Live data from Hacker News

Encrypting private data and private communications is now an ethical duty

blog.tripu.info

41–50 of 240 posts

Re: Encrypting private data and private communications is now an ethical duty

#41
post #7

Latest news is Gerard Darmanin, french minister of the interior, is trying to use the latest attack in a french school to ban encryption or at least force encrypted messaging vendors to add backdoors for governments: https://www.numerama.com/tech/1533652-attaque-a-arras-darman...

Right. If everyone hides in encryption, they'll outlaw encryption.

And by extension ending every internet-connected good or service, from email to online banking to remote work to shopping on Amazon or viewing TV on Netflix — therefore The Powers that Be are more likely to outlaw specific uses of encryption to show to voters that they're "doing something about $the_problem".

If they actually want to catch all crime, the only way to do it is mass physical surveillance, either with laser microphones Van Eck phreaking, or with smart-dust and the like. These technologies aren't limited to just government surveillance, so I've been saying for ages now to anyone who will listen that we need to massively alter our "common sense" attitudes to crime and punishment before organised crime starts using it to automate mass-scale blackmail: a judge or a police officer snorting cocaine would be demonstrating poor judgement just to perform the act, let alone as a result of the drug itself, but society is much worse off if a mafia records them doing it so they can get their people off the hook for bigger crimes.

And no, governments can't just use such surveillance to arrest everyone who breaks the laws: my go-to example of this is heroin in the UK, because as far as I can tell nobody defends heroin, yet enough people use it (200k) that fully enforcing the "no possession" law for that substance alone and nothing else would nearly triple the current UK prison population (95k, though I'm assuming that at most only a small percentage of them are currently getting heroin into their prison).

I don't know what the best way to approach things like this would be, only that it's not going to be an easy thing that can fit into a comment box — the best I can do is say that my vibe is instant-and-tiny penalties, so a speeding offence might be £0.1/minute/(MPH over the speed limit)/(thousand pounds of monthly disposable income) or something like that.

Re: Encrypting private data and private communications is now an ethical duty

#42

> you would be morally obliged to disobey In days of yore my CS law module was taught by a QC - that's a high ranking barrister in the UK - who explained the world of difference between the "The Rule of Law" and "the law" in a class called "jurisprudence". Rule of Law (capitalised conceptual) is there as permanent ground truth in contrast to the ephemeral du-jure laws. At times I still struggle with that profound cou…

I think you meant: du-jure -> de jure

Thankyou. And that's why I got a C minus for law.

Re: Encrypting private data and private communications is now an ethical duty

#43
post #7

Latest news is Gerard Darmanin, french minister of the interior, is trying to use the latest attack in a french school to ban encryption or at least force encrypted messaging vendors to add backdoors for governments: https://www.numerama.com/tech/1533652-attaque-a-arras-darman...

Right. If everyone hides in encryption, they'll outlaw encryption.

That would instantly eliminate all eCommerce. I think politicians still care enough about GDP that they wouldn't do that.

Re: Encrypting private data and private communications is now an ethical duty

#44

Legislation in favour of the consumer is almost starting to seem detrimental to the startup founder. The number of barriers, prerequisites, requirements, etc that a founder needs to consider pre-launch is bordering on insurmountable. This might just be me feeling like this, but even considering geo-residency in some of my early prototype designs feels very odd. I was optimistically hoping PaaS providers would catch u…

[dead]

Re: Encrypting private data and private communications is now an ethical duty

#45
post #13

Earlier quoted context omitted.

If they outlaw encryption but everyone encrypts, they can either do nothing or arrest everyone. I'm Spartacus.

> If they outlaw encryption but everyone encrypts, they can either do nothing or arrest everyone. Whatever protection I'm getting from non-consensual surveillance, I am declining it. I'm not sure if we're mindful of this but Gov's only ethical purpose is to serve us. Past that, it has lost it's way.

> Whatever protection I'm getting from non-consensual surveillance, I am declining it.

So far as I know, the only way to do that is to leave whichever country is doing this, which — trust me on this as one who has done so for slightly messier reasons — is a right PITA even when going somewhere else that has a functioning society. I don't think there's any other way to make yourself an "outlaw" in the old-fashioned sense of the word: https://en.wikipedia.org/wiki/Outlaw

Re: Encrypting private data and private communications is now an ethical duty

#46

> you would be morally obliged to disobey In days of yore my CS law module was taught by a QC - that's a high ranking barrister in the UK - who explained the world of difference between the "The Rule of Law" and "the law" in a class called "jurisprudence". Rule of Law (capitalised conceptual) is there as permanent ground truth in contrast to the ephemeral du-jure laws. At times I still struggle with that profound cou…

Lots of ethical systems justify opposition to unjust laws. Utilitarians would say you should disobey a law if it causes more harm than good (while accounting for the good that comes from general order when people do obey the laws). This isn’t just a conservative position

Re: Encrypting private data and private communications is now an ethical duty

#47

I can sympathize with the general notion that more encryption is better, even if I wouldn't go to the extreme of declaring it a duty . But the author just completely lost me at: > We should all use PGP, SSL or equivalent tools; VPNs, Tor and/or SSH tunnelling; IPFS, or other distributed file systems — and ditch proprietary OS's in favour of Linux or truly free Android distros... Those tools and techniques should ceas…

I don't see it as unrealistic, as for your comprehension ability, that's debatable. For this to work on everything, it needs to be hardware implemented (security chip/SOC), to avoid taxing the CPU and rest of the system. Software engineering has been lax for so long, but paradigm is changing and it should be security first.

It's not unrealistic in technological but sociological terms.

Re: Encrypting private data and private communications is now an ethical duty

#48

I can sympathize with the general notion that more encryption is better, even if I wouldn't go to the extreme of declaring it a duty . But the author just completely lost me at: > We should all use PGP, SSL or equivalent tools; VPNs, Tor and/or SSH tunnelling; IPFS, or other distributed file systems — and ditch proprietary OS's in favour of Linux or truly free Android distros... Those tools and techniques should ceas…

What's unrealistic about it? I've been doing it for more then a decade.

Re: Encrypting private data and private communications is now an ethical duty

#49

Legislation in favour of the consumer is almost starting to seem detrimental to the startup founder. The number of barriers, prerequisites, requirements, etc that a founder needs to consider pre-launch is bordering on insurmountable. This might just be me feeling like this, but even considering geo-residency in some of my early prototype designs feels very odd. I was optimistically hoping PaaS providers would catch u…

You don't need all of that stuff if your business respects people's privacy by design. It's like complaining that the GDPR is causing cookie banners on every site. That's only half the reason. The real reason is that the websites need one's opt-in to do something they shouldn't be doing. Obviously the law should have been crafted with an automatic system to reject all non-necessary cookies in mind, but the fault for…

If your system has the notion of users at all, then most of that red tape is unavoidable, no matter how privacy-respecting you are being.

Either a solid and affordable PaaS solution or at the very least a single global international standard is sorely needed here. The current model is barely sustainable as it is, and it's getting worse, even for privacy-respecting endeavors.

Re: Encrypting private data and private communications is now an ethical duty

#50

I am baffled how we went from a liberal "free" democracy to this ersatz of a totalitarian regime where all our conversations/messages/photos need to be dissected, catalogued and approved by un-elected bureaucrats. I mean you can literally go to eastern Europe to see the vestiges of the Stasi where they used to listen to the conversations of their citizens while trying to find dissidents among them. This isn't some ki…

> Then each and everyone can decide to accept this fact or fight back.

That’s exactly what they want to avoid.

Problem/reaction/solution or manufactured consent is much easier.

Post reply on HN