Slashdot Mirror


The Encryption Wars

Occasionally I read works that simply defy description. This is one of them, an interview with Eben Moglen, general counsel of the Free Software Foundation. It isn't short, but if you read one article referenced from Slashdot this month, this should be the one. Part 1. Part 2.

14 of 148 comments (clear)

  1. Re:Holy shit! by Anonymous Coward · · Score: 3

    So the two-button mouse allows you to grunt at two different pitches, making a disctinction to the Mac cavemen?

  2. Music Makers by bluGill · · Score: 3

    Americans listen to music; they don't make music

    That is a generalization of people that has always been true about all socities. From the days of Homer (who may or may not have been a musician setting the Odyisey to music) on today most people do not make their own music, they listen to music others create. We all need enertainment, some like it more then others. Some feel compelled to create it. The best of those make money at it. (Homer probably made his money going village to village singing the same song/stories, spreading news. Of course he wasn't paid in money so much as food, shelter and other necessities.

    Today some people feel compelled to make music for their own enjoyment. Some familys still gather in the living room at least weekly for their family jam sessions. (I've knowns such folks but they are closed sessions and i'd have to marry into the family to join). Others have open Jams with friends. Some put on a concert for friends/family, some put on a public concert (generally for money).

    It has never been true that the majority of people have every done everything. Go look at metalwork news groups (rec.crafts.metalworking amoung others) and see the cirticism about people who do not know how to fix things in general. Check out the wood working news group and you will find people who can't understand why anyone would buy a bookshelf (either junk from walmart of a quality model) when they can make their own. They don't pause to consider many of them make book shelves for others. Those who take part in the above two groups have favorite clothing they like to wear (xyz make better welding gloves then abc), but none of them even consider butchering their cow (which they don't have anyway) to get leather to make their own welding gloves.

    Or to put it anouther way: I'm ccapable of doing many things, but I don't have time to learn how to do them all. I can paint a house, but a professional painter can do the same job in 1/4th the time, and make less of a mess. I can do a, I can do b, or I can do c; however the time it takes to learn each means I cannot do a, b, and c. At best I might live to be 110, and be healthy along the way, and so perhaps I could do a and b, but I still won't have time to learn c. Now add in the fact that c bores me and suddenly it makes sense why I wouldn't do it.

    My grandpa doesn't care about comptuers except as it relates to keep our family tree. He uses the web for research, email to contact relatives in the old country. He has a specialized genology program that he enters all that data into, which is much nicer then his files that he used to keep pre computer. (He started this hobby long before computers existed, he is making progress much faster now) When he has problems with the computer he calls me. When I want to know where in Germany my ancestors imigrated from I call him.

  3. Re:I prefer 'Never Encrypt. Ever.' by jafac · · Score: 3

    The ironic thing here, is that this is one of the central tennants of Christianity.

    Nobody is perfect. Everyone is a sinner. And therefore - nobody has a right to judge anybody, and if you do notice that another person has made a mistake, you better forgive them.

    I agree, the world WOULD be a better place if everybody would accept these facts. Jeez, that Jesus guy was smart!

    Unfortunately, Christianity's strongest proponents seem to have missed the point.

    --

    These are my friends, See how they glisten. See this one shine, how he smiles in the light.
  4. Choice Quote by MoNickels · · Score: 3

    "It's a paradox of the way the U.S. government works that the secret agencies spent hundreds of millions of dollars building Echelon and all the rest of the interception gear, but when it came down to defending the export controls over encryption in the federal courts you had a couple of assistant U.S. attorneys."

    --

    Wordnik, a dictionary project which aims to collect

  5. Re:Holy shit! by frankie · · Score: 3
    Moglen's objection to the mac gui is amazing

    Note, of course, that Moglen is referring to the entire category of WIMP GUIs, not just MacOS. In fact, he reserves his harshest criticism for Slashdot's favorite whipping boy:

    I lost that war in the early 1980s, [...], because the fundamental turn in the technology - which we see represented in its most technologically degenerate form, which is Windows, the really crippled version.

    The real point he was getting at is that user-friendly systems often discourage people from exploring the depths of their computers, in the same way that modern high school boys don't tinker with cars the way boys did in the 50s. (note: "boys" is in the original article). If the interface is easy and the guts are not user-serviceable, then fewer people will become hackers (in the positive sense of the word).

    His obvious mistake is that if the interface is difficult, fewer people will use computers overall, so the absolute hacker count won't be much different. The key is not an interface that forces people to get their hands dirty just to use it, but instead design the whole system so it's easy to modify. An OS that comes with full documentation, editors, and a compiler pre-installed will encourage the development of more programmers, no matter how nice a GUI you put on top.

  6. Re:Use encryption needlessly, constantly! [MUCH MO by pallex · · Score: 3

    Perhaps SlashDot could publish a public key for comments, and you`d get a +1 bonus for encrypting your comments to that key?

  7. Holy shit! by Shoeboy · · Score: 4

    Occasionally I read works that simply defy description. This is one of them, an interview with Eben Moglen, general counsel of the Free Software Foundation
    Wow, this may be the first time in history that a slashdot editor actually read an article befor posting it.
    The apocalypse is near.
    Seriously though, Moglen's objection to the mac gui is amazing:
    In 1979, when I was working at IBM, I wrote an internal memo lambasting the Apple Lisa, which was Apple's first attempt to adapt Xerox PARC technology, the graphical user interface, into a desktop PC. I was then working on the development of APL2, a nested array, algorithmic, symbolic language, and I was committed to the idea that what we were doing with computers was making languages that were better than natural languages for procedural thought. The idea was to do for whole ranges of human thinking what mathematics has been doing for thousands of years in the quantitative arrangement of knowledge, and to help people think in more precise and clear ways. What I saw in the Xerox PARC technology was the caveman interface, you point and you grunt. A massive winding down, regressing away from language, in order to address the technological nervousness of the user. Users wanted to be infantilized, to return to a pre-linguistic condition in the using of computers, and the Xerox PARC technology's primary advantage was that it allowed users to address computers in a pre-linguistic way. This was to my mind a terribly socially retrograde thing to do, and I have not changed my mind about that.
    I've been trying to express this thought for years and haven't been able to phrase it half as well. The mac gui really does emotionally and intellectually regress those that use it.
    --Shoeboy

    1. Re:Holy shit! by Kaa · · Score: 5

      The real point he was getting at is that user-friendly systems often discourage people from exploring the depths of their computers, in the same way that modern high school boys don't tinker with cars the way boys did in the 50s.

      Well, there is a good reason for this, a reason which Moglen ignores completely. It is called complexity.

      Do I know how Linux works? Kinda. I can get around and even sysadmin a small network. But do I have a clue about the internal workings of the kernel? No. And why? Because it's big and complicated. I cannot dedicate my life to studying it -- there are other interesting things in life to do.

      Moglen comes from time when you had 4K of memory and everything had to fit in there. Operating systems were small and simple. You could learn them and know them very, very well without spending months and years studying them.

      Look at cars. In the 50s (hell, in the 70s as well) cars were simple mechanical devices. I could (and did) take much of the engine apart with a bunch of wrenches, fix it, and put it back together. It even worked after that. Cars were simple and easy to understand.

      Now, there are electronic black boxes all over my car. To adjust ignition I don't turn a screw any more -- I have to plug some electronic thingie into another electronic thingie in my car and adjust something on screen. If a black box breaks, I cannot fix it -- I throw it out and buy a new one.

      So, my point is that it's complexity that is the real problem. Complexity discourages people from exploring "the depths of their computers" because it takes too long and you cannot hold the whole thing inside your head like you used to be able to do. Complexity prevent modern high school boys from tinkering with cars because [electronic] tools are expensive, change all the time and you don't really understand the internal workings anyway.

      And, no, it doesn't have anything to do with GUIs or user-interface systems.

      Kaa

      --

      Kaa
      Kaa's Law: In any sufficiently large group of people most are idiots.
  8. Re:Bruce Sterling on encryption by alexjohns · · Score: 4

    Bruce Sterling was talking about individual privacy, not the larger issue here of a kind of 'civil disobedience'. If everyone were to use encryption all the time, ECHELON and its ilk would become useless.

    On a personal level, it's not really relevant. If someone wants to know all about you, they'll put in keyboard sniffers, or use the radiation emission from your monitor (can't remember the name of it right now) or any number of other social engineering techniques. Shredding your trash only stops your neighbor. Anybody serious can just call up the credit bureaus, phone companies, utilities and own you.

    Short of living in a shack in the woods or having bazillions and living your life through the screen of lawyers and accountants, any ordinary shmoe, on an individual level, is pretty much unable to safeguard their privacy. It wouldn't take much of a 'black bag' operation to break into your doctor's office and copy your medical records, either. On an individual level, you're screwed.

    On a large level, everyone using encryption would put a serious crimp on the NSA, CIA, and corporate espionage. Of course, right now, using encryption in all your communications makes you stick out like a sore thumb.

    So it's OK to participate in this civil disobedience if you have nothing to hide (ooh, a catch-22) and you only communicate with people who are willing to deal with the pain and bother of encryption. There you go.

    --

  9. difficulties with his dreams by Pink+Daisy · · Score: 4
    I thought that was a really silly article. He proposes thins that are not practical. If it were not so verbose, it would actually be funny.

    Has anyone considered the cost of encrypting the majority of Internet traffic? I always encrypt terminal sessions, but the cost of servers encrypting web traffic would be very high. I wouldn't mind; my PC has enough power to encrypt all MY traffic, but how about a busy web server? How much new hardware would slashdot need to support encrypting everything? If slashdot is going to blow that stupid smoke, then slashdot should encrypt all its traffic.

    Second, is his explicit assumption that Linux is the best thing available, and that free software is always better than proprietary software in quality. Linux does have a lot of good points, and in some cases is the best solution. MS Windows has strengths also. Sometimes Microsoft solutions solve a problem better. Sometimes one of the other systems he ignores is better.

    Another thing he guessed wrongly about is the interest of people who grow up with computers in hacking. Maybe I'll be proved wrong, but I haven't been yet. People who grow up with computers don't gain any magical insight or understanding of them. Nor do they desire such. They use them as familiar tools, just like adults at work. The difference is how familiar and what they do. Some people will become hackers; probably more. Definitely not everybody.

    So, I think the article is nonsense, but if Michael thinks this is the most significant article of the year, then he should put slashdot on the same track by encrypting all its traffic.

    --

    If you are modding me down because you disagree with me, use the "Flamebait" category, not the "Troll" one.
  10. Bruce Sterling on encryption by Pseudonymus+Bosch · · Score: 5
    From the Bruce Sterling FAQ:
    What's your PGP key?

    Don't use 'em. I never knew a real-life computer crime cop or investigator who paid any attention to deciphering encryption. I regard this as a 99% theoretical form of "security." Using big number-crunching high-tech to protect the brief transmission of Internet email gives people a false sense of security. If you get in trouble, it won't be because you were tapped and cracked by the NSA. It'll be because somebody you trusted ratted on you (or because you bragged). Trust me on this. If you're really worried about your privacy, stop using credit cards and shred your trash.

    __
    --
    __
    Men with no respect for life must never be allowed to control the ultimate instruments of death.
    GW Bu
  11. OK -- So when's /. going to HTTPS ??? by redelm · · Score: 5

    An interesting an important article. One key point is to invalidate keyword filtering by massive redundant use of encryption.

    So when is SlashDot going to do it's bit and make everything HTTPS? Almost all browsers have it, and it's a simple and transparent way to increase encrypted traffic to nullify keyword filters.

  12. Use encryption needlessly, constantly! [MUCH MORE] by sanemind · · Score: 5

    If there is one most singularly important lesson to learn from this, it is USE ENCRYPTION CONSTANTLY, WHENEVER YOU CAN, AS MUCH AS POSSIBLE (Pardon the theatrics)

    To be honest, if you are the sort who has been reading slashdot for a while, you already know this arguement well, and I see no need to hash it out as if I have anything brilliant to add to it, except for this little nugget of nike-ism. Just DO it. It's one thing to sit around on your buttocks [face it, you generally are when you are at a terminal] and do nothing about it, reveling in the possibilities of this marvelous new [well, sort of ;) ] networked media demense we inhabit, knowing full and well that privacy and anonymity are extremely important issues as society as a whole continues to evolve in it's relation with and reaction to the possibilities of abbundant internetworked end to end communications between private citizens [and don't forget to throw in the presence of rapidly increasing affordable bandwidth].

    It's easy for many of us to say, yes, encryption is important certainly, not enough people are using it such that resources could concievably be targetted at those few who actually bother, but it's someone elses problem.

    It's too much of an inconvienience to use PGP or GPG with any regularly, and besides, what's the point when most people you dialog with in email don't use it? There is a point, and an important one. Either the citizinry will manage to somehow wake up and start taking it's privacy and security into it's own hands, or personal privacy will continue to wither away. Too many other people have some feeling that their interactions on the net are anonymous, when this is so far from the truth.

    If the U.S. postal system were to work as the internet, where every letter sent can be readily and [at virtually no cost in human labor] inspected thoruoughly by the government or other bodies, people would be outraged. But they feel that these sorts of things just don't happen, that it won't happen to them. And, frankly, many people are hopelessly confused about how computers or networks work at all. To them a computer is often just a fancy typewriter and info kiosk.

    People like us need to start to devote some time to serious personal, grass roots activism, to widen the pool of people using encryption.

    Becuase it's only at the grass roots level that their is any liklihood of it actually happening. Perhaps something could be established vaguely [in spirit, certainly not implementation, I'm talking in sweeping generalities about the possible social dynamic] like the RBL. I don't mean a central server or list of people who do/don't use encryption, I mean instead a system whereby people would feel some penalty or disinsintive if they are not using encryption themselves.

    ...Perhaps some sort of extension to sendmail and friends, whereby a simple script configuration could activate a mode wherein outgoing emails [probably only of willing participants, I wouldn't want to be overbearing or myself lessen anyones freedom to use the network as I choose, no matter how foolishly]

    ...wherin outgoing emails would initially be automatically encrypted [say, as a mime attachment to another, autogenerated email, whose body would inform the recipient that they have recieved an email from so-and-so, but that this person values their privacy and dosen't want anyone with good network or social/political real-estate to be able to read their personal communication to them. It could include perhaps a link to an advocacy site, explaining the whole purpose and ideas behind encryption being a Good Thing, as well as simple and transparent to use backend clients to download for all the major platforms, that could just as transparently decrypt and deliver the message as if it had never been encrypted.

    For those who chose [probably most, for I probably wouldn't want all of my email to be completely unreadable by those who didn't agree to run software I liked, even if it was free and open], there could be additional details in the email message to allow for the recipient to respond in a certain way and recieve the unencrypted version. Something akin to the process of confirmation from a mail server, for instance.

    The inconvinience would be a key aspect, for it would turn the tables; wheras now it is more inconvienient for someone to bother with setting up encryption.

    Now I know this is asking a lot, and I don't imagine very many of you have bothered to read this far, but it's something to think about. lesson to be learned from this, it is a l

    --

    ---
    the pen is mightier then the sword. the sword is mightier then the court. the court is mightier then the pen.
  13. Uh! by Vic+Fountain · · Score: 5
    [...] if you read one article referenced from slashdot this month, this should be the one.

    So you tell me this now, when half of the month is already over...