Live data from Hacker News

DOJ plans to strike against encryption while the Techlash iron is hot

cyberlaw.stanford.edu

71–80 of 347 posts

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#71

I was talking to a layperson about encryption and privacy and they were very much against both interestingly. They compared encryption to wearing a mask in public and said if people don't want to be noticed (w.r.t privacy and encryption) they shouldn't be "participating" (it was unclear what they meant by this). Just goes to show you how the average person thinks about these things. I have to admit I wouldn't like it…

Ask them if they'd be ok with the mailman reading all their ingoing and outgoing mail. If they say "Yes", at least they're being consistent.

I think that you might be disappointed with the response. Postcards are a thing for example.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#72

A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…

So in an ethics discussion the professor simply asked "is X bad?" That doesn't seem like a very enlightened ethics discussion. How certain are you he said "bad"? If he has instead asked "is encryption problematic?", the outcome can be interpreted much differently because there are problems with encryption. Especially in an ethics discussion, there are definitely pros and cons to encryption. (FWIW, the pros outweigh t…

Asking about a nuanced subject in broad and blunt terms can be pedagogically useful because you hear what people really think, unfiltered ... and maybe they hear it too, priming them to realize that they've been underthinking the topic. From there you can get into nuance, which is easier when you know where you currently stand.

I have no idea what tack this prof took with the question, but I think you've drawn a hasty conclusion here.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#73

I was talking to a layperson about encryption and privacy and they were very much against both interestingly. They compared encryption to wearing a mask in public and said if people don't want to be noticed (w.r.t privacy and encryption) they shouldn't be "participating" (it was unclear what they meant by this). Just goes to show you how the average person thinks about these things. I have to admit I wouldn't like it…

Ask them if they'd be ok with the mailman reading all their ingoing and outgoing mail. If they say "Yes", at least they're being consistent.

Dangerous analogy to offer in an argument. The easy reply: "The Government can get a warrant to read my mail today. All I'm asking is for the same capability online, so they can get warrants to read pedophile and terrorist messages"

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#74

Earlier quoted context omitted.

> I’m personally okay with secret police What? Why are you ok with secret police? Where has this idea ever worked? > I find it interesting that the hn world is largely unified in beliefs about the trade-offs of exceptional access that aren’t necessarily true. Which trade-offs are you suggesting aren't true? The base claim is that back door access makes security weaker. Do you disagree?

Yes, it’s serious (in response to your handle). I don’t think it’s necessary to create a throwaway to respond and is also against hn policy. I’ve been downvoted to oblivion simply for stating my view; also not necessary. Secret police worked when criminals were put away with parallel reconstruction, for instance. (This being borne of limitations with the anachronistic constitutional notions of civil liberties in the…

> Yes, it’s serious (in response to your handle). I don’t think it’s necessary to create a throwaway to respond and is also against hn policy.

Not a throwaway. I'm a lurker who was stunned into commenting.

As for E2E2EE, this doesn't solve the bad actors problem.

Here is exactly why this wont work: https://www.nytimes.com/2019/11/06/technology/twitter-saudi-...

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#75
post #62
post #52

Earlier quoted context omitted.

> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…

Shamir secret sharing allows for that on paper. The problem is that to be useful for law enforcement, any local police department has to be able to go to any local judge and get a warrant and then get access. There are approximately 30,000 state judges with fairly high turnover in that list. If you can compromise one, or successfully get yourself added to that list, you can then get access to whatever you want. That'…

This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company.

While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight.

Note that strong network encryption is essential for ensuring that they have to get a warrant.

I don't think anyone has come up with a better system than judicial oversight that still allows law enforcement to do their job?

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#76
post #52
post #14

Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…

> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…

You can safeguard the process the government needs to go through to get approval to decrypt things all you want. That doesn't stop bad actors separate from the government from finding and taking advantages of the vulnerabilities introduced by enabling the government to forcibly decrypt things.

Cant fix technology problems with people processes.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#77
post #6

Isn’t the tech lash for the complete opposite reasons? The fact that too many people have too much of our data? Why would people (outside of effective propaganda, which would be true even without the tech lash) support something that makes their problems worse?

Exactly. But for the people that want that data, for the people who will pay for it, FUD is a great political tool, and this issue is too subtle for most people to get. I've tried to explain to my family, how the abdication of private behavior logs to some companies is creating economic/political inequality that may forever destroy norms of fairness & competitiveness that we enjoy, but they just don't get it...

For example, a friend worked at a proprietary hedge fund of a major US bank that was looking into the private accounts of their customers to drive trading decisions. Other investors can't compete against that, stock market investment is no longer fair. And you've broken a fundamental component of the economy, a fair & transparent investment system.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#78
post #52
post #14

Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…

> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…

> 3 or more people in geographically diverse areas

Sure, a system could be designed where the “master key that unlocks everything” is distributed - that makes the problem of the attacker who wants to get his hands on that key slightly harder, because now he has to compromise three systems instead of one, but that doesn’t change the fundamental risk, which is that he can do that in the first place. Remember, you’re talking about one piece (or three pieces) of information which can be used to decode every single secret in the United States - this isn’t limited by technical feasibility, this is the explicit end goal that you’re asking for. If Russian hackers got a hold of it undetected, they could decrypt everything for a very long time. Even if it were revealed that it were compromised, everything that was encrypted using the old key would have to be re-encrypted somehow, and the old copies destroyed somehow.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#79
post #14

Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…

> Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide everyone else protection from evildoers while letting law enforcement find the bad guys

Wasn't this how Google, Adobe and several other tech companies had a major security breach about 5-7 years ago? They provided the DOJ backdoor access.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#80

A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…

It sounds like a majority of the students had no idea what encryption was and because the authority figure (the professor) asked them whether or not it was bad they just went with it? I'm having trouble understanding why people would say mathematical functions are bad.

I hope those people access their bank over port 80.
Post reply on HN