Live data from Hacker News

Times Pulls Article Blaming Encryption in Paris Terror Attack

insidesources.com

151–160 of 312 posts

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#151
post #145
post #120

Earlier quoted context omitted.

It's even more absurd than that. The premise is that we can have a public worldwide debate that emphasizes how important encryption is to successfully carrying out terrorist attacks, convince the world to give up their privacy for the sake of safety, and after the majority of the protestors have been defeated by public awareness that encryption and terrorism go hand-in-hand, the terrorists will go back to using phone…

If (almost) everyone who is not a terrorist were to give up encryption, then it would be much easier to track down/narrow down the terrorists if they keep using it, no?

I don't think so, as far as I know encrypted data doesn't really have a signature that can be easily spotted

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#152
post #145
post #120

Earlier quoted context omitted.

It's even more absurd than that. The premise is that we can have a public worldwide debate that emphasizes how important encryption is to successfully carrying out terrorist attacks, convince the world to give up their privacy for the sake of safety, and after the majority of the protestors have been defeated by public awareness that encryption and terrorism go hand-in-hand, the terrorists will go back to using phone…

If (almost) everyone who is not a terrorist were to give up encryption, then it would be much easier to track down/narrow down the terrorists if they keep using it, no?

No because they're not using it in the first place. It's a totally unrelated issue, dear to some for reasons entirely their own. The fear of terrorism is just a convenient little button to press to get their cookie.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#153

A link to the NYT article now redirects readers to a separate, general article on the attacks, which does not contain the word “encrypt.” The original piece can be found on the Internet Archive. https://web.archive.org/web/20151115191248/http://www.nytime...

The language seems pretty reasonable... "The attackers are believed to have communicated using encryption technology, according to European officials who had been briefed on the investigation but were not authorized to speak publicly. It was not clear whether the encryption was part of widely used communications tools, like WhatsApp, which the authorities have a hard time monitoring, or something more elaborate. Inte…

What's this "encryption technology"? It just sounds like another case of "a hacker named 4chan", meaning the media throwing around buzzwords like they know what they mean. Encryption is built into technologies, not something that stands on its own like a weapon. It's like saying, "the hacker used http to gain access to the server".

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#154
post #145
post #120

Earlier quoted context omitted.

It's even more absurd than that. The premise is that we can have a public worldwide debate that emphasizes how important encryption is to successfully carrying out terrorist attacks, convince the world to give up their privacy for the sake of safety, and after the majority of the protestors have been defeated by public awareness that encryption and terrorism go hand-in-hand, the terrorists will go back to using phone…

If (almost) everyone who is not a terrorist were to give up encryption, then it would be much easier to track down/narrow down the terrorists if they keep using it, no?

Indulging this fantasy, it begs the question of whether those (enencrypted) communications would have been targeted and flagged for analysis

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#155

Earlier quoted context omitted.

I'm pretty sure they are trying to push for encryption with government backdoor access. SSL certificates are issued by centralized authorities that can easily provide access to governments (if they don't do so already). Not that I agree with what they're trying to do.

CAs do not have backdoor access. The most a rogue CA can do is possibly enable a MITM against a website that has taken no protections. Google pins their public key fingerprints right into Chrome, and this feature is open: https://hstspreload.appspot.com/

I don't understand. How can you be sure that they haven't shared their keys to the government?

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#156

I blame prime numbers, even co-primes should be banned. Please contact your representative and help us free the world from evil math.

This! The generation of large primes needs to be banned. The government needs to work with chips manufacturers to insure that no computing device can generate large primes. This is the root of the issue. If large primes go away, so does encryption! We need to make sure our government understands this. #BanLargePrimes

I'll notify the Mersenne project.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#157

"One key premise here seems to be that prior to the Snowden reporting, The Terrorists helpfully and stupidly used telephones and unencrypted emails to plot, so Western governments were able to track their plotting and disrupt at least large-scale attacks. That would come as a massive surprise to the victims of the attacks of 2002 in Bali, 2004 in Madrid, 2005 in London, 2008 in Mumbai, and April 2013 at the Boston Ma…

It would indeed come as a massive surprise to the 2008 Mumbai terrorists, who were well versed in in using encrypted channels to communicate --

http://www.nytimes.com/2008/12/09/world/asia/09mumbai.html?_...

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#158

Earlier quoted context omitted.

CAs do not have backdoor access. The most a rogue CA can do is possibly enable a MITM against a website that has taken no protections. Google pins their public key fingerprints right into Chrome, and this feature is open: https://hstspreload.appspot.com/

I don't understand. How can you be sure that they haven't shared their keys to the government?

You don't need to send your private key to a CA to get a cert. You send them a CSR with your public key.

https://en.wikipedia.org/wiki/Certificate_signing_request

Edit: Ah, if you were talking about the CA's private keys, then the parent is correct.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#159

Earlier quoted context omitted.

Unfortunately this is a very widespread notion in culture and is helped by major religions.

I wonder how true that is. For Christianity at least, most dominant theology takes the view that the things that exist in the world can be used for good or for ill and aren't inherently one or the other in and of themselves.

Same with Buddhism

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#160

"One key premise here seems to be that prior to the Snowden reporting, The Terrorists helpfully and stupidly used telephones and unencrypted emails to plot, so Western governments were able to track their plotting and disrupt at least large-scale attacks. That would come as a massive surprise to the victims of the attacks of 2002 in Bali, 2004 in Madrid, 2005 in London, 2008 in Mumbai, and April 2013 at the Boston Ma…

I think I remember a terrorist attack in 2011 too.
Post reply on HN