Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

201–210 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#201

Earlier quoted context omitted.

His comment makes sense to 99% on non-tech people, and if it was possible it would make sense to all. Would we want to open Bin Laden's iPhone? He wants you to have your home with 100 locks, guard dogs and armed guards. BUT if a court orders you, you have to let the police in to check x, y and z. Now I don't think that a secret key can be somewhere and stay safe for a long time. It will be leaked or hacked. This plac…

I'm not sure why you're being downvoted. Well, actually I do know, and the answer sucks and it's frustrating. But you're right -- in an ideal world, pretty much nobody would design a future where the worst of humanity can hide behind encryption to avoid accountability. The problem is that, with the current set of technologies that we have right now, we either give the cops (effectively) the ability to get everything…

Unpopular but true comment warning:

It's kind of alarming how easily you can throw Osama Bin Ladin (a guy who killed thousands of innocent Americans), with Richard Spencer who _says_ fucked up things. Richard Spencer (just like the Westboro Baptist Church) is probably a complete douchebag nutjob. But to so casually equate saying douchey things with the murder of thousands... that's exactly what leads to Officer Friendly getting more powers over every day, innocent citizens.

Look at Russia and China. They're literally doing what you're suggesting by using thought crimes to justify massive surveillance and censorship of every forum and network to "protect society" from bad thoughts and damaging their "way of life".

The very rights that allowed the civil rights movement to exist, are the ones you guys are casually trying to destroy. Daring to have an opinion the majority finds revolting. Freedom of Speech is literally a protection of minorities from the majority. Those in power don't need protection.

[edit] 1 minute in, and yep, this is going down as I expected. Have a great day. =D

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#202

Earlier quoted context omitted.

Members of congress aren't pro "defend yourself with guns," they are pro "get votes of people who are pro defend yourself with guns."

Does that distinction matter?

It provides context to https://news.ycombinator.com/user?id=sametmax 's confusion.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#203
post #39
post #34

Earlier quoted context omitted.

Clearance rates for homicide have _dropped_ over the past 50 years: America’s homicide clearance rate—the percentage of solved crimes that lead to arrest—has fallen considerably in the past 50 years, from around 90% in 1965 to around 64% in 2012, according to federal statistics. ( https://www.economist.com/news/united-states/21656725-police... ) (See, also, https://www.citylab.com/equity/2017/06/police-arent-getting-…

Wouldn't that be a change in data collection more than in absolute quality of problem-solving? Japan, for example, I remember reading that their near-perfect homicide rate is actually because they'll classify it as "fell down some stairs" if they can't solve it. Particularly in the US with its history of social issues, I can easily see a ton of homicides in the 50s just never being written down.

I lost the link, but another newspaper article said that the clearance rate for homicides of whites dropped from, IIRC, 90% to 85%. So, yes, part of it is social issues. But in any event, it's an interesting fact that official clearance rates have moved in the opposite direction of advances in technology and ease of remote surveillance. Technology doesn't solve our social issues, and in fact can exacerbate them.

Regarding Japan, yes, their official rates are questionable. I wish I could find the journal article, but last year I was researching the supposed 100% clearance rate in Singapore and came across a very in-depth article[1] that discussed clearance rates in Singapore, Japan, and elsewhere in Asia and that left me with the impression that w'ever the actual clearance rates, they're nonetheless _much_ better than the U.S.

[1] Spoiler: the 100% clearance rate in Singapore was plausible, in no small part because it's a small city-state with very few homicides to begin with.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#204

Earlier quoted context omitted.

Members of congress aren't pro "defend yourself with guns," they are pro "get votes of people who are pro defend yourself with guns."

Does that distinction matter?

Yes. That specific difference is the classic vector to corruption, bribery and selling out.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#205

Earlier quoted context omitted.

I don't see how this is a substantive reply. Yes, once your key is known you no longer have security. That's true regardless of how many keys your scheme employs. Just like in traditional encryption scenarios, your personal key remaining secret is a part of the assumption. That there are now two secret keys doesn't alter the analysis substantially.

> Just like in traditional encryption scenarios, your personal key remaining secret is a part of the assumption. That there are now two secret keys doesn't alter the analysis substantially. Of course it does. At best it doubles the risk of key compromise, but it's really much worse than that. A master key isn't like a normal key. If you compromise Alice and Bob's key, you can spy on Alice and Bob, but not Alice and C…

Lets say I grant everything you say about the danger to every Alice and Bob that a master key exists. The question is, can policies be enacted and systems put into place that provide a commensurate amount of security for the risk the backdoor key poses? It seems plausible that it can be. But this is the conversation that needs to happen, not the boneheaded claim that its "mathematically impossible" to have a secure system with a backdoor. It's plausible that a system can be "secure" under appropriate definitions while having such a backdoor mechanism. If the analysis shows its not possible in practice, then that's fine as well. But we have to actually do the analysis.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#206

Earlier quoted context omitted.

Members of congress aren't pro "defend yourself with guns," they are pro "get votes of people who are pro defend yourself with guns."

Does that distinction matter?

It absolutely matters. If a politician is just paying lip-service to a principle, he's definitely not going to fight for it. He's just going to do what he wants to do, and try to give the appearance of caring about the issue.

The person who actually believes what he espouses will actually work for that goal.

Unfortunately, the vast majority of politicians are the former rather than the latter, hence the popular perjorative "RINO". Maybe there's a similar thing on the Democrat side, but I can't think of one right now.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#207
post #104

Earlier quoted context omitted.

Not really. If it is a foregone conclusion that the documents exist, the court can legally compel you to turn them over.

> If it is a foregone conclusion that the documents exist, the court can legally compel you to turn them over. Are you sure? That would imply that you could be compelled to produce documents that are known to exist but were stolen from you. It seems like a faulty premise. If they don't know where the documents are then how could they know they haven't been stolen or destroyed? It's the same problem with encryption ke…

> but were stolen from you.

You're forgetting that the courts are human and would be sympathetic in this case. If it couldn't be shown that you have access to the documents or you could show they were stolen then you would be fine.

> Just because you had it yesterday doesn't mean you have it today

Right, which is why I prefaced the discussion with the situations where the police can prove beyond a reasonable doubt that you posses the key/password. We can make it more direct by arresting you immediately after you prove on video that you're capable of decrypting the documents.

> can't claim you know something

Right, but the difference is we're talking about a case where they can prove you know something. We're firmly in foregone conclusion territory.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#208
post #68

Earlier quoted context omitted.

I don't really think the timeline is meaningful in this case. Having a rule where people cannot be made to decrypt files is just legalizing document shredding with an extra step. To avoid cases where people legitimately forgot their passwords just assume that the police have video evidence of you unlocking the files just before you were arrested. You know the passphrase and the police could prove it beyond reasonable…

Encryption of the file should be treated as a separate step from deletion of the plain text. The latter is destruction of evidence in the case of a crime.

This is a tough sell when hard drive manufacturers use encryption to implement a secure instantaneous delete. You can't really argue that the files were deleted the moment they were encrypted.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#209
post #53

Earlier quoted context omitted.

The other side of this is that enshrining encryption as something that police can't compel you to help with just creates a huge loophole for hiding incriminating documents. You can go to jail for destroying evidence, why would encrypting the data and refusing to provide the password or deleting the key be any different?

But can you go to jail for purposefully hiding evidence and then refusing to help find it after your arrest?

Yep!

https://en.wikipedia.org/wiki/Spoliation_of_evidence

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#210
post #68

Earlier quoted context omitted.

I don't really think the timeline is meaningful in this case. Having a rule where people cannot be made to decrypt files is just legalizing document shredding with an extra step. To avoid cases where people legitimately forgot their passwords just assume that the police have video evidence of you unlocking the files just before you were arrested. You know the passphrase and the police could prove it beyond reasonable…

> This is different than routine shredding because the moment when they become inaccessible is when you refuse, not the moment you encrypted them. If it really had anything to do with when you refuse then you could just proactively refuse as soon as you encrypt so it happens at the same time. And it would imply that if you were killed before being asked to decrypt then the government would have access to the data bec…

The refusal was specific to this situation. The data also becomes inaccessible the moment a person is incapable of producing the password like when they die.

When does encrypted data become inaccessible? When you encrypted them or when you forgot the password?

Post reply on HN