Live data from Hacker News

FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

rietta.com

21–30 of 184 posts

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#21
Remember how New York’s (physical) master keys became easily accessible[1] despite the fact that they were supposedly so carefully managed? All that effort, all that trouble, and now not only is there essentially no security at all but the master keys created a security hole that did not need to exist.

The security of encryption is similarly proportional to the security of keys. The fewer things you have to secure, the easier it is to keep them secret. The “master key” concept in New York only served to create something of great value that people wanted to acquire, and massively increased the risk when that fell into the wrong hands. Obviously the same thing could happen with an encryption key, except it is worse because you don’t even have to be in the same country as the source of the key to acquire it or use it.

[1] http://www.nydailynews.com/new-york/pols-public-outraged-sho...

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#22
post #14

Earlier quoted context omitted.

How many people can be bothered if it's not a turnkey solution?

Like I said it's not about the average person, it's about someone with something to hide. Those with something to hide will always go the extra distance. The issue I take with the FBI approach is it will have no effect on those that have stuff to hide but destroy any semblance privacy for those that don't. Terrorists will use GPG, citizens will use their backdoored iPhone full disk encryption and everyone but the ter…

That's a problem too. Right now people with something to hide don't stand out amidst a background of similar encryption. If they suddenly have to switch to something relatively more exotic, that alone would be a coup for people in signals intelligence, don't you think?

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#23

Sort of a bummer that lawmakers don't have a better understanding of encryption in general and what it protects. They'd condemn hackers breaking into phones/accounts and stealing important notes/pictures, but turn around and condemn the very technology preventing that from happening to _everybody_ Anybody here want to run for office and be a voice for tech rights?

#feelthebern?

http://feelthebern.org/bernie-sanders-on-privacy-and-digital...

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#26

Sort of a bummer that lawmakers don't have a better understanding of encryption in general and what it protects. They'd condemn hackers breaking into phones/accounts and stealing important notes/pictures, but turn around and condemn the very technology preventing that from happening to _everybody_ Anybody here want to run for office and be a voice for tech rights?

I'm not convinced that a lack of understanding isn't borne from a lack of giving a rat's ass to begin with. Why learn about something when your vote and influence are already bought and paid for?

> a lack of giving a rat's ass to begin with.

Agreed...

> your vote and influence are already bought and paid for?

Overly cynical. The standard whipping boy for 'buying politicians' is Big Business, and Apple certainly qualifies as that. In fact, this is an affront to essentially every big business in the world with IP to protect.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#27
post #14

Earlier quoted context omitted.

Like I said it's not about the average person, it's about someone with something to hide. Those with something to hide will always go the extra distance. The issue I take with the FBI approach is it will have no effect on those that have stuff to hide but destroy any semblance privacy for those that don't. Terrorists will use GPG, citizens will use their backdoored iPhone full disk encryption and everyone but the ter…

That's a problem too. Right now people with something to hide don't stand out amidst a background of similar encryption. If they suddenly have to switch to something relatively more exotic, that alone would be a coup for people in signals intelligence, don't you think?

Yeah definitely. This is currently the problem with ToR.

The people that need the protection that ToR provides paint a target on their backs because there isn't enough ToR usage for them to be inconspicuous. Which is sad.. because for all of the bad usage of ToR there are people that depend on it to preserve free speech and any weakening of it could easily get them imprisoned or in many cases executed.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#28

Sort of a bummer that lawmakers don't have a better understanding of encryption in general and what it protects. They'd condemn hackers breaking into phones/accounts and stealing important notes/pictures, but turn around and condemn the very technology preventing that from happening to _everybody_ Anybody here want to run for office and be a voice for tech rights?

It's only a dichotomy if you see it from the angle where data is sacrosanct and its beset on all sides by evil trying to do it in.

The better way to approach this issue, long term, is from a legal point of view with an interim state where encryption holds us over. That is the law decides who may or may not own or access a certain type of data with penalties upon tort or criminality. And we develop civil protocols for days governance between people and between people and governments.

Like trademark. You could have it so trademark, i.e. authentication, is protected by mathematics, or you can have it protected legally.

Personally I don't believe the answer to data theft or surveillance is more mathematics in the form of encryption, but sensible laws regulating data its, use and access with penalties for transgressing. Obviously this would require international cooperation and would be a long way off and in the interim we'd need encryption to protect against unauthorized access until we reach that state of data governance. But ultimately the answer is not "make everything s black hole".

We don't protect against thieves by building impenetrable houses, we rely on legal instruments to dissuade burglary.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#29

Sort of a bummer that lawmakers don't have a better understanding of encryption in general and what it protects. They'd condemn hackers breaking into phones/accounts and stealing important notes/pictures, but turn around and condemn the very technology preventing that from happening to _everybody_ Anybody here want to run for office and be a voice for tech rights?

It might help if one of them gets their personal information leaked because they used unencrypted technology in their private lives. I do suspect this won't have any significant influence since they think the government will prevent the escrow from being hacked.

Part of me hopes that there will be a significant data leak from whatever the NSA has stored. Maybe they'd realize that single point of failure sucks.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#30
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

I see this objection raised so frequently, and I feel it really misses the point badly. The tech community tells itself that it won the first "crypto wars". You cannot win "wars" against governments in that sort of sense and the first crypto war was never actually won at all. I think in light of events in recent years we need to reinterpret the events of the 90's in a new light - the tech industry didn't win, rather,…

If the worst case scenario fulfill and people will get jailed for petty crimes based on evidence snooped from their personal electronic devices and social media accounts, they will realize that they actually have something to hide and will look for alternatives to puppet companies. That's where open source and/or non-USA&Co originated software comes to play. See Twitter and Whatsapp role in recent mass protests.
Post reply on HN