Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

181–190 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#181
post #39
post #34

Earlier quoted context omitted.

Clearance rates for homicide have _dropped_ over the past 50 years: America’s homicide clearance rate—the percentage of solved crimes that lead to arrest—has fallen considerably in the past 50 years, from around 90% in 1965 to around 64% in 2012, according to federal statistics. ( https://www.economist.com/news/united-states/21656725-police... ) (See, also, https://www.citylab.com/equity/2017/06/police-arent-getting-…

Wouldn't that be a change in data collection more than in absolute quality of problem-solving? Japan, for example, I remember reading that their near-perfect homicide rate is actually because they'll classify it as "fell down some stairs" if they can't solve it. Particularly in the US with its history of social issues, I can easily see a ton of homicides in the 50s just never being written down.

A good example of this is sexual assault cases on campus. A lot of times they try to handle them without getting the real police involved, or attempt to downplay everything about it to keep the statistics pointed one way.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#182
post #171

Earlier quoted context omitted.

But it's funny that the US is so adament about being able to defend yourself with guns. But with software it's a debate. And it seems that often, the people for guns are against encryption and vice versa. From a european perspective it's so strange.

The metaphorical person on the street can wrap their head around why having a gun in a person's hand gives that person power. Everyone basically knows that the gun control debate is a debate about who has and is allowed to have power. I'm not sure the metaphorical person on the street even knows encryption exists; if they do, it's only very vague and probably an entirely incorrect understanding of it. As for people w…

> Humans have an all-but-instinctual understanding of physical weapons, encryption is basically magic by comparison.

Fair point. Although that still does feel weird to look at the us from Europe where guns nor anti-encryptions are popular.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#183
post #88

Earlier quoted context omitted.

> Do we want to protect our citizens? The only answer is yes. This is not the right question. It is the one they use but is not the right one. "Do we want our citizen able to protect themselves" is the right question. And as most government have shown, they really don't want it. They want to be in charge of the protecting. Once you see things from their perspective their position makes more sense.

But it's funny that the US is so adament about being able to defend yourself with guns. But with software it's a debate. And it seems that often, the people for guns are against encryption and vice versa. From a european perspective it's so strange.

Members of congress aren't pro "defend yourself with guns," they are pro "get votes of people who are pro defend yourself with guns."

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#184
post #51

I can’t overstate how important it is for Google, Apple, and Microsoft to keep hammering at this. It’s workkng. The DOJ is running into this a lot now (e.g. can’t get into a drug dealer’s iPhone to see who he’s messaging). Eventually, they’ll see that the ship has sailed and encryption is just something they have to deal with.

That's an incredibly optimistic take on this problem. Google, Microsoft, EFF, et al need to win every single battle or they lose the whole war.

The DOJ just needs to find one sympathetic test case, or one sufficiently horrible incident to get the laws changed. Like the Patriot Act in the US, or the new French surveillance law that passed after the Bataclan attacks.

It's the classic asymmetry problem that makes security so hard in general. Only now, the party with all the money and power and time is also the one who only needs to win once.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#185
I understand law enforcement's frustration. However, this is quite simple.

Encryption relies on keys. Either the government has everyone's keys, or they don't.

Any stockpile of encryption keys would give access to millions of people's and businesses' data. It would be a hacking target of inestimable value, targeted by criminal organizations and foreign governments using every technique imaginable.

It would be stolen. Period. And every citizen and business would suffer disastrous consequences.

We can't say this enough in this debate: making everyone's keys accessible to one entity means they absolutely will be stolen. Whether we trust a government entity's motives isn't even relevant. They do not and cannot have perfect security, and that should end the debate.

If anyone doubts that the keys would be stolen, please see:

- https://en.wikipedia.org/wiki/Office_of_Personnel_Management... - https://motherboard.vice.com/en_us/article/qkjkxv/fbi-flash-...

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#186
post #130

Earlier quoted context omitted.

>It isn't that there are no levels of security, it's that you can't be at two separate levels at the same time. There is no overlap. What do you say to DUAL_EC_DRBG, which seems to be precisely that "separate levels" of security you claim is impossible?

DUAL_EC_DRBG is, in principle, equivalent to encrypting the same data with two separate keys, each one being able to recover the plaintext. There are no "two separate levels at the same time" here: the weakest of these two keys determines your security level. With DUAL_EC_DRBG, one of these keys is a static key which, once leaked, can break every message with a small amount of extra effort. The same applies to the re…

I don't see how this is a substantive reply. Yes, once your key is known you no longer have security. That's true regardless of how many keys your scheme employs.

Just like in traditional encryption scenarios, your personal key remaining secret is a part of the assumption. That there are now two secret keys doesn't alter the analysis substantially.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#187
post #151

Earlier quoted context omitted.

>Oh, and the "it's technologically impossible" argumentbe the only one you need -- but they refuse to hear that. Things like DUAL_EC_DRBG seem to prove this claim false.

I guess if you set the bar for what you want to accomplish at barely above "nobody is allowed to encrypt anything, ever." Nobody would knowingly use such a scheme. It's also a security hole giving access to anyone with the key, which is sure to be leaked/compromised if shared with the entire DOJ and others. Also, once the key is compromised, everything in the past that was ever encrypted is now readable by anyone.

>Nobody would knowingly use such a scheme.

Actually, most people would use it because most people just don't care that much.

>which is sure to be leaked/compromised if shared with the entire DOJ and others

But this is a policy issue, not an issue with the idea of backdoored encryption. There are policies that could reduce the probability of leak to negligible levels (e.g. a secure NSA facility does all the decryption). Not to mention that only the NSA will be in a position to decrypt your communications from 5 years ago. No one else is storing such a vast quantity of data.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#188

I understand law enforcement's frustration. However, this is quite simple. Encryption relies on keys. Either the government has everyone's keys, or they don't. Any stockpile of encryption keys would give access to millions of people's and businesses' data. It would be a hacking target of inestimable value , targeted by criminal organizations and foreign governments using every technique imaginable. It would be stolen…

> It would be a hacking target of inestimable value, targeted by criminal organizations and foreign governments using every technique imaginable. It would be stolen. Period.

And we really don't have to look any further than the Equinox hack to prove this. If they think that was bad, and it's clear that nearly all of them do, then imagine it was more than just identity data... what if it was all your actual data. If politicians know that all of their email, their internet history and all of their other secrets will get out if this happens, I wonder if they'll change their minds.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#190
post #4

What did the police do before there was the internet or phones?

They would open letters, tap phones and watch bank accounts. All of those things can be subverted now. That said, they were just lucky back then... it doesn't mean everyone should suddenly give up their right to privacy now.
Post reply on HN