Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

331–340 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#331

Earlier quoted context omitted.

> Today many argue the state has a need to access such correspondence to prevent crime, but such a need is like the need of an addict: nothing good can come from it and the people should not enable these institutions to satisfy an ever growing demand for insight into their private lives. One must remember that democracy is founded on the believe that thoughts and words are not crimes and everyone must be free to expr…

> We need to rather argue that the moral cost and side-effects of public surveillance far outweighs its usefulness. The argument I make is that it is more cost effective to develop a society where one does not need to commit crimes to get by in the first place. Law enforcement is reactionary and can only punish when crimes are already committed. While we shouldn't get rid of law enforcement, because crime will always…

It's very clear that the people in power in the UK and USA don't want the law to be enforced. They seemingly don't want low-crime society, they want only to be immune to prosecution themselves.

Your idea seems predicated on people in general being benevolent towards others. That's not going to work, there's a significant motivated cadre who want to do terrible things provided they 'win'. You don't enlist Cambridge Analytica when you think you're right, you do that sorry of thing when you don't care about being right/moral/legal but only about subjugating others.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#332
post #297

Earlier quoted context omitted.

Both can be done, activist opposition, and a practical move to build the tools that make circumventing such privacy-hating regulatory nonsense all the more easy to pull off. More simply put: while active public opposition to bad laws is good, few things nullify bad laws better than a fait accompli that's out of the bag.

The first half I disagree with: if a law is passed, circumvention tools won’t help. This is what it seems like you have been arguing for up till now, and frankly not getting traction. However, the second part (about the fait accompli) is a very important point. You’d have to achieve widespread usage among the general population for this to be effective to be effective.

I don't see how you could disagree on the first point though. Not only is is often done today to varying degrees of success depending on country and technology, it was exactly how much of consumer crypto got its start back in the earlier days of the internet. During the 90's technologies like RSA, PGP and others basically got built and released while constantly treading all over extremely shaky legal ground. It was their widespread usefulness and steadily growing adoption by users that allowed them to in effect circumvent archaic laws until they were simply recognized as legally usable.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#333

Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…

I agree. If we allow the state to start reading all of our correspondence, we are going to start losing our freedoms at a far faster rate than we already have.

Reflecting on this I think we're watching the wrong people.

Politicians in general have shown they don't have the moral probity to be trusted to direct a democracy.

We need a sort of reverse-Stasi. Everything a senior politician does should be reviewed and only closed if it is provably personal and without public interest.

Maybe our politicians need to wear bodycams.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#334

Earlier quoted context omitted.

> We need to rather argue that the moral cost and side-effects of public surveillance far outweighs its usefulness. The argument I make is that it is more cost effective to develop a society where one does not need to commit crimes to get by in the first place. Law enforcement is reactionary and can only punish when crimes are already committed. While we shouldn't get rid of law enforcement, because crime will always…

It's very clear that the people in power in the UK and USA don't want the law to be enforced. They seemingly don't want low-crime society, they want only to be immune to prosecution themselves. Your idea seems predicated on people in general being benevolent towards others. That's not going to work, there's a significant motivated cadre who want to do terrible things provided they 'win'. You don't enlist Cambridge An…

> You don't enlist Cambridge Analytica when you think you're right, you do that sorry of thing when you don't care about being right/moral/legal but only about subjugating others.

Be careful about how you frame that. While this is true of some people who engage in activities like this, there is also the "ends justify the means" group. The latter does believe what they are doing is right and moral, and that being right and moral justifies behavior that is illegal. It's easy to be cynical and assume that the latter group is just the former group deluding themselves, but there are people who genuinely think that way. Addressing them requires a different approach than addressing those who just want power and control by any means.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#335
post #56
post #45

Earlier quoted context omitted.

Actual competition for ISPs / access provision is required for this. All consumer ISPs still ban "servers" on their pipes; this is a clear sign of insufficient competition.

My consumer ISP allows me to host servers. I can add on a static IP for a few bucks a month and as long as I don’t break any laws they’re cool with it. Previously I had “business class” internet but that is just the name of the plan. Anywhere there was cable I could get business class plans.

> Anywhere there was cable I could get business class plans.

The one time I tried to get a business-class connection from Time Warner they refused to offer any business-class service to a non-commercial address except for their "Home Office" plan, which was basically just their top residential plan with a better SLA.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#336

Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…

Someone’s been reading their Neal Stephenson.. :))

heck yeah! Baroque cycle!

Re: Stop the Earn IT Bill Before It Breaks Encryption

#337
post #254

Earlier quoted context omitted.

To paraphrase someone I know, "once they run out of criminals, they'll just start catching people they don't like". Once they have this ability, it will be much harder to make them give it up.

>To paraphrase someone I know, "once they run out of criminals, they'll just start catching people they don't like". >Once they have this ability, it will be much harder to make them give it up. There's an argument to be made that this is already happening and, in fact, has been happening for decades. I'm of course referring to the "War on Drugs." There's quite a bit of analysis in the literature to show that restric…

>Once they have this ability, it will be much harder to make them give it up.

There's an argument to be made that this is already happening and, in fact, has been happening for decades.

Notable examples are RICO Laws, FISA courts and the PATRIOT act. So. Yes.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#338
post #252

Earlier quoted context omitted.

Would a bill really eliminate the concept altogether? It might make their business more expensive in certain parts but there are multi-billion dollar criminal empires that invest in things like their own submarine tech. Do you think e2e encryption isn't something they'd develop in-house & resell to each other? At best it might help catch some street level crime but any serious organized crime (which arguably is a big…

>criminal empires True, you can’t stop math but you can try to police it. You can regulate consumer access. Doing so means one less “gone dark” area, which makes LE job easier. >security exploits To your point about low level criminals: Now that the cat is out of the bag, yes, surveillance worked way better when people didn’t know about it. Yes, more sophisticated criminals will try to employ their own encryption. If…

> Yes, which is why it is imperative to continually improve and audit such systems, including maybe removing such single points of failure as you noted, both from an insider threat perspective as well as from exploit discovery processes.

Can you join me on a journey to build this hypothetical world to figure out how this addresses the Snowden leak?

Let's imagine a world where every single server had a registered backdoor key. This key also isn't the key itself. No, we're smart. It's instead used to sign one-time use, timestamped keys that give you access. We assume all these servers are also somehow always running the latest version of the software to implement the backdoor to address any exploits that may have been discovered.

We control access to this carefully so that you can only request a code & this is validated by all kinds of bureaucratic controls that are never violated for expediency & no mistakes ever needed. Also the system handing out codes itself doesn't even have the keys. It has a temporary key that can't generate valid signatures past its expiration. To regenerate, we go into a fortified secure vault that is air-gapped. This air-gapped system is used to generate a new key, burning it onto a CD-ROM. So your admin has to, on a monthly basis, go into the vault to generate some secret that can be used to continue backdoor access.

Now imagine your admin going into the vault on a monthly basis with a CD-ROM drive that gets burned is Snowden. You've now stolen the root keys for every machine out there.

Let's also remember a few things that are elided for this hypothetical world we've built. 1. I may have gotten some details wrong here, but this is really close to how OS updates are handled by Google & Apple. This is treated as one of the most secure ways to do software deployment at scale (we're not talking about one-off carefully controlled & vetted backdoors which are a wholly different problems). 2. Software deployment is hard. There's no world in which you will instantly deploy a security fix to your backdoor code. Some machines don't have good uptimes & others can be mostly invisible to the internet. Mobile operating systems are different as Google & Apple dictate the HW design. Google has struggled here more pulling vendors along to do the good security things. Are you proposing we standardize on Apple hardware for everything? 3. If you have the ability to deploy code to any random machine, that deployment mechanism is a target in and of itself. Since every US machine has to implement it in this hypothetical world, this is an attractive exploit. It's easier to secure but now the value of compromising it has increased exponentially. We haven't heard of any exploits of this but given the value already (& exponentially more if we're talking about every single system in the US), we're looking at threat actors with ridiculously deep bank accounts & access to technical expertise. 4. Timestamps are hard. You're talking about every single machine in the world. There's plenty running the wrong time. So someone changing the clock breaks your ability to backdoor (unless you ignore timestamps, but then your keys you're generating are reusable on that website at least). 5. Key rotation & management is insanely hard. You're talking about every machine in the US. Even every server. Mistakes will happen at this scale so your backdoor either won't work (best case) or you'll have unintended compromises (or likely both). 6. Complexity & security are diametrically opposed. The more complexity you add the less secure you are. Modern machines are already ridiculously complex. 7. Everyone outside of the US (including US companies that have servers abroad) will not implement the backdoors. But may implement the backdoors the other nation states will force them to adopt. Sure, it's great if you're the US forcing your way to gain advantage over other countries. How do you keep these systems segmented so that a backdoor from another country doesn't give you access to the US? Moreover, let's say the US implements an impenetrable system. Do you think other countries will care to do the same? Does the US share our tech with them at the risk of making it even easier to find flaws? Also how do we manage distribution of such software when there's a flaw?

No amount of advise to "invent better math" solves the fact that this isn't a technical problem. No amount of "build things better" solves the fact that software engineering is hard & we have 0 examples, even in "big tech" which invests billions here annually, of building truly secure systems that are actively trying to prevent any backdoor/exploit. Above all else, you're proposing a single point of failure for the entire US economy. You can use this to conduct industrial espionage at an even larger & easier scale than happens today or to take down critical infrastructure in a time of conflict.

Is there something I missed in my analysis? What part can we "do better" on that doesn't result in exposing a significant vulnerability?

Re: Stop the Earn IT Bill Before It Breaks Encryption

#339
post #322

Earlier quoted context omitted.

> I feel disregarding the usefulness of surveillance is part of the problem. We should not be arguing that that nothing good comes out of surveillance. It provides your opponent an easy strawman for a hollow victory. Because frankly, surveillance is a useful tool for law enforcement. In this regard I recommend you go look into the evidence on mass surveillance. There have been several reports done on the mass surveil…

Using "it doesn't work" as an argument is a losing battle. If you even manage to convince people of that, best case they'll still be in favour "just in case it does work". The actual, real point is that they're underestimating the downsides or surveillance, and that even if it would work, it would still not be worth it. That's the only argument that can hold, and the actual reason we're against it.

Agreed. I would dismiss those arguments under the well established heading of: "The ends justify the means"

Re: Stop the Earn IT Bill Before It Breaks Encryption

#340
post #230

Earlier quoted context omitted.

> Today many argue the state has a need to access such correspondence to prevent crime, but such a need is like the need of an addict: nothing good can come from it and the people should not enable these institutions to satisfy an ever growing demand for insight into their private lives. One must remember that democracy is founded on the believe that thoughts and words are not crimes and everyone must be free to expr…

> We should not be arguing that that nothing good comes out of surveillance. The problem is that we, the people, can never know what, if any, good is coming out of surveillance. Attorney General Barr admitted that in one of his speeches arguing for back doors in encryption. The government cannot reveal what is being discovered through surveillance without disclosing sources and methods that it (understandably) wants…

Hmm, that's a good point. It is a problem. And a problem for both sides.

If X is the amount of utility coming out of surveillance, and you cannot know X, then you cannot argue that X = 0 or that X > Y (for any Y you want to pick, like downsides of surveillance) or that X Essentially it becomes impossible to rationally debate the issue on the basis of whether it is a net gain.

Which means you need to fall back on other forms of reasoning. A reasonable position is that freedoms shouldn't be sacrificed for something whose utility cannot be demonstrated. But that's an argument about what sorts of justifications are required for laws, not about how much utility the law would have.

Post reply on HN