander.Kvache" <alexk(a)hcl.com> sent the new word:
>
>unsibscribe
to the list. I am pretty sure we have seen them all, now.
OBcrypto - are these spellings randomly generated?
JMR
1
0
17 Dec '03
At 04:45 PM 10/18/96 -0700, John Gilmore <gnu(a)toad.com> wrote:
>Note that this attack requires physical access to the DES chip, to
>stress it so it will fail. It works great against "tamper-proof"
>devices such as smart cards. It doesn't work against encryption
>happening at any distance from the attacker (e.g. across the network).
It's probably most useful for defeating attempts to force smart cards
on the public as the government's solution to Key Recovery
(e.g. Clipper 4 fails, so after the election they come out with Clipper 5
or the Anti-Terrorism Airplane Traveller's License Smartcard.)
# Thanks; Bill
# Bill Stewart, +1-415-442-2215 stewarts(a)ix.netcom.com
# You can get PGP outside the US at ftp.ox.ac.uk
Imagine if three million people voted for somebody they _knew_,
and the politicians had to count them all.
2
1
At 07:30 PM 10/19/95 -0500, "Robert J. Shueey" <rshueey(a)tcgcs.com> wrote:
>ok, not to drag this disscussion out, but apparently I am missing something.
What you're missing is that the IPG guy is a troll.
The reason there are contradictions is that he's making the stuff
up as he goes along. Maybe he's having a good time. Maybe he's a
tentacle of the spammer pretending to be D..V..
On the other hand, the POTP folks are serious. Wrong, but serious,
actually selling a product and trying to convince other people to
include it in their email systems.
# Thanks; Bill
# Bill Stewart, +1-415-442-2215 stewarts(a)ix.netcom.com
# You can get PGP outside the US at ftp.ox.ac.uk
Imagine if three million people voted for somebody they _knew_,
and the politicians had to count them all.
2
1
American Banker: Friday, November 22, 1996
MasterCard Raps Visa Security After Theft
By JEREMY QUITTNER
The theft of a personal computer with several hundred thousand credit
card
accounts stored in its memory has led MasterCard to suggest the security
procedures of rival Visa are inadequate. The computer, stolen from Visa's
San Mateo, Calif., data processing center early this month, contained
information transmitted from point of sale machines for 314,000 active
credit
card accounts -- from Visa, MasterCard, American Express, Discover, and
Citicorp's Diners Club.
Visa has offered to pay $20 per account, potentially $6.3 million, to
replace
the cards.
Although the five brands reacted quickly to the crime, and there has been
no
loss due to fraud, the incident shows how account information is
vulnerable to
fraud and theft from many directions.
Michael Stenger, special agent, financial crimes division for the U.S.
Secret
Service, said criminals will go after account information wherever they
can
find it.
"The computer is seen as a facilitator and a storage point," he said.
"The main
thing is (the thieves) need the information."
Account information from the different credit card networks is commonly
routed through MasterCard and Visa processing systems from point of sale
machines, and sent to the appropriate party.
"The question is, why was the information downloaded?" asked MasterCard
spokesman Sean Healy. "We don't do that type of downloading."
He said MasterCard stores point of sale information on cartridges in high
security locations in its St. Louis processing facility, where it would
be
"virtually impossible to replicate" the Visa theft.
However, David Melancon, a Visa International spokesman, contended,
"Any card company that processes transactions" downloads account
information.
Jerome Svigals, a smart-card and security consultant in Redwood City,
Calif., said Visa would have downloaded this information only if it was
working in the capacity of Vital Processing Services, its merchant
processing
arm.
He added the computer probably contained magnetic stripe information,
such
as account numbers, expiration dates, and encrypted verification codes.
"There is little or no protection against this problem," he said.
Visa said it may have been an inside job, although no one has been
arrested.
The thief or thieves were probably more interested in the computer
hardware
than the account information, Visa said.
"We have had rigorous plant security, but obviously not secure enough,"
Mr.
Melancon added.
Visa, which said the vast majority of affected accounts were its own,
said it
immediately contacted all the parties involved and recommended they get
in
touch with cardholders.
Mr. Healy said the stolen computer contained information on accounts at
500
of MasterCard's member banks.
"We are recommending they close the affected accounts and issue new
cards," Mr. Healy said. "We are monitoring authorizations very closely
and
have issued a worldwide security alert."
American Express, on the other hand, has chosen to monitor its own
accounts without informing cardholders. It would not specify how many of
its
accounts were involved.
"The accounts are being monitored for fraud, but we have not found any,"
said Gail Wasserman, an American Express spokeswoman.
Diners Club and Dean Witter, Discover & Co. said they were taking
measures to protect their cardholders.
American Banker: Friday, November 22, 1996
Bank Group Issues Guidelines for Protecting Consumer
Privacy
By Barbara A. Rehm
Retail bankers on Thursday unveiled a nine-point plan to safeguard
financial
information about their customers.
The Consumer Bankers Association is providing the privacy blueprint to
its
members, 900 financial institutions with more than $2.5 trillion in
assets.
"We are confident that these guidelines will enable our members to
continue
delivering top-quality service and choice while maintaining the trust of
consumers," said Pam Flaherty, Citibank senior vice president and a
member of trade group's board.
The guidelines, in the works for two years, are designed to help banks
maintain customer confidentiality standards even as new technologies
speed
information processing.
For example, under the plan, banks "will limit the use and collection of
information about our customers to what is necessary to administer our
business, provide superior service, and offer opportunities that we think
will
be of interest to them."
The blueprint also notes that banks will provide data about their
customers
only to "reputable information reporting agencies."
The Consumer Bankers issued the privacy guidelines to show the federal
government that the banking industry is policing itself and no new
regulations
are needed.
American Banker: Friday, November 22, 1996
Get On-Line Quickly or Get Left Behind
By JENNIFER KINGSON BLOOM and JEFFREY KUTLER
Almost 600 people paid a quick visit this week to a future in which most
consumers carry smart cards, do most of their banking and shopping on the
Internet, and rest assured that their financial institutions have taken
all
necessary steps to ensure payment security and personal privacy.
By now the bankers among the 600 have returned to a reality in which most
chief executive officers don't know much about personal computers, pay
more attention to commercial loan spreads and credit card profitability
than
to information technology, and still need convincing to pour a lot of
investment capital into creating the aforementioned future.
The vision of the possible appeared at American Banker's second annual
conference on financial services in cyberspace. After three days of
almost
boundless enthusiasm for electronic cash and virtual banking, these
concepts
didn't sound futuristic at all.
Stirring up a revival-meeting atmosphere, Mondex USA chairman Dudley
Nigg referred to Internet banking as "the Holy Grail." But no longer does
he
consider it beyond bankers' grasp. Giving the opening speech Monday, the
Wells Fargo Bank executive vice president decried the industry's past sin
of
"giving away the branch channel for free and charging for on-line service
...
How ludicrous!"
After Wells saw the light and dropped its fees for PC users, on-line
customers jumped from 20,000 in early 1995 to 270,000 today -- 110,000
of them via the Internet. Mr. Nigg expects two million Internet customers
in
five years.
It provides an unusual opening, he said, to "satisfy customer needs
(while) we
lower our costs ... That's the kind of economics that chairmen in our
industry
love to hear about, and is rare in banking. Rare is the channel where
costs
can be driven down."
Mr. Nigg, speaking the same day MasterCard announced its acquisition of
51% of Mondex International, a smart card program he fervently supports,
lived up to his keynote billing with the conference's most quotable
quote: "If
we don't get aboard this train early, we will miss it."
He said technology is advancing so quickly and decisively that bankers no
longer have the luxury of waiting for lower prices or more definitive
outcomes
before making a move.
"If we regard this as purely hype, we will forfeit this opportunity to
others
who are waiting in the wings," Mr. Nigg said. "We have traditionally been
slow to step up. In the past, second-movers had an opportunity to meet
the
train. Today, people are waiting for us to act. If we don't do so,
somebody
else will step in and take our place."
"Don't do nothing, waiting to see if Internet commerce is real," said
Verifone
Inc. vice president Roger Bertman, picking up the theme two days later
when
discussing bank-merchant relationships. "It is absolutely clear you will
miss an
opportunity and risk losing pieces of your merchant portfolios."
The Internet and personal financial management software like Intuit
Inc.'s
Quicken are "wedges driving financial services into the home," said Adam
Schoenfeld, vice president of publishing at Jupiter Communications in New
York.
Though many attempts at electronic financial services were "poorly
conceived
and executed," he said, banks are serving two million customers by PC,
and
more than three times that number express interest in the medium,
according
to a recent Jupiter-Find/SVP study.
Veterans of earlier, unsuccessful attempts at revolutionizing banking
behavior
like to bat around ideas on why the 1990s are different.
One obvious reason is the breakneck spread of personal computers into
consumers' homes. Huntington Bancshares senior vice president William
Randle, a conference co-chairman, cited an October survey that said 19
million U.S. households now use home computers for some aspect of
financial management.
He also showed a commercial that touted the home banking capabilities of
Packard Bell's products. "When manufacturers of computers start
advertising
banking as an application, times are moving fast," he concluded.
There were other ideas as well. Gaurang Desai, a vice president at
Montgomery Securities, said vendors and bankers are growing more
comfortable with one another and are working together more productively.
Henry Lichstein, a vice president and technology strategist at Citibank,
said
banks are learning how to market on-line services so they are attractive
to
consumers.
Pointing out that Citibank has offered home banking for a decade, he said
the
program began "in earnest" last year when the bank stopped charging for
it.
In 1996, Mr. Lichstein said, "the big change was the Internet."
And David Frankel, banking business manager at the Prodigy on-line
service,
recalled that when his company introduced on-line banking in 1988, it
fell flat.
Prodigy has spent the last eight months reconstructing its service for
the
Internet. "People are moving to the Internet directly at almost alarming
speed," Mr. Frankel said. "We have recognized the future of the Internet
and
the ultimate demise of proprietary on-line services."
Several speakers predicted that the introduction this year of television
sets
with Web browsers will jump-start home banking for the mass of consumers.
In the Jupiter Communications survey, 25% of households with personal
computers said they "would prefer to get their electronic financial
services
through the television," said Mr. Schoenfeld.
Mr. Lichstein defined the task at hand -- "the process of anticipating
change
and aligning oneself to it" -- as "finding the strategic groove."
Something is in a strategic groove, he said, when "if we do not step up
to the
challenge, someone else will." By that definition, Mr. Nigg was
describing
strategic grooves for the Internet and smart cards, particularly Mondex,
which can operate as both a real-world cash substitute and a
virtual-world
payment transmission device.
Mr. Lichstein put smart cards and consumer electronic banking in that
very
context. "The strategic groove in home banking," he said, "is in full
swing."
Critical or dissenting voices were pretty much drowned out. Charlotte
Wingfield, a KPMG Peat Marwick partner, said she got a respectful
reception to what she called the only presentation covering the biggest
mode
of banking distribution -- the branch.
Citing a consumer survey KPMG commissioned from Yankelovich Partners,
Ms. Wingfield concluded that "the branch's demise is greatly
exaggerated."
Her data indicated that even frequent PC users put "banking in person"
ahead
of software-based services on their list of preferences.
Agreeing with Ms. Wingfield, a member of the audience who works for a
technology company grumbled about the pro-virtual majority. "They make it
sound like everybody has to be on the Internet by next Tuesday, or
they're
toast. That just isn't the case."
Even a bank executive from the Northeast who is well versed in the
Internet
and intranets said, "I think it's all hype."
In one session that devolved into a small-scale cat fight among software
vendors, a Microsoft Corp. executive was trying to take the high road:
Other
purveyors of personal financial management software divulged the number
of
users they had doing on-line banking, but he wasn't going to play the
numbers
game.
A representative of Intuit said 400,000 people were banking on-line
through
Quicken and BankNow. The chief executive of Meca Software said he had
200,000 active users.
When Microsoft's turn came, Richard Bray, a product manager, kept
insisting that 10% of Microsoft Money users were doing on-line banking.
When pressed for specific numbers, he would go no further.
Unluckily for Mr. Bray, he was also scheduled to speak again later in the
day
about the Microsoft Network for the Internet. It was in that speech that
he
casually said: "Two and a half million people use Microsoft Money."
And 10% of 2.5 million would be ... William N. Melton, founder and
president of Cybercash Inc., was torn within himself. He took a break
from
the American Banker conference to fly to the giant Comdex computer trade
show in Las Vegas and returned with what he termed a "manic-depressive
problem."
When he first arrived in Scottsdale, he became "manic" when he learned
that
the bankers there had apparently gotten religion on the subject of the
Internet.
"We've been trying to talk to bankers for a long time, and said, 'The
Internet
is really here,"' he said. "I didn't think they were really getting it."
After jetting off to Comdex, though, he became "depressed" that while the
250,000 people attending the show were "all doing nothing but thinking
about
the Internet," they didn't seem to be moving quickly enough toward
on-line
commerce.
"We've been working on SET (the Secure Electronic Transactions protocol)
for one to one and a half years, and hopefully within six months we'll
have
interoperability tests," Mr. Melton said with some disdain.
After returning to Arizona, Mr. Melton swung back to manic mode. Hearing
details about MasterCard's buy into Mondex persuaded him that "maybe it's
going to happen."
Mr. Melton was emphatic about what was needed to help make "it" happen:
he called on banks to "unilaterally issue digital certificates" to get
customers
accustomed to on-line commerce and comfortable with evolving privacy and
security measures.
Mr. Melton and Mr. Bertman, general manager of the Internet commerce
division at Verifone (another company Mr. Melton founded), acknowledged
some other impediments or potential obstacles.
"By 2000, the privacy issue will have really hit," Mr. Melton predicted.
He
said the negative consequences of such an explosive political issue could
be
mitigated by banks' convincing the public they have addressed it. But he
warned of "a huge public debate."
Mr. Bertman said the industry must help consumers and merchants make
sense of a dizzying array of payment methods and options. Verifone and
Cybercash, among others, have proposed "virtual wallets" as a solution.
"Technologists tend to oversimplify the payments world," he said, "but
there
are some very complex issues" that financial institutions are best placed
to
resolve.
Mr. Bertman added that while most discussions have focused on the on-
line
consumer, bank-merchant relationships are at least as critical and have
been
"underestimated and under-understood."
"There is a question of how many banks do you need on the Internet," Mr.
Melton said. "This is not a polite question, but it's going to become
very
competitive - more so than in the physical world where you are protected
by
the walls of geography."
Mr. Melton was ready to declare victory on the security issue, saying,
"It's
essentially done."
Given the availability of data encryption techniques and specifications
like
SET, which is being developed by MasterCard and Visa, he said: "Tell your
customers, 'Don't worry. We'll take care of it'."
Mr. Bertman said the SET development process will take well into next
year,
but the card industry should move ahead with Internet payments." Sholom
Rosen, a vice president at Citibank who has invented a computer-
to-computer electronic money system, raised a red flag.
He said electronic currencies like those being promoted for the Internet
--
Citibank's is not among them -- raise security issues different from
those in
conventional commerce, and they are not fully addressed by "strong
encryption and protocols."
For example, Mr. Rosen said, counterfeit losses are conventionally borne
by
the party who is discovered passing fake currency. In on-line commerce,
the
issuer of money -- likely a bank -- is the victim, with consequences for
solvency and systemic risk that Mr. Rosen said haven't been thought
through.
Mr. Rosen stated in an interview that Mr. Melton and others are in an
"entrepreneurial mode" and understandably eager to embrace exciting new
things.
"Comdex is fine, but banks are in the business of having to manage
risks,"
Mr. Rosen said.
ABA Banking Journal: November, 1996
Are You "Toast"?
By William W. Streeter
Has anyone walked up to you recently and said, "You're toast"? As you
might surmise, the question has nothing to do with sun or food. It has to
do
with history, as in, "You're history, pal."
And that's how author Don Tapscott meant it when he used the expression
in
his presentation at the ABA Annual Convention last month.
He was speaking about the digital revolution, and with the single word
"toast," he likely captured the collective angst of most people in the
room.
As author of the best-selling book, The Digital Economy, Tapscott is a
prophet of the new order resulting from the digitizing of information.
Like
many of his ilk, his presentation was both mesmerizing and unsettling. He
spoke of the likely disappearance of entire industries under the
onslaught of
the Internet, specifically referencing travel agents and food
wholesalers.
He didn't foretell that fate for banking, but he did speak of the
"disintermediation" of the middleman.
"If you're in the middleman business, start looking for a job," he said.
It shouldn't take long to realize that banking falls under that heading.
Consider
that traditional banking is deposit intermediation, while the more recent
additions to the business have largely been brokerage. Sounds like a
"middleman" business to us.
Tapscott urged bankers to "reintermediate." We haven't a clue what that
means, but he did cite examples of several banks that have embraced the
Internet -- Security First Network Bank being one (look for an update on
it
next month); Wells Fargo and The Bank of Montreal being two others.
There's no denying that certain business have been displaced by
electronics.
The advent of desktop publishing software, for example, radically altered
the
"pre-press" and typesetting business that thrived pretty much since
Gutenberg. Typesetting in particular was wiped out by computers in the
space of about ten years. The function of putting words into type didn't
disappear, it was simply transferred to publications' staffs, at a
considerable
savings.
Those publications themselves face a challenge with the emergence of the
Internet as a radically different means of disseminating information.
Is banking similarly challenged? The answer without a doubt is "yes."
Will the
industry disappear like the typesetters? There are two considerations in
answering that question. First, the typesetting business disappeared
because
electronics gave publishers greater flexibility at less cost. The same
case is
made by proponents of banking via the Internet, but it's not clear yet
whether
a majority of people and businesses are ready to do banking that way.
Second, "banking" and "industry" are labels. The functions performed
under
those labels will of course continue as long as there is money, or more
broadly, exchange of value.
If by being "digitized" a product or service or process becomes more
convenient, more flexible, or less expensive, the marketplace will
embrace it.
And it will probably do so pretty quickly.
None of this says that there won't be a need for people to meet with
people.
Maybe many "face-to-face" meetings will occur by high-quality video
connection. But all of them won't. There will still be a need to be
reassured
about something in person; to shake hands on a deal; or to look someone
in
the eye -- a live eye.
As a proxy for this, consider that e-mail hasn't eliminated the need to
speak
by phone, any more than telephones eliminated the need to write or to see
someone in person.
Changes in fundamental technology have always caused business casualties
-- as with the proverbial buggy whip example.
Part of top management's job is to stay abreast of changing technology,
and
to hire and train people who can communicate in, and deal with, whatever
medium is appropriate. The difference now is that the change to a digital
age
will bring more far-reaching changes than anything seen recently, and is
occurring at dizzying speed.
For sure, money isn't likely to go away soon, and neither, therefore, is
financial services. That should ease some of the angst you may feel under
the
relentless barrage of "The Digital Age." But don't get comfortable
either, or
you will be toast.
Retail Delivery Systems News: November 22, 1996
Mondex Deal Changes MasterCard Strategy
Expect some turmoil in the smart card market as MasterCard International,
of New York, readjusts its strategy in the wake of buying a majority
interest
in Mondex, of London, a bank partnership formed to pilot smart cards in
England.
The long-time rumored acquisition represents one of the largest
investments
of a U.S. company in smart card technology.
Estimates are that MasterCard paid between $100 million and $150 million
for the majority interest.
MasterCard will adopt Mondex's technology as its strategic chip platform,
the companies say.
This raises questions for the future of pilots, such as the one planned
in New
York City's West Side by Citibank and Chase Manhattan and for the
validity of vendor hardware and software created to work with MasterCash,
analysts say. The New York pilot, which is meant to prove
interoperability of
the MasterCard and Visa systems, already has been delayed until the
second
quarter of 1997.
Additionally, MasterCard has lost several of its key officers in the
MasterCash division, raising questions about who is leading the venture,
RDSN has learned.
"A number of companies would like to see a crystallization of
MasterCard's
strategy with smart cards," says Dave Lott, an analyst with Dove
Associates
in Atlanta. "The deal raises a lot of questions in terms of what are they
going
to do with the product (MasterCash) that they've developed up to this
time."
Washington Post: Sunday, November 24, 1996
The Uncertain Value of 'Smart Cards'
By Jane Bryant Quinn
The next piece of plastic the banks think you ought to keep in your
wallet is a
"smart card." These cards come in several varieties and most aren't ready
for
mass distribution. But pilot projects are forging ahead in Atlanta and
New
York City early next year, and in Canada and several countries abroad.
There's no obvious consumer need for smart cards today. But the bankers
believe that you're going to love them anyway. You may even be mailed one
and urged to try it.
Smart card promoters make the assumption that you hate to carry cash. You
hate fishing for bills and coins to buy a newspaper or a soda. You'd put
down plastic, instead.
This plastic card has money on it, embedded in a computer chip. A $ 20
card, for example, will give you $ 20 in spending power.
If you buy a 75-cent newspaper, the seller will put your card in a
special
terminal and drain off 75 cents. No identification or signature is
required.
You now have a card with $ 19.25 left on it. After spending $ 1 on a
soda,
the value of your card goes down to $ 18.25. If you forget the amount,
you
can check it with a little portable card reader. Some readers also might
list
the last five things you bought.
Don't confuse a smart card with a debit card. When you pay by debit card,
money is moved automatically from your bank account into the merchant's
bank account. With a smart card, however, you first move money from your
bank account onto the card's computer chip. When you buy something, the
money moves from your card to the merchant's terminal and then,
electronically, to the merchant's bank.
If every merchant, street vendor, taxi driver and bus accepted smart
cards,
you wouldn't have to carry cash. To some, that would be a huge
convenience; to others, it's a shrug. But as long as some merchants took
smart cards and others didn't, you'd have to carry both.
Smart cards come in three varieties, some of them more flexible than
others:
* A prepaid, disposable single-purpose card. Telephone cards are a good
example. You pay $ 10 or $ 20 for a card, dial an 800-number, give the
number of your card and then make your telephone call. Minute by minute,
the cost of the call is deducted from the value of the card. When you've
spent
all the money on the card, you throw it out.
* A prepaid, disposable bank card. You buy the card at a bank and can use
it at any store that has a terminal.
* A reloadable card. When your money runs out, you can take it to a bank,
an automated teller machine or a special kiosk and load it up again.
Visa,
MasterCard, Citibank and the Chase Manhattan bank will jointly test a
reloadable card in a section of New York City next year. A reloadable
card
also could serve as your credit card, debit card or ATM card.
What's in it for the banks? Eventually (although not at first), the banks
probably would charge you for the card. There might be a fee when you
used
an ATM to load it up. The merchant also would pay a fee, in return for
getting what is presumably a more secure transaction.
What's in it for consumers? A very little bit of convenience. Putting
down a
card is a tad quicker than fishing out cash. You always have the
equivalent of
exact change. You wouldn't have to count your change, but you'd have to
use the card reader to be sure the merchant's terminal deducted the right
amount. You may or may not pay more for the card than it costs to get
cash
from an ATM.
For a while, the smart cards probably won't have any more than $ 100 on
them and the limit might be lower. So they're strictly for walking-around
money. You'd still need your credit card, debit card or checkbook for
more
serious shopping.
If the card malfunctions -- say, it registers $ 14 when you're sure you
were
carrying $ 36 -- a bank can check the balance on the computer chip, says
Ron Braco, a senior vice president at Chase Manhattan. But if you lose
the
card, it's just like losing cash. You're out the money.
Promoters of smart cards promise a lot of national and international uses
that
aren't yet anywhere in sight. I'll probably wait for them. Banks have a
sales
job to do on people like me who don't find it a nuisance to carry cash.
Forbes: December 2, 1996
Banks are pushing new ATM cards that doubleas a Visa or a MasterCard.
Avoid 'em.
Carte Blanche For Crooks
By Alexandra Alger
Chances are that yet another chunk of unsolicited plastic has popped up
in
your mailbox. It is not just another credit card. It's a combination new
ATM
card and charge card. You can use it to withdraw cash from automated
teller
machines, as you do with your current ATM card. Or you can use it to
charge purchases, without having to use your PIN (personal identification
number). "It's as convenient as a credit card, but it's not credit! The
amount
of your purchase is immediately deducted from the balance in your
checking
account," says the brochure sent out by one major bank. And therein lies
the
danger--it's a debit card. We don't like it for three reasons:
* It could give a thief carte blanche to your checking account. In case
of
fraudulent use of your debit card, you are the one who is instantly
out-of-pocket, not the bank. You may have to fight the bank to recover
your
money, and you could lose it completely if you don't report the loss
right
away. Meanwhile, your bank balance and credit line could be depleted, and
your checks could be bouncing all over town.
* You lose the credit float, of 30 days or so, that you get with a
zero-balance
credit card.
* You lose the option of withholding payments--important leverage in case
of
disputed charges.
Banks are flooding the mails with these new cards. Visa has launched a
multimillion-dollar national TV campaign to promote its debit cards,
starring
football superstar Deion Sanders. Some 4,000 U.S. banks, S&Ls and credit
unions are issuing MasterCard- and Visa-affiliated debit cards--double
the
number of a year ago. Most of the nation's biggest banks have already
joined
the party, including California's Bank of America and New York's Chase
Manhattan Corp. (to its new Chemical Bank customers). Citibank is
planning its blitz next year.
For banks, what's not to like? Merchants pay card issuers an
"interchange"
fee--typically 1% to 2% of the transaction value. Some banks even charge
customers $1 to $1.50 a month just to have the card.
Debit cards also help wean bank customers from costly check-writing. It
costs banks $1.10 or so to process every check, but only 27 cents to
handle
a debit card transaction, says Edward Neumann, director of Dove
Associates, a bank consulting firm in Washington, D.C.
Bankers insist that the cards are good for customers, too. "The key is
convenience--that's what we're selling," says John Russell, a spokesman
for
Banc One in Columbus, Ohio, the first bank to offer a debit card and now
the largest issuer of them (over 4 million).
But we think this convenience comes at too high a risk. Some debit- card
crooks are subtle. They'll use swiped debit cards occasionally, charging
up
relatively small amounts. As long as the account holders overlook the
charges
on their bank statements, the party continues. The thief has a kind of
annuity.
Roy Funderburk Jr. learned about this the hard way. The 53-year-old mail
carrier from Alexandria, Va. was going over his bank statement when he
noticed two debit-card charges in one day at an Exxon station he
occasionally used in Washington, D.C. That sent him back to statements
for
previous months. What he found were $1,000 in bogus gas station charges
made over a nine-month period. No charge was more than $20. He hadn't
lost his Visa debit card, so was baffled about the misuse.
Funderburk's branch manager at American Security Bank (now
NationsBank) told him not to worry, he would be reimbursed for his
losses.
But a month later Funderburk got word that he'd only be recompensed for
the fraudulent charges made within the previous 60 days-- $247. He was
out
$761. Funderburk was furious. He went to the Washington Police
Department, the Secret Service--even the FBI. The latter two told him
they
only looked into cases involving at least $5,000.
Finally, on the advice of a lawyer, he took the bank to small-claims
court. He
struck out there, too; the judge shook his head and told Funderburk the
bank
didn't owe him anything under federal bank rules, and there was nothing
he
could do.
The story has a happy ending. Out of the blue, an American Security
lawyer
called Funderburk about settling. Funderburk said he just wanted his
money
back, without interest. Fine, the attorney said. Within hours the money
was
back in his checking account. But what an ordeal!
How had the thief pulled off the thefts? All he needed to get started was
the
number on Funderburk's debit card, perhaps from a discarded receipt. A
phony card could be made, using that number.
Still, Funderburk was lucky. Banks will normally assume liability for
fraudulent use only if you notify them within two days after you miss
your
card. In that case your loss is limited to $50--often, you won't be
charged at
all. But wait any longer, and you could be liable for as much as $500 of
your
own checking account losses. If you fail to report the fraud within 60
days,
the bank doesn't have to give you a cent.
Your chances of getting hit are uncomfortably high. Last year Visa and
MasterCard issuers shouldered $19 million in fraud-related losses on
their
debit cards, says the Nilson Report, an industry newsletter in Oxnard,
Calif.
PIN-related ATM fraud accounts for $100 million to $200 million in annual
losses.
That is small potatoes compared with the estimated $3 billion in annual
credit-card fraud losses (FORBES, Aug. 26). But, says John Wisniewski, a
postal inspector in Pittsburgh:"The bad guys are just starting to figure
out how
to misuse them."
One of the more ingenious ATM scams involved a bogus telephone. At an
ATM in Miami, Fla. crooks put plastic sleeves into the card slots. When
customers saw their cards were swallowed by the machine, they picked up
the telephone provided to dial the posted customer service number.
But the phone was provided by the thieves, and the posted number put
customers in touch with a thief, not a bank employee. The thief then
asked
customers for their PIN as identification and promised that replacement
cards
would be mailed out in a matter of days.
The crooks then plucked out the stuck ATM cards with tweezers and were
off to the races.
Our advice is to avoid the ATM-debit card. When your ATM card expires,
request a simple replacement instead of the new combo card you'll be
mailed. In our view, the risks of the combo far outweigh the potential
rewards.
1
0
red wrote:
> Why? Date: 20th October 1996.
> The purpose of life,... is not to be found. I have been pursuing
> this thought and question to many of the people I have met in the past
> few weeks. Sad enough to report that I have found no answers or clues
> that if anyone ever know what it is or could be. One thing for sure is
> material and physical objects are close to replacing the purpose, the
> real purpose if there is one.
[remainder deleted]
You could ask yourself, as a technical matter of some importance, just
how you came to be thinking about purpose, or about it in the way that
you think about it, i.e., was the thought developed in you through
bombardment from "philosophical" sources, or did you actually develop it
independently? Try to track that down and deconstruct it, and it will
help in getting a handle on the issues you want to look at.
On the other hand, you could try what I call the Consciousness
Experiment. Intelligent persons have argued (contrary to the notions of
certain religious philosophies and possibly even quantum physicists)
that there is no *free will*, since all *things* are fully predictable,
given sufficient detachment from the universe being studied, and
sufficient resources to analyze the motions of all particles, waves,
and/or other constructs.
In the Consciousness Experiment, you get up every day and attempt to do
something *good* for which you have absolutely no motivation, kinda like
a "Mother Teresa act" or whatever. Use your imagination. The goal is
to separate your "purely altruistic" (for sake of argument, whether this
is real or not) acts from your base acts, i.e., eating, sleeping, and
even loving (in the sense of attachment to particular persons as opposed
to living beings or "earth things" as a whole).
If you can stay focused on the goal, to "prove" that you truly are a
sentient being and not just a living-flesh motivation-driven automaton,
then eventually you will have an answer of sorts to your question, but
with your mind in a different frame of reference or perspective, I
believe you'll be somewhat amused at your original posting on this
topic, assuming you keep a copy around.
1
0
>
> IPG Sales writes:
> > Some of you have sardonically written to say "Nihil Est
> > Demonstrandum," N.E.D. because an OTP must be derived from a
> > hardware source, that is, it must be a pure random sequence
> > of limitless entropy. Accordingly, they unbashfully assert
> > that an OTP generated by a computer program is not possible.
> >
> > How do they know that? Does the Bible tell them so, or the
> > Koran, or do they get it from the Torah? Why not cite the
> > source of their certainty instead of advancing an unsupported
> > proposition.
>
> See Claude Shannon's papers on information theory. [Available as: C.E.
> Shannon, Collected Papers: Claude Elmwood Shannon, N.J.A. Sloane and
> A.D. Wyner, eds., New York: IEEE Press, 1993.]
>
> Shannon invented information theory in 1948 and 1949. Part of his
> papers discuss the information theory of cryptosystems. He
> mathematically proved that only a O.T.P.. using non-reused physically
> random numbers could provide what he termed "perfect secrecy". I
> accept mathematical proofs above the Koran or the Bible. (The Torah is
> a subset of the Bible.)
As in so many other cases, you are so F.O.S. that it is
unbelievable. Your eminence pontificating about it does make
it true. Furthermore, Shannon certainly did not prove that
physically random numbers are required to provide what he termed "perfect
security." I believe that closer reading and interpretation will reveal
that what he was saying was that any mathematical series other than truly
random numbers can theoretically be reconstructed by some means, including
brute force, should that be required. Obviously that is true.
I do not disagree with the fact that brute force can be used to
attack the algorithm that I have advanced. It you try all of the
possible OTPs, PRNG encryptor streams, against the ciphertext, then only
a limited few and maybe only one meaningful plain text can be obtained.
There is absolutely no dispute about that. Accordingly, Shannon
is quite correct in saying that it is not "perfect." It is not perfect in
a mathematical sense, and in that limited sense only, you are correct.
However to try all possibilities, is mathematically impossible - thus the
algorithm must be attacked analytically - as EVEN you, or anyone else,
will be able to clearly see, if you examine the algorithm, it cannot be
attacked analytically.
My algorithm most certainly does NOT produce a theoretical pure Random
Number Stream, accordingly it is a PRNG, but it most certainly does
produce an OTP that meets each and every requirement of such, other
than some theoretical definition that you seek to impose on it by your
dogmatic words. You do not have to take my word for it, the FULL
ALGORITHM, which has never before been published, is set out on our web
site.
There is no mathematical proof that my PRNG streams are not an OTP -
because they are OTPs. There are 156.8816 megabytes of raw encryptor
stream data at our site. They constitute 10 OTPs, all using the same key,
only the message numbers vary.but with different message numbers only.
> > I do not mean to be rude,
>
> You are anyway.
>
You are so vane, so crass, so dogmatic, so blinded by your opinions,
that you obviously look at yourself in the mirror wheneever given the
opportunity. You do niot know what the hell you are constantly
pontificating about. talking aboutand including the one under discussion
herein. Why not show everyone your prowess by telling us what the key and
the As, Bs, and Cs, are they were used to generate the 156.8816 megabytes
referred to above. Of course, you cannot, so you bray like an ass to cover
up your crypto impotence.
> > but excuse me, what
> > scientific proof can they offer for that immovable avowal?
>
> See above.
See above
>
> > There is no scientific proof whatsoever, none at all,
>
> See above.
See above
>
> > except
> > for the words and their steadfast, and maybe self serving,
> > postulate.
>
> See avove.
See above and below
>
> > Accordingly, obviously it is they, not us, who are
> > the ones that have "Nihil Est Demonstrandum," in this matter.
>
> See above.
See above
>
> > There is not one scintilla of sustainable evidence to support
> > such a doctrine.
>
> See above.
See above and below.
>
> > While the vast majority of people knowledgeable about
> > cryptography have not heretofore believed that it is possible
> > for software to produce an OTP,
>
> It is not possible.
It is absolutely possible, Q.E.D.
>
> The information content, or entropy, of the key stream is necessarily
> no larger than its keyspace. That is, if you have a software
> pseudo-random number generator using an N bit seed, the entropy of the
> keyspace is necessarily never greater than N. This is mathematically
> certain -- no amount of prayer on your part can change that.
>
> > that does not make it a
> > scientific fact,
More of your meaningless B.S. - Obviously you wrote your reply before
you read my entire message.
>
> Sorry, its even better -- a MATHEMATICAL fact.
>
You saying it, like a lot of other supercilious crap that oozes out of
you brain as "write bites," does not make it so. All kinds of crap is
running loose up there, you need to get it under control someway.
It is absolutely not perfect in the Shannon sense, but it does not have to
be theoretically perfect to fulfill the requirement of being an OTP. You
definition of an OTP, or a OTP as you mistakenly refer to it, is an
extraneous mathematical definition that people have mistakenly
extrapolated from Shannon.
> > In support of their position, some have pointed out that John
> > von Neumann, to paraphrase, stated that ARITHMETIC cannot
> > produce random numbers,
>
> von Neumann meant any deterministic algorithm, actually.
>
There you go again, pulling things out of you crazy hat, head, running
off at the brain again, stating a falsehood and hoping that people will
overlook it. I assume that you held a seance with von Neumann and he told
you that from the great beyond, since that is clearly not what he said. A
careful reading of von Neumann does not reveal that he said one thing and
meant another. He used the word ARITHMETIC, if he meant something else he
world have said so. Furthermore, he was referring random numbers, and to
repeat emphatically, my algorithm is a PRNG, but it also happens to be
an OTP, as we can prove. Q.E.D.
> > We stipulate the obvious fact that the encryptor stream
> > generated by EUREKA is a PRNG stream, though we do consider
> > it gross denigration to castigate it as ONLY a PRNG stream.
>
> If it is a PRNG, you do not have a One Time Pad, period. What you have
> is a stream cipher.
>
It is a stream cipher, but it is also an OTP, just as a hardware sourced
RNG is a stream cipher that is also an OTP.
>
> Furthermore, past examination has shown you have a POOR stream cipher.
>
Did you see the movie, Dumb and Dumber - you are obviously getting dumber
and dumber and dumber - would I have come back to you 5 months later with
the same thing - you are obviously brain dead - as I have stated on
numerous occasions, the previous proffer was only a part of the overall
algorithm, to solicit help from some of the cypherpunks, which I did get.
The so
called breaking with "Known Plain Text," was an absolute farce, it
would have applied to only one message where it could be applied, if at
all - it did not apply to the whole system, each OTP was, and is
completely different - but that is beside the point, we did make some
changes to negate other possible attacks, but those were modest changes.
Any one that looks at the algorithm, which obviously, as a self proclaimed
crypto Diety, you have not deign to do, can determine that it is in now
way what you have looked at before.
> > It is a PRNG issue that also happens to be an extremely well
> > behaved OTP sequence, with limited but ample entropy, as well.
>
> If the entropy is limited, you do not have a One Time Pad, period, end
> of discussion, its over.
>
You say that Shannon, or you, or someone can prove that
mathematically, so let's see someone do it. 156.8816 megabytes of raw
encryptor stream output should be enough to work with - if you need more,
I can provide same. I agree that theoretically it can be broken by
brute force but that is patently impossible as you can quickly discern if
you examine the algorithm and try it, instead of salivating your
mouth off with baseless blabber. Obviously, my algorithm does not produce
a pure random stream. I agree with Shannon that it is not "perfect,"
but it most certainly is perfect enough to meet any and all practical
requirements, now and forever.
> > It meets each and every criteria rationally established for an
> > OTP in all reasonable aspects.
>
> Set by WHOM? By you? Your criteria bear no resemblance to those
> accepted in general. Are you one of those people who sells someone a
> loaf of bread and says "this is an automobile, by every criterion I
> have set for automobiles"?
>
There you go again, strutting about and spreading your pretentious turkey
droppings, manure, all over the place.
As you know, I headed the OTP group at NSA, and while there I conceived and
implemented, under the direction of Abraham Sinkov, Dottie Bloome, Leon
O'mera and William J. Cherry, LONE STAR, the Library of ONe time pad
Encryption Statistical Analysis Routines. I was responsible for the
generation and computer analysis of OTPs at NSA. I have worked on
thousands of OTPs, both in the generation of, and comprehensive analysis
of same, including looking for repetitive usage of the same OTP, including
direct as well as nth degree derivatives, over the last 40 years, at NSA
and at Mauchly-Wood. I make no claim that I am the world's greatest OTP
authority, or even an authority on them like you obviously THINK you are,
but I think that I have more than a little knowledge about the subject of
OTPs.
That brings up something that utterly fascinates me. Which is your
frequent oblique writings about VERONA, or is it VENONA, or maybe it is
VERONICA, or maybe even VERONIKA - anyway you know what I mean. Would you
be so kind as to enlighten me, us, about that subject - I would like to
finally find out what really happened from an authoritative source. How
were we able to break some of those messages. Please help me, us, out with
details instead of blabber.
For those who have not seen my resume', it together with dozens and
dozens of references, many of whom are well known, and some of whom you
may know, is posted on our web site, but obviously that does not prove
anything, except to provide a point of reference.
The point is that we have disclosed the complete algorithm, for the first
time at the web site, so let's see someone provide us with the key or the
ABCs. Our server is downloading an enormous number of the
algorithms/data/statistical tests, over 1,000 so far, so we assume
someone is testing it and evaluating it.
And for you to claim that my contention is analogous to comparing bread
to an automobile, petty nonsense and mindless hyperbole.
> > Think about that simple supposition for a moment. What do we
> > mean by an OTP?
>
> Something different from what everyone else means, so it makes no
> difference.
Obviously something different from what YOU, and most others,
mistakenly think it means. It is not some esoteric, theoretical
mathematical meaning that has no relation to our real world. It is a tool
to encrypt and decrypt messages with, it is not a mathematical formula. If
you say that a random number sequence is not generated, I agree. If
however, you go on and add that, "thus by definition it is not an OTP,"
then that is patently and absolutely a false statement, though subscribed
to by most of the cryptography community. You are a mix-master
stirring up cryptography and IT, and you simply cannot homogenize
them into a fully blended mix.
I assert that an OTP is a tool used for encryption which by definition,
can never be used again, and which consists of a sequence of bits which
can not be derived by any POSSIBLE, not theoretical but POSSIBLE, means.
Granted, our stream could theoretically be derived by trying all of the
possible 10^34322 keys/table values, but that is theory, it is absolutely
clear that there is no way to try all the possibilities, or even the first
800 bits of an encryptor stream. Any relatively informed mathematician
can quickly discern that there is no analytical attack that can be made
against the stream, it is that simple, as readers/evaluators will find.
If the only method of cracking the system is by brute force, and that is
impossible, then it is absolutely an OTP for encryption and decryption
purposes, which is its purpose - it is not something to define in IT
writings. Our algorithm is absolutely not perfect in the theoretical
sense but it is PERFECT as far as the ability to determine the underlying
plain text is concern.
>
> > Not only that, but you can prove it to yourself, Q.E.D. We
> > maintain that it is discernible to any knowledgeable person
> > who probes the algorithm, that the only analytical tack that
> > can be mounted against EUREKA is brute force and that is
> > patently impossible.. One of your Cpunk colleagues says he
> > uses Triple DES, 168 bits, and he does not believe that it
> > can be brute forced - I agree, 3-DES, 10^50+ possibilities,
> > cannot be brute forced now, or in the foreseeable future -
> > then what about the EUREKA's 10^34322 possibilities,
> > 10^34271+ greater than 3-DES? No way, not now, not ever.
> > Furthermore, EUREKA is an order, or more, magnitude faster
> > than triple DES, easier to use, much more secure, etal.
>
> I believe that we have already established that your cipher is easy to
> crack, so your claims that it is hard to crack really don't matter.
>
> Perry
>
To repeat, we have made some a changes, and for the first time disclosed,
detailed, the FULL ALGORITHM at great length at our web site. The reason
that you do not want to argue that is obviously because you are absolutely
impotent in that regard and you are unable to dispute facts, so you
blindly conjure up some witches brew of words and think that people will
never know the difference. To paraphrase John Dean, the truth will always
come out and your ass braying will never stop that truth.
Don Wood,
1
0