Live data from Hacker News

DOJ plans to strike against encryption while the Techlash iron is hot

cyberlaw.stanford.edu

261–270 of 347 posts

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#261

Earlier quoted context omitted.

Freedom isn't free. I think people have just ought to realize that. People have this idea that free countries are more efficient, which is probably true in the long run, but it's a cop-out to just call it a day there. Once I was in Belarus. It's a heavily authoritarian country, make no mistake. When they had protests against their rigged elections, they traced the phones of everyone who went, then brought them in for…

> This was in the capital of one of the poorest countries in Europe, but it was still one of the safest places I've ever been. Obviously if you put all people in jail they will be very safe there. But then you have less people working and producing more useful stuff than rotting in jail. The best example I give of this trade off between freedom and safety is that of women in saudi arabia. They have the least amount o…

> > This was in the capital of one of the poorest countries in Europe, but it was still one of the safest places I've ever been.

> Obviously if you put all people in jail they will be very safe there. But then you have less people working and producing more useful stuff than rotting in jail.

Friendly reminder that the US has the highest incarceration rate of all countries.

> The best example I give of this trade off between freedom and safety is that of women in saudi arabia. They have the least amount of sexual violence in the world.

Is this according to their official statistics? How do they know they're accurate and comparable? For instance, is rape within marriage considered a crime and regularly prosecuted there?

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#262

Earlier quoted context omitted.

Yeah. I was shocked at how many -CS MAJORS- were pro-DRM.

What does being a CS major having to do with being pro-DRM? Isn't it mainly an economic/philosophical standpoint on copyright?

I believe it's something more to do with the OP's (mistaken) idea that CS majors are somehow more likely to be "hackers" or people who exchange pirated software or wares -- when really there's only a handful of people who know how to crack the DRM in the first place (which requires some degree of technical know-how) and then those people distribute the pirated goods to others (whose technical literacy may be far less, even if it's still enough to distribute the pirated material on down the line).

It's a bit like thinking all painters are in favor of graffiti, or all musicians are okay with "sampling" and remix culture.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#263

Earlier quoted context omitted.

This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company. While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight. Note that strong network encryption is essential for ensuring that they have to get a warrant. I don't…

> that still allows law enforcement to do their job? Do libraries not keeping records of who has read what books not allow law enforcement to do their job? Do prohibitions against arbitrary searches not allow law enforcement to do their job? Does having to make a plausible argument in front of a judge not allow law enforcement to do their job? Do individuals not having a number tattooed on their forehead not allow la…

You're being too binary about this. Yes, we should be skeptical of law enforcement. Judicial oversight is essential. But we should still care about police effectiveness at catching law breakers. Why have laws if they can't be enforced?

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#265
post #257

Earlier quoted context omitted.

If it comes to pass that the department of justice insists on implementation of Exceptional access it would be who’ve the civil libertarians to work towards a better compromise. Hedge your bets.

So, I failed to actually state what I was trying to probe from you: Why do you view it as unethical to not consider Law Enforcement needs wrt strong end-to-end encryption?

Having exceptional access is important to keeping and improving society. It’s unethical to ignore and fight LE’s ongoing needs regarding such access. E2EE at scale, unchecked, is an extreme viewpoint with trade offs that I consider unethical at best, and fundamentally dangerous at worst.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#266
post #62

Earlier quoted context omitted.

Shamir secret sharing allows for that on paper. The problem is that to be useful for law enforcement, any local police department has to be able to go to any local judge and get a warrant and then get access. There are approximately 30,000 state judges with fairly high turnover in that list. If you can compromise one, or successfully get yourself added to that list, you can then get access to whatever you want. That'…

This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company. While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight. Note that strong network encryption is essential for ensuring that they have to get a warrant. I don't…

> This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company.

Which is another reason why consolidating everyone's data into a few centralized locations is also problematic.

> While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight.

But that's not what we're talking about here. The question isn't whether the police should need to get a warrant, it's whether the government should be able to prohibit technology that preserves privacy because some criminals might use it alongside all the law abiding citizens.

And encryption doesn't "prevent law enforcement from doing their jobs" -- that's just a trope. What it does is make their jobs more expensive. Even if they can't just get a copy of all your communications from a megacorp by filing some papers, they can still get a warrant and then plant bugs or guess your password or plant bugs that allow them to observe you entering your password etc. It's not impossible, it just takes more resources to do it -- which prevents it from happening at a massive scale.

That's a feature, not a bug. It still lets them solve murders, because murders are serious and uncommon and can justify the expense of a real investigation. It may make it inexpedient to spend those resources to catch every last hooker and pothead, but so what? Sometimes it's not worth the candle. If you think it really is, give them more money instead of giving everyone else less privacy. But sometimes it just isn't. Sometimes it costs more to solve a crime than to not solve it.

Meanwhile (this is the feature) it doesn't make it too easy for them to identify all the people in group X and give the list to Joe McCarthy or round them all up and put them in internment camps. Law enforcement should have some friction, because when it happens too fast at too large a scale, history shows this to be Bad.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#267

Earlier quoted context omitted.

I don't know about US, but many European countries have access logging in police and health databases, which checks to see for unwarranted snooping. With actual convictions taking place when someone gets too interested in, say, the behind-the-scenes data of the latest celebrity news.

Many times that are implemented so that IT isn't monitored, and the staff who is monitored can have selective enforcement. This allows for people to be fired for abusing their access when in reality they are being fire for some other action that isn't nearly as PR friendly to state.

> This allows for people to be fired for abusing their access when in reality they are being fire for some other action that isn't nearly as PR friendly to state.

TBH sounds a bit like a conspiracy theory. And for what it's worth, at least in Finland getting caught snooping isn't cause for firing people, the convictions have been fines.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#268

Earlier quoted context omitted.

Let's be clear - encryption can absolutely enable those things. That is not all it does, but pretending it does not is stupid.

The internet enables all of those things too. Before that, telephones and fax machines did. Hospitals enable the spread of disease by clustering all the sick together with a constant flow of healthy people (visitors, doctors, etc). They also enable the development of superbugs. What's your point? You're confusing incidental usage with enablement. The lack of these good things doesn't prevent the occurrence of the evi…

the point is that you can track phone calls and fax

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#269

Earlier quoted context omitted.

One time pads are not secure by modern cryptographic standards. Elaboration: https://news.ycombinator.com/item?id=6008695

So the concern then is that the message might be tampered with on the wire? Is there some hypothetical reason we can't just append the SHA256 of the message to the message before encrypting it? It should be impossible for an attacker to alter any message bits undetected with this scheme.

Your scheme fails for replay attacks, and allows modification of messages with low entropy. I'd say easy fixes are to add a counter and a random nonce to each message, but then there is probably something else I am missing. In general there's no "just" in cryptography, which is why cryptosystems are formally defined and then analyzed whole.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#270

Earlier quoted context omitted.

It was the secret police with pr You can stop math. Legally stop fb from using E2EE. You’ve stopped math. You haven’t stopped some people from using it. But you’ve prevented common people from having default usage of that math. Disagree. Don’t use key escrow. Find a better way. Two parties or three parties; three doesn’t have to be significantly more susceptible than two Apologies on the wording. Significantly weaker…

> You can stop math. Legally stop fb from using E2EE. You’ve stopped math. You haven’t stopped some people from using it. But you’ve prevented common people from having default usage of that math. No, you haven't "stopped math". You've enacted a law and stopped Facebook from using end-to-end encryption. Math is universal. Math is something that should never be outlawed. Math is a fundamental right, an irrevocable tru…

Semantics aside, if FB isn’t allowed to use the math behind E2EE, they’ve effectively been stopped from using math. Just trying to avoid getting into the weeds.

Similarly to you questioning my faith in the matter, you’re ignoring my argument, ostensibly not in good faith, either. I’m suggesting to build a better mousetrap. It may not be perfect but might help maintain and improve civility in society.

Alcoholism and alcohol aren’t really a great analogy.

I understand math better than you may realize. You said that you don’t believe there’s a better way. You’ve effectively conceded that the existing key escrow solutions with the known risks are the best that can be done. I’m suggesting to do better. Find a better compromise.

Three party access in current incarnations may have flaws but the statement isn’t factually false. It’s simply undiscovered.

Conflating ideals with beliefs can be tricky..

Post reply on HN