Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

41–50 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#41
It's hard to know where to even begin in arguing against this.

There's the freedom/privacy argument, but I guess this is debatable depending on if you view computer files as an extension of your ideas/knowledge, or an extension of your physical possessions.

Someone brought up the entire "risk of overreach and abuse" argument.

There's also the likelihood of any tools the government has being leaked and used by bad actors (as we have seen too much recently).

Oh, and the "it's technologically impossible" argument, which should be the only one you need -- but they refuse to hear that. (Are there some supposed experts who are telling the DOJ this can be done?)

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#42
post #36
post #20

Earlier quoted context omitted.

> key escrow with access controlled by a multilevel secret sharing system that requires consensus among a diverse international group of shareholders to release the key from escrow. The shareholder group is chosen so that it includes a mix of public and private entities in a variety of jurisdictions, including anonymous shareholders, so that no entity can acquire enough power or influence to force a key to be reveale…

The probability of that can be made arbitrarily low by proper choice of parameters for the secret sharing system, at least against realistic threats over realistic timeframes.

What are some examples of such parameters?

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#43
post #41

It's hard to know where to even begin in arguing against this. There's the freedom/privacy argument, but I guess this is debatable depending on if you view computer files as an extension of your ideas/knowledge, or an extension of your physical possessions. Someone brought up the entire "risk of overreach and abuse" argument. There's also the likelihood of any tools the government has being leaked and used by bad act…

> Someone brought up the entire "risk of overreach and abuse" argument.

I don't have a problem with the authorities operating within the purview of the Constitution, eg. a warrant from a court for a particular device. That, however, is not how we got to where we are today.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#44
When I was in college, there was a retired guy that would come in to tutor students as a way to stay busy.

He was your stereotypical brainiac type dude - quiet, lanky, glasses, soft spoken, and razor sharp. He must have been in his 50s, but you would think he had just completed upper division math, chemistry, and physics "last semester" with perfect grades to boot.

He told me a story about how once while in his Masters program, one of his colleagues figured out how to do some cool stuff with unenriched uranium.

Almost like out of a movie, he said, the government stepped in and made sure he did not publish his research.

I wonder if we'll see that type of stuff happen with cryptography or if it's already happening. I wouldn't be surprised if these theatrics were just to maintain the illusion that they don't have access to stuff.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#45
Here's my biggest complaint with this debate - people are confusing literal with metaphorical. They make the analogy of the unbreakable safe. Encryption isn't that. You can still recover the physical phone and all of the storage chips on it.

That the patterns of bits in the chips make up some unrecognizable utterance is seemingly immaterial. I could write gibberish in my journal at home if I wanted to, and I think we'd all agree it would be ridiculous for the FBI to run around screaming about unbreakable ink

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#47

Earlier quoted context omitted.

That's... just not true. And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies? I mean…

To defend this user's point, I think could be a case made for a key escrow that requires an unlock from different organizations. RSA solved this years ago. We could establish a key escrow that adds a key to your personal key. This extra key would allow unsealing in cases where it would be needed within the law. The extra key could be set up so that it requires X out of Y keys. Each key could be owned by different org…

I as a private citizen do not want the government to have access to my files. Period. End of story. They have zero right to have access to every aspect of my life. Any "solution" that involves any government the ability to access encrypted files is not encryption, but a lie.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#48

Here's my biggest complaint with this debate - people are confusing literal with metaphorical. They make the analogy of the unbreakable safe. Encryption isn't that. You can still recover the physical phone and all of the storage chips on it. That the patterns of bits in the chips make up some unrecognizable utterance is seemingly immaterial. I could write gibberish in my journal at home if I wanted to, and I think we…

His comment makes sense to 99% on non-tech people, and if it was possible it would make sense to all. Would we want to open Bin Laden's iPhone?

He wants you to have your home with 100 locks, guard dogs and armed guards. BUT if a court orders you, you have to let the police in to check x, y and z. Now I don't think that a secret key can be somewhere and stay safe for a long time. It will be leaked or hacked. This places hundreds of million innocent people at extreme danger of having everything personal revealed.

So, IMO, giving the cops a master key opening all our doors "if needed" doesn't work. TSA does that, but presumably while cameras are running, and this is stuff we know it will be searched. So encryption is the best option.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#49
post #29
post #4

What did the police do before there was the internet or phones?

I imagine they spent a lot of time solving crimes, asking questions like: "Where did they keep all their papers and correspondence?" "Can somebody come break into this safe we have a warrant for?" What did the cops do before X was invented? They didn't worry about X being used to commit or cover up criminal activities while continuing to try to do their job of keeping communities either safe or oppressed, depending o…

Except in most circumstances, there wouldn't have been any papers, because nobody was recording all their conversations. Nowadays, everything is happening digitally and is stored indefinitely by default; and law enforcement feels like they deserve access to all that.

The attempts at preventing ubiquitous encryption don't seem to be focused on crimes where there would have been a paper trail if people still used paper; they are focusing on reconstructing the last year or so of someone who is either dead or uncooperative, all in hopes of finding something they can use.

If they were targeting organizations with a bureaucracy for some crime, I think they could just demand access to all documents and get them? If I remember correctly, in the Levandowski case Google's lawyers got access to a huge trove of Uber's internal emails. If a private company can get that access, it should be possible for law enforcement as well, no?

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#50
post #24

The government has demonstrated that they will abuse every power given to them, and even those that weren't. I would not entrust every aspect of my personal information to the very same organizations that indefinitely detains people, including American citizens, without access to a lawyer while commiting acts of torture; and the ones that said the Patriot Act could never be used for domestic surveilance; that lied ab…

> that lied about being unable to unlock the phone of the last guy they tried this with to get the law changed…

I found it very telling that they announced their inability to access the phone only a few days after the incident. It struck me as a very clear PR move that was designed to lay the groundwork to shape public opinion. My threshold for declaring that the device is inaccessible requires more time for research and effort than this.

Post reply on HN