Live data from Hacker News

Key senators have voted for the anti-encryption EARN IT act

eff.org

61–70 of 348 posts

Re: Key senators have voted for the anti-encryption EARN IT act

#61
post #26

Earlier quoted context omitted.

> I wonder why? NSLs: https://www.eff.org/issues/national-security-letters/faq Dragnet/Geofence warrants: https://www.nbcnews.com/news/us-news/google-tracked-his-bike... and https://www.logically.ai/articles/geofence-warrants-on-the-r... Dragnet/Mass-surveillance keyword warrants: https://www.forbes.com/sites/thomasbrewster/2021/10/04/googl... Dragnet/mass-scanning of online storage: https://www.forbes.com/sites/thom…

None of these are the reason. The reason is that HTTPS traffic is generally between a service provider (i.e., company) and an end user, and the former can be easily subpoenaed and compelled to disclose data during an ongoing investigation into the latter. The USG doesn't need to (and doesn't bother to) break HTTPS for domestic LEO, because existing mechanisms are easier and approved by the courts.

That's what he was sayin

Re: Key senators have voted for the anti-encryption EARN IT act

#65
post #36

Earlier quoted context omitted.

> the Apple policy wasn't The Apple policy on your device ratting you out is abominable and anyone telling you otherwise is trying to sell you a brand. What you deem illegal might not be the same thing Apple is told to treat as illegal. In this country or elsewhere. You phone should not be the secret police.

This kind of response illustrates my point. The apple policy was likely about coming up with a way to enable encrypted photos on iCloud while still having some privacy preserving form of CSAM detection. Since it was only enabled when iCloud photos was enabled it was better for privacy on net than the status quo (unencrypted iCloud photos that are accessible to apple and scanned anyway). Now we may end up with a worse…

people are extremely up-in-arms about something that apple already does, and that every other cloud provider do, but when they made it public everyone went crazy. now we don't have CSAM scanning, totally unencrypted and accessible iCloud Photo Library, and for what? because people want privacy.

you don't own anyone else's cloud and you never will, and especially not with government intervention. while i support privacy, i also think it's like freedom of speech, in theory it sounds great but in reality you end up with nazis walking around if you don't have the ability to deter them.

data on my computer == private without a warrant and due cause. data on someone's server == as private as could be, but i don't own it so i can't demand that it be secure from all aspects, especially uploading CSAM.

Re: Key senators have voted for the anti-encryption EARN IT act

#66
post #36

Earlier quoted context omitted.

> the Apple policy wasn't The Apple policy on your device ratting you out is abominable and anyone telling you otherwise is trying to sell you a brand. What you deem illegal might not be the same thing Apple is told to treat as illegal. In this country or elsewhere. You phone should not be the secret police.

This kind of response illustrates my point. The apple policy was likely about coming up with a way to enable encrypted photos on iCloud while still having some privacy preserving form of CSAM detection. Since it was only enabled when iCloud photos was enabled it was better for privacy on net than the status quo (unencrypted iCloud photos that are accessible to apple and scanned anyway). Now we may end up with a worse…

> The apple policy was likely about coming up with a way to enable encrypted photos on iCloud while still having some privacy preserving form of CSAM detection. Since it was only enabled when iCloud photos was enabled it was better for privacy on net than the status quo (unencrypted iCloud photos that are accessible to apple and scanned anyway).

This is an unsupported hypothetical about a future change Apple may have made. The only announcement they made was the client-side scanning which is at best equivalent to the status quo.

Re: Key senators have voted for the anti-encryption EARN IT act

#67
post #9

Earlier quoted context omitted.

I very much doubt it. Law enforcement doesn’t seem too concerned about regular old HTTPS. I wonder why?

HTTPS is not end-to-end encrypted (it kinda would be if we used P2P but we don't) so you can subpoena the server.

Your comment is only confusing because E2EE is a term about encryption where no data between two devices can be read by eavesdroppers. HTTPS is indeed end-to-end encrypted between the server and the device. A better way to put it is that HTTPS does not promote E2EE between end-users, which it doesn't intend/pretend to do anyways.

Re: Key senators have voted for the anti-encryption EARN IT act

#68
post #61

Earlier quoted context omitted.

None of these are the reason. The reason is that HTTPS traffic is generally between a service provider (i.e., company) and an end user, and the former can be easily subpoenaed and compelled to disclose data during an ongoing investigation into the latter. The USG doesn't need to (and doesn't bother to) break HTTPS for domestic LEO, because existing mechanisms are easier and approved by the courts.

That's what he was sayin

I don't think it is. The person I'm responding to seems to be implying that the USG doesn't worry about HTTPS because they've broken it or otherwise extralegally subverted it. I'm saying that the USG doesn't worry about HTTPS because they have effective legal mechanisms for domestic investigations, and using extralegal means domestically is more of a headache than it's worth.

Re: Key senators have voted for the anti-encryption EARN IT act

#69

Earlier quoted context omitted.

"Law Enforcement Organization." Edit: "Officer."

My understanding was that it stood for Law Enforcement Officer.

Looks like I've been getting it wrong for years. Thanks.

Re: Key senators have voted for the anti-encryption EARN IT act

#70

What I don't see in the writeup, is which senators are voting which way. I can tell from the writeup what Blumenthal thinks of it, but not any other committee participants. I really wish politicians would embrace a "we will make policies for things we can understand" motto.

Here's the list of cosponsors, who will presumably vote for it. I don't see the list of committee members who voted for it. https://www.congress.gov/bill/117th-congress/senate-bill/353...

I'm disappointed that Jacky Rosen (D - Nevada) is a co-sponsor. She's a former software developer and should know better.

I just watched some of the Senate hearing on Log4J and she seemed reasonably together on security, open source etc. I was feeling optimistic that she could become the Senatorial analogue to Judge Alsup[1]! But if she's on board with EARN IT, scratch that idea.

[1] https://www.theverge.com/2017/10/19/16503076/oracle-vs-googl...

Post reply on HN