Live data from Hacker News

DOJ plans to strike against encryption while the Techlash iron is hot

cyberlaw.stanford.edu

281–290 of 347 posts

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#281

Earlier quoted context omitted.

> This was in the capital of one of the poorest countries in Europe, but it was still one of the safest places I've ever been. Obviously if you put all people in jail they will be very safe there. But then you have less people working and producing more useful stuff than rotting in jail. The best example I give of this trade off between freedom and safety is that of women in saudi arabia. They have the least amount o…

Well of course they do; it's not rape there as long as you marry the 12-year-old first.

In Sharia law, you need 4 witnesses to prove fornication. Bringing a charge without the evidence subjects the one who brought it to 80 lashes.

Whether or not this applies to rape is a question of debate. However in Pakistan it certainly has been interpreted to so apply. Which means that it is very hard for a woman to prove that she was raped.

See https://en.wikipedia.org/wiki/Hudud#Requirements_for_convict... for verification.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#282
Privacy is extremely important, especially as also our democratic governments cannot be trusted always, at least this is the impression I get when reading the interview with the UN Special Rapporteur on Torture concerning the Assange case: https://www.republik.ch/2020/01/31/nils-melzer-about-wikilea...

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#283

Earlier quoted context omitted.

In that case you would not be forced, at least in a more extreme application of the word. Regarding ethics, my opinion is that it’s unethical to offer strong E2EE to the masses at scale, without considering the needs of LE.

LE in which jurisdiction(s)? If the E2EE is widely used, the "needs" of local LE will be varied and often contradictory.

This is one of many excellent arguments against such backdoors. The US would like backdoors into everyone's communications, and doesn't want anyone else to have them. China would like backdoors into everyone's communications, and doesn't want anyone else to have them. Every country and jurisdiction would like backdoors into everyone's communications, and doesn't want anyone else to have them.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#284
post #264

I'm guessing this is cryptographically impossible but are there any schemes that allow 2 different keys to decrypt to two different messages for deniability? Perhaps a key containing a seed number to adjust the algorithm?

This is a neat idea but I also have no idea if theoretically feasible or not.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#285

Earlier quoted context omitted.

I think we in the tech community tend to vastly under-estimate the threat of legal restrictions on encryption. When the public gets scared, they look to governments to "do something", whether that something is really a smart thing or not. If we're unlucky and we get caught unprepared, we run the risk of getting stuck with a backdoor or "exceptional access" mechanism that provides little or no technical safeguards aga…

I think you'll run into a chicken-and-egg problem here. Without bonafide strong encryption, those strong protections against misuse probably can't exist.

> Without bonafide strong encryption, those strong protections against misuse probably can't exist.

Agreed. I actually did some work on this topic that requires having things like strong ciphers and hash functions, and protocols that provide perfect forward secrecy.

Our approach was to take strong constructions and turn them into a kind of proof-of-work. So you can recover the key, but to do so you have to expend a huge amount of electricity (ie, money).

The idea was partly just to call the bluff of the government types who claim that "exceptional access" is so critical to our safety. If they're not willing to spend the money, then we should not be willing to compromise our security.

NOTE: I'm not suggesting that we should actually deploy this kind of thing, as long as we have a choice in the matter. Just that we should be prepared in case we need it.

Anyway, the paper is here:

C.V. Wright and M. Varia. Crypto Crumple Zones: Enabling Limited Access without Mass Surveillance. In IEEE EuroS&P, 2018. https://web.cecs.pdx.edu/~cvwright/papers/crumplezones.pdf

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#286

Earlier quoted context omitted.

If the NSA can't keep its employees from abusing their spying tools to spy on their neighbors then what chance does law enforcement have?

I'm starting to get the feeling that a lot of these jobs, both tech and government, are low key treating non public data access as a perk. For context, I interviewed with a company that had police videos stored on their systems and were using them for entertainment, to the point of showing me one at the beginning of the interview for grins

this was verbally joked about as a perk while interviewing for Facebook in 2008, specifically: any engineer could view anyone's profile. i think that's been changed though.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#287
post #60

Earlier quoted context omitted.

Ah, but the government already has a backdoor to envelopes, because they can get a warrant to open the envelopes. This analogy only strengthens their position.

Not really. Because strong encryption is like having everything in envelopes only you can open, and weak encryption is like everything passing without an envelope, because you don't know who has compromised the keys (and just like it traveling without an envelope, you have no idea who is seeing and meddling with it). There is no "only the government can remove the envelope, if they get permission". If we had the capa…

> There is no "only the government can remove the envelope, if they get permission".

Okay, but now the case you're trying to explain is "there are deep technological challenges and a wealth of historical precedent make me skeptical that we can correctly design or implement a solution that allows only the government or the intended recipient to decrypt the message, instead of only the intended recipient".

To people who think "technology is magic".

And on the other side of the PR battle, the government is saying "Nah, we got this. And if you try and stop us, we're powerless against pedophiles and terrorists."

Adding enough nuance to make your position technically accurate, also makes it abstract enough to be politically useless.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#288
post #179

Earlier quoted context omitted.

I don't mean this to sound snippy, but where would you go? Most non-US countries I'm aware of have even worse restrictions around speech, encryption, and so forth.

New Zealand has stronger free speech protection than the US and no encryption issues. More freedom of the press and even ‘free’ heathcare for citizens or permanent residents make it a solid contender.

> stronger free speech protection than the US

You do realize this is the same country which made it punishable by up to 10 years' prison to have a specific terrorist's manifesto on your computer?

https://apnews.com/162e85e9418240d3ae3650c8f59caf56

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#289

Earlier quoted context omitted.

This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company. While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want without oversight. Note that strong network encryption is essential for ensuring that they have to get a warrant. I don't…

> This is basically what happens when law enforcement uses a search warrant to get access to user data from a tech company. Which is another reason why consolidating everyone's data into a few centralized locations is also problematic. > While this process does have weaknesses, it is still the difference between a legal process overseen by the courts and one based on espionage where agents do whatever they want witho…

> whether the government should be able to prohibit technology

There is no principle that says governments (as representatives of the people) can't regulate what technologies people can have. Sometimes we decide that yes, the government should do this. Consider how the FCC regulates electronic devices to prevent radio interference. Enforcement is lax and as a hobbyist you aren't likely to get caught, but devices aren't commonly found in retail stores that don't have FCC approval.

There are many practical issues, of course, including making sure there is a balance of power and that law enforcement powers aren't abused. I agree with that part.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#290
post #14

Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…

it's an election year, might as well try to link all this to Trump! (although, as you've noted this has been happening for quite a while across all parties)
Post reply on HN