Earlier quoted context omitted.
Look, same applies for example to 2nd amendment. But people find it plausible and vote for more gun control.
Because a gun is a physical object, whereas a vulnerability is information.
Tech firms “can and must” put backdoors in encryption, AG Barr says
91–100 of 130 posts
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#92> The FBI ended up in possession of the shooter's iPhone during the investigation but was unable to unlock the device, as the attacker had been killed and therefore could not be compelled to share his PIN. Is it not the case that he couldn't be legally compelled to share his PIN even if he were alive?
Criminal law is more binary, and a far stronger burden of proof on the claiming party, the government.
This is already the case in many states when it comes to vehicular traffic laws. Most speeding is a civil offense, no right to plea bargain, or jury trial. It only becomes criminal after a certain speed (careless or wreckless), and becomes criminal after a certain amount and time for the unpaid fine.
It's what happens when people in a democracy aren't paying attention to state and local law making.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#93Earlier quoted context omitted.
[flagged]
But the Mueller report didn't find conclude that Trump colluded with the Russians. And their reasoning? Because they aren't allowed to indict a sitting president. If that's not the most bass-ackwards thing and proof of corruption I've ever heard of. "We held a giant investigation, but didn't conclude the party in question was guilty because we literally aren't allowed to"
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#94This was briefly confusing, as AG Barr is the soft drinks company which manufactures Irn Bru in Scotland, and I was surprised to see they had an opinion. But I'm interested in what the constructive path forward is on the rather more important issue of ubiquitous encryption. I think most people generally accept that well-regulated wiretapping (and other forms of interception of communication) are a useful and importan…
The legal reality today is that while legally we broadly interpret things like "companies are people", we very narrowly look at "papers, and effects" as literal, physical objects. Equating backdoors with wiretapping is only similar on the surface. A traditional wiretap allows the police to hear a series of conversations. A backdoor in an iPhone or your Dropbox/OneDrive/iCloud account potentially allows the police access to the entirety of your "papers, and effects".
I would be willing soften my opinion on the issue, but only if there was a meaningful change in how the law protects digital documents.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#95> The cost of encryption, he said, is measured in "victims" who might have been saved from crime if law enforcement had been able to lawfully intercept communications earlier. The cost of backdoors is measured in hospitals paralyzed by ransomware, personal information stolen by hackers, government secrets obtained by hostile nations. Not to mention the threat of pervasive surveillance by our own government, which has…
Look, same applies for example to 2nd amendment. But people find it plausible and vote for more gun control.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#96I challenge him to describe what an encryption backdoor actually is. Its like putting a hidden switch behind a brick in a wall. The brick looks the same, but if you take the time to knock on every brick, you'll eventually find the button. Every moderately powerful nations will have someone out there knocking on the bricks.
It takes a prohibitively long time to knock on 2^256 bricks. The real risks aren't from the crypto; they're from the humans who have access to the back door. Can they be trusted? Can they be compromised? That's not to mention the business damage this would cause. The US is trying to block Huawei products due to back doors. Other countries will block US products if the US government starts requiring back doors.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#97Earlier quoted context omitted.
[flagged]
But the Mueller report didn't find conclude that Trump colluded with the Russians. And their reasoning? Because they aren't allowed to indict a sitting president. If that's not the most bass-ackwards thing and proof of corruption I've ever heard of. "We held a giant investigation, but didn't conclude the party in question was guilty because we literally aren't allowed to"
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#98I challenge him to describe what an encryption backdoor actually is. Its like putting a hidden switch behind a brick in a wall. The brick looks the same, but if you take the time to knock on every brick, you'll eventually find the button. Every moderately powerful nations will have someone out there knocking on the bricks.
It takes a prohibitively long time to knock on 2^256 bricks. The real risks aren't from the crypto; they're from the humans who have access to the back door. Can they be trusted? Can they be compromised? That's not to mention the business damage this would cause. The US is trying to block Huawei products due to back doors. Other countries will block US products if the US government starts requiring back doors.
No, and yes.
This is not cynicism speaking, this is realism. Basic principle of security is to make the cost of breaking the security greater than the value of what is being protected. In this case, the "backdoor" keys will be protecting many, many billions and probably trillions of dollars of worth of information. At that scale, a foreign (or domestic...) intelligence agency finding the n of m people necessary to get the key and making it clear that if they love their family, their personal well-being, or indeed, anything in the world at all, they will hand over the key information is completely on the table. It isn't even just that there isn't anyone who can't be trusted with the keys, there isn't anyone who can stand up to the pressure that can be brought to bear on them. Put the keys in the hands of the most honest person on Earth who literally can not be coerced into giving it up, and it just means their family is the walking dead until the agency finally gives up and murders our magically honest person, and the key falls to the next in line and they try again.
(Or, in other words, if this backdoor is created, and the people in charge of the backdoor and all their families are still alive in a year, yes, I would consider that proof positive it's already been compromised. The stakes are that high.)
These backdoors would literally be massively more valuable than the nuclear codes, which still require various physical access and other things to be penetrated to use them, whereas these will be immediately valuable simply upon possession. Even if we entirely ignore the question of internal trustworthiness of the holding organization, which we shouldn't, but even if we do, no conceivable organization consisting of conceivable human beings can possibly secure this information. It's just impossible.
(Also: Note the complete lack of reference to any technical considerations. It doesn't matter what the encryption algorithm is, or whether it's secure on its own terms, or whether the tech companies are being unpatriotic, or anything else. There is simply no way to secure any information this valuable.)
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#99Does mr Barr not understand that criminals will simply use free non-backdoored software instead? Of course he does. It's hard not to read this as another attemt to listen in on the conversation of regular citizens instead.
It would be so much wiser to just keep quiet about that topic and rely on the neglicence of the common criminal - below the line there is a plethora of information in metadata and connection data, still incredibly better than anything law enforcement had 15 years ago.
The effect of any public advance into "responsible encryption" is only causing criminals to harden their tools.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#100Earlier quoted context omitted.
It takes a prohibitively long time to knock on 2^256 bricks. The real risks aren't from the crypto; they're from the humans who have access to the back door. Can they be trusted? Can they be compromised? That's not to mention the business damage this would cause. The US is trying to block Huawei products due to back doors. Other countries will block US products if the US government starts requiring back doors.
GPUs have been shown to be very good at complex math problems. A nation state with unlimited money could find a weakness built into crypto in a matter of days at most. A bored hacker would probably find it in a few hours.