Live data from Hacker News

More encryption means less privacy

queue.acm.org

181–190 of 221 posts

Re: More encryption means less privacy

#181

Earlier quoted context omitted.

How many of the NSA's backdoors have ended up in the hands of foreign nations and criminals, again?

All of them.

That's entirely unprovable, given that we have no idea how many backdoors the NSA has, nor for the matter, are we even sure how many have been leaked.

Re: More encryption means less privacy

#182
post #139
post #91

Earlier quoted context omitted.

Until very recently 99.99% of conversations where completely private and society functioned just fine. Even with crypto everywhere the governments have far more access to what people say and do than they had for thousands of years. People with power pretend if they just had more power everything would be better. But, reality is if everything on a computer where private not much would change.

> Until very recently 99.99% of conversations where completely private and society functioned just fine. In fairness, until very recently it was also extremely difficult for two people to privately plot to murder hundreds. Technology has changed the balances on a lot of scales. To be clear, I'm not advocating for government back doors in encryption here. But I am saying we should not pretend that encryption just puts…

When you talk about two people plotting to kill hundreds, do you mean any two people or do you mean two people who are otherwise physically apart but are brought close together by technology? Coz if the medium of communication used by your two would be mass murderers is VoTA (0), that technology is as old as human beings.

0. Voice over The Air. :-)

Re: More encryption means less privacy

#183
post #30

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

I think a very important point was raised though. Before crypto, basically all guarantees where conditional on a judge's say so. With crypto this changes. The issue also comes up, in a clearer way, with crypto currencies. There is no way to deal with fraud or mistaken tranfers in bitcoin. That loss of intervention hurts, and we gotta think about it. Even though no government has given a satisfactory solution, that do…

> There is no way to deal with fraud or mistaken tranfers in bitcoin.

This is a social problem of bitcoin. The bitcoin people consider this a feature.

However, it can be dealt with at an exchange. "MyBitcoinExchange(tm) only allows transfers to other members of MyBitcoinExchange(tm) and yourself. All transfers will be escrowed for 5 days to ensure that they are not fraudulent."

The problem is: nobody in bitcoin would use that exchange.

People who want non-traceable will stay away. People who are using it to sequester wealth out of countries will stay away. People who want fast liquidity will stay away. etc.

So, who's left? Um, people who are perfectly adequately handled by existing credit cards, thanks.

Re: More encryption means less privacy

#184
post #173
post #150

Earlier quoted context omitted.

What are you talking about? There have been plenty on bombings and shootings for hundreds of years.

200 years ago there were "plenty" of bombings and mass shootings orchestrated by groups of 1 or 2 people that resulted in hundreds of lives lost? Can you provide a few examples of this?

That's a rather artificial limitations, few modern plots are from 1 or 2 people with hundreds killed. Historical examples are generally things like fires not bombings / mass shootings. As an example of the risks: https://en.wikipedia.org/wiki/Great_Fire_of_Meireki for example was extremely deadly, though estimates of ~100,000 dead where probably exaggerated.

We have also forgotten a lot of this crap. EX: 40 to 81 people killed from a time bomb in 1875. https://en.wikipedia.org/wiki/Alexander_Keith,_Jr. Note, this was for insurance money not terrorists, but I don't think the dead care.

Some historical examples where donations where probably accidental. The Delft Explosion of 1654 killed 100-200 people. In 1769 ~3000 people where killed when a depo @ Bastion of San Nazaro in Brescia was struck by lighting. A lighting also sparked another detonation in 1856 killing ~4,000.

Re: More encryption means less privacy

#185
post #30

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

I think a very important point was raised though. Before crypto, basically all guarantees where conditional on a judge's say so. With crypto this changes. The issue also comes up, in a clearer way, with crypto currencies. There is no way to deal with fraud or mistaken tranfers in bitcoin. That loss of intervention hurts, and we gotta think about it. Even though no government has given a satisfactory solution, that do…

> With crypto this changes.

It shouldn't. Listening in on a conversation should be illegal whether or not the conversation is encrypted. But we realized that if we weren't encrypting our conversations that our rights were being illegally infringed upon, so we started taking matters into our own hands.

Re: More encryption means less privacy

#186
post #103

Earlier quoted context omitted.

> Until very recently 99.99% of conversations where completely private and society functioned just fine. Until very recently, most conversations were plausibly deniable, and off the record. The internet and cryptography changes that. Edit: [Both plausibly deniable in the formal/cryptographic sense, and in the informal "You're misremembering, there's no record in writing of me saying that" sense]

> The internet and cryptography changes that. By Internet, I think you mean phonographs, magnetic tapes and pocket recorders. Cryptography brings some of that back.

To get access to those, you needed warrants, and you didn't get to listen in on every conversation, only targeted conversations. On the Internet, you have full access to pretty much everything I've ever said to somebody.

They aren't equivalent.

Re: More encryption means less privacy

#187

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

Well, two things: 1. I've always maintained that privacy is a political and social problem, not just a technological one. Nothing stops a more powerful actor from breaking encryption with a rubber hose if they really want to. Technological solutions are still needed since there's a variety of actors involved, only some of which will obey the political doctrine. 2. I often wonder if encryption will make us think of pr…

Rubber hoses don't scale. With our technological solution, we make it so that the government can't access 99.9% of all conversations. If they want to access a conversation here or there, they can use a rubber hose. But if they want to see every conversation in a person's social network (including conversations they weren't directly involved in), then they aren't going to be able to do that anymore.

Technology helps a lot. It brings us from a panoptikon to a situation where enforcement has to be done on an individual basis. That's a big win for freedom in my book.

Re: More encryption means less privacy

#188
post #184
post #173

Earlier quoted context omitted.

200 years ago there were "plenty" of bombings and mass shootings orchestrated by groups of 1 or 2 people that resulted in hundreds of lives lost? Can you provide a few examples of this?

That's a rather artificial limitations, few modern plots are from 1 or 2 people with hundreds killed. Historical examples are generally things like fires not bombings / mass shootings. As an example of the risks: https://en.wikipedia.org/wiki/Great_Fire_of_Meireki for example was extremely deadly, though estimates of ~100,000 dead where probably exaggerated. We have also forgotten a lot of this crap. EX: 40 to 81 peo…

Not to mention smallpox and other infectious diseases where one person could kill thousands easily, even if unintentionally (with some instances intentional).

Re: More encryption means less privacy

#189
post #57

This is a fringe opinion, but I personally wish the U.S. would make all forms of hacking and digital surveillance totally legal. Yes, legal, with no "I". I think this would drastically change the technology landscape, putting more impetus on vendors to provide (and prove) protections such as encryption, and an impetus on users to select the vendors who are the best at doing so. Hacking laws are a crutch that attempt…

That would backfire very rapidly. We have trillions of dollars of infrastructure that would last 3 days against a single competent hacker. There was just an article recently on vulnerable hardcoded-password medical devices. Electrical grids and construction equipment aren't much better. People's webcams that they already own, phones that they already own, highly insecure software is pervasive in everyone's every day life. It's inescapable.

The pressure you are talking about would be too great. Things would collapse if it became legal to actively pursue hacking them.

Re: More encryption means less privacy

#190
post #175
post #157

Earlier quoted context omitted.

Gunpowder plot of 1605 is a rather famous counter example: https://en.wikipedia.org/wiki/Gunpowder_Plot

That's really not a counterexample to my point. This was a conspiracy involving over a dozen people. It's a plot that unraveled because someone leaked the details. This is why technology has changed the balance. You don't need dozens of people to gather enough explosive material to pull this off today. And with fewer people involved, traditional detective work is harder, and those involved are less likely to leak det…

There are plenty of accidental detonations that killed hundreds which could have easily been caused by just one person as noted in another post. Though, wartime sabotage is not exactly terrorism.

Again, if you want to kill lot's of people disease, and fire where the most common historical examples. It's actually much harder for a lone person to kill thousands today than it was 500 years ago due to effective methods of firefighting.

Post reply on HN