Crisis Overload (re Electronic Racketeering)
Folks, I'm not going to exhort you to fight this latest travesty, to send angry letters to your senators and representatives. Every couple of months there's been a new legislative attack on what were once basic American freedoms. (Sorry to focus on America. I'm sure you folks in the liberty-loving paradises of, say, Germany, are gloating over our hand-wringing.) We're losing the war. We can send in donations to the NRA and EFF, offer our support to the ACLU and EPIC, but the tide just keeps rolling in, washing away our efforts. The full-time lawmakers in D.C. can proliferate new repressive laws much faster than we can fight them. Our focus on this list has been on crypto, and crypto is finally coming under the massive assault we knew would come from the earliest rumblings several years ago about "key escrow." Clipper was the warning shot, the current "War on the Internet" (fed by scare stories and hysteria) is part of the propaganda war, and now this bipartisan bill to expand the RICO Act to include any non-GAK implementation of crypto is the nail in the coffin. No wonder Stu Baker and Ron Lee were so smug at the last CFP. Ordinary lobbying is probably a lost cause. The EFF tried to "work with" the government (Administration, Congress) on the Digital Telephony Bill, and got rolled (in the opinion of many, even in the governing circles of EFF). This latest assault is probably unstoppable. The co-sponsorship by Sen. Leahy, once seen as an ally of the EFF (recall the attempts to get the Leahy alternative to Exon adopted), and the enthusiastic support of Republicans, Democrats, and the intelligence community means that GAK is coming. Oh, and the use of RICO and "conspiracy" in such a central way fulfills Whit Diffie's prediction of a few years ago that the main way crypto will be controlled is through such laws, by spreading fear, uncertainty, and doubt amongst users and corporations. Make the corporations so paranoid that they'll crack down on employees, adopt GAK methods, and freeze out the "street corner user" of crypto. (If the only users of PGP and other non-GAK tools are fringe groups and underground communities, then the main goals will have been achieved. The public use of PGP will have been squelched, the public use of anonymous cash will have been suppressed, and the social control goals will have been achieved. ) I think it's time to abandon all lobbying efforts...they don't appear to be working, and the government is proliferating new laws faster than we can fight them. The only hope is to more rapidly deploy crypto, to reach the "point of no return." Optimistically, we may already be there (the views expressed by many of us). Pessimistically, the application of RICO laws and civil forfeiture could put any of us who advocate crypto use and evasion of the new laws into a precarious position. This is enough to say for now. Suffice it to say I view the latest Grassley proposed legislation to be the culmination of the past several years worth of anti-liberty legislation. A much bigger threat than Clipper. In fact, it's what many of us saw implicit in Clipper. --Tim May .......................................................................... Timothy C. May | Crypto Anarchy: encryption, digital money, tcmay@sensemedia.net | anonymous networks, digital pseudonyms, zero 408-728-0152 | knowledge, reputations, information markets, Corralitos, CA | black markets, collapse of governments. Higher Power: 2^756839 | Public Key: PGP and MailSafe available. "National borders are just speed bumps on the information superhighway."
One motivation behind SSH is trying to make it a de-facto standard replacement for rlogin and rsh. That would make it very hard to replace. It provides important benefits in authentication and protection against intruders - and as a side effect it provides hard to break encryption for anyone. Plus, it was created and is primarily distributed *outside* the United States, in a country where none of the algorithms are patented. It can thus be openly available for anyone, and is not limited by US export restrictions. It currently includes two algorithms that I know to be patented: RSA and IDEA. IDEA can be eliminated from it without breaking compability if it turns out necessary (and, several sources say that non-commercial use of IDEA is permitted). RSA is not patented anywhere but in the US, and there it may be possible for most people to get away by using RSAREF. There is more information at http://www.cs.hut.fi/ssh. The RFC describes the protocol. The current list of distribution sites includes: ftp.funet.fi:/pub/unix/security ftp.unit.no:/pub/unix/security ftp.net.ohio-state.edu:/pub/security/ssh ftp.kiae.su:/unix/crypto ftp.cs.hut.fi/pub/ssh More sites are welcome. Tatu Ylonen <ylo@cs.hut.fi>
Date: Fri, 14 Jul 1995 01:15:04 +0300 From: Tatu Ylonen <ylo@cs.hut.fi> to break encryption for anyone. Plus, it was created and is primarily distributed *outside* the United States, in a country where none of the algorithms are patented. It can thus be openly available for Well, I think it's nice that people outside the U.S. will have access to encryption; it appears, however, that those of us in the U.S. writing such software may end up having to forego payment and credit, until Blacknet is very strong... Phil
On Thu, 13 Jul 1995, Timothy C. May wrote:
I think it's time to abandon all lobbying efforts...they don't appear to be working, and the government is proliferating new laws faster than we can fight them.
The only hope is to more rapidly deploy crypto, to reach the "point of no return." Optimistically, we may already be there (the views expressed by many of us). Pessimistically, the application of RICO laws and civil forfeiture could put any of us who advocate crypto use and evasion of the new laws into a precarious position.
Unfortunately, a system of social engineering needs to be adopted to get massive use of cryptography started. This means, and I advocated this from the day I entered this forum, that programs such as PGP need to be redesigned so that the a user friendly . . . so user friendly that any Joe Moron can figure out not only how to use them, but also how it helps them and how it is "good" for them. This means that we need simplified key management easy enough for the point-and-click masses to utilize. This means that common mailing programs, From Elm and Pine to AOLs and Computer$erve's mailers need to have TRANSPARENT signing of mail messages and near-transparent encryption of messages. This means that we need to stop lobbying the governemtn (they dont' listen) and start lobbying Big Business, like IBM, MicroSoft, Apple, etc, to start including encryption hooks in their software. And if PGP is a problem, International PGP might be an option. And if there are problems with patent infringements and that kind of crap, then we (the concerned people of the global network) need to develop a free encrytion scheme that can do everything PGP can do and still be legal. Unfortuately, all I can do is stand on the sidelines and cheer, because I am not a programmer; I'm a user and a teacher. We've seen the enemy, that the are the 535 senators and representatives in D.C., and the staff in the White House. It's time to shore up our allies and enter the battle witht he best weapons we have; information and popular use.
In fact, it's what many of us saw implicit in Clipper.
Yup. We all saw it with clipper. We were all called paranoid. Guess so... ____ Robert A. Hayden <=> Cthulhu Matata \ /__ -=-=-=-=- <=> -=-=-=-=- \/ / Finger for Geek Code Info <=> hayden@krypton.mankato.msus.edu \/ Finger for PGP Public Key <=> http://att2.cs.mankato.msus.edu/~hayden
"Robert A. Hayden" writes:
We've seen the enemy, that the are the 535 senators and representatives in D.C., and the staff in the White House. It's time to shore up our allies and enter the battle witht he best weapons we have; information and popular use.
As unpleasant as the congress is, it isn't the enemy. The governmental forces desiring control are not the same as the congress. Congressmen are by and large harried and ignorant people. They have no idea what any of this is about. We have the choice of letting Louis Freeh do all the educating, or having a white shoe Washington PR firm do some of the educating, too. I favor the latter approach. This is not to say that we shouldn't be widely deploying crypto -- we should. (Of course, offshore sites will always have crypto available, but...) This is also not to say that Congress doesn't pass very bad laws. However, I very, very strongly urge that we not assume that nothing can be done. Just winning a couple years time could totally alter the landscape. Perry
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SANDY SANDFORT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . C'punks, On Thu, 13 Jul 1995, Perry E. Metzger wrote:
As unpleasant as the congress is, it isn't the enemy. The governmental forces desiring control are not the same as the congress.
I'm not so sure. Both politicos and bureaucrats go into their respective lines of work for many reasons. One of the main reasons--in my opinion--is a lust to control others. Being the "others," we should resist this tendancy. This begins with the realization that most of them *are* the enemy and acting accordingly.
This is not to say that we shouldn't be widely deploying crypto -- we should. (Of course, offshore sites will always have crypto available, but...)
Yes, what we really need is easy, drop-in, point-and-click PGP for the computer neophytes. And we need to give it away to all of them. I wish I know how to accomplish all that. My "wish list" also includes a fantasy in which someone (hopefully, a Cypherpunk) cracks some NSA developed, secret algorithm, crypto system, preferably causing some sycophantic company or organization to lose a bundle. Ah, dreams. S a n d y P.S. My 84 year old mother went in to buy a refrigerator from Sears or Monkey Wards or whomever. She picked out a top-of-the-line Tappan. However, when she was getting ready to pay, the salesperson began to ask her a series of questions which included her age and social security number. My mom said, "Just stop right there. If you want to ask all this personal information, I'll just buy it somewhere else." The stopped asking questions and took her check. I think Nancy Reagan had a good idea there. Just say `NO'. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
On Thu, 13 Jul 1995, Sandy Sandfort wrote:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SANDY SANDFORT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
C'punks,
On Thu, 13 Jul 1995, Perry E. Metzger wrote:
As unpleasant as the congress is, it isn't the enemy. The governmental forces desiring control are not the same as the congress.
I'm not so sure. Both politicos and bureaucrats go into their respective lines of work for many reasons. One of the main reasons--in my opinion--is a lust to control others. Being the "others," we should resist this tendancy. This begins with the realization that most of them *are* the enemy and acting accordingly.
Well, now, I wouldn't say THAT.... There are those of us intent enough of defending our rights as to go so far as to make an effort of getting to where we can do so more easily. While I know I was shouted down over NYET, the group does know where I stand on the issue of, for instance, free crypto or the Exon Hustler Protection Act. I intend to run for JP in '98, and (assuming our electoral system, if not our Constition is still intact) higher office later. If I win, you can bet your keyring passwords that _I_ will make sure that my juries are aware of FIJAs position papers. There are others--including one John Tello, a member of the Texas State Republican Executive Committee, who almost single handedly got a unanimous resolution out of the TX SREC calling for an end of our 60-year emergency and a recision of various related acts. Bluntly, if you are bellyaching but _not_ involved with an organized political structure that is capable of influencing legislation, then I blame YOU for this legislation. I am, have, and/or shall have lobbied every Congressman with whom I can claim a minimal connection. And I've done the work so that this is a non-trivial list. Direct mail is useful. But until you've worked to get someone elected, you are just one more voice in the roar. The '96 campaigns are shaping up. (I'm already putting the word out for '98...) This is the time to find people who share our views, and work so that they win their primaries--or maybe don't even have to fight one. Or maybe its time _you_ ran. Nathan Crypto-Christo-punk
massive use of cryptography started. This means, and I advocated this from the day I entered this forum, that programs such as PGP need to be redesigned so that the a user friendly . . . so user friendly that any Joe Moron can figure out not only how to use them, but also how it helps them and how it is "good" for them. This means that we need simplified key management easy enough for the point-and-click masses to utilize. This means that common mailing programs, From Elm and Pine to AOLs and Computer$erve's mailers need to have TRANSPARENT signing of mail messages and near-transparent encryption of messages. This means that we need to
I agree. If you forgive me for again taking the opportunity to advertise SSH, one goal was to make it as simple to use as possible. To get all the benefits of encryption and most benefits of improved authentication, the users need to know absolutely nothing in addition to what they need to know with rlogin. Plus, there are many convenient features, such as automatic X11 forwarding (encrypted; DISPLAY is set to point to a fake display), command exit status is returned properly, etc. Of course, rlogin and rsh are much less important applications for the general public than e-mail. I think the currently the most critical problem areas are exactly e-mail and interactive messaging programs (like irc, rwrite etc). Most mail (at least on the internet) is currently propagated automatically from the sending host to the receiving host. A fairly simple, 90% of the benefit at 10% of the effort solution could be to have sendmail (or equivalent) encrypt all communications that go through the network. This would make electronic mass surveillance and scanning difficult. It is much more expensive (and dangerous publicity-wise) to read messages by breaking into a computer system. This kind of system could be installed without the user even being aware that something like that is in use. It is not a perfect solution - some sites will not support encryption, and some messages might get sent without it. Still, the bulk of the messages would be encrypted, and any really sensitive data could be additionally PGP (or similar) encrypted. The procotol and implementation would have to be well made and established as internet standards. Tatu Ylonen <ylo@cs.hut.fi> For more information about SSH, see http://www.cs.hut.fi/ssh.
participants (7)
-
Nathan Zook -
Perry E. Metzger -
Phil Fraering -
Robert A. Hayden -
Sandy Sandfort -
Tatu Ylonen -
tcmay@sensemedia.net