Live data from Hacker News

DOJ plans to strike against encryption while the Techlash iron is hot

cyberlaw.stanford.edu

251–260 of 347 posts

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#251
post #250

So terrorists will use one-time pads and other strong encryption and everyone else will have their information exposed on a massive scale when the backdoors inevitably are exploited.

I look forward to the day when one time pads are the norm for general encryption. A scifi novel I read, "A Deepness in the Sky" described how the pads themselves were a valuable item of trade. I don't think it's farfetched to imagine purchasing OTP data to use with internet browsing, the way we buy yubikeys to use with passwords. It would be a far simpler encryption scheme than those we currently use, and that simpli…

[deleted]

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#252

Earlier quoted context omitted.

Watching old movies from 60s/70s sometimes have scenes where the characters are worried about calls being recorded or otherwise having no privacy. The typical response is “What is this, Russia?” or something similar. Privacy is really important. I will always error on the side of privacy even if that means not everyone bad is caught.

Freedom isn't free. I think people have just ought to realize that. People have this idea that free countries are more efficient, which is probably true in the long run, but it's a cop-out to just call it a day there. Once I was in Belarus. It's a heavily authoritarian country, make no mistake. When they had protests against their rigged elections, they traced the phones of everyone who went, then brought them in for…

Would Japan qualify as authoritarian? Yet it is safe to leave things out without watching them, except for umbrellas. There are even places in the US where it is safe enough. I doubt these places are more authoritarian but instead allow such social safety because of other reasons. Authoritarianism can, to some extent, replace those reasons if they are lost, but it replaces them with some sort of mutated social structure that I find has far more problems that the original once you look past the surface.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#253

Earlier quoted context omitted.

I've worked on both sides of that, I think you'd be surprised. I also suspect that it's worse at the TLAs and any organization with access to FBI, license plate and various criminal databases. Obviously CCard databases and stuff are off limits as their use is outright fraud, but stuff like traffic cameras, imaging systems, etc.

I don't know about US, but many European countries have access logging in police and health databases, which checks to see for unwarranted snooping. With actual convictions taking place when someone gets too interested in, say, the behind-the-scenes data of the latest celebrity news.

Many times that are implemented so that IT isn't monitored, and the staff who is monitored can have selective enforcement. This allows for people to be fired for abusing their access when in reality they are being fire for some other action that isn't nearly as PR friendly to state.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#254

This will just push people to open source applications and peer to peer networking. Basically, devolve back to the early days of the internet with regard to person to person communications. How is the DoJ going to force Signal or even Telegram to add a back door?

Well, during the Cold War the feds declared encryption to be "Auxiliary Military Equipment," listed on the USML [1]. It was illegal -- prison time illegal -- to ship software which could encrypt communications outside the USA up until 1992 [2]. I'm old enough to remember the tail end of this and it was absolutely absurd, yet still very real. I remember Zimmermann being investigated by the feds [3]. Zimmermann was sma…

I wonder if encryption could be tied to the Second Amendment as well. I'd be interested in the legal theory discussing that.

Many of the arguments I've seen here defending encryption are basically the same as those defending guns.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#255

Earlier quoted context omitted.

> Secret police worked when criminals were put away with parallel reconstruction, for instance. It wasn't the secret police which worked. It was the parallel construction. > “You can’t stop math.” Not true, strictly anyway. You can't stop math. > Backdoors are an antiquated way of implementing exceptional access. The proper way is to provide third party access that is truly exceptional (living up to the name), and no…

It was the secret police with pr You can stop math. Legally stop fb from using E2EE. You’ve stopped math. You haven’t stopped some people from using it. But you’ve prevented common people from having default usage of that math. Disagree. Don’t use key escrow. Find a better way. Two parties or three parties; three doesn’t have to be significantly more susceptible than two Apologies on the wording. Significantly weaker…

> You can stop math. Legally stop fb from using E2EE. You’ve stopped math. You haven’t stopped some people from using it. But you’ve prevented common people from having default usage of that math.

No, you haven't "stopped math". You've enacted a law and stopped Facebook from using end-to-end encryption.

Math is universal. Math is something that should never be outlawed. Math is a fundamental right, an irrevocable truth based solely in fact. You can sooner stop alcoholism by outlawing alcohol than you can stop encryption by outlawing math. The idea of outlawing math would put us hundreds of years behind today; to enact a truth based on the church's "do this because I tell you it's true" instead of "understand this for yourself, I cannot tell you what is true". Outlawing math is dangerous and I cannot believe you are trying to make such an argument in good faith.

> Find a better way.

I do not believe there is a better way. You don't understand the math behind it. Instead of even trying to understand the math which is already widely understood by many, you instead want to make that math illegal and create your own. You don't even want to spend the mental effort to do that much: you demand others to do it for you.

> Two parties or three parties; three doesn’t have to be significantly more susceptible than two

This is factually false. The third party is a moving party which changes every moment. You can not meet that and still be "secure". It is antithetical to the very notion of encryption.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#256

> the “techlash” by Congress and the public “in the wake of myriad privacy scandals” and the 2016 election This just makes my head explode. Because tech companies tend to be poor at privacy, let's use that logic to make it so the government can invade your privacy anytime they want?

Maybe the pitch to voters is: "Your privacy is already toast, your information is being used for ads, why not let us use it for counterterrorism?"

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#257
post #202

Earlier quoted context omitted.

Why should Law Enforcement have a seat at the table in the design of anything? Should my sneakers be made more uncomfortable so I can't run away too fast? Should they be able to remotely disable my car? Remotely open the blinds to my home's windows? Should I not be able to install a front door that resists attempts at forced entry? What's the line where Law Enforcement's wants merit consideration?

If it comes to pass that the department of justice insists on implementation of Exceptional access it would be who’ve the civil libertarians to work towards a better compromise. Hedge your bets.

So, I failed to actually state what I was trying to probe from you:

Why do you view it as unethical to not consider Law Enforcement needs wrt strong end-to-end encryption?

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#258
post #21

Questions to the public should be phrased: “Do you want Chinese style surveillance to be advanced in the United States?”

+1. This is something tech bros don't seem to get, while politicians get very well: the majority is driven by emotions and has small cognitive ability, but they vote and thus arguments to win their vote must be trivial emotionally charged ideas. A politician says "encryption is a tool of criminals!" and those who start arguing in the rational plane have already lost; instead, the answer should be "lack of encryption…

Agreed. I wish I did not have to agree, but framing has proven to be very important.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#259

Earlier quoted context omitted.

One time pads are not secure by modern cryptographic standards. Elaboration: https://news.ycombinator.com/item?id=6008695

If integrity is an issue you can just add a poly1305/ghash tag to the message. They are not encryption algorithms so it is unlikely that they are going to be banned, and just like OTP they are provably secure. In addition they are not difficult to implement (or execute by hand).

No encryption algorithms would be "banned" by the proposed law. Rather corporate service providers would be compelled to act as bona fide MITM, regardless of what primitive(s) they use.

Once we're past the point of users doing something beyond downloading an app from a corporate app store, all secure encryption would be back on the table.

Of course we can foresee a true ban on encryption some years out, but at that point XOR has the exact same signature as AES. Steganography is the corresponding approach for that attack.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#260

A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…

I think we in the tech community tend to vastly under-estimate the threat of legal restrictions on encryption. When the public gets scared, they look to governments to "do something", whether that something is really a smart thing or not. If we're unlucky and we get caught unprepared, we run the risk of getting stuck with a backdoor or "exceptional access" mechanism that provides little or no technical safeguards aga…

I think you'll run into a chicken-and-egg problem here. Without bonafide strong encryption, those strong protections against misuse probably can't exist.
Post reply on HN