Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

61–70 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#61
post #53

Here's my biggest complaint with this debate - people are confusing literal with metaphorical. They make the analogy of the unbreakable safe. Encryption isn't that. You can still recover the physical phone and all of the storage chips on it. That the patterns of bits in the chips make up some unrecognizable utterance is seemingly immaterial. I could write gibberish in my journal at home if I wanted to, and I think we…

The other side of this is that enshrining encryption as something that police can't compel you to help with just creates a huge loophole for hiding incriminating documents. You can go to jail for destroying evidence, why would encrypting the data and refusing to provide the password or deleting the key be any different?

> You can go to jail for destroying evidence, why would encrypting the data and refusing to provide the password or deleting the key be any different?

Specifically encrypting incriminating data after you have evidence of a crime in an effort to cover it up should be treated as the equivalent of shredding documents. (Assuming, of course, they can prove it, just as they have to prove that you had the documents in question prior to destroying them in order to prosecute you for destroying evidence.)

That's not in any way the same thing as having your data encrypted and refusing to decrypt it.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#62

Earlier quoted context omitted.

But again you've made the same error. The locks can be opened and the phone retrieved. iPhones are not indestructible, you can access any part of them if you want.

And do what with an encrypted one? They want the contents, not the phone. Frankly, they might even return it after making a copy of it /fingerprints etc.. Spend $1m on a zero day for each case? What if they run out of zero-days?

Marvel at the encrypted data that they have full access to, and feel free to attempt to brute-force decrypt it, just like any other hostile attacker. The job of the encryption system is to prevent unauthorized access, from the perspective of the owner of the data. If it fails to do that job, it's broken and should be replaced by a system that isn't.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#64
post #53

Here's my biggest complaint with this debate - people are confusing literal with metaphorical. They make the analogy of the unbreakable safe. Encryption isn't that. You can still recover the physical phone and all of the storage chips on it. That the patterns of bits in the chips make up some unrecognizable utterance is seemingly immaterial. I could write gibberish in my journal at home if I wanted to, and I think we…

The other side of this is that enshrining encryption as something that police can't compel you to help with just creates a huge loophole for hiding incriminating documents. You can go to jail for destroying evidence, why would encrypting the data and refusing to provide the password or deleting the key be any different?

[deleted]

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#65
The argument here is extremely simple.

Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone.

Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack.

So the only question that needs to be answered is this. Do we want to protect our citizens? The only answer is yes. The only solution is encryption.

The problem with strong encryption is that it already exists. Even if strong encryption were made illegal, criminals will be the one's securing their data despite the law. To deny citizens the right to protect themselves is just putting them all at risk. It's disarmament.

Under the law, all the police should need is a warrant. It's not even an exception to any rule.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#66

Here's my biggest complaint with this debate - people are confusing literal with metaphorical. They make the analogy of the unbreakable safe. Encryption isn't that. You can still recover the physical phone and all of the storage chips on it. That the patterns of bits in the chips make up some unrecognizable utterance is seemingly immaterial. I could write gibberish in my journal at home if I wanted to, and I think we…

But it does make sense as an analogy? In this case the contents of the safe correspond to the plaintext, the key that opens the safe is the private key, and having the safe without the key is like having the ciphertext without the private key

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#67
post #13

Earlier quoted context omitted.

I had another comment, but in response to your Ed: comment: key size is not a measure of security. It is a measure of how /long/ we intend the key to be secure. More explicitly: Key size does not exist of the gradient of protocol security. We know how long a key takes to break given current technology and algorithms. We choose a key size to render the time to break infeasible against our prediction of state of the ar…

Sincere question: how do you define "how secure it is" except "how long it will remain secure (under attack)"? Edit: You're also completely eliding that security is probabilistic -- they might just guess our key on the first try. We can only discuss it as the expected amount of computation to figure out our key on average. That expected amount has a gradient along keysize.

He meant "how long before technology advances, due to Moore's Law or whatever, to the point where it's really cheap to brute force the key space". Not "how long it takes from the moment you attack it to the moment you break it"

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#68
post #53

Earlier quoted context omitted.

The other side of this is that enshrining encryption as something that police can't compel you to help with just creates a huge loophole for hiding incriminating documents. You can go to jail for destroying evidence, why would encrypting the data and refusing to provide the password or deleting the key be any different?

> You can go to jail for destroying evidence, why would encrypting the data and refusing to provide the password or deleting the key be any different? Specifically encrypting incriminating data after you have evidence of a crime in an effort to cover it up should be treated as the equivalent of shredding documents. (Assuming, of course, they can prove it, just as they have to prove that you had the documents in quest…

I don't really think the timeline is meaningful in this case. Having a rule where people cannot be made to decrypt files is just legalizing document shredding with an extra step.

To avoid cases where people legitimately forgot their passwords just assume that the police have video evidence of you unlocking the files just before you were arrested. You know the passphrase and the police could prove it beyond reasonable doubt in court.

You just start with your files encrypted with a strong passphrase and refuse to provide it when you get caught. This is different than routine shredding because the moment when they become inaccessible is when you refuse, not the moment you encrypted them.

If they were instead physical documents buried somewhere hidden where the police could not possibly find them without your help the court still has the ability to hold you in contempt if you don't produce them. What makes the secret knowledge of their location any different than the secret knowledge of the password?

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#70
post #68

Earlier quoted context omitted.

> You can go to jail for destroying evidence, why would encrypting the data and refusing to provide the password or deleting the key be any different? Specifically encrypting incriminating data after you have evidence of a crime in an effort to cover it up should be treated as the equivalent of shredding documents. (Assuming, of course, they can prove it, just as they have to prove that you had the documents in quest…

I don't really think the timeline is meaningful in this case. Having a rule where people cannot be made to decrypt files is just legalizing document shredding with an extra step. To avoid cases where people legitimately forgot their passwords just assume that the police have video evidence of you unlocking the files just before you were arrested. You know the passphrase and the police could prove it beyond reasonable…

Encryption of the file should be treated as a separate step from deletion of the plain text. The latter is destruction of evidence in the case of a crime.
Post reply on HN