Earlier quoted context omitted.
> I wonder why? NSLs: https://www.eff.org/issues/national-security-letters/faq Dragnet/Geofence warrants: https://www.nbcnews.com/news/us-news/google-tracked-his-bike... and https://www.logically.ai/articles/geofence-warrants-on-the-r... Dragnet/Mass-surveillance keyword warrants: https://www.forbes.com/sites/thomasbrewster/2021/10/04/googl... Dragnet/mass-scanning of online storage: https://www.forbes.com/sites/thom…
None of these are the reason. The reason is that HTTPS traffic is generally between a service provider (i.e., company) and an end user, and the former can be easily subpoenaed and compelled to disclose data during an ongoing investigation into the latter. The USG doesn't need to (and doesn't bother to) break HTTPS for domestic LEO, because existing mechanisms are easier and approved by the courts.
Key senators have voted for the anti-encryption EARN IT act
61–70 of 348 posts
Re: Key senators have voted for the anti-encryption EARN IT act
#62Re: Key senators have voted for the anti-encryption EARN IT act
#63Re: Key senators have voted for the anti-encryption EARN IT act
#64Re: Key senators have voted for the anti-encryption EARN IT act
#65Earlier quoted context omitted.
> the Apple policy wasn't The Apple policy on your device ratting you out is abominable and anyone telling you otherwise is trying to sell you a brand. What you deem illegal might not be the same thing Apple is told to treat as illegal. In this country or elsewhere. You phone should not be the secret police.
This kind of response illustrates my point. The apple policy was likely about coming up with a way to enable encrypted photos on iCloud while still having some privacy preserving form of CSAM detection. Since it was only enabled when iCloud photos was enabled it was better for privacy on net than the status quo (unencrypted iCloud photos that are accessible to apple and scanned anyway). Now we may end up with a worse…
you don't own anyone else's cloud and you never will, and especially not with government intervention. while i support privacy, i also think it's like freedom of speech, in theory it sounds great but in reality you end up with nazis walking around if you don't have the ability to deter them.
data on my computer == private without a warrant and due cause. data on someone's server == as private as could be, but i don't own it so i can't demand that it be secure from all aspects, especially uploading CSAM.
Re: Key senators have voted for the anti-encryption EARN IT act
#66Earlier quoted context omitted.
> the Apple policy wasn't The Apple policy on your device ratting you out is abominable and anyone telling you otherwise is trying to sell you a brand. What you deem illegal might not be the same thing Apple is told to treat as illegal. In this country or elsewhere. You phone should not be the secret police.
This kind of response illustrates my point. The apple policy was likely about coming up with a way to enable encrypted photos on iCloud while still having some privacy preserving form of CSAM detection. Since it was only enabled when iCloud photos was enabled it was better for privacy on net than the status quo (unencrypted iCloud photos that are accessible to apple and scanned anyway). Now we may end up with a worse…
This is an unsupported hypothetical about a future change Apple may have made. The only announcement they made was the client-side scanning which is at best equivalent to the status quo.
Re: Key senators have voted for the anti-encryption EARN IT act
#67Earlier quoted context omitted.
I very much doubt it. Law enforcement doesn’t seem too concerned about regular old HTTPS. I wonder why?
HTTPS is not end-to-end encrypted (it kinda would be if we used P2P but we don't) so you can subpoena the server.
Re: Key senators have voted for the anti-encryption EARN IT act
#68Earlier quoted context omitted.
None of these are the reason. The reason is that HTTPS traffic is generally between a service provider (i.e., company) and an end user, and the former can be easily subpoenaed and compelled to disclose data during an ongoing investigation into the latter. The USG doesn't need to (and doesn't bother to) break HTTPS for domestic LEO, because existing mechanisms are easier and approved by the courts.
That's what he was sayin
Re: Key senators have voted for the anti-encryption EARN IT act
#69Re: Key senators have voted for the anti-encryption EARN IT act
#70What I don't see in the writeup, is which senators are voting which way. I can tell from the writeup what Blumenthal thinks of it, but not any other committee participants. I really wish politicians would embrace a "we will make policies for things we can understand" motto.
Here's the list of cosponsors, who will presumably vote for it. I don't see the list of committee members who voted for it. https://www.congress.gov/bill/117th-congress/senate-bill/353...
I just watched some of the Senate hearing on Log4J and she seemed reasonably together on security, open source etc. I was feeling optimistic that she could become the Senatorial analogue to Judge Alsup[1]! But if she's on board with EARN IT, scratch that idea.
[1] https://www.theverge.com/2017/10/19/16503076/oracle-vs-googl...