Live data from Hacker News

FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

rietta.com

11–20 of 184 posts

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#11
In the future, the few years following Snowden's revealations may be viewed as the golden years of strong cryptography: A time when service providers and application developers began taking these issues seriously.

We're moving into a new era now. All it may take is a single attack in the US to drive the legislative and judicial branches to roll back all the fantastic improvements we've seen over the past few years.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#12
Sort of a bummer that lawmakers don't have a better understanding of encryption in general and what it protects. They'd condemn hackers breaking into phones/accounts and stealing important notes/pictures, but turn around and condemn the very technology preventing that from happening to _everybody_

Anybody here want to run for office and be a voice for tech rights?

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#13
post #4

So... the FBI is essentially arguing we should all keep our doors unlocked because they have had to do some investigations in the past where they came to a home that was locked and it was hard for them to enter the home.

The FBI want to have a giant warehouse that houses a copy of every house key but we don't need to worry because no one will ever manage to break in to the warehouse.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#14
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

How many people can be bothered if it's not a turnkey solution?

Like I said it's not about the average person, it's about someone with something to hide. Those with something to hide will always go the extra distance.

The issue I take with the FBI approach is it will have no effect on those that have stuff to hide but destroy any semblance privacy for those that don't.

Terrorists will use GPG, citizens will use their backdoored iPhone full disk encryption and everyone but the terrorists lose.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#15
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

I see this objection raised so frequently, and I feel it really misses the point badly.

The tech community tells itself that it won the first "crypto wars". You cannot win "wars" against governments in that sort of sense and the first crypto war was never actually won at all. I think in light of events in recent years we need to reinterpret the events of the 90's in a new light - the tech industry didn't win, rather, after realising how awful and worthless the software the cypherpunks produced really was, the government simply got bored of playing.

Nobody, and I mean nobody, gives one tiny shit about GPG. GPG is so bad, such truly unusable software, that terrorists would literally rather die or risk lifetime imprisonment than use it:

   http://privacy-pc.com/articles/how-terrorists-encrypt-threatscape-overview.html
Governments don't care about GPG now, they don't care about some theoretical open source program that you could install from abroad, they only care about the encryption their adversaries actually use which - given that 99.9% of the FBI's adversaries are not crypto experts - turns out to be whatever ordinary people are using automatically thanks to tech companies switching it on.

This is especially true because often people don't meticulously plan crimes out ahead of time: they either commit crimes of passion, or they make basic mistakes. So if you have to plan ahead and convince not only yourself, but all your accomplices, all to install some exotic and awkward to use piece of technology ... well, a lot of bad guys won't do it.

So. If the FBI succeeds in breaking the encryption used by Apple, Google, Microsoft, Twitter, Facebook and a few other big names, then they've got 99% of the guys they want.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#16
post #14

Earlier quoted context omitted.

How many people can be bothered if it's not a turnkey solution?

Like I said it's not about the average person, it's about someone with something to hide. Those with something to hide will always go the extra distance. The issue I take with the FBI approach is it will have no effect on those that have stuff to hide but destroy any semblance privacy for those that don't. Terrorists will use GPG, citizens will use their backdoored iPhone full disk encryption and everyone but the ter…

Oh. I misinterpreted what you were saying to mean "it doesn't matter because we have GPG."

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#17
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

How many people can be bothered if it's not a turnkey solution?

Only terrorists.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#18
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

How many people can be bothered if it's not a turnkey solution?

Would it be possible to provide crypto as an open source "interface library" to commercial applications? So instead of the application doing the crypto (eg. Apple iOS) it would be farmed out to an optional library of the user's choosing.

Apple could make it easy for a user to install such a library and then say (truthfully) that the cryptographic functions of their OS is not in their hands, since that feature is handled by a third party open source maintainer.

At that point it would be an infinite game of whack-a-mole for the FBI to try to get backdoors in open source crypto interface libraries which could be maintained outside of the US.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#19
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

How many people can be bothered if it's not a turnkey solution?

Just those that have a lot to hide, such as the terrorists the FBI wanted to catch in the first place.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#20

Sort of a bummer that lawmakers don't have a better understanding of encryption in general and what it protects. They'd condemn hackers breaking into phones/accounts and stealing important notes/pictures, but turn around and condemn the very technology preventing that from happening to _everybody_ Anybody here want to run for office and be a voice for tech rights?

I'm not convinced that a lack of understanding isn't borne from a lack of giving a rat's ass to begin with. Why learn about something when your vote and influence are already bought and paid for?
Post reply on HN