Live data from Hacker News

An even worse anti-encryption bill than EARN IT

cyberlaw.stanford.edu

281–290 of 367 posts

Re: An even worse anti-encryption bill than EARN IT

#281
post #176

Earlier quoted context omitted.

Not in the US.

That some concentration camps in other countries were also death camps is entirely the point. They are not the same thing, but they're just one step removed. In fact, thousands of people died in the American camps even though there was not an official policy of extermination.

From some light research, it looks like 120,000 Japanese-Americans were put in these camps for 2-3 years and 1,862 died. In the country at large, if I'm reading this [1] right, 1,459,000 people died outside of the camps in the US, which had a population of 136,700,000. That's a ~1% base death rate per year, which would account for ~2/3 of these deaths in a year.

This could be investigated further; was the average length of imprisonment less than a year, were the causes of death different than in the larger population, did economic conditions and racism increase the base death rate among Japanese-Americans in the first place, was the age distribution different among those the US bothered to move to camps, pushing their base rate lower?

Evidently people died because of these camps, and it is incredibly likely that many of those deaths were racist hate crimes committed by US employees on US citizens. Even that aside, it was very much wrong it imprison innocent civilians on the basis of their race. 'Thousands died' does seem like a substantial overstatement when the only number I can find is less than 2,000 (it's from the US, so it may be biased). Probably a few hundred died as a result of these camps, mostly from disease.

[1] https://www.cdc.gov/nchs/data/vsus/VSUS_1943_2.pdf

Re: An even worse anti-encryption bill than EARN IT

#282
post #274
post #232

Earlier quoted context omitted.

As an ignorant non-lawyer, it seems to me that the "illegal search" argument won't hold up. Laypeople see encryption as a lock on a safe that the govt should be able to compel you to open. Why not use a 1st Amendment approach? Doesn't my freedom to speak also cover the "language" (i.e. encrypted bits) I'm using?

I still don't get why they're burdening the service providers with this? Like I know why but I'm surprised a bill that says that police can compel you to unlock your device hasn't come around. Like why are you making it the mailman's problem?

A service provider like Google or Apple (a) provides a single point of access to many devices, and (b) is very likely to comply with law enforcement requests if compliance is legally required.

Re: An even worse anti-encryption bill than EARN IT

#283

Do we need an amendment to the constitution? We can't keep fighting these fights. Eventually they will win.

Yes, I'm surprised there is no "right to privacy" spelled out in clear terms. Sounds like that would be a wonderful thing to add directly to the Constitution.

> I'm surprised there is no "right to privacy" spelled out in clear terms.

The problem is, there is no definition of the word “privacy” in the context of “right to privacy” that a majority can agree on. I highly doubt even the niche audience of HN could agree on what they feel is private or not. I think the EU took a decent shortcut around that debate with “right to be forgotten”.

Re: An even worse anti-encryption bill than EARN IT

#284

Earlier quoted context omitted.

Would you apply the same reasoning to any other country that used nukes to "end an existing war"?

> Would you apply the same reasoning to any other country that used nukes to "end an existing war"? Yes, using nukes defensively is less bad than using it to start a war. That doesn’t mean I support the use of nukes. WWII was unique in starting with no nukes and ending with them. We also didn't yet understand the long-term ramifications of the weapon's use.

So which conflicts since WWII would you OK the "defensive" use of nuclear weapons?

Re: An even worse anti-encryption bill than EARN IT

#285
post #197

Earlier quoted context omitted.

Congress should be the first to lose the things they vote to restrict. They should lose it for at least a year before a bill is allowed to pass by simple majority.

Yeah the TL;DR: on this is “Bill Barr (or any AG) could read all of your emails without a warrant if you vote for this.” I know they would legally require a warrant to read them, maybe, but he’d have the access without it. Not a fun thought to go back to Hoover-style DoJ practices.

> “Bill Barr (or a Democrat AG) could read all of your emails without a warrant if you vote for this.

That would fix it.

Re: An even worse anti-encryption bill than EARN IT

#286
post #280

Earlier quoted context omitted.

You won't like the answer... 1. Most congresspersons don't even read what they are voting on. 2. Most congresspersons don't even write the bills that have their name on them, most of that work being done by staffers in collusion with K-street or the MICC. 3. If a congressperson reads it and doesn't like it, K-street/MICC is likely to put real pressure on them to change their stance. If they are a freshman in any way…

You're not wrong on any count, but it's impossible to take your arguments seriously when you say "congresscritters"

Edited while I still had the ability. Thanks for the constructive criticism, I should know better.

Re: An even worse anti-encryption bill than EARN IT

#287

A Twitter thread [1] from Matthew Green in this bill. Essentially he says that this bill is a dead on arrival bill which is designed to make EARN IT look like a fair compromise. And we better not fall for it [1] https://twitter.com/matthew_d_green/status/12759760840231198...

We (HNers) might not fall for it but the proven technologically illiterate Representatives and their staff just might. This is why citizen's lobbying is so important. If the lawmakers are willfully ignorant - or in this case willfully arrogant about attacking encryption - the only thing that will get them to vote the right way is to hear from enough real constituents that the lawmakers feel like their reelection will…

> the only thing that will get them to vote the right way is to hear from enough real constituents that the lawmakers feel like their reelection will be in jeapordy if they do vote the wrong way.

Like most real world systems this sounds incredibly inefficient to me. In germany there used to be (and maybe still is) the "Wahl-O-Mat" [1] ( an artificial word made out of two words: vote and automation ). The idea is to answer some questions and the Wahl-O-Mat tells you for which party you should vote.

Let's extend this idea and make a thought experiment. Imagine the questions and the answers would be tended / adjusted over time (like a profile on a dating site). The rules how the voting suggestion is computed are straight forward ( a weighted sum or something ). If a new controverse question arises then people adjust their voting-profile according to their beliefs (or if it doesn't matter to them they don't). If the profiles are public then the outcome of the next elections can be predicted easily. Best next thing to direct democracy.

[1] https://de.wikipedia.org/wiki/Wahl-O-Mat

Edit:grammar

Re: An even worse anti-encryption bill than EARN IT

#288
post #272
post #250

Earlier quoted context omitted.

> My favorite example is probably the infamous Indiana Pi Bill, via which local politicians wanted to regulate the value of Pi to be exactly 3.2, according a "proof" published by some crank. Honestly, that seems to be a bit of a distortion. What I've read about that makes it sound like some state legislators were fooled for a little while by a crank, which caused a dumb bill to advance a little before being killed. N…

According to the rationalwiki link: > The bill easily passed committee and was unanimously passed by the house. Representatives received it favorably, with one gushing that "The case is perfectly simple. If we pass this bill which establishes a new and correct value of pi, the author offers our state without cost the use of his discovery and its free publication in our school textbooks, while everyone else must pay h…

> According to the rationalwiki link:

The Wikipedia link is way better and more credible:

> Upon its introduction in the Indiana House of Representatives, the bill's language and topic occasioned confusion among the membership; a member from Bloomington proposed that it be referred to the Finance Committee, but the Speaker accepted another member's recommendation to refer the bill to the Committee on Swamplands, where the bill could "find a deserved grave".[5]:385 It was transferred to the Committee on Education, which reported favorably;[6] following a motion to suspend the rules, the bill passed on February 6, 1897[5]:390 without a dissenting vote.

Honestly, it sounds like none of them understood the mathematics and the main effect of the bill had something to do with getting the state a license to use the copyrighted techniques royalty free. I'm speculating, but I wouldn't be surprised if many of those who voted for did so because they thought there'd be little harm in getting something for free.

If anything, the more embarrassing thing seems to be they didn't seem to understand copyrights or patents very well, which are creatures of law that legislators should better understand than mathematics. I don't know if the precedents existed 120 years ago, but you can't patent/copyright mathematical truth, so even if the crank was right they should have known they didn't need to to anything to avoid paying him royalties to use his results.

Re: An even worse anti-encryption bill than EARN IT

#289
Contrary to what some people are implying, support for mandatory decryption is not evidence of technological illiteracy.

From the perspective of these lawmakers, encrypted storage is like a safe. You have the right to store records in a safe to keep them away from prying eyes, but law enforcement has the right to order you to unlock that safe if they have a warrant. You have the same right to store those same records on an encrypted device, but law enforcement has the same right to order you to decrypt that device if they have a warrant.

Since people will sometimes refuse to decrypt a device, even when ordered to do so by a court, these lawmakers want to require OEMs and service providers to maintain control of the keys when they encrypt information on a user's behalf so as to increase the chances that lawful decryption can take place.

Is this a bad policy? Quite possibly. It has certain risks and makes certain tradeoffs, like any other policy. But it is arrogant to assume that anyone who supports it must be ignorant of how encryption works.

Re: An even worse anti-encryption bill than EARN IT

#290

Contrary to what some people are implying, support for mandatory decryption is not evidence of technological illiteracy. From the perspective of these lawmakers, encrypted storage is like a safe. You have the right to store records in a safe to keep them away from prying eyes, but law enforcement has the right to order you to unlock that safe if they have a warrant. You have the same right to store those same records…

The difference is that for the government to come into my house and force me to open my safe: 1) I will both know about it. 2) government will need a warrant.

In the case of my digital data that might be stored on google (or some other third party) I may never know that the government asked google to decrypt my data for them. In the past companies have done so without a warrant.

Maybe the contents of this bill does not work this way. I don't know.

Post reply on HN