Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

131–140 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#131
post #65

The argument here is extremely simple. Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone. Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack. So the only question that needs to be answered is this. Do we want to protect our…

> Even if strong encryption were made illegal, criminals will be the ones securing their data despite the law. Well, anybody can hide their use of encryption by using steganography, [1]. E.g. you just piggy-back your secret file as noise on top of a legitimate file. [1] https://en.wikipedia.org/wiki/Steganography

Or you write an email to your friend, saying:

    Hi Alice, I just did a billion coin-tosses, and the outcomes were:

    HTTHHTHTHHTHHTHHTHHTTTHTHTHTTTHHTHTTHT ...

    Regards, Bob

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#132

Earlier quoted context omitted.

> Even if strong encryption were made illegal, criminals will be the ones securing their data despite the law. Well, anybody can hide their use of encryption by using steganography, [1]. E.g. you just piggy-back your secret file as noise on top of a legitimate file. [1] https://en.wikipedia.org/wiki/Steganography

Or you write an email to your friend, saying: Hi Alice, I just did a billion coin-tosses, and the outcomes were: HTTHHTHTHHTHHTHHTHHTTTHTHTHTTTHHTHTTHT ... Regards, Bob

What's the point of such an email?

If you consider police officers and judges to be that stupid, you don't even need that. You can simply say: "No, my hard drive isn't encrypted, I'm just collecting white noise."

The whole point of steganography is to not raise suspiciousness in the first place.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#133
post #24

The government has demonstrated that they will abuse every power given to them, and even those that weren't. I would not entrust every aspect of my personal information to the very same organizations that indefinitely detains people, including American citizens, without access to a lawyer while commiting acts of torture; and the ones that said the Patriot Act could never be used for domestic surveilance; that lied ab…

> The government has demonstrated that they will abuse every power given to them, and even those that weren't

I think this mixes up what is true and what people (myself included) wish was true.

Governments don’t have power given to them. Their default state is God-Kings ruling on personal whims.

Governments have power taken from them, either by corporations, or by religions, or by other governments — sometimes these groups even call themselves “the people” — but the restrictions are not stable equilibriums, they are constantly fought against on all sides.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#134

Earlier quoted context omitted.

To defend this user's point, I think could be a case made for a key escrow that requires an unlock from different organizations. RSA solved this years ago. We could establish a key escrow that adds a key to your personal key. This extra key would allow unsealing in cases where it would be needed within the law. The extra key could be set up so that it requires X out of Y keys. Each key could be owned by different org…

I as a private citizen do not want the government to have access to my files. Period. End of story. They have zero right to have access to every aspect of my life. Any "solution" that involves any government the ability to access encrypted files is not encryption, but a lie.

And that's where I have to disagree.

"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized." 4th Amendment, Bill of Rights, US Constitution

That's a balance, of between "Get off my lawn", and "I affirm I saw X illegal thing and I swear it in front of a judge, and the judge agreed."

Now, I don't trust some bureaucratic department to honor the constitution. And from the sounds of it, neither do you. Which is why I was keeping in mind of having an antagonist based key-holding scheme which would require a multitude of people to unlock before the data would be unsealed. To me, that does re-enable the balance set forth in the Constitution, namely the 4th Amendment to the Bill of Rights.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#135
post #88
post #65

The argument here is extremely simple. Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone. Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack. So the only question that needs to be answered is this. Do we want to protect our…

> Do we want to protect our citizens? The only answer is yes. This is not the right question. It is the one they use but is not the right one. "Do we want our citizen able to protect themselves" is the right question. And as most government have shown, they really don't want it. They want to be in charge of the protecting. Once you see things from their perspective their position makes more sense.

But it's funny that the US is so adament about being able to defend yourself with guns. But with software it's a debate. And it seems that often, the people for guns are against encryption and vice versa.

From a european perspective it's so strange.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#136

Earlier quoted context omitted.

But how do you design a strong encryption algorithm that can be trivially unlocked once a warrant is provided? Answer: you can’t.

> Answer: you can’t. No, it is incredibly simple. You have a master key and the government holds this key on a secure audited system which can only be used to unlock a device once a court order is granted. The government's security for the master key will certainly be much better than the average user's password security so this will not decrease the average user's security in the least. You would also make the maste…

If you want all the investigators to be able to open things with the master keys without compromising it, it's not simple at all.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#138

Gotta love the fact that the EU seems to think the exact opposite https://www.theguardian.com/technology/2017/jun/19/eu-outlaw...

It's not as simple as that. In the EU there are lots of political factors (like the director of the Dutch intelligence service, to name just one) that are quite vocal about abolishing strong end-to-end encryption; just as there are political factors in the US that wish to grant citizens the freedom to use strong encryption unencumbered.

Which is funny when you think they invented enigma in the first place.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#139
post #65

The argument here is extremely simple. Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone. Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack. So the only question that needs to be answered is this. Do we want to protect our…

> Encryption is the only way to secure information. I am not sure that this argument is simple at all. Encryption only provides theoretical security. In practice even if strong encryption can't be broken it can almost always be bypassed rather trivially if data is being accessed on a regular basis. If data is encrypted and left cold then that can be difficult or impossible to retrieve if a secure key is used and that…

This ignores transport encryption, which is the bulk of what protects you on a daily basis from street criminals.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#140
post #68

Earlier quoted context omitted.

I don't really think the timeline is meaningful in this case. Having a rule where people cannot be made to decrypt files is just legalizing document shredding with an extra step. To avoid cases where people legitimately forgot their passwords just assume that the police have video evidence of you unlocking the files just before you were arrested. You know the passphrase and the police could prove it beyond reasonable…

Encryption of the file should be treated as a separate step from deletion of the plain text. The latter is destruction of evidence in the case of a crime.

Are you arguing you should legally have to keep a plain text copy of anything you encrypt? I mean I get your train of thought but that seems to be the conclusion
Post reply on HN