Live data from Hacker News

FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

rietta.com

61–70 of 184 posts

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#61

Comey's argument makes sense at first. Why not have a trusted escrow provider keep keys safe, and also respond to court orders when necessary. It feels almost like a checks and balances kind of argument, the kind that Americans find persuasive with our three-branch government. The problem is that we now know that the government has the goal of unlawful surveillance without oversight from courts, the legislature, or t…

So what do you do when the "trusted" escrow provider gets hacked, just like OPM was, and countless US corporations who've had customer records and credit card numbers stolen?

What's the point of using encryption if you're going to put the keys in the hands of some unaccountable entity which is easily hacked? You might as well not use it at all then.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#62
It seems as though the tech community (myself included) uniformly agrees that the FBI's requests are unreasonable.

Is there someone with a sound technological understanding of encryption that thinks we should have some back door / key escrow / master key? I've seen that Fred Wilson and other USV partners seem to think the FBI's requests are reasonable, and usually I trust their analysis. But this whole thing just seems like such a bad idea.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#63
post #31

Earlier quoted context omitted.

Interesting article. I find amusing this (quite popular) type of argumentation: > "This is a serious security breach," said Councilman Peter Vallone (D-Queens), who heads the Council's Public Safety Committee. "We know terrorists are planning to attack our subways, and the MTA and NYPD better find these magical morons quickly, and then make them disappear for a year in jail." Like the only thing between terrorists an…

But that is so revealing of the mindset. * We can have strong encryption just for the good guys * We can have master keys that only approved staff will use * We can block all the bad things on the internet and it'll be like they don't exist * If we have a back door into an encrypted device, only the good guys will use it It's like no politician ever read about crime. Staff can't be blackmailed or bribed. No one worki…

Change it up:

• We can have guns just for the good guys • We can have guns that only approved staff will use • We can block all the bad people from having guns and it'll be like guns don't exist! • If we have guns, only the good guys will use them.

Seems like any dangerous technology can follow this mindset. :P

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#64

Remember how New York’s (physical) master keys became easily accessible[1] despite the fact that they were supposedly so carefully managed? All that effort, all that trouble, and now not only is there essentially no security at all but the master keys created a security hole that did not need to exist. The security of encryption is similarly proportional to the security of keys. The fewer things you have to secure, t…

People challenging this anti-crypto movement should really push this example because it is really perfect. Before we consider key escrow, please explain exactly how physical key escrow was breached in New York and tell us how that will be prevented when the key in question isn't even something you have to physically get.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#65
post #54

Earlier quoted context omitted.

> a lack of giving a rat's ass to begin with. Agreed... > your vote and influence are already bought and paid for? Overly cynical. The standard whipping boy for 'buying politicians' is Big Business, and Apple certainly qualifies as that. In fact, this is an affront to essentially every big business in the world with IP to protect.

>In fact, this is an affront to essentially every big business in the world with IP to protect. it really isn't, because many of the biggest business want a greater degree of population control, and having access to all of every individuals info is a means to that end.

It seems a bit of a reach to say that government is demanding the tools to build a surveillance state because of unnamed "big business" wanting population control. That seems to only happen in bad sci-fi and Internet comments.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#66
post #53
post #48

Earlier quoted context omitted.

The FBI already has access to pretty much any locked door they want if they get a warrant. Their problem is that warrants don't work against encryption.

The front door is a less useful metaphor than your safe. We have safes in addition to locked front doors because it's accepted getting into the house is generally not that hard, whether you be law enforcement or a criminal.

A warrant is just as effective against nearly all safes. I have little doubt that if a safe was in FBI custody as long as the San Bernardino shooter's phone has been, the FBI would have been able to legally and physically get whatever was inside.

The FBI simply wants the digital world to mirror the physical world and a 100% unbreakable physical lock is almost impossible to produce in the physical world. It is easy to see why they would want that to be true in the digital world.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#67
post #31

Earlier quoted context omitted.

Interesting article. I find amusing this (quite popular) type of argumentation: > "This is a serious security breach," said Councilman Peter Vallone (D-Queens), who heads the Council's Public Safety Committee. "We know terrorists are planning to attack our subways, and the MTA and NYPD better find these magical morons quickly, and then make them disappear for a year in jail." Like the only thing between terrorists an…

But that is so revealing of the mindset. * We can have strong encryption just for the good guys * We can have master keys that only approved staff will use * We can block all the bad things on the internet and it'll be like they don't exist * If we have a back door into an encrypted device, only the good guys will use it It's like no politician ever read about crime. Staff can't be blackmailed or bribed. No one worki…

Government agencies & the military have to use computers. Those devices either will be secure or they won't be. How does the CIA, NSA, and DoD feel about that?

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#68

Sort of a bummer that lawmakers don't have a better understanding of encryption in general and what it protects. They'd condemn hackers breaking into phones/accounts and stealing important notes/pictures, but turn around and condemn the very technology preventing that from happening to _everybody_ Anybody here want to run for office and be a voice for tech rights?

#feelthebern? http://feelthebern.org/bernie-sanders-on-privacy-and-digital...

Both Bernie and Hillary have been vague about their stance on having encryption backdoors, almost to the point of implicitly supporting encryption backdoors but not wanting to outright say it. Bernie's message about privacy isn't necessarily incompatible with encryption backdoors, at least not through the lens of political speak and all of its half-truths.

disclaimer: bernie supporter, and not a supporter of encryption backdoors

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#69
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

I see this objection raised so frequently, and I feel it really misses the point badly. The tech community tells itself that it won the first "crypto wars". You cannot win "wars" against governments in that sort of sense and the first crypto war was never actually won at all. I think in light of events in recent years we need to reinterpret the events of the 90's in a new light - the tech industry didn't win, rather,…

Yup.

By analogy the lawyers can outlaw six egg omelets with butter and orange flavor. So, then McDonald's won't be able to sell them, but I can still make them in my own kitchen.

The lawyers can outlaw strong encryption on products from Apple, Google, Microsoft, etc. and, then, crooks who use those products can more easily be caught, and that will amount to nearly all the common crooks. But I can still get some simple, open source C code for some simple command line RSA or PGP de/encryption and use it for secure communications with others who do the same. And serious people will, and likely do.

I.e., just get the open source code for RSA from Schneier's book or look at the open source code in Zimmerman's PGP. Or just read Schneier's book and write your own code and make it open source for yourself and all people you want to communicate with.

So, to send an encrypted message in a file, from a smartphone, tablet, laptop, desktop, etc., copy the file to an old computer, if only via diskette, running PC/DOS and never connected to the Internet. Run the command line C program for encryption. Get the output file, in just simple base 64. Then copy that file to the smartphone or whatever and send it, with no attempt at security. Done.

This way, it doesn't matter what Apple, Google, Microsoft, do/don't do since they are just moving base 64 gibberish that is perfectly safe even if printed in the NYT.

The command line programs? Easy enough for middle school children to use. Simple.

Math 1. Lawyers 0.

Now what is there to argue about?

So, all this stuff about the FBI is just the village idiot playing public pocket pool, right?

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#70
post #31

Earlier quoted context omitted.

Interesting article. I find amusing this (quite popular) type of argumentation: > "This is a serious security breach," said Councilman Peter Vallone (D-Queens), who heads the Council's Public Safety Committee. "We know terrorists are planning to attack our subways, and the MTA and NYPD better find these magical morons quickly, and then make them disappear for a year in jail." Like the only thing between terrorists an…

But that is so revealing of the mindset. * We can have strong encryption just for the good guys * We can have master keys that only approved staff will use * We can block all the bad things on the internet and it'll be like they don't exist * If we have a back door into an encrypted device, only the good guys will use it It's like no politician ever read about crime. Staff can't be blackmailed or bribed. No one worki…

It's a huge lack of systems thinking. It's like they believe that the universe somehow cares about what they were trying to accomplish.

* If we reward schools for increasing student test scores, then we'll have better schools.

* If we fund a "war on drugs", we'll reduce the damage drugs do.

* If we enact rent controls and mandate the construction of below-market rate housing units, it'll help people afford housing.

This belief - that "having a goal and doing something that pattern-matches to helping" works - is incredibly dangerous in policy-makers. It's also incredibly difficult to fix, since the incentives for politicians are to make rationalizations that are convincing to voters, and that kind of reasoning is much easier to convey.

Post reply on HN