Live data from Hacker News

More encryption means less privacy

queue.acm.org

41–50 of 221 posts

Re: More encryption means less privacy

#41
post #8

Kinda clickbait-y, and ignores the fact that encrypted communications were able to be used (with some effort) before Snowden, but his last point is solid: > The only way to retain any amount of electronic privacy is through political engagement.

No its not. The reality is the biggest threat to privacy is due to political engagement. Stronger encryption that no one can break is really the only viable option.

I totally disagree. Political and social solutions prevailed in our physical space during the 60s and 70s with the expansion of rights related to search and seizure and the statement of rights to those who are unaware of them. There is precedent for social engagement here.

And remember, all encryption is susceptible to rubber hose cryptography. There needs to be a two pronged approach here.

Re: More encryption means less privacy

#42
post #7

The article seems to make the fundamental error of assuming that there is any middle ground between "unbreakable crypto" and "effectively no crypto at all". If crypto can be broken, it will be broken, whether that's by state actors or by some kid in Mongolia who wants to make a quick buck by ransoming all your files.

Because it's not a fundamental error or indeed an error at all. What you've just expressed is one of those fascinating pieces of mental junk that clutters up social groups, a political desire that's so strongly held you've managed to rationalise to yourself that it's a fact and not a personal desire at all. But it's still not a fact. It is trivial to use cryptography in ways that yield some sort of balance between pe…

It is trivial to use cryptography in ways that yield some sort of balance between personal privacy and the needs of the state.

But that's the point: we've seen that this balance doesn't exist, because if the service providers have access to the plaintext, the State will not contain itself to issuing case-by-case warrants - see Room 641A, "SSL added and removed here", etc.

The current move to encrypt everything is a reaction to the realization that the balance that was thought to exist, does not, and political participation is not sufficient because the information is kept hidden, so no informed political discourse is possible.

Re: More encryption means less privacy

#43
> Kazakhstan announced that a "state root certificate" would have to be installed on all computers wanting to use SSL/TLS/HTTPS out of the country

Devils advocate: Practically every country (national telecom) has its own root certificate. Here is the list:

https://mozillacaprogram.secure.force.com/CA/IncludedCACerti...

When Czech goverment started digitalization, it was very user unfriendly to install Czech CA. I think Kazakhstan is just using force it has to speedup its own application.

Re: More encryption means less privacy

#44
post #6

Earlier quoted context omitted.

>no precedent for political engagement actually helping! Off the top of my head: In the US: the fourth amendment, Miranda rights, the right to abortion, various efforts to decrim gay sex. Here in Canada, Trudeau père famously said "there's no place for the state in the bedrooms of the nation", adding that "what's done in private between adults doesn't concern the Criminal Code" https://en.wikipedia.org/wiki/Criminal_…

Presumably "no precedent" means "relating to privacy and security". To the extent that there are legal wins there, they were either extracted by technical means (e.g. the crypto wars) or effectively meaningless (e.g. 'oversight' of bulk surveillance).

I think the point is that privacy and security are physical as well as digital and if political engagement made one prevail, why not the other? We have more privacy protections now than we did 100 years ago due to political engagement, there is not reason to believe we cannot continue that effort into the digital realms.

Re: More encryption means less privacy

#45
post #32

I'd put it a different way. Encryption and other forms of good security force surveillance out of the shadows. Without it we wouldn't know what Kazakhstan is doing. If the law requires a warrant to access your GMail account, good security is why law enforcement has to get a valid warrant and send it to Google to get access. Done right, it's not a substitute for politics. It enables politics. It allows agreements on c…

We all like end to end encryption though. In fact, most people call it the pinnacle of crypto done right. And yet, it completely circumvents any warrants.

I don't think e2e crypto circumvents any warrant, in fact it makes it very similar to a warrant for a physical thing at your house.

An analogy:

Gmail is like having a safe at your bank, if the police want something in it, they get a warrant to search your safe. E2E Crypto is like having a safe at home, if they want something in it, they get a warrant to search your house.

So I wouldn't say it circumvents any warrants, it just changes who is served said warrant.

Re: More encryption means less privacy

#46
post #2

> Slapping unbreakable crypto onto more and more packets is just going to make matters worse. The only way to retain any amount of electronic privacy is through political engagement. While political engagement is an alternative to "slapping unbreakable crypto" onto things, this article establishes no precedent for political engagement actually helping! I see the technical as political, direct action as engagement. An…

SOPA's defeat was a big win. There is almost no political engagement from the technology sector, as compared to others (like pharmaceuticals, finance, telecoms, entertainment). If there had, the DMCA might not be so onerous, the CFAA would be gone, and SOPA would never have gotten as far as it did.

I wonder. I've seen people on HN saying that Google is one of the biggest lobbyist, so apparently tech sector is very much present in Washington. So maybe it's not that there is no engagement, but that those who engage have different goals in mind than your average HNer?

Re: More encryption means less privacy

#47
post #30

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

I think a very important point was raised though. Before crypto, basically all guarantees where conditional on a judge's say so. With crypto this changes. The issue also comes up, in a clearer way, with crypto currencies. There is no way to deal with fraud or mistaken tranfers in bitcoin. That loss of intervention hurts, and we gotta think about it. Even though no government has given a satisfactory solution, that do…

>There is no way to deal with fraud [...] in bitcoin

Don't we have an extensive legal system to deal with fraud? The fact that a lot of payment providers elect to deal with fraud themselves probably shows that that legal system isn't working as smoothly as it should; but that's really something that should be fixed in the legal system, not in the payment channel.

Re: More encryption means less privacy

#48
post #2

> Slapping unbreakable crypto onto more and more packets is just going to make matters worse. The only way to retain any amount of electronic privacy is through political engagement. While political engagement is an alternative to "slapping unbreakable crypto" onto things, this article establishes no precedent for political engagement actually helping! I see the technical as political, direct action as engagement. An…

I'm actually curious: can anyone cite a serious win for privacy that was wholly political? I frequently see pieces criticizing over-reliance on crypto as solutionism and political apathy, but I don't understand what they expect. The people fighting for strong cryptography have also led the political fight for privacy, but their nontechnical efforts have been ignored or circumvented at every turn. At this point it's h…

How far back are you willing to look? "The Video Privacy Protection Act (VPPA) was a bill passed by the United States Congress in 1988 ... to prevent what it refers to as "wrongful disclosure of video tape rental or sale records..." Congress passed the VPPA after Robert Bork's video rental history was published during his Supreme Court nomination." [1]

I thought there were also some U.S. privacy laws around library records, but can't locate a clear reference just now.

[1]: https://en.m.wikipedia.org/wiki/Video_Privacy_Protection_Act

Re: More encryption means less privacy

#49

Earlier quoted context omitted.

SOPA's defeat was a big win. There is almost no political engagement from the technology sector, as compared to others (like pharmaceuticals, finance, telecoms, entertainment). If there had, the DMCA might not be so onerous, the CFAA would be gone, and SOPA would never have gotten as far as it did.

I wonder. I've seen people on HN saying that Google is one of the biggest lobbyist, so apparently tech sector is very much present in Washington. So maybe it's not that there is no engagement, but that those who engage have different goals in mind than your average HNer?

Google (Alphabet) has been spending way more than previously, but the "Internet" industry as a whole doesn't even reach the top 20: https://www.opensecrets.org/lobby/top.php?showYear=2015&inde...

Re: More encryption means less privacy

#50

Earlier quoted context omitted.

Because it's not a fundamental error or indeed an error at all. What you've just expressed is one of those fascinating pieces of mental junk that clutters up social groups, a political desire that's so strongly held you've managed to rationalise to yourself that it's a fact and not a personal desire at all. But it's still not a fact. It is trivial to use cryptography in ways that yield some sort of balance between pe…

If there is a backdoor, that backdoor can be used by anyone that has the key. I do not trust a government to responsibly handle such a key, as it leaking once results in total failure of security for everyone. A backdoored crypto system is a broken crypto system.

A backdoored crypto system is a no crypto system.
Post reply on HN