Live data from Hacker News

Ask HN: What are your arguments in favor of end-to-end encryption?

news.ycombinator.com

31–40 of 255 posts

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#31
Those who would give up essential Liberty

For a little temporary Safety

Deserve neither Liberty nor Safety

Edit: Also, when you "think of the children" you have to think not only of their immediate safety but to think of their future ability to freely and safely converse with their peers, no matter what the current government deems "acceptable".

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#32
post #12
post #4

Earlier quoted context omitted.

[flagged]

I love this devil's advocation. I certainly don't agree with it but it makes a great conversation. Stir that pot.

> I certainly don't agree with it but it makes a great conversation.

Does it though? It seems like a fallacious comparation for reasons that other comments have already explained. And as such, it makes a confuse, meaningless conversation.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#35
The security and safety of almost everything relies on strong, uncompromised encryption.

There’s no way to reasonably draw, much less enforce, a line dividing licit and illicit uses.

If you compromise some subset of messages, illicit uses will just move to a non-compromised technology.

So instead of drawing a line, which is impossible (and also comes down to human judgements about things like whether gay people should be killed) the only choice left, if you insist on being able to decrypt messages, is to legislate the ability to decrypt all of them.

First of all, good luck enforcing that; second, in so doing you will sweep in a lot of legitimate uses of encryption and make people and businesses less safe by endangering their finances, their privacy, and even their physical safety.

Because once you give governments the ability to read messages even assuming key escrow entities can protect the integrity of the system (unlikely) this ability will be abused by bad governments who have records of inflicting human rights abuse on citizens for “crimes” as minor as being gay, being trans, or saying the wrong words about god.

And in addition to being accessed by the bad people in government and the bad people drawn like flies to honey to work in the key escrow organization, the escrow keys will get out and be abused by more bad people which will be an entire other level of problems.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#36

Encryption is math. Can we really make a form of math illegal? I feel privacy is a basic human right regardless of what country you live in. I’m not fan of punishing the majority because of a screwed up minority. People who commit illegal acts as horrible as child abuse and terrorism are not going to respect the law when it comes to encryption. Again, you can’t stop people from doing math. The idea of making it illeg…

Yes, and the silly people are often in power.

"Well the laws of Australia prevail in Australia, I can assure you of that. The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia."

https://www.theguardian.com/technology/2017/jul/14/forcing-f...

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#37
Just as E2EE can be used for crime, channels without E2EE can also be utilized for crime - mostly for blackmail, and especially if it gets compromised.

Even if you trust all actors involved in non-E2EE communication channel you can never assume that:

* This channel won't be compromised(hacking, wiretapping etc)

* That all actors involved(ISP, VPN host) will always stay trustworthy

Latter part is also related to laws - if you cannot prove that law cannot be abused by a bad actor then it shouldn't be a law.

Also banning encryption won't change the fact that it will be used. Criminals will still use it to hide their action, plus there is always steganography.

Also one of basic rules of law is "Innocent until proven guilty", banning E2EE basically reverses that.

I love the "nothing to fear, nothing to hide" argument, just reverse it and instead of applying to general populace - apply it to government as whole. Rules should work both ways - if citizens have nothing to fear if they have nothing to hide, the same should apply to all politicians and all government agencies.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#38
post #16

> how do you respond when someone brings up concerns of E2EE platforms being used for child sexual abuse imagery or terrorism? These are only a tiny part of uses of encryption. Ask anyone if he would like to have his bank transfers, or his credit card credentials in plain text. End to end encryption allows the whole internet to act as a commerce platform. Encryption allows journalists and activists in strict, control…

You are confusing E2EE encryption with encryption in transit/rest in the commerce example. The majority of transactions today are encrypted in transit and (you would hope) encrypted at rest so that the bank and selected parties can access the data (including the customer). There is no bank that would encrypt financial data using E2EE so that only the customer and merchant could access it, which is the analogy here on E2EE with messaging.

Sure, now we are looking at tokenization which reduces the risk merchants store your details insecurely, but commerce will always require a bank to store your information and share it with legislators for anti money laundering purposes etc.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#39
My go to about a government backdoor is that the NSA hacking tools are now leaked and the leading tool for Crypto Ransoms;

If CIA and NSA can't keep dangerous tools safe and secure from the bad actors; if the FBI (commonly thought of as less cover) or local police have a ready backdoor access to my phone, messages, credit cards, or anything else, then they're practically already in bad actor's hands.

The similar argument is that my state has lost my personally identifiable information in no less than 3 security incidents.

Post reply on HN