Live data from Hacker News

DOJ plans to strike against encryption while the Techlash iron is hot

cyberlaw.stanford.edu

111–120 of 347 posts

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#111
post #21

Questions to the public should be phrased: “Do you want Chinese style surveillance to be advanced in the United States?”

+1. This is something tech bros don't seem to get, while politicians get very well: the majority is driven by emotions and has small cognitive ability, but they vote and thus arguments to win their vote must be trivial emotionally charged ideas. A politician says "encryption is a tool of criminals!" and those who start arguing in the rational plane have already lost; instead, the answer should be "lack of encryption enables Chinese style totalitarian communism!" - no need to explain the details, just push their "scary communism" button and let the public contemplate on the "crime vs communism" topic.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#112

I’ve posted plenty of times on HN about the danger of the government being overly involved in tech and the last thing you should want if you value your liberty is more government involvement. I’ve also warned that giving government more power to “protect” people from big tech would come back to bite the very people who for some strange reason trust government. Every time I’ve been downvoted to oblivion. Now the chick…

So, you can't trust the government to oversee the tech companies. You can't trust companies to protect privacy. You can't trust voters/users to make good decisions on voting for the government or choosing the "right" companies to support. That doesn't leave a lot of options, unfortunately.

Before just responding with all the ways this could go wrong immediately, I'm making clear that this is a discussion point, not a call to action. I'm aware of a lot of the immediate problems this suggestion could cause, I'm not posting this lightly. So:

As an expression of the extreme opposite end of all this, a talking point: what would happen if we simply stopped hiding information? Open up every server, make lists of name/add/SSN/credit info, medical, legal, everything under the sun open? Governments, too. And every company. Find every 'secured' server and remove all access restrictions, every machine, everywhere.

No doubt there would be about a generation or two worth of chaos, as everyone learns everything about everyone and we figure out new ways to protect ourselves from the bad actors/stalkers/black ops people now in the open, etc etc etc.

What would we look like as people and as a society?

Could we learn to be honest and aboveboard and treat each other with respect, instead of taking advantage of each other because of all the secrets and perceived leverage?

Remember, in this new world, all the corporate info is out there to see, all the personal details and dealings of the manipulators as well as us peons.

How hard is it going to be to be Google, profiting off marketed secrets, when there aren't any?

How hard is it going to be to peddle misinformation, when the actual history is there for anyone to look at?

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#113
post #62

Earlier quoted context omitted.

Shamir secret sharing allows for that on paper. The problem is that to be useful for law enforcement, any local police department has to be able to go to any local judge and get a warrant and then get access. There are approximately 30,000 state judges with fairly high turnover in that list. If you can compromise one, or successfully get yourself added to that list, you can then get access to whatever you want. That'…

This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company. While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight. Note that strong network encryption is essential for ensuring that they have to get a warrant. I don't…

Part of it is how we scope law enforcement's job. Thanks to technology there's tremendous growth in the amount of information about people. Traditionally law enforcement needs to find evidence that a person may have committed a crime, not necessarily prove a crime. Limited availability of data makes it less likely that law enforcement finds evidence on innocent people.

My take is that even with a warrant, law enforcement's reach into private data should be limited for a free society.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#114

Earlier quoted context omitted.

> Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide everyone else protection from evildoers while letting law enforcement find the bad guys Wasn't this how Google, Adobe and several other tech companies had a major security breach about 5-7 years ago? They provided the DOJ backdoor access.

> They provided the DOJ backdoor access. If you're thinking of PRISM, no, at least not in the voluntary, intentional sense of the word "provided". Many of the major tech companies had non-public backbone fiber, and links across that fiber were unencrypted. The NSA tapped this dark fiber to read unencrypted traffic. This famously hit Google, which subsequently moved to encrypt all internal traffic, even traffic that w…

Wouldn’t tapping dark fibre be a bit useless? Or were the links tapped while dark waiting for the target to start using them?

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#115
post #57

Earlier quoted context omitted.

OTPs are impractical to use for average people, while their use is entirely tractable (and widespread) for covert operations.

Everything technological is impractical to use for average people until people like us go out and build a practical solution. OTP is not a very complicated scheme. All you need is a good source of entropy, a place to store a big fat array of it all, some XOR operations, and a safe way to hand the codebook to your trusted parties (e.g. phone-to-phone transfer options).

One time pads are not secure by modern cryptographic standards.

Elaboration: https://news.ycombinator.com/item?id=6008695

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#116

A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…

I think we in the tech community tend to vastly under-estimate the threat of legal restrictions on encryption. When the public gets scared, they look to governments to "do something", whether that something is really a smart thing or not.

If we're unlucky and we get caught unprepared, we run the risk of getting stuck with a backdoor or "exceptional access" mechanism that provides little or no technical safeguards against massive and nearly unlimited government overreach.

IMO this makes it our responsibility to figure out how we might design such a system that does have strong protections against misuse. Of course that is a very difficult thing to do. Doesn't mean we shouldn't try.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#117
post #6

Isn’t the tech lash for the complete opposite reasons? The fact that too many people have too much of our data? Why would people (outside of effective propaganda, which would be true even without the tech lash) support something that makes their problems worse?

In fact, user data usage and share is a multi-faceted issue. The most obvious stances are (but not limited to):

  * Pro-privacy claims that big techs share their user data to too many irrelevant entities.
  * Pro-competition claims that big techs monopolize uses of their user data.
  * Pro-regulation claims that big techs don't share their user data to accountable government entities.
Each of those arguments has some valid points but also conflicts to each other in a some degree.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#119
post #36

Earlier quoted context omitted.

It sounds like a majority of the students had no idea what encryption was and because the authority figure (the professor) asked them whether or not it was bad they just went with it? I'm having trouble understanding why people would say mathematical functions are bad.

Encryption allows data to be locked away from the government including law enforcement and prosecutors in a way that was nearly impossible for the average citizen a few decades ago. Warrants can't break encryption like they could doors or locks. As much of life moves to the digital world and becomes encrypted, that can be a drastic change in how the justice system works. Pro-encryption people need to keep this in min…

I always have trouble imagining examples of this kind of evidence that criminals were previously utterly unable to hide but can now do it easily using encryption. It seems any kind of evidence could had just been shredded and burned in times past or hidden in an obscure, physical safe that no one knows about. If anything, the digital age had made the location of evidence more obvious and even produced entirely new kinds of evidence (traffic and connection logs, emails, etc).

It seems to me that law enforcement is simply pining for the fjords of a very short time span in human history when ample digital information co-existed with the lack of widely available cryptographic systems.

Post reply on HN