Live data from Hacker News

Times Pulls Article Blaming Encryption in Paris Terror Attack

insidesources.com

161–170 of 312 posts

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#161

"One key premise here seems to be that prior to the Snowden reporting, The Terrorists helpfully and stupidly used telephones and unencrypted emails to plot, so Western governments were able to track their plotting and disrupt at least large-scale attacks. That would come as a massive surprise to the victims of the attacks of 2002 in Bali, 2004 in Madrid, 2005 in London, 2008 in Mumbai, and April 2013 at the Boston Ma…

I don't fully understand this line of thinking. To me, it's like saying "The belief that seat belts save lives might come as a surprise to these people who died in automobile accidents while wearing seat belts."

It may indeed be that this kind of signals intelligence isn't actually helpful, but I don't think this is a very good argument either way. If there was a massive disruption of planned terrorist attacks, it is not useless just because there wasn't a complete elimination of terrorist attacks.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#162
post #120

"One key premise here seems to be that prior to the Snowden reporting, The Terrorists helpfully and stupidly used telephones and unencrypted emails to plot, so Western governments were able to track their plotting and disrupt at least large-scale attacks. That would come as a massive surprise to the victims of the attacks of 2002 in Bali, 2004 in Madrid, 2005 in London, 2008 in Mumbai, and April 2013 at the Boston Ma…

It's even more absurd than that. The premise is that we can have a public worldwide debate that emphasizes how important encryption is to successfully carrying out terrorist attacks, convince the world to give up their privacy for the sake of safety, and after the majority of the protestors have been defeated by public awareness that encryption and terrorism go hand-in-hand, the terrorists will go back to using phone…

> It's even more absurd than that... after the majority of the protestors have been defeated by public awareness that encryption and terrorism go hand-in-hand, the terrorists will go back to using phone calls and unencrypted email.

I think you're straw-manning their position here.

The opponents of encryption aren't claiming terrorists will start using unencrypted communication, they're advocating for legally-mandated "back doors" to be built into supposedly-secure communication systems.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#163
post #145
post #120

Earlier quoted context omitted.

It's even more absurd than that. The premise is that we can have a public worldwide debate that emphasizes how important encryption is to successfully carrying out terrorist attacks, convince the world to give up their privacy for the sake of safety, and after the majority of the protestors have been defeated by public awareness that encryption and terrorism go hand-in-hand, the terrorists will go back to using phone…

If (almost) everyone who is not a terrorist were to give up encryption, then it would be much easier to track down/narrow down the terrorists if they keep using it, no?

Maybe, but I'd rather not send my financial information over the Internet in cleartext every time I buy something from a web site.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#164

Earlier quoted context omitted.

CAs do not have backdoor access. The most a rogue CA can do is possibly enable a MITM against a website that has taken no protections. Google pins their public key fingerprints right into Chrome, and this feature is open: https://hstspreload.appspot.com/

I don't understand. How can you be sure that they haven't shared their keys to the government?

Having a CA's private keys only allows you to generate new signed certificates for a site, not decrypt traffic encrypted using an existing signed key pair. At best, it gives you the ability to spoof a website with a man-in-the-middle attack (e.g. you run a rogue wifi hotspot with a fake amazon.com that uses a private key you generated), although certificate-pinning would warn the user that Amazon's certificate had changed unexpectedly.

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#165
post #142
post #18

Earlier quoted context omitted.

You seem to be overlooking the obvious argument that if a small group of people use encryption, then you greatly reduce the number of messages that you need to flag. Furthermore, if someone on a Watch List starts using encryption then perhaps you have an imminent problem. I'm not on the side of reading messages but you missed the real argument being made. Typical HN. How about someone answering the argument that will…

Encryption is important and is crucial to the security mechanisms that underly the whole internet. I don't think anybody is seriously advocating making encryption illegal. (Which makes your argument pointless.) What does seem being argued for is to mandate adding a 'backdoor' for the government. The counter argument to that is that adding a 'backdoor' makes the encryption pretty much worthless. The weighing of risks…

"Which makes your argument pointless"

Of course it doesn't, and that's not what I meant. I didn't mean wholesale outlaw, as in no one would be allowed to use it. Governments can mandate consumer communication technology, for example, like they are trying to do with Apple now.

http://betanews.com/2015/11/17/tim-cook-apple-wont-weaken-en...

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#166
post #145
post #120

Earlier quoted context omitted.

It's even more absurd than that. The premise is that we can have a public worldwide debate that emphasizes how important encryption is to successfully carrying out terrorist attacks, convince the world to give up their privacy for the sake of safety, and after the majority of the protestors have been defeated by public awareness that encryption and terrorism go hand-in-hand, the terrorists will go back to using phone…

If (almost) everyone who is not a terrorist were to give up encryption, then it would be much easier to track down/narrow down the terrorists if they keep using it, no?

[deleted]

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#168

"One key premise here seems to be that prior to the Snowden reporting, The Terrorists helpfully and stupidly used telephones and unencrypted emails to plot, so Western governments were able to track their plotting and disrupt at least large-scale attacks. That would come as a massive surprise to the victims of the attacks of 2002 in Bali, 2004 in Madrid, 2005 in London, 2008 in Mumbai, and April 2013 at the Boston Ma…

[deleted]

Re: Times Pulls Article Blaming Encryption in Paris Terror Attack

#169
post #134

Earlier quoted context omitted.

Historically, though, the real threat is usually a state actor -- often one's own government -- that has been granted (or has seized) a monopoly on such tools. In particular, the modern notion that the state is the only rightful wielder of force has an unlimited downside. Terrorism is pretty far down the list of things that frighten me.

The problem with having everybody possess potentially deathly tools is not terrorism, but crime in general. I, for myself, can think of a lot more crimes committed by normal people than the government. The historical argument is of course not completely unreasonable, but there are also an awful lot of discrepancies when looking at states government today and 300 years ago. At least in Europe, where I live, the govern…

At least in Europe, where I live, the government can be trusted in a lot of issues --- especially it is highly likely that they _try_ to do what is best and are no "evil emperors".

The Europeans are fond of reminding Americans that we think 200 years is a long time. So, how long ago was the Stasi disbanded, again?

Post reply on HN