Live data from Hacker News

The Moral Failure of Computer Scientists

theatlantic.com

11–20 of 49 posts

Re: The Moral Failure of Computer Scientists

#11
post #9

In short: no. This is a political problem that must be solved by laws that people push for. People have been supporting surveillance state or apathetic. Hence, it's winning and their combo of police power + secrecy + immunity is stronger than crypto.

Wrong. The surveillance state does not follow laws, and it has all the dirt it could ever want on politicians. Laws are not a solution here. The first rule of security is "don't trust the network". Computer scientists and developers who build systems that require users to trust the network are uniquely culpable. This is an unpopular opinion here because many of us would like to continue collecting hefty paychecks whi…

You're way off. The people and politicians knew to get a grip on this decades ago when they discovered all the abuses of CIA, etc. They had two main choices:

1. Create accountability mechanisms a la GAO working alongside these organizations ensuring they follow the law and imprison offenders.

2. Create a court that approves most of what they do, never imprisons offenders, and operates in secret.

America went with No 2. Further, most of those caught red-handed didn't do time. Americans also didn't push hard for reform with their votes. Intelligence and oversight fought back and forth but effective immunity let their corruption and power expand over time. It went into overdrive post-9/11 where people not only didn't do crap: they encouraged giving secrecy, vast power, and criminal immunity to the very groups that failed pre-9/11.

So, this didn't happen in a vacuum and isn't today. American's apathy and frankly ignorance is what gave scumbags a series of blank checks with immunity. Americans didn't do anything learning about Iraq WMD's, 2008 frauds, Snowden leaks, and so on. Largely nothing but griping. Meanwhile, in Iceland, they straight up overthrew their dirty government after 2008 abuses and passed new laws protecting their citizens. Exactly what Americans have to do.

Let's say they don't. Then, Congress continues passing police state style legislation, secret agencies bribe our ISP's/whoever, fabs eventually get compromised, dissidents are harassed via many means, opponents with dirt are jailed via parallel construction, patent system will be used against tech companies trying to solve it, and so on. Damn near pointless to try to technologically solve a problem that a country's citizens and politicians are creating and expanding with laws that can attack users of the tech.

All this shit is Americans' fought. Their common sense should've told them giving God-like knowledge and power to already-dirty groups was stupid. Doing it with secrecy and immunity was stupider. Not doing anything post abuses was foolish. My money is on them still being fools aiding surveillance state 5 years from now. They have to wise up and remove the internal threats' legal authority before technical solutions have a chance.

Re: The Moral Failure of Computer Scientists

#12

In short: no. This is a political problem that must be solved by laws that people push for. People have been supporting surveillance state or apathetic. Hence, it's winning and their combo of police power + secrecy + immunity is stronger than crypto.

Strongly disagree. Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen. Consider: we can send all our email as non-enveloped postcards and rely on the laws that our correspondence privacy is protected. But for some reason we don't. Why we still send send out our Internet corr…

"Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen."

It actually prevents many things when the law is clear. Your email example misses the entire point. So, let's use it to illustrate the point. I create an encryption system to protect email. It gets large uptake to point NSA and FBI are pissed by it. With current laws, they will feel free to:

1. Hit me with a FISA warrant to order a backdoor or key leak.

2. Hit me with court order to do the same.

3. Parallel construct some dirt on me.

4. Use NSA TAO or TAREX to smash my systems for their benefit.

5. Use FBI to raid my stuff or seize my property.

6. Have me audited by SEC or IRS depending on my company structure.

We've seen stuff like this happen to leakers, supporters of Wikileaks, companies resisting subversion, etc. You can build all the tech in the world but it's not that helpful if legal system is set up to destroy the user or developer easily. Those laws need to be rolled back. Only the people can do that. They don't give a shit enough to act. So, it's a political problem rather than technical one.

Feel free to continue to deploy and use tech to protect yourself. Just know the bigger problem is what's enabling their surveillance dragnet and police state problem in first place. The things that can get you with or without crypto. The things that have to go away to maintain democracy.

Re: The Moral Failure of Computer Scientists

#13
Yes, cryptographers should take on the surveillance state.

So should developers, and entrepreneurs, and politicians, and the common citizen that thinks AES is some foreign sports conference or IND-CCA is a new trade agreement.

I'm growing tired of watching journos try to point the fingers of "encryption is good, says cryptographers" and "encryption is bad, says this guy in a federal law enforcement position" and completely miss the greater point that unless everyone takes on the surveillance state, everyone will lose. The intelligence community is made up of humans. Some of them are there idealistically; others are there solely for power, just like in any megapolitical organization.

Should take on the surveillance state is a shit clickbait title. It can always be reduced to:

Should you take on the surveillance state?

If you care at all about a semblance of privacy and the expression of individual ideas, the answer is always yes. Of course, there's a whole lot less to write about there to generate ad revenue.

Any approach in which a single subculture, whether it is thought leaders or soccer moms, tries to enact meaningful change in a system that at least pretends to be a representative democracy, will not be enough to reach a critical mass to actually do something. Cultures correct negative behavior through consistent reinforcement of a norm. Until people want privacy as a norm, and fight for privacy as a norm, the flames fueling a surveillance state are simply being retarded, not extinguished.

Re: The Moral Failure of Computer Scientists

#14

Yes, cryptographers should take on the surveillance state. So should developers, and entrepreneurs, and politicians, and the common citizen that thinks AES is some foreign sports conference or IND-CCA is a new trade agreement. I'm growing tired of watching journos try to point the fingers of "encryption is good, says cryptographers" and "encryption is bad, says this guy in a federal law enforcement position" and comp…

" tries to enact meaningful change in a system that at least pretends to be a representative democracy, will not be enough to reach a critical mass to actually do something. Cultures correct negative behavior through consistent reinforcement of a norm. Until people want privacy as a norm, and fight for privacy as a norm, the flames fueling a surveillance state are simply being retarded, not extinguished."

That's my exact point. The laws need to change to reduce what they can do, punish offenses, and optionally encourage the better approaches. To get that, a huge amount of people have to lean on Congress. That will only happen if they start valuing their privacy or at least have common sense that scumbags + unlimited power/knowledge + immunity is a bad idea. Cryptographers, past speaking out, can't solve that problem and hence are just irritating to opponents who continue to win while laws enable them to.

Re: The Moral Failure of Computer Scientists

#15

Earlier quoted context omitted.

Strongly disagree. Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen. Consider: we can send all our email as non-enveloped postcards and rely on the laws that our correspondence privacy is protected. But for some reason we don't. Why we still send send out our Internet corr…

"Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen." It actually prevents many things when the law is clear. Your email example misses the entire point. So, let's use it to illustrate the point. I create an encryption system to protect email. It gets large uptake to point N…

Pointers to (seemingly) frivolous prosecutions (3) and pointers to anything resembling 4 or 6 would make them a lot more interesting.

Without just a little bit of evidence, they are like saying the NSA will shoot your dog.

My naive, facile reading suggests that systems like Signal, Pond and Tor tend to be more effective at actually securing communications, so it would be especially interesting to hear about the jackboots kicking them.

Re: The Moral Failure of Computer Scientists

#16

Earlier quoted context omitted.

Strongly disagree. Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen. Consider: we can send all our email as non-enveloped postcards and rely on the laws that our correspondence privacy is protected. But for some reason we don't. Why we still send send out our Internet corr…

"Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen." It actually prevents many things when the law is clear. Your email example misses the entire point. So, let's use it to illustrate the point. I create an encryption system to protect email. It gets large uptake to point N…

Ah, sorry, I see your point now. I suppose I got it wrong when I replied to your comment. Yes, I fully agree with you here on the point that the laws that allow this are wrong and they must be rolled back. Those are legal issues and they must be fixed as such.

I must make it clear that I stand that both legal and technological measures are necessary and are equally important. And I believe that neither would work well without the other one.

Current mass surveillance relies on lack of technical measures that protect from one. So, I believe that if everyone and their dog encrypts their correspondence in a secure manner, it would cause much greater hit on mass surveillance programs than any lawmaking could do. Please note I don't say that lawmaking is not necessary here. On the contrary, it is equally important to prevent TLAs from even trying to break technological measures and hold them responsible for their actions.

Re: The Moral Failure of Computer Scientists

#17
post #9

Earlier quoted context omitted.

Wrong. The surveillance state does not follow laws, and it has all the dirt it could ever want on politicians. Laws are not a solution here. The first rule of security is "don't trust the network". Computer scientists and developers who build systems that require users to trust the network are uniquely culpable. This is an unpopular opinion here because many of us would like to continue collecting hefty paychecks whi…

You're way off. The people and politicians knew to get a grip on this decades ago when they discovered all the abuses of CIA, etc. They had two main choices: 1. Create accountability mechanisms a la GAO working alongside these organizations ensuring they follow the law and imprison offenders. 2. Create a court that approves most of what they do, never imprisons offenders, and operates in secret. America went with No…

This comment doesn't make a whole lot of sense to me.

What's all this talk about America? We've been talking about China the whole time. You're seriously blaming the Chinese people for their heavy-handed government? By focusing their work in directions that harm freedom, computer scientists and developers make it easier for the Chinese government to use surveillance to hold onto power.

Re: The Moral Failure of Computer Scientists

#18

In short: no. This is a political problem that must be solved by laws that people push for. People have been supporting surveillance state or apathetic. Hence, it's winning and their combo of police power + secrecy + immunity is stronger than crypto.

The legal aspect was taken care of by the Bill of Rights. The govt is trying to erode them and so now we need to "fight" against it.

Re: The Moral Failure of Computer Scientists

#19

Earlier quoted context omitted.

"Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen." It actually prevents many things when the law is clear. Your email example misses the entire point. So, let's use it to illustrate the point. I create an encryption system to protect email. It gets large uptake to point N…

Ah, sorry, I see your point now. I suppose I got it wrong when I replied to your comment. Yes, I fully agree with you here on the point that the laws that allow this are wrong and they must be rolled back. Those are legal issues and they must be fixed as such. I must make it clear that I stand that both legal and technological measures are necessary and are equally important. And I believe that neither would work wel…

"I must make it clear that I stand that both legal and technological measures are necessary and are equally important. And I believe that neither would work well without the other one."

100% agree. The overall solution will combine technological methods and legal reforms. We continue developing and implementing what technical solutions we can for privacy and security in general. Just have to never fool ourselves on what it will take to stop the huge internal threat.

Re: The Moral Failure of Computer Scientists

#20
post #17

Earlier quoted context omitted.

You're way off. The people and politicians knew to get a grip on this decades ago when they discovered all the abuses of CIA, etc. They had two main choices: 1. Create accountability mechanisms a la GAO working alongside these organizations ensuring they follow the law and imprison offenders. 2. Create a court that approves most of what they do, never imprisons offenders, and operates in secret. America went with No…

This comment doesn't make a whole lot of sense to me. What's all this talk about America? We've been talking about China the whole time. You're seriously blaming the Chinese people for their heavy-handed government? By focusing their work in directions that harm freedom, computer scientists and developers make it easier for the Chinese government to use surveillance to hold onto power.

I'm talking about the surveillance state in America. My points apply to surveillance states in most democracies, though. China is a rather extreme situation. Yet, the points still apply: their people at the mercy of a corrupt government means the government can use laws and money poured into harmful tech to continue to hold them down. The solution, even there, will be aimed by the people straight at the government.
Post reply on HN