This will only hit innocent people or low-level criminals, the real bad actors will find ways around it.
DOJ plans to strike against encryption while the Techlash iron is hot
121–130 of 347 posts
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#122The older I get the less hope I see of people learning anything from history. Perhaps we really are doomed to repeat it.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#123Earlier quoted context omitted.
> They provided the DOJ backdoor access. If you're thinking of PRISM, no, at least not in the voluntary, intentional sense of the word "provided". Many of the major tech companies had non-public backbone fiber, and links across that fiber were unencrypted. The NSA tapped this dark fiber to read unencrypted traffic. This famously hit Google, which subsequently moved to encrypt all internal traffic, even traffic that w…
Wouldn’t tapping dark fibre be a bit useless? Or were the links tapped while dark waiting for the target to start using them?
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#124Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
When done correctly and with everyone's knowledge and consent, this is a form of key escrow. But there's some simple math at play here - the more unlock options there are, the more points of vulnerability and failure. https://haveibeenpwned.com/ lists 8 breaches of my data and I'm aware of more they don't list - the industry can't even keep my data under lock and key without adding more points of failure via key escrow as another thing they can fuck up.
> For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were in a position to agree that a request for information was legitimate (by court order) and thereby produce what is needed to unlock certain information? So one person would not have the key or access.
Bitcoin is a great example, in a way - there are several stories out there of exchanges fucking up and losing access to their coins or having their coins stolen, even when they were using cold storage. All 3 people will likely be duped by the same fradulent (or just overreaching) LEO email, in part because of the all too human tendency for each of them to assume that "one of the other two would have caught it if it was fishy, right?"
> After all right now you have a case where a single person (the owner) is able to unlock information. The feeling is a back door can be hacked. What if it's not a back door though?
The label you use doesn't matter - the more people who can unlock things, the more points of failure you have, and the more likely things will end up hacked. The industry struggles enough to secure things even when it takes a hard line approach and espouses end-to-end encryption. Defending against abuse by insiders/employees usually means going through a bunch of trouble to lock your own employees out of customer data - or making it unavailable to the company in the first place - not giving them more tools to access it.
Governments already have more than enough tools to completely pwn my privacy if they actually need to. Convince a judge to sign a sneak and peek warrant, have law enforcement covertly install a hardware keylogger, and I'd wager you'll pwn most people - even if they're tech savy. But that requires pesky things like indivudalized suspicion, "checks and balances", actual work, and involving multiple people (your landlord or a locksmith for the keys or entry access, your security company to silence the alarms, a judge to sign off on the warrant and a leo to execute it) so it's harder to run a long term secret warrantless suspicionless mass surveilance dragnet as a rogue employee or agency. But not impossible, as certain three letter agencies have shown.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#125Earlier quoted context omitted.
Shamir secret sharing allows for that on paper. The problem is that to be useful for law enforcement, any local police department has to be able to go to any local judge and get a warrant and then get access. There are approximately 30,000 state judges with fairly high turnover in that list. If you can compromise one, or successfully get yourself added to that list, you can then get access to whatever you want. That'…
This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company. While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight. Note that strong network encryption is essential for ensuring that they have to get a warrant. I don't…
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#126Earlier quoted context omitted.
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Apart from what others said, there is also the following problem. People won't like this and will start encrypting traffic with non-compromised algorithms. Given that properly encrypted traffic appears random, how would you enforce the requirement that everyone uses the state-sanctioned, compromised algorithm? In order to check and enforce, you'd have to turn this into an online, warrantless, dragnet-style system, th…
The article below argues that the real use case for breaking encryption is to catch everyday criminals, not to go after shadowy Bond villains. Would the public still go for it, if they looked at it this way? Probably not...
The Encryption Debate Isn't About Stopping Terrorists, It's About Solving Crime https://www.lawfareblog.com/encryption-debate-isnt-about-sto...
Edit: And most everyday criminals are not technologically savvy. Half of them probably have a hard time using Telegram safely.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#127Earlier quoted context omitted.
> why people would say mathematical functions are bad. People don't think 'encryption' is a mathematical function. They think it's like a radar detector in your car. "Why would you have it unless you intend on speeding?" [goes their thought process] "Oh I use this frequently and things I do every day would be totally broken without it? Really?!" [is the realization we hope dialogue could bring]
Then again, given speeding is so widely accepted, radar detectors are legal to use in 49 out of 50 states. It would be nice if encryption was viewed the same way.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#128Earlier quoted context omitted.
Dangerous analogy to offer in an argument. The easy reply: "The Government can get a warrant to read my mail today. All I'm asking is for the same capability online, so they can get warrants to read pedophile and terrorist messages"
And isn't that a valid point to make?
In the real world, resources are naturally constrained. It's usually impossible to read everyone's mail in real time and retroactively pull up the contents of a letter sent 3 years ago. This limitation vanishes with online communications. Encrypted messages can be stored indefinitely and later decrypted.
The super safe backdoor we build today could very easily be used by a tyrannical regime a decade from now to get dirt on everyone. We can dream up all sorts of technical solutions that allow for a backdoor, but make it really hard to abuse, but at the bottom, those solutions rely on the government obeying their own law.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#129How is the DoJ going to force Signal or even Telegram to add a back door?
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#130Earlier quoted context omitted.
It sounds like a majority of the students had no idea what encryption was and because the authority figure (the professor) asked them whether or not it was bad they just went with it? I'm having trouble understanding why people would say mathematical functions are bad.
> I'm having trouble understanding why people would say mathematical functions are bad. That's such a naïve way of putting it. People don't care about the mathematics behind it. They think it's "bad" because they think it enables terrorism and the spread of child sexual abuse imagery or whatever politicians have led them to believe.
That is not all it does, but pretending it does not is stupid.