Live data from Hacker News

More encryption means less privacy

queue.acm.org

71–80 of 221 posts

Re: More encryption means less privacy

#71
post #66

Earlier quoted context omitted.

Absolutely disagree. A) Even when the government has the data to stop someone, they don't: https://theintercept.com/2015/11/18/terrorists-were-already-... B) Outlawing crypto just doesn't work. You can't outlaw math. You can try all day long, but that only hurts the masses At some point, you have to realize that breaking encryption has nothing to do with safety, but is all about power.

a) I don't want to comment on that intercept piece because there is clear bias there and I don't have all the facts. b) I think actually the FBI is mainly talking about the defaults in software, like how Apple enabled strong encryption for any user. Defaults matter when you consider the 95% of people who would not otherwise use encryption, including all kinds of criminals. I think everyone realizes you can't remove e…

B) The FBI is certainly not talking about only defaults. They have said that they don't want unbreakable encryption anywhere.

> They aren't meant to have their own will and goals like "power".

Yet they undeniably do. Pretending that they don't is sheer naivety.

I'm not much of a political theorist, but we have government because we tend to trust them more than the average mob. They aren't infallible though, and we need checks and balances to keep them in place.

Re: More encryption means less privacy

#72
post #7

The article seems to make the fundamental error of assuming that there is any middle ground between "unbreakable crypto" and "effectively no crypto at all". If crypto can be broken, it will be broken, whether that's by state actors or by some kid in Mongolia who wants to make a quick buck by ransoming all your files.

That's like saying there is no middle ground between product X being free and being infinitely expensive. Even if product X has a price I can afford, I have to consider the trade-offs between buying it and other uses for my money. If it's free, though, there are no trade-offs. If somebody can break my crypto, fine, but I want them to expend valuable resources on it so they won't do it for shits and giggles.

Re: More encryption means less privacy

#73

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

Well, two things: 1. I've always maintained that privacy is a political and social problem, not just a technological one. Nothing stops a more powerful actor from breaking encryption with a rubber hose if they really want to. Technological solutions are still needed since there's a variety of actors involved, only some of which will obey the political doctrine. 2. I often wonder if encryption will make us think of pr…

Oh, a purely tool based solution to privacy has failure built in to it. It's a necessary component of a larger system.

Re: More encryption means less privacy

#74

Earlier quoted context omitted.

Because it's not a fundamental error or indeed an error at all. What you've just expressed is one of those fascinating pieces of mental junk that clutters up social groups, a political desire that's so strongly held you've managed to rationalise to yourself that it's a fact and not a personal desire at all. But it's still not a fact. It is trivial to use cryptography in ways that yield some sort of balance between pe…

If there is a backdoor, that backdoor can be used by anyone that has the key. I do not trust a government to responsibly handle such a key, as it leaking once results in total failure of security for everyone. A backdoored crypto system is a broken crypto system.

There are lots of examples of governments maintaining the integrity of keys over the long term. The e-Passport system is an example of that. Another would be that the NSA had the ultimate insider hack - literally a sysadmin who dumped their entire internal wikis and document stores - and yet it appears that no key material was compromised.

You can repeat "a backdoored system is no system" mantra to yourself if you like, but there are a LOT of threats that aren't governments and those are the ones people tend to care about the most.

Re: More encryption means less privacy

#75
post #30

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

I think a very important point was raised though. Before crypto, basically all guarantees where conditional on a judge's say so. With crypto this changes. The issue also comes up, in a clearer way, with crypto currencies. There is no way to deal with fraud or mistaken tranfers in bitcoin. That loss of intervention hurts, and we gotta think about it. Even though no government has given a satisfactory solution, that do…

This point is a tired falsehood. There have always been phenomena with physical rules that supersede any human decision. The legal system recognizes and works with such boundaries - some even end up codified in our highest laws such as the 5th amendment.

We're only in this present quandary because of professionally irresponsible "web 2.0 services" that siloed up user data for their own surveillance goals, creating enticing targets for governments' desires of control.

Re: More encryption means less privacy

#76

Earlier quoted context omitted.

Part of the way the legal system deals with fraud is by recovering money (where possible). With bitcoin, unless the destination wallet can be obtained, that is not possible. With cash, you seize the cash. Bank accounts can be frozen, Credit card transactions canceled, wire transfers flagged ( http://www.npr.org/sections/money/2016/01/29/464859624/episo... ).

With cash, unless the wallet in which it resides can be obtained, that is not possible. I fail to see the difference.

The law does actually have ways of extracting cash from people even when it can't locate the cash in question. It's harder, and less effective, but overall it works more than it doesn't.

Re: More encryption means less privacy

#77
post #65

Earlier quoted context omitted.

Presumably "no precedent" means "relating to privacy and security". To the extent that there are legal wins there, they were either extracted by technical means (e.g. the crypto wars) or effectively meaningless (e.g. 'oversight' of bulk surveillance).

I do not follow. The fourth amendment establishes that "[t]he right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated" Roe v Wade literally invented the legal right to privacy in the US: https://en.wikipedia.org/wiki/Roe_v._Wade#Right_to_privacy

The Fourth and Roe are relevant, although I would argue that gay marriage and Miranda are essentially unrelated. In the US, "no government in the bedroom" privacy and non-self-incrimination don't really carry over into "don't read my mail" style privacy. They might bound prosecution, but not surveillance.

More broadly, what I meant was that digital privacy, security, and ownership have been a consistently losing battle. The interpretation of how legal protections (the Fourth included) apply to computers has skewed towards state power in virtually every case, and victories on digital issues are almost all a result of technological activism rather than pure political work.

Re: More encryption means less privacy

#78

Earlier quoted context omitted.

Because it's not a fundamental error or indeed an error at all. What you've just expressed is one of those fascinating pieces of mental junk that clutters up social groups, a political desire that's so strongly held you've managed to rationalise to yourself that it's a fact and not a personal desire at all. But it's still not a fact. It is trivial to use cryptography in ways that yield some sort of balance between pe…

It is trivial to use cryptography in ways that yield some sort of balance between personal privacy and the needs of the state. But that's the point: we've seen that this balance doesn't exist, because if the service providers have access to the plaintext, the State will not contain itself to issuing case-by-case warrants - see Room 641A, "SSL added and removed here", etc. The current move to encrypt everything is a r…

You're arguing with something different to what I said.

I pointed out that it's easy to design cryptosystems to be unbreakably strong against all adversaries except governments, and indeed can be unbreakably strong against mass eavesdropping by governments, yet still provide access on a case by case basis. And in fact this is the outcome of all kinds of natural and widely adopted designs.

You're arguing that governments won't content themselves with such access. That's a different question entirely. I think many of them would and that we're heading in that direction, more or less, where mass decryption of TLS isn't done by most governments and the era of GCHQ/NSA style bulk wire tapping slowly fades away, but it doesn't matter to them much because they can still warrant the other end and ultimately that's what politicians feel safe campaigning on.

Re: More encryption means less privacy

#79
So what does he suggest? I think we are supposed to read between the lines, but I am not sure what that is yet.

Is it just pointing out an interesting contradiction and we should enhance and improve existing products, or there a message about moving back and reverting to using weak encryption like before or treating it like "munitions" for purposes of export control. So you you end up in prison just as long long for using OpenSSL as for reselling grenade launchers.

Yeah I can see how PR is on government side here -- "look terrorists use this and other horrible criminals, this needs to be stopped".

The answer usually is -- "Ah, but think of the human rights people from " or make a reference to some generalized principle from the Constitution about freedom from search. Both of those lose in comparison to an image of scary guy with a bomb under their arm.

So the answer is to operate at the same level of PR. Bring in issues people can identify with: for companies and enterprises remind them of the Target credit card breach, about the Sony hack and how embarrassing that is. Or for private individuals talk about identity theft. Everyone has heard about that how disruptive and upsetting that is. "We need stronger encryption to protect you from criminals" kind of message.

(I am not the first one to think of this, I noticed Apple applied this in their response to FBI. I just thought it was a great approach).

Re: More encryption means less privacy

#80

It sure makes for a nice contrarian opinion, but fighting politically vs technically is a needless dichotomy. At least this post attempts to back up this assertion, but it seems a quite handwavey to assume that because eg a protocol contains key escrow, that governments aren't still going to want to preemptively read, archive, and datamine the cleartext. Yes, all governments. Because governments, even democratic ones…

> The problems are centered around naming.

What's that expression? "All problems in computer science are ultimately about naming."

Post reply on HN