Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

21–30 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#21

Earlier quoted context omitted.

To defend this user's point, I think could be a case made for a key escrow that requires an unlock from different organizations. RSA solved this years ago. We could establish a key escrow that adds a key to your personal key. This extra key would allow unsealing in cases where it would be needed within the law. The extra key could be set up so that it requires X out of Y keys. Each key could be owned by different org…

We can also require that the hardware issuer (eg, Apple) stores an encrypted copy of the key (throwing away the key used to encrypt the original key), such that it costs $1M (or other amount) to break the encryption and reveal the key. There's no reason it shouldn't require expense and physical breaking to gain entry, just because it's digital (and I think that this scheme gains legal protection because of such featu…

To be honest, I'm against the "moneyball" solution. Hardware's going to only get: cheaper, faster, better. That $1m price will inexorably come down to the point that skiddie could do it on their phone with AWS.

I still stand by the point of having a consortium of opposing interests as a combined group (or supermajority) to override an encryption. I think of it as a strong version of checks and balances.

In that case, if members are also hidden, it doesn't matter how many dollars are thrown at the problem. Unless you have peoples' willful intent, the escrow doesn't work.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#22
post #6
post #4

What did the police do before there was the internet or phones?

Right? Apparently police never solved crime before they were allowed full access to every aspect of your life.

To be fair, it used to be that they didn't really solve most crimes.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#24
The government has demonstrated that they will abuse every power given to them, and even those that weren't. I would not entrust every aspect of my personal information to the very same organizations that indefinitely detains people, including American citizens, without access to a lawyer while commiting acts of torture; and the ones that said the Patriot Act could never be used for domestic surveilance; that lied about being unable to unlock the phone of the last guy they tried this with to get the law changed; and that continues to engage in parallel construction, torture by proxy, and extraordinary rendition. And now they're saying that we should trust them to stop those bad guys once again. And the most chilling aspect of this request, despite its inherent absurdity, unenforcibility, and threat to freedom and privacy, is that they have a very good chance of winning that power.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#25
post #13

Earlier quoted context omitted.

I had another comment, but in response to your Ed: comment: key size is not a measure of security. It is a measure of how /long/ we intend the key to be secure. More explicitly: Key size does not exist of the gradient of protocol security. We know how long a key takes to break given current technology and algorithms. We choose a key size to render the time to break infeasible against our prediction of state of the ar…

Sincere question: how do you define "how secure it is" except "how long it will remain secure (under attack)"? Edit: You're also completely eliding that security is probabilistic -- they might just guess our key on the first try. We can only discuss it as the expected amount of computation to figure out our key on average. That expected amount has a gradient along keysize.

A protocol is secure if, and only if, the fastest attack is an attack on the key itself. All of the recent crypto breaks (that not cause by prior key size restrictions req'd by gov agencies) have been protocol flaws, e.g. flaws in the protocol allowed you to derive the key without having to just explore the entire key space.

Anything other than deriving the plaintext of encrypted data alone would mean the protocol was insecure.

That said, I am coming to agree with you in terms of trying to explain to people who don't write crypto code that saying key size is gradient of security is probably the most sensible thing.

I still disagree with you on the actual statement :D

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#26
post #22
post #6

Earlier quoted context omitted.

Right? Apparently police never solved crime before they were allowed full access to every aspect of your life.

To be fair, it used to be that they didn't really solve most crimes.

there has never been a point where they solved most crimes. The difference is now people just happen to be carrying more information with them in their pocket than they ever had before.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#28
The wording of this brings up a worrisome point. What encryption methods does the DOJ currently have access to? Why are they complaining about needing access to this encryption now? Is it because other previous encryption methods are know to be broken or they already have access to that data?

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#29
post #4

What did the police do before there was the internet or phones?

I imagine they spent a lot of time solving crimes, asking questions like:

"Where did they keep all their papers and correspondence?"

"Can somebody come break into this safe we have a warrant for?"

What did the cops do before X was invented?

They didn't worry about X being used to commit or cover up criminal activities while continuing to try to do their job of keeping communities either safe or oppressed, depending on how well they related to them.

I support strong crypto, but I think implying detectives and the DoJ are just too lazy or dumb or whatever to deal with this problem is a little unfair.

Apologies if that wasn't the implication

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#30
post #22
post #6

Earlier quoted context omitted.

Right? Apparently police never solved crime before they were allowed full access to every aspect of your life.

To be fair, it used to be that they didn't really solve most crimes.

To be fair, they still don't
Post reply on HN