Live data from Hacker News

Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

feinstein.senate.gov

201–210 of 275 posts

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#201

Earlier quoted context omitted.

Why do you feel that decreasing your IT security will increase your security?

Two responses to that. Firstly because, well, that's just the way it is sometimes. Putting a gate in your wall can let in bad guys who can plunder your city, yes. But it can also let in good guys who can fortify it. You just need to design and use your gate well...and, I suppose, think of the government as good guys. (Soz, I've been indulging in some nostalgia with AOE 2: HD recently....) And two: who says this has t…

>who says this has to involve decreasing IT security?

Which type of system would you feel safer guarding all of your most personal information in? Keep in mind that the system doesn't care if you're a "bad guy" or a "good guy":

1. A system which was designed to be "unbreakable"

2. A system which was designed to be breakable

Without encryption there is no IT security (if there even was such a thing).

Love me some AOE btw.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#202

Earlier quoted context omitted.

This is not true. The bill would only apply to encryption mechanisms provided by Microsoft or a third-party application installed by Microsoft as part of the operating system. Interestingly, this bill covers vendors and presumably US persons that "provide a product or method". You'll still be able to legally use foreign-developed tools. The US would have grounds to ask those foreign agents to decrypt data, but would…

It covers anything that's been licensed into the software, which would include encryption libraries. It covers hard drive manufacturers (provides a product or method of to facilitate a communication or the processing or storage of data). Communication, by their definition btw, includes electronic and ORAL communication. As others have mentioned, it literally covers whispering if someone or something amplifies or tran…

Absolutely, but the bill does nothing to prevent users from installing hardware or software that has been built without a backdoor. You will still be able to use Veracrypt, if you'd like, without backdoors. I do not see in this bill provisions which prevent vendors building equipment that can run arbitrary code, use arbitrary devices, or arbitrary mechanisms. (However, I'll look again)

The assumption of liability is on vendors. Vendors are expected to sell you broken goods. Developers of VeraCrypt in the above example would be expected to provide a backdoor. If they're foreign, then it will be largely unenforceable, although those developers will likely face difficulties visiting the USA.

Where users are restricted is wherein they become vendors or providers of software or services. Running a Tor server may require being prepared to provide keys or offer a backdoor, for instance. I think the bill as written could have trouble with distributing VM and container images as well, although a case may be made that they are not operating as "software manufacturers" and are simply distributors, with the liabilities reaching back to Canonical, RedHat, Microsoft, etc.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#203
post #142

Earlier quoted context omitted.

Guns are somewhat difficult to produce. This is more akin to knife control.

Any weapon analogy is bad for our side of the argument, because weapons sound to many people like things that bad people use to do bad things. Yes, I realize that knives are used in kitchens to cut vegetables, but with the way this discussion is rightly framed as a security thing, people are not thinking about kitchens. I would prefer to see lock analogies. Here's a half baked example: This is like a law requiring al…

You mean like a Knox Box[0]?

[0]: https://en.wikipedia.org/wiki/Knox_Box

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#204

I'm getting pretty deep into bets on Twitter AGAINST this bill having a chance of passing. My logic is simple: this bill outlaws all sorts of things huge corporations use to protect their networks. No big company I've ever done security work for has ever been OK with crypto keys being escrowed by vendors; in fact, we were often instructed to look for exactly those kinds of features as disqualifiers for products. I do…

This is negotiation. It's an adversarial system. The proponents of this bill know they are not going to get everything they ask for. The point is to stake out a position very far toward what they want so as to force opponents of this bill to just whittle it down.

If they proposed something saner and lost, they'd lose completely. But propose something insane and lose and you still might win something.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#205
post #152

Earlier quoted context omitted.

I wouldn't count on that. They could go with a licensing system where you need to pay big bucks to use crypto without escrow. This scheme, of course would be beneficial for incumbents, because it raises the barrier for entry and pushes out the smaller players who can't afford such costs.

Sure, but that's not this law.

This is still the initial draft of the law, and it's common for laws to get marked up with changes that benefit those in power.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#206

What this does and doesn't do: This bill effectively makes it illegal for US companies and persons to build or use secure enclaves / TPMs and to publish cryptosystems without either including backdoors or retaining and storing keys. It also implies that companies would need to store keys indefinitely, otherwise they would not be able to decrypt data, as no time limitations are set on the capability of accessing data.…

Respectfully, I disagree WRT SSH/TLS Section 2 (4) spells it out: communication service and software providers. That's the maker of every app on your phone, the phone manufacturer, your phone company, emails provider, retailer (they're communicating your data to their data warehouses). The summary clearly says "software manufacturers" (aside: manufacture software? facepalm ), "providers of wire...electronic...[or] re…

> aside: manufacture software? facepalm

This is likely to make it less obviously a 1st-amendment issue.

Saying "authors of software" makes it a fairly obvious restraint of speech.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#207

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

> Government is not as stupid as we'd like to think. Government doesn't believe that "terrorists" will stop using encryption. These laws are not for "terrorists". They're for us.

This is one of the things that the Snowden leaks should have made clear to everyone but sadly that isn't the case.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#208

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

Remember folks, the Government you get in the future is unwritten and unknowable.

Sure, I don't think Obama is going to throw me in jail and I have nothing to hide now...but that doesn't mean in 20 years there won't be some Nationalist/Authoritarian type in control of the country like we saw with countless fallen democracies in the 20th century.

Similarly, the Government has shown it incapable of keeping a secret with the sheer number of security failures they've experienced. So anything they have, we can assume is both public and indefensible. They use this capability and they might as well hand the information to criminals on a silver platter.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#209
The bill may allow the government to force a software vendor to perform work without any agreement regarding costs. It allows the government to decide "reasonably necessary costs".

Once any work has begun, the government can force (subpoena) the vendor to testify regarding results, without any payment whatsoever.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#210
I'm always conflicted with this.

On one end, I feel like security is hard enough that we don't need to go weakening it, in any way, to allow the government to be able to (with a lawful warrant) read the data. I feel like the citizens of the US are overall more secure with end to end encryption that no-one can backdoor.

On the other end, security is hard and we fail in so many other obvious, exploitable ways. Even with mandating that e.g. Apple be able to decrypt the contents of any iPhone it does not actually reduce our security in a meaningful way because there's so many other ways we routinely fail at security.

Post reply on HN