Live data from Hacker News

More encryption means less privacy

queue.acm.org

61–70 of 221 posts

Re: More encryption means less privacy

#61
post #30

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

I think a very important point was raised though. Before crypto, basically all guarantees where conditional on a judge's say so. With crypto this changes. The issue also comes up, in a clearer way, with crypto currencies. There is no way to deal with fraud or mistaken tranfers in bitcoin. That loss of intervention hurts, and we gotta think about it. Even though no government has given a satisfactory solution, that do…

> Before crypto, basically all guarantees where conditional on a judge's say so.

Sadly, they weren't.

> With crypto this changes.

Actually, with crypto it is much harder to claim that a judge's authorization isn't required to even try to subvert the privacy intent.

> There is no way to deal with fraud or mistaken tranfers in bitcoin.

There's no way because legally the system (for the most part) considers it outside the scope of fraud laws.

> That loss of intervention hurts, and we gotta think about it.

TLS doesn't create a real loss of intervention. It requires that the intervention be far more explicit and/or targeted.

Re: More encryption means less privacy

#62
post #8

Kinda clickbait-y, and ignores the fact that encrypted communications were able to be used (with some effort) before Snowden, but his last point is solid: > The only way to retain any amount of electronic privacy is through political engagement.

No its not. The reality is the biggest threat to privacy is due to political engagement. Stronger encryption that no one can break is really the only viable option.

You don't need to break the strong encryption, when you can break the kneecaps of people using strong encryption.

Re: More encryption means less privacy

#63
post #32

Earlier quoted context omitted.

We all like end to end encryption though. In fact, most people call it the pinnacle of crypto done right. And yet, it completely circumvents any warrants.

I don't think e2e crypto circumvents any warrant, in fact it makes it very similar to a warrant for a physical thing at your house. An analogy: Gmail is like having a safe at your bank, if the police want something in it, they get a warrant to search your safe. E2E Crypto is like having a safe at home, if they want something in it, they get a warrant to search your house. So I wouldn't say it circumvents any warrants…

Except, the safe in your house can be cracked on a judge's order. Your encrypted machine, on the other hand, does not listen to judges.

Ergo, the FBI-unlocking-dead-guy's-iPhone thing, and the key-disclosure thing.

Re: More encryption means less privacy

#65
post #6

Earlier quoted context omitted.

>no precedent for political engagement actually helping! Off the top of my head: In the US: the fourth amendment, Miranda rights, the right to abortion, various efforts to decrim gay sex. Here in Canada, Trudeau père famously said "there's no place for the state in the bedrooms of the nation", adding that "what's done in private between adults doesn't concern the Criminal Code" https://en.wikipedia.org/wiki/Criminal_…

Presumably "no precedent" means "relating to privacy and security". To the extent that there are legal wins there, they were either extracted by technical means (e.g. the crypto wars) or effectively meaningless (e.g. 'oversight' of bulk surveillance).

I do not follow.

The fourth amendment establishes that "[t]he right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated"

Roe v Wade literally invented the legal right to privacy in the US: https://en.wikipedia.org/wiki/Roe_v._Wade#Right_to_privacy

Re: More encryption means less privacy

#66
post #9

Nobody really knows the correct answer and I think that's the reason communication is failing between the government and the tech sector. I think we have to realize that some transparency into private lives is needed to have a proper society, and the anarcho-capitalists want full privacy from the get go and then increasing transparency as needed for society, while government is kind of hovering on the "we need transp…

Absolutely disagree. A) Even when the government has the data to stop someone, they don't: https://theintercept.com/2015/11/18/terrorists-were-already-... B) Outlawing crypto just doesn't work. You can't outlaw math. You can try all day long, but that only hurts the masses At some point, you have to realize that breaking encryption has nothing to do with safety, but is all about power.

a) I don't want to comment on that intercept piece because there is clear bias there and I don't have all the facts.

b) I think actually the FBI is mainly talking about the defaults in software, like how Apple enabled strong encryption for any user. Defaults matter when you consider the 95% of people who would not otherwise use encryption, including all kinds of criminals. I think everyone realizes you can't remove encryption from the face of the earth, it's just not doable and not worthy of discussion and that's not what I'm talking about. The FBI is doing this because they try to reverse the Apple defaults and don't really have any other way. The next step is to "have the debate" but as we can see that is incredibly difficult.

Regarding your last point. Sure, that's one way to talk about it, but if it is the case that it's all about power, then why do we even have governments? All the trust is broken and we are essentially asking to be left alone to solve crimes that happen in our neighborhoods. The government and the FBI / others are supposed to work FOR us, for society as a whole, based on the laws we vote for/lobby for. They aren't meant to have their own will and goals like "power". Only private corporations and individuals want power, that's what the whole point of this government thing was in the first place.

Re: More encryption means less privacy

#67
post #32

I'd put it a different way. Encryption and other forms of good security force surveillance out of the shadows. Without it we wouldn't know what Kazakhstan is doing. If the law requires a warrant to access your GMail account, good security is why law enforcement has to get a valid warrant and send it to Google to get access. Done right, it's not a substitute for politics. It enables politics. It allows agreements on c…

We all like end to end encryption though. In fact, most people call it the pinnacle of crypto done right. And yet, it completely circumvents any warrants.

With end to end crypto, if the government wants something from me and has acquired a warrant for it, they are still reliant on me to produce the decrypted data, but I refuse it they can hold me in contempt of court. It's not like they lose all leverage.

Re: More encryption means less privacy

#68

Earlier quoted context omitted.

I don't think e2e crypto circumvents any warrant, in fact it makes it very similar to a warrant for a physical thing at your house. An analogy: Gmail is like having a safe at your bank, if the police want something in it, they get a warrant to search your safe. E2E Crypto is like having a safe at home, if they want something in it, they get a warrant to search your house. So I wouldn't say it circumvents any warrants…

Except, the safe in your house can be cracked on a judge's order. Your encrypted machine, on the other hand, does not listen to judges. Ergo, the FBI-unlocking-dead-guy's-iPhone thing, and the key-disclosure thing.

> Your encrypted machine, on the other hand, does not listen to judges.

My machine doesn't, but I do, unless I am willing to face the consequences of being in contempt of court.

Re: More encryption means less privacy

#69

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

Well, two things: 1. I've always maintained that privacy is a political and social problem, not just a technological one. Nothing stops a more powerful actor from breaking encryption with a rubber hose if they really want to. Technological solutions are still needed since there's a variety of actors involved, only some of which will obey the political doctrine. 2. I often wonder if encryption will make us think of pr…

How does a rubber hose work when the people are talking via Tox or via .onion sites?

Re: More encryption means less privacy

#70

Earlier quoted context omitted.

Because it's not a fundamental error or indeed an error at all. What you've just expressed is one of those fascinating pieces of mental junk that clutters up social groups, a political desire that's so strongly held you've managed to rationalise to yourself that it's a fact and not a personal desire at all. But it's still not a fact. It is trivial to use cryptography in ways that yield some sort of balance between pe…

If there is a backdoor, that backdoor can be used by anyone that has the key. I do not trust a government to responsibly handle such a key, as it leaking once results in total failure of security for everyone. A backdoored crypto system is a broken crypto system.

You can always mitigate the "failure for everyone" scenario. Plethora of government keys, for example, or rotating government keys, or rapidly expiring government keys... Anyway, they've managed to keep stacks and stacks of information secret for decades and decades. It seems like it could be managed. No one has stolen the cert for *.whitehouse.gov.

Sidenote, why do people call a second key a backdoor? To me, backdoor suggests exploit, not used-as-designed.

Post reply on HN