Live data from Hacker News

FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

rietta.com

31–40 of 184 posts

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#31

Remember how New York’s (physical) master keys became easily accessible[1] despite the fact that they were supposedly so carefully managed? All that effort, all that trouble, and now not only is there essentially no security at all but the master keys created a security hole that did not need to exist. The security of encryption is similarly proportional to the security of keys. The fewer things you have to secure, t…

Interesting article. I find amusing this (quite popular) type of argumentation:

> "This is a serious security breach," said Councilman Peter Vallone (D-Queens), who heads the Council's Public Safety Committee. "We know terrorists are planning to attack our subways, and the MTA and NYPD better find these magical morons quickly, and then make them disappear for a year in jail."

Like the only thing between terrorists and the subway platforms is that they can't afford ticket, so they have to go through the staff gate.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#32
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

I see this objection raised so frequently, and I feel it really misses the point badly. The tech community tells itself that it won the first "crypto wars". You cannot win "wars" against governments in that sort of sense and the first crypto war was never actually won at all. I think in light of events in recent years we need to reinterpret the events of the 90's in a new light - the tech industry didn't win, rather,…

Usage patterns can easily change for a variety of reasons. WhatsApp is hugely popular now, but tomorrow it might be something else not based in the US.

If they manage to write a law such that it bans strong encryption from the App Store, that will achieve their goal. But any other scenario is at best a temporary gain.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#33
post #13
post #4

So... the FBI is essentially arguing we should all keep our doors unlocked because they have had to do some investigations in the past where they came to a home that was locked and it was hard for them to enter the home.

The FBI want to have a giant warehouse that houses a copy of every house key but we don't need to worry because no one will ever manage to break in to the warehouse.

And everyone with legitimate access to the warehouse will be 100% trustworthy no matter what for the entire span of time they are granted access, and nobody without legitimate access will ever be allowed in, even someone like a co-worker of someone with access, and even under the full supervision of someone with legitimate access.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#34
post #4

So... the FBI is essentially arguing we should all keep our doors unlocked because they have had to do some investigations in the past where they came to a home that was locked and it was hard for them to enter the home.

The only reason they aren't actually advocating for exactly that is because it's easy for them to break into a locked home. If there were some new technology that made breaking into a house almost totally impossible, this is exactly what would happen.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#35
post #13
post #4

So... the FBI is essentially arguing we should all keep our doors unlocked because they have had to do some investigations in the past where they came to a home that was locked and it was hard for them to enter the home.

The FBI want to have a giant warehouse that houses a copy of every house key but we don't need to worry because no one will ever manage to break in to the warehouse.

It's worse than that. They want to ship those keys to their agents, only they'd arrive instantly and the only authentication is probably a password (their kid's name and birthday) with no human intervention.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#36
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

I see this objection raised so frequently, and I feel it really misses the point badly. The tech community tells itself that it won the first "crypto wars". You cannot win "wars" against governments in that sort of sense and the first crypto war was never actually won at all. I think in light of events in recent years we need to reinterpret the events of the 90's in a new light - the tech industry didn't win, rather,…

GPG was just an example. Other end-to-end open-source systems are more widely used like Signal are the same, not exactly easy to insert a backdoor into a system that is a) open and b) completely distributed with no central key authority.

Maybe it still misses the point because the FBI doesn't actually care about hitting hard targets. If that is the case that is pretty sad.

Average crimes can be solved with average tools, we shouldn't be authorising access to phones and other electronic intercepts or access without crimes that go beyond average.

You could argue the San Bernadino case was beyond average, and you would probably be right. But the perps knew that too, that is why they destroyed the phones after they were done, chances are they took other measures too but no one will know as they destroyed the devices.

What is clear is not that these laws wouldn't make their jobs easier - they almost certainly would. But they aren't needed and that implementing them would have 0 effect on the actually hard targets that they in theory would be useful for neutralising.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#37

Remember how New York’s (physical) master keys became easily accessible[1] despite the fact that they were supposedly so carefully managed? All that effort, all that trouble, and now not only is there essentially no security at all but the master keys created a security hole that did not need to exist. The security of encryption is similarly proportional to the security of keys. The fewer things you have to secure, t…

And terrifyingly enough, the Council's Public Safety Commitee said to this: "We know terrorists are planning to attack our subways, and the MTA and NYPD better find these magical morons quickly, and then make them disappear for a year in jail."

So, clearly the solution is to JAIL the users of the keys, instead of actually replacing this with a better system.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#38
post #13

Earlier quoted context omitted.

The FBI want to have a giant warehouse that houses a copy of every house key but we don't need to worry because no one will ever manage to break in to the warehouse.

And everyone with legitimate access to the warehouse will be 100% trustworthy no matter what for the entire span of time they are granted access, and nobody without legitimate access will ever be allowed in, even someone like a co-worker of someone with access, and even under the full supervision of someone with legitimate access.

An even stronger guarantee: That the definition of trustworthy and "good guy" are unchanging, and even in a dystopian future where a rogue actor is in control of government, those keys are safe because they understand the morality of the people who created them.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#39

Remember how New York’s (physical) master keys became easily accessible[1] despite the fact that they were supposedly so carefully managed? All that effort, all that trouble, and now not only is there essentially no security at all but the master keys created a security hole that did not need to exist. The security of encryption is similarly proportional to the security of keys. The fewer things you have to secure, t…

Why? They're not a taxi company. Thry

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#40

So we've moved from the clipper chip to, prospectively in the near future, the Clapper chip. History is trying to repeat itself, but this time we have legal precedent. https://en.wikipedia.org/wiki/Bernstein_v._United_States https://blog.cr.yp.to/20160315-jefferson.html All this sort of tactic will do is result in irreparable damage to the tech sector and the US economy. No murders, rapes, child abductions, terrorist…

> On October 15, 2003, almost nine years after Bernstein first brought the case, the judge dismissed it and asked Bernstein to come back when the government made a "concrete threat".

I guess the threat's technically not here yet, but seems like it's right around the corner. djb, pack your bags for the ninth circuit.

Post reply on HN