Live data from Hacker News

Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

rietta.com

31–40 of 139 posts

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#31
post #23

Earlier quoted context omitted.

> The likelihood for a criminal to use a one time pad is extremely low. The likelihood of them having an encrypted cell phone with useful information is much higher. Maybe that's the case right now, but how can you be so confident that these actors won't switch to OTP if such a law is enacted?

Because prior to cell phone total encryption (less than 10 years ago) we did not have a pandemic of criminals using one time pads.

That's a terrible example.

Encryption wasn't mainstream at all back then and, more crucially, digital surveillance was still in its infancy. The most popular chat app in the world right now implements full E2E encryption. Go back 10 years and having a "chat" consisted of sending your friends SMS messages.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#32
post #26

Earlier quoted context omitted.

I would not be so sure of that. I really believe the President's guiding principle is to do whatever it is that will enrage liberals the most. If Republicans see that liberals want strong encryption, they might decide to oppose it just to piss off liberals. It's amazing to me that a lot of the same people advocating gun rights are also the ones that support government mandated encryption backdoors.

Those who fought against having strong encryption classified as a munition for purposes of export were on the wrong side of the issue. They didn't realize that one day they would need the second amendment to protect their right to such "weapons". -- this post is a poor paraphrase of a comic I saw once. Edit: turns out it's a relevant xkcd™ https://m.xkcd.com/504/

Sure, but civilians can't own nukes, for example.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#33
post #31

Earlier quoted context omitted.

Because prior to cell phone total encryption (less than 10 years ago) we did not have a pandemic of criminals using one time pads.

That's a terrible example. Encryption wasn't mainstream at all back then and, more crucially, digital surveillance was still in its infancy. The most popular chat app in the world right now implements full E2E encryption. Go back 10 years and having a "chat" consisted of sending your friends SMS messages.

Exactly - and yet most criminals were happy to use that insecure and broken SMS. I'd love to see a study on the proportion of criminals that even know what encryption is. I expect it to be extremely low.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#34
post #31

Earlier quoted context omitted.

That's a terrible example. Encryption wasn't mainstream at all back then and, more crucially, digital surveillance was still in its infancy. The most popular chat app in the world right now implements full E2E encryption. Go back 10 years and having a "chat" consisted of sending your friends SMS messages.

Exactly - and yet most criminals were happy to use that insecure and broken SMS. I'd love to see a study on the proportion of criminals that even know what encryption is. I expect it to be extremely low.

Exactly what? My point is that encryption is fairly common right now, even for average consumers. If political activists use Tor and Signal quite regularly, why wouldn't criminals do the same? I still don't quite understand why you're comparing what criminals did back then to what they could do right now.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#35

Wait does he have a Masters in Information Security from the College of Computing at the Georgia Institute of Technology???! Joking aside, unfortunately it takes deep problems to motivate people/the US to change. It'll swing this way, and there will be dramatic consequences. Only then will things swing back the other way. It's too bad there isn't any balance here -- it does make sense in many situations that the poli…

It looks like you forgot to pay your Squarespace bill: "This account has expired. ( http://empiric.al )"

Joking aside, I guess you're saying that leading with credentials in an article is unnecessary if that article is relatively short and you've got a bio blurb at the bottom of the page?

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#36
Does anyone here remember the clipper chip? If you don't, I'd recommend boning up on this chapter of the crypto wars.

The 'because terrorism' excuse falls a bit flat with me.

Thought experiment: how hard would it be for a terrorist organization with access to 100's of millions of dollars (eg. ISIS) to come up with a secure communications scheme? One time pad. A reasonable cipher that hasn't had any 'help' during development. Even run an encrypted channel over a backdoored product. I'm sure many of us could come up with something in a day (with decryption over an airgap). How about a hostile government with multi-billion dollar budgets (and who have been using OTP already for decades).

Is this about terrorists, or is this about citizens? My bet is on the latter.

https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Crypto_Wars

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#37
post #35

Wait does he have a Masters in Information Security from the College of Computing at the Georgia Institute of Technology???! Joking aside, unfortunately it takes deep problems to motivate people/the US to change. It'll swing this way, and there will be dramatic consequences. Only then will things swing back the other way. It's too bad there isn't any balance here -- it does make sense in many situations that the poli…

It looks like you forgot to pay your Squarespace bill: "This account has expired. ( http://empiric.al )" Joking aside, I guess you're saying that leading with credentials in an article is unnecessary if that article is relatively short and you've got a bio blurb at the bottom of the page?

That's actually a good point. I originally wrote this as a private message to each of the Congressional candidates in the Georgia 6th district and in that format there was not the bio and all the surrounding blog template. It feels weird to be to lead with it too, but I'm trying to answer real quick to a politician who does not know the science why he or she should read on to the next paragraph.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#39
post #37
post #35

Earlier quoted context omitted.

It looks like you forgot to pay your Squarespace bill: "This account has expired. ( http://empiric.al )" Joking aside, I guess you're saying that leading with credentials in an article is unnecessary if that article is relatively short and you've got a bio blurb at the bottom of the page?

That's actually a good point. I originally wrote this as a private message to each of the Congressional candidates in the Georgia 6th district and in that format there was not the bio and all the surrounding blog template. It feels weird to be to lead with it too, but I'm trying to answer real quick to a politician who does not know the science why he or she should read on to the next paragraph.

I think you're discovering that text written for one medium might benefit from revision when published elsewhere. :-)

Also, I think it's reasonable these days to write hardcopy letters that look more like websites -- multiple columns, a bio section, etc. Don't restrict yourself to obsolete and arbitrary etiquette.

Post reply on HN