Live data from Hacker News

Rethinking Encryption

lawfareblog.com

71–80 of 125 posts

Re: Rethinking Encryption

#71
post #19

I'm confused at the assumption that you can prevent serious organized criminals from having access to strong cryptography simply by backdooring common communications apps. The genie is out of the bottle: Powerful criminal enterprises will have no difficulty hiring people to build overlay tools that they can run inside their backdoored comms that will provide adequate (at least, if not effectively unbreakable) cryptog…

Really when dealing with known bad actors it is best to always treat their arguements as in bad faith.

It doesn't make sense because why they want it isn't honest - even if they fully believe their own lies with a passion.

Re: Rethinking Encryption

#72
post #8

Earlier quoted context omitted.

Uhh.. no. In fact it doesn't. If your goal is to secure the entire internet via SSL or get people to use PGP signed emails in a mass market then the tremendous technical and cultural hurdles in place that create making a 'truly secure' implementation that gets widely accepted a near impossibility. But if you goal is to secure the communication between trained people in a 'terrorist cell' or other small group then tha…

USB stick... I'm sure it'll work out great. What if you have to give it up with a gun to your head? > Hand wavy as heck. Then you meander. Not sure what you're responding to.

The whole point of a one time pad is that it is never used again and destroyed after use. Even the sick fucks in the CIA don't think they can get a key sequence from you with torture or threats after it has already been stomped and put in a microwave.

Re: Rethinking Encryption

#73
post #48

Interesting speech by William Barr: https://www.c-span.org/video/?464971-3/attorney-general-barr... "Only two ways to protect society ... 1) Ability to detect and apprehend criminals .. 2) Regiment society as a whole" "Our ability to protect the public from criminal threats is rapidly deteriorating" "Status quo is exceptionally dangerous"

Wow the Trump administration really does love saying the quiet part out loud. Literally saying a free society is dangerous and must be controlled.

Re: Rethinking Encryption

#74
The flaw in these over zealous mind- policemens arguments is that they say will be no other way to tell what someone is doing without reading their texts and phone data live.

A beat cop knows there are many "tells" about what someone is doing. Similarly, one has to commit several crimes leading up to a terrorist act. Catching those before hand crimes is an effective way at stopping the final act.

And who is going to be investigating all the people with keywords in their texts? There are not enough cops in the US to do that.

If we use the net, there's a government file with a rating on how dangerous we are.

My blog on these issues www.cyderinc.net

Re: Rethinking Encryption

#75
post #48

Interesting speech by William Barr: https://www.c-span.org/video/?464971-3/attorney-general-barr... "Only two ways to protect society ... 1) Ability to detect and apprehend criminals .. 2) Regiment society as a whole" "Our ability to protect the public from criminal threats is rapidly deteriorating" "Status quo is exceptionally dangerous"

Wow the Trump administration really does love saying the quiet part out loud. Literally saying a free society is dangerous and must be controlled.

The depressing thing is people with his views have been active in politics for decades (and not all in the political circles that currently run the government) - they're just finally getting their time in the sun, gathering together and doing whatever they want.

Even if some of this gets unraveled and the worst actors get kicked out, people like him will still be active in local and federal government trying to roll back civil freedoms. It's rough. Hopefully the events of the past few years will act as a wake-up call for people who were previously willing to ignore what was already going on.

Re: Rethinking Encryption

#76
post #62

Earlier quoted context omitted.

Well, China issues aside, that should be the case in every country -- such services should be local, governed by local laws, and not giving a free-pass to foreign countries/governments (foreign as to the users of the service) to enforce their laws/surveillance. E.g. I would like the EU iCloud to be hosted in EU.

> that should be the case in every country -- such services should be local, governed by local laws So a cloud service that's available worldwide should store and process data locally in every country (or perhaps even every sub-jurisdiction of every country) just so that that jurisdiction can serve warrants to it and others cannot? Or worse, people in multiple countries should have to use different services and hope…

>So a cloud service that's available worldwide should store and process data locally in every country (or perhaps even every sub-jurisdiction of every country) just so that that jurisdiction can serve warrants to it and others cannot?

Simply put, yes.

You are maybe concerned with the technical issues / problems to the service provider.

I'm more concerned with the decentralization, surveillance, and data sovereignty.

>Or worse, people in multiple countries should have to use different services and hope those services interoperate with each other, just so that they can "shop local"?

Yes. In fact, this decentralized nature, and resilience, was an early vision about the internet itself, and not just some hippie dream, even in its army-research origins... And of course all the way to ideas such as XMPP, Diaspora, and so on.

Nobody dreamed a Facebook silo somewhere gathering all the world's data...

>The Internet does not and should not work that way.

That it does not, it's obvious. That it should not, less so.

(And of course, if one's county is the one doing the data-gathering/policing of data for the rest of the world, it's "naturally" all A-OK to them that it is so).

>If we're going to go to the trouble of building interoperable, federated services, it should be to put them in the control of individual users, not in the control of governments.

Notice how I didn't propose putting them "in control of governments".

They already are in control of at least one government (the one of the country of Facebook, Google, MS, Apple, Twitter, etc).

So what I proposed is already de-centralized: putting each users data under democratic control in the places where they themselves are (and vote, have rights, etc), as opposed to a central place, where they don't vote, don't have any right or resource as foreigners and are "fair game" to the whims of both the service-origin government and the service company.

If they're going to go to control of individual users, even better. But stopping the control of a single foreign government is already a good first step.

(Exceptions could be made for non-democratic countries -- no reason to give control of a service's local data to a dictatorship).

Re: Rethinking Encryption

#77

Earlier quoted context omitted.

A warrant canary is utterly useless as a defense. Any secret legal order to alter IT systems (the specific threat model it is most often suggested for) can logically also include an order to maintain a fake warrant canary.

Part of the theory of a warrant canary is that compelled speech (and in particular a compelled lie) may be easier to challenge than suppressed speech. While that isn't definitive, there's some jurisprudence to back that theory. If you have a warrant canary, you should be prepared to challenge any such order in court and use that as the defense.

How so? Censorship is explicitly forbidden by the US constitution, and even so it happens (in this case, "in the name of national security" or whatever).

Re: Rethinking Encryption

#78
post #48

Interesting speech by William Barr: https://www.c-span.org/video/?464971-3/attorney-general-barr... "Only two ways to protect society ... 1) Ability to detect and apprehend criminals .. 2) Regiment society as a whole" "Our ability to protect the public from criminal threats is rapidly deteriorating" "Status quo is exceptionally dangerous"

Wow the Trump administration really does love saying the quiet part out loud. Literally saying a free society is dangerous and must be controlled.

I honestly prefer that to someone who lies to your face and stab you in the back. It's easier to fight.

Re: Rethinking Encryption

#79
post #76

Earlier quoted context omitted.

> that should be the case in every country -- such services should be local, governed by local laws So a cloud service that's available worldwide should store and process data locally in every country (or perhaps even every sub-jurisdiction of every country) just so that that jurisdiction can serve warrants to it and others cannot? Or worse, people in multiple countries should have to use different services and hope…

> So a cloud service that's available worldwide should store and process data locally in every country (or perhaps even every sub-jurisdiction of every country) just so that that jurisdiction can serve warrants to it and others cannot? Simply put, yes. You are maybe concerned with the technical issues / problems to the service provider. I'm more concerned with the decentralization, surveillance, and data sovereignty.…

> Simply put, yes.

Feel free to build such services, if you wish.

> You are maybe concerned with the technical issues / problems to the service provider.

Not just that (though I certainly don't consider it reasonable to expect a service to have thousands of servers in thousands of jurisdictions and deal with thousands of legal systems; frankly, I want services to expose themselves to as few jurisdictions as possible).

I'm concerned about the usefulness of the service to its users. As a user of a service, I will not accept partitioned and walled-off services where I cannot interact with people elsewhere in the world. That's my choice, and the choice of people and projects I collaborate with, and I choose to use services that allow me to collaborate with those people and projects.

> And of course all the way to ideas such as XMPP, Diaspora, and so on.

I did specifically say that:

If we're going to go to the trouble of building interoperable, federated services, it should be to put them in the control of individual users, not in the control of governments.

If you have the capability of interoperability and federation, then where you host your data should have nothing to do with jurisdiction, and everything to do with who wants to store and control the data.

Post reply on HN