Live data from Hacker News

Tech firms “can and must” put backdoors in encryption, AG Barr says

arstechnica.com

51–60 of 130 posts

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#51

> The cost of encryption, he said, is measured in "victims" who might have been saved from crime if law enforcement had been able to lawfully intercept communications earlier. The cost of backdoors is measured in hospitals paralyzed by ransomware, personal information stolen by hackers, government secrets obtained by hostile nations. Not to mention the threat of pervasive surveillance by our own government, which has…

Look, same applies for example to 2nd amendment. But people find it plausible and vote for more gun control.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#52
post #20

Earlier quoted context omitted.

Seems like a failure of the tech community that most people don’t understand the ramifications of backdoors. People can also point to the example of China where there are indeed government backdoors and things are fine (from the government can get access but others can’t point of view). Clearly we don’t want to be like China in this regard but it does give an example of a “working” backdoor setup.

If I tell a child that 2 + 2 = 4, and show them four blocks in groups of two, and have them draw pictures demonstrating that 2+2=4, and sing songs about 2+2=4, and yet they persist in believing that 2+2=5, is that my failure? The tech community has repeatedly and thoroughly explained the impossibility of secure backdoors, but it is apparently a more difficult thing to grasp than 2+2=4, especially when one does not wi…

The way I see it, the general population didn't pay attention[0], and the legislators see this as a problem of colour. What they want is a back door that opens only to people bearing keys of the right colour, and you can't get them to understand that the concept of colour doesn't make sense in the world of bits, for the reasons outlined in [1].

--

[0] - They never do - they don't care, and it's hard to argue why should they care especially about this, over a million other urgent things. Media being saturated with outrage-inducing crap doesn't help push through the noise either.

[1] - https://ansuz.sooke.bc.ca/entry/23

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#53

Yeah but what's to stop a bad actor simply switching to a provably secure cryptographic system or app? Don't forget there's an arms race going on, where bad actors consistently try to outpace law enforcement by switching to provably secure and private systems. Take for example when 3DES[0] was discovered as insecure and all the criminals switched to AES[1]. And don't forget the old adage: If you outlaw encryption, th…

> then only outlaws will use encryption

Which makes them easy to find in a dragnet unless they're also using stenography.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#54

Does mr Barr not understand that criminals will simply use free non-backdoored software instead? Of course he does. It's hard not to read this as another attemt to listen in on the conversation of regular citizens instead.

You could say that about criminalizing TOR. If you knew that by using TOR you were going to get swatted at 3am you'd probably stop using it. Same goes for encryption. The second any law is passed google/apple are going to pull apps; whatsapp etc are going to remove e2e (or alter it so the UI is the same but it can be snooped on) and criminals are going to have to figure out how to use PGP or whatever.

In this scenario, Amazon, Facebook, and Microsoft will immediately fold as they can no longer securely sell products to customers. If e2e crypto is banned, the entire ecommerce market is fucked.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#55
post #39

We don't need to make arguments like "I trust the state, but what about criminals?". All US administrations have exhibited strong evidence of criminality and work to suppress dissent and oppress minorities. The current administration makes AG Barr's machinations exceptionally clear as they employ an ever more viscous kidnapping force and (incompetently) attempt to start wars around the world. If you want to be able t…

A "viscous kidnapping force" is an especially sticky problem. ^__^;

I hate it when the kidnappers are thick.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#56

We don't need to make arguments like "I trust the state, but what about criminals?". All US administrations have exhibited strong evidence of criminality and work to suppress dissent and oppress minorities. The current administration makes AG Barr's machinations exceptionally clear as they employ an ever more viscous kidnapping force and (incompetently) attempt to start wars around the world. If you want to be able t…

Even if the state is completely trustworthy, has zero potential criminals in its ranks and always acts with good intentions, it's not enough. There is repeated proof, ad nauseum, that governments are incapable of consistently protecting their data from hackers. So if a state has access to backdoors it's a matter of when, not if, that access will be captured by criminals and enemy states.

I work in a small company where I honestly believe everyone is trustworthy. Still it is a good thing that our users' passwords are hashed and none of our staff can decode them. It's a tragic example of motivated reasoning that the head of the Department of Justice doesn't get that.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#57

I challenge him to describe what an encryption backdoor actually is. Its like putting a hidden switch behind a brick in a wall. The brick looks the same, but if you take the time to knock on every brick, you'll eventually find the button. Every moderately powerful nations will have someone out there knocking on the bricks.

It takes a prohibitively long time to knock on 2^256 bricks. The real risks aren't from the crypto; they're from the humans who have access to the back door. Can they be trusted? Can they be compromised?

That's not to mention the business damage this would cause. The US is trying to block Huawei products due to back doors. Other countries will block US products if the US government starts requiring back doors.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#58

This was briefly confusing, as AG Barr is the soft drinks company which manufactures Irn Bru in Scotland, and I was surprised to see they had an opinion. But I'm interested in what the constructive path forward is on the rather more important issue of ubiquitous encryption. I think most people generally accept that well-regulated wiretapping (and other forms of interception of communication) are a useful and importan…

Imagine the worst case ("worst" from this PoV): end-to-end encryption is widely adopted and effective. How hard is a cop's legitimate job, compared to before telephone wiretaps? They can get to ubiquitous (and always increasing) surveillance footage and cell-phone tracking, just for a start. It seems really phony to frame this scenario as "going dark".

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#59

Earlier quoted context omitted.

That's an interesting argument, but only the most extreme interpretation of the 2nd Amendment argues that it covers _all_ munitions. And I'm having trouble finding a contemporary example of someone making this claim. On top of that, we now have years of SCOTUS jurisprudence that "arms" are absolutely subject to _some_ regulations, with the debate focusing on what "some" actually means.

>And I'm having trouble finding a contemporary example of someone making this claim. Maybe you were looking for someone notable, but I'll make it for you right now.

You're certainly more notable than homonculus2!

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#60

This was briefly confusing, as AG Barr is the soft drinks company which manufactures Irn Bru in Scotland, and I was surprised to see they had an opinion. But I'm interested in what the constructive path forward is on the rather more important issue of ubiquitous encryption. I think most people generally accept that well-regulated wiretapping (and other forms of interception of communication) are a useful and importan…

"This was briefly confusing, as AG Barr is the soft drinks company which manufactures Irn Bru in Scotland, and I was surprised to see they had an opinion"

Me too. I would have thought they would have been in favour of very strong encryption.... Made from girders.

https://m.youtube.com/watch?v=H4PxuFQCDis

Post reply on HN