Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

201–210 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#201

PGP was specifically created to combat this sort of legal threat. It is proof that encryption is ultimately controlled by individuals. The identity management is completely decentralization and it works over pretty much any medium. It seems that the world has somehow forgotten the lesson. People can only see the centralized systems and don't realize that the problem they are trying to solve is not solvable in general…

Encryption might be unstoppable but they can always just assign you an IPV6 address and encryption fingerprint that becomes your new online social security number that is required from the compiler on up. Notarize your apps buddy and sign into your app account... ;)

The threat here is not against anonymity, it is against encryption.

You can make as many PGP identities as you want and associate them with any sort of identity you desire, so there might be a political point available with respect to anonymity as well in some situations.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#202

Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…

Rather than calling for backdoors, or secret rooms, this law explicitly prevents civil lawsuits or criminal prosecution for companies that refuse to install backdoors or use end to end encryption that they cannot crack. I'm not really sure what the EFF is unhappy with about this act, since their complaints don't seem to be reflected in the text. From the act: CYBERSECURITY PROTECTIONS DO NOT GIVE RISE TO LIABILITY.—N…

https://www.eff.org/deeplinks/2020/07/new-earn-it-bill-still...

> Sen. Leahy’s amendment prohibits holding companies liable because they use “end-to-end encryption, device encryption, or other encryption services.” But the bill still encourages state lawmakers to look for loopholes to undermine end-to-end encryption, such as demanding that messages be scanned on a local device, before they get encrypted and sent along to their recipient.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#203

PGP was specifically created to combat this sort of legal threat. It is proof that encryption is ultimately controlled by individuals. The identity management is completely decentralization and it works over pretty much any medium. It seems that the world has somehow forgotten the lesson. People can only see the centralized systems and don't realize that the problem they are trying to solve is not solvable in general…

You don't seem to understand that this is not about us, but about the average joe who will never learn about PGP.

Average Joes routinely use PGP on the darknets. So we even have a good current example of how encryption used in crime can come in a form that this legislation is powerless against.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#204

If you're so scared about your government that your activity might get you thrown away for life and it doesn't involve murdering someone, then you need better government, not better security because those kinds of governments will just say you murdered someone without any proof and lock you up or kill you anyway if they don't like you.

Better government and better security are not mutually exclusive. You can work towards both simultaneously, and claiming that one negates the other is a logical fallacy.

And actually, the latest xkcd says it better than me:

https://xkcd.com/2368/

Re: Stop the Earn IT Bill Before It Breaks Encryption

#205
post #147

Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…

serious q: encryption challenges the authority of government and the power of its leaders. Why would they willingly give up this power, when they can manufacture consent[1] via a perpetual state of war[2] ? [1] https://www.google.com/search?q=manufacturing+consent [2] https://www.google.com/search?q=perpetual+war

While morally reprehensible, endless "safe" wars are pretty profitable for industry owners if they are run in countries that do not target their valuable industries. Since the tax payer is footing the bill for it all, they're the ones who have to concent to it. Or perhaps not.

Using the invasion of Iraq as an example, there has been many years where public opinion was negative, or at least lukewarm, towards the invasion, though not violently so. Casually reviewing the polling history, this can be observed as early as in 2004. [1] But I think one can safely say that the war hasn't been at the forefront of most people's minds during the last few decades, except for the very beginning. But then, there has been very little mention of the financial cost of the war in the media, if any. And why would there be, as the media also earns a lot of money on these "safe" wars.

The video “Troops Versus Building --- an Iraq War tale” by soldier grunt Blacktail should give you a pretty hands-on idea of the financial cost of the war, however. [2]

[1]: https://en.wikipedia.org/wiki/Public_opinion_in_the_United_S...

[2]: Troops Versus Building --- an Iraq War tale, 24 Nov 2009, Blacktail, https://youtu.be/2N-1E2F9pmc

Re: Stop the Earn IT Bill Before It Breaks Encryption

#206
post #88

Earlier quoted context omitted.

>Plus if you really really want to know what's happening there, call the NSA Not sure if they give me any information as a Swiss citizen :-) >They'll send a few chaps to join the matrix dev community That's probably more on the James Bond side of reality >Or they'll use other tools to access the machines in question Yes that's what they probably will do, but that is targeting and not a Backdoor/break encryption by la…

We know from Snowden that the NSA actively and covertly submitted code to open source projects including Android\Linux: https://www.androidauthority.com/nsa-android-code-239118/ They're also involved in the Coreboot alternative BIOS project: https://www.tomshardware.com/news/nsa-contributes-low-level-... One of the key revelations from Snowden was that all that stuff that seemed far fetched or paranoid to us, wasn't…

So to hide a backdoor in a opensource software it's the best solution to tell the world that you (the NSA) is actively working on a Project? Like SELinux? Man do you think they are stupid? They work on those projects to make their own infrastructure more secure, don't you think every one looks on their fingers/commits?

>You should also consider as a swiss citizen that US law is increasingly world law

That's Bullshit, was probably half true in the Cold War era but for sure not today.

> They're doing that to Assange right now.

That's England, you know those little dogs of yours.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#207

Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…

> Today many argue the state has a need to access such correspondence to prevent crime, but such a need is like the need of an addict: nothing good can come from it and the people should not enable these institutions to satisfy an ever growing demand for insight into their private lives. One must remember that democracy is founded on the believe that thoughts and words are not crimes and everyone must be free to expr…

I agree with your conclusion.

However I think it’s a very serious fallacy to split surveillance into a ‘useful’ component and ‘side-effects’.

They aren’t side-effects. They are the effects.

Reduced crime may be a consequence of a surveillance society.

In such a society you may discover that discussing crime statistics in a negative light would reflect badly on the party bosses and must be done with caution.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#208

Earlier quoted context omitted.

Better government and better security are not mutually exclusive. You can work towards both simultaneously, and claiming that one negates the other is a logical fallacy.

And actually, the latest xkcd says it better than me: https://xkcd.com/2368/

I see heavy security with zero recourse by anyone to break it and anonymity is the top single problem with the Internet, not the lack of it.

We should all have to log on with our identification through a blanket "know your customer" law like they do to combat money laundering in banks, and our country of origin at least should be displayed. Other than that... You want encryption? Fine, but if your id links you to 4chan offshoots planning domestic terror attacks i should be able to report your address to the authorities and there should be social repercussions for bad behavior. And I need to know if you're Russian or from the US and that you're human before I engage in US politics with you.

Music got worse since Napster, Sean Parker was the guy who got Zuckerberg funded, Google is evil, and John Perry Barlow is dead.

Wake up.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#209
post #140

Earlier quoted context omitted.

This tirade and "go improve it" recommendation may make sense in a vacuum, without governments undermining encryption and criminalizing parts of the activities to provide secure, private comms "because terrorism/pornography/covid/whatever". In the real world, many states freely admit that they will fight against secure, private messaging between citizens (say, because law enforcement needs a backdoor to solve crimes)…

Why not work on said technology? It can even end up being very lucrative to take up the cause. Do you forget that prior to the 90s (and also during part of the 90s) much of the lead-in to the completely common, widely commercially and privately used digital encryption we have today was completely discouraged or even made illegal by governments except for their own use. It was a generation of pioneers who weren't quit…

I agree vehemently with your call to go work on this stuff.

What I don’t understand is why you seem to be suggesting that as an alternative to opposing legislation which would prohibit such work.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#210

Earlier quoted context omitted.

It's not that different, only that China was acting in response to the status quo of US companies dominating this global market. For most users outside of the US those companies are the default; China excepted. By 'default' I don't mean to imply that this is desirable or healthy though.

I'm not very up to date on the history of WeChat, was it launched as a reaction to US services or did it just grow organically?

It grew ‘organically’ in China where the US services were not allowed to operate.
Post reply on HN