Live data from Hacker News

Encrypting private data and private communications is now an ethical duty

blog.tripu.info

31–40 of 240 posts

Re: Encrypting private data and private communications is now an ethical duty

#31
post #22

I take issue with the phrasing. No one can force upon me their moral obligations. It’s my choice alone.

Especially with these gems in the text: > (Norway) the most robust democracy in the world (which also happens to be a EU member state) Norway is not in the EU. > Hungary and Poland, are still immature barely-liberal regimes with more than a whiff of political repression (“flawed democracies”) Coming from a Spaniard? Go fuck yourself. Like tripu , I am strongly and vocally in favour of privacy and individual agency. B…

> Norway is not in the EU.

You are right, thank you! I just fixed that.

> Coming from a Spaniard? Go fuck yourself.

I was already fixing the error, and writing in my head the kind answer above. I hadn't seen this nasty comment.

Why the ad hominem?

I'm ranking governments — not individuals — according to international reports I've seen. Those classifications are debatable, of course. There might be bias, or nuances I'm missing. But why do you presume malice on my part?

How on Earth is it relevant that I'm a Spaniard?

Re: Encrypting private data and private communications is now an ethical duty

#32

> you would be morally obliged to disobey In days of yore my CS law module was taught by a QC - that's a high ranking barrister in the UK - who explained the world of difference between the "The Rule of Law" and "the law" in a class called "jurisprudence". Rule of Law (capitalised conceptual) is there as permanent ground truth in contrast to the ephemeral du-jure laws. At times I still struggle with that profound cou…

> if one deeply, passionately believes in the necessity of The Law and all of society's institutions, one must with equal passion break laws

"-- That whenever any Form of Government becomes destructive of these ends, it is the Right of the People to alter or to abolish it, and to institute new Government, laying its foundation on such principles and organizing its powers in such form, as to them shall seem most likely to effect their Safety and Happiness."

Re: Encrypting private data and private communications is now an ethical duty

#33

Legislation in favour of the consumer is almost starting to seem detrimental to the startup founder. The number of barriers, prerequisites, requirements, etc that a founder needs to consider pre-launch is bordering on insurmountable. This might just be me feeling like this, but even considering geo-residency in some of my early prototype designs feels very odd. I was optimistically hoping PaaS providers would catch u…

The culture and politics around what startups are and can be seem to have avoided these questions too long. Now that we're evaluating these concerns more in earnest I think it is worth a little soul-searching to determine if it really is worth the money to follow the herd and invest one's time and effort into such applications of technology.

Re: Encrypting private data and private communications is now an ethical duty

#34

> you would be morally obliged to disobey In days of yore my CS law module was taught by a QC - that's a high ranking barrister in the UK - who explained the world of difference between the "The Rule of Law" and "the law" in a class called "jurisprudence". Rule of Law (capitalised conceptual) is there as permanent ground truth in contrast to the ephemeral du-jure laws. At times I still struggle with that profound cou…

Of course, the idea that there is any kind of "permanent ground truth" around morals/laws is very much up for debate. Some philosophers think it exists (usually called "natural law" [1]), while many others think it's nonsense.

I would guess that most anthropologists, for instance, would say it's rubbish -- people who have studied the exceedingly wide variation in what is considered moral or immoral across cultures. A duty in one community may very well be a prohibition in another.

But you don't need to believe in any kind of "permanent ground truth" law in order to "break laws and throw rocks at the police". You merely have to believe that the current laws/administration are acting unjustly according to the local morals of the time and place.

[1] https://en.wikipedia.org/wiki/Natural_law

Re: Encrypting private data and private communications is now an ethical duty

#35

> you would be morally obliged to disobey In days of yore my CS law module was taught by a QC - that's a high ranking barrister in the UK - who explained the world of difference between the "The Rule of Law" and "the law" in a class called "jurisprudence". Rule of Law (capitalised conceptual) is there as permanent ground truth in contrast to the ephemeral du-jure laws. At times I still struggle with that profound cou…

I think you meant: du-jure -> de jure

Re: Encrypting private data and private communications is now an ethical duty

#36

Legislation in favour of the consumer is almost starting to seem detrimental to the startup founder. The number of barriers, prerequisites, requirements, etc that a founder needs to consider pre-launch is bordering on insurmountable. This might just be me feeling like this, but even considering geo-residency in some of my early prototype designs feels very odd. I was optimistically hoping PaaS providers would catch u…

You don't need all of that stuff if your business respects people's privacy by design.

It's like complaining that the GDPR is causing cookie banners on every site. That's only half the reason. The real reason is that the websites need one's opt-in to do something they shouldn't be doing. Obviously the law should have been crafted with an automatic system to reject all non-necessary cookies in mind, but the fault for the cookie banners still lies with the website.

Re: Encrypting private data and private communications is now an ethical duty

#37

I am baffled how we went from a liberal "free" democracy to this ersatz of a totalitarian regime where all our conversations/messages/photos need to be dissected, catalogued and approved by un-elected bureaucrats. I mean you can literally go to eastern Europe to see the vestiges of the Stasi where they used to listen to the conversations of their citizens while trying to find dissidents among them. This isn't some ki…

The "how" is simple: because it could be done with relative ease now. So those charged with preventing crimes can push for it and pushing back against crime fighting is a tough stance to take.

Also, assuming high levels of privacy in the days of old might be in error, depending on what you were doing.

Re: Encrypting private data and private communications is now an ethical duty

#38
post #13
post #7

Earlier quoted context omitted.

Right. If everyone hides in encryption, they'll outlaw encryption.

If they outlaw encryption but everyone encrypts, they can either do nothing or arrest everyone. I'm Spartacus.

Mind you, Spartacus failed.

Re: Encrypting private data and private communications is now an ethical duty

#39
post #20

The author advocates using encryption as an ethical duty, OK. But it would not be an effective form of civil disobedience. This is unrealistic: > We should all use PGP, SSL or equivalent tools; VPNs, Tor and/or SSH tunnelling; IPFS, or other distributed file systems — and ditch proprietary OS's in favour of Linux or truly free Android distros. This is not anything the general public, for whom today their mobile phone…

Author here. (Thank you for all the comments!) Yes, I know SSH tunnelling and compiling your own Android are tall orders for the average user. Here I'm just hinting at some examples that are well-known among us geeks, but there are easier to use alternatives to all that. I suspect Protonmail is as easy to use as GMail. VPNs are so easy to use nowadays. The UX on Signal isn't particularly challenging to the average us…

> we keep on neglecting that responsibility under the excuses of bad usability, lack of features, or convenience for users.

A value leverage point to look at is; why are these perceived to be in tension in the first place?

Revising the concepts of "convenience" and "usability" to incorporate not having your life, business and affairs ruined petty tyrants seems the way to go.

It seems quite possible to design software such that it's more difficult not to encrypt than it is to use insecure defaults.

That's more or less what happened with browsers vis a vis https by default, no? I really have to go out of my way these days to view a plain http site.

Re: Encrypting private data and private communications is now an ethical duty

#40

I can sympathize with the general notion that more encryption is better, even if I wouldn't go to the extreme of declaring it a duty . But the author just completely lost me at: > We should all use PGP, SSL or equivalent tools; VPNs, Tor and/or SSH tunnelling; IPFS, or other distributed file systems — and ditch proprietary OS's in favour of Linux or truly free Android distros... Those tools and techniques should ceas…

I don't see it as unrealistic, as for your comprehension ability, that's debatable. For this to work on everything, it needs to be hardware implemented (security chip/SOC), to avoid taxing the CPU and rest of the system. Software engineering has been lax for so long, but paradigm is changing and it should be security first.
Post reply on HN