Earlier quoted context omitted.
I think a very important point was raised though. Before crypto, basically all guarantees where conditional on a judge's say so. With crypto this changes. The issue also comes up, in a clearer way, with crypto currencies. There is no way to deal with fraud or mistaken tranfers in bitcoin. That loss of intervention hurts, and we gotta think about it. Even though no government has given a satisfactory solution, that do…
Before crypto, basically all guarantees where conditional on a judge's say so Tell that to J. Edgar Hoover.
More encryption means less privacy
211–220 of 221 posts
Re: More encryption means less privacy
#212Earlier quoted context omitted.
Before crypto, basically all guarantees where conditional on a judge's say so Tell that to J. Edgar Hoover.
That just shows they were conditional on things beyond a judge's say so. I.e. security can also be broken by people willing to break the law.
Re: More encryption means less privacy
#213Earlier quoted context omitted.
You fail to grasp the key point here: If the state cannot break your encryption, they will break you instead.
Which makes your whole argument sound like: "I'm such a coward! Please take my private data, just don't hurt me!" Belive it or not, but some people actually have balls to fight evil governments.
Re: More encryption means less privacy
#214Earlier quoted context omitted.
Well, two things: 1. I've always maintained that privacy is a political and social problem, not just a technological one. Nothing stops a more powerful actor from breaking encryption with a rubber hose if they really want to. Technological solutions are still needed since there's a variety of actors involved, only some of which will obey the political doctrine. 2. I often wonder if encryption will make us think of pr…
Rubber hoses don't scale. With our technological solution, we make it so that the government can't access 99.9% of all conversations. If they want to access a conversation here or there, they can use a rubber hose. But if they want to see every conversation in a person's social network (including conversations they weren't directly involved in), then they aren't going to be able to do that anymore. Technology helps a…
Re: More encryption means less privacy
#215Earlier quoted context omitted.
> Before crypto, basically all guarantees where conditional on a judge's say so. Sadly, they weren't. > With crypto this changes. Actually, with crypto it is much harder to claim that a judge's authorization isn't required to even try to subvert the privacy intent. > There is no way to deal with fraud or mistaken tranfers in bitcoin. There's no way because legally the system (for the most part) considers it outside t…
> with crypto it is much harder to claim that a judge's authorization isn't required to even try to subvert the privacy intent. No doubt, but the issue is that a judge's authorization can be ineffective in the face of crypto. > TLS doesn't create a real loss of intervention. It requires that the intervention be far more explicit and/or targeted. That targeted intervention is really easy to block for those who want to…
Only when it should be. Crypto just means you need a secret to access the data. If you can't compel the secret, why should you be able to compel the data?
> That targeted intervention is really easy to block for those who want too. All it takes is not revealing a key/passphrase.
You say that like it is an easy thing. Try keeping your key/passphrase protected against an adversary that can replace/intercept your keyboard, your touch screen, your mouse, your network, etc. It's just a lot more intrusive and a lot more work, which is why it has to be far more explicit and targeted.
> > There's no way because legally the system (for the most part) considers it outside the scope of fraud laws. > Not just that though, it is also impossible because the conditionals introduced by a court system are very hard to encode in a crypto system, even more so if you want to do this and be able to retain trust.
Those conditionals were all choices made by the legal system. Those rules can always be changed if so desired. If they aren't... maybe it is because they shouldn't be. ;-)
Re: More encryption means less privacy
#216Earlier quoted context omitted.
How many of the NSA's backdoors have ended up in the hands of foreign nations and criminals, again?
To be fair, the NSA did have a very high profile incided where they were considering legally mandating a physical backdoor, called the Clipper Chip, until it was proven that the chip had a gaping vulnerability. https://en.wikipedia.org/wiki/Clipper_chip
Re: More encryption means less privacy
#217This is a fringe opinion, but I personally wish the U.S. would make all forms of hacking and digital surveillance totally legal. Yes, legal, with no "I". I think this would drastically change the technology landscape, putting more impetus on vendors to provide (and prove) protections such as encryption, and an impetus on users to select the vendors who are the best at doing so. Hacking laws are a crutch that attempt…
That would backfire very rapidly. We have trillions of dollars of infrastructure that would last 3 days against a single competent hacker. There was just an article recently on vulnerable hardcoded-password medical devices. Electrical grids and construction equipment aren't much better. People's webcams that they already own, phones that they already own, highly insecure software is pervasive in everyone's every day…
This "too big too risk" is precisely why we need this, and needed it twenty years ago. And we need it now, so that we aren't in a worse spot next year, etc.
To lessen the pain maybe for the first few years only "mostly harmless" hacks with full disclosure could be made fully legal. We could ramp up slowly.
Re: More encryption means less privacy
#218I don't totally understand this view. Government doesn't have a right to ephemeral conversations that happen in physical space between two people. We aren't required to record them in case some law enforcement officer might request them. Why is online discourse different? Just because the bits still exist in some sense, why does that mean they need to be accessible?
Government doesn't have a right to meticulous transcriptions of every verbal conversation you've ever had. But, it does have a right to do its utmost to figure out what was said. It has a right to search your file cabinet, or tap your phone, or tail you with a detective, with a warrant of course.
Because in our system it's not the judge who can make that call, it's you (theoretically a citizen) who grants the government the authority to take certain (constitutionally limited) actions as long as it serves the people.
If the government has a "right" to tap your phone they have the same right to plant a microphone on you, and at that, they do have a right to every verbal conversation you've had. Because they can get one from the other.
Re: More encryption means less privacy
#219The article seems to make the fundamental error of assuming that there is any middle ground between "unbreakable crypto" and "effectively no crypto at all". If crypto can be broken, it will be broken, whether that's by state actors or by some kid in Mongolia who wants to make a quick buck by ransoming all your files.
Because it's not a fundamental error or indeed an error at all. What you've just expressed is one of those fascinating pieces of mental junk that clutters up social groups, a political desire that's so strongly held you've managed to rationalise to yourself that it's a fact and not a personal desire at all. But it's still not a fact. It is trivial to use cryptography in ways that yield some sort of balance between pe…
So not enough crypto to prevent absolute centralization of power by the institution with a monopoly on violence.
Re: More encryption means less privacy
#220Earlier quoted context omitted.
If there is a backdoor, that backdoor can be used by anyone that has the key. I do not trust a government to responsibly handle such a key, as it leaking once results in total failure of security for everyone. A backdoored crypto system is a broken crypto system.
There are lots of examples of governments maintaining the integrity of keys over the long term. The e-Passport system is an example of that. Another would be that the NSA had the ultimate insider hack - literally a sysadmin who dumped their entire internal wikis and document stores - and yet it appears that no key material was compromised. You can repeat "a backdoored system is no system" mantra to yourself if you li…