To me, this seems like only one very passionate side of an important debate. A big question I have is, "how likely is this legislation to actually become law?" UK and Australia passed similar laws, sure, but they also banned guns and that's not gonna happen here.
DOJ plans to strike against encryption while the Techlash iron is hot
91–100 of 347 posts
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#92Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Judge, Jury & Encryptioner: Exceptional Access with a Fixed Social Cost
https://arxiv.org/abs/1912.05620
> We present Judge, Jury and Encryptioner (JJE) an exceptional access scheme for unlocking devices that does not give unilateral power to any single authority and places final approval to unlock in the hands of peer devices. Our scheme, JJE, distributes maintenance of the protocol across a network of "custodians" such as courts, government agencies, civil rights watchdogs and academic institutions. Unlock requests, however, can only be approved by a randomly selected set of unlock delegates, consisting of other peer devices that must be physically located to gain access. This requires that law enforcement expend both human and monetary resources and pay a "fixed social cost" in order to find and request the participation of law abiding citizens in the unlock process.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#93Re: DOJ plans to strike against encryption while the Techlash iron is hot
#94Re: DOJ plans to strike against encryption while the Techlash iron is hot
#95Earlier quoted context omitted.
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
> 3 or more people in geographically diverse areas Sure, a system could be designed where the “master key that unlocks everything” is distributed - that makes the problem of the attacker who wants to get his hands on that key slightly harder, because now he has to compromise three systems instead of one, but that doesn’t change the fundamental risk, which is that he can do that in the first place. Remember, you’re ta…
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#96Earlier quoted context omitted.
> Yes, it’s serious (in response to your handle). I don’t think it’s necessary to create a throwaway to respond and is also against hn policy. Not a throwaway. I'm a lurker who was stunned into commenting. As for E2E2EE, this doesn't solve the bad actors problem. Here is exactly why this wont work: https://www.nytimes.com/2019/11/06/technology/twitter-saudi-...
The article you linked is an example of why offering access to employees who aren’t properly vetted, don’t have security clearances is a bad idea. Further, a proper exceptional access system, in my view, will aim to reduce abuses as described in the article you’ve linked, perhaps even using a design that offers technologically enforced checks and balances against abuses.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#97A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#98> the “techlash” by Congress and the public “in the wake of myriad privacy scandals” and the 2016 election This just makes my head explode. Because tech companies tend to be poor at privacy, let's use that logic to make it so the government can invade your privacy anytime they want?
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#99Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
It's not feasible to ban people from using their own encryption unless you plan on severely restricting their freedom.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#100Earlier quoted context omitted.
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Maybe something like this? Judge, Jury & Encryptioner: Exceptional Access with a Fixed Social Cost https://arxiv.org/abs/1912.05620 > We present Judge, Jury and Encryptioner (JJE) an exceptional access scheme for unlocking devices that does not give unilateral power to any single authority and places final approval to unlock in the hands of peer devices. Our scheme, JJE, distributes maintenance of the protocol across…
https://cseweb.ucsd.edu/~savage/papers/lawful.pdf
Lawful Device Access without Mass Surveillance Risk:A Technical Design Discussion
> This paper proposes a systems-oriented design for supporting court-ordered data access to “locked” devices with system-encrypted storage, while explicitly resisting large-scale surveillance use. We describe a design that focuses entirely on passcode self-escrow(i.e., storing a copy of the user passcode into a write-only component on the device) and thus does not require any changes to underlying cryptographic algorithms. Further, by predicating any lawful access on extended-duration physical seizure, we foreclose mass-surveillance use cases while still supporting reasonable investigatory interests. Moreover, by couching per-device authorization protocols with the device manufacturer, this design avoids creating new trusted authorities or organizations while providing particularity (i.e., no “master keys” exist). Finally, by providing a concrete description of one such approach, we hope to encourage further technical consideration of the possibilities and limitations of trade-offs in this design space.