Live data from Hacker News

European Union dedicated questionnaire on the Encryption of Data

blog.lukaszolejnik.com

41–50 of 113 posts

Re: European Union dedicated questionnaire on the Encryption of Data

#41
I find the german answers [1] surprisingly reasonable.

High Five for the final answer:

> 11. Are there other issues that you would like to raise in relation to encryption and the possible approach to these issues? Please share any relevant national experience or considerations arising from your practice that need to be taken into account.

> Yes. A regulation to prohibit or to weaken encryption for telecommunication and digital services has to be ruled out, in order to protect privacy and business secrets.

Go Germany!

[1] https://www.asktheeu.org/en/request/3347/response/11727/atta...

Re: European Union dedicated questionnaire on the Encryption of Data

#42
post #7
post #4

Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…

The problem is: How do you handle cases where data appears to be encrypted but it isn't? Or, the data is encrypted but the suspect has forgotten the password?

The state has little incentive to care about such issues. Look at the success and continued use of BS forensic science... False positives aren't a problem.

Re: European Union dedicated questionnaire on the Encryption of Data

#43
post #17

Can anybody point to organized lobbying efforts we can support to maintain all of this as far away as possible from Europe ? My country has refused to give the answers citing security reasons (according to the article).

In the Netherlands we have Bits of Freedom, they are mentioned in the article:

> Thanks to Bits of Freedom, those answers are now public. That's called transparency.

Another Dutch one I know is Privacy First. When elections come up we always have a vote advice website which is quite popular. You enter your opinion on some current topics (old example: joint strike fighter funding: continue or not?) and it computes which party's goals align the most. Privacy First had an interesting take on this: they looked at what parties pushed for in the past and matched that with what you would have wanted (focusing on privacy-related topics of course). Not looking at promises but at track record. Privacy First probably does other stuff as well, just like BoF, but I don't keep up.

I don't know about other countries unfortunately.

Re: European Union dedicated questionnaire on the Encryption of Data

#44

You don't need to take on cryptography to fight cybercrime. Cybercrime usually leaves huge trail of evidence. Usually in form of lost money (transactions) and bricked devices. Fighting cybercrime has different obstacles: it's usually cross-border, and its victims are usually common people. Nobody cares terribly much when a commoner loses $100. Even when there's a thousand of them. What you need to take on cryptograph…

> Usually in form of lost money (transactions) and bricked devices.

This is precisely why law enforcement doesn't need to weaken encryption nor weaken the rights of suspects and defendants. If there is a material crime, that crime has left a trail of evidence in the real world, especially a money trail.

And if you think Leviathan needs unbounded powers or you'll be left as a tasty morsel in the state of nature, physics has always bounded state power, and injustices happen when state power is pushed beyond natural bounds.

Re: European Union dedicated questionnaire on the Encryption of Data

#45
Regulation of cryptography can help investigations but regulation is still a bad idea. A good explanation is something that my ethics professor said. It was something along the lines of "If a pen was used to write orders for the army to start WW2, should pens be banned?". The war would probably happened anyway even if pens were banned/regulated and it is certainly not the cause of the war. Cryptography is very similar: even if it would have been regulated, criminality will not just vanish.

Re: European Union dedicated questionnaire on the Encryption of Data

#46
post #11

Earlier quoted context omitted.

> but I'll give the password to police if they have a search warrant. That’s not right. In most countries, you don’t need to incriminate yourself. Before making wrongheaded decisions, contact a lawyer.

This. In the U.S. at least, the 5th amendment gives you the right not to incriminate yourself. A search warrant doesn't change that. Not all authentication methods are equal it appears. Fingerprint, facial recognition, other bio-metrics aren't considered the same as if you need to "speak" your password to someone. In other words, they can make you scan your finger or look into a camera, but they can't force you to te…

Yes, there is a distinction in US law between acquiring physical and "mental" evidence.

The former can be forced (e.g. I must provide my safe key) and the latter cannot (e.g. I don't have to reveal my password).

The line gets blurry: keyed lock vs combination lock, password vs SSH key.

Re: European Union dedicated questionnaire on the Encryption of Data

#47
post #32

Earlier quoted context omitted.

How about forcing you to type the password, behind a Mantle of Power if need be, such that they can decrypt the disk, without ever knowing the password?

As I understand it, in the US at least this is indeed the line. Same goes for combination vs keyed locks: you can't be forced to self-incriminate by sharing information, but you can be held in contempt for withholding evidence. I imagine it gets murky around things like SSH keys, which are technically a kind of password, but too big for a human to remember - and therefore must be "instantiated" in a physical device s…

> I imagine it gets murky around things like SSH keys, which are technically a kind of password, but too big for a human to remember - and therefore must be "instantiated" in a physical device somewhere.

A likely interpretation might be: an SSH key without a keyphrase is like a physical key, and you must hand it over, while a key with a keyphrase is like a combination lock, where you must hand it over but you are not required to state the keyphrase.

Re: European Union dedicated questionnaire on the Encryption of Data

#48
post #7
post #4

Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…

The problem is: How do you handle cases where data appears to be encrypted but it isn't? Or, the data is encrypted but the suspect has forgotten the password?

How do you handle cases where someone lies about a crime they've committed?

Solving offenses without 100% certain evidence is by no means a new problem.

Post reply on HN