Encryption will never be intentionally backdoored on a large scale. I think one of RSA argued this, basically "Do you really think the government will want to review and approve everything on the app store?" Forcing big players to divulge data, making accused people decrypt their devices -- those are things the government could do. Encryption per se isn't in any danger.
I don't think it is the encryption protocols at risk really. Secure protocols exist now, they will continue to exist. It is the future hardware implementations and closed source software implementations that we will no longer be able to trust.
Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
71–80 of 139 posts
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#72Earlier quoted context omitted.
Personally I think you can make it a crime not to produce a key if a warrant has been issued to search what ever you've encrypted. That is a lot more out in the open than a "back door". When the government bashes through the door at least it's in plain site and the house owner knows it's happening. But with encryption how would you know if the government has used their access?
>Personally I think you can make it a crime not to produce a key if a warrant has been issued to search what ever you've encrypted. Personally, I find that suggestion repugnant.
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#73The irony here is that simple one-time-pad solutions (OTP) will continue to be available to securely encrypt the sort of messaging that's of use to terrorists (relatively short infrequent messages), instead it's the general communications (including for banking) that the rest of us perform online that will be made vulnerable. You don't even have to program or use a computer to create these OTP solutions, for limited…
Well, 'they' allowed door locks to be easily broken by anyone with minuscule knowledge in lockpicking because that is the type of locks 'they' like on doors. It's going to be no different for "crypto" solutions. *Part of the FBI's job was to harrass anyone they considered a dissident or counter to their view of what US citizen should be or how they should behave. I doubt they changed at all. It's already documented a…
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#74Earlier quoted context omitted.
>Personally I think you can make it a crime not to produce a key if a warrant has been issued to search what ever you've encrypted. Personally, I find that suggestion repugnant.
How is this different to getting a warrant to search say a safe deposit box at a bank? Is there something about encrypted data that should be beyond the reach of the law?
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#75Earlier quoted context omitted.
How is this different to getting a warrant to search say a safe deposit box at a bank? Is there something about encrypted data that should be beyond the reach of the law?
I already have so many different accounts on various websites that I regularly forget a password, the same can happen with an encryption key. Should that be a crime?
We also require people to document their finances to accurately tax them. You're presumed 'guilty until proven innocent' in the sense that you're taxed on income unless you can document that it's untaxable(a business expense). There are penalties for failing to document things. What's wrong with requiring you to document your private keys, along with your receipts?
If you sell apples under the name "Loving Apples", you have to pay your state government to register that name. You can be fined for not registering your name, and your bank or other financial provider will want to see the government approval document. You could have the government maintain a central registry of all private keys, and make it a crime to encrypt a document with a key not documented in a state agency.
If you receive a document that is encrypted, you may be further required to tell the government who gave it to you, to ensure compliance with the encryption law; similar to how giving someone money requires you to tell the government about the transaction for compliance with tax law.
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#76Earlier quoted context omitted.
I already have so many different accounts on various websites that I regularly forget a password, the same can happen with an encryption key. Should that be a crime?
We already require corporations to preserve all their email, voice, and other electronic communications in case the government wants to investigate it. Maybe you're irresponsible for losing your key, and need to be held accountable. We also require people to document their finances to accurately tax them. You're presumed 'guilty until proven innocent' in the sense that you're taxed on income unless you can document t…
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#77Just think of the outrage if the government required master keys to everyone's homes? I know there is a difference, but it's not a huge leap to compare the two. We don't want the government to have such easy access to our homes because we can't trust every government employee not to abuse it. I think the same goes here. No mater what safe guards you put in place it's a scary thought that you simply can't keep the gov…
Disclaimer: I agree with you but I always struggle to convince people that this line of reasoning makes sense. The government can already enter anybody's home upon receiving a warrant to do so. If you don't let them in, they can bust through a door or tear down a wall. We trust the government not to do this without court oversight. We trust courts to provide good and honest oversight. It is far from a perfect system,…
Clearly the solution is to require every paper shredder to be equipped with a camera to scan documents and upload them to cloud.gov before shredding. Of course, nobody would be authorized to look at the data without a warrant, and we should trust that nobody working for the government would ever break this law.
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#78Earlier quoted context omitted.
We already require corporations to preserve all their email, voice, and other electronic communications in case the government wants to investigate it. Maybe you're irresponsible for losing your key, and need to be held accountable. We also require people to document their finances to accurately tax them. You're presumed 'guilty until proven innocent' in the sense that you're taxed on income unless you can document t…
Wouldn't the same reasoning apply to all communication? Do you keep transcripts and/or recordings of all private conversations you have (in meatspace) so that you can hand those to the government when they show up with a warrant? Would you like to live in a society where not keeping such records is a crime? If not, why should communication "on a computer" be held to a different standard?
Which direction of the implication you take is a matter of preference. People who agree with giving the government full power(and trust them not to abuse it) or who agree with not giving the government any of this power are both logically consistent with my argument.
I'm only attempting to rule out people who are okay with all of the existing documentation requirements, but balk at documenting their encryption keys.
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#79Earlier quoted context omitted.
Well, 'they' allowed door locks to be easily broken by anyone with minuscule knowledge in lockpicking because that is the type of locks 'they' like on doors. It's going to be no different for "crypto" solutions. *Part of the FBI's job was to harrass anyone they considered a dissident or counter to their view of what US citizen should be or how they should behave. I doubt they changed at all. It's already documented a…
Picking locks requires physical presence. Stealing bank credentials online can be done from another continent using public wifi. It's not a great comparison because the number of criminals with access to your computer is much higher than the number of criminals with access to your front door (multiple orders of magnitude), and their ability to distance themselves from the act (both geographically and forensically) is…
Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress
#80Just think of the outrage if the government required master keys to everyone's homes? I know there is a difference, but it's not a huge leap to compare the two. We don't want the government to have such easy access to our homes because we can't trust every government employee not to abuse it. I think the same goes here. No mater what safe guards you put in place it's a scary thought that you simply can't keep the gov…
Disclaimer: I agree with you but I always struggle to convince people that this line of reasoning makes sense. The government can already enter anybody's home upon receiving a warrant to do so. If you don't let them in, they can bust through a door or tear down a wall. We trust the government not to do this without court oversight. We trust courts to provide good and honest oversight. It is far from a perfect system,…
Imagine if the government busted down a quarter of all doors in the country - that's a lot of industrial-scale police work, and it's very visible to all citizens. On the other hand, the government can tap half of all phones in the country, or intercept half of all emails sent by US residents, and we're not even legally allowed to know it happened, so we can't even argue against it in a public court of law.
Atomic-grade offense requires atomic-grade defense. We will have un-breakable encryption, or we will be crushed by secret intelligence agencies with immense power and no public accountability. It's a whole new game.
Anyway, I'm not too worried, strong encryption is open source and widely available already (even if not used in nearly all the circumstances it should be yet). This cat isn't going back in the bag.