Live data from Hacker News

Key senators have voted for the anti-encryption EARN IT act

eff.org

131–140 of 348 posts

Re: Key senators have voted for the anti-encryption EARN IT act

#131

> it will let the use of encryption be evidence in lawsuits and criminal trials Is this true? Will use of encryption be evidence of guilt if this thing passes? Incredible.

If anyone in power in our 3 branches of government was under 80 and actually understood how all of this worked, this would be struck down immediately. Heck, this law would be a non-starter to begin with.

Re: Key senators have voted for the anti-encryption EARN IT act

#132
post #72

You can watch the meeting from this morning here: https://www.judiciary.senate.gov/meetings/02/03/2022/executi... The discussion on the EARN IT act starts around 1:42:00 Any mention of concerns over encryption are with a really incredulous, dismissive tone. I have a hard time understanding whether that's actual ignorance on the part of the Senators, or if it's some kind of theatrics that plays into the broader politi…

Thanks. Lots of commending! They must be a commendable lot.

Re: Key senators have voted for the anti-encryption EARN IT act

#133

What I don't see in the writeup, is which senators are voting which way. I can tell from the writeup what Blumenthal thinks of it, but not any other committee participants. I really wish politicians would embrace a "we will make policies for things we can understand" motto.

> [politicians embrace] "we will make policies for things we can understand"

I wish that too but to be fair: what would any of us be able to make a policy for if we had to really understand the subject first? I'm afraid we'd have to elect about 1 million politicians and let any subset of them make policies about what they are experts about. This is probably what's already going on except nearly everyone in that million is not elected and is part of organizations lobbying for something.

Re: Key senators have voted for the anti-encryption EARN IT act

#134
post #70

Earlier quoted context omitted.

I'm disappointed that Jacky Rosen (D - Nevada) is a co-sponsor. She's a former software developer and should know better. I just watched some of the Senate hearing on Log4J and she seemed reasonably together on security, open source etc. I was feeling optimistic that she could become the Senatorial analogue to Judge Alsup[1]! But if she's on board with EARN IT, scratch that idea. [1] https://www.theverge.com/2017/10/…

I've worked as a software developer for 8 years so far. I have yet to meet a single fellow developer who is privacy-conscious.

There are a lot but it seems they slowly become a minority. Large companies priming them to be less careful with user data is an issue here.

Re: Key senators have voted for the anti-encryption EARN IT act

#136

Incredible, once again the Senate is completely incapable of doing anything good but gets their shit together whenever it’s time to do something stupid and terrible. Would be better to just vote against the majority going forward, at least try to tie things up so they can do nothing instead of what they end up doing whenever they get around to doing something . Truly amazing how Chuck Schumer gets a pass in the media…

I don't understand why people keep voting them back in?? They've been useless for so long, yet people continue to check the box next to their name. Why?

Welcome to "democracy," where college studies show that only the rich and powerful ever get what they want while the normal citizen is continuously shafted in new and exciting ways.

Re: Key senators have voted for the anti-encryption EARN IT act

#137
post #47

Dianne Feinstein, senior senator from California and presumably elected with majority support from Silicon Valley, is one of the co-sponsors of the bill. Talk about being out of touch. I also have no doubt that she wouldn't be able to explain a single line of text in the bill if asked.

The only ones outn of touch are the people surprised by this. She, her party, and even the Republicans across the aisle are always perfectly sympatico with the wishes of their mostly identical donors.

Re: Key senators have voted for the anti-encryption EARN IT act

#138
post #121

> and it will let the use of encryption be evidence in lawsuits and criminal trials How long until the comparisons to East Germany start? America is apparently gearing up for "If you have nothing to hide you have nothing to fear", with many seemingly agreeing with this sentiment. Perhaps more importantly, how have major journalistic networks not written about this bill in the worst possible light? When your sources w…

We don’t really have journalism in the US anymore. Most of the financially healthy ones are owned by foreigners that are actively trying to sabotage our democracy. The remainder are on life support, and are running with something like 10% the number of reporters they used to have. Also, Godwin's law was repealed years ago, so you may as well compare to the third reich.

Foreigner or us national, all news sourced ultimately serve the interests of their owners.

Re: Key senators have voted for the anti-encryption EARN IT act

#139
Let me translate this into practical arguments depicting where this leads (how both dangerous and stupid it is).

If this bill passes, imagine a world where:

- all cloud files, activity, messages, regular over internet activity (provided by any legal company registered in US or wanting to operate in the US) etc shall be readable by the government

- this would apply to ALL countries in the world

- all companies will not be allowed to use nor support any application on their platform that has end2and encryption

- US government will heave sort of "master key" to not just US but the whole world

- end2end encryption use will be outlawed/criminal and forbidden (if you try to install any app that uses end2end encryption, this can be recorded and government can choose to bring you to court and serve you with draconian fines, regardless what you did over end2end encrypted communication)

- there will be nothing stopping any individual actor (good and bad) to use end2end encryption!

- it is impossible to enforce to stop use of end2end encryption (as nobody can control what runs on end points PC/Windows/OS/Mac/de-googled-Android/etc)

- No more VPN, Telegram, Signal, TOR/onion, emails, HTTPS? (all messaging like skype/whatsapp/snapchat/zoom/tiktok/etc in todays form), etc all will be forbidden/criminalized in today's form until changed to allow government to read it in clear form. This does not mean that there won't be still versions of TOR, VPN, HTTPs that use end2end encryption (without giving master key to the government) no there will be, it will just be criminalized and unenforceable unless government decides to not sue/press-charges to all using it (of which there will be hundreds of millions) but instead reserves right to sue/charge or worse bomb you

- centralization of such great power, by design per system threat model, makes one point of failure as total failure and history has proven that such design always fails (i.e. to translate: basically malicious actor will try and eventually succeed to hack the government central control place to take over this capability and such power in the hands of a really determined malicious actor is infinite!) == so technically/logically this is hugely stupid, not just dangerous for government malpractice (which is also historically more norm than exception)

- Internet division of the world will be forced by this! as imagine that you are some/any country (in Europe, especially China or Russia, but hey any) that just wants NOT TO be without clothes fully open to US spying, then you're left with only one choice to FULLY ISOLATE YOUR Internet (including everything, your infrastructure, your devices, your versions of operating systems, etc,..) so this would HUGELY IMPACT ALL BUSINESSES as they will suddenly not be able to sell anything outside of US (other than to allied or vasal countries)!!! (this is inevitable outcome in short period of time and in a divided world you can draw the prediction where that leads = to all worst outcomes)

PLEASE ALL UNDERSTAND THIS CORRECTLY and ACT asking your representatives TO VOTE AGAINS EARN IT

Feel free to use my description when writing to your representative, as it is more understandable to uneducated people and conveys grave dangers versus just your vote!

Government agencies have many different ways to FULLY protect the children and not to destroy the world, only if they use competent people!

Re: Key senators have voted for the anti-encryption EARN IT act

#140
To test whether HN has become an echo chamber censoring any viewpoints they disagree with, I will share my actual viewpoint on end-to-end encryption. I have posted it elsewhere in the past:

https://news.ycombinator.com/item?id=25030085

First, my bona fides: I am a huge proponent of decentralization, empowering people and giving them control over their own data, relationships, and identity. I distrust large states and organizations and hold them to a very high standard of not harming people. I have put my money where my mouth is and reinvested nearly 90% of our company’s profits to build open source alternatives to Big Tech companies, and routiney give away our software on github. We have built probably the most useful and battle-tested open source alternatives for Web2 and Web3, in the world: https://intercoin.org/overview.pdf

Now, having said all that… as someone who designs distributed systems that reach millions of people across 95+ countries, I have had to seriously consider my responsibility in designing the systems. It would not be very difficult to circumvent whatever laws various jurisdictions have. But regardless of the laws, consider what your tech is enabling. (I wish FB and others did this, but the capitalist profit motive keeps them from doing it, they have to extract rents and distract you at dinner with notifications and get you addicted to arguing online, and suck you into virtual reality or they lose money).

OK, so now to the point

If you are relying on end-to-end encryption to protect you against state-level actors or police, you have already lost and have been reduced to sneaking around. The real solution is to work together fix your democracy and make it a more liberal democracy, with more sensible laws that allow greater freedom of actions and make the punishments fit the amount of harm it caused, with punitive multipliers that account for the probability of not getting caught.

End-to-end encryption, if you uncompromisingly apply critical thinking and call a spade a spade (which is what we should be doing as designers of distributed software) is just an abdication of any sort of governance about what to do about any speech. Freedom of speech is certainly a lofty goal, and personally I don’t think the CSAM in and of itself is the problem — rather it is the acts before and after the content. Terrorists plotting an attack for example, or any group organizing to harm people. Even financial collusion.

Forget states and think organizations. Consider that organizations find it desirable to know whether an employee was using their messaging system and giving away company secrets or plotting to harm the company. A dating site may want to know if a predator is luring women into a trap or duping elderly people into giving up their money. Sex trafficking and many other harms can be investigated.

Now what is the proper way to handle encryption? Due to dropping costs and minituarization we will soon have ubiquitous cameras and surveillance everywhere anyway (including college dorms etc. to solve allegations of rape). The recorded info should all be encrypted at the camera, and anything sent over the network must be encrypted. BUT…

There should be a process to decrypt specific minutes from specific cameras, following a process that involves a complete audit of those trying to access the footage. For example: only if a court case is brought and the video is subpoenaed can the keys be produced, by having the judge, lawyers and the tech companies come together, and only for specific times and specific cameras. In other words: the answer is watching the watchers to only access the info for the correct reasons and always ahve audit trail, rather than having no possibility of watchers in the first place and not knowing whether a rape occurred or not.

Based on this example with cameras, we can extrapolate to communication and groups. If there is suspicion of a group, our society should have the means to decrypt its messages, but ONLY via mesns that highlight WHY, and WHICH times. Certainly it should be possible to do after a crime is alleged to have been committed, and false claims of a crime would be punished too. The remaining question is rather about “precrime”, and whether we should “chill” speech of eg determined would-be criminals plotting something, rather than letting them discuss it and catching them before they commit their destructive acts. For that, there is still open discussion.

But for the rest — the EFF is wrong. We can have freedom of speech, and yet ways to have due process to investigate speech that was tighly related to crimes committed before and after it. What we should REALLY be doing is making sure our agencies (which don’t have to be top-down run by the State, they could be fulfilling yearly contracts paid by neighborhoods or cities) are using the Accountability software the software industry should standardize. The agencies serving us should be more transparent. Rather than citizens sneaking around, they should demand their government become more transparent. The tradeoff of secrets vs transparency which should be discussed is that of GOVERNMENT. 99% of the time, government secrecy harms society, why do we allow it?

To summarize about how our society SHOULD ideally function:

1. Have neighborhoods exercise consumer choice in agencies and courts, let those face market competition. The vouchers used by neighborhoods can be a single payer system by states, but neighborhoods choose to renew contracts or not.

2. Agencies should act transparently. In the case of a court case, responsible platforms should allow decryption by agencies following specific procedures and the public should always have access to the entire audit details

3. We still need https, ie encryption in transit. We still need decentralization and resiliency, so content cannot be taken down, and people’s identity and choices aren’t controlled by specific third parties.

4. Content can harm society (and be exacerbated with botnets retweeting stuff). Individuals do not have the right to unfiltered megaphones, responsible publishing platforms should require peer review (like in science, or wikipedia talk pages) before disseminating information.

The profit motive and capitalism prevent #4 and co-opt ideals like “freedom of speech” to allow pushing messages to groups and radicalizing them. It is not an accident people globally are increasingly divided and hateful politically due to the Internet.

Post reply on HN