Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

351–360 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#351
post #230

Earlier quoted context omitted.

> We should not be arguing that that nothing good comes out of surveillance. The problem is that we, the people, can never know what, if any, good is coming out of surveillance. Attorney General Barr admitted that in one of his speeches arguing for back doors in encryption. The government cannot reveal what is being discovered through surveillance without disclosing sources and methods that it (understandably) wants…

It's often not the the government "cannot" reveal those details (maybe not immediately and directly in some cases, sure, but certainly with the distance of time that tools such as FOIA requests require), but that they "won't" and have no interest to. It should be the public demand with each attempt to increase surveillance to increase oversight. Sousveillance (watching the watchers) is the best known defense we have…

> with the distance of time that tools such as FOIA requests require

Often that is way too much time--25 to 50 years in many cases, since those are the time frames for declassification of classified information--for such revelations to be useful for oversight, especially with the state of encryption as it is since computers and the Internet.

Before computers and the Internet, it was possible to have a reasonable tradeoff between strength of encryption and the ability of law enforcement to conduct surveillance, because perfect encryption was impossible and imperfect encryption got more expensive the closer you wanted it to be to perfect. So people were already making a cost-benefit tradeoff (difficulty of breaking the encryption and obtaining private data vs. cost), and it was reasonable for the government to ask that the potential benefits of surveillance be included in the tradeoff, since that would just adjust the balance of the tradeoff, and the adjustment could be periodically reviewed based on data on past surveillance that was revealed by things like FOIA requests.

But now, with computers and the Internet, perfect encryption is cheaper than imperfect encryption. Perfect encryption is just a mathematical algorithm, and it's straightforward to put that algorithm in computer code and verify that the code correctly executes the algorithm. Imperfect encryption requires adding code to that perfect algorithm, which adds cost, and also adds a risk that wasn't even there before, of whatever back doors are in the code being exploited. So now we users, to enable surveillance by law enforcement, would not be just making a small adjustment that could be periodically reviewed in a tradeoff we have to make anyway. We would be adding a new tradeoff that we have no other incentive to make, and thus taking on a new oversight burden, which is, if not impossible, at least extremely difficult to properly fulfill, that we have no other incentive to take on. That is simply not a bargain that free citizens of a free society should accept.

> embedding those checks/balances/required transparency in the surveillance processes in such a way that they cannot be circumvented by those in power.

The processes can't be transparent because, as I said, that would reveal sources and methods that should be concealed from adversaries. An application for a FISA warrant can't wait for the years it would take to allow a FOIA request to be fulfilled in the interest of transparency.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#352
post #323
post #296

Earlier quoted context omitted.

what are they going to publish, and why?

>shut down projects by exerting pressure on developers Because i don't like pressure from a Secret Services...do you? OK with one exception...Xenia Onatopp

Ok, but how is the press involved in all this? You think the press protects people against pressure from secret services?

Re: Stop the Earn IT Bill Before It Breaks Encryption

#353
post #351

Earlier quoted context omitted.

It's often not the the government "cannot" reveal those details (maybe not immediately and directly in some cases, sure, but certainly with the distance of time that tools such as FOIA requests require), but that they "won't" and have no interest to. It should be the public demand with each attempt to increase surveillance to increase oversight. Sousveillance (watching the watchers) is the best known defense we have…

> with the distance of time that tools such as FOIA requests require Often that is way too much time--25 to 50 years in many cases, since those are the time frames for declassification of classified information--for such revelations to be useful for oversight, especially with the state of encryption as it is since computers and the Internet. Before computers and the Internet, it was possible to have a reasonable trad…

> Often that is way too much time--25 to 50 years in many cases, since those are the time frames for declassification of classified information

That's only part of what I mean about the goal to demand expanding oversight, maybe those timeframes are too long, but the point is that those time frames sometimes serve a useful purpose to slow things down for safety of parties involved or other reasons. A goal should be to find a healthy "medium" where "Surveillance FOIA 2.0" still allows for transparency/oversight/review without hobbling the process, and FOIA was just one example of an existing transparency tool to model from, it's not the only tool/model it was the first example to mind, but you would hopefully expand to a larger suite of transparency/sousveillance ("watch the watchers") tools.

I'm also not claiming that we shouldn't fight surveillance attempts, simply that where surveillance seems inevitable/a foregone conclusion/rough to fight that we also need to devote resources to fighting for increased sousveillance/transparency, because power will always abuse surveillance.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#354
post #351

Earlier quoted context omitted.

> with the distance of time that tools such as FOIA requests require Often that is way too much time--25 to 50 years in many cases, since those are the time frames for declassification of classified information--for such revelations to be useful for oversight, especially with the state of encryption as it is since computers and the Internet. Before computers and the Internet, it was possible to have a reasonable trad…

> Often that is way too much time--25 to 50 years in many cases, since those are the time frames for declassification of classified information That's only part of what I mean about the goal to demand expanding oversight, maybe those timeframes are too long, but the point is that those time frames sometimes serve a useful purpose to slow things down for safety of parties involved or other reasons. A goal should be to…

> where surveillance seems inevitable/a foregone conclusion

To me, breaking perfect encryption by putting backdoors in computer algorithms is precisely the kind of place where we should not think that surveillance is inevitable/a foregone conclusion, but should draw a line in the sand and say that no, we're not going to accept this, law enforcement simply needs to up its game and figure out how to operate in this new environment where anyone who wants to can use perfect encryption.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#355
post #149

Earlier quoted context omitted.

> You see, the EARN IT Act grants the Attorney General broad authority to force tech companies to do whatever he wants I looked and could not find this. That article did not offer any specifics either.

https://cyberlaw.stanford.edu/blog/2020/01/earn-it-act-how-b... Scroll to summary, specifically "Section 230 immunity for CSAM can be earned via 1 of 2 “safe harbors”."

The basis of the arguments in that article are based on items that have been stricken from the Act. That article and the EFF post are out of date. Compliance with "best practices" is no longer part of the bill. As of right now there is no teeth to the bill.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#356

Earlier quoted context omitted.

Notwithstanding means in spite of paragraph 6. So 7(see above) preempts 6(see below). “(6) NO EFFECT ON CHILD SEXUAL EXPLOITATION LAW.—Nothing in this section (other than subsection (c)(2)(A)) shall be construed to impair or limit— “(A) any claim in a civil action brought against a provider of an interactive computer service under section 2255 of title 18, United States Code, if the conduct underlying the claim const…

So what's the reason for the EFF's warning?

I believe the original EFF post is outdated. Much of the complaints about the bill have been deleted in the current text.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#357
post #268

Earlier quoted context omitted.

The "best practices by a committee they control" requirement which is carte blanche. They could easily set it to considering "key escrow" or "master key" backdoors.

But the worst thing that happens if you fail to implement the best practices is that you lose section 230 protections. If you're and E2E messaging app or the author of device encryption software you don't need section 230 protections to begin with.

Not according to the current text of the bill. The EFF post is outdated I think. The commission no longer has teeth. This bill will probably die.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#358

All of you smart arses out here and there, we know it, we know. We know, VPNs and other stuff in between are not so secure and not private. Stop saying it, don't you have some other piece of knowledge to be proud of? for god's sake. Tor and Signal are better than Public Cloud, Chrome & SMS if you're looking for privacy. Don't you have common sense? - HTTPS is more secure and private than HTTP - Signal is more secure…

I don't understand what people have against VPNs. I don't want my ISP knowing when I use Tor, since my ISP is in the same country as me and that makes it easier for them to have access to me if they wanted to. Using a VPN means my ISP only sees me connecting to a VPN (which is arguably more innocuous). Then you can use Tor from there. And if you only use HTTPS sites, then only you and the end site can read the traffi…

There are some points against using VPN with Tor here: https://write.privacytools.io/my-thoughts-on-security/slicin...

Re: Stop the Earn IT Bill Before It Breaks Encryption

#359

Earlier quoted context omitted.

i didn't know that. what does that mean for the fate of this bill? doesn't that just mean that the senate must consider it? does the commerce committee have anything to do with it? since they oversee commerce and basically the internet (at least from what little i know...)

>i didn't know that. what does that mean for the fate of this bill? IIUC, for this particular bill[0], the next step in the Senate is to debate it on the floor and then vote on it. The companion House bill[1] has been introduced, but has not gone through committee or been voted upon. The Senate would need to pass the bill. Then, separately , the House would need to pass their bill. Then, the House and Senate would re…

I know all that, but I was wondering what role the Senate Judiciary Committee plays in that process.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#360

Earlier quoted context omitted.

>i didn't know that. what does that mean for the fate of this bill? IIUC, for this particular bill[0], the next step in the Senate is to debate it on the floor and then vote on it. The companion House bill[1] has been introduced, but has not gone through committee or been voted upon. The Senate would need to pass the bill. Then, separately , the House would need to pass their bill. Then, the House and Senate would re…

I know all that, but I was wondering what role the Senate Judiciary Committee plays in that process.

>I know all that, but I was wondering what role the Senate Judiciary Committee plays in that process.

A good question.

IIUC, none at all.

Once the full House and Senate have passed their bills, a conference committee[0] will be convened to create a single bill to be voted upon by both the House and the Senate.

One would expect that members of the relevant Senate and House committees would be part of the the conference committee, but that's not necessary, and leadership generally chooses the members of a conference committee.

Once the conference report is complete, the bill then goes directly to the floor of each house for debate and a vote.

The specific committee (in this case the Senate Judiciary Committee) that approved each house's bill is not involved.

Of course the members of that committee get to vote on the bill from the conference committee just like every other member of that house.

[0] https://en.wikipedia.org/wiki/United_States_congressional_co...

Post reply on HN