"There were mathematicians doing new science to make Flame work."
the government thinks that this is just like normal weapons research.
what they don't realize is that "secure-enough" crypto is far more important to the world economy than their small use in breaking it.
if a government could spend $800B and prove/create a machine that makes asymmetric cryptography impossible - and will be reverse-engineered and known to the world within 3 years of when they start using it, they probably would.
meanwhile, the world loses a lot more than $800B if you can't do anything secure over the public Internet anymore, or have to have previously exchanged a one-time pad to anyone you want a secure connection with.
this isn't just another weapon. mathematics is a public good. Of course, if you can spend $800B on new math and then break it, then in some sense it was "always broken." In another sense, however, that's not true at all. Quit messing it up for everyone.
>if a government could spend $800B and prove/create a machine that makes asymmetric cryptography impossible - and will be reverse-engineered and known to the world within 3 years of when they start using it, they probably would.
The alternative is waiting 10 years for academia to discover the vulnerability, the whole time risking that an even worse organization will discover and exploit it.
Ideally they would spend the $800B breaking it, along with another $200B developing something to replace it before it goes public. Even if they don't do the second part, it's still no worse than what would happen eventually anyway.
This will only become an arms race, or skipping that entirely; the web will just be a destructive place. Another battlefield. Where in the history of civilization can we pull similarities and find a solution?
As the facts appear today; someone (or group, or government) attacked someone else (or group, or government) abusing a mechanism millions upon millions rely upon. Now the instructions to mimic that abuse is in the hands of another malignant.
There is no past for this type of thing. In 1857, 40,000 people could not sit in the woods of Russia and (potentially, just possibly) ruin worldwide communications, much of commerce, trade and banking, etc, for everyone just by invalidating some mathematics and sending a few letters out stating their findings - with no other direct or indirect manipulation of anything. That's what I meant by saying it's a "public good."
This is unprecedened. I chose $800B as an absurdly large sum that I believe is more than Academia would spend on this question in a few years. (I could be wrong though.)
Downvoter: I know you think it's not secure if a trillion dollars of research can break it - but guess what: there is a nonzero chance that between here and 800 billion dollars from here there is a quantum device. that doesn't mean it actually exists. it means it could exist if one of the world's biggest economies throws that much military R&D at it. I'm saying they shouldn't. at least, not with that goal (breakig crypto for everyone; quantum computing itself is a welcome advance). Please be more practical.
It seems as though the governments of western democracies are spending a lot more effort on digital swords to stab at our enemies than on digital shields to protect their citizens.
The NSA says that about 1/3 of their budget is put towards protecting US government systems and data (though there is no way to verify that). It is extremely difficult for them to even attempt to protect non-governmental systems. The NSA was involved in SELinux, and designed the SHA family of hash functions. This, along with their certification of various cryptographic standards as acceptable for government use, seems to me to be about all they could do defensively without requiring them to have access to private systems and data.
"There were mathematicians doing new science to make Flame work."
the government thinks that this is just like normal weapons research.
what they don't realize is that "secure-enough" crypto is far more important to the world economy than their small use in breaking it.
if a government could spend $800B and prove/create a machine that makes asymmetric cryptography impossible - and will be reverse-engineered and known to the world within 3 years of when they start using it, they probably would.
meanwhile, the world loses a lot more than $800B if you can't do anything secure over the public Internet anymore, or have to have previously exchanged a one-time pad to anyone you want a secure connection with.
this isn't just another weapon. mathematics is a public good. Of course, if you can spend $800B on new math and then break it, then in some sense it was "always broken." In another sense, however, that's not true at all. Quit messing it up for everyone.