Live data from Hacker News

The FBI Should Stop Attacking Encryption

eff.org

11–20 of 130 posts

Re: The FBI Should Stop Attacking Encryption

#11

> When the FBI says it’s “going dark” because it can’t beat encryption, what it’s really asking for is a method of breaking in that’s cheaper, easier The way I see it, authorities all over have zero difficulty in breaking into devices (deus ex Cellebrite). I always believe that any password we use (computers, phones, etc.) is only to protect us against the common criminal . Someone who will take your phone, and a str…

> Just warrant+gag

And ... that’s probably ok? The people are not meant to be protected against all searches, only warrantless search.

Re: The FBI Should Stop Attacking Encryption

#12
post #3

I dont understand why the US people still trust these agencies. FBI, CIA, NSA have all shown to act against the democracy in many cases. If they could be trusted, they could be trusted with a backdoor. Since they cannot be trusted, the backdoor only makes them a more dangerous enemy of the people.

What’s the alternative?

[deleted]

Re: The FBI Should Stop Attacking Encryption

#13
post #3

I dont understand why the US people still trust these agencies. FBI, CIA, NSA have all shown to act against the democracy in many cases. If they could be trusted, they could be trusted with a backdoor. Since they cannot be trusted, the backdoor only makes them a more dangerous enemy of the people.

What’s the alternative?

The alternative is to design systems, structures, and procedures more robust against infiltration by selfish actors or actors loyal to foreign governments. "Defense in depth" instead of assuming you can ring fence the good guys, etc.

Law enforcement ends up having to rely more on undercover work and informants, as it used to in the past. The CIA and NSA end up getting less intelligence for the same budget, but conversely, spies who infiltrate the CIA, NSA, etc. get less bang for their buck, as well.

Re: The FBI Should Stop Attacking Encryption

#14
The article's title is a little misleading, but I agree with their overarching message.

Law enforcement should never be given the easy way out in terms of breaking encryption. Asking for backdoors to be installed in every device is extremely lazy police work. I'm sure there are other ways of breaking encryption like the rubber-hose technique (of course with valid arrest warrant).

Arguing that law enforcement should stop attacking encryption because it jeopardises privacy seems a little naive to me. What about criminals that profit from creating spyware? In fact, allowing law enforcement to actively research new ways to break encryption can be productive for improving security in the long run. Stop using weak passwords people.

Re: The FBI Should Stop Attacking Encryption

#15
post #4
post #3

I dont understand why the US people still trust these agencies. FBI, CIA, NSA have all shown to act against the democracy in many cases. If they could be trusted, they could be trusted with a backdoor. Since they cannot be trusted, the backdoor only makes them a more dangerous enemy of the people.

Nobody can be "trusted" with a backdoor, because it isn't really a valid concept. A backdoor is a vulnerability that doesn't care who you are or what your purpose is or who pays you. If you found the backdoor it is open to you. However hard the backdoor's security is, an insider recruited by Swedish intelligence (or Russia whatever the bogeyman du jour is) will leak the key at some point. Now all your "secure" shit c…

The TSA masterkey case is an interesting analogue example.

I don't know much about locks, but I wonder how it could ever be secure, even if they never leaked photos of the masterkeys. In principle, it should be possible to reverse-engineer the shape of the masterkey from any masterkey-compatible lock. Would it be practical to do this?

Re: The FBI Should Stop Attacking Encryption

#16
post #3

I dont understand why the US people still trust these agencies. FBI, CIA, NSA have all shown to act against the democracy in many cases. If they could be trusted, they could be trusted with a backdoor. Since they cannot be trusted, the backdoor only makes them a more dangerous enemy of the people.

Why do you think we have any control or say over the situation?

Re: The FBI Should Stop Attacking Encryption

#17
post #7

> When the FBI says it’s “going dark” because it can’t beat encryption, what it’s really asking for is a method of breaking in that’s cheaper, easier The way I see it, authorities all over have zero difficulty in breaking into devices (deus ex Cellebrite). I always believe that any password we use (computers, phones, etc.) is only to protect us against the common criminal . Someone who will take your phone, and a str…

App updates has always struck me as the big one. I can't turn them off, I can't easily validate them, and there's little preventing an update just for my device being shipped.

Whether you can turn them off depends on your operating system. Most of them allow you to turn them off. What are you using? And if it really bothers you, why don't you switch?

Re: The FBI Should Stop Attacking Encryption

#18

The article's title is a little misleading, but I agree with their overarching message. Law enforcement should never be given the easy way out in terms of breaking encryption. Asking for backdoors to be installed in every device is extremely lazy police work. I'm sure there are other ways of breaking encryption like the rubber-hose technique (of course with valid arrest warrant). Arguing that law enforcement should s…

What I find most upsetting about this is that it seems the real goal is to defend the monopoly of big pharmaceutical companies and it has nothing to do with protecting the public. Cannabis is a great enemy of some corporations that are heavily pushing their opiate based drugs and they corrupt law makers and law enforcement to protect their markets at the expense of public who pays for it. This is obscene and erodes trust in any public services.

Re: The FBI Should Stop Attacking Encryption

#19
post #17
post #7

Earlier quoted context omitted.

App updates has always struck me as the big one. I can't turn them off, I can't easily validate them, and there's little preventing an update just for my device being shipped.

Whether you can turn them off depends on your operating system. Most of them allow you to turn them off. What are you using? And if it really bothers you, why don't you switch?

The point XorNot made (and I agree) is that "it is switched on by default". And then you need to go to 5 different settings to switch them off (OS update, App update, iCloud login, iCloud sync of Backup-StockApps-Messages-etc).

The "welcome" should not be "all your data are belong to us". It should be "Hi, iCloud-Y/N, AutoUpdateOS-Y/N, Backup Message-Y/N, Backup Notes-Y/N, etc.).

I get it that for MANY reasons Apple wants everyone to run the latest OS/Apps versions, but.... did they ASK me?

Exiting their ecosystem is painful. Apple/Google rely on this. There are plenty of discussions on 'how to exit' and alternatives, but this is HN. The average HN-er is not exactly the same as the average smartphone user.

Re: The FBI Should Stop Attacking Encryption

#20
post #8

Another argument against the "going dark" claim is that before smartphones and the internet, the only conversations the FBI could monitor was through phonelines and mail. These were known to be easily monitored and I doubt there was much more criminal activity happening through those then than now. I would argue that the conversations that have gone online are the interactions that were previously happening in-person…

15 years ago, if I had said that society would build a tracking system and that most people would happily carry a tracker in their pocket and pay monthly fees to support the tracking networks, I would have been laughed out of the room.

But that is what happened, and most people are oblivious to this fact.

Post reply on HN