Earlier quoted context omitted.
Seems like a failure of the tech community that most people don’t understand the ramifications of backdoors. People can also point to the example of China where there are indeed government backdoors and things are fine (from the government can get access but others can’t point of view). Clearly we don’t want to be like China in this regard but it does give an example of a “working” backdoor setup.
> but it does give an example of a “working” backdoor setup. I'd argue that it's actually giving the illusion of a working setup - not that the setup actually works.
Tech firms “can and must” put backdoors in encryption, AG Barr says
101–110 of 130 posts
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#102Earlier quoted context omitted.
Seems like a failure of the tech community that most people don’t understand the ramifications of backdoors. People can also point to the example of China where there are indeed government backdoors and things are fine (from the government can get access but others can’t point of view). Clearly we don’t want to be like China in this regard but it does give an example of a “working” backdoor setup.
If I tell a child that 2 + 2 = 4, and show them four blocks in groups of two, and have them draw pictures demonstrating that 2+2=4, and sing songs about 2+2=4, and yet they persist in believing that 2+2=5, is that my failure? The tech community has repeatedly and thoroughly explained the impossibility of secure backdoors, but it is apparently a more difficult thing to grasp than 2+2=4, especially when one does not wi…
1) well, people just are too dumb / don't care enough / stubborn, we've done all we can and it is what it is
2) the message isn't getting through, let's try something different
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#103We don't need to make arguments like "I trust the state, but what about criminals?". All US administrations have exhibited strong evidence of criminality and work to suppress dissent and oppress minorities. The current administration makes AG Barr's machinations exceptionally clear as they employ an ever more viscous kidnapping force and (incompetently) attempt to start wars around the world. If you want to be able t…
Even if the state is completely trustworthy, has zero potential criminals in its ranks and always acts with good intentions, it's not enough. There is repeated proof, ad nauseum, that governments are incapable of consistently protecting their data from hackers. So if a state has access to backdoors it's a matter of when, not if, that access will be captured by criminals and enemy states. I work in a small company whe…
There's another point to make here: Not giving individuals the keys to the kingdom protects them from being targets.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#104We can have a little test - let's put backdoors on all of law enforcement's encryption usage and see how long it stays safe. I really don't know if people like Barr are arguing in good faith. But then I try to assume incompetence first and malice second.
Except we have actual history to look at in Barr's case, Iran-Contra. I absolutely consider this malice first and incompetence second. That malice is classism, people are not equal, some people are inherently better people, and they have more money. Everything is a product. And wealthy people can buy more of that product than others. This is an attempt to make sure ordinary people cannot have privacy, cannot be prote…
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#105Earlier quoted context omitted.
If I tell a child that 2 + 2 = 4, and show them four blocks in groups of two, and have them draw pictures demonstrating that 2+2=4, and sing songs about 2+2=4, and yet they persist in believing that 2+2=5, is that my failure? The tech community has repeatedly and thoroughly explained the impossibility of secure backdoors, but it is apparently a more difficult thing to grasp than 2+2=4, especially when one does not wi…
If you are making an argument for something and people aren't convinced, who's issue is that? The tech community wants the general population to be against installing backdoors. If people aren't convinced or don't care, we can take a couple of stances: 1) well, people just are too dumb / don't care enough / stubborn, we've done all we can and it is what it is 2) the message isn't getting through, let's try something…
At _some_ point, this quits being a failure of the tech community. _Some_ people simply are not teachable, because they refuse to listen. No "something different" is going to convince someone of something they don't want to believe.
P.S. You didn't say "issue" before, you said "failure." That it's an issue is indisputable. Assigning blame seems counter-productive at best.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#106Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#107Earlier quoted context omitted.
No one can force your to share information. Let's say your PIN code is 1324, and you suffer from stress induced transposia (just made that up). Every time you are asked to say or share your PIN code, you get stresses & use 1234, even though you meant to use 1324. There's no way make you say the correct PIN code. In a more realistic example, what are you going to do to someone who simply forgot their PIN code?
They cannot compel you to divulge a password, but they can mandate a thumb unlock, just as while they cannot compel you to divulge a safe combination, they can mandate you give them a key. Information versus material.
This is an excellent point. That is why do I not use biometrics on my personal devices. I honestly don't have anything to hide, but I also have no desire to give people the idea that it's going to be easy to fish through my personal stuff.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#108Just add a 'USGOV BACKDOOR' tab and password/encrypt it or whatever the fuck. It doesn't need to be a real control panel or anything other than trivial options (a grayed-out unchangeable toggle box that says 'Enable backdoor', for instance). I'm not the guy to provide you UI tips.
Let users understand it's there without relying on security-through-obscurity. Disallow any temptation to use StO and ensure users are fully informed of the government's firm and fatherly hand.
Yes, I know that the GUI/man page information are not 'the backdoor'. It is also not actually any functionality for the software you're using. It is function through abstracted symbols.
Protest via abstracted symbolism - visible and immutable vulnerability.
Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#109Re: Tech firms “can and must” put backdoors in encryption, AG Barr says
#110Earlier quoted context omitted.
It's pretty close. For a while crypto was classified as munition and placed under very strict export control in the United States.
When did that change ?