Encryption and Globalization 15 Years Later: E2EE and the "Going Dark" Debate (papers.ssrn.com)
41 points by iamnothere 5 hours ago
aliasxneo 4 hours ago
I've been working on a project for the last six months that brings mTLS to the masses. Meaning, post-quantum end-to-end encryption with human readable identities. It uses a decentralized root of trust for, basically, a lot of the history this article covers.
iamnothere 4 hours ago
Human readable identities are the hardest part (unless you just mean BIP-style word chains). What’s your approach look like? How do you prevent collisions?
aliasxneo 4 hours ago
You register a DNS-style name. Registrations lasts a year with a 3 month post-expiration window to reregister, otherwise it gets released back. The system goes out of its way to make name trading uneconomical - specifically to work against speculators and name-sitters from coming in and ruining things.
iamnothere 4 hours ago
saltcured 2 hours ago
mspecter 3 hours ago
Coauthor here, somewhat surprised to see this on HN. Any thoughts, questions, or feedback welcome.
iamnothere 2 hours ago
Thanks for putting this together. Found via Schneier’s blog; I thought it was a good summary, and perhaps needed information in the face of attacks like Chat Control.
mspecter an hour ago
Oh, I didn't realize it'd made it to Schneier's blog, thanks for letting me know!
A goal of the work was to try to explain to a new audience (specifically nontechnical legal folks) the ongoing challenges with Going Dark. Hopefully it helps!
iririririr an hour ago
The paper says ghost protocol has never been implemented, but wasn't it widely used on trump administration version of the signal-custom-client, which sent messages to a ghost account responsible for indexing and backup of plain text copies?
mspecter 20 minutes ago
Good point. Most of this was written before the signal-custom-client thing happened, so it wasn't top of mind. We also considered "serious" systems, deployed en masse. Perhaps we should've included this as well.
mvdwoord 4 hours ago
“Everything is end-to-end encrypted… depending on how you define the ends.”
g-b-r 3 hours ago
It is not great that they use the E2EE term to describe TLS, although it's for a good cause