Live data from Hacker News

DOJ plans to strike against encryption while the Techlash iron is hot

cyberlaw.stanford.edu

311–320 of 347 posts

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#311
post #310

Earlier quoted context omitted.

> This was in the capital of one of the poorest countries in Europe, but it was still one of the safest places I've ever been. Obviously if you put all people in jail they will be very safe there. But then you have less people working and producing more useful stuff than rotting in jail. The best example I give of this trade off between freedom and safety is that of women in saudi arabia. They have the least amount o…

This is plain false, with no legislation protecting women from marital rape and punishment for women who report rape, nothing indicates that Saudi Arabia actually has "the least amount of sexual violence in the world" this is a laughable statement at best. https://en.m.wikipedia.org/wiki/Rape_in_Saudi_Arabia

I think that is the point that OP was making.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#312

Earlier quoted context omitted.

It sounds like a majority of the students had no idea what encryption was and because the authority figure (the professor) asked them whether or not it was bad they just went with it? I'm having trouble understanding why people would say mathematical functions are bad.

I hope those people access their bank over port 80.

They do, on their open wifi network.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#313

> the “techlash” by Congress and the public “in the wake of myriad privacy scandals” and the 2016 election This just makes my head explode. Because tech companies tend to be poor at privacy, let's use that logic to make it so the government can invade your privacy anytime they want?

Yeah, "techlash" is a weird term but it's as good as any I've heard for the phenomena. I have plenty of these amorphous attacks on Facebook in particular here on HN, where you get some amount of too much sharing, some amount of "it's just like drugs, man", some amount of too much privacy and so-forth all cobbled together into some sort of complaint.

A lot of smart people seemed to get on board that train without thinking much.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#314
post #250

So terrorists will use one-time pads and other strong encryption and everyone else will have their information exposed on a massive scale when the backdoors inevitably are exploited.

I look forward to the day when one time pads are the norm for general encryption. A scifi novel I read, "A Deepness in the Sky" described how the pads themselves were a valuable item of trade. I don't think it's farfetched to imagine purchasing OTP data to use with internet browsing, the way we buy yubikeys to use with passwords. It would be a far simpler encryption scheme than those we currently use, and that simpli…

You'd have to have a OTP of the same length as the data you want to send/receive.

So your mobile phone for example would need to have local storage the same size as all the data you ever expected it to send/receive.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#315
post #250

So terrorists will use one-time pads and other strong encryption and everyone else will have their information exposed on a massive scale when the backdoors inevitably are exploited.

I look forward to the day when one time pads are the norm for general encryption. A scifi novel I read, "A Deepness in the Sky" described how the pads themselves were a valuable item of trade. I don't think it's farfetched to imagine purchasing OTP data to use with internet browsing, the way we buy yubikeys to use with passwords. It would be a far simpler encryption scheme than those we currently use, and that simpli…

One Time Pads are perfect, except for the rather crucial problem of key exchange. You have to meet your intended recipient irl at some point to exchange pads, and I don't fancy meeting up with every sysadmin who's server I want to access some HTML files from.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#316

Earlier quoted context omitted.

> But it does work. I was at a restaurant there. Some girls are chatting, and they walk away to go get something, and just leave their bags there unattended. Why? Because it's an authoritarian country - people aren't going to steal stuff there. Chances are high that you could do the same in most European countries. Just like in the Soviet Union, thieves exist in Belarus. People's perception might be that they're safe…

I don't recommend leaving bags unattended in public anywhere these days, they're likely to call in the bomb squad.

rotfl ! spot on ! (or they may check it for whatever trending corona virus)

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#317

This will just push people to open source applications and peer to peer networking. Basically, devolve back to the early days of the internet with regard to person to person communications. How is the DoJ going to force Signal or even Telegram to add a back door?

I really would not be surprised if will surface that Telegram has a backdoor for Russian special services. After Anton Rosenberg's posts [1] and Durov's (very unconvincing) responses, it is clear that Durov lies a lot how Telegram operates, and it is quite likely that all their 'blocking' in Russia is just a show to boost credibility. It also should be noted, that while Telegram markets itself as the most safe and pr…

> BUT IF ONE USES END-TO-END ENCRYPTION, ONE CAN'T ACCESS MESSAGES ON ANOTHER DEVICE, BY DEFINITION!!!!!

You can encrypt each message separately for each device, that's still end-to-end encryption.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#318

Earlier quoted context omitted.

It is you and law enforcement who are being binary. Plenty of laws are currently being enforced in the presence of strong encryption. The sky hasn't fallen. In fact, these high profile cases the FBI et al attempt to use as wedges generally involve someone who has already been caught with plenty of evidence, but the authoritarian impulse still demands more . As far as laws that can only be enforced/observed by reading…

If we're agreed that there is no deep principle is at stake and there are shades of grey, it seems that the difference between end-to-end encryption and link-level encryption (as cloud providers typically do) is a matter of practicality? Law enforcement agencies send legal requests to Google and Facebook all the time, and the sky hasn't fallen. Actually, for all X where X exists, the sky hasn't fallen :)

That's fallacious generalizing, though. "All sorts of things have been allowed, so allowing this other thing can't hurt." Yes, yes it can.

I think we can agree that, say, putting a chip in everyone's heads that transmits their thoughts to the government would indeed, as you put it, cause the sky to fall. I'm not trying to suggest that outlawing encryption is the exact same thing, but I do believe it would cause much more injustice than it would prevent.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#319

Earlier quoted context omitted.

Many times that are implemented so that IT isn't monitored, and the staff who is monitored can have selective enforcement. This allows for people to be fired for abusing their access when in reality they are being fire for some other action that isn't nearly as PR friendly to state.

> This allows for people to be fired for abusing their access when in reality they are being fire for some other action that isn't nearly as PR friendly to state. TBH sounds a bit like a conspiracy theory. And for what it's worth, at least in Finland getting caught snooping isn't cause for firing people, the convictions have been fines.

Not true. While it has been pretty rare for anyone to get fired over snooping other people's data, there has been several cases where it has been the basis of firing the employee. Especially the health care sector has been sensitive about snooping, see for example [1], article in Finnish.

[1] https://yle.fi/uutiset/3-7460193

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#320
post #14

Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…

Yeap. Lazy cops' leadership would rather trade in everyone's rights to make their jobs a little bit easier. TBH, we already exist in an inverted totalitarian regime that is risking becoming worse than Orwellian like China if the DOJ gets their way. I do not consent.
Post reply on HN