Live data from Hacker News

Key senators have voted for the anti-encryption EARN IT act

eff.org

171–180 of 348 posts

Re: Key senators have voted for the anti-encryption EARN IT act

#171
post #160

Earlier quoted context omitted.

It would destroy the US tech sector. In Europe, no company would be permitted to store any data on any servers operated by a U.S. company. They might go further and require the company to have no association with the U.S. counterpart, if this Bill is sufficiently broad, which I believe it is. In other words, Google, Microsoft, Facebook, Dropbox, Apple, Amazon, etc. etc. would lose their entire European customer base.…

I would expect companies that can do so to move most of their activities out of the US and silo their US operations.

There would be many divided regions, physical and virtual with middle criminalized zones. In reality of this wild world scenario the strongest rules and there is no place to hide other than temporarily.

Re: Key senators have voted for the anti-encryption EARN IT act

#172

Earlier quoted context omitted.

> this makes it essentially a cloud feature. Wrong. Physically, the routines run on the device. It is not a cloud feature by definition. There are no wormholes here. The work happens on the device. When this work happens the device's battery gets drained so it's happening on the device. It's not a cloud feature. Both technically and physically you are wrong here. I hate that you have this wrong and continue to say it…

You're kind of arguing a straw man, sure it technically runs it on the phone (I don't dispute that), but only when upload to iCloud is enabled and the photo is being uploaded to iCloud . The latter bit matters (and what I meant by 'essentially'). Running the check on the phone on upload with these constraints is what would enable iCloud to be encrypted. I don't think there's much point in discussing further, the main…

> only when upload to iCloud is enabled and the photo is being uploaded to iCloud

You have to trust Apple that this will always be the case.

Your model should be to trust no one. Don't take anyone at their word as it's subject to change at any time. Especially not a corporation which is easily manipulated governments (look how they bend to Russia and China).

It's entirely obtuse that this can be turned with product use. Product use that might be triggered at a distance by simply using the "blessed path". Most people won't even be aware this is happening. And that's beyond shameful.

This puts one foot in the door. There will be more. They'll be ramming everything through that they can to spy on you.

Companies should not be trusted with liberty and privacy. Not even Apple.

Re: Key senators have voted for the anti-encryption EARN IT act

#173

Let me translate this into practical arguments depicting where this leads (how both dangerous and stupid it is). If this bill passes, imagine a world where: - all cloud files, activity, messages, regular over internet activity (provided by any legal company registered in US or wanting to operate in the US) etc shall be readable by the government - this would apply to ALL countries in the world - all companies will no…

Imagine hacking that master key... So will I have to shut down my personal Nextcloud and Matrix server? Also what will happen to SSH? it's also E2EE

As stated 3rd party actor breaching/hacking government is guaranteed! Another factor if money which is not on the individual side, but on a state actors (i.e. China will focus all to get there and per history it will get there).

In addition chance of "the beast" finding a method to break any new end2end encryption is likely/tbd/time, however individuals/open-source shall be finding another new method over night :-) as I ~40 years ago on 8bit computers I made very similar algorithm to Rijndael AES and I was a kid and that was ~20 years before AES was invented!

Re: Key senators have voted for the anti-encryption EARN IT act

#174
post #140

To test whether HN has become an echo chamber censoring any viewpoints they disagree with, I will share my actual viewpoint on end-to-end encryption. I have posted it elsewhere in the past: https://news.ycombinator.com/item?id=25030085 First, my bona fides: I am a huge proponent of decentralization, empowering people and giving them control over their own data, relationships, and identity. I distrust large states and…

> Now what is the proper way to handle encryption? Due to dropping costs and minituarization we will soon have ubiquitous cameras and surveillance everywhere anyway (including college dorms etc. to solve allegations of rape). The recorded info should all be encrypted at the camera, and anything sent over the network must be encrypted. BUT…

> There should be a process to decrypt specific minutes from specific cameras, following a process that involves a complete audit of those trying to access the footage.

I see your point with this, and I don't contest that it's a conceivable technical solution (all caveats aside). But I don't want to live in the world you describe. That is, it's not a societal solution to me.

Re: Key senators have voted for the anti-encryption EARN IT act

#175
post #64

Ppl should start to use messenger apps as dump pipes and use a level 3 encryption. https://github.com/enigma-reloaded/enigma-reloaded

Yes there will be tons of new open-source end2end encrypted apps that you can install and government shall not be able to enforce it! But the new Act will give them power to proclaim anyone using it a criminal and they can start exercising draconian fines (i.e. hundreds of thousands or millions of dollars life crippling). No matter how you slice this and when you get totality of all possibilities all scenarios end up with world destruction making this the most dangerous and most stupid Act ever!

Re: Key senators have voted for the anti-encryption EARN IT act

#177

Earlier quoted context omitted.

The only way out of this is embracing to become a criminal. You have to even the playing field with intelligence agencies breaking the law without any consequence. They have to justify their existence, citizens do not. You have to protect yourself because the government cannot and will not do it. So focusing on illegal channels is the obvious choice.

that is "Oblivion" scenario if this passes or 2nd version is The World will face the music that would destroy it I'd rather try to act now with ~100000x less effort to stop this immensely stupid and dangerous act

Of course that would be the priority. But there needs to be a cultural change that fears don't lead to ambitions for more control. That is only possible through sensible opposition and controlling instruments. Secrets laws and secret courts play no part here.

Re: Key senators have voted for the anti-encryption EARN IT act

#178
post #70

Earlier quoted context omitted.

Here's the list of cosponsors, who will presumably vote for it. I don't see the list of committee members who voted for it. https://www.congress.gov/bill/117th-congress/senate-bill/353...

I'm disappointed that Jacky Rosen (D - Nevada) is a co-sponsor. She's a former software developer and should know better. I just watched some of the Senate hearing on Log4J and she seemed reasonably together on security, open source etc. I was feeling optimistic that she could become the Senatorial analogue to Judge Alsup[1]! But if she's on board with EARN IT, scratch that idea. [1] https://www.theverge.com/2017/10/…

> I'm disappointed that Jacky Rosen (D - Nevada) is a co-sponsor. She's a former software developer and should know better.

I don't know why you feel this way - IME software devs are the least likely to care about privacy.

Maybe they've been so acclimatized to being online all the time, or maybe it's because they feel that they aren't at risk.

In any event, the first people to throw away their privacy has always been software developers. Just look at how many of them use Chrome, for example. Or how many of their personal projects are tied to some proprietary tooling that, as a first action, grabs their data.

Re: Key senators have voted for the anti-encryption EARN IT act

#180
post #140

To test whether HN has become an echo chamber censoring any viewpoints they disagree with, I will share my actual viewpoint on end-to-end encryption. I have posted it elsewhere in the past: https://news.ycombinator.com/item?id=25030085 First, my bona fides: I am a huge proponent of decentralization, empowering people and giving them control over their own data, relationships, and identity. I distrust large states and…

Shortest path to the 1st solution is often centralized, which is where we are now.

Decentralized design is the next TBD step which will follow together with defining how societies could better work with new form of decentralized direct democracies to maximize potential in each of us in a golden rule, maturely balanced way. Decentralized money will follow in new design forms too. I have lots of ideas and number of solutions to propose, but all that takes time and preferable evolution.

However, now we need to stop this evil!

Post reply on HN