Live data from Hacker News

Rethinking Encryption

lawfareblog.com

101–110 of 125 posts

Re: Rethinking Encryption

#101
post #19

I'm confused at the assumption that you can prevent serious organized criminals from having access to strong cryptography simply by backdooring common communications apps. The genie is out of the bottle: Powerful criminal enterprises will have no difficulty hiring people to build overlay tools that they can run inside their backdoored comms that will provide adequate (at least, if not effectively unbreakable) cryptog…

I still want an answer from these people. How was crime solved before end-to-end encrypted mobile apps existed? Maybe it makes it easier but maybe it doesn't. These devices connect to WiFi and cell networks and have GPS. It seems like coded messages at pay phones were even more unbreakable.

Re: Rethinking Encryption

#102
post #77

Earlier quoted context omitted.

Part of the theory of a warrant canary is that compelled speech (and in particular a compelled lie) may be easier to challenge than suppressed speech. While that isn't definitive, there's some jurisprudence to back that theory. If you have a warrant canary, you should be prepared to challenge any such order in court and use that as the defense.

How so? Censorship is explicitly forbidden by the US constitution, and even so it happens (in this case, "in the name of national security" or whatever).

The current interpretation says there are certain reasonable restrictions on the 1st for the public safety. Compelled speech isn't accepted as constitutional.

Remember the constitution only really, effectively, says whatever the current Supreme Court says it means. And really I don't think anyone want's the 100% literal 'shall make no law' interpretation of free speech; that would throw out any kind of labeling laws for starters, companies would have no government compulsion to accurately label drugs or food products for example.

Re: Rethinking Encryption

#103
post #37

This guy is all about how much of a threat the expansion of Chinese hardware is but doesn't say a word about the same being true for American hardware. Chinese networking hardware may contain backdoors, American hardware has been confirmed to contain backdoors over and over again. Re: the iPhone: when any country has the golden keys, every country has the golden keys. How hard is it to. Get that through your head. Th…

Backdoors have been revealed a few times in US products, but US companies have learned their lesson and appear to be pushing back. 9/11 is almost a decade in the past and the Snowden revelations embarrassed several companies. Things like warrant canaries are pretty common and companies like Apple have been publicly fighting government attempts to access Apple devices in court. One thing the US has going for it is tha…

9/11 is almost two decades in the past. Shall we return to the Crimean war?

Re: Rethinking Encryption

#104
post #4

This is fundamentally a fight about the autonomy of the human mind, and what the government can command you to do with your own brain. If you and a cohort were the last survivors of a dying tribe, with your own special language that no one understood, and you criminally conspired with them via written word, the government could not compel you to translate your messages just because they cannot understand them. That's…

Well, you know, the 5th Amendment only works in the USA. In most other parts of the world, speech is regulated. I'm not sure whether that is a good thing or a bad thing. I guess it depends on the regulations.

Re: Rethinking Encryption

#105
post #19

I'm confused at the assumption that you can prevent serious organized criminals from having access to strong cryptography simply by backdooring common communications apps. The genie is out of the bottle: Powerful criminal enterprises will have no difficulty hiring people to build overlay tools that they can run inside their backdoored comms that will provide adequate (at least, if not effectively unbreakable) cryptog…

I still want an answer from these people. How was crime solved before end-to-end encrypted mobile apps existed? Maybe it makes it easier but maybe it doesn't. These devices connect to WiFi and cell networks and have GPS. It seems like coded messages at pay phones were even more unbreakable.

> How was crime solved before end-to-end encrypted mobile apps existed?

One meaningful investigative tool was (and still is) the wiretap, where access to the physical channel gives unencrypted access to the contents. Phone encryption is possible, but was generally used rarely.

It sounds to me as if investigators want to preserve some equivalent of this tool, although its existence in the first place was more of a technical limitation than a legal one.

Re: Rethinking Encryption

#106
post #74

The flaw in these over zealous mind- policemens arguments is that they say will be no other way to tell what someone is doing without reading their texts and phone data live. A beat cop knows there are many "tells" about what someone is doing. Similarly, one has to commit several crimes leading up to a terrorist act. Catching those before hand crimes is an effective way at stopping the final act. And who is going to…

The flaw in your argument is that the article actually argues for strong encryption.

Re: Rethinking Encryption

#107
post #7

I’m extremely skeptical about ANYTHING put out by this group, and Jim Baker in particular. This guy was general counsel for the FBI at the same time they were abusing FISA warrants to secretly spy on Trump admins. You think they’ll stop at Trump? They’re just getting started. We need to get back to our roots of being extremely careful about our intelligence agencies. I know you’ll initially be turned off by the subje…

Don't post conspiracy theories.

Also: the article actually comes out in favour of strong encryption. How does that fit with your worldview?

Re: Rethinking Encryption

#108

Earlier quoted context omitted.

That is technically incorrect. As I understand it, the iPhones are generic (global), but the iCloud service is what the Chinese authorities have full snooping rights to. Apple doesn't cut a custom firmware with special/additional golden keys or anything of that nature, as I understand it, for anyone . The iPhone in this case is safe, assuming you don't use iCloud, in China.

> assuming you don't use iCloud But most people use iCloud, right? Apple forbids you from using competing full phone cloud backup services. The built in backup software continuously sends iCloud copies of most user data on the phone.

As far as I understand, they send an encrypted binary blob of the data on your phone, and the keys stay local. That’s much different.

Re: Rethinking Encryption

#109

Earlier quoted context omitted.

> assuming you don't use iCloud But most people use iCloud, right? Apple forbids you from using competing full phone cloud backup services. The built in backup software continuously sends iCloud copies of most user data on the phone.

As far as I understand, they send an encrypted binary blob of the data on your phone, and the keys stay local. That’s much different.

This is not correct. Apple's page explaining their iCloud encryption states that they use end-to-end encryption only for a few specific types of data, and only if you enable two factor authentication. iMessage in particular explicitly sends its encryption keys to iCloud (so that iCloud can unlock your messages if you lose your device, but of course this means iCloud can unlock your messages for any other reason without your knowledge). https://support.apple.com/en-us/HT202303
Post reply on HN