Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

31–40 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#31
post #14

If they want to convince me to accept some kind of back door in my encryption, they have to propose a system where it can be shown that it cannot be abused by bad actors within my government, and where there are clearly stated public rules about when it can be used. It is possible to design such a system, where the probability of abuse is arbitrarily low [1], but I have a hard time imagining the current DOJ proposing…

I don't see how limiting access to a key escrow is sufficient to reduce the probability of abuse or exploitations.

Let's assume we have this "diverse group of shareholders" all with private keys and published public keys. The process for distributing and revoking those public keys adds a lot of complexity and points of failure.

Up to this point, the idea "works" but still provides a non-neglible increase in implementation complexity and decrease in security.

Once I use all those public keys to to encrypt my private key to place in escrow, it is impossible to verify if I have complied with the law and honestly provided an accurate escrow entry without actually having all those share holders decrypt my private key and verify that it correctly decrypts my content. At this point my content is exposed anyway.

It is NOT possible to create a secure, enforceable and un-abusable key escrow system.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#32
post #14

If they want to convince me to accept some kind of back door in my encryption, they have to propose a system where it can be shown that it cannot be abused by bad actors within my government, and where there are clearly stated public rules about when it can be used. It is possible to design such a system, where the probability of abuse is arbitrarily low [1], but I have a hard time imagining the current DOJ proposing…

> diverse international group

No government would ever agree to give multiple foreign governments/NGOs the veto power over tools that are "important for national security".

More realistically, your "shareholder groups" in any plan the government might actually approve would be existing groups the government is already involved with (e.g. Equifax).

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#33

The wording of this brings up a worrisome point. What encryption methods does the DOJ currently have access to? Why are they complaining about needing access to this encryption now? Is it because other previous encryption methods are know to be broken or they already have access to that data?

Probably because so many communications are moving to encrypted by default, HTTPS everywhere and WhatsApp for instance (as Brazil has found out). If the big players decide to switch to E2E then governments would need to get them to change their products. Better to head them off before it is too late.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#34
post #17
post #4

What did the police do before there was the internet or phones?

I'm no supporter of insecure cryptography, but before there was internet or phones and access to such, lots of crimes went unsolved.

Clearance rates for homicide have _dropped_ over the past 50 years:

  America’s homicide clearance rate—the percentage of solved
  crimes that lead to arrest—has fallen considerably in the
  past 50 years, from around 90% in 1965 to around 64% in
  2012, according to federal statistics.
(https://www.economist.com/news/united-states/21656725-police...) (See, also, https://www.citylab.com/equity/2017/06/police-arent-getting-...)

IMO, similar to counter-terrorism efforts (most spectacularly, 9/11), technology becomes a crutch. Frankly, I wouldn't be surprised if mass encryption leads to _improved_ clearance rates, as law enforcement becomes less complacent. Take this latest example: the FBI agent declines Apple's help because he's convinced the geeks at the FBI lab can handle it. He presumably doesn't bother actually confirming with the geeks in the lab, nor does he attempt to put Apple in touch with the lab. Just utter complacency, confident that the machine (computers, bureaucracy) will suffice.

This sort of laziness wouldn't have been tolerated in Hoover's FBI. Moreover, Hoover likely would have been more aggressive using the tools available to him--keyloggers, etc--rather than whining.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#35
post #13

Earlier quoted context omitted.

That's... just not true. And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies? I mean…

I had another comment, but in response to your Ed: comment: key size is not a measure of security. It is a measure of how /long/ we intend the key to be secure. More explicitly: Key size does not exist of the gradient of protocol security. We know how long a key takes to break given current technology and algorithms. We choose a key size to render the time to break infeasible against our prediction of state of the ar…

The "how long" is fits well with some other estabilished measures of security we use. For example, safes are designed to resist entry for a certain length of time. In military, defenses are often quantified by how long they should be able to hold back a presumed attack scenario.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#36
post #20
post #14

If they want to convince me to accept some kind of back door in my encryption, they have to propose a system where it can be shown that it cannot be abused by bad actors within my government, and where there are clearly stated public rules about when it can be used. It is possible to design such a system, where the probability of abuse is arbitrarily low [1], but I have a hard time imagining the current DOJ proposing…

> key escrow with access controlled by a multilevel secret sharing system that requires consensus among a diverse international group of shareholders to release the key from escrow. The shareholder group is chosen so that it includes a mix of public and private entities in a variety of jurisdictions, including anonymous shareholders, so that no entity can acquire enough power or influence to force a key to be reveale…

The probability of that can be made arbitrarily low by proper choice of parameters for the secret sharing system, at least against realistic threats over realistic timeframes.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#37
post #35
post #13

Earlier quoted context omitted.

I had another comment, but in response to your Ed: comment: key size is not a measure of security. It is a measure of how /long/ we intend the key to be secure. More explicitly: Key size does not exist of the gradient of protocol security. We know how long a key takes to break given current technology and algorithms. We choose a key size to render the time to break infeasible against our prediction of state of the ar…

The "how long" is fits well with some other estabilished measures of security we use. For example, safes are designed to resist entry for a certain length of time. In military, defenses are often quantified by how long they should be able to hold back a presumed attack scenario.

But thanks to math, we jumped from safes that can withstand hours of attack to math that can withstand every computer on this planet for the next 1e7 years before being cracked.

The problem with what others have posited as "money based encryption" easily scales up with AWS, Azure, GCE, and private clouds. Even individuals can buy a large cloud for 1h for cheap and crack with rainbow tables or such.

But for a real safe, I can go get a thermic lance. It nicely cuts inside most safes. Or I can use a bunch of liquid nitrogen and freeze-shatter it.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#38
post #32
post #14

If they want to convince me to accept some kind of back door in my encryption, they have to propose a system where it can be shown that it cannot be abused by bad actors within my government, and where there are clearly stated public rules about when it can be used. It is possible to design such a system, where the probability of abuse is arbitrarily low [1], but I have a hard time imagining the current DOJ proposing…

> diverse international group No government would ever agree to give multiple foreign governments/NGOs the veto power over tools that are "important for national security". More realistically, your "shareholder groups" in any plan the government might actually approve would be existing groups the government is already involved with (e.g. Equifax ).

Countries are known to do this on big issues, see eg. NATO.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#39
post #34
post #17

Earlier quoted context omitted.

I'm no supporter of insecure cryptography, but before there was internet or phones and access to such, lots of crimes went unsolved.

Clearance rates for homicide have _dropped_ over the past 50 years: America’s homicide clearance rate—the percentage of solved crimes that lead to arrest—has fallen considerably in the past 50 years, from around 90% in 1965 to around 64% in 2012, according to federal statistics. ( https://www.economist.com/news/united-states/21656725-police... ) (See, also, https://www.citylab.com/equity/2017/06/police-arent-getting-…

Wouldn't that be a change in data collection more than in absolute quality of problem-solving? Japan, for example, I remember reading that their near-perfect homicide rate is actually because they'll classify it as "fell down some stairs" if they can't solve it. Particularly in the US with its history of social issues, I can easily see a ton of homicides in the 50s just never being written down.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#40
This has been the refrain for 35 years. Open source strong encryption is everywhere now. The horse has left the barn, farm, county, state, and is currently swimming the Pacific.

Police have other ways to fight crime. Eventually we may be forced to deploy the ultimate weapon, namely correcting the social, economic, psychological, and neurological factors that breed it in the first place.

Post reply on HN