Live data from Hacker News

Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

cyber.law.harvard.edu

21–30 of 82 posts

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#21
post #8

If we could only make them understand that forcing the good guys to not encrypt doesn't take encryption away from the bad guys. Legislators don't understand that encryption doesn't have to be made by Apple for the bad guys to have encryption. A shared key and XOR gives you unbreakable encryption. A high school comp sci. kid could implement that.

Incorrect, if the key is shared the encryption is breakable. If you're just doing one round of XOR it's pretty easy to break the key given a known plaintext, in the same way that AES is very breakable in ECB mode.

For unbreakable encryption, I'd suggest XORing with the contents of /dev/random (assuming /dev/random is unknowable). Of course decryption may be an issue.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#22

This fake crisis of "Going Dark" as if we haven't been that way for all of time before the Internet is dangerous. The "scary" notion that the police won't be able to read everything about everyone is being recast by the Feds as if it really is national crisis. Benjamin Wittes suggests on Lawfare we make Common Carrier Immunity conditional on the company being able to make all data available in the clear to the govern…

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once they have a warrant their power to search is nearly limitless.

Thus, the government has always had a way to search the long-distance communications mechanisms of its day. Wiretapping telegraph or telephone lines was not deemed a violation of the 4th amendment until 1967. Even after that, a wiretap was authorized with a warrant.

Now, you have a pervasive mechanism of long-distance communications, and it's increasingly opaque to the government, even with a warrant. That's an unprecedented state of affairs.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#23
post #21
post #8

If we could only make them understand that forcing the good guys to not encrypt doesn't take encryption away from the bad guys. Legislators don't understand that encryption doesn't have to be made by Apple for the bad guys to have encryption. A shared key and XOR gives you unbreakable encryption. A high school comp sci. kid could implement that.

Incorrect, if the key is shared the encryption is breakable. If you're just doing one round of XOR it's pretty easy to break the key given a known plaintext, in the same way that AES is very breakable in ECB mode. For unbreakable encryption, I'd suggest XORing with the contents of /dev/random (assuming /dev/random is unknowable). Of course decryption may be an issue.

In context, I'm sure the parent commenter meant "a random key the same length as the plaintext", not a repeating key or a reused key.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#24
post #21
post #8

If we could only make them understand that forcing the good guys to not encrypt doesn't take encryption away from the bad guys. Legislators don't understand that encryption doesn't have to be made by Apple for the bad guys to have encryption. A shared key and XOR gives you unbreakable encryption. A high school comp sci. kid could implement that.

Incorrect, if the key is shared the encryption is breakable. If you're just doing one round of XOR it's pretty easy to break the key given a known plaintext, in the same way that AES is very breakable in ECB mode. For unbreakable encryption, I'd suggest XORing with the contents of /dev/random (assuming /dev/random is unknowable). Of course decryption may be an issue.

Wrong. It's just not secure in all contexts e.g. your example where you have a known plaintext that you can use to crack the key which then lets you decrypt something encrypted with the same key. You're discovering why XOR isn't widely used in a real-world setting.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#25
post #23
post #21

Earlier quoted context omitted.

Incorrect, if the key is shared the encryption is breakable. If you're just doing one round of XOR it's pretty easy to break the key given a known plaintext, in the same way that AES is very breakable in ECB mode. For unbreakable encryption, I'd suggest XORing with the contents of /dev/random (assuming /dev/random is unknowable). Of course decryption may be an issue.

In context, I'm sure the parent commenter meant "a random key the same length as the plaintext", not a repeating key or a reused key.

Thanks. Yup.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#26
post #22

This fake crisis of "Going Dark" as if we haven't been that way for all of time before the Internet is dangerous. The "scary" notion that the police won't be able to read everything about everyone is being recast by the Feds as if it really is national crisis. Benjamin Wittes suggests on Lawfare we make Common Carrier Immunity conditional on the company being able to make all data available in the clear to the govern…

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

Prior to the Internet, cipher schemes existed that could delay or foil the best government analysts, and that took significant government efforts to even attempt to crack. It was never illegal to use such a code and transmit the result on a letter, postcard, or phone. And a government warrant would not compel the decipherment of such a scheme, unless someone had possession of a physical key usable for decipherment.

The two differences now: we've made that technology available to non-experts, and we hope that no amount of government effort can crack the scheme (as opposed to obtaining the key).

I agree with your comment that it's not a "fake crisis", though. It's one with only one right answer, but it's a "crisis" in the sense that no possible path forward will make both parties happy, so we fundamentally need the government to either realize they're wrong or to lose. Government positions don't change easily, and governments do not like to lose.

While it bothers me to see terms like "common ground" used, as they imply that both positions have grounds worth considering, I do think one of the few paths that has a hope of success is to convince the government that there exists a position they can adopt that doesn't look like it goes back on their current stance.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#27
post #12

Something learned in my 30y career as low level felon and spending fairly significant amounts of time (to me at least...a week in jail is no picnic!) locked up in both jail and prisons... 95% of cases are made via informants and not CSI-type investigations, so the whole "going dark" thing, I feel, isn't going to affect law enforcement the way a lot of people think it might. I did notice, however, my last time through…

Going dark has a significant effect on law enforcement. It'll force them to rely on active investigations instead of passively collecting data that they can review at their leisure.

I think this will reduce their ability to target people for political reasons.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#28
post #18

Earlier quoted context omitted.

I think (most) of us on HN are on the same page here. But we are a minority... many people truly don't care and are not incentivized to care.

For pretty much any political issue the people caring are a minority (on each side) with middle being populated with people who don't care or don't know what's going on. Those people on the sides that do care then shape the debate and ultimately the outcome of pretty much any democratic decision (as little as those are still left).

"Never doubt that a small group of thoughtful, committed citizens can change the world; indeed, it's the only thing that ever has." -Margaret Mead

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#29

Earlier quoted context omitted.

> If you want to beat it, brand it. Obamacare, The Surge, War on Terror. The Surge and the War On Terror were branded by their supporters. Obamacare was branded that way by those trying to defeat it, but it hasn't worked. So, not sure your examples illustrate your point.

I shall be sure to quote more pertinent examples in future.

>The receptivity of the great masses is very limited, their intelligence is small, but their power of forgetting is enormous. In consequence of these facts, all effective propaganda must be limited to a very few points and must harp on these in slogans until the last member of the public understands what you want him to understand by your slogan. As soon as you sacrifice this slogan and try to be many-sided, the effect will piddle away, for the crowd can neither digest nor retain the material offered. In this way the result is weakened and in the end entirely cancelled out.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#30
post #22

This fake crisis of "Going Dark" as if we haven't been that way for all of time before the Internet is dangerous. The "scary" notion that the police won't be able to read everything about everyone is being recast by the Feds as if it really is national crisis. Benjamin Wittes suggests on Lawfare we make Common Carrier Immunity conditional on the company being able to make all data available in the clear to the govern…

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

We could also say that Americans have always had a right to encrypt their long-distance communications, and the government is now questioning this right for what may be the first time.

http://vjolt.net/vol2/issue/vol2_art2.html

As Eben Moglen also observed in a closely related context, Americans have also always had the right to use languages or shorthands of their choice when communicating, many of which significantly (perhaps even entirely) hindered the government from understanding them, and sometimes by design.

http://old.law.columbia.edu/publications/yu-encrypt.html

Post reply on HN