Earlier quoted context omitted.
This means anyone implementing and using effective crypto will be flagged for closer monitoring. A jury is made up of twelve people who aren't smart enough to get out of jury duty. It won't be hard for a prosecutor to convince them that going out of your way to use encryption is proof of possessing child pornography. Or terrorist stuff. Or drug stuff. Or whatever else people are terrified of at the time.
Then start sending random bytes of everyone. Random bytes are undistinguishable from encrypted data. If everyone is in possession of what appears to be encrypted data, then it's no longer reasonable cause for suspicion.
Stop the Earn IT Bill Before It Breaks Encryption
281–290 of 361 posts
Re: Stop the Earn IT Bill Before It Breaks Encryption
#282Earlier quoted context omitted.
Well, no. That's the issue! If you only have peer-to-peer encryption with communications still passing through servers unencrypted then, sure, you can get a warrant to force disclosure. With end to end encryption, however you can show up with a warrant all you want it makes no difference because they physically cannot hand you clear-text communications. Same for encryption at rest. The strength of the encryption algo…
> With end to end encryption, however you can show up with a warrant all you want it makes no difference because they physically cannot hand you clear-text communications. Well, no. That's the issue! They shouldn't be executing search warrant behind your back to some their party that happens to be stirring your data. They should execute the search warrant on the person who owns the data they're investigating. If they…
Warrants aren't issued for data, they're issued for property. A warrant authorizes law enforcement to search for and/or seize evidence (i.e. physical property) without regard for the owner's property rights. The owner doesn't have to give them anything or aid the search in any way beyond simply not interfering. Standing back and leaving them to break into the safe on their own does not violate any law. You might open it anyway just to show goodwill and avoid damage to the safe, but there is no obligation to do so, and unnecessarily demonstrating that you have the ability to open the safe may, in certain situations, amount to testifying against yourself.
Re: Stop the Earn IT Bill Before It Breaks Encryption
#283Earlier quoted context omitted.
They used to be able to record phone calls with a warrant. They used to be able to read letters with a warrant, IIUC. With E2E encryption now widely available, no sane criminal will use any non-encrypted channel. So, a lot of methods law enforcement used to find very helpful effectively no longer exist. The steelman principle says that this is what you need to argue isn't a problem. Disclaimer: I lean towards the EFF…
Perhaps what we need to be doing is not finding new and creative ways for law enforcement to read people's correspondence, but finding new and creative ways to eliminate the underlying factors that cause people to turn to crime in the first place.
Re: Stop the Earn IT Bill Before It Breaks Encryption
#284Earlier quoted context omitted.
They used to be able to record phone calls with a warrant. They used to be able to read letters with a warrant, IIUC. With E2E encryption now widely available, no sane criminal will use any non-encrypted channel. So, a lot of methods law enforcement used to find very helpful effectively no longer exist. The steelman principle says that this is what you need to argue isn't a problem. Disclaimer: I lean towards the EFF…
I don't think the cops ever needed widespread surveillance capability. They can park a van across the street from my house or office. They don't need access to the telco infrastructure to do their jobs. The lack of foresight in previous generations is not an excuse to perpetuate their mistakes.
Decades ago, if they had evidence you were involved in crime, they could apply for a warrant to tap your phone, search your house, or read your mail.
That's focused surveillance, not mass, and it's under the oversight of a judge.
In a world of end-to-end encryption, they can't realistically find useful evidence by doing those things any more.
Parking their van outside doesn't help as much, either - you can conspire to commit crimes quite easily without ever leaving your house or having confederates come there, thanks to encrypted video chats.
Re: Stop the Earn IT Bill Before It Breaks Encryption
#285Earlier quoted context omitted.
Then start sending random bytes of everyone. Random bytes are undistinguishable from encrypted data. If everyone is in possession of what appears to be encrypted data, then it's no longer reasonable cause for suspicion.
Unless receiving/storing unexplainable random bytes becomes illegal (like "forgetting" your password).
If someone gets charged for possession of random bytes, send the prosecutor and judge a bunch of random bytes and see if they're still intent on moving forward with charges.
Re: Stop the Earn IT Bill Before It Breaks Encryption
#286Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…
Everyone should be able to read private politician's correspondence and what they are up to. We should also know their bank accounts and their location at all times. Why should government know those things about us but we can't know that about them? That's a modern slavery.
Re: Stop the Earn IT Bill Before It Breaks Encryption
#287All of you smart arses out here and there, we know it, we know. We know, VPNs and other stuff in between are not so secure and not private. Stop saying it, don't you have some other piece of knowledge to be proud of? for god's sake. Tor and Signal are better than Public Cloud, Chrome & SMS if you're looking for privacy. Don't you have common sense? - HTTPS is more secure and private than HTTP - Signal is more secure…
Re: Stop the Earn IT Bill Before It Breaks Encryption
#288Earlier quoted context omitted.
Rather than calling for backdoors, or secret rooms, this law explicitly prevents civil lawsuits or criminal prosecution for companies that refuse to install backdoors or use end to end encryption that they cannot crack. I'm not really sure what the EFF is unhappy with about this act, since their complaints don't seem to be reflected in the text. From the act: CYBERSECURITY PROTECTIONS DO NOT GIVE RISE TO LIABILITY.—N…
https://www.eff.org/deeplinks/2020/07/new-earn-it-bill-still... > Sen. Leahy’s amendment prohibits holding companies liable because they use “end-to-end encryption, device encryption, or other encryption services.” But the bill still encourages state lawmakers to look for loopholes to undermine end-to-end encryption, such as demanding that messages be scanned on a local device, before they get encrypted and sent alon…
The original Earn It Act was bad. But that bad stuff has been massively ripped out. Plus real protections for privacy added in. It's not the same as it was - look up the text and compare what's been struck through with what is left.
I think in the current form it's a definite win for privacy and common sense.
Re: Stop the Earn IT Bill Before It Breaks Encryption
#289Here is the contact form for the Senator who is Chairman of the Committee on Commerce, Science, and Transportation. I'm pretty sure that's the committee who would be involved with this bill. https://www.wicker.senate.gov/public/index.cfm/contact
It already passed through the Senate Judiciary Committee unanimously