Earlier quoted context omitted.
Sure, but don't you think there are less drastic solutions than to require the manufacturer to create a master key, distribute it to law enforcement, and cross their fingers hoping that it doesn't get exploited?
I mean, what would the less drastic solution be in this analogy?
An even worse anti-encryption bill than EARN IT
321–330 of 367 posts
Re: An even worse anti-encryption bill than EARN IT
#322Crypto is classified as an armament for export control. I’m keeping mine under the second amendment, since the folks who wrote this bill seem to care about that one. As an aside: does that mean US DoD will get a back door as well? As a secure provider with over 1M users that required encryption at rest and in transit I think they should be the first to give up the keys to law enforcement.
https://xkcd.com/504/
Re: An even worse anti-encryption bill than EARN IT
#323Contrary to what some people are implying, support for mandatory decryption is not evidence of technological illiteracy. From the perspective of these lawmakers, encrypted storage is like a safe. You have the right to store records in a safe to keep them away from prying eyes, but law enforcement has the right to order you to unlock that safe if they have a warrant. You have the same right to store those same records…
Remember "a series of tubes" memes long predating youtube or its many pornographic not-quite-competitors?
It may map to better understanding but it is still ignorant as somebody software proposing applying computer antivirus software style scanning to infectious disease gene scanning of all micro-organisms in the body.
Even if the metaphor is technically correct in some aspects (the microbes being unauthorized executables in a space) the differences are substantial enough that it cannot be called anything but ignorant by those in the know who would point out precisely the current limitations and theoretical impossibilities like "we can't read cell DNA without destroying them currently". In the case of the safe analogy it is essentially impossible for someone to wind up ordered to open a random piece of garbage that is indistinguishable from a safe. Unlike with encryption.
Re: An even worse anti-encryption bill than EARN IT
#324Please stop voting dumbasses in the US, it affects everyone living in countries who have commercial agreements with then
Unfortunately only dumbasses vote. Smart people won't vote away their souvereignty to others who are then going to make far reaching decisions about their life. Basically it's choosing to become a slave.
Re: An even worse anti-encryption bill than EARN IT
#325Earlier quoted context omitted.
People won't vote for them. Everyone complains about how politicians behave, but the truth is that they won't vote for you unless you behave like a politician. Voters are just as two-faced as the representatives they complain about.
Not true. We have a pirate party that has like 20% of the mandates in the capital city leadership (won the last election), and 11% in the parliament. Currently it polls around 17% for the parilamentary elections (second place) https://www.ceske-volby.cz/2020/06/14/preference-kantar-cz-c...
Re: An even worse anti-encryption bill than EARN IT
#326What’s the situation when two (ostensibly friendly) superpowers, the US and EU, have totally mutually incompatible laws regarding something totally transnational? I’m not asking rhetorically, I’m asking legally, what is a company to do if they want to do business in both locations?
Effectively the solution has been an effective hard split into two companies one for each set of laws. They certainly have to sever monetary and organizational ties to not locally be engaged in conspiracy. Without coordination or assistance they have no responsibility to tbeir illegal twin abroad.
They do what they can get away with locally and relying upon their counterpart's enforcement failures abroad. It may be illegal but if they are in another superpower's territory entirely they are protected. Being fully lawful to both at once was precluded so they effectively become mirror universe versions of themselves lawful in one and scofflaw in the other.
Other less shady alternative approaches include withdrawing from one superpower and shifting their business entirely or simply deciding to dissolve themselves entirely and distribute their assets to the shareholders.
Re: An even worse anti-encryption bill than EARN IT
#327Earlier quoted context omitted.
We (HNers) might not fall for it but the proven technologically illiterate Representatives and their staff just might. This is why citizen's lobbying is so important. If the lawmakers are willfully ignorant - or in this case willfully arrogant about attacking encryption - the only thing that will get them to vote the right way is to hear from enough real constituents that the lawmakers feel like their reelection will…
If you live in California, let Senator Feinstein's office know you're not pleased with this. Unfortunately I don't think she's up for reelection this year, but if she doesn't retire next year, consider not voting for her in the next primary, Feinstein was one of the EARN-IT Act's sponsors, and a long-time opponent of cryptography.
Thank you for writing to me to share your concerns about law enforcement access to encrypted communications. I appreciate the time you took to write, and I welcome the opportunity to respond.
I understand you are opposed to the “Eliminating Abusive and Rampant Neglect of Interactive Technologies (EARN IT) Act of 2020” (S. 3398), which I introduced with Senators Lindsey Graham (R-SC), Richard Blumenthal (D-CT), and Josh Hawley (R-MO) on March 5, 2020. You may be interested to know that the Senate Judiciary Committee - of which I am Ranking Member - held a hearing on the “EARN IT Act” on March 11, 2020. If you would like to watch the full hearing or read the testimonies given by the hearing witnesses, I encourage you to visit the following website: https://sen.gov/53RV
The “EARN IT Act” would establish a National Commission on Online Sexual Exploitation Prevention to recommend best practices for companies to identify and report child sexual abuse material. Companies that implement these, or substantially similar, best practices would not be liable for any child sexual abuse materials that may still be found on their platforms. Companies that fail to meet these requirements, or fail to take other reasonable measures, would lose their liability protection.
Child abuse is one of the most heinous crimes, which is why I was deeply disturbed by recent reporting by The New York Times about the nearly 70 million online photos and videos of child sexual abuse that were reported by technology companies last year. It is a federal crime to possesses, distribute, or produce pictures of sexually explicit conduct with minors, and technology companies are required to report and remove these images on their platforms. Media reports, however, make it clear that current federal enforcement measures are insufficient and that we must do more to protect children from sexual exploitation.
Please know that I believe we must strike an appropriate balance between personal privacy and public safety. It is helpful for me to hear your perspective on this issue, and I will be mindful of your opposition to the “EARN IT Act” as the Senate continues to debate proposals to address child sexual exploitation.
Once again, thank you for writing. Should you have any other questions or comments, please call my Washington, D.C. office at (202) 224-3841 or visit my website at feinstein.senate.gov
Re: An even worse anti-encryption bill than EARN IT
#328Earlier quoted context omitted.
> Do you think, in that scenario, that safe manufacturers should be required to make a master key and distribute it to law enforcement? I'm not sure, to be honest, but I think it's certainly a reasonable position to take. > IANAL, but as far as I know, if the police can't physically break into your safe, there is nothing saying that they have any legal recourse to compel you to open it. If it can be established that…
> If it can be established that the safe is yours and that you possess the key or know the combination, I believe a court can indeed order you to open it or to produce the contents, punishable by contempt of court. I got curious about this, so I did some quick research. Again, IANAL, but my understanding is that, in the US, the court can order you to give up the physical key (if it is determined that you have it) but…
Not exactly. Yes, revealing the combination requires the person to implicitly admit that they know the what the combination is. But if the government can prove that they already know this "testimony" -- which they can in most cases -- then the "foregone conclusion" doctrine applies and the 5th Amendment privilege cannot be asserted. See, for example, the Massachusetts Supreme Court's decision in Commonwealth v. Jones. [1]
There is also conflicting 11th Circuit precedent that further requires the government to establish with "reasonable particularity" what is on the encrypted device. [2] In my opinion this is not correct; the contents of the drive have nothing to do with the testimonial value of the combination. In any event, this issue will eventually need to be resolved at the Supreme Court.
> I think it is unreasonable because it's asking companies to willfully violate their user's privacy and trust, and to severely undermine encryption as a whole. There is zero chance that this does not get abused.
I don't see how it violates user privacy or trust. In general, you don't have the right to keep records secure from law enforcement if they have a warrant. If this law is passed, these companies should simply disclose to their customers that they will provide law enforcement with the means to decrypt their data, as many already do.
I also don't see how it severely undermines encryption. Yes, end-to-end encryption is more secure, but it's not the industry norm. Security is relative, but I wouldn't call Gmail "insecure" just because Google allows law enforcement to read emails with a warrant.
[1] https://www.socialaw.com/services/slip-opinions/slip-opinion...
Re: An even worse anti-encryption bill than EARN IT
#329Earlier quoted context omitted.
> Whatever technical solution you come up with will simply be made illegal if anyone but the nerdy 0.0001% will end up using it. But that never happened with BitTorrent. Conversely, industry gradually stopped caring about pursuits of IP violators. While this is ultimately a political problem it will only be practiced where it’s enforceable like all other political problems.
Nobody really uses Bittorrent to undermine the police state. They don't care about your dealings with the media industry as much. And hey, why didn't you say "but that never happened to encryption"? Because it's about to happen in the US? Because it happened in Australia already? You think a government that is seriously considering such bills will "gradually stop caring" about assaulting constitutional protections by…