Live data from Hacker News

DOJ plans to strike against encryption while the Techlash iron is hot

cyberlaw.stanford.edu

131–140 of 347 posts

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#131
post #36

Earlier quoted context omitted.

It sounds like a majority of the students had no idea what encryption was and because the authority figure (the professor) asked them whether or not it was bad they just went with it? I'm having trouble understanding why people would say mathematical functions are bad.

Encryption allows data to be locked away from the government including law enforcement and prosecutors in a way that was nearly impossible for the average citizen a few decades ago. Warrants can't break encryption like they could doors or locks. As much of life moves to the digital world and becomes encrypted, that can be a drastic change in how the justice system works. Pro-encryption people need to keep this in min…

> Criminals being able to hide evidence is a serious concern for the average person.

Suspects. Alleged criminals. Until convicted, they're not criminals. The government does not have an unlimited right to collect all information; they have a limited, judicially controlled right to try to collect information.

One key detail: strong encryption does not prevent investigations from targeted collection of information, such as through physical surveillance, bugs, etc. There are many tools available to law enforcement, those tools are just less convenient. Framing it that way helps: in order to make investigations more convenient, the DOJ wants to prevent anyone from using secure communications.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#132

Earlier quoted context omitted.

Dangerous analogy to offer in an argument. The easy reply: "The Government can get a warrant to read my mail today. All I'm asking is for the same capability online, so they can get warrants to read pedophile and terrorist messages"

And isn't that a valid point to make?

Well, at first sight yes, but a) they would gather everything instead of just actual targets and b) their access could not be protected properly from third parties who are not authorized.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#133

Earlier quoted context omitted.

> Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide everyone else protection from evildoers while letting law enforcement find the bad guys Wasn't this how Google, Adobe and several other tech companies had a major security breach about 5-7 years ago? They provided the DOJ backdoor access.

> They provided the DOJ backdoor access. If you're thinking of PRISM, no, at least not in the voluntary, intentional sense of the word "provided". Many of the major tech companies had non-public backbone fiber, and links across that fiber were unencrypted. The NSA tapped this dark fiber to read unencrypted traffic. This famously hit Google, which subsequently moved to encrypt all internal traffic, even traffic that w…

You are mistaken. PRISM is specifically a program that "collects stored internet communications based on demands made to internet companies" [em. mine]. NSA wiretapping the non-public links of Google et ol was not PRISM (I'm not even sure that the name of that program was ever disclosed).

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#134

Earlier quoted context omitted.

Ask them if they'd be ok with the mailman reading all their ingoing and outgoing mail. If they say "Yes", at least they're being consistent.

Dangerous analogy to offer in an argument. The easy reply: "The Government can get a warrant to read my mail today. All I'm asking is for the same capability online, so they can get warrants to read pedophile and terrorist messages"

The easy counter: "Except encryption works on maths; a mathematical "warrant" is more like a skeleton key that applies to every single letter ever sent and every safe ever made and every house ever built – and not one of those fancy keys that's hard to forge, because it's data; once you've seen one, you can just copy it and use it without anybody ever knowing. What happens if [terrorists] see one of these "warrants"?"

And to pre-empt: "And no, we haven't discovered the maths to make it not work like that. Nothing we know about comes even close, and such mathematics might not even exist."

A slightly more abstract counter:

> The government can get a warrant to read your letters. The law can regulate that, and there's no way they can get a warrant to read everybody's letters; only suspects will have their letters read. But these are computers. A computer could just go through, unlocking and reading everybody's letters, and looking for — look, imagine a future, slightly more evil government decides that puppies are illegal. A computer could look through everyone's letters for anybody who'd ever been pro-puppy, and then fine them for puppy-supporting, and then anybody who continues to support puppies would be put in prison. I know that puppies are a stupid example, but imagine that the government really wants to start a war, or something, and you disagree, and the election's coming up, and you can't talk about maybe not starting that war.

> Okay, so you trust this government, and all future governments, not to do that? Do you trust every single person who's ever seen a warrant? Say you want to get a job, but you can't, because you maybe don't want to save the pandas while children are starving in [impoverished nation] and you said so in a message to a partner three years back and your employer does a quick background check with some company somewhere and it comes back "[person's name] does not like pandas". It's your dream job, and now they don't want to hire you because the HR person is a really big fan of pandas. I'm picking innocuous examples, but come on, you can think of more significant ones. (And those background check companies already exist – they literally Twitter-stalk people; do you really think they'd ignore private conversations if they had access to them?)

> Do you trust anybody who's ever seen a warrant with your bank details? Sure, those skeleton keys will be kept fairly secure, but it only takes one person to make a mistake and then every single message that's ever touched a computer, past, present and future, is public.

> Or they could just look at the lock and figure out what shape of skeleton key would fit it. That's how all of the other backdoors the government put in computer systems like this were spotted. And once you've spotted it, you can just decrypt everything almost instantly, because you're just getting the computers to do maths and computers are fast at maths.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#135
post #4

Interesting to read in context of the fact that public sentiment surveys suggest there is no “techlash” at all.

Overly large companies wield disproportionately large amounts of influence in our lives and probably should be regulated more. But that disproportionate influence doesn't mean "tech" is the root cause.

There shouldn't be a backlash against tech companies specifically, but really companies that are overly large and use and abuse their power and position in ways that benefit shareholders in ways that are severely detrimental the common good. Such as limiting competition, influencing and manipulating legislation, ensuring people have no other options and then raising prices exponentially, selling your data to the highest bidder, etc.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#136
post #71

Earlier quoted context omitted.

Ask them if they'd be ok with the mailman reading all their ingoing and outgoing mail. If they say "Yes", at least they're being consistent.

I think that you might be disappointed with the response. Postcards are a thing for example.

I am free to put the postcode in an envelope if I feel the message is private or confidential; terrible example.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#137

Earlier quoted context omitted.

You say “might offer”. Have they offered anything?

"Offer" is perhaps an overly positive term. The DOJ has issued a number of speeches, letters, etc. insisting that tech companies must build a backdoor to let the government decrypt messages as required.

I know but I have never heard any details especially how they want to keep the backdoor secret. Cracking the backdoor would be such a high value target that a lot of people would spend insane amounts of money and energy on it.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#138

This will just push people to open source applications and peer to peer networking. Basically, devolve back to the early days of the internet with regard to person to person communications. How is the DoJ going to force Signal or even Telegram to add a back door?

> How is the DoJ going to force Signal or even Telegram to add a back door?

Hypothetically: they could easily force the Apple and Google stores to stop carrying it, or even to prevent its installation using the same mechanisms used to scan for malware. Do not underestimate the means by which use of real encryption could be made inconvenient.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#139

This will just push people to open source applications and peer to peer networking. Basically, devolve back to the early days of the internet with regard to person to person communications. How is the DoJ going to force Signal or even Telegram to add a back door?

They'll force device manufacturers to give access to keys locally locally. China did it with Apple's iCloud backups by just nationalizing the servers.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#140

Earlier quoted context omitted.

> I’m personally okay with secret police What? Why are you ok with secret police? Where has this idea ever worked? > I find it interesting that the hn world is largely unified in beliefs about the trade-offs of exceptional access that aren’t necessarily true. Which trade-offs are you suggesting aren't true? The base claim is that back door access makes security weaker. Do you disagree?

Yes, it’s serious (in response to your handle). I don’t think it’s necessary to create a throwaway to respond and is also against hn policy. I’ve been downvoted to oblivion simply for stating my view; also not necessary. Secret police worked when criminals were put away with parallel reconstruction, for instance. (This being borne of limitations with the anachronistic constitutional notions of civil liberties in the…

> I’ve been downvoted to oblivion simply for stating my view; also not necessary.

I personally downvoted because I believe your statement is wrong in fact and problematic in opinion.

> Secret police worked when criminals were put away with parallel reconstruction, for instance.

Parallel construction is a morally dubious method of hiding illegal and unconstitutional activity on law enforcement's part. What crime was truly committed to warrant law enforcement's action is therefore hidden.

Using the idea of parallel construction to support secret police is likewise dubious.

> “You can’t stop math.” Not true, strictly anyway. You can ban tech oligarchs from using unbreakable E2EE which slows it down and reduces the proliferation of digital entropy.

When you outlaw guns, only outlaws will have guns.

It's illegal for citizens to download and distribute music and movies too, but illegality doesn't stop them from doing it. You might block tech oligarchs from using it, but you won't be able to block citizens from using it.

Likewise when you outlaw math, only outlaws will have math. Banning tech oligarchs from using unbreakable E2EE won't undo the fact that that encryption has already been created and disseminated in open source repositories.

> The proper way is to provide third party access that is truly exceptional (living up to the name), and not based on flaws that a malicious actor or rogue nation can break. Instead of E2EE, how about building E2E2EE. Doesn’t need to be measurably weaker.

I have yet to see even a single idea which isn't open to abuse by someone, whether it's law enforcement or citizens. And, frankly, the constitution's goals are fairly clear: citizens have rights and law enforcement is prohibited.

Post reply on HN