Slashdot Mirror


Non-US Encryption Is 'Theoretical', Claims CIA Chief In Backdoor Debate (theregister.co.uk)

Iain Thomson, writing for The Register: CIA director John Brennan told U.S. senators they shouldn't worry about mandatory encryption backdoors hurting American businesses. And that's because, according to Brennan, there's no one else for people to turn to: if they don't want to use U.S.-based technology because it's been forced to use weakened cryptography, they'll be out of luck because non-American solutions are simply "theoretical." Thus, the choice is American-built-and-backdoored or nothing, apparently. The spymaster made the remarks at a congressional hearing on Thursday after Senator Ron Wyden (D-OR) questioned the CIA's support for weakening cryptography to allow g-men to peek at people's private communications and data. Brennan said this was needed to counter the ability of terrorists to coordinate their actions using encrypted communications. The director denied that forcing American companies to backdoor their security systems would cause any commercial problems.

312 comments

  1. American Companies by Anonymous Coward · · Score: 3, Funny

    LOL, how quaint. As if a company belongs to a particular nation state. Freemasons 2016, huyah!

    Sir Bush, president and knighted...

    1. Re:American Companies by St.Creed · · Score: 3, Interesting

      National companies and multi-national companies *do* belong to a nation-state. It doesn't show much, until they need someone to get their potatoes out of some hot fire somewhere. They can't just move and up, since they need ties on a personal level when you get into the big leagues. Not to mention the fact that if they have a lot of infrastructure somewhere, it's also physically difficult to move.

      Let's assume corporations don't belong to a particular nation state. Like Disney. Could be Chinese, right? Mi Lao Shu and security guards with pink rifles. Works quite well in Shanghai - they are a minority shareholder though because, for some reason or another, the local company *does* belong to their nation state and the nation state knows it. Or take Coca Cola. Wouldn't hurt the brand at all if it incorporated as a Nigerian company tomorrow, I think. Or Mercedes. It could easily become an Italian brand. Would do wonders for its design, probably. Volkswagen could move to Rumania - their cars have the same amount of pollution as the old cars they have there so they wouldn't stand out so much.

      But seriously: no company can do without the protection of a nation state because in the final analysis, a tug of war between competing business interests will eventually be decided with weapons. And that is the job of the nation state. And it will only defend it's *own* companies. Companies that don't have a protector will be at a severe disadvantage. Just consider what the support of the CIA meant for Boeing when it sank lucrative trade deals in the Middle East for Airbus because they had been tapping the trade negotiations and were able to provide tapes that proved corruption. Do you think that would have happened if it had been Airbus versus Dassault? Not a chance.

      --
      Therefore, by the (faulty) logic you're using, you're just a cow with a keyboard - osu-neko (2604)
    2. Re:American Companies by MobSwatter · · Score: 1

      LOL, how quaint. As if a company belongs to a particular nation state. Freemasons 2016, huyah!

      Sir Bush, president and knighted...

      And they should pay no mind to the boycott on US products involving code produced within the US either...

      The trouble with Mason's is what the banksters did to them long ago, a line was drawn and if you didn't swing the mafia/banksters way you became cannon fodder. Freemason's were the ones that built a lot of stuff, from what I understand of my great grandfather, a master mason out of Wisconsin who left his initials on the underground river plug under Virginia City and was tossed into Lake Tahoe for his efforts to pay the crew and that was pretty close to what they did with the Asian rail workers, Freemason was a perverted definition of a Mason by the mafia/banksters, because the work of a Freemason was paid for with their own blood.

    3. Re:American Companies by dbIII · · Score: 1

      Well put.

      A very good example on the domestic level that we can all safely point at (since it's dead and buried) is Enron. The final CEO of that Texas based company spent the majority of several years in Washington forging strong political links and calling in favors. That is a major reason why what turned out to be a company with far less than zero worth was able to get away with running like that for so long before the bankers tore them apart.
      On the foreign side - Joint Strike Fighter. So many allies have been told by the US government to give money to Lockheed Martin. There is a LOT of that sort of thing going on with government helping out defence contractors at the expense of foreign policy with so much money and trips to Vegas just falling into people's pockets it smells almost as bad as the sort of corruption you get in China.

    4. Re:American Companies by djinn6 · · Score: 1

      I don't disagree with the rest of your post, but it seems to me the CIA's job should not be business espionage. There's nothing stopping Boeing from doing that themselves.

  2. Lies from Spies by schneidafunk · · Score: 4, Insightful

    Well of course he's going to say this nonsense, no surprise there. What is surprising is hearing about it from a british newspaper without a bleep in U.S. news. I imagine apple, microsoft, google and the likes will have a response soon.

    --
    Some people die at 25 and aren't buried until 75. -Benjamin Franklin
    1. Re:Lies from Spies by Anonymous Coward · · Score: 0

      You can try Sailfish OS (jolla) for phones, you can port it to some phones unoficially.
      reviewjolla.blogspot.com.ee/p/devices.html

      May-be the US dont have enough dirty fingers in that yet.

    2. Re:Lies from Spies by wierd_w · · Score: 3, Interesting

      There would just be something like cyanogenmod that hits less than a year later. in fact, CM would probably issue a statement that they wont include the back doors.

      CM is based on AOSP, and is wholly open source. If your device supports it, then you can use real crypto, while everyone else in the US gets to enjoy fake crypto.

      The issue of course, is that you would need to encrypt so much, (because GSM and other hardware assisted crypto would be backdoored, so you have to put real crypto on top) that your battery goes flat very fast.

      IMHO, the solution to that is for eurozone countries to mandate denying US variant GSM devices from working in their countries as an issue of national security. The corporate backlash would be intense.

    3. Re:Lies from Spies by Bob+the+Super+Hamste · · Score: 4, Informative

      Seriously why?

      I find that the Brits generally do a better job covering the US than the US news does.

      --
      Time to offend someone
    4. Re:Lies from Spies by ceoyoyo · · Score: 3, Informative

      Android itself is open source. Anyone can download it. It's mirrored extensively outside the US. In terms of actual devices, by far the largest providers of those are non-American companies.

      Android itself uses a linux cryptography library. Those libraries are likewise open source and extensively mirrored. Of the ones that could actually be said to have a particular nationality, most of them are not the US: https://en.wikipedia.org/wiki/....

      Seems like Android is an excellent example of how this guy is wrong.

    5. Re:Lies from Spies by umghhh · · Score: 1

      Let us see. There are governments that wholeheartedly cooperate with US on 'security' i.e. war on drugs and war on terrorism and other such - UK for instance. French cooperate because they have a good reason, Swedish cooperate because their ruling class is inbred so much that that affects their brains, the southern flank is corrupt and thus cheap to buy and the eastern flank are so scared of Ruskis (not sure if the Ukraine affair was done on this purpose or just happened this way but either way - well done!) that they do what they are told even if they disagree. Who is left - Germans? They have the Emperor in Berlin who after the wiretapping of her phone came to the public, decided to do nothing, she also refused to reveal the trigger lists because NSA did not let her. Hmmm - how big chances of that do you think there are there? 1%? Besides after the same Merkel invited millions of people to swim and walk to Germany there is an urgent need to eavesdrop everybody now. There are simply too many good reasons why European elites will cooperate. The matters are too complex and if my educated neighbours say to such arguments that they obey the law and have thus nothing to fear I'd say chances of success are null. Admittedly if against all the odds such law would have been passed then indeed the big IT gorillas would try to repeal the laws but quite frankly you do not believe this happens, ever. I do not either.

    6. Re:Lies from Spies by Anonymous Coward · · Score: 1

      What is surprising is hearing about it from a british newspaper without a bleep in U.S. news.

      The US news media is incredibly insular. They got as far as "Non-US ..." and lost all interest.

      Seriously. Say the entirety of Ethiopia is wiped off the map.
      Headlines in Europe: "Ethiopia destroyed by unknown cause. Over 100 million presumed dead."
      Headlines in US: "Tragedy befalls Ethiopia. Over 100 US tourists presumed dead."

      ... followed shortly by "Could aliens have caused the Ethiopia disaster? Hear what Twitter users have to say!"

    7. Re:Lies from Spies by dpilot · · Score: 2

      Gee, you've completely missed Russia and China. Of course both of those nations would probably applaud such a move on the part of the US, because it makes pursuing their desires easier.

      It's time to remember the classification of encryption as a weapon, and invoke our second amendment rights, "If encryption is outlawed, only outlaws will have encryption."

      --
      The living have better things to do than to continue hating the dead.
    8. Re:Lies from Spies by rahvin112 · · Score: 1

      Good luck with that, the US would simply threaten to stop sharing intelligence information and EU countries would buckle under in about 30 seconds. EU spying apparatuses are entirely dependent on data supplied by the US and the 5 eyes program just like the EU is totally dependent on the US to guarantee their defense. That's the complication of relying on the US to fund these activities for you as the EU is unwilling to pay the cost to do this themselves.

    9. Re:Lies from Spies by currently_awake · · Score: 1

      You are suggesting that your phone baseband isn't backdoored. Or that you can audit the firmware running on it?

    10. Re:Lies from Spies by ceoyoyo · · Score: 1

      No, I'm saying that lots of phones running Android isn't a good example of the "practical truth" of there not being any encryption outside the US.

      Of COURSE the baseband is compromised.

    11. Re:Lies from Spies by LVSlushdat · · Score: 1

      What is surprising is hearing about it from a british newspaper without a bleep in U.S. news.

      Not surprising at all.. The American news media has become the defacto US Department of Propaganda... What do you expect??

      --
      THANK YOU, Edward Snowden!! Americans owe you a debt of gratitude (whether they know it or not..)
    12. Re:Lies from Spies by Maow · · Score: 1

      There would just be something like cyanogenmod that hits less than a year later. in fact, CM would probably issue a statement that they wont include the back doors.

      CM is based on AOSP, and is wholly open source. If your device supports it, then you can use real crypto, while everyone else in the US gets to enjoy fake crypto.

      In the binary blobs is where it'll be found.

      Which you address:

      The issue of course, is that you would need to encrypt so much, (because GSM and other hardware assisted crypto would be backdoored, so you have to put real crypto on top) that your battery goes flat very fast.

      >

      Too bad there isn't much left of the European telecomm manufacturors (Nokia, Erikson(sp?), and Blackberry for that matter (widening the net)).

      IMHO, the solution to that is for eurozone countries to mandate denying US variant GSM devices from working in their countries as an issue of national security. The corporate backlash would be intense.

      I agree with everything you've said, but on the last point, expect the US to respond with

      "Nice Airbus, shame if something happened to exports to USA.

      Care for some Freedumb Fries?"

      Then the Europeans fold like a house of cards (sadly).

    13. Re:Lies from Spies by Carewolf · · Score: 1

      I imagine apple, microsoft, google and the likes will have a response soon.

      You have vivid imagination.

    14. Re:Lies from Spies by dbIII · · Score: 1

      and invoke our second amendment rights

      The right to hand your guns back when you turn 45 and are no longer considered a potential member of the militia?
      The STATE has second amendment rights, the right to draft your ass into uniform and get you to fight. You have your gun rights because they have not been taken away. It has nothing to do with the second amendment no matter what the ranting of people in nothing but a sports club, the NRA, consists of. That's why you get to keep your guns even when you no longer fit the "militia" definition.

    15. Re:Lies from Spies by Impy+the+Impiuos+Imp · · Score: 1

      The 2nd directly mentions The People and not the states. The state cannot regulate away the people keeping and bearing arms, as that is the backbone upon which is built the well-regulated militia, which is what is necessary to keeping freedom.

      "The state shall have the power to take away arms...the right to keep and bear arms shall not be infringed." -- this makes no sense if government can take it away under "regulated militia".

      --
      (-1: Post disagrees with my already-settled worldview) is not a valid mod option.
    16. Re:Lies from Spies by schneidafunk · · Score: 1

      Have you not been following the news?
      http://www.latimes.com/busines...

      --
      Some people die at 25 and aren't buried until 75. -Benjamin Franklin
    17. Re:Lies from Spies by dbIII · · Score: 1
      So when you turn 45 what then? You are no longer potentially part of the "well regulated militia". If it was all about the second amendment as Oliver North and the other NRA directors say then the government could take those guns away once you hit the age limit.

      The reason they don't is because you have the right to do anything unless laws are enacted to stop you having that right. There is no law to stop you. The second amendment distraction from a sporting club turned political has nothing to do with it.

      The 2nd directly mentions The People and not the states

      Not "states" - the state. In this context "state" means nation or national government, as it does in many political documents worldwide especially the US constitution. I put it in all capitals to try to make that more obvious but kept the word "state" since that's in the document. See also

  3. Dumfounded at the ignorance by fnj · · Score: 1

    This halfwit is the best that the US can come up with to head their "intelligence" apparatus?

    1. Re:Dumfounded at the ignorance by tiberus · · Score: 1

      What?!? Hey, guess neither of a new the US was an international leader in technology and encryption.

      Um, yeah...

    2. Re:Dumfounded at the ignorance by pushing-robot · · Score: 5, Insightful

      When it comes to intelligence agencies, never attribute to ignorance that which can adequately be explained by malice.

      --
      How can I believe you when you tell me what I don't want to hear?
    3. Re:Dumfounded at the ignorance by Kernel+Kurtz · · Score: 3, Insightful

      He is worse than the terrorists.

    4. Re:Dumfounded at the ignorance by myowntrueself · · Score: 0

      This halfwit is the best that the US can come up with to head their "intelligence" apparatus?

      You've heard how "Military intelligence" is an oxymoron? Well "'Murcan intelligence" is the same.

      --
      In the free world the media isn't government run; the government is media run.
    5. Re:Dumfounded at the ignorance by Anonymous Coward · · Score: 0

      Yes, George Washington would be shitting himself in his grave.

    6. Re:Dumfounded at the ignorance by thegarbz · · Score: 3, Informative

      This halfwit is the best that the US can come up with to head their "intelligence" apparatus?

      You wouldn't come up with the same excuse given the following information:

      1. You're standing in front of a group of people who consider you the expert.
      2. You stand to gain a lot from forced backdoors and the job for your agency becomes far easier.
      3. You have almost zero chance of being punished for lying through your teeth.

      What would you have said? Personally I would have come up with the exact same thing and sugar coated it by saying all terrorists use all American technology.

    7. Re:Dumfounded at the ignorance by Bob+the+Super+Hamste · · Score: 1

      Statements like that aren't for the people who work for him, or even the /. crowd. They are for the consumption of the assorted idiots and defectives in congress as well as to placate the general populous that has know knowledge of how encryption works. He knows exactly what he is after and is positioning things so that he gets them even if he is lying through his teeth. Before the Paris attacks there were statements out of the FBI or CIA (I forget which) where one of their people said it would take a terror attack where the terrorists used encryption before they could seek to get rid of strong crypto available to the general public. Then a few weeks later the Paris attacks happen and there was tons of news coverage about the terrorists using encryption. Also lets not forget the whole San Bernardino attack and that fucking iPhone. This is just the next step in their long game. Sadly no tin foil is needed.

      --
      Time to offend someone
    8. Re:Dumfounded at the ignorance by Anonymous Coward · · Score: 1

      When it comes to intelligence agencies, is there a difference?

    9. Re:Dumfounded at the ignorance by Anonymous Coward · · Score: 0

      I Disagree, probably the only thing our intelligence agencies have done successfully his hide their own incompetence. Here is a good read, https://en.wikipedia.org/wiki/Legacy_of_Ashes_%28book%29 National Book award winner by a Pulitzer-prize winning author. Only sourced-on the record interviews and materials.

      Anyway, the CIA has bungled almost everything it's done since inception. Read the latest leaks about the NSA trying to figure out if Snowden's claims are accurate. The NSA is a big bungling bureaucracy that can't even monitor it's own email when given several months.

      The people that work at these places are mostly just clock-punchers like the rest of us; they are guided by medicore management that does it's best to respond to the changing whims of dishonest politicians, who in-turn try their best to capitalize on whatever is happening around the world.

  4. Jobs Creator by archatheist · · Score: 4, Funny

    Glad to see that this fellow has figured out how to create new technology jobs in foreign countries. I didn't realize that was his job, but kudos nevertheless.

    --
    "No sane man will dance." -- Marcus Tullius Cicero
    1. Re:Jobs Creator by PCM2 · · Score: 4, Insightful

      What's the saying? "When strong crypto is outlawed in the US, only non-US companies will have strong crypto"?

      --
      Breakfast served all day!
    2. Re:Jobs Creator by ceoyoyo · · Score: 1

      That cart has left the horse. US export laws caused much of the cryptography business to move out of the US decades ago.

    3. Re:Jobs Creator by HiThere · · Score: 1

      Last time it was:
      "When strong crypto is outlawed in the US, US companies will import it from outside."

      Of course, it was a little be different last time, it wasn't possession of strong crypto that was illegal, it was on exporting it. But that was still enough of a barrier that it got developed outside the US.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  5. wait by Anonymous Coward · · Score: 0

    are you shitting me with this

    1. Re:wait by Opportunist · · Score: 1

      The problem with Johnny is that he knows so little that it's hard to say whether he is actually trying to bullshit you or whether he really believes what he says.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  6. As the parable says: by Anonymous Coward · · Score: 0

    Those who can, do. Those who cannot, subvert free speech.

  7. Only "theoretical"? by Anonymous Coward · · Score: 2, Informative

    This guy is smoking some premium shit.

    He realizes that many of the Nordic area countries in Europe have some really talented crypto people, and that it would take all of about 2-3 years for some seriously competing cryptographic solutions to hit the commercial space, right?

    What will his precious 3-letter agency do when everyone stops sitting on inertia, and is compelled to create cryptography outside their control, while all the people in the US are forced to use the shitty crap he insists on-- you know, where the rest of the world can actually keep secrets secret, but his own country now cant, and foreign governments the world over just backdoor the shit out of everything, resulting in a powerful asymmetry in effective intelligence gathering?

    What a fucking douche.

    1. Re:Only "theoretical"? by Opportunist · · Score: 1

      "Purely theoretically" you could just take any OSS encryption implementation, audit the living shit out of it to ensure that none of li'l Jonny's backdoors remain and recompile it.

      If that takes a WEEK I'd be surprised.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:Only "theoretical"? by Anonymous Coward · · Score: 0

      A week? That is crazy talk. No one would spend that amount of time to create secure encryption.

    3. Re:Only "theoretical"? by sexconker · · Score: 1

      Be sure to audit your compiler, the compiler used to compile it, 8 layers of firmware/uefi/bios, and the physical CPU itself.

    4. Re: Only "theoretical"? by Anonymous Coward · · Score: 0

      Its been how many years since the Snowden revelations and where are all these competing products on the market? I dont agree with Mr. B but the ability to create something is worthless without the incentivised desire to do it. If the rest of the world could compete with American tech companies, they would. Instead, they move here and do it for the largest tech market without export restriction worries.

    5. Re:Only "theoretical"? by HiThere · · Score: 1

      It would take a lot longer than a week. Years wouldn't surprise me. What *would* surprise me is if someone hasn't already done it.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    6. Re:Only "theoretical"? by Opportunist · · Score: 1

      That's actually the interesting part, more so than whether or not I can invent an "independent" encryption implementation.

      If absolute confidentiality is key, the most sensible solution would be to split it into the three parts of receiving the encrypted message, decrypting the message and outputting the cleartext, implement each part in a separate unit and have them interface only in an easily auditable way, so that at the very least you can ensure that the unit that can transmit information to the outside neither knows what keys are used nor what clear text message is the result.

      But yes, that's actually the tricky part.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    7. Re:Only "theoretical"? by cwsumner · · Score: 1

      That's actually the interesting part, more so than whether or not I can invent an "independent" encryption implementation. ...

      Nothing in this world is absolute.
      But making it just a little bit more secure can save your life. 8-)

      Lack of perfection is not an excuse for failing to try...

  8. You aren't understanding him by Anonymous Coward · · Score: 1

    He's using FUD. Simple trick to get people to change up something you can't break. Trying to convince them that their stuff is being read by the US. And if they change up their techniques, maybe the US intelligence apparatus gets lucky and then *can* actually read their stuff.

    I suspect professionals will understand this and roll their eyes, continuing on as before.

    1. Re:You aren't understanding him by Anonymous Coward · · Score: 0

      Professionals need to cry out at the level of bullshit being spewed here.

      Otherwise, they're a) not professional, and b) not going to have that job for the longterm.

  9. Good thing all mathematicians are American then by xxxJonBoyxxx · · Score: 5, Insightful

    >> (for crypto) there's no one else for people to turn to (mofos)

    Well, it's a good thing that all mathematicians have always been and will always be American then.

    1. Re:Good thing all mathematicians are American then by TheSouthernDandy · · Score: 3, Insightful

      You don't have to be a mathematician, you only need to be able to implement algorithms designed by mathematicians on computers. I think they called that profession "programmer" once, and there even used to be Americans who did it.

    2. Re:Good thing all mathematicians are American then by Anonymous Coward · · Score: 0

      Non-American mathematicians go by another term, terrorists. You know what happens to terrorists.

    3. Re:Good thing all mathematicians are American then by Anonymous Coward · · Score: 0

      LOL. All important programs ever create din the U.S. are usually started by German, Polish, British, Italian, Bulgarian, etc. immigrants. Just read about how the nuclear bomb was created here. Native born Americans had little to do with the creation of the nuclear bomb, airplane jets or rockets after and before WW2. U.S. just put the money on the table, immigrants from around the world are the ones that put their mind together to create such inventions with that money. U.S. nationalize them, but they were not born in America.

    4. Re:Good thing all mathematicians are American then by chihowa · · Score: 1

      No kidding. The current Advanced Encryption Standard in the US (Rijndael) was even created by two Belgian mathematicians.

      --
      If you want a vision of the future, imagine a youtube comments section scrolling - forever.
    5. Re:Good thing all mathematicians are American then by F.Ultra · · Score: 1

      Not only that but the submissions during the AES process came from all over the world. And looking at the names of the current submissions to the upcoming CEASAR I wonder if there is even a single American among them: https://competitions.cr.yp.to/...

  10. The "response" should be an indictment. by mrchaotica · · Score: 5, Interesting

    Under 18 U.S.C. ss. 1001, lying to Congress is offense punishable by up to five years in prison (or eight if the lie is terrorism-related). The correct "response" to John Brennon's blatant, politically motivated, criminal lie is to indict him, convict him, and send him to Federal prison where totalitarian freedom-hating enemies of the American public like him belong.

    --

    "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    1. Re:The "response" should be an indictment. by NatasRevol · · Score: 4, Insightful

      In theory, yes.

      In practice, not a fucking chance.

      --
      There are two types of people in the world: Those who crave closure
    2. Re:The "response" should be an indictment. by Anonymous Coward · · Score: 0

      "Terrorists use encryption!" Therefore, eight years in prison seems more legally correct, though in reality it's eight more years than he'll ever get.

    3. Re:The "response" should be an indictment. by Anonymous Coward · · Score: 2, Insightful

      Well, given the fact that the Chinese are at least as smart and as technological advantage as far as public math goes as the Americans, and have more than enough money to do it and more than enough reason to do it, you could actually argue that this guy is advocating for a position where China can break American encryption, while using non-weakened encryption of their own (which there is no reason to believe to be any worse than the best American encryption).

      So, well, what is the punishment for high treason?

    4. Re:The "response" should be an indictment. by mrchaotica · · Score: 1

      Speaking of "in theory," considering what the news is reporting about how the FBI is going after the wife of the Orlando shooter, wouldn't failure to indict make every member of Congress an accomplice?

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    5. Re:The "response" should be an indictment. by bluefoxlucid · · Score: 1

      High-treason is defined in the U.S. Constitution and is punished by execution.

    6. Re:The "response" should be an indictment. by Megol · · Score: 1

      No?

    7. Re:The "response" should be an indictment. by Anonymous Coward · · Score: 0

      Punishable by execution... but it doesn't happen very often.
      Most of the time they get held for future possible prisoner exchange...

      Or elected to office.

    8. Re:The "response" should be an indictment. by Bob+the+Super+Hamste · · Score: 1

      Good luck.

      As much as I would like to see people like him sent off to federal PMITA prison it isn't going to happen. These guys are part of the protected class and they really need to screw over congress. Even spying and hacking into the Senate Intelligence Committee servers didn't' get them into trouble, so I doubt anything will ever come of this. I just wonder what they have on the congress critters.

      --
      Time to offend someone
    9. Re:The "response" should be an indictment. by Immerman · · Score: 4, Insightful

      O course not. They're exempt under the thoroughly time-tested doctrine of "we have wealth and power, so the law doesn't apply to us unless we piss off someone even wealthier and more powerful"

      --
      --- Most topics have many sides worth arguing, allow me to take one opposite you.
    10. Re:The "response" should be an indictment. by geekmux · · Score: 1

      In theory, yes.

      In practice, not a fucking chance.

      If "practice" has been reduced to not-a-fucking-chance-in-hell, then US law is nothing more than a "theory".

      I really grow tired of the American people supporting criminals who blatantly ignore the law, especially when those same Americans want to bitch about how fucked up things are.

    11. Re:The "response" should be an indictment. by Anonymous Coward · · Score: 0

      Oh you're ever-so-good at quoting U.S. law, that's impressive.

      How about you pull your thumb out of your ass and actually FUCKING DO SOMETHING ABOUT IT? Fucking slacktivists who think a Facebook post or a Slashdot comment is going to fucking change anything, you're a god damned waste of oxygen. Put up or shut the fuck up.

    12. Re:The "response" should be an indictment. by mrchaotica · · Score: 4, Informative

      The two Senators from my state plus Ron Wyden got emails from me on this issue before I posted on Slashdot. What did you do about it, mister shit-talking anonymous coward?

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

    13. Re:The "response" should be an indictment. by davester666 · · Score: 1

      I'm ok with trading him to China. Or even just giving him to them as a sign of goodwill.

      --
      Sleep your way to a whiter smile...date a dentist!
    14. Re:The "response" should be an indictment. by LVSlushdat · · Score: 2

      Under 18 U.S.C. ss. 1001 [house.gov], lying to Congress is offense punishable by up to five years in prison (or eight if the lie is terrorism-related). The correct "response" to John Brennon's blatant, politically motivated, criminal lie is to indict him, convict him, and send him to Federal prison where totalitarian freedom-hating enemies of the American public like him belong.

      Oh didnt you know?.. 18 U.S.C. ss. 1001 ONLY applies to the unwashed plebs, ie: Joe and Jane Six-pack.. People like Brennon don't have to worry about violating any of those pesky laws..

      --
      THANK YOU, Edward Snowden!! Americans owe you a debt of gratitude (whether they know it or not..)
    15. Re:The "response" should be an indictment. by LVSlushdat · · Score: 1

      Oooops... Forgot the /s for the sarcasm-challenged among us....

      --
      THANK YOU, Edward Snowden!! Americans owe you a debt of gratitude (whether they know it or not..)
    16. Re:The "response" should be an indictment. by ChadL · · Score: 1

      China seems to be well ahead of the US on the regulating encryption front, so I don't think that China will be ahead in terms of the general populous using encryption that can't be broken (excluding governments, of course). This article indicates that a lot of Chinese firms don't use encryption in China at all to avoid having to deal with giving the government keys. They also mandate usual encryption algorithms (SMS4 comes to mind) which are presumably selected because they can be broken.

    17. Re:The "response" should be an indictment. by Anonymous Coward · · Score: 1

      Under 18 U.S.C. ss. 1001 [house.gov], lying to Congress is offense punishable by up to five years in prison (or eight if the lie is terrorism-related). The correct "response" to John Brennon's blatant, politically motivated, criminal lie is to indict him, convict him, and send him to Federal prison where totalitarian freedom-hating enemies of the American public like him belong.

      They didn't even slap Jimmy Clapper's wrist for his blatant, repeated perjury. What makes you think they'll do anything to this yo-yo?

    18. Re:The "response" should be an indictment. by Anonymous Coward · · Score: 0

      Han people have, on average, an IQ of about 104/105. White people have, on average, an IQ of 98.

      This won't work out well for Brennan.

    19. Re:The "response" should be an indictment. by driblio · · Score: 1
      But he didn't lie. And he's not stupid (see thread above). An idiot, yes. But here's what he said: "American *companies* dominate the market for encryption *apps*". Absolutely true. Then he said something about "theoretically, foreign companies could [have strong encryption and] dominate the market." But they don't. And they won't [dominate the market].

      Because people don't give a shit about encryption, they're not going to stop using their iphones or facebook. Hardcore terrorist can already use whatever encryption they like, but they don't- they use pain GSM SMS. He knows that. This isn't about that. This is about making sure the average American doesn't use encryption on a day-to-day basis.

      I'm sure I had a point in there somewhere.

    20. Re:The "response" should be an indictment. by razberry636 · · Score: 2
      He didn't technically lie to congress. No cryptography is provably secure. We can prove some to be insecure, and that's when we stop using them. Until then we believe that our current technologies are secure.

      It's true: non-US encryption is theoretical, but so is US-developed encryption. It's all theoretical.

      I don't know if saying something that is technically true but is misleading would be enough to convict someone of lying to congress.

      Correction: I don't know if it would be enough to convict a high mucky-muck of a TLA.

    21. Re:The "response" should be an indictment. by meerling · · Score: 1

      He's already lied to them before, and even admitted to it when pressed.
      Of course, nothing happened then, and he doesn't believe anything will happen now.
      Kind of makes you wonder if he's got a black file on the politicians he uses for leverage.

    22. Re:The "response" should be an indictment. by NatasRevol · · Score: 1

      Who said they're supported? Read through the comments. No one supports this bullshit.

      But that doesn't mean we're not realistic.

      --
      There are two types of people in the world: Those who crave closure
    23. Re:The "response" should be an indictment. by NatasRevol · · Score: 1

      The FBI doesn't report to congress, so no.

      --
      There are two types of people in the world: Those who crave closure
    24. Re:The "response" should be an indictment. by Demena · · Score: 1

      Where do those numbers come from?

    25. Re:The "response" should be an indictment. by dbIII · · Score: 1

      So, well, what is the punishment for high treason?

      You get to run for office with photos of you wrapped in a flag and then when that fails you get a gig as one of the directors of the National Rifle Association.
      That's if high treason is giving classified anti-tank weapons and a pile of other ordinance to Hezbolla less than a year after they blew up over a hundred US Marines.
      These days high treason probably means beating a Russian at chess instead.
      Giving weapons to terrorists (North) or giving away state secrets for sex (Petraeus) just doesn't seem to make the grade when political connections are strong.

    26. Re:The "response" should be an indictment. by dave420 · · Score: 1

      You are confusing "slashdotters who have replied to this thread" with "All Americans". That is not going to do you any favours, as it just takes one American supporting this tripe for your claim to be false. Try to ditch the hyperbole and exaggerations - if your argument is sound that won't hurt it one iota.

  11. Ahem by Anonymous Coward · · Score: 0

    Someone might wish to bring his attention to Bouncy Castle...
    https://www.bouncycastle.org/latest_releases.html

    Non US Encryption, so yeah, there's that.

  12. Black Hat Herring by lylefile · · Score: 3, Interesting

    The issue isn't whether the rest of the world would use it. The question is how long until the backdoor is hacked. Knowing its there will make it a prime target. Is the US government willing to back up its confidence with a guarantee to reimbursed all losses for everyone using this technology? Only then could the claim that it wouldn't "cause any commercial problems" be at all plausible.

    1. Re:Black Hat Herring by msauve · · Score: 1

      "Is the US government willing to back up its confidence with a guarantee to reimbursed all losses for everyone using this technology?"

      You do realize that simply ends up being taxpayers footing the bill.

      Better to hold CIA director John Brennan, and those congresscritters who support such backdoors personally responsible for the consequences of their actions..

      --
      "National Security is the chief cause of national insecurity." - Celine's First Law
    2. Re:Black Hat Herring by bluefoxlucid · · Score: 1

      You do realize that simply ends up being taxpayers footing the bill.

      Most people think money is wealth, and don't believe in labor and production. They think you work for money, and don't think about where all the shit they're buying comes from (aside from "CHINA!").

      You can't eat money, as much as everyone seems to want to.

  13. Mr. Gorbachev by Anonymous Coward · · Score: 0

    I guess he not only tore down that wall on command, he must also have executed all of the USSR's cryptologists. And their children. And blinded all the babies so they couldn't learn anything about cryptography.

    Nice work, Brennan. I can only hope your attempt to hoodwink congressmen into believing your crap didn't work.

  14. Countries outside the US are only theoretical by presidenteloco · · Score: 3, Funny

    Would be only a slight generalization of his view point.

    A lot of people think this is how Americans think about the rest of the world.

    We've heard it's out there, but it doesn't matter very much, as long as they have a McDonalds, a 7-11, and a Starbucks.

    --

    Where are we going and why are we in a handbasket?
    1. Re:Countries outside the US are only theoretical by PCM2 · · Score: 1

      The irony is that 7-Eleven is a Japanese company.

      --
      Breakfast served all day!
    2. Re:Countries outside the US are only theoretical by Darinbob · · Score: 1

      Everything is theoretical. Theoretically, setting off a bomb in my basement would cause a lot of unnecessary damage. Theoretically, invading a country would damage diplomatic efforts with that country.

      I think Brennan is using this word to confuse congress. They'll think "oh, it's just a theory, like evolution and climate change, so we can ignore it."

    3. Re:Countries outside the US are only theoretical by Carewolf · · Score: 1

      Would be only a slight generalization of his view point.

      A lot of people think this is how Americans think about the rest of the world.

      We've heard it's out there, but it doesn't matter very much, as long as they have a McDonalds, a 7-11, and a Starbucks.

      We are talking about people who believe the Super Bowl is some kind of world wide event, that people who haven't been culturally brainwashed to watch the most boring sport in world would watch. And who considers the NHL a world championship.

    4. Re:Countries outside the US are only theoretical by AK+Marc · · Score: 1

      https://en.wikipedia.org/wiki/... 7-Eleven is a US company. The owners changed in the '90s when Southland went bankrupt, but the HQ is, and has always been in the US (unless you count the holding company, who changed their name to match).

  15. Isn't GnuPG German? by HawkinsD · · Score: 4, Informative

    Hold up there a minute, Mr SpyMaster. I think GnuPG (open-source implementation of PGP) is German. Or at least: " g10code GmbH, the legal entity employing some of the GnuPG hackers" is German.

    My company has been using GnuPG for ten years.

    See https://gnupg.org/ .

    --
    Never attribute to malice that which can be explained by mere idiocy.
    1. Re:Isn't GnuPG German? by Richard_at_work · · Score: 1

      Britains GCHQ came up with public key encryption years before others, so its not as if the rest of the world cant do encryption theory...

    2. Re:Isn't GnuPG German? by Anonymous Coward · · Score: 0

      And this is the case because we have already tried pretty much this exact thing... back when "export grade" encryption was a thing everybody could started developing and distributing from Europe. I'm sure the same thing will happen (though likely on a larger scale) if we try the same experiment again.

    3. Re:Isn't GnuPG German? by Anonymous Coward · · Score: 2, Informative

      Also AES is based on Rijndael which was created by a couple of Belgium cryptographers lol

    4. Re:Isn't GnuPG German? by BitZtream · · Score: 1

      . . So your talking about software which is a OSS REIMPLEMENTATION of software written in America. So, his point is 100% true in relation to PGP. You simply don't understand the roots of the germen implementation.

      Now this bullshit about encryption back doors and export restrictions are EXACTLY why GnuPG exists.

      --
      Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
    5. Re:Isn't GnuPG German? by Anonymous Coward · · Score: 0

      Yeah, but all know the Germans can't do crypto, right? I mean, that Enigma machine was cake to break. You didn't have to steal one on a sub and reverse engineer it or anything. It was just crap. LOL.

    6. Re:Isn't GnuPG German? by Anonymous Coward · · Score: 0

      AES is based on the Rijndael cipher[5] developed by two Belgian cryptographers, Joan Daemen and Vincent Rijmen
      https://en.wikipedia.org/wiki/...

  16. Can't decide by fyngyrz · · Score: 5, Insightful

    I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

    I readily admit this is not an uncommon reaction of mine when I read of the things presented by elected and appointed officials. The US government is a madhouse.

    --
    I've fallen off your lawn, and I can't get up.
    1. Re:Can't decide by Jawnn · · Score: 4, Insightful

      I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

      Judging by the universal cringe displayed by all the analysts and technicians who an actual understanding of crypto, I'd go with "a little of both". I just can't believe he's so clueless as to not understand that math doesn't recognize lines on a map, nor can I quite believe he didn't expect to get called out on his bullshit. Either way, it was a dumbass thing to say.

    2. Re:Can't decide by CrashNBrn · · Score: 1

      I'm opting for F'N-Batshit-Crazy - which could include him thinking everyone else is stupid.

    3. Re:Can't decide by bluefoxlucid · · Score: 4, Insightful

      If he's incompetent, the President should dismiss him from his post. (Executive)

      If he's lying, Congress can impeach him.

      Being so severely wrong so often is hazardous to your health.

    4. Re:Can't decide by Cro+Magnon · · Score: 4, Insightful

      I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

      The two aren't mutually exclusive.

      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
    5. Re:Can't decide by lgw · · Score: 0

      I see that you use this slur a lot.

      If you're American yourself, please stop taking your self-hatred out on those around you. Find a therapist instead.

      If not, carry on. Yay patriotism! But do have the courtesy to call out what team you do root for: it's unfair to mock one team without allowing the same in return.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    6. Re:Can't decide by whoever57 · · Score: 4, Insightful

      I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

      He thinks enough people are stupid, and, unfortunately, he isn't wrong about that.

      --
      The real "Libtards" are the Libertarians!
    7. Re:Can't decide by kheldan · · Score: 3, Interesting

      He's the head honcho of the freakin' CIA, of course he thinks everyone else is stupid, especially politicians! How else other than overweening arrogance and likely a liberal amount of narcissism do you think someone gets that job in the first place? Strong work ethic? A strong sense of justice? LOL no, more likely successfully backstabbing all the competition and covering his tracks so thoroughly that nobody could pin anything on him!

      --
      Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
    8. Re:Can't decide by zlives · · Score: 2, Informative

      actually i would say he was telling the 100% truth. The target for backdoor is compliant American citizens that would only purchase approved and not legally blocked soft/hardware. This has nothing to do with terrorists, corporations or any one with any knowledge at all.

    9. Re:Can't decide by ceoyoyo · · Score: 3, Insightful

      Why does he have to root for a team? The US has a history, especially in cryptography, of assuming that the rest of the world is hopelessly behind them. Remember the export ban on strong cryptography? Remember the t-shirts with the RSA algorithm printed on them? This is just another aspect of the same thing. If the US doesn't provide the crypto, there's nobody else to get it from. Obviously.

    10. Re:Can't decide by cayenne8 · · Score: 5, Insightful

      I just can't believe he's so clueless as to not understand that math doesn't recognize lines on a map, nor can I quite believe he didn't expect to get called out on his bullshit.

      Well, it isn't HIS cluelessness that is the problem here..is the his audience...the US Senators/CongressCritters that he speaks to in these hearings.

      See, they are the ones that pass the laws that could mandate weakening software and forcing backdoors.

      He may know perfectly well that this is a false and stupid thing to say, but it IS something the TLA's want badly...so, he tells them this and they think that it won't cause harm to US businesses, and they have, instead, just helped to fight the terrorists...and have their constituents be happy about this.

      It is the ignorance of the lawmakers that you have to worry about.....and unfortunately they're getting their information from a guy like this, that wants what he wants, no matter the cost to business or the constitution.

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    11. Re:Can't decide by Anonymous Coward · · Score: 0

      He knows that his audience - in this case the government - IS stupid.

    12. Re:Can't decide by lgw · · Score: 2

      "The US"? Each individual living here? Including all the US cryptographers pointing out how silly this was, and selling T-shirts?

      Stereotyping whole countries by their sillier government acts is fine if were doing patriotic trash-talking, like calling people "Murcans" or "cheese-eating surrender monkeys" or "I know he wasn't Canadian, or he would have apologized afterwards". That's just being silly, but if you're going to do that, it's rude not to identify your side.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    13. Re:Can't decide by unrtst · · Score: 1

      If he's incompetent, the President should dismiss him from his post. (Executive)

      If he's lying, Congress can impeach him.

      Being so severely wrong so often is hazardous to your health.

      And when neither happens, then similar rules apply to both the President and Congress. This eventually trickles down to blaming the voters. The majority of voters are currently proving that point quite well in their handling of the current presidential election, so this should be no surprise to anyone that's conscious.

    14. Re:Can't decide by ceoyoyo · · Score: 1

      It's fairly common custom to use the name of a country when referring to official actions undertaken by that country. For example, "the US invaded Iraq."

      In the specific case of a democracy, official policy is determined by the government, which is elected by the citizenry, so collective responsibility for national activities can be ascribed to those citizens, if you're into that kind of thing.

    15. Re:Can't decide by lgw · · Score: 0

      Sure, but you're saying "the US" and he's using the slur "Murcans", which is what I was objecting to: the trash talking. He uses it a lot.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    16. Re:Can't decide by myowntrueself · · Score: 3, Insightful

      I see that you use this slur a lot.

      If you're American yourself, please stop taking your self-hatred out on those around you. Find a therapist instead.

      If not, carry on. Yay patriotism! But do have the courtesy to call out what team you do root for: it's unfair to mock one team without allowing the same in return.

      I honestly don't root for any team. IMO all governments are really just organized crime syndicates.

      --
      In the free world the media isn't government run; the government is media run.
    17. Re:Can't decide by BitZtream · · Score: 1

      Considering AES is a product of Sweden, he's stupid at a minimum for thinking that bullshit would fly, and he's CIA so you know for a fact that he thinks your stupid and he's lying.

      --
      Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
    18. Re:Can't decide by Anonymous Coward · · Score: 0

      It's official guys - Only America has mathematicians or any concept of math. The rest of the world is too stupid to come up with a working system of numbers.
      People don't move out of America. There's no such thing as emigration from America. We're safe knowing the mathematicians are all here and they'll stay here forever. Math will never be invented anywhere else.

      This is arrogance beyond all comprehension or common sense, and these people are in charge.

      I just can't...

    19. Re:Can't decide by bluefoxlucid · · Score: 1

      I wish they'd let citizens debate a stand-in and then give a pass or fail to debate presidential and congressional candidates. I like the argument about how Trump can't debate Bernie on policy, but Bernie can't debate Trump on finances (where is Bernie getting all this money?), because I can actually develop economic policy *and* show exactly where the money's coming from. I would break Trump in a policy debate and, honestly, sometimes I just want to crush *someone*.

    20. Re:Can't decide by Anonymous Coward · · Score: 0

      "Murcans" is offensive? Goddamn people are touchy these days.

    21. Re:Can't decide by Anonymous Coward · · Score: 5, Insightful

      I can understand how you'd make that mistake, but he's not clueless. It's much worse than that.

      He's a man who knows that no one can challenge the power that he's amassed for himself, because the establishment is on his side. Surveillance is just a fact of life now, some people aren't going to give up their Facebook accounts until they die and he's grinning like the shit-eater he really is, because he's getting paid to take away the same freedoms they claimed they were "defending" after September 11th happened. People are legally required to pay money out of pocket straight into the hands of the same people who are supressing their rights to privacy and free speech.

      If you knew that you were taken care of for life and there were no consequences to anything you did, no matter how horrendous, how would you act? These are the same people that had pictures of their torture at Abu Ghraib published around the world, a thousand-plus-page report on their methods published around the world and what did people do? Fuck all nothing, that's what. Brennan has that grin because he knows nobody is challenging him any time soon, period.

    22. Re:Can't decide by lgw · · Score: 1, Troll

      "Murcans" is offensive? Goddamn people are touchy these days.

      I'm not offended by trash-talking -- that's all good fun, like your mother said last night -- but I am offended when people trash-talk their own country.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    23. Re:Can't decide by Anonymous Coward · · Score: 0

      It sounds more like he's misrepresenting data to push an agenda.

      Chances are what he said is 100% true right now.

      What was unsaid is that it's only true because crypto requires high attention to detail so usually you want to use a well verified implementation rather than rolling your own, and having a third party develop your crypto app means adding anotehr entry on your list of people who can screw you over if they lied to you about their intentions. However adding a backdoor to it renders it largely useless so, and thus creates the market for non US actors to implement their own non-backdoored crypto and "theoretical" will become "is availabe on the 'dark-web'" within a short span, possibly less than it takes for Congress to pass the bill.

    24. Re:Can't decide by ceoyoyo · · Score: 2

      "Americans" is the collective term for citizens of the United States of America. "'Murricans" is a mild slur of "Americans." Americans are collectively responsible for this ass holding office. As such, he's representing you to the world when he says that the rest of the world is too dumb to implement encryption without American help.

      Use of the slur seems reasonable in this case. If you collectively don't like it, get rid of the jerk. If you individually don't like it, stop taking criticism of the collective personally. Perhaps you like feeling proud of being an American when your country does something good, but you'd rather pass the buck when they do something asinine?

    25. Re: Can't decide by Anonymous Coward · · Score: 0

      How about 'merkins, is that offensive?

    26. Re:Can't decide by Rakarra · · Score: 1

      It's intentionally insulting. Yeah, it's not majorly insulting, just something to make the eyes roll a bit at his immaturity. He wouldn't have used it if he wasn't trying to be insulting. That's the entire point.

    27. Re: Can't decide by Anonymous Coward · · Score: 0

      Tough shit.

      We're not obligated to support the policies of your candidate merely because he won the election.

      Winning an election doesn't grant one a waiver from criticism, jackass.

    28. Re:Can't decide by Anonymous Coward · · Score: 0

      There's no such thing as emigration from America.

      This is true but not in the way you meant it. At least if you want to stay in the developed world good fucking luck finding a country that will let you move in with nothing but the clothes on your back.

    29. Re: Can't decide by Anonymous Coward · · Score: 0

      Said trash-talking is clearly aimed at the so-called 'murcans', ie the retards that regurgitate such nonsense about superiority.

      If you took offence to that, it's on you.

    30. Re:Can't decide by compro01 · · Score: 4, Informative

      Not sure where you're getting Sweden from, as Daemen and Rijmen are from Belgium and work at a Belgian university.

      --
      upon the advice of my lawyer, i have no sig at this time
    31. Re:Can't decide by FlyHelicopters · · Score: 1

      I would break Trump in a policy debate and, honestly, sometimes I just want to crush *someone*.

      And he would break you in the game of persuasion... which he is quite good at....

      You're assuming the average person cares about policy details, facts, and logic... they don't...

    32. Re:Can't decide by Anonymous Coward · · Score: 0

      What if they (NSA, CIA) are blackmailing the politicians with information that they... wouldn't want to get out
       
      Maybe I've watched too much Sherlock

    33. Re:Can't decide by Anonymous Coward · · Score: 0

      It wasn't clear to me that OP intended that 'or' as an exclusive or.

    34. Re: Can't decide by Anonymous Coward · · Score: 0

      Force a back door and every enemy in the World now has access to that back door. There's no alternative to safe and redundant and opaque encryption to keep our economy safe. The person we need to educate is the President, so he can shout down his underlings.

    35. Re:Can't decide by Anonymous Coward · · Score: 0

      Honestly if you are going to insult and generalize the entire population of America in the interests of proving you're not a hypocrite you should tell us where you are from.

      I am willing to bet that your country has at least one ahole running the show, and it would be fair play to point out how you haven't gotten rid of your ahole yet either.

      So my good friend, where do you hail from?

    36. Re:Can't decide by Anonymous Coward · · Score: 0

      I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

      Fascist? Totalitarian? I dare say talking about this in terms of stupidity is dangerously naive.

    37. Re: Can't decide by lgw · · Score: 0

      Apparently you don't understand the difference between criticism and trash-talking, nor the different between trash-talking one politician and the country that you live in. That's rather sad, really.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    38. Re:Can't decide by Anonymous Coward · · Score: 1

      Yeah, that's why there are so many Clipper devices deployed right? /s

      BTW, who came up with the AES algorithm? Was that the United States? lol

    39. Re:Can't decide by Anonymous Coward · · Score: 0

      North Korea, Iran, and Venezuela are considered "democracies" in name. Doesn't mean they are one. Same with the US. The Dems and the Reps are private entities and are showing that they can choose their candidate regardless of how people voted. The real voter system, when one votes for the candidate doesn't even allow for write-ins. I wouldn't be surprised if elections get tossed in a future year, and Congress seats just go up for auction, and toss any pretenses of voting.

      Don't blame the US citizens for what the government does. Iraq had zero popular support, for example. Also, when you see people talk about guns, 99% of the population is hoping the next President will pass some gun bans like Australia as soon as she gets office. Again, what you might read on the news isn't what the country is like.

    40. Re:Can't decide by Anonymous Coward · · Score: 0

      He's a politician. He not only thinks
      a) everyone else is stupid
      , but
      b) it's safer to sleep at night,

      than to consider there are rogue mathematicians, and crypto-analysts in the world, creating unknown designs, ciphers and mechanisms the CIA or NSA, don't know about.

      It is in his interest, and his especially interest to Congress... but certainly not the US overall, to assume everyone else on the planet is stupid, inferior and wholly reliant on the US for encryption.

    41. Re:Can't decide by Livius · · Score: 1

      Or, he is both lying and incompetent, and he's showing off how powerful he is in comparison to mere citizens by the fact that he will face none of those consequences.

    42. Re:Can't decide by Anonymous Coward · · Score: 0

      Mind blown!

    43. Re: Can't decide by Anonymous Coward · · Score: 0

      here! here!

      suck it up buttercup!

    44. Re:Can't decide by Anonymous Coward · · Score: 0

      LOL

      Goddamn grammar nazi!

      save your sanctimonious murrican crap for the 1 million muslim immigrants ... cuz you're gonna need it if their wacco nutjob kids keep pulsing :(

    45. Re:Can't decide by Anonymous Coward · · Score: 0

      You, sir, are totally correct.

      Sadly, like most folks, you miss the point completely.

      in politics, the BEST LIAR always wins. PERIOD

      this lie is just one more seed for the "ID ten T" crowd (idiot politicians) to slurp up and act on.

      think of the children ...

    46. Re:Can't decide by JenovaSynthesis · · Score: 1

      Yeah. I guess he never heard of the 16 year old Irish girl who came up with an encryption method better than what RSA was using at the time.

      --
      Anonymous Cowards generally receive no replies because you're a coward and I'm a bitch :)
    47. Re:Can't decide by Anonymous Coward · · Score: 1

      He may know perfectly well that this is a false and stupid thing to say, but it IS something the TLA's want badly...so, he tells them this and they think that it won't cause harm to US businesses, and they have, instead, just helped to fight the terrorists...and have their constituents be happy about this.

      I have this theory that if the anti-backdoor people really want the least harm in the long run, the right answer is to let the pro-backdoor people have their way in the short run. Really, think about how it will play out.

    48. Re:Can't decide by Anonymous Coward · · Score: 0

      If he's lying, Congress can impeach him.

      Isn't it nice to know how many options Congress has. Why, look at all the wonderful choices they have made over the years.

      The detail of the how and why he is lying can be summed up by the TLA CYA that is perhaps ironically related to the controversial use of the compound word "backdoor". This is just another person in the highest level of responsibility, who will verbally trash the 4th ammendment and every other protection of civil liberties, because 10 years from now, when another child is raped, and another terrorist commits a crowdstrike, he can say "I wanted to do sneak and peaks on every citizens house at least once per fortnight, but those pedophile, terrorist protecting civil libertarians just wouldn't let me SAVE THE CHILDREN. And he also gets to take home a healthy paycheck and not have difficulties making his mortgage payments all the while. It's not really THAT complicated.

      Of course as principled as I like to consider myself, if I found myself unable to opt out of such a position of responsibility and authority amidst the sea of diseducation that the NSA and CIA have been sowing for so long... Hell, I think my fear of crucifixion would lead me to be just as much of a hypocrite.

    49. Re:Can't decide by meerling · · Score: 1

      Definitely both

    50. Re: Can't decide by Anonymous Coward · · Score: 0

      They're not mutually exclusive.

    51. Re:Can't decide by Anonymous Coward · · Score: 0

      What do you mean, they are not the same country? :p

    52. Re: Can't decide by backslashdot · · Score: 1

      Yeah cause governments don't double down on failure and blame something else?

    53. Re:Can't decide by Anonymous Coward · · Score: 0

      If he's incompetent, the President should dismiss him from his post. (Executive)

      If he's lying, Congress can impeach him.

      Being so severely wrong so often is hazardous to your health.

      Really, the president dismiss him? You can't be serious. This president didn't choose him in a vacuum. Do any of you watch Person of Interest?
      Sincerely
      Anonymous Coward

    54. Re:Can't decide by jcr · · Score: 1, Funny

      I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

      These are not mutually exclusive.

      Idiots are often shockingly arrogant.

      -jcr

      --
      The only title of honor that a tyrant can grant is "Enemy of the State."
    55. Re:Can't decide by CanadianMacFan · · Score: 1

      Or he's smart because he's telling the Senators exactly what they want to hear.

    56. Re:Can't decide by rtb61 · · Score: 1

      In this case the underlying claim behind "US companies dominate the international market as far as encryption technologies that are available through these various apps, and I think we will continue to dominate them,", is extremely threatening. The US under the guise of the North American Territorial Occupation farce is also claiming cross border hacking is a declaration of war and should result in a military strike. So that claim of dominance is really pushing the bound of , block our backdoors and we will consider you a foreign threat and take you out. Pushing dominance brooks no peace, brooks no diplomacy, preserving dominance demands killing all opposition in the most bloody and violent manner possible to send a message. That maroon is an idiot threat to world peace and should be put out to pasture, where he can grumble and makes threats at passing flies and annoying weeds. Keep talking the demand for dominance America and everyone is going to tell you to fuck off.

      --
      Chaos - everything, everywhere, everywhen
    57. Re:Can't decide by AchilleTalon · · Score: 1

      That's why lobbying exists. I cannot believe the Senators were not 'educated' on the matter by the enterprises with interests in this law to not pass.

      --
      Achille Talon
      Hop!
    58. Re:Can't decide by Anonymous Coward · · Score: 0

      I readily admit this is not an uncommon reaction of mine when I read of the things presented by elected and appointed officials. The US government is a madhouse.

      It's just as Upton Sinclair said, "It is difficult to get a man to understand something, when his salary depends upon his not understanding it." That really explains much of what goes on in Congressional hearings and our halls of government. My own personal theory is that there are three main reasons why we're not yet living in a fascist state. First, Americans are ingenious and industrious whether that means starting new businesses, creating new technologies or yes, finding ways around laws and government regulations. Second, our government is woefully incompetent and inefficient which prevents it from being as effective with the resources it confiscates from us as it otherwise might be. Third and finally, the US Government has so many enemies these days that they cannot give even a fraction of them their full attention, which follows from reason two.

    59. Re: Can't decide by Anonymous Coward · · Score: 0

      Sweeden, Belgium, it's all the same socialist evil middle-eastern country. Prime example of the average understanding of 'the rest of the world' by natives. But I bet poster can name all the major sports team names for the 50 US states

    60. Re: Can't decide by Anonymous Coward · · Score: 0

      Are you the brother of the guy who thinks AES was invented in Sweeden?

    61. Re:Can't decide by ultranova · · Score: 1

      I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

      Probably neither. We're witnessing the equivalent of climate change "scepticism": he has a position based on ideology which happens to disagree with reality, yet has to convince other people it's nonetheless true, so he'll simply say any excuse he can think of in hopes one of them sticks.

      --

      Forget magic. Any technology distinguishable from divine power is insufficiently advanced.

    62. Re:Can't decide by Anonymous Coward · · Score: 0

      Those two options are not mutually exclusive. In fact, they are strongly associated with each other.

    63. Re: Can't decide by LinuxLuver · · Score: 1

      Maybe he knows something we don't know. Like... They have managed to compromise - somehow - almost every encryption method out there. Or he wants us to believe they have. Around and around we go on that one.

      --
      Only boring people are ever bored.
    64. Re:Can't decide by RockDoctor · · Score: 1

      I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

      That's an inclusive-OR, isn't it. I.E. Brennan is that stupid, and he thinks everyone else is stupid enough to swallow this line.

      Didn't the German state invest some money in paying for development of GPG a few years ago? So shouldn't the German Ambassador be creating a diplomatic incident out of this?

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
    65. Re: Can't decide by Anonymous Coward · · Score: 0

      True. Another way to think about it with some minor comic relief would be thinking he's pulling a Charlie Sheen during his "Tiger Blood" phase.

      aka: "Winning!!!!!11"

    66. Re:Can't decide by Anonymous Coward · · Score: 0

      If you knew that you were taken care of for life and there were no consequences to anything you did, no matter how horrendous, how would you act?

      I'd still think long and hard about the consequences to others, for one because I happen to believe that what goes around comes around, eventually. There's also that I'm a technician at heart and if you're looking at that level of government, while suboptimal situations for some cogs^Wcitizens may be tolerable, suboptimality for all cogs means a barely-to-really-not-at-all working society.

      But that's just me, and yes, many people in positions of power are there exactly to learn this lesson. Which is why I'm not there and they are.

    67. Re:Can't decide by bluefoxlucid · · Score: 2

      Trump is good at persuasion and negotiation; it's part of business.

      You're assuming the average person cares about policy details, facts, and logic... they don't...

      The problem comes when you lay out facts and logic in short, concise form in front of someone people look to for leadership, and his only response is, "Uh, I don't believe that." You can get away with that to a very limited degree, even with the authority of popularity behind you; it's impossible to continue to look good when your attacks are cleanly parried and reversed.

      Take Trump's talk about immigration, for example. Trump said we let hundreds of thousands of Muslim immigrants into this country, and "hundreds" of they and their children have been implicated in acts of terror. Pundits are yelling a lot of "No Mr. Trump, you're wrong and stupid," pointing out that the Orlando shooter's parents moved to America 25 years ago and he was born and raised American, so there's no sensible way to pre-screen this. Of course nobody buys into that.

      We associate terrorism with murder.

      In the United States, we have 4.9 murders per 100,000 people per year. Of 783,000 Muslim refugees from Afghanistan and Iran in the past 15 years, three (3) have been implicated in terrorism. Over 15 years, we've stocked 2.77 million Muslim immigrants and their children, including those refugees. If only 100 are implicated in terrorism, then any single full-blooded American is TWENTY TIMES as likely to be a murderer as one of these Americanized Muslims. Even if as many as 2,000 were implicated as terrorists--which even Trump hasn't claimed--that's still a lower rate of murderers among Muslim American immigrants than all other Americans.

      You pull something like that. It puts Trump on the defensive. Now he has to say something about how a non-immigrant American is way more likely to murder you than a Muslim immigrant, but not really, because Islam; or he has to just claim whatever you just said isn't true, somehow. You pull out all your contorted logic *after* you put him on defense. Trump argued that Muslims don't turn in their own; the FBI says otherwise. This is where you pull out the logical argument that someone born and raised American for the whole 20 years of his life and radicalized over the Internet by out-of-country extremists isn't a threat we missed when his parents immigrated here.

      You don't go in and say, "Let's think about this rationally: do you really believe there's a checkbox that says you plan to raise a child to be a fifth-column terrorist while you're here in America?" You quickly and sharply pull out facts-and-figures, something hard that will nudge him off-balance. Then, before he recovers, you hit him with every other proposition; the audience will just see a clown stumbling around on stage. If you start with something that doesn't solidly undermine his argument and force a response, you'll just get mocked for having a differing and sheltered opinion, and then *you* look stupid, which means no one's convinced you have a clue what's going on.

      I like economic policy though.

      Trump's entire argument against Bernie-style policies (e.g. a UBI) is funding: where do you get the money? I can actually tackle that (Bernie can't; he has undeveloped ideals with lots of holes, most of which are legitimately dangerous). This is a *huge* problem for Trump, because his entire line of debate would be undermined: for any attack he has, I can give a short and concrete answer.

      Not only can I answer for funding problems, but I can also cite and control immigration risks, fanciful unemployment risks, and risks of diminishing the support of our existing system. My arguments for a Citizen's Dividend include that it establishes a basic standard-of-living and worker protection via a non-wage income stream, which avoids the job loss and reduction of consumer buying power cause

    68. Re:Can't decide by dave420 · · Score: 1

      You frequently make mistakes a few seconds of googling would solve... You might want to replace your hubris with something more useful.

    69. Re:Can't decide by beastofburdon · · Score: 1

      The answer is generally that they think you are stupid. History also agrees with them on most subjects too.

    70. Re:Can't decide by beastofburdon · · Score: 1

      That is not an if, that is a guarantee.

    71. Re:Can't decide by FlyHelicopters · · Score: 1

      In the United States, we have 4.9 murders per 100,000 people per year. Of 783,000 Muslim refugees from Afghanistan and Iran in the past 15 years, three (3) have been implicated in terrorism. Over 15 years, we've stocked 2.77 million Muslim immigrants and their children, including those refugees. If only 100 are implicated in terrorism, then any single full-blooded American is TWENTY TIMES as likely to be a murderer as one of these Americanized Muslims. Even if as many as 2,000 were implicated as terrorists--which even Trump hasn't claimed--that's still a lower rate of murderers among Muslim American immigrants than all other Americans.

      You pull something like that. It puts Trump on the defensive.

      No, he'll respond with a funny comeback, everyone will laugh, and completely forget all that boring stuff you said.

    72. Re:Can't decide by bluefoxlucid · · Score: 1

      Depends on how you structure it. That up there is a lot to read; it's not a lot to say. You can abridge some of the numbers, let Trump try to call your bluff, then dump more numbers (that happens when you just say something like, "Over the past 15 years with millions of Muslim immigrants, all we've found is that any given American is twenty times as likely to murder you as the next Muslim immigrant!"). Taking the bait on a bluff like that gets the audience smiling and waiting to see what ridiculous shit your opponent pulls out... unless they pull out something concrete.

      As for making a funny comeback, well... that works equally as well both ways. If Trump draws up this mean dialogue about how Mexicans will rape your 8-year-old daughter and then stuff her full of cocaine to traffic over the border, a silly quip about how Trump seems disturbingly obsessed with sticking things in third-grade girls will come off as flippant and uncaring. It belittles the audience, because it's a blatant grab for their attention and support; you need some kind of substance. Part of it also relies on how well you can show, and a couple jokers doesn't work too well; the risk of being *the* joker is your opponent might just call you on it, pointing out that you're showing a lack of real concern for real issues--in other words, claiming that you don't really care about the things the audience finds important, and thus that you don't stand with them.

    73. Re:Can't decide by slashdotwannabe · · Score: 1

      I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

      He's giving the Senators plausible cover stories to protect themselves for when they vote for bills that would write mandatory backdoors into law. That's not stupid; that's playing the game masterfully.

      Never, ever, think of your enemy as stupid -- even if s/he appears to be, even if s/he IS -- as it will cause you to underestimate them. Always assume that what appears to be their stupidity is a deception, and look at it until you find it. If you cannot find it, assume that it is YOU that is being stupid.

      --
      This comment is my opinion and does not represent an official position of Donald Trump or others I do not work for
    74. Re:Can't decide by slashdotwannabe · · Score: 1

      I'm not offended by trash-talking -- that's all good fun, like your mother said last night -- but I am offended when people trash-talk their own country.

      Huh. You know what I'm offended by? Fucking morons who vote against their interests because the lies they're fed make them feel good. Idiots who don't bother to fact-check the bullshit they're eating by the bucketload because it allows them to see themselves as better than someone. Asswipes who think "my country, right or wrong". In other words, 'Muricans.

      I'm an AMERICAN. I read both sides of every issue. I fact-check sources. I follow the money. My priorities are Conscience, Country, God, (Party?), NOT God, Party, Country, (Conscience?). I understand Cui Bono is the basis for nearly everything someone paid for me to see. I do the work required of a Citizen of this country and take it as my sacred duty... and 'Muricans fucking PISS ME OFF. They make us look stupid. They give other countries a reason to doubt our global leadership and the very notion of Democracy itself (for example, the very popular belief in China that a Technocracy is much better than a Democracy, the United States being the number one example of why). They are a threat to our very existence, blithely voting in dumbfuck ideas that shit all over the Constitution like arresting reporters and protesters, a Mexican border wall or banning Muslims because it makes them feel good.

      But yea, you go ahead and be offended by people who trash-talk their country, because the Lord knows that YOUR country can do no wrong, and in the case of the United States, the First Amendment doesn't apply to people who offend your sensibilities...

      --
      This comment is my opinion and does not represent an official position of Donald Trump or others I do not work for
    75. Re: Can't decide by Anonymous Coward · · Score: 0

      Brennamn on encryption:

      "He either doesn't get it or he gets it way better than anyone else"...

      âoeLook, weâ(TM)re led by a man that either is not tough, not smart, or heâ(TM)s got something else in mind. And the something else in mind â" you know, people canâ(TM)t believe it,â ...Sounds like trumpon Obama. (I know Its a stretch, but the fearmongferinf 'murica' first sure has seem the same tone)

      Not sure what that means, other than yet another example of 'the gov'ment' thinking we're all idiots.

    76. Re: Can't decide by Anonymous Coward · · Score: 0

      You should've said "obviously (/sarcasm)" it came through loud and clear, to mw but...

      Cheers

    77. Re: Can't decide by Anonymous Coward · · Score: 0

      "Chances are what he said is 100% true right now."...

      Sry but the vast majority of experts- people that understand and focus on the real theory/ math behind modern cryptography and cryptanalysts- totally disagree with you...

      And even if they didn't (again, they do), strong crypro from U.S. sources had already been disseminated throughout the world, starting with Zimmerman and PGP (or earlier, like Lucifer in the 70s). The genie is out of the bottle, and irt won't be put back in by a couple of laws created by non--expert congressmen and US gov apologists that lack the basic facilities to understand the technology...

      Its (in the words of Schernier) "security theater"- but worse, since it actrually does harm instead of just doing no good at all.

      I know that this is beating a dead horse, but: strong CRYPTO makes us SAFER, not more vulnerable even from terrorists...

    78. Re: Can't decide by Anonymous Coward · · Score: 0

      "Yeah. I guess he never heard of the 16 year old Irish girl who came up with an encryption method better than what RSA was using at the time."

      What, a one time pad?

      Genius!!! (/sarcasm)

      I have a 100% unbreakable form of crypto. (OTP). Except ya could probably beat it (me) with a rubber hose.

      Lol

  17. Dear Mr. Brennan by Opportunist · · Score: 1

    Jonny, listen. There is a thing called "compiler". That's a program that lets anyone around the globe take source code, that is like some sort of text that anyone who knows how to program can read (trust me on that one, anyone who can program can read this stuff. Just because you can't doesn't mean nobody else can, there is intelligence outside of your agency on the planet, ya know? Some of it even in people). That source code can also be changed by people who can read it. And then they put that source code into a compiler.

    What this means for your backdoor is that even if there was only 'murrican code (which there isn't, but let's play pretend as you usually do) is that your backdoor gets ripped out of that code, tossed onto the pile of junk code where it belongs and you're standing outside the door.

    You AND your industry.

    Because if I can easily create a non-broken version of your code, why the hell should I use yours which is inferior?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Dear Mr. Brennan by rlp · · Score: 1

      'Compiler' you say, yeah about that ... https://www.ece.cmu.edu/~gange...

      --
      [Insert pithy quote here]
    2. Re:Dear Mr. Brennan by Opportunist · · Score: 2

      That you audit the compiler first is a given. I mean, no later than this it's a given that the first thing you do when auditing source code is auditing the compiler for it.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    3. Re:Dear Mr. Brennan by Megol · · Score: 1

      Yes and the problem (theoretically) applies even to assembly code on a bare-bone system without an OS. It's actually worse than that for many systems as many have embedded control processors for power control, supporting secure boot etc.

      Which is why the idea of open-source hardware is attractive even if it in itself doesn't plug all potential security holes...

    4. Re:Dear Mr. Brennan by Opportunist · · Score: 1

      Even if OS-Hardware had security holes, at least it won't have security holes placed there intentionally. Accidental security holes may be known to your adversary. Deliberate security holes are by definition known to your adversary.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    5. Re:Dear Mr. Brennan by Demena · · Score: 1

      And correct policy would be to assume that that they are known. Any important messages are handled by cipher not encryption. By any sensible agency. They are not after the professionals but the amateurs. The motives here are deeper than we are discussing.

  18. what this idiot dont get is by FudRucker · · Score: 2

    if the Government spooks & goons can peek at your stuff then the criminals that are good at cybercrime will find a way to crack the key to the Government's backdoor

    --
    Politics is Treachery, Religion is Brainwashing
    1. Re:what this idiot dont get is by Nethemas+the+Great · · Score: 1

      You make the probably invalid assumption that they care.

      --
      Two of my imaginary friends reproduced once ... with negative results.
  19. threat assessment by micahraleigh · · Score: 2

    The biggest threat to US security is US security.

  20. It's not "theoretical." by BarbaraHudson · · Score: 1

    He shouldn't have said it was just theoretical. After all, how does he know for certain that it doesn't already exist and the US hasn't detected it?

    --
    "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
  21. Slippin Slippin Slippin, into the future... by Anonymous Coward · · Score: 0

    I have a feeling non-US encryption will not be theoretical for long with that attitude.

  22. Warning Labels by Anonymous Coward · · Score: 0

    Software should contain the following warning, taking 50% of the package/screen:

    "WARNING: This software uses intentionally weak encryption. Your data will be vulnerable to brute force attack. You are encouraged NOT to store any critical data using this product, such as SSNs, personal data, HIPPA data, etc. You are encourage to purchase identity theft protection insurance, as you WILL be vulnerable. Identity theft insurance also uses intentionally vulnerable encryption, you are encouraged to store your personal documents in a sock drawer, along with your cash."

  23. Rijndael? by Anonymous Coward · · Score: 1

    Like the "theoretical" encryption Rijndael...?

    1. Re:Rijndael? by Bob+the+Super+Hamste · · Score: 1

      Shut your filthy Commie Islam loving pie hole. /sarcasm

      Although it does look like AES 256 has some problems with related key attacks.

      --
      Time to offend someone
    2. Re:Rijndael? by gweihir · · Score: 1

      Well, banks all over the world use it for the most critical transactions. But since all the money is electronic, I guess in some sense it is "theoretical money" and banking is a "theoretical business".

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    3. Re:Rijndael? by cryptizard · · Score: 1

      There are no significant protocols or implementations that use related keys though, this attack is purely theoretical. Also, 2^100 work is still out of the range of reasonable attackers for the foreseeable future.

    4. Re:Rijndael? by Bob+the+Super+Hamste · · Score: 1

      All true and and effort of ~2^100 is huge requiring massive amounts of energy even on an ideal computer, I believe a significant percentage of the total worldwide energy production for an entire year. My point was that AES 256 is turning out to not be as strong as believed and for this type of attack is weaker than AES 192. There are other options out there but are not as fast but were considered to have a high security margin instead of just a moderate one during the AES competition.

      It may be time to have a new competition to get a new set of algorithms but this time go for some that should hold until the heat death of the universe which would mean a key length in the 540 to 600 bit range (they need to be unbreakable on quantum computers otherwise we could get buy with key lengths in the 270 to 300 bit range). I use these number because even on an ideal computer the universe runs out of energy before the key space can be searched but I forget the exact value as it was a while since I did that calculation and both of those number sound about right.

      --
      Time to offend someone
    5. Re:Rijndael? by cryptizard · · Score: 1

      Interestingly, the reason AES-256 is vulnerable to this related key attack is because it uses a modified key schedule compared to AES-128. AES-128 is not vulnerable to any significant related key attacks, so in that respect it is actually more secure than AES-256. As far as I am aware, the fastest attack in any model against AES-128 runs in time something like 2^125. So, I don't think it is fair to call it quits on AES just yet. Also, some prominent cryptographers like Bruce Schneier have suggested that simple increasing the number of rounds in AES-128 would eliminate most if not all of the attacks on it.

    6. Re:Rijndael? by Nethemas+the+Great · · Score: 1

      AES? You mean the American Encryption System?

      --
      Two of my imaginary friends reproduced once ... with negative results.
    7. Re:Rijndael? by Bob+the+Super+Hamste · · Score: 1

      I have read much the same but a break is a break and the breaks don't get worse over time. Personally I just want to poke the bear as I am getting sick of these attempts to weaken or backdoor encryption and would like to put it beyond their ability to ever have any hope of cracking it unless they get out the jumper cables and car battery. It has been a real concerted effort for almost the last year or so to make it so that people view encryption poorly and let the FBI and CIA have their backdoors and weakened ciphers available for all so they can spy on us.

      --
      Time to offend someone
    8. Re:Rijndael? by Anonymous Coward · · Score: 0

      Banks only care about profit. If they loose 1% due to security problems they don't care about that. The do care about creating the impression that they are secure, that's why banks always have been the most impressive buildings in town, or at least the parts of the building visible to clients.

  24. idioic AND stupid because... by evolutionary · · Score: 3, Insightful

    If it's known there is a backdoor people WILL find it. And the arrogance that only American companies can create encryption libraries is dumbfounding. We have China's Red Flag, edition of Linux, North Korea appearently has "Red Star" and I suspect Russia has their own version of Linux as well. It may a crime to use non-use encryption, but it will be there and used if people fear for their privacy. We recently had an event in France where the CIA tried to claim encryption was used to coordinate their operation, and it turns it...it had nothing to do with coordination. The best people will use method with less technology dependencies. This will only make it easier for people (terrorists or "partner" like China) to go through their backdoors to access data. . We seem to "terrorism" as an excuse for everything the same way we used "communism" in the Mccarthy days. the end doesn't justify the means

    --
    "Imagination is more important than knowledge" - Einstein
    1. Re:idioic AND stupid because... by epine · · Score: 1

      If it's known there is an undiscovered backdoor people WILL find it.

      So what? After you exhume the first backdoor, you no longer know whether additional undiscovered backdoors still exist. Merely finding a backdoor is no guarantee you can exploit it yourself.

      In the security business, if there's a thing, there's ambiguity of the thing. You can't simply make this go away by busting out all-caps at the critical juncture.

      Wait, it gets worse.

      The NSA just needs to get a law passed that a certain piece of equipment must implement an NSA kernel, then install some frightfully devious code that doesn't actually contain a backdoor, so that the security industry can run around in circles failing to break the "known" back door.

      There's no naive like all-caps naive. Accept no substitutes.

    2. Re:idioic AND stupid because... by Anonymous Coward · · Score: 0

      I didn't even see the argument in the statement.

      Try to do X to Y.
      Public backlash.
      But only American Y's exist, we must do X!

      We should explain to these people that the world is a changing place. It doesn't stay the same forever. Their argument would hold for at most a few weeks and then America would be royally fucked.

  25. No, he's right by LichtSpektren · · Score: 4, Funny

    I took a trip to Europe last week. I tried using GPG but it told me that it won't encrypt anything because I'm not in the USA. Then I tried VeraCrypt but it made my hard drive fizzle out.

    1. Re:No, he's right by gweihir · · Score: 1

      Hehehehe, nice.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    2. Re:No, he's right by Anonymous Coward · · Score: 0

      Similar story, I was in Germany and visited microsoft.com site using https. Found out later that Windows 10 tried to rape my mom because of encryption.

      Needless to say, I wasn't a happy camper about the rape thing. But as a taxpayer I'm glad that our intelligence agencies are making everyone aware of this serious issue.

  26. My Apologies by jesse.alan.johnson · · Score: 2

    I would like to apologize on behalf of the American people. Director Brennan clearly has no knowledge on the subject which he is speaking about and was advised poorly by his staff.

  27. AES is Belgian by chill · · Score: 4, Informative

    The name of the algorithm behind AES is Rijndael -- a combination of the names of the Belgian cryptographers who developed it.

    His utterings are in the running for either biggest lie of the year, or most ignorant.

    --
    Learning HOW to think is more important than learning WHAT to think.
    1. Re:AES is Belgian by Anonymous Coward · · Score: 0

      You forgot... Arrogant.

      Who needs encryption when you can simply broadcast your PROPAGANDA on Facebook, Twitter et al. (ISIL 'cough'). Terrorist groups have corporate backing nowadays.

    2. Re:AES is Belgian by cryptizard · · Score: 1

      It doesn't matter who developed it, the thing that doesn't seem to fit into his world view is that the details for all these encryption schemes are already out there. Anyone with halfway decent coding ability can implement them from the the specs to get an encryption library with no backdoor. And the crypto that we have now, by all estimations, should be more than good enough for the next few decades.

    3. Re:AES is Belgian by fustakrakich · · Score: 1

      C'mon, he is just reading a speech the propaganda minister gave him. They all have to do this, even the president

      --
      “He’s not deformed, he’s just drunk!”
    4. Re:AES is Belgian by BarneyGuarder · · Score: 2

      The name of the algorithm behind AES is Rijndael -- a combination of the names of the Belgian cryptographers who developed it.

      Right. And after 10 seconds of searching, one finds the Wikipedia page on AES:

      The Advanced Encryption Standard (AES), also known as Rijndael[4][5] (its original name), is a specification for the encryption of electronic data established by the U.S. National Institute of Standards and Technology (NIST) in 2001.[6]

      AES is based on the Rijndael cipher[5] developed by two Belgian cryptographers, Joan Daemen and Vincent Rijmen

      I don't know which possibility is more concerning: that the director has such myopic American exceptionalism or that he would expect the public to be so stupid.

    5. Re:AES is Belgian by Anonymous Coward · · Score: 0

      "American Encryption Standard" according to http://ostatic.com/libaes

  28. Wait tell he wakes one day by Anonymous Coward · · Score: 0

    To find every cent at Bank Of America is gone.

    1. Re:Wait tell he wakes one day by HiThere · · Score: 1

      The Bank of America is a private institution. As, in fact, is the Federal Reserve. Alexander Hamilton made carefully sure that the monetary system in the US would be under (certain) private ownership.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  29. Sombody get the clubat. And use it, a LOT. by Anonymous Coward · · Score: 0

    For the longest time, US encryption was held back by being classified as "munitions".

    Businesses were held back from using encryption for the same reason - so, SSL was implemented overseas and NOT in the US. Made a rather large hit.

    The US encryption standard (AES) was designed by the Dutch researchers.

    1. Re:Sombody get the clubat. And use it, a LOT. by Anonymous Coward · · Score: 0

      The US encryption standard (AES) was designed by the Dutch researchers.

      Joan Daemen and Vincent Rijmen are Belgian, not Dutch.

  30. Considering how much by nehumanuscrede · · Score: 3, Insightful

    the various agencies of the US Government tend to lie ( even to Congress ), I'm somewhat puzzled about why they even bother to ask questions of them anymore.

    Perhaps Congress should forgo asking questions of the professional liars ( any intelligence agency ) and ask the tech world instead. I'm quite sure the likes of Cisco, Juniper, Apple, Google and many others ( assuming they're not secretly on the Governments payroll ) would have a much different perspective on the issue at hand.

    1. Re:Considering how much by nehumanuscrede · · Score: 1

      as an afterthought, it has been shown time and time again that even when they DO have actionable intelligence on a would-be terrorist, they typically fail to act on the information. So, other than spying for different purposes than what they would have us believe, I fail to see the point in giving them access if they're incapable of doing anything with it.

      The only thing backdooring encryption will do is ensure the world avoids US made products at all costs. It will likely bankrupt several major companies and completely undermine the security of. . . . well. . . . just about anything that is stored or transmitted.

    2. Re:Considering how much by Jason+Levine · · Score: 1

      Exactly this. Even if you could somehow, magically, prevent non-backdoored strong encryption from existing (and that would be some serious "rewrite the laws of physics" level magic there), your improved security from terrorists would be exactly 0. However, your vulnerability from criminals exploiting the backdoors for their own nefarious purposes would shoot through the roof. And that's not even getting into government abuse of their backdoor.

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
    3. Re:Considering how much by sinij · · Score: 1

      Perhaps Congress should forgo asking questions of the professional liars ( any intelligence agency ) and ask the tech world instead. I'm quite sure the likes of Cisco, Juniper, Apple, Google and many others would have a much different perspective on the issue at hand.

      Yes, they will have different perspective, but this doesn't mean that they are on our side. This perspective is to squeeze out competition by any means possible and to minimize their own liability. They would likely tell us that consumers don't like privacy and would only use cryptography to pirate movies and hide child porn.

    4. Re:Considering how much by Anonymous Coward · · Score: 0

      No more Kool-aid for you.

      The CIA are the terrorists. Have you ever heard of Ed Snowden? Do you think the NSA and CIA live on different planets? The same computers, the same networks, and that includes Google tracking everything.

      There are so many corporations already infiltrated since even before 9/11. It is the same NWO hope they had, to take over the world. The problem is, to take over God's world you would have to ask Him. Jesus is Lord and He is coming.

    5. Re:Considering how much by cbhacking · · Score: 1

      While that's a tempting view to hold... Apple encrypts their iOS devices with crypto the government cannot easily, if at all, break (the San Bernadino shooter's phone, which kept them flummoxed for a while, was an old model and improvements have been made since then). Apple also recently announced changes to their app SDK that basically means your servers *must* use good TLS, unless you want to apply for exceptions for every unsecured connection your app wants to make. Microsoft has been making BitLocker available in more and more devices, and as far as I know the government has no way to break that either (unless you let Win10 upload your recovery key to Microsoft, which is not the most trustworthy move on their part but can be avoided). Google has been pushing encryption on their devices as well, and between their data centers, and in their browser. Amazon temporarily dropped encryption on Kindle Fire devices, but then restored it. Not sure what Cisco/Juniper/F5 would have to say (and they've sometimes been the bottleneck on crypto (TLS) advances on the Internet, though I think that's more out of laziness and lack of quality than anything else), but they've got to compete with the likes of Huawei and aren't going to want the government to do anything that makes them look even less trustworthy than those folks. I wouldn't trust anything out of Oracle even if they just said the sky was blue, but I doubt it's actually in their best interest to have backdoored crypto either. In other words, there are plenty of tech companies that are demonstrably fighting against this bullshit.

      Of course, at some level all those companies rely on other organizations (hardware manufacturers, certificate authorities, compiler providers, all the way up to the people who pick cryptographic primitives to support and identify the parameters that are best to use with them) to make it possible to build a backdoor-less crypto system. Remember Dual_EC_DRBG, and how the NSA bribed RSA Security to make it the default? How about "Reflections on Trusting Trust" (PDF link)?

      --
      There's no place I could be, since I've found Serenity...
  31. OFFS, Crypt Madness! by Anonymous Coward · · Score: 0

    Might as well kill off what remains of made in US electronics, cuz security!

  32. That is utter nonsense by gweihir · · Score: 2

    For example, AES is a Belgian design. The US has long since lost leadership in this. That is if they ever had it.

    Incidentally, when did US TLAs catch any terrorists "coordinating via encryption" the last time? Oh, right, NEVER.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    1. Re:That is utter nonsense by Anonymous Coward · · Score: 0

      I think he was trying to walk the line between truthful and technically accurate. By saying that other country's crypto was "theoretical" that really means they aren't shipping commercial products. The misleading part is the implication that they couldn't do so if they had a reason to. But with most of the major OS's being built in the US the barrier to entry of another country's crypto implementation becoming mainstream is fairly high. But given his stupid comments he almost guaranteed that we will see a fleet of such implementation rolling in within months.

    2. Re:That is utter nonsense by gweihir · · Score: 1

      1. OSes are not the only things doing crypto. In fact they usually do it only as extra functionality.
      2. Linux is a major OS in the security-sphere and it is not "build in the US". Some of the people involved in it are US residents, that is all.
      3. The focus on commercial products is misleading. For example, OpenSSL is not a commercial product, but more important than most/all commercial cypto.
      4. Much crypto made by US companies is actually not implemented in the US.

      I think he was trying to sell a thinly camouflaged lie for propaganda purposes. But I fully agree on your conclusion. In fact I know of European companies that are already looking for domestic replacements for US products, specifically because of the threat of US backdoors. Implementing crypto well is hard, but not that hard and there are plenty of people outside of the US that can do it well.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    3. Re:That is utter nonsense by Anonymous Coward · · Score: 0

      Incidentally, when did US TLAs catch any terrorists "coordinating via encryption" the last time? Oh, right, NEVER.

      They all seem to use Facebook and Twitter though. Maybe we should ban those...

  33. Is he saying that known crypto is broke? by Nkwe · · Score: 1

    As other posters have said, his words are those of an idiot.

    Any possibly that he is actually saying that known crypto algorithms have been broken by the US? I doubt it, but it is interesting to ponder.

    1. Re:Is he saying that known crypto is broke? by Anonymous Coward · · Score: 0

      Hah, actually that was the first thing I took away from it. But more likely he just wants that possibility to remain, while, as others have said, using the "theory" terminology to confuse politicians who don't believe in things like climate change, evolution, or gravity(?).

  34. He's a smart man by Anonymous Coward · · Score: 0

    like most Americans. They all believe that they "made all the things", and conveniently ignore that _everything_ builds upon existing innovation, and that almost _everything_ made in the U.S involves highly skilled European and Asian first-generation immigrants, and technology and research coming from all corners of the world.

  35. CIA = ? by GreatOldOne · · Score: 1

    It sounds like they have a lot of the CENTRAL and AGENCY, but not INTELLIGENCE.

    1. Re:CIA = ? by bsDaemon · · Score: 1

      They're often referred to around this area as "Clowns in Action".

  36. Then the tech company becomes non-US by Bugler412 · · Score: 1

    Given that nearly every major tech company has large presence in multiple foreign countries, then they move their headquarters outside the US. For instance, I know for a fact that MS has contingency plans to move headquarters 60 miles up the road to Vancouver BC for some situations and given their presence in India, that likely wouldn't be much of a challenge either. I'm sure that most other big players are similar. They simply leave to avoid the law. Yay, great for America right?

    1. Re:Then the tech company becomes non-US by cbhacking · · Score: 1

      Redmond is well over 60 miles from the border - more like 120, and more if you want to get into Vancouver proper - but your point stands. They'd lose out tremendously if they had to avoid selling to the US too, but quite possibly less than they'd lose out if nobody *but* the US would buy backdoored products.

      --
      There's no place I could be, since I've found Serenity...
  37. this guy whould write a book... by rbgnr111 · · Score: 1

    This guy should write a book on how to drive away the American tech industry and promote off-shoring of jobs.

    Just because most encryption is developed by us companies, doesn't mean it'll always stay that way. Something like this just makes Offshore and Foreign vendors become more attractive. Why would anyone buy a software security package that is known to be compromised or have back doors. Even if it's meant only for the "good guys" to get through, something like that is just a ticking timebomb, eventually it'll get into the hands of someone who shouldn't have it, then at that point, you may as well have no encryption at all.

    1. Re:this guy whould write a book... by GreatOldOne · · Score: 1

      This guy should READ a book.

    2. Re:this guy whould write a book... by cryptizard · · Score: 1

      Most encryption is not developed by US companies, it is developed by academics, who are famously difficult to censor or control. Also as other people have said, lots of those academics are not Americans.

    3. Re:this guy whould write a book... by Bob+the+Super+Hamste · · Score: 1

      Even those who are US citizens tend to like to poke people like Director Brennan in the eye with a stick. I mean it isn't like Schneier is out there preaching the virtues of the CIA, but instead has basically told them and the FBI to go piss up a rope.

      --
      Time to offend someone
  38. The devil you know by mamono · · Score: 1

    Who's to say that some other country will do any better? I agree it is a poor move and will likely just end up being abused more against US citizens than espionage. However, it's not like the US is the only surveillance-happy country out there. The UK and China are as bad, if not worse. At least the US is being relatively transparent about their intentions. I doubt you would get much notification if China mandated that all its companies installed backdoors in their products.

    1. Re:The devil you know by ukoda · · Score: 1

      Actually the Chinese government are pretty open about it. The non-Chinese company I worked for in China had VPN connections to a free country and also to the USA. They were told they would be expected to install government supplied equipment on their internal network so the government could properly monitor their communications. It had not happen yet as of when I left their employ.

  39. Aiding and Abetting by Sir+Holo · · Score: 2

    It would be "aiding or giving comfort to the enemies of the United States" – by encouraging them to take over for the US companies that this type of legislation would kill.

    You or I would go to Federal Prison for that.

  40. Gchq by martin · · Score: 2

    Who actually invented public key encryption first, oh yeah a British fella working for gchq one evening in his head cos he couldnt write it down

  41. Terrorism excuse works for everything by Anonymous Coward · · Score: 0

    Eat your vegetables to be stronger and defeat terrorism. Give us your privacy so we can defeat terrorism. Give us your tax money to combat terrorism. Re-elect this/that president to keep combating terrorism. Watch cat videos to be cute enough to combat terrorism.

    It is funny how the "terrorism" excuse is used by the gov all the time except for giving us the freedom to own guns. Why not "own more guns and we will even make them cheaper so you can help us defend this country from terrorism"?

  42. Response question by DarkOx · · Score: 1

    And how long does it theoretically take for some non US entity to grab some existing OSS code out there today, fork it an package it un-crippled?

    --
    Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
    1. Re:Response question by ceoyoyo · · Score: 1

      Negative twenty years? Lots of open source encryption packages were started by non-Americans and specifically hosted outside the US in the 90s because of US export restrictions.

  43. John Brennan is an ASSHOLE by Anonymous Coward · · Score: 0

    Fire his ass. Preferably, out of a very large cannon, pointed straight at the Moon.

    1. Re:John Brennan is an ASSHOLE by BlueStrat · · Score: 1

      Fire his ass. Preferably, out of a very large cannon, pointed straight at the Moon.

      "One of these days, Alice, one of these days!

      Bang, zoom!

      To the moon, Alice, to the moon!"

      https://youtu.be/98qw86DsdZ0

      Strat

      --
      Progressivism (aka US 'Liberalism'): Ideas so good they need a police/surveillance-state to enforce.
  44. WOOO! by Anonymous Coward · · Score: 0

    I am seriously hoping that the spy masters force American encryption to have a mandated backdoor!

    In other news i will be starting a Canadian company to create encryption products! Thank you dear spymasters for relinquishing your monopolistic hold on encryption, I look forward to competing with other countries in this growing market!

    Statements like the ones that Brennan has made make him look extremely short sighted which should terrify the white house. even is he is spot on that any other option is "theoretical" how can he be so naive to believe that there aren't at least 40 other countries with the skills and abilities to go from theoretical to operational in under 4 months (which is the length of a business quarter and seems to be about as far ahead as any politician or business person can think"

    on a serious note, do Americans not realize how quickly their elected representatives are making them irrelevant in the current age. they may have helped birth the internet but trying to stuff everything back in Pandora's box does nothing but make Americans in general look foolish.

    1. Re:WOOO! by ceoyoyo · · Score: 1

      Yeah, I had that thought as well. Except I think I'll start a bank.

  45. File under WTF, he seriously said that? by Proudrooster · · Score: 1

    The director denied that forcing American companies to backdoor their security systems would cause any commercial problems.

    This is lie, an outright lie, and I hope he was under oath when testifying before congress. Absolute, outright lie! Liar, liar, pants on fire. Everyone email their representative and let them know the director outright lied to their face and cite the CEO of Cisco.

    This will hurt American Tech in China. To interoperate, China will steal all corporate America's IP and integrate it into their products.

    Dr. Mr. Director of CIA, your reality distortion field is NOT WORKING! I am still in disbelief. This is how you kill American products in emerging markets and hurt growth. What an absolute lie!

    1. Re:File under WTF, he seriously said that? by Bob+the+Super+Hamste · · Score: 1

      While I will write my idiot Senators and defective Congressman I doubt it will do any good. I write them a lot and nothing ever comes of it but it doesn't stop me from writing them anyway. It isn't like they went after the CIA when they hacked the Senate Intelligence Committee and spied on them so why would they go after them for this minor infraction.

      --
      Time to offend someone
  46. Ummm let me think about this by dayton967 · · Score: 2

    Encryption Routines created by people who are not American
    - AES (Rijndael)
    - IDEA
    - Serpent

    Hashing Routines created by people who are not American
    - SHA-3 (Keccak)

    So the Current Encryption Standard and Future Hashing Standards in the US were created by non-American's, but hey, "non-American solutions are simply 'theoretical.'"

  47. It's politics, stupid by Anonymous Coward · · Score: 2, Interesting

    You have to be not actually dumb to get high up in government. But you do have to have a certain capacity to believe in the institutional lies, or at least repeat them as if you mean them. They still institutionally believe in a rather simplistic device to the point that gaming the thing is a criminal offence, for example.

    More to the point, this here is politics in action. He is furthering an agenda in front of an audience that made this agenda-pushing their day-and-night jobs, but who do not necessarily have any clue whatsoever about what goes on under the veneer of the nice words from the very respectable chief of this here government outfit reporting to congress. So he's basically daydreaming his "truth" into existence. If he can get it enacted in law, he has won.

    * Quiz: What other organisation institutionally believes in an unproven, even outright silly, bullshit device based on similar principles?

    1. Re:It's politics, stupid by fyngyrz · · Score: 4, Insightful

      You have to be not actually dumb to get high up in government

      o U.S. President George Walker Bush.
      o U.S. Senator Ted Stevens.
      o U.S. Representative Michele Bachmann.
      o U.S. Representative Todd Akin.
      o U.S. Representative Joe Barton

      I rest my case. I could go on, but it's really quite painful to think about.

      --
      I've fallen off your lawn, and I can't get up.
    2. Re: It's politics, stupid by rickb928 · · Score: 1

      Whoosh...

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    3. Re:It's politics, stupid by Anonymous Coward · · Score: 0

      Those are all elected politicians*, not career bureaucrats. Different career track, different skillset demands.

      * By whom, exactly, is up for debate. I hear this guy "Hanging Chad" has quite the influence.

    4. Re:It's politics, stupid by Anonymous Coward · · Score: 0

      Try a list of top bureaucrats, you know, the government folk who aren't elected.

    5. Re:It's politics, stupid by Anonymous Coward · · Score: 0

      Those people were all elected by voters even stupider than they are.

      I think the parent poster was referring to people who, over the course of a career, work their way up to jobs of high authority.

    6. Re:It's politics, stupid by Anonymous Coward · · Score: 0

      You forgot Governor Sarah Palin.

    7. Re:It's politics, stupid by Anonymous Coward · · Score: 0

      For one example...

      o U.S. Representative Michele Bachmann.

      This says more about local politics than anything else. She was not always winning a majority of the popular vote in the general election even, but the Independence party (Ventura's party) would get 10% of the vote, and she got more votes than the Democrat running against her.

    8. Re:It's politics, stupid by Anonymous Coward · · Score: 0

      If they're so dumb then how come they made it to high office and you didn't?

    9. Re:It's politics, stupid by Carewolf · · Score: 1

      Try a list of top bureaucrats, you know, the government folk who aren't elected.

      You mean the people hand picked by the retard elects to serve as their assistents?

    10. Re:It's politics, stupid by fyngyrz · · Score: 1

      I didn't exactly forget her. I just stopped listing idiots after I got to five.

      --
      I've fallen off your lawn, and I can't get up.
    11. Re:It's politics, stupid by fyngyrz · · Score: 1

      So mid-level government positions rather than top level, as the post I responded to asserted. Congress writes the legislation that controls the regulatory agencies. The president directs the executive branch. That's as high up as you can get in those two branches; there is nothing higher. The assertion that "You have to be not actually dumb to get high up in government" is clearly false. The judiciary is different, in that those are appointments.

      If you'd like to make the assertion that "You have to be not actually dumb to get appointed to a subordinate position in government or to the judiciary" that's fine. See if anyone argues with you. I won't. It's probably rare, at least.

      Which is not to say that such appointed people are not often evil bags of shit, because of course they are.

      --
      I've fallen off your lawn, and I can't get up.
    12. Re:It's politics, stupid by Anonymous Coward · · Score: 0

      Are we going to pretend that U.S. President Barack Obama and U.S. Vice President Joe Biden do not belong on that list?

      Because otherwise it just sounds like "dumb" means "does not agree with me".

    13. Re:It's politics, stupid by fyngyrz · · Score: 1

      lol. You assume or imply (why?) I was trying to make it to high office. I most certainly have not been doing that. Never threw my hat in the ring even once, for any public position. Nor do I ever plan to. I can't see how the government we have presently could possibly mutate into anything I'd want anything to do with, and it certainly isn't that now. My policy WRT the US government is "eat the bread, watch the circus, vote whenever possible."

      --
      I've fallen off your lawn, and I can't get up.
    14. Re:It's politics, stupid by fyngyrz · · Score: 1

      Obama is probably one of the most intelligent presidents we've ever had. He is an extremely intelligent person. Like him or despise him, he's been playing chess to congress's "angry checkers" for the entire seven-plus years he's been in office thus far.

      The fact that you imply he is "dumb" identifies you as someone who has absolutely no clue what is going on.

      --
      I've fallen off your lawn, and I can't get up.
  48. John Brennan is a cocksucking liar by Anonymous Coward · · Score: 0

    https://en.wikipedia.org/wiki/Motives_for_spying
    https://en.wikipedia.org/wiki/Edward_Snowden
    https://en.wikipedia.org/wiki/Treason
    http://www.merriam-webster.com/dictionary/subterfuge
    http://www.wisegeek.org/what-are-the-penalties-for-treason.htm
    https://en.wikipedia.org/wiki/False_flag

    https://kat.cr/tails-1-4-1-i386-iso-multilang-tntvillage-t10922671.html
    http://lsuzvpko6w6hzpnn.onion/tails-1-4-1-i386-iso-multilang-tntvillage-t10922671.html

    Ask the CIA why Microsoft spies and Google spies and Facebook spies. Expect him to say he has no idea.

    God is watching you John. Life is too short to go to Hell for your Jesuit masters.

    1. Re:John Brennan is a cocksucking liar by Anonymous Coward · · Score: 0

      If only I had an account with mod points.

      BRAVO!!!!!!!!!!!!!!

  49. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  50. 'American Companies Dominate' by Jason+Levine · · Score: 3, Interesting

    Another article has more of the exchange:

    Sen. Ron Wyden (D-Ore.), another committee member and staunch privacy advocate, has pilloried proposals to give law enforcement access to encrypted data, saying bad actors would simpy use foreign-based encrypted messaging apps. Brennan argued at the hearing that such a concern was theoretical because “U.S. companies dominate the international market as far as encryption technologies that are available through these various apps.”

    Warner [Sen. Mark Warner (D-Va.)] questioned Brennan’s assertion. “Two thousand apps a day are added to the phone store. Over half of those are foreign-based entities,” he said.

    In a statement following the hearing, Wyden countered that allowing government access to encrypted platforms “would not stop terrorists from using strong encryption and it would undermine American competitiveness and Americans’ digital security at a time when the threat from foreign hackers and cyberattacks has never been greater.”

    Let's allow the assumption that American companies currently dominate the encryption field. We'll say that's true. How long would that dominance that last if foreign companies used strong encryption and American companies used hobbled encryption left vulnerable to the American government and hackers? Thank goodness for Warner and Wyden for pointing out how idiotic Brennan 's assertion was.

    --
    My sci-fi novel, Ghost Thief, is now available from Amazon.com.
    1. Re:'American Companies Dominate' by fnj · · Score: 1

      Let's allow the assumption that American companies currently dominate the encryption field.

      Let's not. Let's not even allow that COMPANIES dominate any technology. I think the words you want are "worlwide" instead of "American", and "scientists" instead of "companies".

    2. Re:'American Companies Dominate' by MightyMartian · · Score: 1

      Let's pretend math works differently in the US than elsewhere in the world...

      Clearly the man is either a simpering halfwit, or more likely believes Congress is full of simpering halfwits. Sadly, he may be right.

      --
      The world's burning. Moped Jesus spotted on I50. Details at 11.
    3. Re:'American Companies Dominate' by hawaiian717 · · Score: 1

      A few messaging applications I can think of that aren't developed in the US:

      Line: Japan
      WeChat: China
      Kik: Canada
      BlackBerry Messenger: Canada
      QQ: China
      Threema: Switzerland
      Viber: Originally Israel, now owned by a Japanese company
      Gadu-Gadu: Poland
      Telegram: Russia/St. Kitts and Nevis

      --
      End of Line.
    4. Re:'American Companies Dominate' by Jason+Levine · · Score: 1

      I'm fully aware that Brennan’s assumption was wrong. My point was that even if he were right (which he isn't), then requiring backdoors in all encryption in the US would destroy any dominance that exists (even if it exists solely in Brennan’s mind).

      --
      My sci-fi novel, Ghost Thief, is now available from Amazon.com.
  51. Completely incompetent or lying? No need to answer by Anonymous Coward · · Score: 2, Insightful

    The AES encryption algorithm is Rijndael, which is Belgian
    The runner-up for the contest for becoming the AES standard was Serpent, which was a British/Danish/Israeli collaboration.
    Third place went to the Twofish algorithm, designed by Bruce Schneier, a US citizen who happens to be a vocal opponent of backdoors.

    The "main" encryption du jour happens to be from outside the USA. The best alternative is also from outside the USA. Of course, the nationality of the creators doesn't matter - the USA is able to make modified implementations that include backdoors, but the original non-backdoored versions are already out there for everyone to use instead.

  52. he is a drooling moron... by Lumpy · · Score: 1

    Oh dear god, really? This is why we are ineffective. The men in charge are idiots, morons and buffoons.

    --
    Do not look at laser with remaining good eye.
  53. What an IDIOT by rholtzjr · · Score: 1

    I can not believe he is head of an agency with the word "Intelligence" in it.

  54. Translation by fustakrakich · · Score: 1

    ALL encryption is theoretical. I wonder they would want to blow that cover.

    --
    “He’s not deformed, he’s just drunk!”
  55. CIA by Anonymous Coward · · Score: 0

    "Intelligence" in CIA is purely theoretical.

  56. Only in the US of A by Kefeus · · Score: 0

    Damn, I did not know that americans was that stupid !

  57. Its the other way 'round by gosand · · Score: 1

    the various agencies of the US Government tend to lie ( even to Congress ), I'm somewhat puzzled about why they even bother to ask questions of them anymore.

    Perhaps Congress should forgo asking questions of the professional liars ( any intelligence agency ) and ask the tech world instead. I'm quite sure the likes of Cisco, Juniper, Apple, Google and many others ( assuming they're not secretly on the Governments payroll ) would have a much different perspective on the issue at hand.

    Companies aren't on the payroll of the government, it's the other way around.

    --

    My beliefs do not require that you agree with them.

    1. Re:Its the other way 'round by HiThere · · Score: 1

      Actually, it works both ways. Sometimes the government overrules the desires of the companies, and sometimes the other way around. Neither, however, is primarily interested in benefiting the citizens, or even the voters.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  58. Starting to wonder... by Anonymous Coward · · Score: 0

    If CIA director John Brennan is a double agent for the Russians or Chinese. This is exactly what they would want to have happen. I'm sure Feinstein will back it 100%. Perhaps she's an agent for them as well. It fits.

    1. Re:Starting to wonder... by Anonymous Coward · · Score: 0

      If CIA director John Brennan is a double agent for the Russians or Chinese. This is exactly what they would want to have happen. I'm sure Feinstein will back it 100%. Perhaps she's an agent for them as well. It fits.

      Know this,

      It's not his real name.

    2. Re:Starting to wonder... by Anonymous Coward · · Score: 0

      It does kind of suck as an American citizen always having the feeling that everyone loves their country and wants what's best for it, except the people in positions of authority who assure you you are simply not smart enough to know why they do what they do. And they typically disagree with all the people in the previous group on every issue of domestic and foreign policy.

  59. Meanwhile, across the pond... by simplypeachy · · Score: 1

    I'm sure Werner Koch could get a giggle out of such a statement.

  60. Schneier Psy-Op Conspiracy Theory. by Anonymous Coward · · Score: 0

    Some months ago Bruce Schneier on his blog S.O.S. made a call for a survey of global (read: non-US) encryption tools. The exercise smelled fishy at the time. I suspect this is all a choreographed psy-op and this was just the next step that the insiders knew was going to happen months ago. Because it is that stupid and retarded.

  61. In other news... by JustNiz · · Score: 1

    In other news, the US invented everything and won WW2 single-handed.

  62. Ministry Of Unvention by Anonymous Coward · · Score: 0

    that sounds interesting. In general it feels like the end-game is fundamentally reshaping the vision that people have that they are free to just go and invent anything they want without asking permission first. The totalitarians are rationally afraid that even beyond inventors with non-conforming intent, there are probably children and less intelligent people that could often invent something that a non-conformist might use against the conformists somehow. If we had a new government office, like the patent office, that inventors were required to screen their potential ideas with prior to further work, it would be much more efficient for the nation. Or so I think their worldview goes.

  63. Doesn't it, through? by Anonymous Coward · · Score: 0

    The director denied that forcing American companies to backdoor their security systems would cause any commercial problems.

    Personally I'm avoiding US products when I have an alternative.

    according to Brennan, there's no one else for people to turn to: if they don't want to use U.S.-based technology because it's been forced to use weakened cryptography, they'll be out of luck because non-American solutions are simply "theoretical."

    LOL! Who the fuck is this clown?

  64. Already know it by Anonymous Coward · · Score: 0

    He might be onto something. The last time we tried to write a point-to-point encrypted texting software, our working team suddenly grew with three american employees, wearing blacks suits and sunglasses!

  65. Can't tell if... by EvilSS · · Score: 1

    ... complete moron, blatant liar, or maybe both.

    Does anyone in Washington remember what happened back in the 90's when the State Department declared strong cryptography a weapon and put heavy export controls on it? Hell I was a teenager and ever I remember. Tons of EU companies sprang up to fill the gap. Ireland, in particular, had quite a few software companies spring up offering software product with strong encryption. It wasn't that long ago that the government finally figured out how useless the export controls were and loosened them to where they are now. They did nothing but hurt US tech companies. How in the hell could anyone not think the same thing would happen again?

    --
    I browse on +1 so AC's need not respond, I won't see it.
  66. economic equiv of yelling "Fire" in a theater by Anonymous Coward · · Score: 0

    I worked in radio til gov't handed the entire spectrum over to Clr Chnl. Loss of jobs and democracy was palpable (during reign of Clinton 1).

    Now that I found work doing DevOps, guess that will be flattened by Clinton 2.

    We all know story of Ford. Surely we have heard the name Honda as well....

  67. A few things, by sandbagger · · Score: 1

    It's tempting to dismiss this as him being wrong by orders of magnitude and then talking down our noses at him by assuming we need to explain what an order of magnitude is, or that he's adopting this stance for transparent political reasons, but let's assume for the moment that he's telling the truth. What would he have to know for that statement to be true?

    Have you all forgotten the Snowden revelations yet? How it became known that the US grabbed cell phone encryption standards before the ink was dry on them, how they tapped the lines between Google data centres. If the operational tools for creating for encryption are compromised or at least weakened, it may well be that they have visibility into source code in a lot of industries as well as communications, which is as good *if not better*.

    --
    ---- The above post was generated by the Turing Institute. Maybe.
  68. What an IDIOT.. by h8sg8s · · Score: 1

    What an idiot. Imperialism is bad, but technological imperialism is simply stupidity masked as pride.

    --
    Organization? You must be joking..
  69. Theoretical vs Broken by Anonymous Coward · · Score: 0

    I would go with theoretical anyday.

  70. Smartest and most open administration in history by Anonymous Coward · · Score: 0

    File under: Obama Administration

    Where not spying on the citizens is maximized, but called something else.

    Where "open" and "transparent" is secret off-site servers, massive document deletion/destruction, and more redacted documents than any previous administration

    Where terrorism is "man caused disasters", and nearly all the terrorism on the planet in the past 40 years has no common thread other than "extremism".... better watch-out for those "extreme coders", "extreme athletes", extreme JWs and/or Mormons knocking on your door, etc...

    Goebbles would be so very proud: controlling the population by controlling the vocabulary and telling massive blatant lies. Baghdad Bob was a piker...

  71. The list by evilviper · · Score: 1

    The AES NIST standard encryption competition finalists:

            CAST-256--Canada
            CRYPTON--South Korea
            DEAL--Canada and Norway
            DFC--France
            E2--Japan
            FROG--Costa Rica
            HPC--U.S.A.
            LOKI97--Australia
            MAGENTA--Germany
            MARS--U.S.A.
            RC6--U.S.A.
            Rijndael--Belgium
            SAFER+--U.S.A.
            SERPENT--Norway
            TWOFISH--U.S.A.

    http://www.eurekalert.org/pub_...

    --
    Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
  72. rofl by Anonymous Coward · · Score: 0

    why do you elect idiots? weak encryption is a double edged sword... at the minimum...

  73. Never roll your own! by cbhacking · · Score: 1

    While I get what you are trying to say... that is so, so wrong that I realllllly hope you are nowhere near any crypto code, in either your professional or personal hours.

    Getting the basics of a crypto function right is easy. The algorithms, complete with pseudocode or even a basic implementation in some real language, are well-published. As you say, anybody with halfway-decent skill can implement them from specifications.

    Getting the details of a crypto library write is really bloody hard! There's always a risk of incorrect behavior in some edge case that completely breaks your system, for example - Heartbleed was probably the most famous and easiest-to-understand of these, but there's plenty of others across many libraries - but risks like that are not unique to crypto libs (although they are usually *worse* in a crypto lib). Side-channel attacks like timing attacks, padding oracles, CPU cache line attacks (technically a kind of timing attack, but not the sort most people think of when you say "timing attack"), and many more things than I know about bedevil implementations of such things.

    Just like nobody but an expert in crypto theory should ever attempt to design their own crypto algorithm, nobody but an expert in crypto implementation should ever attempt to write a cryptosystem in live code. If you think "anyone with halfway-decent coding ability can implement them from the specs and get an encryption library with no backdoor", then there is ~0% chance that you could implement a crypto library and get one that cannot be broken, at which point who cares if it has a backdoor explicitly built in?

    --
    There's no place I could be, since I've found Serenity...
  74. bah... by Anonymous Coward · · Score: 0

    They don't need weak encryption, they drop hellfire via clear channel metadata every day.

  75. Skillset by dbIII · · Score: 1

    Being good at all the political games to get into a high position does not automatically mean competence with a different skillset.
    Especially when there is nepotism in the mix.

    Remember this?
    "Brownie, you're doing a heck of a job"

  76. Americuh... fuck yeah! by Anonymous Coward · · Score: 0

    I can't decide if Brennan is stupid, or if he thinks everyone else is stupid.

    Judging by the universal cringe displayed by all the analysts and technicians who an actual understanding of crypto, I'd go with "a little of both". I just can't believe he's so clueless as to not understand that math doesn't recognize lines on a map, nor can I quite believe he didn't expect to get called out on his bullshit. Either way, it was a dumbass thing to say.

    'Merica has the very best, the classiest and yugest mathers in the world. Our math people are gooder then all teh other country mather people. So American crypto is thu bestest kind of crypto there is. It is withow pier, barn un. So if you wants crypto you has to get it frum Americuh, or your just pretending to use cyrtop because no other cuntry can crypto liek we cann cyrpto .

    Amuricha iz number WON!

    (Didn't someone recently rail against the teaching of Algebra in American schools? How can anyone reasonably expect this nation to keep up with things like cryptography and cryptanalysis when we don't even teach basic math? And how does anyone imagine our crypto to be the only real crypto when there are lots of other countries out there, many with brilliant people, even some (gasp!) mathematicians and cryptography experts! Is this dude serious? Or is he a troll?)

  77. Re: Good thing all mathematicians are American the by AgNO3 · · Score: 2

    Im only aware of 4 countires, America,russia, china, and terrorizerstan. Clearly we must be the only smart people.

    --
    OMG Ponies!!! with Glitter!!!! I miss Pink :-(
  78. Re: Good thing all mathematicians are American the by AgNO3 · · Score: 1

    We sell them weapons to fight the pinko commi bastards then we bomb them?

    --
    OMG Ponies!!! with Glitter!!!! I miss Pink :-(
  79. USA equals the known universe by Anonymous Coward · · Score: 0

    Pretty sure that everything outside of the USA is theoretical.
    Nobody has proven that any of it exists.

  80. Encryption by Anonymous Coward · · Score: 0

    I'd say the case of the FBI going third party to Crack an iPhone disproves this bullshit.