Earlier quoted context omitted.
An even stronger guarantee: That the definition of trustworthy and "good guy" are unchanging, and even in a dystopian future where a rogue actor is in control of government, those keys are safe because they understand the morality of the people who created them.
I'd say something to invoke Godwin's law, but it seems pretty clear that genocidal governments that sweep into power love having access to copious amounts of detailed records.
FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
91–100 of 184 posts
Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#92Keep an eye on the would-be profiteers. Why would VCs like Fred Wilson land on the side of the FBI and parrot their position despite certainly knowing better? Because there are billions of dollars of government investment money being lined up to implement the wishful thinking key escrow and other back-door schemes. Even if back-doored encryption is doomed in the market, co-investors will be rewarded.
Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#93Earlier quoted context omitted.
Change it up: • We can have guns just for the good guys • We can have guns that only approved staff will use • We can block all the bad people from having guns and it'll be like guns don't exist! • If we have guns, only the good guys will use them. Seems like any dangerous technology can follow this mindset. :P
If only good guys used guns, nobody would need them. It actually is "we know bad guys already have guns, so better if good guys have them too". Same with crypto, btw.
Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#94Earlier quoted context omitted.
How many people can be bothered if it's not a turnkey solution?
Would it be possible to provide crypto as an open source "interface library" to commercial applications? So instead of the application doing the crypto (eg. Apple iOS) it would be farmed out to an optional library of the user's choosing. Apple could make it easy for a user to install such a library and then say (truthfully) that the cryptographic functions of their OS is not in their hands, since that feature is hand…
How? Keep the de/encryption software simple, dirt simple, just open source C code, run as a command line program on, say, an old PC/DOS system with no hard disk. For encryption, just put the file on, say, a smartphone, to be encrypted on a diskette, give the diskette to the PC, erase the orignal file from the smartphone, have the command line C code on the PC do the encryption and write the results as a base 64 file to a diskette, and, with no effort at all at encryption or security, let the smartphone read the diskette and send the file. Simple.
Just keep it simple, just dirt simple, really small, open source code.
The de/encryption has to be, what, just a few loops in C, in a few hundred lines of code? The rest is just dirt simple C file I/O just one byte at a time? So, very much do not want some 100,000 line app with the de/encryption buried deep inside somewhere. And want the de/encryption run on some other device, maybe an old PC/DOS machine with no hard disk and no network connection. Or get a Raspberry Pi running some simple operating system and where can be sure that no important data will be left on the computer.
Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#95Earlier quoted context omitted.
#feelthebern? http://feelthebern.org/bernie-sanders-on-privacy-and-digital...
Both Bernie and Hillary have been vague about their stance on having encryption backdoors, almost to the point of implicitly supporting encryption backdoors but not wanting to outright say it. Bernie's message about privacy isn't necessarily incompatible with encryption backdoors, at least not through the lens of political speak and all of its half-truths. disclaimer: bernie supporter, and not a supporter of encrypti…
http://www.washingtontimes.com/news/2015/nov/13/rand-paul-sa...
> “The head of the FBI came out with this recently. He says, ‘Oh, we’re going to ban encryption.’ And it’s like we want to build a backdoor into Facebook and a backdoor into Apple products,” the presidential hopeful said at the Yahoo Digital Democracy conference this week. “A backdoor means that the government can look at your stuff, look at your information, your conversations. … The problem is, is that the moment you build an opening — and I’m not an expert on coding or anything — but the moment you give a vulnerability to a code that someone can get into your source code, not only can the government, but so can your enemies, so can foreign governments.”
Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#96Earlier quoted context omitted.
The front door is a less useful metaphor than your safe. We have safes in addition to locked front doors because it's accepted getting into the house is generally not that hard, whether you be law enforcement or a criminal.
My parents worked for the NSA before there was an NSA. A guy came in to do a talk about how there is no such thing as security. He had a table with a bunch of common locks and even some safes. He proceeded to unlock each one in a matter of seconds to demonstrate his point. Modern encryption however is changing the game. It's no longer true that security is just a matter of perception. It's becoming a reality and that…
Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#97Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#98Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#99"A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication." [0]
The FBI can lobby to change that, but that's not what they're doing. They're lobbying that OTHER laws (e.g. the All Writs Act) enable what they want. Frankly, that's absurd... how can a 1789 law overrule a 1994 law when you're talking about modern technology?
Ironically, the FBI is creating incentives for new tech startups to incorporate outside of the USA. If you're building a product which depends on reliable encryption in order to be valuable, why the fuck would you incorporate in the USA?!? You would alienate foreign customers who are suspicious of the US legal/surveillance apparatus. And you would be entering a murky legal landscape where it seems increasingly likely that, if your startup ever becomes big enough to be a target, the government will require some kind of key escrow or it will shut down your business or even jail you.
In the face of that much uncertainty, it seems like it would be asinine to incorporate in the USA.
Maybe there is space in the market for a business to commoditize offshore incorporation. Make setting up a Seychelles corporation as easy as setting up a US LLC. Build in as many legal protection mechanisms as possible, e.g. owning the corporation via a trust that you are the sole executioner of.
[0] http://www.law.cornell.edu/uscode/47/usc_sec_47_00001002----...
Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow
#100Earlier quoted context omitted.
It's a huge lack of systems thinking. It's like they believe that the universe somehow cares about what they were trying to accomplish. * If we reward schools for increasing student test scores, then we'll have better schools. * If we fund a "war on drugs", we'll reduce the damage drugs do. * If we enact rent controls and mandate the construction of below-market rate housing units, it'll help people afford housing. T…
> If we enact rent controls and mandate the construction of below-market rate housing units, it'll help people afford housing. To be fair, this does in fact help many people afford housing. It just doesn't fix the endemic issue.