Live data from Hacker News

Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

globalencryption.org

151–160 of 240 posts

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#151

Earlier quoted context omitted.

If you think Republicans are against eroding privacy I have a bridge to sell you.

Indeed, the Patriot Act passed under a Republican House and Presidency. Where there was opposition, it came from Democrats in the House.[0] [0]: https://clerk.house.gov/evs/2001/roll398.xml

I wouldn't however consider that enough evidence to say Democrats "opposed" the Patriot Act. They aren't "Both sides the same", but on this issue, Democrat politicians largely buy into the law enforcement POV that "bad people" are doing things and there must be an easy way to stop them, instead of making cops do actual work to solve crimes.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#152
post #145

Earlier quoted context omitted.

In the current world Apple is not actually able to compromise your iPhone, warrant or not, by design (remember the whole FBI debacle?). Encryption is done through separate hardware on the phone that they can’t remotely bypass. In the world you’re proposing they would have to be legally compelled to engineer a weaker system. That’s the problem.

I could be wrong but I don't remember Apple claiming it was literally impossible for them to open an iPhone. If that were true then Apple wouldn't have had to fight them at all. The government can't force you to do impossible things. Apple objected to being compelled to create the tooling to bypass an iPhone's security. That implies they can do it whenever they want, they just choose not to.

They could create a build with unlock attempts removed, making it possible to brute-force weaker unlock schemes. That's what they didn't want to do because if they created something like that they would lose a lot of customers.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#153
post #73

I have no problem with the police hacking into devices. They have the right to use bugs and find exploits just like they have the right to pick a safe of force a door. But backdoors and unacceptable, that's like mandating that every house have microphones in every room connected to the police center

This is problematic if, as is often the case, it leads to keeping vulnerabilities undisclosed, so that they can continue to exploit them. This gives bad actors more opportunity to find and exploit the same vulnerabilities, and it gives security companies that find vulnerabilities the incentive to sell their services to the police and to government agencies instead of informing the software manufacturer.

There's a solution to this problem for the big actors. Bug bounty programs that pay as well or better than the likes of NSO group.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#154
post #141

Earlier quoted context omitted.

> Interesting how our leaders see their role not as representing our interests, but in shaping our interests. I mean that's what "leader" means at the end of the day. Of course, though, leader isn't the only way to refer to politicians. In German leader translates literally to Führer ... which isn't really used since the ultimate demise of Herr Schickelgruber. We also use "Repräsentant" whose English counterpart is o…

Historically once people recognize the media is not trustworthy they discount it. You see this in the former USSR countries. People don't take the media seriously like they do in the west.

Yes, and this is very exploitable by dictators and those wanting to become such. If you can't get people to buy into your propaganda paper you can at least get them to buy into nothing at all, detach themselves from any notion of objective reality, and accept all complicity with whatever war crimes the regime wishes you to commit.

The most dangerous situation for a dictator is to be faced with multiple independent and competing sources of truth that all disagree with you, because they will propagandize your subjects away from you quite quickly.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#155
post #143
post #136

Earlier quoted context omitted.

I'd disagree. Democracy in the US is already extremely well controlled. You only have two realistic options, and the primary that led to those two options is fairly undemocratic. Between gerrymandering, citizens united, private control over corporate news, and a million other things, meaningful democracy may as well be dead (or perhaps never existed). Control over encryption is overwhelmingly about those in power kee…

The cool thing about technology is it works both ways. If backdoors are mandated it’s only a matter of time until all texts, location history, etc. etc. of those in power become public - we already learned that those people don’t have the strongest opsec to begin with. This will lead to a backlash and an equilibrium of sorts.

Those in power will be allowed to use encryption due to "state security" or something stupid like that. Only us plebeians will be forced to reveal our dirty laundry to the world.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#156
post #47
post #40

Earlier quoted context omitted.

"Manifacturing Consent" is a book written by Edward S. Herman and Noam Chomsky. They discuss the propaganda model of communication in much broader sense.

Don't forget about > "The Engineering of Consent" is an essay by Edward Bernays first published in 1947,

And he surely knows what he is talking about.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#157
post #153
post #73

Earlier quoted context omitted.

This is problematic if, as is often the case, it leads to keeping vulnerabilities undisclosed, so that they can continue to exploit them. This gives bad actors more opportunity to find and exploit the same vulnerabilities, and it gives security companies that find vulnerabilities the incentive to sell their services to the police and to government agencies instead of informing the software manufacturer.

There's a solution to this problem for the big actors. Bug bounty programs that pay as well or better than the likes of NSO group.

This is limited by the “big actor’s” perceived benefit of catching the bugs. They are already known to not be overly generous. Conversely, security companies can potentially monetize the same vulnerability over and over.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#158

Interesting how our leaders see their role not as representing our interests, but in shaping our interests. There exists an entire subject in political science dealing with how to increase compliance with the schemes of regulators (see Nudge Theory). The mistake they make is a classic short-run vs. long-run miscalculation. In the short-run, you can get away with these kinds of tactics to increase compliance. For exam…

You should call them representatives then. Leaders lead.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#159
post #26

The logical conclusion to the war on general purpose computing (as currently perpetrated in the large by Apple, and spun even by people here as a worthwhile tradeoff for "security") is that computers will be replaced with appliances that can only run government-sanctioned, closed-source software. That is the only way these laws could be enforced.

Yeah. It started with silly things like copyright enforcement, slowly paving the way to ever greater oppression. As an AMD engineer put it, these days processors essentially come pwned from the factory. Computers are too subversive a technology to allow normals unrestricted access. Encryption is powerful enough to defeat nations.

Re: Statement on EU-US Cooperation on Turning Public Opinion Against Encryption

#160

>As we have stated in the past, there is no effective way to weaken encryption for some use cases such as law enforcement while keeping it strong for others. I've never been fully satisfied by this assertion. Apple has the ability to push whatever code it wants to whatever device it wants. They can make a version of iOS that bypasses encryption and restrict it to only run on devices identified by a warrant. They coul…

> They can make a version of iOS that bypasses encryption and restrict it to only run on devices identified by a warrant.

Of course. Apple could absolutely do this and undermine any trust people have in them in seconds if they want to.

Didn't they pass a law in Australia requiring corporations to do exactly what you describe? I remember reading news here about several corporations just moving off of Australia as a result of the inherent untrustworthiness of any system where the government can compel any party you're doing business with to ship you malware.

Post reply on HN