Live data from Hacker News

More encryption means less privacy

queue.acm.org

111–120 of 221 posts

Re: More encryption means less privacy

#111

everything means everything. lately i am starting to become really mad at high schools and universities for teaching this "x implies y" mentality as a tool to look at real world phenomenas. thanks to this kind of "education" everyone constantly feels like s/he is discovering some Ultimate Truth™ and thus fails at accounting for a chaotic, ever changing world. "cause and effect" may exists but these pattern mostly happens on a scale for which human language is just too clumsy.

stop writing and discussing these articles. if you really got nothing better to do at any point in time, just stare out of the window for a while and relax a bit.

Re: More encryption means less privacy

#112
post #87

Earlier quoted context omitted.

Breaking kneecaps is expensive though. You can't just set up a ring of roadblocks around a city that kneecaps everyone passing through as a matter of course.

> Breaking kneecaps is expensive though. You can't just set up a ring of roadblocks around a city that kneecaps everyone passing through as a matter of course. Once you establish the willingness to break kneecaps, the number of kneecaps you actually need to break is fairly small.

That's true if determining whose kneecaps you need to break is either trivial (e.g. open dissidents and protesters) or can be easily achieved using social engineering (e.g. anonymous print pamphleteers). If doing so is a /technical/ rather than social task, and your technical cryptanalysis isn't up to par, breaking kneecaps is much less powerful of a deterrent because your hit rate will be very low. Breaking kneecaps to deter the use of encryption itself is another matter though.

Re: More encryption means less privacy

#113
post #69

Earlier quoted context omitted.

How does a rubber hose work when the people are talking via Tox or via .onion sites?

Rarely does encryption exist in a complete vacuum. Just as we cannot necessarily listen to every one on one conversation, those conversations become important when related to something occurring withing the "physical" world. I think we've seen that Tor does not protect you from someone who's determined to find you (see: Silk Road).

Indeed, at least with Tox, all I need is a separate key exchange, somewhere. In person works wonders. So does random email, or instant message, or you name it.

At least for communications that need that layer of security and anonymity, it's certainly there. And as I implied, rubber hoses won't work on anonymous and encrypted digital identities "somewhere else".

At least regarding Silk Road, that's because he made amateur mistakes by posting his real name and then changing it on StackExchange, about making a e-commerce .onion website.

And that was the beginning of his fuckups, with the final one by paying for an assassination attempt.

Re: More encryption means less privacy

#114
post #2

> Slapping unbreakable crypto onto more and more packets is just going to make matters worse. The only way to retain any amount of electronic privacy is through political engagement. While political engagement is an alternative to "slapping unbreakable crypto" onto things, this article establishes no precedent for political engagement actually helping! I see the technical as political, direct action as engagement. An…

I'm pretty sure that both former slaves, women and most recently nonheteronormative lovers would disagree that there is "no precedent for political engagement actually helping".

That is the only way human rights have ever been won, and privacy in electronic communication is very much a human right.

(Yes, I'm the author of that piece)

Re: More encryption means less privacy

#115
post #55

This argument is like saying that if you build a castle to protect yourself from the attacker, you are responsible for the enemy's construction of trebuchets that siege the castle. Yeah, the castle builders are at fault. Nevermind that they protect so many innocent with their work. Of course we need political involvement, but we also need encryption everywhere, literally everywhere.

You should study the history of anti-ballistic-missile defense systems, and you will find that for the longest time nobody wanted them, because that would force the enemy to attack before they were completed.

Never build more formidable weapons or defenses than you are willing to lay your life down for.

Re: More encryption means less privacy

#116
post #58
post #38

Earlier quoted context omitted.

> I think we have to realize that some transparency into private lives is needed to have a proper society, and the anarcho-capitalists want full privacy from the get go This is almost a non-sequitor. If your private life is transparent then it ceases to be private. You're in fact advocating no private life. I strongly disagree that this position would be good for society. It's funny how you'd think you have to be an…

> You're in fact advocating no private life. I strongly disagree that this position would be good for society. No, I'm not advocating for anything per se, I'm just bringing up opposite points of view. I don't have an easy answer either. Second, no privacy is what has been the standard since governments started. There has been no technology that has been able to make some aspect of reality 100% private, other than the…

"No privacy" has certainly NOT been the standard. Before the information age, people were more likely to communicate extremely private information in person. Until the invention of microphones, this communication was most certainly private if you could avoid eavesdroppers! Now, with everything from TVs to phones to lampposts listening in, this type of communication carries less of a privacy guarantee, but it's still one of the only methods to obtain actual privacy under the right conditions.

So let's all go back to in-person conversations, right? It's not that easy. Friends and loved ones no longer live as close as they once did, as technology has allowed us to stay connected at greater distances. This means that our options under the current state of the world are (a) keep sensitive information away from our trusted confidantes until we see them in person, whenever that is, or (b) get used to the idea that sensitive information could be exposed. Either one of these options brings with it increased psychological stress. This is a big reason why people want "unbreakable" security, and there's nothing nefarious about it!

Re: More encryption means less privacy

#117
post #8

Kinda clickbait-y, and ignores the fact that encrypted communications were able to be used (with some effort) before Snowden, but his last point is solid: > The only way to retain any amount of electronic privacy is through political engagement.

No its not. The reality is the biggest threat to privacy is due to political engagement. Stronger encryption that no one can break is really the only viable option.

You fail to grasp the key point here:

If the state cannot break your encryption, they will break you instead.

Re: More encryption means less privacy

#118
post #8

Earlier quoted context omitted.

No its not. The reality is the biggest threat to privacy is due to political engagement. Stronger encryption that no one can break is really the only viable option.

You don't need to break the strong encryption, when you can break the kneecaps of people using strong encryption.

If you break someones kneecaps, you may get the information they have, but you will never get anything more. After that they and their whole network will take precautions, even going as far as never communicating electronically if required. Such bullying may also easily backfire, which limits its use.

A broken communication channel in contrast is the gift that keep giving. You can get up to date information that the opponent think is confidential as it happens, and they will not take precautions, and you can continue to use the information against them, giving you the upper hand. This is why NSA was so determined to keep their actions hidden.

Re: More encryption means less privacy

#119
>When Edward Snowden made it known to the world that pretty much all traffic on the Internet was collected and searched by the NSA, GCHQ (the UK Government Communications Headquarters) and various other countries' secret services as well, the IT and networking communities were furious and felt betrayed.

That's not how I remember it. Among those communities it was pretty well known that such surveillance was occurring. Knowing the scope of it caused a sense of obligation; that we should finally get around to adding some privacy protection to day to day internet traffic. Everyone knew that it was something that had to be done sooner or later.

Re: More encryption means less privacy

#120
post #86

Earlier quoted context omitted.

> The FBI is certainly not talking about only defaults. You are right that considering the whole history of encryption and the FBI, they don't want it anywhere, but as James Comey has himself said, this debate kicked into high gear late 2014 when Apple started with the default encryption, and law enforcement saw an increase in devices they couldn't get into. I think if strong encryption had been on the outliers as it…

And we wouldn't have kicked privacy into high-gear if government agencies had proven themselves trustworthy. But they abused their powers, and here we are. I hate saying "they started it", but... they did. > There are real harms to strong encryption, whether one would like to admit it or not, so the point is to weigh the costs and benefits and go from there. Right now encryption seems more like a religion, a last bas…

This is becoming a super long thread now but I want to say I understand your points, that's why this is difficult to discuss.

What I see is that if evidence collection becomes seriously hampered because of strong encryption, then hacking, backdoors and surveillance will have to go up to compensate, and that's not a good situation either. If there comes a point where a large percentage of pedophiles, 'common criminals' and others can't get convicted because of default encryption (the evidence is on their phones), then the FBI and police will move to other methods, like the aforementioned ones. Because of this, I'm not sure your last point holds:

> But, just statistically speaking, there is vastly more harm in not having strong encryption. The cost/benefits are so skewed to one side, it's not even really a discussion.

Maybe we just haven't seen the actual consequences yet. Unless the FBI and the police are lying, then it will get worse as time goes on.

Here's a quote by Comey

http://www.msnewsnow.com/story/32698131/fbi-chief-calls-for-...

> Speaking Friday at the American Bar Association annual conference in San Francisco, James Comey said the agency was unable to access 650 of 5,000 electronic devices investigators attempted to search over the last 10 months.

Barring some bigger discussion about government power altogether, this seems to be the issue we are facing. I also want to say that it's not just about conviction and putting someone in jail. Sure in a lot of these cases, there will be other evidence and other things to nail them on, but it's also about revealing the full scope of a crime and not just a harsher crime. In the name of justice so to speak.

Post reply on HN