Live data from Hacker News

Rethinking Encryption

lawfareblog.com

81–90 of 125 posts

Re: Rethinking Encryption

#82

I don't think the threats from people "going dark" justify weakening encryption. The potential for abuse is too real and there are already a lot of instances when governmental actors have acted in bad faith. The text I would consider manipulative with its references of a terrorist bombing. State actors suppressing dissent isn't mentioned at all. It is not a black and white issue, but in most parts of the world, peopl…

If you read the whole article you will find out that you are in complete agreement with it.

Re: Rethinking Encryption

#83

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

China already got golden keys for Chinese iPhones. Apple handed them iCloud.

That is technically incorrect. As I understand it, the iPhones are generic (global), but the iCloud service is what the Chinese authorities have full snooping rights to.

Apple doesn't cut a custom firmware with special/additional golden keys or anything of that nature, as I understand it, for anyone.

The iPhone in this case is safe, assuming you don't use iCloud, in China.

Re: Rethinking Encryption

#84
post #10
post #4

This is fundamentally a fight about the autonomy of the human mind, and what the government can command you to do with your own brain. If you and a cohort were the last survivors of a dying tribe, with your own special language that no one understood, and you criminally conspired with them via written word, the government could not compel you to translate your messages just because they cannot understand them. That's…

By "cannot compel you to translate," you mean "must not compel" or "should not compel," because an entity that controls 11 aircraft carriers can compel you to translate whatever the hell they want you to.

What does 11 carrier strike groups have to do with the 5th amendment? The former is to project power beyond the borders of the United States. The latter is to protect you from an abusive government domestically.

Also to take it further, technically, the US Constitution does not apply beyond our borders (like any other US law, absent a bilateral treaty).

I fail to see the connection you are trying to make.

Re: Rethinking Encryption

#85
post #61
post #37

Earlier quoted context omitted.

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court. One thing the US has going for it is tha…

> Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. Yeah, that's not exactly the case...

In comparison to Chinese companies which comply 100% of the time with Chinese military intelligence, it matters.

Re: Rethinking Encryption

#86
post #46
post #40

Earlier quoted context omitted.

USB stick? the entertainment industry provides an excellent source for the distribution of 1-time pads, just agree on some particular stream/CD/DVD/etc ("number 27 on this week's top 40") and use the LSBs in some agreed order

A one time pad must be truly random to be secure. A music stream is far from that.

'The Nth 4096 bits from this week's mod(N,100) top video on YouTube'

Can you tell me what's wrong with that approach? In my head, it seems reasonable.

Re: Rethinking Encryption

#87

Earlier quoted context omitted.

A warrant canary is utterly useless as a defense. Any secret legal order to alter IT systems (the specific threat model it is most often suggested for) can logically also include an order to maintain a fake warrant canary.

Part of the theory of a warrant canary is that compelled speech (and in particular a compelled lie) may be easier to challenge than suppressed speech. While that isn't definitive, there's some jurisprudence to back that theory. If you have a warrant canary, you should be prepared to challenge any such order in court and use that as the defense.

An important detail in the US juristiction certainly.

On a practical basis i cannot evaluate the jurisprudence involved and I would assume the number of people who credibly can is very small, especially in the context of "secret courts for national security reasons".

A useful test would be if any of those few had demonstrated a personal risk using this as a defense and succeeded. The rest of us can only guess the risk based on the reputation of the entites involved.

Re: Rethinking Encryption

#88

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

I would be excited to read about how we can rethink encryption to enable a stateless society.

Re: Rethinking Encryption

#89
post #60

Earlier quoted context omitted.

All public encryption algorithms have backdoors in their implementation and sometimes (as with Elliptic Curve standards from NIST adopted in the browser) in their spec. You might get lucky if you have a cryptographer design you a custom algorithm but that's mostly security thru obscurity and if a state actor really wanted to defeat it they may just kidnap the cryptographer at gun point and have them reveal how to. Cr…

If this was the case, there would be no push in government sectors to diminish cryptography and provide backdoors. Or perhaps they are double-bluffing us? ;-)

The "government" is not one coherent entity. Also, its primary goal is the oppression, intimidation and subjugation of the masses, not logical thinking.

Re: Rethinking Encryption

#90

Earlier quoted context omitted.

A warrant canary is utterly useless as a defense. Any secret legal order to alter IT systems (the specific threat model it is most often suggested for) can logically also include an order to maintain a fake warrant canary.

Part of the theory of a warrant canary is that compelled speech (and in particular a compelled lie) may be easier to challenge than suppressed speech. While that isn't definitive, there's some jurisprudence to back that theory. If you have a warrant canary, you should be prepared to challenge any such order in court and use that as the defense.

You threaten that and they say “go pound sand in the courts”. And even if you “win” in the courts you still lose because “the process is the punishment”.
Post reply on HN