[Cryptography] Schneier's Internet Security Agency - bad idea because we don't know what it will do

Tom Mitchell mitch at niftyegg.com
Tue Feb 28 16:57:54 EST 2017


On Tue, Feb 28, 2017 at 7:09 AM, Henry Baker <hbaker1 at pipeline.com> wrote:

> At 04:35 PM 2/27/2017, Kevin W. Wall wrote:
> >On Mon, Feb 27, 2017 at 4:14 PM, Henry Baker <hbaker1 at pipeline.com>
> wrote: ...<big snip>...
> >> How hard is it for a wifi device to search for all SSID's (including
> hidden

....

> So it wouldn't be hard for a sleazy Vizio to make deals with these even
> sleazier ISP's for easy/legal access to the Internet.


This is an interesting risk.
If the key used by a Vizio like company was to become public a million
"secure" hot spots
would become universal untraceable access to anyone: good, bad, frugal,
cheap.

If the TLAs are serious about national security this should be tested for
as well as be made
illegal to import including software updates.

As convenient setup goes little prevents a device from setting up a mesh
network of nearest neighbors
and then hop their way to a connection.

Automatic updates with bad services might precede a heavy handed larger
attack.
Like sleeper cells but not people.


-- 
  T o m    M i t c h e l l
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20170228/5ebc3cf8/attachment.html>


More information about the cryptography mailing list