Live data from Hacker News

Ask HN: What are your arguments in favor of end-to-end encryption?

news.ycombinator.com

141–150 of 255 posts

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#141
post #90

Earlier quoted context omitted.

Shouldn’t they come to me then and look into my phone instead of constantly looking into my messages on the server? I think the door is a great analogy.

and if you say "no", they're screwed. Whereas with a door, they can just push you out of the way and kick it down. I'm opposed to back doors, but the door analogy is a bad one.

They can't kick it down and push me out of the way if I have built an underground bunker.

And surely we all deserve an underground bunker.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#142

Earlier quoted context omitted.

I see these comparisons made so, so frequently and it bothers me. Guns are not the same as encryption or cars. Yet they're so often made in apples to apples comparisons that it's mind boggling to me. Weapons are uniquely special in that they are specifically designed to maim and kill. Via defense or justified actions is irrelevant; it's a tool of war. Arguably, if there was E2E software that was specifically designed…

guns have legitimate uses such as defense and hunting.

Maybe you missed the part where I discussed defense and hunting.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#144
One comparison I don't see yet, which is the easiest and most non-technical I know: E2EE communication is just a long-distance version of speech. The usual comparison for E2EE is physical mail, but the entire argument happens over the flaws of the metaphor. The lack of bulk mail analysis or systematic mail fraud means that the good and bad parts of encryption are both mostly hypothetical.

Talking make a much better comparison. When you say something, someone can listen or record you, just like E2EE doesn't protect against shoulder-surfing or a compromised device. But once you've said a thing, it's gone. It's not just inadmissable but inaccessible. No police tactic in the world can physically reconstruct it, and the Fifth Amendment says you can't be forced to confess anything incriminating that you've said. (The comparison for encrypting illegal media is messier, but a spoken threat is a crime composed only of words, so we could compare that to an encrypted picture.)

And vitally, all the things governments warn about E2EE apply to speech. People use speech to plot all sorts of heinous acts. Criminals gravitate towards in-person speech instead of using letters or phone calls. Whether it's clergy covering up child abuse or terrorists plotting bombings, talking is the standard method of coordinating crimes without leaving evidence. There's speech which is itself criminal, like threatening bodily injury, which leaves no evidence after it's said. When people resort to speech instead of calls or letters, the job of the police gets harder. If everyone had to carry a running voice recorder or make phone calls, it would be much easier to convict criminals, and bulk analysis could be used to be proactive about terrorism and abuse instead of investigating after the fact.

It's hopefully intuitive to most people why "all speech needs to be recorded for police use" is unacceptable. "Nothing to hide" doesn't justify letting the police in on your pillow talk. Bulk analysis of who's talking about what is abhorrent, but warrant-only access isn't tolerable either. The government would abuse the system, private people would try to break into the logs, and the breach of privacy is fundamentally out of bounds regardless. And policing still happens just fine without such a log. Officers listen as people speak, just like they can monitor a device before it sends a message. People who hear bad things said report them. When physical crimes are plotted, the crimes leave evidence. And for speech like threats, we can still collect witness accounts or convict over follow-through. The government doesn't need a log of everything we say.

In the same way that all the horrors of cryptocurrency are grandfathered into cash, the menace of encrypted texts is already present in everyday speech, but the world keeps turning.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#145
Let's be clear about something, the threats from exposing our information are not hypothetical, the last 10 years of repeated hacks into banks and services that expose people's financial and personal information (CC numbers, SSN numbers, etc) is proof that there are adversarial actors actively trying to get and exploit our information for financial gain. Right now, a database with structured data is useful (and amazing that its not encrypted in a way where it would be useless to steal at rest), but if you were able to get a treasure trove of unstructured messages we may not be far off from being able to extract a ton of information from that too.

And that's just financial stuff. The current generation has repeatedly proven that they want to send revealing photos on these chat platforms. Remember the iCloud leaks of revealing photos? These were done with phishing attacks, but once again proves that there are malicious actors looking to take what most of us would consider to be private personal property. Today it was phishing attacks, but without encryption, tomorrow it might be an actual massive data dump of every photo ever sent on Messenger. Again, we currently have AI models that can do facial recognition and that can do nudity detection (as employed on YouTube, etc.), so access to the data set of photos sent on Messenger could then be analyzed by a computer to extract all nudes of key people (if targeted), or just all nudes (if not targeted). If your response to this is "they shouldn't be using it that way" -- again, consider that you might have second-order exposure to this problem. You may be smart enough to not send compromising information on Messenger, but maybe a close family member isn't and now you can be blackmailed or extorted to prevent revealing something of theirs. Or let's say everyone in your family is smart enough not to use Messenger this way. Your representative or senator's relatives might not though, and now they can be blackmailed too, and there's not much you can do about that since you may not even find out. All these problems similarly exist with respect to corporate privacy as well (trade secrets vs. potentially malicious foreign companies, people trying to get inside information for trading, etc.)

At the end of the day, to me the question of whether the US is trustworthy is besides the point: the lack of encryption exists for anyone trying to get in, and we know there are bad people trying to get in. If you take the lock off the door you might trust your friendly neighborhood policeman but the cat burglar can just as easily turn your doorknob.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#146
In the spirit of writing a simple and condensed answer, and assuming e2e encryption would remain with a government backdoor, there are three main problems (I don’t see any other):

1. Government abuses their power

2. Government gets hacked and hacker abuses their power

3. You have something to hide

Now we can debate on each of these points. Tell me if I’m missing something.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#147

Encryption is math. Can we really make a form of math illegal? I feel privacy is a basic human right regardless of what country you live in. I’m not fan of punishing the majority because of a screwed up minority. People who commit illegal acts as horrible as child abuse and terrorism are not going to respect the law when it comes to encryption. Again, you can’t stop people from doing math. The idea of making it illeg…

> Again, you can’t stop people from doing math. The idea of making it illegal is silly. I don't think anybody is suggesting two individuals should not be allowed to use math to protect their conversations. Even if Facebook adds a way for law enforcement to access communications individuals are still free to talk in code or encrypt their messages before putting it on the wire. With your old telephone, your carrier can…

Such a law would serve no reasonable purpose, though. Criminals can use one-time pads and it's also not hard to make a little encryption program based on existing cryptographic primitives. In fact, drug cartels have specialists for that who could probably even develop and implement their own secure-enough Feistel cipher if they wanted to.

The only purposes such a law seems to serve is to catch clueless idiots who will be caught anyway, and to enable mass-surveillance of law-abiding citizens.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#148
I always recall that statement Eric Schmidt once made about if you've got nothing to hide, you've got nothing to fear. It's not about fear of having my messages read, it's that you shouldn't have the right to read them. I guess at the end of the day, regardless of anyone else's behavior, I don't want my private communications being readable by outside parties. Should everyone be forced to wear a microphone and video camera so their private face-to-face communications can be monitored by a "trusted authority"? Of the volume of communications going back and forth constantly, I doubt "sexual abuse imagery or terrorism" combined makes up less than 0.01% of messages.

If respecting individuals privacy makes law enforcement more difficult, so be it. I'm sorry you have your work cut out for you.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#149
Encryption is intangible, but it's a tool like many other objects surrounding us. Let's compare it to a hammer.

You can use it to do good things (hammer down nails to create a building to shelter people) or bad things (hurt people with it, smashing toes, etc). If someone does bad things with it, banning it stops people to do good things with it, and everyone lose.

Encryption ensure everyone can speak their mind freely, without worrying that someone with unclear motives can snoop around and read legitimate, but private discussions between two persons.

Not having this ability to speak freely hurts everyone, simply to remove a tool that could be used for bad things. Don't fight the tool, fight the bad actors with all the means at your disposition.

Re: Ask HN: What are your arguments in favor of end-to-end encryption?

#150
I support it 100%, because I have everything to hide as my life is mine and doesn't belong to anyone else, including governments or improbable divinities. If for some people in power this mean I'm either a murderer, a rapist, a drug dealer, a pedophile, a terrorist, or whatever, they're free to spend taxpayers money to find out how wrong their assumptions were, then get voted out of their seats. Anyone using the "if you have nothing to hide" argument is just pushing you into relinquishing your privacy rights to gain power over you. Just try asking them their own passwords and hear the very predictable reply.

Intelligence does exist for the purpose of catching people doing nasty things even when they do it behind the curtain. Making curtains illegal would be the obvious stupid response which would harm everyone. Nobody ever said that democracy is either free or easy; a bunch more criminals at large sometimes somewhere is a price we have to pay to have billions of people, including us, enjoying what remains of their freedom.

Just to avoid the most predictable counter argument: I'd keep defending this principle even in case one of those criminals would exterminate my entire family.

Post reply on HN