Live data from Hacker News

An even worse anti-encryption bill than EARN IT

cyberlaw.stanford.edu

291–300 of 367 posts

Re: An even worse anti-encryption bill than EARN IT

#291
The thing I always wonder about something like the government having the power to force people to decrypt data is what happens if the person claims they forgot their key. I could very much see this happening to me if I was arrested and my computers taken away only to months later be asked to unlock them.

Also what happens if the person used Rubber Hose cryptography. They could give up a key and the government gets some data but it would be impossible to know if they gave up all the keys. https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis

Re: An even worse anti-encryption bill than EARN IT

#292

Earlier quoted context omitted.

Yes, the same as any unrecorded conversation is inaccessible by warrant after it happens. Law enforcement doesn't need omniscience, but we do need freedom to associate and privacy in a democracy.

But encrypted conversations, by definition, are recorded. With a warrant, law enforcement is permitted to search a safe containing written records of a conversation; why shouldn't they be allowed to search an encrypted consumer electronic device containing the same?

The difference is that a safe can be "brute forced"; you don't need to know the combination in order to be able to get in, with enough resources (i.e. a large enough drill). The same cannot be said about encrypted data, which is (as far as we know) literally impossible to break into no matter how much money you throw at the problem. If the same were true of safes—if they were physically impossible to get into without the key—then this same conversation would apply. Do you think, in that scenario, that safe manufacturers should be required to make a master key and distribute it to law enforcement?

IANAL, but as far as I know, if the police can't physically break into your safe, there is nothing saying that they have any legal recourse to compel you to open it. Why should encrypted data be any different? Any why should it be the responsibility of the manufacturer/service provider to supply law enforcement with a key? The government can always pass a law allowing law enforcement to legally require you to unlock your device, but that is not what they are doing.

Re: An even worse anti-encryption bill than EARN IT

#293
post #240

Earlier quoted context omitted.

Yes, I'm surprised there is no "right to privacy" spelled out in clear terms. Sounds like that would be a wonderful thing to add directly to the Constitution.

The 4th amendment is supposed to guarantee this right. The Senators are old men who don't understand technology, so they believe that the protections that applied to letters at the time of the constitution don't apply to the medium that has replaced letters, namely email and messaging.

Please... These people know exactly what they are doing. The internet is a lot of things, and one of those things is a tool for mass surveillance. It's always, always been about power and money.

Re: An even worse anti-encryption bill than EARN IT

#294

Earlier quoted context omitted.

But encrypted conversations, by definition, are recorded. With a warrant, law enforcement is permitted to search a safe containing written records of a conversation; why shouldn't they be allowed to search an encrypted consumer electronic device containing the same?

The difference is that a safe can be "brute forced"; you don't need to know the combination in order to be able to get in, with enough resources (i.e. a large enough drill). The same cannot be said about encrypted data, which is (as far as we know) literally impossible to break into no matter how much money you throw at the problem. If the same were true of safes—if they were physically impossible to get into without…

> Do you think, in that scenario, that safe manufacturers should be required to make a master key and distribute it to law enforcement?

I'm not sure, to be honest, but I think it's certainly a reasonable position to take.

> IANAL, but as far as I know, if the police can't physically break into your safe, there is nothing saying that they have any legal recourse to compel you to open it.

If it can be established that the safe is yours and that you possess the key or know the combination, I believe a court can indeed order you to open it or to produce the contents, punishable by contempt of court.

> Any why should it be the responsibility of the manufacturer/service provider to supply law enforcement with a key?

Because the state has a compelling public interest in ensuring that law enforcement can successfully execute lawful search warrants. The existence of indestructible safes would constitute a significant impediment to achieving that goal, so manufacturers of such safes have the responsibility of ensuring that law enforcement can access them.

I don't necessarily agree with that argument, but I don't think it's unreasonable.

Re: An even worse anti-encryption bill than EARN IT

#295
post #176

Earlier quoted context omitted.

That some concentration camps in other countries were also death camps is entirely the point. They are not the same thing, but they're just one step removed. In fact, thousands of people died in the American camps even though there was not an official policy of extermination.

From some light research, it looks like 120,000 Japanese-Americans were put in these camps for 2-3 years and 1,862 died. In the country at large, if I'm reading this [1] right, 1,459,000 people died outside of the camps in the US, which had a population of 136,700,000. That's a ~1% base death rate per year, which would account for ~2/3 of these deaths in a year. This could be investigated further; was the average len…

That's true. If you count the Alaskan camps [1] you get another 118 American citizens who died in U.S. government camps, which would put us at 1980 dead - leaving us 20 short of thousands. I stand corrected.

[1] - https://www.npr.org/sections/codeswitch/2017/02/21/516277507...

Re: An even worse anti-encryption bill than EARN IT

#296
post #218
post #163

Earlier quoted context omitted.

Nancy Pelosi backed EARN-IT, a bill that's just a more passive aggressive way to try to get the same camel into the same tent.

Feinstein (D-CA) co-introduced EARN IT. She might be up for re-election one more time before she retires. She votes according to Trump’s recommendations more than any other democrat, and more than many republicans. Her history of supporting right wing causes and overt corruption spans many decades. As a California Democrat, her position has been unassailable most of her career. I suspect getting rid of her was a moti…

> Feinstein (D-CA) co-introduced EARN IT. She might be up for re-election one more time before she retires.

Yes. I call her Senator Hollywood. That's the only constituency she really represents. She's been on the wrong side of all tech related bills over her entire career. EARN-IT is simply the latest one in that list.

Re: An even worse anti-encryption bill than EARN IT

#297

Earlier quoted context omitted.

There is something worse than gulags. Telescreens, watched by "AI". They can arrest you on trumped up charges, but it's not really feasible to do that to everybody, and extreme heavy-handedness promotes resistance. Once they reach inside your device, they don't have to murder or imprison you, they can just give you a little slap whenever you try to stray from the garden path. Let you know that they're watching so the…

They can arrest you on trumped up charges, but it's not really feasible to do that to everybody No, but I would imagine there would soon be some way of removing your liberty and keep you under house arrest for a set period. Imagine if they made sure your banking and cards were frozen for the period to stop you going anywhere...

Or a social credit system that prevented you from using public transit

Re: An even worse anti-encryption bill than EARN IT

#298

Earlier quoted context omitted.

If you live in California, let Senator Feinstein's office know you're not pleased with this. Unfortunately I don't think she's up for reelection this year, but if she doesn't retire next year, consider not voting for her in the next primary, Feinstein was one of the EARN-IT Act's sponsors, and a long-time opponent of cryptography.

Feinstein needs to go

87? Yep. My 2 year old has a deeper appreciation for modern society.

Re: An even worse anti-encryption bill than EARN IT

#299
post #290

Contrary to what some people are implying, support for mandatory decryption is not evidence of technological illiteracy. From the perspective of these lawmakers, encrypted storage is like a safe. You have the right to store records in a safe to keep them away from prying eyes, but law enforcement has the right to order you to unlock that safe if they have a warrant. You have the same right to store those same records…

The difference is that for the government to come into my house and force me to open my safe: 1) I will both know about it. 2) government will need a warrant. In the case of my digital data that might be stored on google (or some other third party) I may never know that the government asked google to decrypt my data for them. In the past companies have done so without a warrant. Maybe the contents of this bill does n…

[deleted]

Re: An even worse anti-encryption bill than EARN IT

#300

Earlier quoted context omitted.

Yes, I'm surprised there is no "right to privacy" spelled out in clear terms. Sounds like that would be a wonderful thing to add directly to the Constitution.

> I'm surprised there is no "right to privacy" spelled out in clear terms. The problem is, there is no definition of the word “privacy” in the context of “right to privacy” that a majority can agree on. I highly doubt even the niche audience of HN could agree on what they feel is private or not. I think the EU took a decent shortcut around that debate with “right to be forgotten”.

Case in point, there’s a heated debate on HN today in the comments section of the DoJ post on Wikileaks whether Steve Job’s medical history (as shared by Wikileaks) should be private or not.
Post reply on HN