Live data from Hacker News

An even worse anti-encryption bill than EARN IT

cyberlaw.stanford.edu

311–320 of 367 posts

Re: An even worse anti-encryption bill than EARN IT

#311
post #309

Earlier quoted context omitted.

You don't think China has protestors? They protest on a scale not seen in the US, with 2010 having 180,000 "mass incidents".

They aren't allowed, is the point. You can be disappeared for speaking against Xi. Any comparison is a false one.

They absolutely are allowed.

Re: An even worse anti-encryption bill than EARN IT

#312

Earlier quoted context omitted.

Sorry to say, but even in Australia the combination of SC, AR, TN leaves me worrying. There's a lot of dark history associated with those states that the world has known about for years. That's without taking the "R" into account. Sometimes I think the USA should have it's own history A/B compared against it's own history as recorded by the rest of the world. Not saying it's Tiananmen level yet, but it seems some peo…

The northeast states are built on a legacy of making life hard for anyone who didn't hail from the right country or worship in just the right way. The west coast treated Asians like crap. The plains states had to kick the natives out and that wasn't pretty. It's harder to fit that crap into something short and sweet enough for history textbooks so you don't hear about it whereas simple skin tone based discrimination…

> The plains states had to kick the natives out

...and the rest of the states...

Re: An even worse anti-encryption bill than EARN IT

#313

Earlier quoted context omitted.

> using the term "moral high ground" is not helpful for a number of reasons The U.S. had a global nuclear monopoly for several years. It didn’t abuse it. That’s a hell of a high ground.

The US is the only country to have used nuclear bombs in anger, and that was during it's nuclear monopoly.

Yes, that's a fact. I can't tell whether you approve of that or not, but here's the background.

After the failure of the Treaty of Versailles at the end of of WW1, resulting in WW2, the Allies learned that unconditional surrender was needed to prevent future wars.

The Japanese military command preferred that their troops never surrender.

So the 2 options the US had were:

1) Curtis LeMay would use 10,000 bombers to napalm those cities, and every last village in Japan.

2) Use 2 nuclear weapons and demand a surrender. The military commanders in Washington debated the ethics of using such weapons, so this wasn't done lightly.

Having studied this over a period of years, #2 makes the most sense to me.

https://en.wikipedia.org/wiki/Curtis_LeMay

Re: An even worse anti-encryption bill than EARN IT

#314
post #293
post #240

Earlier quoted context omitted.

The 4th amendment is supposed to guarantee this right. The Senators are old men who don't understand technology, so they believe that the protections that applied to letters at the time of the constitution don't apply to the medium that has replaced letters, namely email and messaging.

Please... These people know exactly what they are doing. The internet is a lot of things, and one of those things is a tool for mass surveillance. It's always, always been about power and money.

You are right, they have no excuse.

Re: An even worse anti-encryption bill than EARN IT

#315

Earlier quoted context omitted.

I didn't say they do. Encryption is still a different idea from warrantless searches though.

But the beauty of E2E is that indeed it forces law enforcement to cough up a warrant.

With strong E2EE, a warrant won't do much.

Re: An even worse anti-encryption bill than EARN IT

#316

Earlier quoted context omitted.

But encrypted conversations, by definition, are recorded. With a warrant, law enforcement is permitted to search a safe containing written records of a conversation; why shouldn't they be allowed to search an encrypted consumer electronic device containing the same?

The difference is that a safe can be "brute forced"; you don't need to know the combination in order to be able to get in, with enough resources (i.e. a large enough drill). The same cannot be said about encrypted data, which is (as far as we know) literally impossible to break into no matter how much money you throw at the problem. If the same were true of safes—if they were physically impossible to get into without…

If impenetrable safes existed, the government stance would certainly not just be to say "oh well, guess we gotta let criminals store whatever contraband they want".

Re: An even worse anti-encryption bill than EARN IT

#317

Earlier quoted context omitted.

The difference is that a safe can be "brute forced"; you don't need to know the combination in order to be able to get in, with enough resources (i.e. a large enough drill). The same cannot be said about encrypted data, which is (as far as we know) literally impossible to break into no matter how much money you throw at the problem. If the same were true of safes—if they were physically impossible to get into without…

> Do you think, in that scenario, that safe manufacturers should be required to make a master key and distribute it to law enforcement? I'm not sure, to be honest, but I think it's certainly a reasonable position to take. > IANAL, but as far as I know, if the police can't physically break into your safe, there is nothing saying that they have any legal recourse to compel you to open it. If it can be established that…

> If it can be established that the safe is yours and that you possess the key or know the combination, I believe a court can indeed order you to open it or to produce the contents, punishable by contempt of court.

I got curious about this, so I did some quick research. Again, IANAL, but my understanding is that, in the US, the court can order you to give up the physical key (if it is determined that you have it) but not the combination. The latter is protected by the Fifth Amendment right against self incrimination, in the same way as sharing knowledge verbally. So then the question becomes, is an encryption key (or passcode, etc) more like a physical key, or a combination? If the former, then you would be legally compelled to decrypt it if law enforcement asked you to do so. If the latter, however, then there is no legal way for law enforcement to force you to decrypt the device.

The legal framework for deciding how to handle encrypted data already exists, it's just ambiguous. Instead of passing a law that completely changes the scope and usefulness of encryption, doesn't it make much more sense to simply disambiguate and update existing laws accordingly? I don't know the full repercussions of that, but it seems that there exist less drastic solutions to the problem.

> I don't necessarily agree with that argument, but I don't think it's unreasonable.

I think it is unreasonable because it's asking companies to willfully violate their user's privacy and trust, and to severely undermine encryption as a whole. There is zero chance that this does not get abused.

Re: An even worse anti-encryption bill than EARN IT

#318

Earlier quoted context omitted.

The US is the only country to have used nuclear bombs in anger, and that was during it's nuclear monopoly.

Yes, that's a fact. I can't tell whether you approve of that or not, but here's the background. After the failure of the Treaty of Versailles at the end of of WW1, resulting in WW2, the Allies learned that unconditional surrender was needed to prevent future wars. The Japanese military command preferred that their troops never surrender. So the 2 options the US had were: 1) Curtis LeMay would use 10,000 bombers to na…

Except the Japanese didn't have the context to know the implications of the nuclear bombs. And the contemporaries noted that it was the Soviet declaration of war and invasion of Manchuria that forced their hand. The use of atomic bombs was superfluous.

Re: An even worse anti-encryption bill than EARN IT

#319

Earlier quoted context omitted.

The difference is that a safe can be "brute forced"; you don't need to know the combination in order to be able to get in, with enough resources (i.e. a large enough drill). The same cannot be said about encrypted data, which is (as far as we know) literally impossible to break into no matter how much money you throw at the problem. If the same were true of safes—if they were physically impossible to get into without…

If impenetrable safes existed, the government stance would certainly not just be to say "oh well, guess we gotta let criminals store whatever contraband they want".

Sure, but don't you think there are less drastic solutions than to require the manufacturer to create a master key, distribute it to law enforcement, and cross their fingers hoping that it doesn't get exploited?

Re: An even worse anti-encryption bill than EARN IT

#320

Earlier quoted context omitted.

If impenetrable safes existed, the government stance would certainly not just be to say "oh well, guess we gotta let criminals store whatever contraband they want".

Sure, but don't you think there are less drastic solutions than to require the manufacturer to create a master key, distribute it to law enforcement, and cross their fingers hoping that it doesn't get exploited?

I mean, what would the less drastic solution be in this analogy?
Post reply on HN