[12192] in Commercialization & Privatization of the Internet
Clipper and Ames....
daemon@ATHENA.MIT.EDU (Barry Shein)
Mon May 9 03:47:35 1994
Date: Mon, 9 May 1994 01:16:41 -0400
From: bzs@world.std.com (Barry Shein)
To: mo@uunet.uu.net
Cc: com-priv@psi.com
In-Reply-To: Mike O'Dell's message of Sun, 8 May 94 22:47:12 -0400 <9405090247.AA05766@rodan.UU.NET>
>From: mo@uunet.uu.net (Mike O'Dell)
>given that Ames was willing to sell the entire CIA Soviet Ops network
>for a measly $2 million, large industrial users should consider how
>much it will cost to get they keys for, say, GM's design networks,
>or GE's new medical imaging technology, or etc, etc, etc.
Yes, one of the cardinal rules of security: Don't make it any more
expensive to break your security than it costs to bribe one of your
"trusted" staff, it's just wasted effort.
What I wonder is whether there is any provision in this whole Clipper
thing to compel the-powers-that-be to inform those potentially
affected that their keys may have been compromised?
I realize it would seem like a nice thing to do. But I also tend to
suspect that unless it was unavoidable more than a few involved might
prefer to play duck-and-cover unless the downside of doing so was
really severe.
Assuming this or something like it goes forth (and I hope not) I think
the least we deserve is some sort of criminal provision for not
informing either individuals or the general public as appropriate
should there be a likelihood or suspicion of compromise.
-Barry Shein
Software Tool & Die | bzs@world.std.com | uunet!world!bzs
Purveyors to the Trade | Voice: 617-739-0202 | Login: 617-739-WRLD