Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you maybe thinking about it being a bad idea to decrypt without validating message integrity (i.e. decrypt without having or checking the message authentication code)? You absolutely can authenticate without encryption, it's one of the few ways you'll be able to get away with restricting access to functions and features legally on the ham bands. One time passwords and challenge/response authentication procedures are some alternatives.


Well if I can use a key and otp that makes it safer. But I'm more thinking how do you send a password safely. On the internet we don't want to do that with http. As I understand it, if you send your password without encryption you are sending your password with plain text. I don't see why this is different with electrical signals traveling through the air vs electrical signals traveling through cables. I figure we'd want to use the same security practices regardless of what medium that signal is being sent through.


Diffie Hellman. There are all kinds of schemes for Alice and Bob to share keys over a hostile channel. A brief secrets exchange isn't the same as an encrypted pipe.

Once you have authentication, you can send whatever control signals you want in the clear, as long as they are signed.

Message: set foo to baz Author: kortex Checksum: 0x1337ace5 Sig: 0xdeadbeef

The endpoint checks for message integrity and authentication, and executes or rejects.

The difference is cables are waveguides from A to B. Radio is a common bus.


Diffie Hellman is encryption

> (wiki) encryption is the process of encoding a message or information in such a way that only authorized parties can access it and those who are not authorized cannot.

>> 97.113 (4) “…messages in codes or ciphers intended to obscure the meaning thereof..."

You are obscuring the message that is the password.

Cipher

>>> 2 a: a method of transforming a text in order to conceal its meaning

>>> 4 : a combination of symbolic letters

>>>> (wiki) Diffie–Hellman key exchange (DH)[nb 1] is a method of securely exchanging cryptographic keys over a public channel

You definitely want to obscure and hide your password for authentication. I guess it depends how you interpret the rules though. Is a cryptographic signature a message in codes or ciphers the more important part or is it about the content of the message? At a minimum I think this should be clarified more.

That being said, if I am using radio to control certain devices I may not want that content to be public (and where I can still abide by the part of not using radio for illegal activities).


I don't think we ever reach the question about which element is more important. Elsewhere in the rules situations permitting encryption are spelled out (telemetry, RC). None of those exceptions apply to server passwords. Under common rules of construction it's safe to conclude that DH key exchange - of a shared secret, if we're being fair - is prohibited. One that can be worked around but not cleanly. There may not be a clean fix that doesn't involve something distasteful like a key escrow or unachievable like a rules change.

Thank you for a challenging exchange. Those interested can inspect the full reg at https://www.law.cornell.edu/cfr/text/47/97.113 . The permitted exceptions aren't hard to search for from there.


I don't think a rules change is unachievable. There's literally talk about it. I would be perfectly okay with a compromise of encrypted signatures or passwords. But I think that is difficult to verify that other things aren't being passed there. So it's probably just easier to allow encryption. I mean Soviet spies probably aren't using HAM bands for secret communications anymore.

I also don't understand the argument that encryption makes HAM closed. The internet is pretty open with encryption.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: