[12192] in Commercialization & Privatization of the Internet

home help back first fref pref prev next nref lref last post

Clipper and Ames....

daemon@ATHENA.MIT.EDU (Barry Shein)
Mon May 9 03:47:35 1994

Date: Mon, 9 May 1994 01:16:41 -0400
From: bzs@world.std.com (Barry Shein)
To: mo@uunet.uu.net
Cc: com-priv@psi.com
In-Reply-To: Mike O'Dell's message of Sun, 8 May 94 22:47:12 -0400 <9405090247.AA05766@rodan.UU.NET>


>From: mo@uunet.uu.net (Mike O'Dell)
>given that Ames was willing to sell the entire CIA Soviet Ops network
>for a measly $2 million,  large industrial users should consider how
>much it will cost to get they keys for, say, GM's design networks,
>or GE's new medical imaging technology, or etc, etc, etc.

Yes, one of the cardinal rules of security: Don't make it any more
expensive to break your security than it costs to bribe one of your
"trusted" staff, it's just wasted effort.

What I wonder is whether there is any provision in this whole Clipper
thing to compel the-powers-that-be to inform those potentially
affected that their keys may have been compromised?

I realize it would seem like a nice thing to do. But I also tend to
suspect that unless it was unavoidable more than a few involved might
prefer to play duck-and-cover unless the downside of doing so was
really severe.

Assuming this or something like it goes forth (and I hope not) I think
the least we deserve is some sort of criminal provision for not
informing either individuals or the general public as appropriate
should there be a likelihood or suspicion of compromise.

        -Barry Shein

Software Tool & Die    | bzs@world.std.com          | uunet!world!bzs
Purveyors to the Trade | Voice: 617-739-0202        | Login: 617-739-WRLD

home help back first fref pref prev next nref lref last post