Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

1–10 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#7
post #5

I wish this could be hammered into the thick heads of congress: there is secure, and there is insecure. There is not a gradient.

That's... just not true.

And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies?

I mean -- "there is not a gradient"? ...what do you call changing key size?

Ed:

I'd like the people downvoting to explain how changing the keysize isn't a gradient of security. (Hint: You can't, because it is.)

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#8
post #4

What did the police do before there was the internet or phones?

They do just like they do now: lobby to get more laws to either (1) gain more leverage to coerce compliance or (2) criminalize actions which are tangent to the behavior they want to coerce.

I realize your question was rhetorical.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#9
post #5

I wish this could be hammered into the thick heads of congress: there is secure, and there is insecure. There is not a gradient.

That's... just not true. And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies? I mean…

We change key size because what is secure in terms of key size is literally compute bound. Key strength changes because we predict when a key will /cease being secure/.

That said most of the demands made by DoJ aren't for reduced key size, they're for variations of key /escrow/: literally breaking the security model of crypto entirely.

So maybe I could be more specific: there is no such thing as an almost secure protocol.

The key (ha!) result of this recognition is that all secure protocols have been moving to some variant of ephemeral keys. Specifically to deal with the problem of all static keys eventually becoming insecure.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#10
post #5

I wish this could be hammered into the thick heads of congress: there is secure, and there is insecure. There is not a gradient.

That's... just not true. And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies? I mean…

To defend this user's point, I think could be a case made for a key escrow that requires an unlock from different organizations. RSA solved this years ago. We could establish a key escrow that adds a key to your personal key. This extra key would allow unsealing in cases where it would be needed within the law.

The extra key could be set up so that it requires X out of Y keys. Each key could be owned by different organizations, like the state govt, FBI, Courts, Nonprofit oversight committees, citizens oversight of police, and such. This could provide a balance of security and privacy, and allow in extreme circumstances a forced break of encryption.

(Ideally, it would require many orgs that are normally in opposition to agree. It would not be "state govt", "FBI", "CIA" like the old Clipper Chip.)

Post reply on HN