Live data from Hacker News

Re: Obama on Fetishizing Our Phones

jonathanmh.com

141–150 of 337 posts

Re: Re: Obama on Fetishizing Our Phones

#141
post #28

Earlier quoted context omitted.

That's wrong. The government isn't saying that no one should be able to encrypt data. They just thing that, in some cases, it should be done in such a way that certain data can be read by use of a centralized master key. This, of course, presents certain problems. What if that master key leaks? But it's not binary. Data secured this way is absolutely safer than not encrypting something at all. "Is it safe enough?" is…

It's actually less safe. People will think their data is secure, but it won't be. The government always leaks keys. Sometimes literally. http://www.wired.com/2015/09/lockpickers-3-d-print-tsa-lugga... http://nypost.com/2015/09/20/the-8-key-that-can-open-new-yor... Plus, any key that the government can use without your permission, they can illegally abuse. And if there's one thing we've seen proven recently, it's that…

It's worth noting that in this case we're only talking about keys that are useful to someone in physical possession of a phone. So as long as I retain physical possession of my phone no one can get at it, keys or not.

That's still pretty safe.

Re: Re: Obama on Fetishizing Our Phones

#142
post #119

Earlier quoted context omitted.

The fundamental issue is that any back door accessible to "the good guys" will also be accessible to sufficiently-technically-advanced "bad guys". And from the perspective of securing the United States' defense infrastructure, major corporations, etc., there are multiple sufficiently-technically-advanced "bad guys" in the world already (i.e., certain major foreign governments and their intelligence/defense complexes)…

We're talking about iPhones here. Not the nuclear launch codes. Maybe you have information on your phone that KGB is interested in, but most people don't. Again, security & encryption aren't binary. It isn't on or off. Different levels of protection are appropriate for different levels of threats. The lock on my mom's suburban house is a lot weaker than the lock on the vault holding the gold at Fort Knox. Similarly t…

And you presume that compromising the iPhones belonging to the men and women who do control the nuclear launch codes wouldn't serve to compromise everything they control, by extension? Either by using the data as a lever against the people, or directly snooping, this would be a very powerful opening, and your position seems to defy all common sense.

Re: Re: Obama on Fetishizing Our Phones

#143

Obama has a meta-point however that proponents of the absolutist position don't seem to want to face. Democracy relies on transparency. Many of the progressives who are rallying in support of absolute right to privacy are some of the same people who constantly criticize Swiss bank accounts, Cayman island financial shenanigans. But if companies were to implement the same sorts of impenetrable encryption, on every devi…

They can still plant bugs in offices, cars, homes, etc. That's specific and targeted and proportional, but expensive and hard.

There's no good reason they have to have access to electronic devices, they can install cameras and mics. It's just easier going straight to the phones and emails.

But they had that power and they abused it massively, and are now suffering the backlash, and why should privacy stop given they've demonstrated they can't be proportional in their surveillance?

They were not specific with what they got from the phones and emails, so they've demonstrated they're not responsible or measured and now strong encryption is necessary as government has clearly shown that secret courts === warrantless mass surveillance.

The other thing that's clear is that the US couldn't care less about privacy for anyone not in the US, so all us non-US citizen need this encryption to protect us from your peeping tom government.

Re: Re: Obama on Fetishizing Our Phones

#145
post #142
post #119

Earlier quoted context omitted.

We're talking about iPhones here. Not the nuclear launch codes. Maybe you have information on your phone that KGB is interested in, but most people don't. Again, security & encryption aren't binary. It isn't on or off. Different levels of protection are appropriate for different levels of threats. The lock on my mom's suburban house is a lot weaker than the lock on the vault holding the gold at Fort Knox. Similarly t…

And you presume that compromising the iPhones belonging to the men and women who do control the nuclear launch codes wouldn't serve to compromise everything they control, by extension? Either by using the data as a lever against the people, or directly snooping, this would be a very powerful opening, and your position seems to defy all common sense.

Obama used the word "fetishizing" for a reason. It's a pretty unusual word to use don't you think? It was carefully chosen though I'm sure.

Comments like this are exactly why he used it.

Re: Re: Obama on Fetishizing Our Phones

#146
post #125
post #99

Earlier quoted context omitted.

I disagree - digital surveillance state will be gone within a decade, or twenty years at most. Already we see programs like Telegram becoming very popular (100 million users) where the opportunity for surveillance is massively reduced. Platforms are going to slowly transition towards encrypted content and data that not even service providers can decrypt (SpiderOak is a good example). The biggest holdout will be opera…

I'm not talking about the state exclusively, nor am I talking about your online activities. I'm saying you will have a camera and microphone trained on you, always. My personal AI assistant - smart but not nearly sentient - knows to highlight the most titillating segments, which I have just captioned and published for all to see (anonymously, over an encrypted connection). It's great that one's ISP doesn't know what…

I guess I thought the drones were a joke or hyperbole in your post.

There are a lot of things that make me not concerned about your scenario. Firstly, cameras are easily defeated, especially by technology 50 years from now. You're presently a single curtain away from defeating them. In the future it might be some non-human visible light array that blinds a camera (these already exist today but aren't very common). Who knows.

Secondly, most people benefit from security and privacy through obscurity. No one cares about what 99% of people do. The other 1% will have easy means for protecting privacy, whether it be closing their curtains or some futuristic piece of technology.

Thirdly, I think expectations of privacy are going to naturally diminish a lot in the future. Sexuality will probably be a lot less stigmatized, and no one will care whether a state senator is jackin it to gay scat porn.

However advanced drones get, the technology to counter them bothering you will no doubt be a lot more advanced.

Re: Re: Obama on Fetishizing Our Phones

#147
post #119

Earlier quoted context omitted.

The fundamental issue is that any back door accessible to "the good guys" will also be accessible to sufficiently-technically-advanced "bad guys". And from the perspective of securing the United States' defense infrastructure, major corporations, etc., there are multiple sufficiently-technically-advanced "bad guys" in the world already (i.e., certain major foreign governments and their intelligence/defense complexes)…

We're talking about iPhones here. Not the nuclear launch codes. Maybe you have information on your phone that KGB is interested in, but most people don't. Again, security & encryption aren't binary. It isn't on or off. Different levels of protection are appropriate for different levels of threats. The lock on my mom's suburban house is a lot weaker than the lock on the vault holding the gold at Fort Knox. Similarly t…

Maybe you have information on your phone that KGB is interested in, but most people don't.

You have a very narrow view of what information is sensitive. Do you know how many Americans work either directly in, or in industries associated with, defense? How many of them use Apple products as part of their work?

Or let's take a more down-to-earth example: I work for a company in the health-care space. We have health records on thousands of people, and as we expand we'll have more health records on more people. With your approach, where should we draw the line? Would it be OK to use security bad enough that, say, an Eastern European organized-crime ring could break in? Or do we need to defend against them and not against the KGB? How do we figure out what level of tools to use to do that? How do we figure out whether what we have now will still be mafia-proof in five years?

Oh, and keep in mind that legally we have to protect that data, and improper access to it can not just shut down the company but send me and my co-workers to jail. How much would you be willing to compromise with that on the line? If the potential consequences to you were jail time, how much on the side of Obama and the FBI would you be? How much risk of that would you take on in order to make law enforcement's life a little bit easier?

And in case you think this is a red herring, remember the San Bernardino shooter... worked for a public-health department.

Re: Re: Obama on Fetishizing Our Phones

#148

Obama has a meta-point however that proponents of the absolutist position don't seem to want to face. Democracy relies on transparency. Many of the progressives who are rallying in support of absolute right to privacy are some of the same people who constantly criticize Swiss bank accounts, Cayman island financial shenanigans. But if companies were to implement the same sorts of impenetrable encryption, on every devi…

> 100% impregnable, and people maintain good OpSec

fortunately, that never happens. Even the strongest defenses consistently fall to human error

Re: Re: Obama on Fetishizing Our Phones

#149

A key promise of Obama's campaign for the presidency was to run the “most transparent” government- however the only person to really deliver on that promise was a whistleblower. Secret courts, secret domestic spying, and now calls for weakening of the digital equivalent of the safe shows that he either was not honest about transparency, or has radically changed his opinion since becoming POTUS. Maybe it's that he dec…

Ah, come ON: It was plenty clear just what the heck Obama was well before and during the election. E.g., Bill Ayers, Reverend Wright, and his other buddies. Then, during the campaign where he was campaigning and on a stage with Hillary and Bill Richardson and the US National Anthem was playing, Hillery and Bill had their hands over their hearts and Obama had his hands together and below his belt. Then there was his "my Muslim faith". Then on his apology tour where he bowed down to the heads of China, France, Saudi Arabia, and Japan.

What did you expect?

Re: Re: Obama on Fetishizing Our Phones

#150

Obama has a meta-point however that proponents of the absolutist position don't seem to want to face. Democracy relies on transparency. Many of the progressives who are rallying in support of absolute right to privacy are some of the same people who constantly criticize Swiss bank accounts, Cayman island financial shenanigans. But if companies were to implement the same sorts of impenetrable encryption, on every devi…

You're completely right that there are undesirable consequences to mathematically absolute privacy that can't be compromised by any means. But I'd argue that the government has brought this scenario upon itself by blowing up the old system of procedural (rather than mathematical) safeguards.

In the past, Apple had your iMessage data, or at least the ability to decrypt it on-demand. It was understood that this data would be private by default, but would be disclosed to the government through an established, case-by-case process supervised by the courts. Everyone was pretty much OK with this. You and I got our data kept private, unless there was some material, specific reason for the government to suspect it was related to a crime. The government got to dump the data of people under investigation, if a court thought there was good reason to do so.

Then the government went nuclear. They said, here's a National Security Letter that compels you to give us everything you have. Bulk data. Any cooperation that is physically possible. You can't talk about it and you can't appeal to the courts. If you have to capability to MiTM all of your users and pipe everything to us, you have to do it. No oversight, no transparency and no safeguards. Whatever we do with the data is up to us.

In this context, what alternative do tech companies have besides to similarly escalate and build systems that make it physically impossible for them to cooperate?

The government destroyed the social compact between telecom providers and law enforcement with forced, secret bulk surveillance. If the government is willing to step back and make binding, unequivocal commitments that companies that do maintain the ability to decrypt their users' communications won't be forced to secretly use them en masse, maybe we can go back to the old status quo. But the government doesn't seem willing to do that. They want cooperation, but they also want the ability to bust in the back door with an NSL and say "give us everything, on everyone."

The legal system has become so tilted in the government's favour (see: the inability to challenge the constitutionality of bulk surveillance, because you can't prove it happened to you), that companies will no longer trust in the old procedural safeguards. The only thing we can trust is the mathematically proven safety of encryption. And that's the government's fault. So now we are forced to chose between absolute privacy and zero privacy.

So far, I think Apple is making the right choice.

Post reply on HN