A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…
So in an ethics discussion the professor simply asked "is X bad?" That doesn't seem like a very enlightened ethics discussion. How certain are you he said "bad"? If he has instead asked "is encryption problematic?", the outcome can be interpreted much differently because there are problems with encryption. Especially in an ethics discussion, there are definitely pros and cons to encryption. (FWIW, the pros outweigh t…
DOJ plans to strike against encryption while the Techlash iron is hot
61–70 of 347 posts
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#62Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
The problem is that to be useful for law enforcement, any local police department has to be able to go to any local judge and get a warrant and then get access.
There are approximately 30,000 state judges with fairly high turnover in that list. If you can compromise one, or successfully get yourself added to that list, you can then get access to whatever you want. That's way too many people to trust.
This is not a hypothetical weakness. I personally know someone whose physical location was compromised through a court order obtained by bribing a judge. How many cases are there where similar access was gained but the victim doesn't know how it happened? And the better the access that you can get, the more incentive there is to get it. (There is no shortage of reasons why a motivated party would want such access.)
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#63I find it interesting that the hn world is largely unified in beliefs about the trade-offs of exceptional access that aren’t necessarily true. Perhaps this is a cultural top-down tribal mentality borne of an adversarial arrangement between the billionaire oligarchs behind the startup scene and the government which serves to offer counterbalance against unchecked power. I personally find it reprehensible that large tr…
> I’m personally okay with secret police What? Why are you ok with secret police? Where has this idea ever worked? > I find it interesting that the hn world is largely unified in beliefs about the trade-offs of exceptional access that aren’t necessarily true. Which trade-offs are you suggesting aren't true? The base claim is that back door access makes security weaker. Do you disagree?
I’ve been downvoted to oblivion simply for stating my view; also not necessary.
Secret police worked when criminals were put away with parallel reconstruction, for instance. (This being borne of limitations with the anachronistic constitutional notions of civil liberties in the rapidly evolving digital age). I’m all for reducing abuses of surveillance systems, but frankly it’s tech oligarchs who own us, not as much the nsa.
“You can’t stop math.” Not true, strictly anyway. You can ban tech oligarchs from using unbreakable E2EE which slows it down and reduces the proliferation of digital entropy.
Backdoors are an antiquated way of implementing exceptional access. The proper way is to provide third party access that is truly exceptional (living up to the name), and not based on flaws that a malicious actor or rogue nation can break. Instead of E2EE, how about building E2E2EE. Doesn’t need to be measurably weaker.
Sorry on my phone, response isn’t nuanced.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#64Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
I think the history of crypto exchange hacks should be of interest here.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#65Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
https://www.cdt.org/wp-content/uploads/pdfs/paper-key-escrow...
And this from 2015:
https://academic.oup.com/cybersecurity/article/1/1/69/236706...
See also https://cdt.org/insights/the-nsas-split-key-encryption-propo...
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#66Earlier quoted context omitted.
Then again, given speeding is so widely accepted, radar detectors are legal to use in 49 out of 50 states. It would be nice if encryption was viewed the same way.
Isn't (relatively) strong encryption legal in every one of your 50 states and deployed to more than 10^10 devices globally?
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#67I’ve posted plenty of times on HN about the danger of the government being overly involved in tech and the last thing you should want if you value your liberty is more government involvement. I’ve also warned that giving government more power to “protect” people from big tech would come back to bite the very people who for some strange reason trust government. Every time I’ve been downvoted to oblivion. Now the chick…
So, you can't trust the government to oversee the tech companies. You can't trust companies to protect privacy. You can't trust voters/users to make good decisions on voting for the government or choosing the "right" companies to support. That doesn't leave a lot of options, unfortunately.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#68Conspiracy theory: The NSA hamfistedly contributed to various leaks in the same way the CIA gave guns to terrorists, i.e. by providing various groups with the tools they'd need to break into American companies. Now they can capitalize on it - "see, tech companies can't be trusted with your data. Trust us instead."
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#69Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Make a door, it won't stay secret. And you can't assure that there won't be bad actors involved in any number of parties that have to agree.
The whole backdoor system, once it exists, is open to subversion and/or misuse. The only way to not have the problem is not create the door in the first place.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#70Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Example: None of us case about midget porn. If we all agree that banning midget porn will not have an impact on anyone, government then quickly moves on to octopus porn. Now, on a matter of principle you will find your position weaker and weaker.