I was talking to a layperson about encryption and privacy and they were very much against both interestingly. They compared encryption to wearing a mask in public and said if people don't want to be noticed (w.r.t privacy and encryption) they shouldn't be "participating" (it was unclear what they meant by this). Just goes to show you how the average person thinks about these things. I have to admit I wouldn't like it…
Ask them if they'd be ok with the mailman reading all their ingoing and outgoing mail. If they say "Yes", at least they're being consistent.
DOJ plans to strike against encryption while the Techlash iron is hot
71–80 of 347 posts
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#72A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…
So in an ethics discussion the professor simply asked "is X bad?" That doesn't seem like a very enlightened ethics discussion. How certain are you he said "bad"? If he has instead asked "is encryption problematic?", the outcome can be interpreted much differently because there are problems with encryption. Especially in an ethics discussion, there are definitely pros and cons to encryption. (FWIW, the pros outweigh t…
I have no idea what tack this prof took with the question, but I think you've drawn a hasty conclusion here.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#73I was talking to a layperson about encryption and privacy and they were very much against both interestingly. They compared encryption to wearing a mask in public and said if people don't want to be noticed (w.r.t privacy and encryption) they shouldn't be "participating" (it was unclear what they meant by this). Just goes to show you how the average person thinks about these things. I have to admit I wouldn't like it…
Ask them if they'd be ok with the mailman reading all their ingoing and outgoing mail. If they say "Yes", at least they're being consistent.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#74Earlier quoted context omitted.
> I’m personally okay with secret police What? Why are you ok with secret police? Where has this idea ever worked? > I find it interesting that the hn world is largely unified in beliefs about the trade-offs of exceptional access that aren’t necessarily true. Which trade-offs are you suggesting aren't true? The base claim is that back door access makes security weaker. Do you disagree?
Yes, it’s serious (in response to your handle). I don’t think it’s necessary to create a throwaway to respond and is also against hn policy. I’ve been downvoted to oblivion simply for stating my view; also not necessary. Secret police worked when criminals were put away with parallel reconstruction, for instance. (This being borne of limitations with the anachronistic constitutional notions of civil liberties in the…
Not a throwaway. I'm a lurker who was stunned into commenting.
As for E2E2EE, this doesn't solve the bad actors problem.
Here is exactly why this wont work: https://www.nytimes.com/2019/11/06/technology/twitter-saudi-...
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#75Earlier quoted context omitted.
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Shamir secret sharing allows for that on paper. The problem is that to be useful for law enforcement, any local police department has to be able to go to any local judge and get a warrant and then get access. There are approximately 30,000 state judges with fairly high turnover in that list. If you can compromise one, or successfully get yourself added to that list, you can then get access to whatever you want. That'…
While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight.
Note that strong network encryption is essential for ensuring that they have to get a warrant.
I don't think anyone has come up with a better system than judicial oversight that still allows law enforcement to do their job?
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#76Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Cant fix technology problems with people processes.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#77Isn’t the tech lash for the complete opposite reasons? The fact that too many people have too much of our data? Why would people (outside of effective propaganda, which would be true even without the tech lash) support something that makes their problems worse?
For example, a friend worked at a proprietary hedge fund of a major US bank that was looking into the private accounts of their customers to drive trading decisions. Other investors can't compete against that, stock market investment is no longer fair. And you've broken a fundamental component of the economy, a fair & transparent investment system.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#78Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Sure, a system could be designed where the “master key that unlocks everything” is distributed - that makes the problem of the attacker who wants to get his hands on that key slightly harder, because now he has to compromise three systems instead of one, but that doesn’t change the fundamental risk, which is that he can do that in the first place. Remember, you’re talking about one piece (or three pieces) of information which can be used to decode every single secret in the United States - this isn’t limited by technical feasibility, this is the explicit end goal that you’re asking for. If Russian hackers got a hold of it undetected, they could decrypt everything for a very long time. Even if it were revealed that it were compromised, everything that was encrypted using the old key would have to be re-encrypted somehow, and the old copies destroyed somehow.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#79Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
Wasn't this how Google, Adobe and several other tech companies had a major security breach about 5-7 years ago? They provided the DOJ backdoor access.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#80A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…
It sounds like a majority of the students had no idea what encryption was and because the authority figure (the professor) asked them whether or not it was bad they just went with it? I'm having trouble understanding why people would say mathematical functions are bad.