Live data from Hacker News

Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

rietta.com

111–120 of 139 posts

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#111
post #87

The irony here is that simple one-time-pad solutions (OTP) will continue to be available to securely encrypt the sort of messaging that's of use to terrorists (relatively short infrequent messages), instead it's the general communications (including for banking) that the rest of us perform online that will be made vulnerable. You don't even have to program or use a computer to create these OTP solutions, for limited…

> the sort of messaging that's of use to terrorists It seems increasingly apparent that recruitment and radicalisation are done in the open . After all, political speech is free speech. Then people either self-radicalise (go on a murder spree without coordinating action with a larger group; e.g. many mass shooters), or they meet up in person. Lots of radicalised people go to the Middle East where they can't be survei…

> There's remarkably little evidence that terrorists are making routine use of strong encryption.

Even if they were, we Americans have a fundamental right to strong encryption, protected under the Second, Ninth & Tenth Amendments to the Constitution. I'd go further still, and argue that everyone in the world (who's not a prisoner or otherwise unfree) has a right to strong encryption.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#112
post #46
post #36

Does anyone here remember the clipper chip? If you don't, I'd recommend boning up on this chapter of the crypto wars. The 'because terrorism' excuse falls a bit flat with me. Thought experiment: how hard would it be for a terrorist organization with access to 100's of millions of dollars (eg. ISIS) to come up with a secure communications scheme? One time pad. A reasonable cipher that hasn't had any 'help' during deve…

The Clintons and Al Gore have their paws all over the Clipper Chip.

It's a grave mistake to demonize a single politician you dislike: if it were that simple, they'd have dropped it as soon as that one person left office. In reality, there's a large community pushing for things which they perceive as making their job easier and that persists across administrations — that started well before Clinton ran for office and certainly didn't end after he left.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#113

The irony here is that simple one-time-pad solutions (OTP) will continue to be available to securely encrypt the sort of messaging that's of use to terrorists (relatively short infrequent messages), instead it's the general communications (including for banking) that the rest of us perform online that will be made vulnerable. You don't even have to program or use a computer to create these OTP solutions, for limited…

I'd rank the ability of terrorists to properly utilize OTPs as relatively low.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#114
post #3

The irony here is that simple one-time-pad solutions (OTP) will continue to be available to securely encrypt the sort of messaging that's of use to terrorists (relatively short infrequent messages), instead it's the general communications (including for banking) that the rest of us perform online that will be made vulnerable. You don't even have to program or use a computer to create these OTP solutions, for limited…

One time pads are perfect! Everything less than that trades security for convenience. So true.

If used properly they are, but many times people get lazy and reuse pads or use pads that are too short.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#115

Earlier quoted context omitted.

Also, > The cybersecurity threats that face our nation are very important to my wife and I. "to my wife and me"

"my wife and I" is fine. https://en.oxforddictionaries.com/usage/i-or-me

Um, what? You have linked to an explanation of why it's not fine. This mistake is getting more and more common, even among educated people. It's quite embarrassing/funny because it stems from a belief that "I" is inherently more "educated", and the result sounds anything but. I know us English speakers can't speak any non-English languages, in contrast to the rest of the educated world, but it's really not too much to ask for us to be able to comprehend the concept of subject of a sentence. Our parents' and grandparents' generations managed it fine, in fact would have been mortified to make a mistake like this.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#116
post #21

Just think of the outrage if the government required master keys to everyone's homes? I know there is a difference, but it's not a huge leap to compare the two. We don't want the government to have such easy access to our homes because we can't trust every government employee not to abuse it. I think the same goes here. No mater what safe guards you put in place it's a scary thought that you simply can't keep the gov…

Disclaimer: I agree with you but I always struggle to convince people that this line of reasoning makes sense. The government can already enter anybody's home upon receiving a warrant to do so. If you don't let them in, they can bust through a door or tear down a wall. We trust the government not to do this without court oversight. We trust courts to provide good and honest oversight. It is far from a perfect system,…

I agree that this effectively counters the lock and door analogy, and that it's better to avoid these analogies all together when making the case for strong encryption.

Another line of argument is to emphasize the extent that our digital economy and national security rely on strong encryption. If you outlaw it, then all of our online banking and shopping, corporate and government secrets, and more are vulnerable to hackers and foreign governments. And just as the conservative gun advocacy argument goes, outlawing it won't necessarily take encryption out of the hands of criminals, only law-abiding citizens.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#117
post #77

Earlier quoted context omitted.

Disclaimer: I agree with you but I always struggle to convince people that this line of reasoning makes sense. The government can already enter anybody's home upon receiving a warrant to do so. If you don't let them in, they can bust through a door or tear down a wall. We trust the government not to do this without court oversight. We trust courts to provide good and honest oversight. It is far from a perfect system,…

My preferred analogy is paper shredders. Imagine if any criminal could just walk into a store and buy a paper shredder so effective that it's impossible for the FBI to piece the data back together, with or without a warrant, no matter how many resources they throw at it. Clearly the solution is to require every paper shredder to be equipped with a camera to scan documents and upload them to cloud.gov before shredding…

The next step would be to outlaw fire because of its ability to render paper 100% unrecoverable.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#119
post #3

The irony here is that simple one-time-pad solutions (OTP) will continue to be available to securely encrypt the sort of messaging that's of use to terrorists (relatively short infrequent messages), instead it's the general communications (including for banking) that the rest of us perform online that will be made vulnerable. You don't even have to program or use a computer to create these OTP solutions, for limited…

One time pads are perfect! Everything less than that trades security for convenience. So true.

Of course, that perfection is achieved by shifting all your risk to key distribution.

I think of OTPs as a form of time-shifting. Think of it this way: if you and your correspondent have viable OTPs, that implies that, at some point in the past, you securely communicated that OTP. Since it is (at least) the length of a future message, you could have just passed a secure message then. Instead, you passed something that enables passing a secure message now.

Re: Americans' Access to Strong Encryption Is at Risk, an Open Letter to Congress

#120
post #119
post #3

Earlier quoted context omitted.

One time pads are perfect! Everything less than that trades security for convenience. So true.

Of course, that perfection is achieved by shifting all your risk to key distribution. I think of OTPs as a form of time-shifting. Think of it this way: if you and your correspondent have viable OTPs, that implies that, at some point in the past, you securely communicated that OTP. Since it is (at least) the length of a future message, you could have just passed a secure message then. Instead, you passed something tha…

Imagine implementing your amazing solution in real life.

I don't see a situation being frequent where you'd know the message weeks or months in advance of when you send it. If we follow your scheme, there's no encryption; we just meet up when we need to communicate. What if we're on opposite sides of the earth? If we had exchanged keys months earlier, this wouldn't be a problem.

Post reply on HN