Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

51–60 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#51
I can’t overstate how important it is for Google, Apple, and Microsoft to keep hammering at this. It’s workkng. The DOJ is running into this a lot now (e.g. can’t get into a drug dealer’s iPhone to see who he’s messaging). Eventually, they’ll see that the ship has sailed and encryption is just something they have to deal with.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#52
post #24

The government has demonstrated that they will abuse every power given to them, and even those that weren't. I would not entrust every aspect of my personal information to the very same organizations that indefinitely detains people, including American citizens, without access to a lawyer while commiting acts of torture; and the ones that said the Patriot Act could never be used for domestic surveilance; that lied ab…

> that lied about being unable to unlock the phone of the last guy they tried this with to get the law changed… I found it very telling that they announced their inability to access the phone only a few days after the incident. It struck me as a very clear PR move that was designed to lay the groundwork to shape public opinion. My threshold for declaring that the device is inaccessible requires more time for research…

Don't forget that the phone was unencrypted when they got it, and that it was the FBI who locked it in the first place: https://www.nytimes.com/2016/03/02/technology/apple-and-fbi-...

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#53

Here's my biggest complaint with this debate - people are confusing literal with metaphorical. They make the analogy of the unbreakable safe. Encryption isn't that. You can still recover the physical phone and all of the storage chips on it. That the patterns of bits in the chips make up some unrecognizable utterance is seemingly immaterial. I could write gibberish in my journal at home if I wanted to, and I think we…

The other side of this is that enshrining encryption as something that police can't compel you to help with just creates a huge loophole for hiding incriminating documents. You can go to jail for destroying evidence, why would encrypting the data and refusing to provide the password or deleting the key be any different?

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#54
post #24

The government has demonstrated that they will abuse every power given to them, and even those that weren't. I would not entrust every aspect of my personal information to the very same organizations that indefinitely detains people, including American citizens, without access to a lawyer while commiting acts of torture; and the ones that said the Patriot Act could never be used for domestic surveilance; that lied ab…

Everything you're saying is true, but I think there's something far less dramatic that somehow rings true for people even more. One revelation of Snowden is that the NSA would regularly 'seize' and pass around attractive nudes and other such media that were intercepted from people. [1] At other times there was something that even got its own little name 'LOVEINT' which would involve NSA workers spying on their love or romantic interests for reasons. [2]

When you talk about things like torture nobody really worries about things like that happening to them, because it mostly won't. But I think people tend to forget that these ABC agencies are made up of people. People that, like all people, are very flawed. My family tends to be of the 'I don't care - I have nothing to hide' state of mind. Referencing these events, which are really just basic consequences of human nature, sent them on a 180 fast.

[1] - http://www.businessinsider.com/edward-snowden-guardian-inter...

[2] - https://blogs.wsj.com/washwire/2013/08/23/nsa-officers-somet...

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#55
post #5

I wish this could be hammered into the thick heads of congress: there is secure, and there is insecure. There is not a gradient.

That's... just not true. And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies? I mean…

I wish I didn't agree with you but I do.

Security is a process not a state. You cant say that something is "secure", there is more secure and less secure. What the politicians are saying is that your individual security is not as important as their responsibility in security policy.

Security + Politics = Every shade of grey conceivable and then some not yet conceived.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#56

Here's my biggest complaint with this debate - people are confusing literal with metaphorical. They make the analogy of the unbreakable safe. Encryption isn't that. You can still recover the physical phone and all of the storage chips on it. That the patterns of bits in the chips make up some unrecognizable utterance is seemingly immaterial. I could write gibberish in my journal at home if I wanted to, and I think we…

His comment makes sense to 99% on non-tech people, and if it was possible it would make sense to all. Would we want to open Bin Laden's iPhone? He wants you to have your home with 100 locks, guard dogs and armed guards. BUT if a court orders you, you have to let the police in to check x, y and z. Now I don't think that a secret key can be somewhere and stay safe for a long time. It will be leaked or hacked. This plac…

But again you've made the same error. The locks can be opened and the phone retrieved. iPhones are not indestructible, you can access any part of them if you want.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#57
post #42
post #36

Earlier quoted context omitted.

The probability of that can be made arbitrarily low by proper choice of parameters for the secret sharing system, at least against realistic threats over realistic timeframes.

What are some examples of such parameters?

That's a good question. We should probably be cooperating to find out instead of asking it to silence ideological opponents. It might be useful to know for transient key secure multiparty computation.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#58
This subject always reminds me of a talk I heard Eben Moglen give, where he said:

"In 1995, there was a debate at Harvard Law School – four of us discussing the future of public key encryption and its control. I was on the side, I suppose, of freedom. It’s where I try to be. With me at that debate was a man called Daniel Weitzner who now works in the White House making Internet policy for the Obama administration.

On the other side was the then Deputy Attorney General of the United States and a lawyer in private practice named Stewart Baker who had been chief council to the National Security Agency, our listeners, and who was then in private life helping businesses to deal with the listeners. He then became, later on, the deputy for policy planning in the Department of Homeland Security in the United States and has much to do with what happened in our network after 2001.

At any rate, the four of us spent two pleasant hours debating the right to encrypt and at the end there was a little dinner party at the Harvard faculty club, and at the end, after all the food had been taken away and just the port and the walnuts were left on the table, Stuart said, “All right, among us now that we are all in private, just us girls, I’ll let our hair down.”

He didn’t have much hair even then, but he let it down.

“We are not going to prosecute your client, Mr. Zimmermann," he said. “Public key encryption will become available. We fought a long, losing battle against it, but it was just a delaying tactic.” And then he looked around the room and he said, ”But nobody cares about anonymity, do they?"

And a cold chill went up my spine and I thought, all right, Stuart, and now I know you’re going to spend the next twenty years trying to eliminate anonymity in human society and I am going to try to stop you and we’ll see how it goes.

And it’s going badly."

https://www.softwarefreedom.org/events/2012/Moglen-rePublica...

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#60

Earlier quoted context omitted.

His comment makes sense to 99% on non-tech people, and if it was possible it would make sense to all. Would we want to open Bin Laden's iPhone? He wants you to have your home with 100 locks, guard dogs and armed guards. BUT if a court orders you, you have to let the police in to check x, y and z. Now I don't think that a secret key can be somewhere and stay safe for a long time. It will be leaked or hacked. This plac…

But again you've made the same error. The locks can be opened and the phone retrieved. iPhones are not indestructible, you can access any part of them if you want.

And do what with an encrypted one? They want the contents, not the phone. Frankly, they might even return it after making a copy of it /fingerprints etc.. Spend $1m on a zero day for each case? What if they run out of zero-days?
Post reply on HN