Live data from Hacker News

FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

rietta.com

101–110 of 184 posts

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#101
post #66
post #53

Earlier quoted context omitted.

The front door is a less useful metaphor than your safe. We have safes in addition to locked front doors because it's accepted getting into the house is generally not that hard, whether you be law enforcement or a criminal.

A warrant is just as effective against nearly all safes. I have little doubt that if a safe was in FBI custody as long as the San Bernardino shooter's phone has been, the FBI would have been able to legally and physically get whatever was inside. The FBI simply wants the digital world to mirror the physical world and a 100% unbreakable physical lock is almost impossible to produce in the physical world. It is easy to…

In this case, the digital world mirrors the physical world. Since this phone doesn't have secure enclave, they could trivially break into it. The fact that they've said they can't makes them liars. Very public liars. And are liars considered trustworthy?

https://www.aclu.org/blog/free-future/one-fbis-major-claims-...

[EDIT for added link]

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#102
I think an interesting approach that could be taken by Apple is to concede to letting the FBI have a master key, so long as they hold an insurance policy that covers the damages in the case of a key leak, including but not limited to the potential damage to Apple's brand and market value, and the same damages to all of Apple's customers that relied on their security.

That would force the FBI to reconcile the costs of maintaining a multi-trillion dollar insurance policy with the expected value of a potential reduction in terrorism. When it comes to the US government, money seems to talk louder than anything else...seems like it could possibly work.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#103
post #11

In the future, the few years following Snowden's revealations may be viewed as the golden years of strong cryptography: A time when service providers and application developers began taking these issues seriously. We're moving into a new era now. All it may take is a single attack in the US to drive the legislative and judicial branches to roll back all the fantastic improvements we've seen over the past few years.

They can "roll back" for mass marketed products but not for some simple, open source software in standard C that someone runs on an old PC with PC/DOS, no hard disk and no network connection. So, when turn the power off, the PC forgets everything about the de/encryption. The only non-volatile storage is on diskette. If worried, then just burn those. With the encryption done, the output is just a base 64 file of gibberish safe to mail to the NYT, FBI, CIA, NSA, etc. And with no attempts at security, can use products from Apple, Google, and Microsoft can send such data with no problem.

The little command line programs on PC/DOS? Easy enough for middle school students to use; when that was state of the art computing, middle school students did use it.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#105

Earlier quoted context omitted.

But that is so revealing of the mindset. * We can have strong encryption just for the good guys * We can have master keys that only approved staff will use * We can block all the bad things on the internet and it'll be like they don't exist * If we have a back door into an encrypted device, only the good guys will use it It's like no politician ever read about crime. Staff can't be blackmailed or bribed. No one worki…

It's a huge lack of systems thinking. It's like they believe that the universe somehow cares about what they were trying to accomplish. * If we reward schools for increasing student test scores, then we'll have better schools. * If we fund a "war on drugs", we'll reduce the damage drugs do. * If we enact rent controls and mandate the construction of below-market rate housing units, it'll help people afford housing. T…

* If we fund a "war on climate change", we'll reduce the damage of (or hey, even stop!) climate change.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#106
post #95
post #68

Earlier quoted context omitted.

Both Bernie and Hillary have been vague about their stance on having encryption backdoors, almost to the point of implicitly supporting encryption backdoors but not wanting to outright say it. Bernie's message about privacy isn't necessarily incompatible with encryption backdoors, at least not through the lens of political speak and all of its half-truths. disclaimer: bernie supporter, and not a supporter of encrypti…

Encryption policy will ultimately be resolved by the legislature and not the president. The only presidential candidate who was on the record as explicitly against encryption backdoors was Rand Paul, but that ship has sailed: http://www.washingtontimes.com/news/2015/nov/13/rand-paul-sa... > “The head of the FBI came out with this recently. He says, ‘Oh, we’re going to ban encryption.’ And it’s like we want to build a…

The issue is that the NSA, FBI, etc are essentially controlled by the President. These groups have and will continue to have extremely creative interpretations of the law, to the point of essentially ignoring it and doing whatever the fuck they want without repercussion. Legislature can pass whatever they want, but three letter orgs will continue to have secret courts, secret laws, and secret operations that operate outside established public law.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#107
post #31

Earlier quoted context omitted.

Interesting article. I find amusing this (quite popular) type of argumentation: > "This is a serious security breach," said Councilman Peter Vallone (D-Queens), who heads the Council's Public Safety Committee. "We know terrorists are planning to attack our subways, and the MTA and NYPD better find these magical morons quickly, and then make them disappear for a year in jail." Like the only thing between terrorists an…

But that is so revealing of the mindset. * We can have strong encryption just for the good guys * We can have master keys that only approved staff will use * We can block all the bad things on the internet and it'll be like they don't exist * If we have a back door into an encrypted device, only the good guys will use it It's like no politician ever read about crime. Staff can't be blackmailed or bribed. No one worki…

> Are most politicians really that stupid?

They aren't stupid, they just don't share your interests.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#108

I think an interesting approach that could be taken by Apple is to concede to letting the FBI have a master key, so long as they hold an insurance policy that covers the damages in the case of a key leak, including but not limited to the potential damage to Apple's brand and market value, and the same damages to all of Apple's customers that relied on their security. That would force the FBI to reconcile the costs of…

I, for one, would gladly enjoy having to pay for the insurance policy in the form of taxes out of my paycheck to cover the stupidity of having a master key system in place, not to mention when the premiums skyrocket after said key gets stolen and all of our iPhones get breached. /s

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#109
post #28

Sort of a bummer that lawmakers don't have a better understanding of encryption in general and what it protects. They'd condemn hackers breaking into phones/accounts and stealing important notes/pictures, but turn around and condemn the very technology preventing that from happening to _everybody_ Anybody here want to run for office and be a voice for tech rights?

It's only a dichotomy if you see it from the angle where data is sacrosanct and its beset on all sides by evil trying to do it in. The better way to approach this issue, long term, is from a legal point of view with an interim state where encryption holds us over. That is the law decides who may or may not own or access a certain type of data with penalties upon tort or criminality. And we develop civil protocols for…

> That is the law decides who may or may not own or access a certain type of data with penalties upon tort or criminality.

What if criminals are willing to break those laws? (That's kind of the definition of criminals, after all.) Who cares, you say, because data isn't sacrosanct? Well, some of the data we'd like to protect is financial, and criminals can use it to steal my money, so I care.

What if foreign governments are willing to break those (US) laws? Again, who cares, you ask? Well, if I'm a company facing foreign competition, and the foreign government is willing to do economic espionage to help their companies, then I care. And if I'm the US government or military, I definitely care.

What if the US government is willing to break those laws? It'll never happen, you say? Read some history. It's happened before, and it will again.

The law only protects me against people willing to obey the law. I also need protection against those unwilling to obey the law.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#110
post #66
post #53

Earlier quoted context omitted.

The front door is a less useful metaphor than your safe. We have safes in addition to locked front doors because it's accepted getting into the house is generally not that hard, whether you be law enforcement or a criminal.

A warrant is just as effective against nearly all safes. I have little doubt that if a safe was in FBI custody as long as the San Bernardino shooter's phone has been, the FBI would have been able to legally and physically get whatever was inside. The FBI simply wants the digital world to mirror the physical world and a 100% unbreakable physical lock is almost impossible to produce in the physical world. It is easy to…

> the FBI would have been able to legally and physically get whatever was inside.

What if the safe has a self-destruct mechanism for the contents in case of breach?

Post reply on HN