Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

211–220 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#211

Earlier quoted context omitted.

This ignores transport encryption, which is the bulk of what protects you on a daily basis from street criminals.

Interesting example. Transport encryption provides basically no real world security at all. The fact of the matter is that there are hundreds of millions of credit cards with full PII available for sale so it is almost certain that whatever PII you are sending over your highly secure connection is already in the hands of criminals. The only security you have is the fact that there aren't nearly enough criminals to ex…

For random criminals, you are right, ROI is low. But Data in Transit protection is essential to prevent targeted attacks, whether it is attempt at data interception or whacking your device with an exploit to steal information off it (continuously if desired).

It may not be in everyone’s threat model, but it is definitely very important and provides real world security.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#212
post #101
post #16

Earlier quoted context omitted.

I didn't downvote you, but ultimately either someone else can get in or they can't, the fact that keys have varying sizes is tangential to this issue since the size chosen only needs to be one that is sufficient. The fact that I don't know what that value is doesn't change the fact that the outcomes are binary (secure|insecure).

Your initial assumption seems to be wrong. In cryptography there is one information theoretical secure scheme: The one time pad. But even that relies on circumstances to keep it secure. Without limitations you can not say no one can break it, because obtaining the key material might still be possible. That leaves us with most other schemes. They are computationally secure. This implies that the security of the system…

>most systems today, if not all, are insecure

I'd say that's a fair assessment.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#213

I understand law enforcement's frustration. However, this is quite simple. Encryption relies on keys. Either the government has everyone's keys, or they don't. Any stockpile of encryption keys would give access to millions of people's and businesses' data. It would be a hacking target of inestimable value , targeted by criminal organizations and foreign governments using every technique imaginable. It would be stolen…

> It would be a hacking target of inestimable value, targeted by criminal organizations and foreign governments using every technique imaginable. It would be stolen. Period. And we really don't have to look any further than the Equinox hack to prove this. If they think that was bad, and it's clear that nearly all of them do, then imagine it was more than just identity data... what if it was all your actual data. If p…

Oh - politicians won't have their data subject to the backdoors, only the rest of us.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#214

Earlier quoted context omitted.

Encryption of the file should be treated as a separate step from deletion of the plain text. The latter is destruction of evidence in the case of a crime.

Are you arguing you should legally have to keep a plain text copy of anything you encrypt? I mean I get your train of thought but that seems to be the conclusion

No, only that destruction of evidence could pertain to deleting the plaintext of crime-related documents.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#215

Earlier quoted context omitted.

I'm not sure why you're being downvoted. Well, actually I do know, and the answer sucks and it's frustrating. But you're right -- in an ideal world, pretty much nobody would design a future where the worst of humanity can hide behind encryption to avoid accountability. The problem is that, with the current set of technologies that we have right now, we either give the cops (effectively) the ability to get everything…

Unpopular but true comment warning: It's kind of alarming how easily you can throw Osama Bin Ladin (a guy who killed thousands of innocent Americans), with Richard Spencer who _says_ fucked up things. Richard Spencer (just like the Westboro Baptist Church) is probably a complete douchebag nutjob. But to so casually equate saying douchey things with the murder of thousands... that's exactly what leads to Officer Frien…

You're right - I picked Spencer because he's an easy target, especially on a board that generally leans to the Left. If there's some incident of racial violence that somehow traces back to him, I doubt the typical HN reader would object to the FBI getting a warrant to search his house or his car.

And I suspect that most here wouldn't mind them getting a warrant for his phone under the same circumstances, if they can just bring themselves to admit it.

> The very rights that allowed the civil rights movement to exist

I think I see what you're saying here, but encryption wasn't really around in MLK's day.

> are the ones you guys are casually trying to destroy.

Whoa there, please don't lump me in with the authoritarians, especially the new Leftist flavor that's so popular lately.

The case that I'm trying to make in this thread is that we've got to find a better balance that protects minority voices (like MLK, or Ben Shapiro, or Milo Yanawhatshisname or whoever Berkeley is rioting about this week) in a cryptographically strong way, while still allowing for some sort of accountability in extreme cases.

If we fail at this - or worse, if we can't be bothered to try - then I'm afraid we're going to wind up stuck with something crappy like key escrow, and then the thought police are really going to have a field day.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#216
post #168

Earlier quoted context omitted.

> Answer: you can’t. No, it is incredibly simple. You have a master key and the government holds this key on a secure audited system which can only be used to unlock a device once a court order is granted. The government's security for the master key will certainly be much better than the average user's password security so this will not decrease the average user's security in the least. You would also make the maste…

> You would also make the master keys expire regularly (maybe daily) so as long as a user updates their phone they will get updated with the new keys to protect against a leaked key. What would the logistics of this be? Would the government need to store all master keys to be able to decrypt an old message? How would you know you're using the right key to decrypt a message? What happens if all the old keys leak? What…

We are talking about different things. I was talking about allowing access to encrypted data on devices which is the main issue that le has been complaining about. You seem to be talking about a backdoor for all crypto everywhere which is very different.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#217
post #88

Earlier quoted context omitted.

> Do we want to protect our citizens? The only answer is yes. This is not the right question. It is the one they use but is not the right one. "Do we want our citizen able to protect themselves" is the right question. And as most government have shown, they really don't want it. They want to be in charge of the protecting. Once you see things from their perspective their position makes more sense.

But it's funny that the US is so adament about being able to defend yourself with guns. But with software it's a debate. And it seems that often, the people for guns are against encryption and vice versa. From a european perspective it's so strange.

Obligatory XKCD: https://www.xkcd.com/504/

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#218

Earlier quoted context omitted.

To be honest, I'm against the "moneyball" solution. Hardware's going to only get: cheaper, faster, better. That $1m price will inexorably come down to the point that skiddie could do it on their phone with AWS. I still stand by the point of having a consortium of opposing interests as a combined group (or supermajority) to override an encryption. I think of it as a strong version of checks and balances. In that case,…

Let's work through your $1M example. Assume Moore's Law continues for the foreseeable future, so the price of all computation halves every 18 months (ie, every 1.5 years). Then in 15 years, that $1M computation still costs $1000. In 30 years, it can be done for one dollar. Is that good or bad? I guess it depends on your threat model and what the data is worth.

At a technical level, that supposes the file you want to decrypt still exists in X years.

My actual thought was to have the secure enclave emit an encrypted copy of the key with a targeted key strength when presented with a request signed by Apple's key. It would require Apple's participation (or compromising Apple) but still require that the person spend a significant amount of money on the process.

By having it encrypt a key, you can make normal messages much stronger, such that you can't decrypt messages without the device in question (because the key can't be attacked directly, only the weakly encrypted version of the key when the secure enclave shares it). Further, because you can change how strong the SE emitted key is with each revision, you can have new phones always have a 10 year expected safety window (and even turn up the difficulty over time). In the case of a total compromise of Apple's storage, the attacker still has to spend significant funds to compromise any given phone -- so we'll only see targeted attacks. (That is, they might say, crack Bill Gates' phone, but are they really going to spend hundreds of thousands a pop to break the keys of random Starbucks workers? I'm honestly not super worried if Bill Gates has to spend a few thousand extra dollars every few years to protect his billions.)

But we're never going to get to discuss those kinds of scoping and cost-benefit tradeoffs if we don't engage in the process of shaping legislation in an open and honest way.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#219

Earlier quoted context omitted.

> Just like in traditional encryption scenarios, your personal key remaining secret is a part of the assumption. That there are now two secret keys doesn't alter the analysis substantially. Of course it does. At best it doubles the risk of key compromise, but it's really much worse than that. A master key isn't like a normal key. If you compromise Alice and Bob's key, you can spy on Alice and Bob, but not Alice and C…

Lets say I grant everything you say about the danger to every Alice and Bob that a master key exists. The question is, can policies be enacted and systems put into place that provide a commensurate amount of security for the risk the backdoor key poses? It seems plausible that it can be. But this is the conversation that needs to happen, not the boneheaded claim that its "mathematically impossible" to have a secure s…

> The question is, can policies be enacted and systems put into place that provide a commensurate amount of security for the risk the backdoor key poses? It seems plausible that it can be.

It's plausible that the government can permanently keep a key to every lock secure against every attacker?

That is such a ridiculous claim that just skipping right to "no, that's impossible" is a completely reasonable thing to do. But we can do the analysis if you really want to.

Look at the other things the government has tried really hard to protect. Nuclear secrets? Nope.

https://en.wikipedia.org/wiki/Atomic_spies

The government has actually lost hydrogen bombs on multiple separate occasions. Not the secrets, the actual live thermonuclear weapons. The things that one of which can turn all of D.C. into radioactive glass.

What about all the sensitive information about the people with security clearances?

https://en.wikipedia.org/wiki/Office_of_Personnel_Management...

Incredibly dangerous biological materials ("arguably the most deadly disease ever to affect mankind")?

https://www.npr.org/2014/07/08/329884145/in-a-lab-store-room...

Classified information in general? The list of violations is too long to even enumerate.

And this is what happens when the thing they're supposed to be protecting doesn't have incomprehensibly large commercial value on the black market.

There is no question that they are not capable of doing this.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#220
post #207

Earlier quoted context omitted.

> If it is a foregone conclusion that the documents exist, the court can legally compel you to turn them over. Are you sure? That would imply that you could be compelled to produce documents that are known to exist but were stolen from you. It seems like a faulty premise. If they don't know where the documents are then how could they know they haven't been stolen or destroyed? It's the same problem with encryption ke…

> but were stolen from you. You're forgetting that the courts are human and would be sympathetic in this case. If it couldn't be shown that you have access to the documents or you could show they were stolen then you would be fine. > Just because you had it yesterday doesn't mean you have it today Right, which is why I prefaced the discussion with the situations where the police can prove beyond a reasonable doubt th…

> You're forgetting that the courts are human and would be sympathetic in this case. If it couldn't be shown that you have access to the documents or you could show they were stolen then you would be fine.

But that's the whole problem. How are you supposed to prove that you don't have something? It's completely reasonable that someone can have stolen it from you without you being able to prove it.

They can prove that you do have it by finding it in your possession, but if they could do that then they wouldn't need you to tell them where it is. If they don't know where it is then they can't know whether you have it or not.

> Right, which is why I prefaced the discussion with the situations where the police can prove beyond a reasonable doubt that you posses the key/password.

That's just assuming the conclusion.

Proving beyond a reasonable doubt that somebody knows something is next to impossible. You can have them on video entering the correct pass phrase and it only proves that they knew it when the video was made, not that they still remember it now.

Post reply on HN