Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

141–150 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#141

Earlier quoted context omitted.

But how do you design a strong encryption algorithm that can be trivially unlocked once a warrant is provided? Answer: you can’t.

> Answer: you can’t. No, it is incredibly simple. You have a master key and the government holds this key on a secure audited system which can only be used to unlock a device once a court order is granted. The government's security for the master key will certainly be much better than the average user's password security so this will not decrease the average user's security in the least. You would also make the maste…

This is called a key escrow, which is known for not working, mainly because the assumptions ("once a court order is granted") can't be implemented technically.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#142

Earlier quoted context omitted.

But how do you design a strong encryption algorithm that can be trivially unlocked once a warrant is provided? Answer: you can’t.

> Answer: you can’t. No, it is incredibly simple. You have a master key and the government holds this key on a secure audited system which can only be used to unlock a device once a court order is granted. The government's security for the master key will certainly be much better than the average user's password security so this will not decrease the average user's security in the least. You would also make the maste…

> The government's security for the master key will certainly be much better than the average user's password security so this will not decrease the average user's security in the least.

Yes it will. A single user being careless with their password only exposes that user. Leaking the master key (and it will leak) exposes everyone. The target is much bigger, the payoff is much bigger for the bad guys, the risks are immense.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#143
post #132

Earlier quoted context omitted.

Or you write an email to your friend, saying: Hi Alice, I just did a billion coin-tosses, and the outcomes were: HTTHHTHTHHTHHTHHTHHTTTHTHTHTTTHHTHTTHT ... Regards, Bob

What's the point of such an email? If you consider police officers and judges to be that stupid, you don't even need that. You can simply say: "No, my hard drive isn't encrypted, I'm just collecting white noise." The whole point of steganography is to not raise suspiciousness in the first place.

What if you were to use the noise (encrypted data on a hard drive) as a one time pad to send obviously innocent messages to your friend, messages you could produce the plaintext for on demand? With the right setup it would appear very innocent, if a little strange.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#144
post #74

Earlier quoted context omitted.

You don't know what's in the file. Police need reasonable cause to take action. If all you have is an encrypted file, there's nothing to say it is incriminating. Encryption is necessary for a whole range of things. Would you like banks to be forced to use weak encryption when processing bank-to-bank transfers?

What they want is strong but backdoored. Nobody told them that backdoors are detected and leaked or cracked. A single set of powerful keys will be a really high value target. Alternatively the backdoor key schedule. Net time, they should ask DoD if they would use the proposed scheme. Or whether the critical economical infrastructure of the US warrants less protection than DoD documents.

> Nobody told them that backdoors are detected and leaked or cracked.

People have been telling that to politicians over and over and over and over again. They refuse to hear it.

The problem with politics is that a lot of people have this idea of how the world should work, and they think this somehow overrules how the world actually works. In the fantasy world they live in backdoors can only ever be used by the good guys.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#145
You can't legislate reality. You can't legislate physics, or the value of pi, or weather or not it's technically possible to create nuclear weapons. The fact is that strong public key encryption is possible with a few lines of code. No matter how hard they jump up and don't the universe is not going to put that genie back in the bottle because someone writes a law or an executive order.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#146

Earlier quoted context omitted.

It's not as simple as that. In the EU there are lots of political factors (like the director of the Dutch intelligence service, to name just one) that are quite vocal about abolishing strong end-to-end encryption; just as there are political factors in the US that wish to grant citizens the freedom to use strong encryption unencumbered.

Which is funny when you think they invented enigma in the first place.

The Enigma machine was invented by the Germans, not the Dutch.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#147

Earlier quoted context omitted.

Which is funny when you think they invented enigma in the first place.

The Enigma machine was invented by the Germans, not the Dutch.

Sorry, deutschemark being the german money before the euro, I still confuse them in my head.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#148

Earlier quoted context omitted.

> Answer: you can’t. No, it is incredibly simple. You have a master key and the government holds this key on a secure audited system which can only be used to unlock a device once a court order is granted. The government's security for the master key will certainly be much better than the average user's password security so this will not decrease the average user's security in the least. You would also make the maste…

This is called a key escrow, which is known for not working, mainly because the assumptions ("once a court order is granted") can't be implemented technically.

> known for not working

care to provide any evidence for that claim?

> ("once a court order is granted") can't be implemented technically

we live in the real world. if you can't trust your judiciary then your precious little algorithms aren't going to save you. (sorry to be the bearer of bad news)

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#149
post #88

Earlier quoted context omitted.

> Do we want to protect our citizens? The only answer is yes. This is not the right question. It is the one they use but is not the right one. "Do we want our citizen able to protect themselves" is the right question. And as most government have shown, they really don't want it. They want to be in charge of the protecting. Once you see things from their perspective their position makes more sense.

But it's funny that the US is so adament about being able to defend yourself with guns. But with software it's a debate. And it seems that often, the people for guns are against encryption and vice versa. From a european perspective it's so strange.

Doesn't seem odd to me, the government has bigger and more guns at their disposal and that's the situation they want with encryption too.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#150

This subject always reminds me of a talk I heard Eben Moglen give, where he said: "In 1995, there was a debate at Harvard Law School – four of us discussing the future of public key encryption and its control. I was on the side, I suppose, of freedom. It’s where I try to be. With me at that debate was a man called Daniel Weitzner who now works in the White House making Internet policy for the Obama administration. On…

It's odd because peoples desire for anonymity is preventing their use of good encryption. A solid online identity and reliable way to get data to you without 3rd parties would be a good foundation for exchanging keys and encrypting data between parties. I'm talking fixed IP addresses as a starting point. We have whole infrastructure to make it easy to interact with public web sites (DNS, etc) but it's very hard to find and send a packet to your friend. Any efforts to change this would be seen by a lot of people as an attack on anonymity.

I don't want make believe anonymity, I want to know where data is going and where it's coming from. Once I have that I can encrypt for privacy and web sites can strip identifying information if they want to provide an anonymous forum.

Post reply on HN