Live data from Hacker News

Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

feinstein.senate.gov

211–220 of 275 posts

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#211

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

> The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to have secrets and whisper to each other.

A huge amount of my social and work communication is via IM, text, email etc. What is the justification this should all be recorded and reviewable but things I say in person are not? I don't see a huge difference at this stage given how much communication happens online now.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#212

I'm getting pretty deep into bets on Twitter AGAINST this bill having a chance of passing. My logic is simple: this bill outlaws all sorts of things huge corporations use to protect their networks. No big company I've ever done security work for has ever been OK with crypto keys being escrowed by vendors; in fact, we were often instructed to look for exactly those kinds of features as disqualifiers for products. I do…

The poor drafting of the bill is reflective of lack of support from groups who have the expertise to produce a more realistic bill like NSA lawyers. The bill reflects the lack of cooperation from the Intelligence Community that has been reported.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#213
post #178

I'm not a lawyer, but it seems like complying with this law would preclude compliance with HIPAA, ISO 9001, various NSA-IAD directives, etcetera. Compliance with standards like those is often written into government contracts and sometimes required by statute or policy. If this law passed in its current form, wouldn't entire industries have to choose which laws to break when storing data?

I was wondering about this, but the data can remain encrypted and compliant as long as it's ultimately accessible by court order. I then assume the existing laws regarding courts accessing private health data apply.

There's no stipulation that data needs to be decryptable by the party holding it, is there? If the law passes in its current form, we'll probably see a slew of client-side encryption and secure multiparty computation offerings from providers.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#214

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

> Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. That is already the case. If you whisper a secret into my ear, the government can subpoena me and force me to tell a court what you said. They can force you to tell a court what you said so long as it's not incriminating to you, and even then they can do it if they give you immunity. We can debate about what…

> force me to tell a court what you said

Incorrect.

Government can attempt to legally compel you, but they cannot actually "force" you to do something. Even torture cannot actually "force" you to do something. What can force you to "tell a court what you said" is making it impossible for you to keep a secret; like mind-reading technology.

> ...legal system is built on being able to get whatever evidence is relevant wherever it may be found...

Think about it for a minute; Government says "tell us what you whispered", you say "no", then Government says "fine. you go to jail for contempt". Has our society collapsed because people said "no" to this question?

> ...being disingenuous to pretend that the government...

I'm not sure "disingenuous" was the word you meant to use here. There is nothing I've feigned ignorance about, and I've made my points pretty clear.

EDIT:

Ah, see @JoeAltmaier's already great sibling reply.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#215
post #96
post #73

Earlier quoted context omitted.

When guns are outlawed, only outlaws will have guns.

When guns are outlawed, only lawmen and outlaws will have guns. Good. That's the state of affairs in every developed country except one and it's demonstrably better in every way.

> That's the state of affairs in every developed country except one

Not even close to factual.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#216

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

A question for the more politically inclined:

Feinstein's seat is up in 2018, and she'll probably retire. How do we ensure our next Senator has a more technically literate position on encryption? Who are the plausible candidates?

In the 2012 open primary, the next highest Democratic candidate only got 2 percent of the vote compared to Feinstein's 49.5. So who is waiting in the wings?

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#217

Instead of complaining into the echo chamber of comments, here are some things you can do to fight back: Donate to the EFF: https://supporters.eff.org/donate/button Call your Reps: http://TryVoices.com Petition the President: https://savecrypto.org/

I just called my local reps (John Larson, Chris Murphy and Richard Blumenthal). Each call was quick, professional and friendly.

That was my first time calling and it was surprisingly painless.

I opted to provide my name and zip code. I think that allows them verify that I am a resident and maybe makes my comment carry more weight than it would without personalizing it. They seemed willing to accept comments either with a name or without one.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#218
post #206

Earlier quoted context omitted.

Respectfully, I disagree WRT SSH/TLS Section 2 (4) spells it out: communication service and software providers. That's the maker of every app on your phone, the phone manufacturer, your phone company, emails provider, retailer (they're communicating your data to their data warehouses). The summary clearly says "software manufacturers" (aside: manufacture software? facepalm ), "providers of wire...electronic...[or] re…

> aside: manufacture software? facepalm This is likely to make it less obviously a 1st-amendment issue. Saying "authors of software" makes it a fairly obvious restraint of speech.

Also, the government tends to separate out makers (manufacturers) from sellers (vendors), though they could be the same entity. Someone may be able to sell software (say on the Google Play Store or Steam or Apple's App Store), without restrictions. But the makers of the software would be subject to this law if their applications permitted or enabled encrypted communication.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#219

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

I think probably the right way to go after this bill is not to tell people that they need to protect their secrets from the government, but that they need to protect their secrets from 'criminals'. Point out all the times that government databases have been hacked, and that if their secrets are swept up in government dragnets, it's only a matter of time before blackmailers and identity thieves get hold of them.

Right. The anti-privacy lobby has their big 3 boogey men: "terrorists", "drug dealers", and "child molesters".

The pro-privacy lobby has 2 big boogey men: "criminals" and "the Chinese". What's our third boogeyman? We must close the boogeyman gap!

I suppose "crooked LEOs" doesn't have enough of a ring to it.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#220

Earlier quoted context omitted.

Why do you feel that decreasing your IT security will increase your security?

Two responses to that. Firstly because, well, that's just the way it is sometimes. Putting a gate in your wall can let in bad guys who can plunder your city, yes. But it can also let in good guys who can fortify it. You just need to design and use your gate well...and, I suppose, think of the government as good guys. (Soz, I've been indulging in some nostalgia with AOE 2: HD recently....) And two: who says this has t…

Which government are you even talking about ? All of them ? The Internet is still global.
Post reply on HN