Live data from Hacker News

Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

cyber.law.harvard.edu

51–60 of 82 posts

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#51
post #46

It's not just about tech. The real issue is that government is running up against scaling limits. Arguably, a government can only rule over how people relate within boundaries it can defend and control. Previously the boundaries were physical geographies, and then regulated channels (mail, PSTN, etc). Now, we have a kind of fractal boundary of peer-to-peer connections that provide tremendous freedom to organize and t…

Is graffiti not illegal?

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#52
post #48

Earlier quoted context omitted.

A brick or electronic circuit is speech when being used as a medium of expression. Code is speech all the time because it can't be anything else. It's pure information. You can't email someone a brick. It happens we have machines that will turn that information into action, but the code isn't the machine or the action. It's just a type of speech that machines can understand too. People are always wanting to regulate…

A piece of encryption software is clearly both. It is speech. If you wanted to you could even go find the source code and translate it into english in such a way that a relatively competent programmer could turn it back into code ("If the first bit in the byte is 1 then do .... other wise do ...."). But it's clearly also a tool. I've never read the source code to the software I use to encrypt my hard drive. It's unli…

> Trying to say that it's either one or the other is silly. It's both.

I'm not trying to say that it's one or the other. I'm trying to say that there is no part of it that isn't speech. There is not a part which is a tool and a distinct part which is speech. The whole of it is speech. All you're saying is that it's possible to use pure speech as a tool. But what of it?

You can't win by talking about balancing because encryption software is meta. You can use it to distribute it. If people who are breaking no law have the right to be able to communicate without government surveillance then the government would have to violate that right universally to enforce any rule restricting the distribution of software, because distributing software over a secure channel is indistinguishable from any other communication of the same size. It's hard to imagine anything that could justify that level of intrusion, and certainly not anything that has been proposed as a countervailing interest in this context.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#53
post #46

It's not just about tech. The real issue is that government is running up against scaling limits. Arguably, a government can only rule over how people relate within boundaries it can defend and control. Previously the boundaries were physical geographies, and then regulated channels (mail, PSTN, etc). Now, we have a kind of fractal boundary of peer-to-peer connections that provide tremendous freedom to organize and t…

Is graffiti not illegal?

I've never lived in a district where it wasn't.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#54
post #29

Earlier quoted context omitted.

I shall be sure to quote more pertinent examples in future.

>The receptivity of the great masses is very limited, their intelligence is small, but their power of forgetting is enormous. In consequence of these facts, all effective propaganda must be limited to a very few points and must harp on these in slogans until the last member of the public understands what you want him to understand by your slogan. As soon as you sacrifice this slogan and try to be many-sided, the effe…

The subtitled versions of his speeches certainly shed new light on the guy. You realize how powerful (and potentially dangerous) charisma can be.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#55
post #32
post #23

Earlier quoted context omitted.

In context, I'm sure the parent commenter meant "a random key the same length as the plaintext", not a repeating key or a reused key.

Some people when faced with an encryption problem think 'I know, I'll use a non-repeating random text to XOR against the plain text', now they have two encryption problems.

Three if you count entropy.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#56
post #21
post #8

If we could only make them understand that forcing the good guys to not encrypt doesn't take encryption away from the bad guys. Legislators don't understand that encryption doesn't have to be made by Apple for the bad guys to have encryption. A shared key and XOR gives you unbreakable encryption. A high school comp sci. kid could implement that.

Incorrect, if the key is shared the encryption is breakable. If you're just doing one round of XOR it's pretty easy to break the key given a known plaintext, in the same way that AES is very breakable in ECB mode. For unbreakable encryption, I'd suggest XORing with the contents of /dev/random (assuming /dev/random is unknowable). Of course decryption may be an issue.

"If you're just doing one round of XOR it's pretty easy to break the key"

If you're doing two rounds, it's even easier!

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#57

My kneejerk reaction to this is to panic about the opposite of what the concern here seems to be. Seems to me like ubiquitous surveillance via any and all available technology is a bigger threat than "going dark" would be. I know encryption can provide an obstacle for law enforcement but my inclination is to worry about privacy in society over potential lawbreakers.

This ^

It seems to me that all this report is saying is: "Hey government, don't worry about tech 'going dark', we will still have the ability to spy on people through their poorly implemented Internet of Things devices, services that won't use end to end encryption, metadata, and because software is still fragmented."

But they don't seem to even slightly condemn the simple fact that governments are turning into surveillance machines...

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#58
post #22

This fake crisis of "Going Dark" as if we haven't been that way for all of time before the Internet is dangerous. The "scary" notion that the police won't be able to read everything about everyone is being recast by the Feds as if it really is national crisis. Benjamin Wittes suggests on Lawfare we make Common Carrier Immunity conditional on the company being able to make all data available in the clear to the govern…

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#59
post #22

Earlier quoted context omitted.

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

Prior to the Internet, cipher schemes existed that could delay or foil the best government analysts, and that took significant government efforts to even attempt to crack. It was never illegal to use such a code and transmit the result on a letter, postcard, or phone. And a government warrant would not compel the decipherment of such a scheme, unless someone had possession of a physical key usable for decipherment. T…

"possible path forward will make both parties happy" -> We only have to make 1 party happy: the 'people', as the government (should) serve them.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#60
There's an underlying issue that the report dances around, but doesn't address directly: sovereignty. Understandably enough, US authorities expect US companies to comply with US law. When foreigners are involved, as users or counterparties, things get iffy. Diplomatic relationships, treaties, agreements, etc become dispositive.

For example, the US supports Chinese dissidents, and maybe Thai dissidents, but for sure not ISIS. And so decrypted ISIS messages would be widely shared, but decrypted messages from Chinese dissidents would not be shared with China.

Old-school sovereignty just doesn't work on the Internet. If the US pushes hard enough, some firms will fold. But some may just leave. Consider the extent to which Apple has already left the US, for tax purposes.

Post reply on HN