Live data from Hacker News

Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

feinstein.senate.gov

261–270 of 275 posts

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#261
post #15

Another brick in the wall. What are we going to do a out it? Maybe Wikipedia or Google will deface their own websites, and the bill will die only to resurrect shortly after. A better solution would be for the millions of tech workers to unite and vote GOP just to send a message that we don't automatically vote for anyone or any party. If California's vote is locked for a certain party, then it is taken for granted.

Voting for GOP candidates isn't going to change anything.

Of course not. Unless you happen to have R. Paul as your senator the GOP typically is worse.

Its playing the two sides off each other that might work. Make the GOP think will vote for them. Make the democrats think they'll loose our contributions.

Getting rid of Feinstein will be an excellent first step.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#262

Earlier quoted context omitted.

It's really the establishment within both the Democratic and Republican parties that is pushing for this. It's opposed by more left-leaning Democrats and more libertarian-leaning Republicans.

I'm confused here - Democrats are "left-leaning".

I hate the whole "left" vs "right" way of looking at politics. It's far more complicated than looking at things as a scale between two extremes.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#263
post #142

Earlier quoted context omitted.

Guns are somewhat difficult to produce. This is more akin to knife control.

Any weapon analogy is bad for our side of the argument, because weapons sound to many people like things that bad people use to do bad things. Yes, I realize that knives are used in kitchens to cut vegetables, but with the way this discussion is rightly framed as a security thing, people are not thinking about kitchens. I would prefer to see lock analogies. Here's a half baked example: This is like a law requiring al…

Personally I like that analogy because it was recently revealed that people can 3D print working keys from a photo of a key. So even the "physical" key is vulnerable to security attacks of a digital nature. All someone needs to do is get a photo of the global "key" and they can then get into anybody's safe.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#264
post #47

Earlier quoted context omitted.

It's really disheartening to read or hear almost any discussion about this issue. They're chock-full of broken analogies to meatspace that sound perfectly reasonable if you don't understand the nuances. The instant access, wide platform, and cheap copying that the Internet provides is unlike anything our species has dealt with before, and if you're not really informed on these issues, it's easy to lead yourself into…

> My point being, the anti-encryption side has the support of nearly everyone who isn't informed about encryption and computing, which is a whole lot of people. That just means there is more of a chance for technologists to take a leading role in this discussion through activism. It's an easy win if you can keep a cool head while explaining the issues.

I hate that because we understand we have a responsibility. I just wanted to share cat pictures discretely with my friends.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#265

Instead of complaining into the echo chamber of comments, here are some things you can do to fight back: Donate to the EFF: https://supporters.eff.org/donate/button Call your Reps: http://TryVoices.com Petition the President: https://savecrypto.org/

The EFF is great but we need to figure out a way to kill this thing. Get your checkbooks. We need an apparatus to kill things like this. Think of it as an NRA for crypto. Richard Burr is up for reelection this year. Remember to send money to his opponents. We might want to look for any other groups that have issues with Burr and send them money too. Perhaps this is how you kill a bill. https://ballotpedia.org/Richard…

> NRA for crypto

There is definitely a market for this for anyone who wants to pioneer it. We ran a bunch of Cryptoparties and at each we had to clarify that we weren't a political organization - strictly an educational one. This seemed to disappoint a number of people.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#266

Earlier quoted context omitted.

As technologists, we think this issue is so straightforward that you must either be evil or a complete idiot if you support this law I don't think it is either. More likely it is the "something must be done, this is something" kind of thinking. You don't need to be absolutely evil or absolutely idiotic to subscribe to this philosophy. The problem is that we end debating the right side of that claim (because that's wh…

> "something must be done, this is something" kind of thinking. You don't need to be absolutely evil or absolutely idiotic to subscribe to this philosophy. To fall into it without warning, no. Like all fallacies, it's a local maxima. But to stick with it after it's pointed out... At best that's stupidity, at worst it's deceit and treachery.

There are not many people with technical knowledge in respected positions of government. The US CTO, Megan Smith, is probably the most respected. She claims Obama supports strong encryption [1]. She omits the fact that Obama is looking for ways to keep strong encryption out of the hands of criminals, which as we know is as impossible as keeping knives out of the hands of criminals.

The Press Secretary recently stated this about the President,

> he believes that strong encryption should be robustly deployed. At the same time, we should not set up a situation where bad actors -- terrorists -- can essentially establish a safe haven in cyberspace. [2]

There's also a commission that was formed yesterday to handle this question. It is called the President’s Commission on Enhancing National Cybersecurity [3] and they are due to give a report by the beginning of December (7.5 months).

[1] http://www.cnet.com/news/megan-smith-highlights-heritage-of-...

[2] https://www.whitehouse.gov/the-press-office/2016/04/12/press...

[3] https://www.whitehouse.gov/blog/2016/04/13/announcing-presid...

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#268
I think policy makers do not understand how easy encryption is to use. I'm sending this letter to help them understand a little better why this bill makes no sense and will not prevent criminals nor terrorists from hiding data if they want to.

Dear Senator,

I am writing today to explain how a draft bill, the Compliance with Court Orders Act of 2017, will affect me.

For the last 7 years I have been developing a data backup program, HashBackup. HashBackup allows people to securely backup their computer data to cloud storage, without worrying about the storage company or one of its employees accessing confidential data through the use of strong encryption.

There are many reasons for maintaining strict confidentiality: - financial records - medical records - company trade secrets - top secret intelligence - general privacy protection - and yes, committing crimes

The purpose of this bill as I understand it is to compel any person or company who provides software or devices that can create unintelligible (encrypted) data, to assist the goverment in producing the original, unencrypted data, with a court order.

The critical piece of information to have in order to produce the original data is the encryption key. Without that, no one in the world can produce the original data, whether they wrote the software or not. So this bill's ultimate purpose is to compel individuals and companies selling encryption products to use subversive technical means to obtain encryption keys from its customers, presumably without the customers' knowledge.

My backup program, HashBackup, creates keys on each customer's computer. The customer is responsible for their key, just like the lock on their front door. Similar to a lock manufacturer, I do not know or have access to any customers' encryption keys. If the customer loses their key, they lose their backup, and there is nothing I can do to help them recover it.

If my customer uses HashBackup to store their data at Amazon or Google, and the government decides they want that data, I am the one who will get a court order to provide it since I wrote the software that encrypted it. The only way I could possibly comply with the order is to install special "backdoor" code in HashBackup that relayed the customer's key to the government. If customers realize that their encrypted backup data is not really secure and private, I will be out of business.

Our government presents this issue as a way for law enforcement to prosecute crime and prevent terrorism. But as we all know, criminals and terrorist do not obey laws; the laws end up only affecting the law-abiding. If this law is passed, criminals will be unaffected, as they can easily encrypt their own data and hide their keys.

Some people may believe that encryption is a complex technology that only big companies like Apple can use. It is not. Encryption is a simple technology that anyone can use. It doesn't require any special computer skills, training, or equipment. Criminals and terrorists will continue to use simple encryption after this law is passed.

To show how easy it is to encrypt and decrypt messages, here are two very simple programs to encrypt and decrypt messages. These are written in the Python computer language, but similarly simple programs can be written in most modern computer languages.

The first example program encrypts a message. The lines beginning with # are comments to explain what the program is doing:

  import binascii
  import AES
  import os

  # create a key and display it
  key = os.urandom(16)
  print 'Key:', binascii.hexlify(key)

  # here's the message to protect;
  # add spaces until it a multiple of 16 letters
  message = 'this is a secret'

  # encrypt and display the same message 3 times
  for i in range(3):
      iv = os.urandom(16)
      encrypted = AES.new(key, AES.MODE_CBC, iv).encrypt(message)
      print 'Encrypted message:', binascii.hexlify(iv + encrypted)

The next example program decrypts an encrypted message and display the original secret message:

  import binascii
  import AES
  import os
  import sys

  # get the key and encrypted message
  key = binascii.unhexlify(sys.argv[1])
  encrypted = binascii.unhexlify(sys.argv[2])

  # separate the iv
  iv = encrypted[:16]
  encrypted = encrypted[16:]

  # decrypt and display the original message
  print 'Original message:', AES.new(key, AES.MODE_CBC, iv).decrypt(encrypted)

Now we show the encryption program creating 3 completely different encryptions of the same secret message, all using the same key:

  [jim@mb ~]$ py easy1.py
  Key: 9cba06caad965229457652b3ae760595
  Encrypted message: 4c77810f6f39946a2e525b2ef0e2fe6ed70201d22bb263734dd3aebbbf11af0d
  Encrypted message: d262cca8d9da4aa01c36be5dcf2809d212348438752ffea491a13dacd2999ba9
  Encrypted message: 0749d160d9e751a67bb908ba8df7800a177e53ea03fad3694bbeab54cd680469

Here is the decryption program changing all 3 encrypted messages back to the original message:

  [jim@mb ~]$ py easy2.py 9cba06caad965229457652b3ae760595 4c77810f6f39946a2e525b2ef0e2fe6ed70201d22bb263734dd3aebbbf11af0d
  Original message: this is a secret

  [jim@mb ~]$ py easy2.py 9cba06caad965229457652b3ae760595 d262cca8d9da4aa01c36be5dcf2809d212348438752ffea491a13dacd2999ba9
  Original message: this is a secret

  [jim@mb ~]$ py easy2.py 9cba06caad965229457652b3ae760595 0749d160d9e751a67bb908ba8df7800a177e53ea03fad3694bbeab54cd680469
  Original message: this is a secret

An interesting fact you may not realize: one key can be used to encrypt the same message in many different ways. These simple programs above can encrypt the same message, using the same key, 340,282,366,920,938,463,463,374,607,431,768,211,456 different ways.

No matter what laws our government passes, criminals will not obey them. If a criminal wants to keep something secret using technology, it is not hard: all they have to do is privately share a key with someone, then send encrypted message like the above.

An important point is that these encrypted messages can be sent over ANY communication medium. Whether the government has access to them or not, they cannot be decoded without the key. Criminals can encrypt GPS coordinates and times for example, send them as a simple text message, and the government, Apple, nor anyone else would be able to see the original message.

I have no problem with law enforcement doing an authorized search to obtain a suspected criminal's encryption key(s) FROM THE SUSPECT. But as a producer of software, I should not be compelled to violate my customers' trust by stealing their key without their knowledge. Then I become the criminal.

Please do not pass this bill. It will not affect criminals or terrorists - just the rest of us law-abiding citizens.

Thank you, Jim Wilcoxson

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#269
post #268

I think policy makers do not understand how easy encryption is to use. I'm sending this letter to help them understand a little better why this bill makes no sense and will not prevent criminals nor terrorists from hiding data if they want to. Dear Senator, I am writing today to explain how a draft bill, the Compliance with Court Orders Act of 2017, will affect me. For the last 7 years I have been developing a data b…

I haven't done it yet but I've contemplated sending a letter along the lines of:

Dear Senator,

The draft bill, the Compliance with Court Orders Act of 2017, fails to take into account the necessity of convenient, effective encryption for protecting things like online commerce and it fails to account for how easy it is to access encryption technology that is not compliant with the bill. An example of readily available software that does not comply with the requirements of the bill is "Pretty Good Privacy" often referred to as PGP. This software is widely used and available outside of US jurisdiction.

Many well qualified technologists are speaking out against the bill. Their reservations and the apparent lack of input from the broader technology industry is very worrying.

I consider support for a bill with these issues disqualifying and will vote as such in all future elections.

Thank you,

Max Erickson

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#270

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

> Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. That is already the case. If you whisper a secret into my ear, the government can subpoena me and force me to tell a court what you said. They can force you to tell a court what you said so long as it's not incriminating to you, and even then they can do it if they give you immunity. We can debate about what…

All that pervasive unbreakable encryption does is make it possible to whisper in someone's ear at a distance. You right there said there is a tool for that situation:"the government can subpoena me and force me to tell a court what you said."

That is, you said it is a "game changer," and not a game-changer. You have to issue subpoenas, conduct depositions, etc.

Post reply on HN