Live data from Hacker News

Encrypting private data and private communications is now an ethical duty

blog.tripu.info

141–150 of 240 posts

Re: Encrypting private data and private communications is now an ethical duty

#141
post #67

I am baffled how we went from a liberal "free" democracy to this ersatz of a totalitarian regime where all our conversations/messages/photos need to be dissected, catalogued and approved by un-elected bureaucrats. I mean you can literally go to eastern Europe to see the vestiges of the Stasi where they used to listen to the conversations of their citizens while trying to find dissidents among them. This isn't some ki…

Many people look at things like the Stasi and think - the problem with it was who was in charge, not that it existed. We’re the good guys so it would be a good thing. Not a bad thing. The problem is, they’re almost always the absolute worst to deal with, as almost any evil is excusable when done ‘for the right reasons’ or when ‘we’re the good guys’, where selfish evil at least sometimes takes a break or feels bad. An…

“If only it were all so simple! If only there were evil people somewhere insidiously committing evil deeds, and it were necessary only to separate them from the rest of us and destroy them. But the line dividing good and evil cuts through the heart of every human being. And who is willing to destroy a piece of his own heart?” ― Aleksandr Solzhenitsyn, The Gulag Archipelago 1918–1956

Re: Encrypting private data and private communications is now an ethical duty

#142
post #100

Earlier quoted context omitted.

Eh, might makes right is in one scenario. Poisoning, betrayal, manipulation, propaganda, co-opting often work too. As many ‘strong men’ have learned to their detriment. Underlying it, those who survive will justify however they want, they’ll be the ones writing the history books.

I meant that in the fundamental sense, that I can do whatever I want and nobody can stop me, as long as I have the most physical - in the sense of physics - power. The only thing that I can not do is force others to do things I want them to do, they can always decide to refuse and die. Poisons are just molecular bullets. Betrayal, manipulation, and propaganda, not sure how they would achieve anything if I have enough…

Theoretically, sure. Though if you went that route, ultimately you might just be ruling over a pile of ashes no?

Practically, how do you propose acquiring that power, or having anyone to rule over, that would not leave you vulnerable to all those other things I listed?

As in, whatever power you have being used to serve someone elses interests instead of your own, or even be used to destroy you. Or your own basic needs being sabotaged behind your back to murder you.

There is a reason why dictators and kings tend to have somewhat predictable endings, and it's rarely 'passing away peacefully in their sleep at a ripe old age'.

Re: Encrypting private data and private communications is now an ethical duty

#143

Earlier quoted context omitted.

I think the Law of Power (basically, "might makes right") will run circles around any other "law" concept. Whether even this conforms to some "natural law" underneath, is secondary IMHO.

“Might makes right” seems more like an observation of a particular instance in the feedback loop of building power. America is for example in a pretty strong position, but maintains power by doing diplomatic stuff. Being in some sense the leader of a big coalition of friendly countries (imagine if we had to force EU countries to accept our bases by violence, it is way cheaper to just be on friendly terms with them an…

It's called hegemony. Hegemony is just another form of dominance, as ultimately it's backed up by force of arms. Power flowing from the barrel of a gun and all that.

Re: Encrypting private data and private communications is now an ethical duty

#146

Earlier quoted context omitted.

Unfortunately this doesn't work because a _lot_ of will people legitimately will tell you they "have nothing to hide" and would tell you they'd let 3-letter agencies in the U.S. go through their phone with a fine-tooth comb (at least, until they're actually being faced with that reality and try to get out of it). The only reason we currently have any message encryption is because a few tech companies have made the de…

"The only reason we currently have any message encryption is because a few tech companies have made the decision to protect as many as possible by releasing products which enable it (iOS, Whatsapp, and now texts via Google Messages)." Completely false. Phil Zimmerman gave us PGP for free in 1991, and numerous open encryption standards now belong to the general public. Giving credit to Apple, Meta, and Google for this…

PGP et al is basically irrelevant given how few people use PGP compared to the >2.5 billion users that use Whatsapp and >1B using iMessage.

My wording wasn't exact; other encryption programs have enabled secure messaging, but without big players it would've been outlawed by now because it would've been easier to say "only criminals" use encrypted communication.

As for the "numerous open encryption standards", these are fairly irrelevant since the foremost goal is not encrypted messaging, but mostly for creating a secure way for business to interface with customers (can't run a startup or Fortune 500 business without being able to trust requests and responses). Getting people to use encrypted communications is the hard part, not designing the encryption or even implementing it.

Re: Encrypting private data and private communications is now an ethical duty

#147
> We should switch to Protonmail or similar webmail

Doesn't Protonmail decrypt at the server? That is, can't Protonmail read your encrypted messages? And don't they have form for grassing people up?

I'm not sure about those two claims. But that's the point - it's difficult for even a techie to use crypto(graphy) safely. If you want to use it as an impediment to snoopers, or as some kind of statement, cool. But if you let the server decrypt your messages, you aren't really safe.

Signal disloses your phone number.

I think I understand the limitations of PGP/GPG; I'd use that, if my correspondents had ever heard of it (and if I were sure that they weren't going to forward/reply-to my messages in plain, or store the plaintext on some Google server). But at the moment, the state of end-user encrypted messaging software doesn't look very safe to me. What I would like to see is an end-to-end scheme that can't be used unsafely, even if the user is an idiot, and that is used more-or-less universally.

Otherwise I'm reluctant to SHOUT my secrets over the internet.

Re: Encrypting private data and private communications is now an ethical duty

#149
post #20

Earlier quoted context omitted.

Author here. (Thank you for all the comments!) Yes, I know SSH tunnelling and compiling your own Android are tall orders for the average user. Here I'm just hinting at some examples that are well-known among us geeks, but there are easier to use alternatives to all that. I suspect Protonmail is as easy to use as GMail. VPNs are so easy to use nowadays. The UX on Signal isn't particularly challenging to the average us…

> There is a lot we techies can do to educate normies... This isn’t something you’ll find universal agreement about. My own position is that we techies are seen as weirdos by most of the population, and what we should do is leave normal people alone. Definitely not try to “educate” them – think about how elitist that’s going to sound to many of them.

The phrasing of "educate" (not to mention "normies") definitely implies a patronizing and unhelpful approach. I don't think technical people should go around giving unsolicited lectures to people they perceive as lacking technical expertise. However, I don't think there's anything wrong with technical people sharing what we know in a respectful way to people who are actually interested in a way that accounts for their needs. For example, if a social group you're in is deciding what messaging app to use to coordinate meeting up, it would be appropriate to share what you know about the various options' end-to-end encryption. But going on a rant about the privacy issues of a social media app because a distant relative mentioned it offhandedly probably isn't productive.

By analogy, I wouldn't mind a friend with medical training sharing what they know about heatstroke prevention to a group of us before we embark on an hike. I would mind them giving me nutrition advice based solely on what I ordered at a restaurant.

(Edited to fix wording)

Re: Encrypting private data and private communications is now an ethical duty

#150

I am baffled how we went from a liberal "free" democracy to this ersatz of a totalitarian regime where all our conversations/messages/photos need to be dissected, catalogued and approved by un-elected bureaucrats. I mean you can literally go to eastern Europe to see the vestiges of the Stasi where they used to listen to the conversations of their citizens while trying to find dissidents among them. This isn't some ki…

> The future is grim and to be honest I would just rather they came out in the open and acknowledged the fact that democracy and privacy as we know it is dead.

That's overcooked. We've only had strong end-user crypto(graphy) for about 20 years; you can still have private conversations, whether in a field or in a private space that you are sure isn't bugged. This is no worse than it was 20 years ago. "Democracy [...] is dead" is a counsel of despair.

Post reply on HN