Live data from Hacker News

An even worse anti-encryption bill than EARN IT

cyberlaw.stanford.edu

341–350 of 367 posts

Re: An even worse anti-encryption bill than EARN IT

#341

Earlier quoted context omitted.

But the beauty of E2E is that indeed it forces law enforcement to cough up a warrant.

With strong E2EE, a warrant won't do much.

A law abiding citizen might comply at the advise of their lawyer. My point is, E2E will at least ensure that warrants are used and not warrantless tactics, which seems to be an ever growing issue.

Re: An even worse anti-encryption bill than EARN IT

#343

When Phil Zimmerman created PGP one of his stated use cases was protection of speech in totalitarian regimes. Well... looks like we're approaching that use case. Encryption is permissionless by design.

Also, I think begging politicians to see it any other way is a waste of time. Widespread disobedience and resistance is the only way to knock it down. Make it cost a lot to enforce.

Re: An even worse anti-encryption bill than EARN IT

#344

Earlier quoted context omitted.

> Our word used to mean something. > But now? How can we hold a higher ground than China when our own police forces use the very same tactics against our own protesters? How can we accuse the other side of building concentration camps when we have our own? But we’ve had things like this for a long time. The police have acted like they do for generations, we had concentration camps for Japanese people during World War…

> we had concentration camps for Japanese people during World War II I study WW2, and it's important to be factual. The correct term is internment camps. Japanese-Americans usually lost their property, but the purpose was to locate them in central locations, not to re-educate or liquidate them, as our enemies did to the Allies. For that time in history, it could be argued that the decision made sense. Japanese subs d…

You are conflating extermination with concentration.

Re: An even worse anti-encryption bill than EARN IT

#345
post #262

A Twitter thread [1] from Matthew Green in this bill. Essentially he says that this bill is a dead on arrival bill which is designed to make EARN IT look like a fair compromise. And we better not fall for it [1] https://twitter.com/matthew_d_green/status/12759760840231198...

This is called the "Door in the Face technique" ( https://en.wikipedia.org/wiki/Door-in-the-face_technique )

Thanks for the reference, I didn't know that name and always called it the "aim at 1000 to get 100" rule, which is essentially trading without doing it openly.

Re: An even worse anti-encryption bill than EARN IT

#346

Earlier quoted context omitted.

With the safe analogy, I swear there's precedent that, if the security is a physical key , then a court can compel the owner to produce it. But if the safe uses a combination , the court cannot compel its divulgence, since that would violate the fifth amendment protections against being forced to testify against oneself. Encryption "keys", and the passwords from which they are commonly derived, are much more akin to…

I think there might be a circuit split on this issue, but IMO merely divulging a combination or encryption key is not "testimonial" (and therefore not a 5th Amendment violation) except insofar as it admits knowledge of the combination or key itself. But if police can establish separately that you know it, then the "foregone conclusion" exception applies. If you can point to specific precedent that would be helpful.

Did some more research on this; see this comment: https://news.ycombinator.com/item?id=23647018

Re: An even worse anti-encryption bill than EARN IT

#347

Earlier quoted context omitted.

> If it can be established that the safe is yours and that you possess the key or know the combination, I believe a court can indeed order you to open it or to produce the contents, punishable by contempt of court. I got curious about this, so I did some quick research. Again, IANAL, but my understanding is that, in the US, the court can order you to give up the physical key (if it is determined that you have it) but…

> The latter is protected by the Fifth Amendment right against self incrimination, in the same way as sharing knowledge verbally. ... If the latter, however, then there is no legal way for law enforcement to force you to decrypt the device. Not exactly. Yes, revealing the combination requires the person to implicitly admit that they know the what the combination is. But if the government can prove that they already k…

> Not exactly. Yes, revealing the combination requires the person to implicitly admit that they know the what the combination is. But if the government can prove that they already know this "testimony" -- which they can in most cases -- then the "foregone conclusion" doctrine applies and the 5th Amendment privilege cannot be asserted.

That's fascinating, thank you for sharing! That helps make my point, though, that the legal framework for handling encryption already exists and just needs to be clarified a little bit, instead of making new, far-reaching laws with serious implications on the landscape.

> I don't see how it violates user privacy or trust. In general, you don't have the right to keep records secure from law enforcement if they have a warrant. If this law is passed, these companies should simply disclose to their customers that they will provide law enforcement with the means to decrypt their data, as many already do.

It will get abused. Just like wire tapping got abused, just like NSA surveillance got abused. Furthermore, having a master key floating around means that at some point, inevitably, a foreign government or organization will get ahold of it. If this were implemented correctly—over a special, secure channel that only law enforcement could access (with a warrant!)—that would be mostly harmless, but I simply don't trust our government and businesses to implement anything correctly that has to do with the privacy and security of user data. There have simply been too many previous violations.

> I also don't see how it severely undermines encryption. Yes, end-to-end encryption is more secure, but it's not the industry norm. Security is relative, but I wouldn't call Gmail "insecure" just because Google allows law enforcement to read emails with a warrant.

But the issue with bills like the EARN IT Act is that they make end-to-end encryption completely infeasible for any company to implement. That's the problem: you can't even have E2EE in the first place if it passes, because it conflicts with the requirement to allow law enforcement to be able to read messages.

Re: An even worse anti-encryption bill than EARN IT

#348
post #262

A Twitter thread [1] from Matthew Green in this bill. Essentially he says that this bill is a dead on arrival bill which is designed to make EARN IT look like a fair compromise. And we better not fall for it [1] https://twitter.com/matthew_d_green/status/12759760840231198...

This is called the "Door in the Face technique" ( https://en.wikipedia.org/wiki/Door-in-the-face_technique )

[deleted]

Re: An even worse anti-encryption bill than EARN IT

#349

Earlier quoted context omitted.

> The latter is protected by the Fifth Amendment right against self incrimination, in the same way as sharing knowledge verbally. ... If the latter, however, then there is no legal way for law enforcement to force you to decrypt the device. Not exactly. Yes, revealing the combination requires the person to implicitly admit that they know the what the combination is. But if the government can prove that they already k…

> Not exactly. Yes, revealing the combination requires the person to implicitly admit that they know the what the combination is. But if the government can prove that they already know this "testimony" -- which they can in most cases -- then the "foregone conclusion" doctrine applies and the 5th Amendment privilege cannot be asserted. That's fascinating, thank you for sharing! That helps make my point, though, that t…

> That helps make my point, though, that the legal framework for handling encryption already exists and just needs to be clarified a little bit, instead of making new, far-reaching laws with serious implications on the landscape.

I think this can be a reasonable argument, but it depends on whether criminal suspects generally comply with decryption orders. If most don't, then it is understandable that the government also wants the keys to reside with parties that almost certainly will comply: OEMs and service providers.

> It will get abused. Just like wire tapping got abused, just like NSA surveillance got abused.

Yes, warrants get abused, but they're necessary for the criminal justice system to function.

I think we need to be careful not to conflate this issue with warrantless surveillance, which is a different beast.

> Furthermore, having a master key floating around means that at some point, inevitably, a foreign government or organization will get ahold of it.

I don't see why this is necessarily true, and many Internet services are premised on it not being true. HTTPS requires that you trust the ability of CAs to keep their master keys secret. Gmail and Outlook require that you trust that Google and Microsoft will keep their master keys secret.

> But the issue with bills like the EARN IT Act is that they make end-to-end encryption completely infeasible for any company to implement.

I realize that. My point was that there's an argument to be made that in practice, most people don't use E2EE or even need it in the first place.

E2EE is probably necessary in certain cases -- for example, if you're a dissident in an authoritarian regime. But that doesn't mean it needs to come standard on every iPhone.

To be honest, I'm undecided on this issue. Maybe the security benefits of standard E2EE are worth making it more difficult for law enforcement to execute lawful search warrants. But to me the answer isn't obvious.

Re: An even worse anti-encryption bill than EARN IT

#350

These bills terrify me. A lot of stuff happens in politics that’s frustrating, and much of it doesn’t catch my attention. There’s something about the pure ignorance that goes into breaking encryption that I can’t comprehend. I can understand when bills come through and the extreme differences in opinion are the result of different interpretations of facts and truth, but when it comes to encryption, there is no safe p…

What's more terrifying is that this is something you understand. Think of all the bills you don't understand that are just as bad!

I agree. If I had the ability to make one change in government, it would be that bills must be focused on a single topic and resolution. I don't want my members of my government voting to pass bad bills which compromised their integrity with a million small inclusions.
Post reply on HN