Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

231–240 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#231
I have been wondering if there is a way to satisfy law enforcement without breaking encryption or adding backdoors. An idea: what if platforms allowed law enforcement (with a warrant) to conduct rainbow table attacks against encrypted content of a specific user? In other words, what if platforms allowed law enforcement to determine whether a specific known object (e.g. a known photo or video) was sent / stored by a user rather than decrypting all sent or stored objects?

This would allow law enforcement to track the spread of a known piece of content while avoiding breaking encryption. Perhaps it could be a compromise.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#232
post #180

Earlier quoted context omitted.

> Today many argue the state has a need to access such correspondence to prevent crime, but such a need is like the need of an addict: nothing good can come from it and the people should not enable these institutions to satisfy an ever growing demand for insight into their private lives. One must remember that democracy is founded on the believe that thoughts and words are not crimes and everyone must be free to expr…

By the same token, one could say that extra-judicial torture could have "usefulness" as you put it. We could have a similar discussion of how absolutists on the torture question aren't doing a proper cost/benefit analysis and are "providing their opponents an easy strawman for a hollow victory." I know this is Hacker News, but not every argument requires infinite nuance, we don't need to sit down and examine the pros…

The nuance here is pretty blunt: no matter how useful torture is, it is never enough to legalize it.

Same with banning secure private communication.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#233
post #147

Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…

serious q: encryption challenges the authority of government and the power of its leaders. Why would they willingly give up this power, when they can manufacture consent[1] via a perpetual state of war[2] ? [1] https://www.google.com/search?q=manufacturing+consent [2] https://www.google.com/search?q=perpetual+war

The ability to manufacture consent is finite, even in North Korea.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#234

Earlier quoted context omitted.

And actually, the latest xkcd says it better than me: https://xkcd.com/2368/

I see heavy security with zero recourse by anyone to break it and anonymity is the top single problem with the Internet, not the lack of it. We should all have to log on with our identification through a blanket "know your customer" law like they do to combat money laundering in banks, and our country of origin at least should be displayed. Other than that... You want encryption? Fine, but if your id links you to 4ch…

I respectfully disagree with most of this. The last part was a bit all over the place though, not sure where exactly you were going.

Others who know history much better than me are far better equipped to debate against your position. If you really want a challenge, I would invite you to reply to the top comment in this thread by Jon_Lowtek to help open a discussion on the deeper merits of your position. For me personally, your arguments aren't very persuasive.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#235
post #206

Earlier quoted context omitted.

We know from Snowden that the NSA actively and covertly submitted code to open source projects including Android\Linux: https://www.androidauthority.com/nsa-android-code-239118/ They're also involved in the Coreboot alternative BIOS project: https://www.tomshardware.com/news/nsa-contributes-low-level-... One of the key revelations from Snowden was that all that stuff that seemed far fetched or paranoid to us, wasn't…

So to hide a backdoor in a opensource software it's the best solution to tell the world that you (the NSA) is actively working on a Project? Like SELinux? Man do you think they are stupid? They work on those projects to make their own infrastructure more secure, don't you think every one looks on their fingers/commits? >You should also consider as a swiss citizen that US law is increasingly world law That's Bullshit,…

Per the links above, they didn't tell anyone, Snowden outed them.

In the cold War it was true of the western world and the USs use was limited because the US wanted to look gentle and reasonable. Today it's true for most of the planet and the US wants to look tough.

If you don't like the Assange case (I agree the brits are lap dogs, but that case actually got kicked off in Sweden and was handled under EU law much more aggressively than the in UK), try the FIFA case. The US ordered Switzerland to arrest and extradite foreign nationals, many had never set foot in the US for trial, Switzerland obeyed...

https://www.washingtonpost.com/news/the-fix/wp/2015/05/27/ho...

I don't like any of this. But it's time to abandon our innocence. If you're working on any meaningful project in encryption, the NSA are at least aware of you. The US are happy to use covert methods to undermine you if they think its worth it (and the bar is low). If you're important enough (or a DA wants to expense some flights) they'll use overt methods. Proceed at your own risk and don't assume that America banning encryption doesn't make it illegal for you just because you're a Swiss citizen in Switzerland.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#237

I have been wondering if there is a way to satisfy law enforcement without breaking encryption or adding backdoors. An idea: what if platforms allowed law enforcement (with a warrant) to conduct rainbow table attacks against encrypted content of a specific user? In other words, what if platforms allowed law enforcement to determine whether a specific known object (e.g. a known photo or video) was sent / stored by a u…

Maybe this is possible instead with homomorphic encryption.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#238

Earlier quoted context omitted.

If you have been defeated, acknowledging it is crucial. It's hard to make progress while denying the actual nature of the situation. Not saying that's necessarily true in either of these situations, just that it's not a waste of energy to spread depressing truths.

"it's not a waste of energy to spread depressing truths." It certainly is, if those "truths" are not absolutes. Find a way to redirect your -- and others' -- energies toward something positive and constructive. Spreading doom and gloom, full stop? Always a waste.

If you never move on to constructive action, that's a problem, for sure.

However, telling a sad or difficult truth and stopping there is still a big improvement on pretending there was no issue in the first place.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#239
I don't get the sudden press on this bill. It was introduced in March, and it was added to the Senate calendar in July. There was one hearing back in March, yes, but there isn't even a companion bill in the House at this point. Don't get me wrong, it's bad legislation, but is there some imminent action planned?

https://www.congress.gov/bill/116th-congress/senate-bill/339...

Re: Stop the Earn IT Bill Before It Breaks Encryption

#240
post #71

Earlier quoted context omitted.

Do you really see most people leaving the likes of Facebook, Instagram and Twitter? I don't think they care about privacy enough to stop doing what's easy and fun

People have been leaving Facebook in droves. Hardly any of the original users use the platform regularly. Facebook has only remained relevant by buying relevant platforms as they start to take off. Companies that declines an offer or regulation to prevent this buy up behavior is what it takes. Social networks have no monetary buy in to discourage switching the moment your friends aren't on the platform any longer

You might get this impression if your main source of news is HN, but Facebook's monthly traffic among North American users has been steadily climbing quarter after quarter, year after year. Globally, it's up 8% YoY.

https://www.statista.com/statistics/247614/number-of-monthly....

Post reply on HN