Live data from Hacker News

Earn-IT threatens encryption and therefore user freedom

fsf.org

81–90 of 209 posts

Re: Earn-IT threatens encryption and therefore user freedom

#81
This particular article (not the subject) looked suspicious to me, since I didn't see it contain a link to the EARN-IT bill. I respect that it was created by the FSF, but they really should link to the bill's text.

The bill's text is here. [1] I don't think it does anything that is stated in the article. It's stated purpose is to create a commission that will create recommendations that nobody will have to follow. It actually says that. Then, in Section 5, (7)(A) it explicitly says that it won't affect end-to-end encryption - it says that companies won't need to stop using E2EE and there won't be any liability created for using E2EE.

In general, I am against regulation, but this bill doesn't do what the article claims it will do. Yes, it is absolutely politicking, but it doesn't seem to do much of anything outside of wasting time and resources.

[1] https://www.congress.gov/bill/117th-congress/senate-bill/353...

Re: Earn-IT threatens encryption and therefore user freedom

#82
post #21

Earlier quoted context omitted.

Thankfully with the mass adoption of HTTPS most messages are going to be encrypted over the person's network you are using.

And with the law. We whould have a backdoor in tls. And HTTPS will be meaningless

No we wouldn't. This law doesn't even ban E2EE. E2EE eliminates any liability of transferring the messages.

Re: Earn-IT threatens encryption and therefore user freedom

#83

>Are you "hiding" when you lock the door of your home every day, just because the government is not permitted to enter it without a warrant If this is your reason then I would say you are trying to hide. >Is it "hiding" to seal the envelope of the card you're sending your Valentine? Yes, the point is to keep it a surprise. >helps protect queer youth from intolerant violence (at home and abroad, as in Ghana). E2EE doe…

> Most parents aren't technical and wouldn't even know how to MITM even an unencrypted messaging app. Give it a couple of weeks and someone will have put together surveillance and parental control system for it.

>Give it a couple of weeks and someone will have put together surveillance and parental control system for it.

????? CSGO chat is unencrypted. It's been more than a few weeks since source games have been out. Show me this parental control system you theorize would have been created.

Re: Earn-IT threatens encryption and therefore user freedom

#84
post #38

Earlier quoted context omitted.

>Everyone has something to hide from public view But we aren't talking about making something public. We are only talking about a case where the government already has a warrant.

No, we're not. We're talking about the EARN-IT act, which wants to legally require all website owners to report all kinds of things to law enforcement, without any probable cause that anyone has commmitted a crime and without any kind of warrant.

We were on a tangent. E2EE isn't even banned by the bill so it's all somewhat off topic to talk about.

Re: Earn-IT threatens encryption and therefore user freedom

#85

Earlier quoted context omitted.

>Everyone has something to hide from public view But we aren't talking about making something public. We are only talking about a case where the government already has a warrant.

There's literally no difference. None. This was tried before with special locks that 'only the TSA had the keys to open'. The keys were posted online for anyone to make their own. It's also been tried commercially with various DRM and failed. There is no such thing as a 'government only, and only with a warrant' backdoor. There is either private or not private.

The problem with TSA keys is that they are all the same, can easily be cloned, and couldn't be rotated.

It is possible to design a system where judges have their own hardware keys. Hardware keys can not be cloned assuming strong tamper protection. If a hardware key gets stolen it can be revoked as being valid and a judge can be issued a new one.

DRM is different because the client ultimately has to have the keys to decrypt the content they have been permitted access to.

Re: Earn-IT threatens encryption and therefore user freedom

#86

Earlier quoted context omitted.

> Without it the criminals WILL have access to your systems and data Replacing criminals and state overreach with foreign adversaries may be more salient. Our encryption debate came of age after the Cold War. The boogeymen of that era have been surpassed. We have new ones, and they're more sinister than thieves and more tangible than a your government turning on you.

> Replacing criminals and state overreach with foreign adversaries may be more salient. For you and me, certainly. For the members of Congress you need to convince of this? They ARE the state. Outside of a few ideological libertarians, protecting the people from the state is not on their agenda.

> For the members of Congress you need to convince of this? They ARE the state

We agree in a limited sense. (There are lots of politicians who genuinely believe in curtailing state power.)

Arguments about state overreach won’t convince a power-hungry vote chaser. Talk about foreign adversaries will.

Re: Earn-IT threatens encryption and therefore user freedom

#87
Look Russia and see what happens. They are actively monitoring and censoring 140M citizens. Fortunately Russians are using Signal/Telegram[1] to avoid those censorship.

This is not a tradeoff between just privacy and child safety. This is the matter of freedom and democracy.

[1]: I would say Telegram is available option for privacy but Telegram has pretty much possibility to be attacked than Signal...

Re: Earn-IT threatens encryption and therefore user freedom

#88

Throw away account (does not do much good with modern AI and ML). But here goes. I am a US citizen (never left the country) and I always vote Republican. Down-vote away! The FBI came to my house in October 2021. Two special agents (one of which I knew from prior IT Security engagements) and a 'Threat Assessment' Police Officer from the local police department. They asked me if I was an Islamic extremist/terrorist. I…

More plausibly, someone used extremely weak WiFi cryptography to access the Internet through your ISP. Even if you have a password on such services, between routers with vulnerabilities, backward compatible connectivity (E.G. for your old game consoles / appliances), and maybe even passwords guest devices have shared with the cloud; it really could be anyone who was ever near your connectivity.

I am sorry that these things happened to you, and this highlights how the rights of the accused to face their accusers, with legal representation present as well as to not be discriminated against before adjudication of those charges should be the standard and only procedures. Maybe for some highly important things these accusations might initially be under seal; but there should still be a defense present to advocate for the accused.

Re: Earn-IT threatens encryption and therefore user freedom

#89
post #38

Earlier quoted context omitted.

No, we're not. We're talking about the EARN-IT act, which wants to legally require all website owners to report all kinds of things to law enforcement, without any probable cause that anyone has commmitted a crime and without any kind of warrant.

We were on a tangent. E2EE isn't even banned by the bill so it's all somewhat off topic to talk about.

> E2EE isn't even banned by the bill

Not explicitly, no. But it is not feasible for applications to comply with the provisions of the bill while still supporting E2EE, so the bill's effect will be to largely eliminate the use of E2EE.

Re: Earn-IT threatens encryption and therefore user freedom

#90
post #20

I feel like they missed the primary point which is that E2E encryption is the primary thing protecting everyone from hackers/criminals/other-governments. Without it the criminals WILL have access to your systems and data and then you can basically say goodbye to anything being valuable at all. Locking your door at night is a poor metaphor. A criminal can literally infiltrate and search through every unsecured compute…

> Without it the criminals WILL have access to your systems and data Replacing criminals and state overreach with foreign adversaries may be more salient. Our encryption debate came of age after the Cold War. The boogeymen of that era have been surpassed. We have new ones, and they're more sinister than thieves and more tangible than a your government turning on you.

> Replacing criminals and state overreach with foreign adversaries may be more salient.

Or if you're in the US, depending on your audience, Donald Trump or Joe Biden.

Post reply on HN