Live data from Hacker News

Earn-IT threatens encryption and therefore user freedom

fsf.org

51–60 of 209 posts

Re: Earn-IT threatens encryption and therefore user freedom

#51
post #29

I don’t understand why folks don’t just point out any back doors in these services will be abused or hacked eventually. Do our leaders want their own personal correspondence—-to their big donors, bankers, brokers, interns, mistresses, drug dealers, coup instigators—-available to the FBI or the media too?

Leaders are "special". These bans are for people like us, not for them. I'm sure everyone in the government will be using effective encryption. They just don't want the masses using it against them because then it's subversive.

Re: Earn-IT threatens encryption and therefore user freedom

#52

Earlier quoted context omitted.

> Without it the criminals WILL have access to your systems and data Replacing criminals and state overreach with foreign adversaries may be more salient. Our encryption debate came of age after the Cold War. The boogeymen of that era have been surpassed. We have new ones, and they're more sinister than thieves and more tangible than a your government turning on you.

On what occasion have any of these new cyberattacking boogeymen-on-steroids done anything to anyone? I'm going to continue to worry about criminal fraud and my own government, rather than ghosts with foreign names.

Uh, Colonial Pipeline? HSE Ireland? Stuxnet?

Take your pick, it isn't like there's a shortage!

Re: Earn-IT threatens encryption and therefore user freedom

#53
post #40

Earlier quoted context omitted.

You can ask @marcan42 who is porting Linux to Apple Silicon for more information. https://mobile.twitter.com/marcan42/status/10406262109994311...

That thread is pretty persuasive, but I don’t know if he’s attacking a straw-man. Sadly, as seen in some comments here, more than a few people have an irrational animosity towards the FSF. Can anyone present a steel-man of the FSF position?

Free software has never been about demanding corporations open source their intellectual property. For example, Stallman didn't bring a bunch of protesters to Digital Equipment Corporation and the Bell System to beg that they relicense PDP and UNIX as GPL. What Stallman did was create an entirely new operating system that is not UNIX which let freedom loving people use UNIX while escaping the restrictions that were imposed upon users of UNIX.

Richard Stallman wrote at length in the past about how he feels it's ethical to use non-free systems to build free systems if there's no viable alternative. But you can only do that if there's a clean division between what you're doing and what the hardware vendors are doing. Unfortunately it's messy in the embedded world. These makers don't abstract the products they build like Intel does. They rely on legal means instead to secure their advantage. While many corporations might view an agreement to access those bits under restrictive terms as a good thing, it can lead an open source dev to feel like the proprietary stuff, which they intend to decouple themselves from and ultimately escape, is instead being rubbed in their faces. No one wants to be constantly reminded of all the freedom they don't have.

So in other words, it's just a compromise. I'm sure if they could find someone willing to manufacture a truly libre phone, they would have used them instead. I think the FSF has a good understanding of the open source developer's needs / wants / desires and this compromise is perfectly in keeping with that. Perhaps one day they'll attain the obvious end game of a libre phone, which would be a ham radio that looks like iphone with unfettered access to ss7. It will be anarchy. https://youtu.be/eXnvTwRBrgc

Re: Earn-IT threatens encryption and therefore user freedom

#54

Wrote to Dianne Feinstein of CA about being against Earn-IT act and got a letter back about how Earn IT act would prevent child sexual abuse material online. Sigh. As disappointed as I was in the response, I'm glad that EFF makes it really easy to reach out to reps. Took me less than a minute to send out my stance against the Earn IT act to my representatives https://act.eff.org/action/stop-the-earn-it-act-to-save-ou…

Do politicians even read these letters?

Re: Earn-IT threatens encryption and therefore user freedom

#55
post #20

I feel like they missed the primary point which is that E2E encryption is the primary thing protecting everyone from hackers/criminals/other-governments. Without it the criminals WILL have access to your systems and data and then you can basically say goodbye to anything being valuable at all. Locking your door at night is a poor metaphor. A criminal can literally infiltrate and search through every unsecured compute…

> Without it the criminals WILL have access to your systems and data Replacing criminals and state overreach with foreign adversaries may be more salient. Our encryption debate came of age after the Cold War. The boogeymen of that era have been surpassed. We have new ones, and they're more sinister than thieves and more tangible than a your government turning on you.

> Replacing criminals and state overreach with foreign adversaries may be more salient.

For you and me, certainly. For the members of Congress you need to convince of this? They ARE the state. Outside of a few ideological libertarians, protecting the people from the state is not on their agenda.

Re: Earn-IT threatens encryption and therefore user freedom

#56

Devil's advocate: encryption is also what's stopping users with locked-down devices (increasingly common and hard to avoid) from having freedom to run and/or modify the software they use. It's a tough situation. Encryption can be used for good or bad (and even the definition of what's "good" or "bad" encryption varies depending on who you ask). Unfortunately, I see it increasingly being used to oppress users, in the…

I'd imagine that companies would get licenses to use encryption in limited and restricted circumstances, such as for DRM or basic system security. The user won't be able to use strong encryption, but only backdoored or weak encryption to keep the average attacker out.

> but only backdoored or weak encryption to keep the average attacker out.

I realize this is likely not your argument but the only thing that does is delay the access to data, not prevent it.

Private keys will eventually leak, if not publicly, through nation state espionage.

Weak encryption prevents the average attacker today but not the average attacker in the future.

Re: Earn-IT threatens encryption and therefore user freedom

#57

Devil's advocate: encryption is also what's stopping users with locked-down devices (increasingly common and hard to avoid) from having freedom to run and/or modify the software they use. It's a tough situation. Encryption can be used for good or bad (and even the definition of what's "good" or "bad" encryption varies depending on who you ask). Unfortunately, I see it increasingly being used to oppress users, in the…

What does any of this have to do with the EARN-IT act? This all appears to be just claims about possible uses of encryption with no particular relation to the subject of the article. If these other uses of encryption you're discussing wouldn't be affected by the EARN-IT act, then they aren't relevant here.

I'm saying that "the war on encryption" isn't all one-sided.

Re: Earn-IT threatens encryption and therefore user freedom

#58
post #21

Earlier quoted context omitted.

Thankfully with the mass adoption of HTTPS most messages are going to be encrypted over the person's network you are using.

And with the law. We whould have a backdoor in tls. And HTTPS will be meaningless

It's possible that the commission will require ISPs to block non-backdoored TLS. But I'd consider that to be more of a worst-case scenario, rather than something that's particularly likely to happen. More likely outcome is companies that store user messages on their servers won't be allowed to provide end to end encryption, and would be forced to store the messages on their servers in plaintext, or using backdoored encryption. The bill allows for differing requirements for different kinds of services, so hopefully ISPs would not have much of a change from the current situation.

Of course, even just that scenario is bad enough. It would mean that the police, the FBI, the NSA, people at the messaging company, and hackers who breach the company's security would all be able to read those messages.

Re: Earn-IT threatens encryption and therefore user freedom

#59
Where can I find more detailed information on how Earn-IT changes encryption law? I just skimmed the Wikipedia article but it doesn't seem to insist that this act changes encryption law. Just that "best practices" that would provide "guidance" to sites might include backdoors.

I'm all for encryption rights, but if I'm going to call my congressional rep, I want to know what I'm talking about, and the FSF link really doesn't explain what's going on.

Re: Earn-IT threatens encryption and therefore user freedom

#60

Wrote to Dianne Feinstein of CA about being against Earn-IT act and got a letter back about how Earn IT act would prevent child sexual abuse material online. Sigh. As disappointed as I was in the response, I'm glad that EFF makes it really easy to reach out to reps. Took me less than a minute to send out my stance against the Earn IT act to my representatives https://act.eff.org/action/stop-the-earn-it-act-to-save-ou…

Do politicians even read these letters?

Wrote to a state legislator regarding a specific bill.

They voted opposite of what I requested, then wrote back giving a synopsis of the bill and mentioning it passed without even mentioning their vote against the bill.

Post reply on HN