Live data from Hacker News

Tech firms “can and must” put backdoors in encryption, AG Barr says

arstechnica.com

21–30 of 130 posts

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#22
We don't need to make arguments like "I trust the state, but what about criminals?". All US administrations have exhibited strong evidence of criminality and work to suppress dissent and oppress minorities. The current administration makes AG Barr's machinations exceptionally clear as they employ an ever more viscous kidnapping force and (incompetently) attempt to start wars around the world.

If you want to be able to resist these assholes (e.g. having anti-war or anti-ICE meetings that aren't snooped on, enable whistleblowers, etc), you need secure communications. Don't give them a backdoor.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#23

Does mr Barr not understand that criminals will simply use free non-backdoored software instead? Of course he does. It's hard not to read this as another attemt to listen in on the conversation of regular citizens instead.

If he doesn't right now, he soon will. That will mean first, random government checking whether encrypted comms are backdoored. If they discover that some are double-encrypted, and the inner encryption isn't backdoored, then they will do what we right now call MITM all encrypted comms. By law, with harsh penalties, because that's how we roll in the USA.

I think this is just another step in a War on Change. Snooping was good when the bulk of the comms weren't encrypted, and cellphones could be confiscated and read because plaintext. Change to HTTPS, dominance of a cellphone company that isn't too compliant, and here's a change that needs to be reversed, to be stopped.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#25

Mr. Barr is working for a President who's son in law was discussing to establish an encrypted and covert back-channel through the Russian embassy. He himself is accused of suppression and obfuscation of critical information that should have gone to Congress ages ago. He has less than zero standing in this area.

[flagged]

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#26

>He also accused tech firms of "dogmatic" posturing, saying lawful backdoor access "can be and must be" done, adding, "We are confident that there are technical solutions that will allow lawful access to encrypted data and communications by law enforcement, without materially weakening the security provided by encryption." This reminds me of the classic article about trisectors https://web.mst.edu/~lmhall/WhatToDoWhe…

"We are confident that there are technical solutions that will allow squaring circles without materially making them not circles."

Or drying water, or any number of other impossibilities.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#27
Yeah but what's to stop a bad actor simply switching to a provably secure cryptographic system or app? Don't forget there's an arms race going on, where bad actors consistently try to outpace law enforcement by switching to provably secure and private systems. Take for example when 3DES[0] was discovered as insecure and all the criminals switched to AES[1]. And don't forget the old adage: If you outlaw encryption, then only outlaws will use encryption

[0] https://en.wikipedia.org/wiki/Triple_DES

[1] https://en.wikipedia.org/wiki/Advanced_Encryption_Standard

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#28
This was briefly confusing, as AG Barr is the soft drinks company which manufactures Irn Bru in Scotland, and I was surprised to see they had an opinion.

But I'm interested in what the constructive path forward is on the rather more important issue of ubiquitous encryption. I think most people generally accept that well-regulated wiretapping (and other forms of interception of communication) are a useful and important law enforcement tool. Easy-to-use, commodity encryption makes this tool mostly useless. But obviously any "back door" would be immediately leaked/abused, and more to the point would just be circumvented by anybody who really did still want privacy. You can't shut the stable door etc.

We do sometimes choose to outlaw useful and entirely legitimate technology because of the potential for abuse. Is there a reasonable argument for doing so with mass-market encryption? In reality, it seems that the public benefit of having encryption in place is so overwhelming that this is a total non-starter. Or is it simply the case that we now have to accept that this tool is no longer one which can be used? I think we'd have to accept that ubiquitous encryption is here to stay and stop trying to fight it.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#30
post #2

We can have a little test - let's put backdoors on all of law enforcement's encryption usage and see how long it stays safe. I really don't know if people like Barr are arguing in good faith. But then I try to assume incompetence first and malice second.

If you know anything about Barr's long background, you'll know he is not "arguing in good faith".
Post reply on HN