home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!nntp1.radiomail.net!csl.sri.com!porthos.csl.sri.com!not-for-mail
- From: boucher@csl.sri.com (Peter K. Boucher)
- Newsgroups: sci.crypt
- Subject: Re: PGP and real criminals
- Date: 20 Nov 1992 12:53:35 -0800
- Organization: Computer Science Lab, SRI International
- Lines: 31
- Message-ID: <1ejj8fINNlt@porthos.csl.sri.com>
- References: <1992Nov17.001101.21926@ncar.ucar.edu> <iyqHuB7w165w@mantis.co.uk> <4022@randvax.rand.org>
- NNTP-Posting-Host: porthos.csl.sri.com
- Summary: Easiness of evasion eliminates objections to key registration
- (other than cost and/or inconvenience of registering keys).
-
- One simple way for criminals to safely and easily get around any
- key registration is the following:
- 1) Use a non-registered "bad" key only occasionally (when really
- incriminating data is sent). Then encrypt again, with the
- registered "good" key before sending.
- 2) Always reply to every message received that was encrypted
- with the "bad" key, saying that the message was totally
- garbled and unreadable, and could they please resend.
- 3) Resend a "sanitized" version, encrypted only with the "good"
- key.
-
- Using this method would allow a competent lawyer to prevent your
- being convicted of "crypto-evasion." Of course they couldn't
- decrypt the "garbled" message. (It was caused by a glitch ;-)
- Their own tap records will back up your story.
-
- Given that one can safely and easily get around any such legislation,
- the only reasonable objections to it are it's cost and inconvenience.
- If these can be minimized, then why not register keys? Of course,
- an equally valid question is "why register keys?"
-
- I don't see why people who distrust the Gov't get so emotional about
- key registration. They can legislate all they want. It might be
- inconvenient and/or costly, but not dangerous to your privacy. It
- might help catch lazy or casual criminals - perhaps even enough to
- justify the cost and inconvenience.
-
- --
- Peter K. Boucher
- --
- RIPEM public key available upon request.
-