Earlier quoted context omitted.
Yes, it’s serious (in response to your handle). I don’t think it’s necessary to create a throwaway to respond and is also against hn policy. I’ve been downvoted to oblivion simply for stating my view; also not necessary. Secret police worked when criminals were put away with parallel reconstruction, for instance. (This being borne of limitations with the anachronistic constitutional notions of civil liberties in the…
> I’ve been downvoted to oblivion simply for stating my view; also not necessary. I personally downvoted because I believe your statement is wrong in fact and problematic in opinion. > Secret police worked when criminals were put away with parallel reconstruction, for instance. Parallel construction is a morally dubious method of hiding illegal and unconstitutional activity on law enforcement's part. What crime was t…
DOJ plans to strike against encryption while the Techlash iron is hot
151–160 of 347 posts
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#152Earlier quoted context omitted.
> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…
Apart from what others said, there is also the following problem. People won't like this and will start encrypting traffic with non-compromised algorithms. Given that properly encrypted traffic appears random, how would you enforce the requirement that everyone uses the state-sanctioned, compromised algorithm? In order to check and enforce, you'd have to turn this into an online, warrantless, dragnet-style system, th…
In practice even the tech types weary of using and maintaining truly secure solutions. So if they outlaw backdoor-less solutions then companies won't support them. And without commercial support the options will dwindle.
And even donation supported projects like Truecrypt will fold under pressure.
Crypto isn't a one-person job
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#153Earlier quoted context omitted.
"Offer" is perhaps an overly positive term. The DOJ has issued a number of speeches, letters, etc. insisting that tech companies must build a backdoor to let the government decrypt messages as required.
I know but I have never heard any details especially how they want to keep the backdoor secret. Cracking the backdoor would be such a high value target that a lot of people would spend insane amounts of money and energy on it.
[1] https://www.justice.gov/opa/speech/attorney-general-william-...
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#154A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…
So in an ethics discussion the professor simply asked "is X bad?" That doesn't seem like a very enlightened ethics discussion. How certain are you he said "bad"? If he has instead asked "is encryption problematic?", the outcome can be interpreted much differently because there are problems with encryption. Especially in an ethics discussion, there are definitely pros and cons to encryption. (FWIW, the pros outweigh t…
That is an apt summary of my college ethics discussions. Even in cases where the professor was doing their best to encourage discussion, the majority of the class couldn't think beyond first order effects and hypotheticals would quickly get emotional and devolve into character attacks.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#155If you were forced to design an exceptional access system that minimized abuses and risks of compromise, how would you do it?
One way to do data-at-rest (e.g. a locked phone) is to require physical access to the phone along with some kind of expensive, destructive procedure (e.g. an electron tunneling microscope and shaving away the housing of the secure enclave area).
Also, I'd assume that any competent target would just layer their own encryption on top of the existing stuff, so the whole system would only be good for catching unsophisticated criminals (and spying on the general public).
Or I'd just subpoena the iCloud backups and have Apple decrypt them, which they can already do.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#156Are there any concrete proposals on the table that can be looked at? This feels to me like one of the typical debates where people are shooting at each other but nobody understands what they really are talking about.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#157Earlier quoted context omitted.
> They provided the DOJ backdoor access. If you're thinking of PRISM, no, at least not in the voluntary, intentional sense of the word "provided". Many of the major tech companies had non-public backbone fiber, and links across that fiber were unencrypted. The NSA tapped this dark fiber to read unencrypted traffic. This famously hit Google, which subsequently moved to encrypt all internal traffic, even traffic that w…
You are mistaken. PRISM is specifically a program that "collects stored internet communications based on demands made to internet companies" [em. mine]. NSA wiretapping the non-public links of Google et ol was not PRISM (I'm not even sure that the name of that program was ever disclosed).
The NSA placed key people into companies like Google who had security clearances that specifically forbade them from saying exactly what they were doing to higher ups. They then created systems for extracting data in an automated way based on requests from the NSA. All that executives knew was that they were doing something important for complying with law enforcement requests.
The CEOs of these companies learned about the existence of the back doors from public reporting based on Snowden's revelations. When they first heard, they issued public denials that were, as far as they knew, truthful. Their subsequent actions upon finding out that they were wrong strongly suggest that they wouldn't have approved the programs had they known what was happening.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#158Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…
> Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide everyone else protection from evildoers while letting law enforcement find the bad guys Wasn't this how Google, Adobe and several other tech companies had a major security breach about 5-7 years ago? They provided the DOJ backdoor access.
https://arstechnica.com/tech-policy/2020/02/us-gave-allies-e...
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#159Seriously question, how are they going to stop me from downloading signal from source, building it locally, and installing it on my and everyone i knows cell phones?
Why would they try to stop you, when they could just order Apple or Google to push out a backdoored update to the OS?
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#160Earlier quoted context omitted.
This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company. While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight. Note that strong network encryption is essential for ensuring that they have to get a warrant. I don't…
> that still allows law enforcement to do their job? Do libraries not keeping records of who has read what books not allow law enforcement to do their job? Do prohibitions against arbitrary searches not allow law enforcement to do their job? Does having to make a plausible argument in front of a judge not allow law enforcement to do their job? Do individuals not having a number tattooed on their forehead not allow la…
In the US, the idea of the publicly funded law enforcement officer can trace its lineage back to antebellum slave catchers.
Much like they now (and forever) frame any perceived difficulty as preventing them from doing their job, they've successfully re-framed their role in society as protecting and serving (people) instead of protecting and serving (property rights), despite that obviously not being the case.