Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

171–180 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#171
post #88

Earlier quoted context omitted.

> Do we want to protect our citizens? The only answer is yes. This is not the right question. It is the one they use but is not the right one. "Do we want our citizen able to protect themselves" is the right question. And as most government have shown, they really don't want it. They want to be in charge of the protecting. Once you see things from their perspective their position makes more sense.

But it's funny that the US is so adament about being able to defend yourself with guns. But with software it's a debate. And it seems that often, the people for guns are against encryption and vice versa. From a european perspective it's so strange.

The metaphorical person on the street can wrap their head around why having a gun in a person's hand gives that person power. Everyone basically knows that the gun control debate is a debate about who has and is allowed to have power.

I'm not sure the metaphorical person on the street even knows encryption exists; if they do, it's only very vague and probably an entirely incorrect understanding of it.

As for people who are for one and not the other, even though I'm personally in favor of both the second amendment and encryption in the hands of people, it's not hard to see a meaningful difference between them that would make it reasonable to have differing opinions. Guns in the hands of the populace is a positive power to do harm, encryption in the hands of the populace is strictly defensive. Criminals can use encryption to defend things we'd rather not have defended, but that is fundamentally a different concern that criminals using guns to attack things we'd rather not have attacked.

I think the only weird case would be being in favor of gun rights but thinking the government should have back door access to encryption, on the part of someone who deeply understands both. That is to say, I'm sure you can find people who believe both those things, but I suspect the latter is mostly an un-thought-out instinctive reaction to generally trust authority figures who seem generally trustworthy to them combined with a lot of ignorance about what encryption is and how it works. Humans have an all-but-instinctual understanding of physical weapons, encryption is basically magic by comparison.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#172
If angels were to govern men, neither external nor internal controls on government would be necessary. In framing a government which is to be administered by men over men, the great difficulty lies in this: you must first enable the government to control the governed; and in the next place oblige it to control itself.

-- James Madison

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#173

Earlier quoted context omitted.

> The government's security for the master key will certainly be much better than the average user's password security so this will not decrease the average user's security in the least. Yes it will. A single user being careless with their password only exposes that user. Leaking the master key (and it will leak) exposes everyone. The target is much bigger, the payoff is much bigger for the bad guys, the risks are im…

> Leaking the master key (and it will leak) exposes everyone I agree that it should be assumed that the key will leak but there are plenty of ways to practically mitigate the usefulness of a leaked key. I mentioned expiring keys already, which is obvious, but there are more sophisticated protocols that can be put in place. > The target is much bigger, the payoff is much bigger for the bad guys I don't think this is t…

> If you trust the government to secure a massive stockpile of NBC weapons [etc]

Physical security and digital security are very different. Someone stealing a bomb is still only one bomb. Securing that bomb involves fortifying a well-defined local border. Attacking it requires personal risk that is hard to parallelize.

Digital networks can be attacked at any time from any number of opponents. These attacks are usually automated without the risk of being found by a guard with a machine gun. Stealing the escrow key database isn't merely a single bad event; it would allow access - possibly retroactively - everything supposedly protected by those key, which is presumably "everything".

> key

You seem to be using "key" to mean several different concepts.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#174

Earlier quoted context omitted.

This is called a key escrow, which is known for not working, mainly because the assumptions ("once a court order is granted") can't be implemented technically.

> known for not working care to provide any evidence for that claim? > ("once a court order is granted") can't be implemented technically we live in the real world. if you can't trust your judiciary then your precious little algorithms aren't going to save you. (sorry to be the bearer of bad news)

[deleted]

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#175
post #65

The argument here is extremely simple. Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone. Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack. So the only question that needs to be answered is this. Do we want to protect our…

But how do you design a strong encryption algorithm that can be trivially unlocked once a warrant is provided? Answer: you can’t.

Dual-key encryption. You just have to trust the government not to lose their key.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#176

Earlier quoted context omitted.

I as a private citizen do not want the government to have access to my files. Period. End of story. They have zero right to have access to every aspect of my life. Any "solution" that involves any government the ability to access encrypted files is not encryption, but a lie.

And that's where I have to disagree. "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized." 4th Amendment, Bill of Rights, US Constitution T…

I personally consider parts of the contents of my computer to actually be an extension of my mind. A daily diary for instance. Once we get to the point where we have computer chips embedded in our skull, this will be literally true.

What should be considered part of one's mind is not clear, but what is clear is that whatever the mind is, no one should be able to pry without consent.

Not commenting on what the constitution actually means, just saying what I think it should mean.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#178
post #65

The argument here is extremely simple. Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone. Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack. So the only question that needs to be answered is this. Do we want to protect our…

> Encryption is the only way to secure information. I am not sure that this argument is simple at all. Encryption only provides theoretical security. In practice even if strong encryption can't be broken it can almost always be bypassed rather trivially if data is being accessed on a regular basis. If data is encrypted and left cold then that can be difficult or impossible to retrieve if a secure key is used and that…

[deleted]

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#179

Earlier quoted context omitted.

The "government master key" idea is silly (for a number of reasons). Yet, it's very possible to share a copy of every user key using methods like Shamir's secret sharing - therefore requiring P out of N entities agreeing on allowing the decryption to happen. The secrets can be shared in advance with attorneys, civil rights groups, government entities and allows a democratic-ish process around decryption.

> The "government master key" idea is silly (for a number of reasons). all of the security experts advising law enforcement, intelligence agencies, and politicians seem to think it is pretty reasonable. care to share any of your reasons for disagreeing with them?

[deleted]

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#180

The wording of this brings up a worrisome point. What encryption methods does the DOJ currently have access to? Why are they complaining about needing access to this encryption now? Is it because other previous encryption methods are know to be broken or they already have access to that data?

Probably because so many communications are moving to encrypted by default, HTTPS everywhere and WhatsApp for instance (as Brazil has found out). If the big players decide to switch to E2E then governments would need to get them to change their products. Better to head them off before it is too late.

This is exactly it. The Going Dark Problem: https://www.fbi.gov/services/operational-technology/going-da...
Post reply on HN