Live data from Hacker News

Tech firms “can and must” put backdoors in encryption, AG Barr says

arstechnica.com

111–120 of 130 posts

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#111
post #101
post #34

Earlier quoted context omitted.

> but it does give an example of a “working” backdoor setup. I'd argue that it's actually giving the illusion of a working setup - not that the setup actually works.

Well (one of) the arguments has been that it's possible to put in a secure backdoor such that only folks that should have access has access. In this case the government. In China the backdoor as far as I know is only accessible by the government and hasn't been otherwise exposed yet.

Most governments won't kill you, your family, friends and and anyone you could have communicated with if you release the backdoor.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#112

Earlier quoted context omitted.

It takes a prohibitively long time to knock on 2^256 bricks. The real risks aren't from the crypto; they're from the humans who have access to the back door. Can they be trusted? Can they be compromised? That's not to mention the business damage this would cause. The US is trying to block Huawei products due to back doors. Other countries will block US products if the US government starts requiring back doors.

> It takes a prohibitively long time to knock on 2^256 bricks This assumes you have to knock on 2^256 bricks and not just wiggle the mortar free in one spot. WEP wifi encryption is an example of an implementation failure vs. theoretical time to brute force the encryption.

You're right, but the answer to encryption backdoors can't be "we don't think you'll make good enough backdoors". Even if the backdoor can't be opened by anything other than acquiring the government key, it's still not acceptable.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#113

I challenge him to describe what an encryption backdoor actually is. Its like putting a hidden switch behind a brick in a wall. The brick looks the same, but if you take the time to knock on every brick, you'll eventually find the button. Every moderately powerful nations will have someone out there knocking on the bricks.

Ditto larger and more organized criminal organizations.

I'm going to add that toddlers [teenagers / lone wolves] will also try knocking on bricks if they see their parents [governments] doing so successfully.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#114

Earlier quoted context omitted.

That's an interesting argument, but only the most extreme interpretation of the 2nd Amendment argues that it covers _all_ munitions. And I'm having trouble finding a contemporary example of someone making this claim. On top of that, we now have years of SCOTUS jurisprudence that "arms" are absolutely subject to _some_ regulations, with the debate focusing on what "some" actually means.

>And I'm having trouble finding a contemporary example of someone making this claim. Maybe you were looking for someone notable, but I'll make it for you right now.

Just out of curiosity, does that extend to things like chemical or biological weapons?

I suppose such an interpretation would have the side effect of making literally any hazardous substance legal to possess.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#115

Earlier quoted context omitted.

> It takes a prohibitively long time to knock on 2^256 bricks This assumes you have to knock on 2^256 bricks and not just wiggle the mortar free in one spot. WEP wifi encryption is an example of an implementation failure vs. theoretical time to brute force the encryption.

You're right, but the answer to encryption backdoors can't be "we don't think you'll make good enough backdoors". Even if the backdoor can't be opened by anything other than acquiring the government key, it's still not acceptable.

Yup, in fact that's my point. No matter how good the encryption or implementation is, there will always be a weak link and someone that finds a way in. For some people, its a fun challenge and bragging rights. For others, it's profit.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#116

I challenge him to describe what an encryption backdoor actually is. Its like putting a hidden switch behind a brick in a wall. The brick looks the same, but if you take the time to knock on every brick, you'll eventually find the button. Every moderately powerful nations will have someone out there knocking on the bricks.

A backdoor isn't just an entry point. Its a m architecture. A vulnerability like the the exhaust vent on the Death Star plus a detonator custom built to blow the whole thing up, and then hoping that no one misused this thing that shouldn't even exist.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#117

They do not need to hide the backdoor's existences though Just add a 'USGOV BACKDOOR' tab and password/encrypt it or whatever the fuck. It doesn't need to be a real control panel or anything other than trivial options (a grayed-out unchangeable toggle box that says 'Enable backdoor', for instance). I'm not the guy to provide you UI tips. Let users understand it's there without relying on security-through-obscurity. D…

I like this a lot. Great idea!

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#118
post #2

We can have a little test - let's put backdoors on all of law enforcement's encryption usage and see how long it stays safe. I really don't know if people like Barr are arguing in good faith. But then I try to assume incompetence first and malice second.

This already happened. NSA/Booz Allen had a back door and Snowden exploited it. The Embassy had a back door and Manning exploited it.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#119

>He also accused tech firms of "dogmatic" posturing, saying lawful backdoor access "can be and must be" done, adding, "We are confident that there are technical solutions that will allow lawful access to encrypted data and communications by law enforcement, without materially weakening the security provided by encryption." This reminds me of the classic article about trisectors https://web.mst.edu/~lmhall/WhatToDoWhe…

"We are confident that there are technical solutions that will allow squaring circles without materially making them not circles." Or drying water, or any number of other impossibilities.

WWE is a squared circle.

Ice is dry water.

Re: Tech firms “can and must” put backdoors in encryption, AG Barr says

#120

Yeah but what's to stop a bad actor simply switching to a provably secure cryptographic system or app? Don't forget there's an arms race going on, where bad actors consistently try to outpace law enforcement by switching to provably secure and private systems. Take for example when 3DES[0] was discovered as insecure and all the criminals switched to AES[1]. And don't forget the old adage: If you outlaw encryption, th…

They don't want to catch intelligent bad actors. They want to intimidate their powerless enemies.
Post reply on HN