Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

281–290 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#281

Earlier quoted context omitted.

This means anyone implementing and using effective crypto will be flagged for closer monitoring. A jury is made up of twelve people who aren't smart enough to get out of jury duty. It won't be hard for a prosecutor to convince them that going out of your way to use encryption is proof of possessing child pornography. Or terrorist stuff. Or drug stuff. Or whatever else people are terrified of at the time.

Then start sending random bytes of everyone. Random bytes are undistinguishable from encrypted data. If everyone is in possession of what appears to be encrypted data, then it's no longer reasonable cause for suspicion.

Unless receiving/storing unexplainable random bytes becomes illegal (like "forgetting" your password).

Re: Stop the Earn IT Bill Before It Breaks Encryption

#282
post #41

Earlier quoted context omitted.

Well, no. That's the issue! If you only have peer-to-peer encryption with communications still passing through servers unencrypted then, sure, you can get a warrant to force disclosure. With end to end encryption, however you can show up with a warrant all you want it makes no difference because they physically cannot hand you clear-text communications. Same for encryption at rest. The strength of the encryption algo…

> With end to end encryption, however you can show up with a warrant all you want it makes no difference because they physically cannot hand you clear-text communications. Well, no. That's the issue! They shouldn't be executing search warrant behind your back to some their party that happens to be stirring your data. They should execute the search warrant on the person who owns the data they're investigating. If they…

> If they refuse to give the data you have a warrant for they broke the law.

Warrants aren't issued for data, they're issued for property. A warrant authorizes law enforcement to search for and/or seize evidence (i.e. physical property) without regard for the owner's property rights. The owner doesn't have to give them anything or aid the search in any way beyond simply not interfering. Standing back and leaving them to break into the safe on their own does not violate any law. You might open it anyway just to show goodwill and avoid damage to the safe, but there is no obligation to do so, and unnecessarily demonstrating that you have the ability to open the safe may, in certain situations, amount to testifying against yourself.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#283

Earlier quoted context omitted.

They used to be able to record phone calls with a warrant. They used to be able to read letters with a warrant, IIUC. With E2E encryption now widely available, no sane criminal will use any non-encrypted channel. So, a lot of methods law enforcement used to find very helpful effectively no longer exist. The steelman principle says that this is what you need to argue isn't a problem. Disclaimer: I lean towards the EFF…

Perhaps what we need to be doing is not finding new and creative ways for law enforcement to read people's correspondence, but finding new and creative ways to eliminate the underlying factors that cause people to turn to crime in the first place.

But if the government stopped the factors that lead to crime, then how could it justify its massive spending on a surveillance and selective enforcement regime that it can use against its political enemies (e.g. voters in the wrong demographics)?

Re: Stop the Earn IT Bill Before It Breaks Encryption

#284
post #274

Earlier quoted context omitted.

They used to be able to record phone calls with a warrant. They used to be able to read letters with a warrant, IIUC. With E2E encryption now widely available, no sane criminal will use any non-encrypted channel. So, a lot of methods law enforcement used to find very helpful effectively no longer exist. The steelman principle says that this is what you need to argue isn't a problem. Disclaimer: I lean towards the EFF…

I don't think the cops ever needed widespread surveillance capability. They can park a van across the street from my house or office. They don't need access to the telco infrastructure to do their jobs. The lack of foresight in previous generations is not an excuse to perpetuate their mistakes.

I'm not talking about widespread surveillance.

Decades ago, if they had evidence you were involved in crime, they could apply for a warrant to tap your phone, search your house, or read your mail.

That's focused surveillance, not mass, and it's under the oversight of a judge.

In a world of end-to-end encryption, they can't realistically find useful evidence by doing those things any more.

Parking their van outside doesn't help as much, either - you can conspire to commit crimes quite easily without ever leaving your house or having confederates come there, thanks to encrypted video chats.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#285

Earlier quoted context omitted.

Then start sending random bytes of everyone. Random bytes are undistinguishable from encrypted data. If everyone is in possession of what appears to be encrypted data, then it's no longer reasonable cause for suspicion.

Unless receiving/storing unexplainable random bytes becomes illegal (like "forgetting" your password).

Right that's why you send random bytes to other people. You're forcing everyone else to receive or store random bytes. Thus rendering any actual enforcement of a law forbidding possession of encrypted data (or random bytes) nigh-impossible.

If someone gets charged for possession of random bytes, send the prosecutor and judge a bunch of random bytes and see if they're still intent on moving forward with charges.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#286

Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…

Everyone should be able to read private politician's correspondence and what they are up to. We should also know their bank accounts and their location at all times. Why should government know those things about us but we can't know that about them? That's a modern slavery.

Everybody should be able to read the private correspondence of politicians? That's absurd. Politicians are (believe it or not) people too, and have families, and relationships, and private lives. We should absolutely be able to read all their work related material, but private things should stay private.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#287

All of you smart arses out here and there, we know it, we know. We know, VPNs and other stuff in between are not so secure and not private. Stop saying it, don't you have some other piece of knowledge to be proud of? for god's sake. Tor and Signal are better than Public Cloud, Chrome & SMS if you're looking for privacy. Don't you have common sense? - HTTPS is more secure and private than HTTP - Signal is more secure…

I don't understand what people have against VPNs. I don't want my ISP knowing when I use Tor, since my ISP is in the same country as me and that makes it easier for them to have access to me if they wanted to. Using a VPN means my ISP only sees me connecting to a VPN (which is arguably more innocuous). Then you can use Tor from there. And if you only use HTTPS sites, then only you and the end site can read the traffic. And obviously don't login to accounts created outside of Tor or that use details that can lead back to your real identity.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#288

Earlier quoted context omitted.

Rather than calling for backdoors, or secret rooms, this law explicitly prevents civil lawsuits or criminal prosecution for companies that refuse to install backdoors or use end to end encryption that they cannot crack. I'm not really sure what the EFF is unhappy with about this act, since their complaints don't seem to be reflected in the text. From the act: CYBERSECURITY PROTECTIONS DO NOT GIVE RISE TO LIABILITY.—N…

https://www.eff.org/deeplinks/2020/07/new-earn-it-bill-still... > Sen. Leahy’s amendment prohibits holding companies liable because they use “end-to-end encryption, device encryption, or other encryption services.” But the bill still encourages state lawmakers to look for loopholes to undermine end-to-end encryption, such as demanding that messages be scanned on a local device, before they get encrypted and sent alon…

How does the bill encourage that? Unless I'm really missing something, the language in the new child pornography section is the same as the current language in section 230e covering sex trafficking. That existing sex trafficking clause hasn't done any of the things that the EFF says this new one will do.

The original Earn It Act was bad. But that bad stuff has been massively ripped out. Plus real protections for privacy added in. It's not the same as it was - look up the text and compare what's been struck through with what is left.

I think in the current form it's a definite win for privacy and common sense.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#289

Here is the contact form for the Senator who is Chairman of the Committee on Commerce, Science, and Transportation. I'm pretty sure that's the committee who would be involved with this bill. https://www.wicker.senate.gov/public/index.cfm/contact

It already passed through the Senate Judiciary Committee unanimously

i didn't know that. what does that mean for the fate of this bill? doesn't that just mean that the senate must consider it? does the commerce committee have anything to do with it? since they oversee commerce and basically the internet (at least from what little i know...)
Post reply on HN