Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

101–110 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#101
post #16

Earlier quoted context omitted.

That's... just not true. And that kind of misrepresentation just weakens the arguments for strong encryption, because intelligent people will see them as pretty transparent misrepresentations. Have you considered that's why the arguments for strong encryption aren't going well -- that we're not actually engaging with intelligent people trying to understand the issue, we're chanting trite, shallow inaccuracies? I mean…

I didn't downvote you, but ultimately either someone else can get in or they can't, the fact that keys have varying sizes is tangential to this issue since the size chosen only needs to be one that is sufficient. The fact that I don't know what that value is doesn't change the fact that the outcomes are binary (secure|insecure).

Your initial assumption seems to be wrong.

In cryptography there is one information theoretical secure scheme: The one time pad. But even that relies on circumstances to keep it secure. Without limitations you can not say no one can break it, because obtaining the key material might still be possible.

That leaves us with most other schemes. They are computationally secure. This implies that the security of the system depends on the computational power of the attacker. So a system can only be secure for a class of attackers and to a certain extent.

If you apply a binary clssification of secure insecure as you proposed it someone can get in", most systems today, if not all, are insecure.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#102
post #44

When I was in college, there was a retired guy that would come in to tutor students as a way to stay busy. He was your stereotypical brainiac type dude - quiet, lanky, glasses, soft spoken, and razor sharp. He must have been in his 50s, but you would think he had just completed upper division math, chemistry, and physics "last semester" with perfect grades to boot. He told me a story about how once while in his Maste…

And then Chinese figure it out for a third of the price and have a monopoly on nuclear reactors.

Remember the time when organisations like DARPA actually promoted public research of this magnitude? Or when DoD was making certain research public?

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#103
post #65

The argument here is extremely simple. Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone. Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack. So the only question that needs to be answered is this. Do we want to protect our…

It’s interesting because these arguments are identical to those that could support the Second Amendment for exactly the same reasons.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#104
post #68

Earlier quoted context omitted.

I don't really think the timeline is meaningful in this case. Having a rule where people cannot be made to decrypt files is just legalizing document shredding with an extra step. To avoid cases where people legitimately forgot their passwords just assume that the police have video evidence of you unlocking the files just before you were arrested. You know the passphrase and the police could prove it beyond reasonable…

"If they were instead physical documents buried somewhere hidden where the police could not possibly find them without your help the court still has the ability to hold you in contempt if you don't produce them" Are you sure this is so, this sounds awfully similar to compelling you to testify against yourself. Perhaps you are confused.

Not really. If it is a foregone conclusion that the documents exist, the court can legally compel you to turn them over.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#105
Governments are the next on the Silicon Valley ‘disrupt’ list.

The music industry had to be dragged kicking and screaming away from their physical distribution model.

Governments will have to be dragged similarly until they accept encrypted content is something they have the same right of access to as private thoughts.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#106
post #4

What did the police do before there was the internet or phones?

In my nation, and as I hear in many other places, the police force was much more decentralized in the past. You had local police handling problems at the local level using local knowledge. As I hear/read it was a bit more costly, had the occasional problem of local corruption, quality had a bit more variance, organized crime was a bigger problem, but the average crime had better results and was done quicker. There was also no mass surveillance.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#107
post #74

Earlier quoted context omitted.

You don't know what's in the file. Police need reasonable cause to take action. If all you have is an encrypted file, there's nothing to say it is incriminating. Encryption is necessary for a whole range of things. Would you like banks to be forced to use weak encryption when processing bank-to-bank transfers?

What they want is strong but backdoored. Nobody told them that backdoors are detected and leaked or cracked. A single set of powerful keys will be a really high value target. Alternatively the backdoor key schedule. Net time, they should ask DoD if they would use the proposed scheme. Or whether the critical economical infrastructure of the US warrants less protection than DoD documents.

> Nobody told them that backdoors are detected and leaked or cracked

Many experts have told them. They have told them that 'backdoored' is contradictory to 'strong.

The impression I get - being as far away from this debate as any other non-US citizen - is this request for "strong but accessible" "encryption" is repeated by administration and echoed by media consistently. Eventually, every citizen with the limited understanding and memory that we have to spare will be asking 'why aren't our scientists giving law enforcement what they need?', instead of what does that actually mean. In a way I find myself very fortunate to be on the side of the pond where these voices still exist, but reason temporarily prevails.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#108
post #65

The argument here is extremely simple. Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone. Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack. So the only question that needs to be answered is this. Do we want to protect our…

But how do you design a strong encryption algorithm that can be trivially unlocked once a warrant is provided? Answer: you can’t.

my first though as to how you would do this, is that you would implement some kind of key bag. You don't ever own your own private keys, theres a copy of them held in a central repository. they are all centrally stored and can be requested by a warrant.

The problem with this of course is that its a truly horrible idea which defeats the whole concept of a private key. Another massive problem here is that you've just created the biggest target for hackers. once the keys are out... everyone is screwed.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#109

Earlier quoted context omitted.

To defend this user's point, I think could be a case made for a key escrow that requires an unlock from different organizations. RSA solved this years ago. We could establish a key escrow that adds a key to your personal key. This extra key would allow unsealing in cases where it would be needed within the law. The extra key could be set up so that it requires X out of Y keys. Each key could be owned by different org…

We can also require that the hardware issuer (eg, Apple) stores an encrypted copy of the key (throwing away the key used to encrypt the original key), such that it costs $1M (or other amount) to break the encryption and reveal the key. There's no reason it shouldn't require expense and physical breaking to gain entry, just because it's digital (and I think that this scheme gains legal protection because of such featu…

This might be unpopular (and is certainly counter to the government's desires), but I am absolutely against breakable encryption of any sort. I am absolutely fine with criminals being able to use strong encryption to make data impossible to ever be read by the government.

The bit I take issue with here is that breakable encryption is absolutely necessary for law enforcement to do its job. No. It makes it _easier_ for them to do their job, at the expense of everyone else's security. There are usually other ways to get a conviction other than being able to decrypt a criminal's data. And if in some instances there isn't, I'm ok with that. I value freedom and privacy higher.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#110
post #34
post #17

Earlier quoted context omitted.

I'm no supporter of insecure cryptography, but before there was internet or phones and access to such, lots of crimes went unsolved.

Clearance rates for homicide have _dropped_ over the past 50 years: America’s homicide clearance rate—the percentage of solved crimes that lead to arrest—has fallen considerably in the past 50 years, from around 90% in 1965 to around 64% in 2012, according to federal statistics. ( https://www.economist.com/news/united-states/21656725-police... ) (See, also, https://www.citylab.com/equity/2017/06/police-arent-getting-…

Given that we're now learning that many of the convictions won last century were based on bad evidence and corrupt behavior, I don't really put much stock into those figures.
Post reply on HN