Live data from Hacker News

A brief history of the U.S. trying to add backdoors into encrypted data (2016)

atlasobscura.com

191–200 of 207 posts

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#191

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

I didn't know any of this. Thanks. "The U.S. Munitions List changes over time. Until 1996–1997, ITAR classified strong cryptography as arms and prohibited their export from the U.S.[5] Another change occurred as a result of Space Systems/Loral's conduct after the February 1996 failed launch of the Intelsat 708 satellite. The Department of State charged Space Systems/Loral with violating the Arms Export Control Act an…

Does that make crypto nerds arms dealers?

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#192

Earlier quoted context omitted.

In some cases artwork where no child was harmed counts as CSAM. Is that execution worthy?

Can you give an example? If we're talking about Loli-type stuff, I hate it, but it doesn't harm kids directly, so execution is too harsh.

> If we're talking about Loli-type stuff

Yeah, IIRC, there is precedent for this being prosecuted. Reprehensible as it is, it worries me deeply that consuming fiction can cross a line into illegality. Pedophilia is such a rightfully hated thing that it's a powerful motivator in politics and social action; people will throw away their lives just to spite child abusers sometimes. I think we need to be extra careful about our response to the issue because of that, especially as it pertains to essential rights.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#193

Earlier quoted context omitted.

Can you give an example? If we're talking about Loli-type stuff, I hate it, but it doesn't harm kids directly, so execution is too harsh.

> If we're talking about Loli-type stuff Yeah, IIRC, there is precedent for this being prosecuted. Reprehensible as it is, it worries me deeply that consuming fiction can cross a line into illegality. Pedophilia is such a rightfully hated thing that it's a powerful motivator in politics and social action; people will throw away their lives just to spite child abusers sometimes. I think we need to be extra careful abo…

And that's why I'm cautious about that. Actual CSAM (and pedophilia) should be punished as harshly as possible, period. Once we're out of that realm, intent begins to be relevant. Perhaps harsher punishments for pedophiles (chemical castration is an artful solution) would help quell the issues that CSAM "art" can cause.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#194

Earlier quoted context omitted.

> If we're talking about Loli-type stuff Yeah, IIRC, there is precedent for this being prosecuted. Reprehensible as it is, it worries me deeply that consuming fiction can cross a line into illegality. Pedophilia is such a rightfully hated thing that it's a powerful motivator in politics and social action; people will throw away their lives just to spite child abusers sometimes. I think we need to be extra careful abo…

And that's why I'm cautious about that. Actual CSAM (and pedophilia) should be punished as harshly as possible, period. Once we're out of that realm, intent begins to be relevant. Perhaps harsher punishments for pedophiles (chemical castration is an artful solution) would help quell the issues that CSAM "art" can cause.

> period.

Yeah, within the bounds of not torturing people and all that constitutional punishment stuff.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#195

Honorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thaw…

RSA = Republic of South Africa

RSA (Rivest–Shamir–Adleman) is a public-key cryptosystem, one of the oldest widely used for secure data transmission.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#196

Earlier quoted context omitted.

And that's why I'm cautious about that. Actual CSAM (and pedophilia) should be punished as harshly as possible, period. Once we're out of that realm, intent begins to be relevant. Perhaps harsher punishments for pedophiles (chemical castration is an artful solution) would help quell the issues that CSAM "art" can cause.

> period. Yeah, within the bounds of not torturing people and all that constitutional punishment stuff.

Of course, make it quick and painless, but that behavior simply cannot be tolerated in a civilized society. Children are incredibly important, and how we treat them as a society is critical. The threats—perceived and real—to children in modern times have reduced the freedoms afforded to them, hampering their ability to develop in the real world from a younger age.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#197
post #104
post #99

Earlier quoted context omitted.

The idea was to make it blatantly clear that it's not a "munition".

Why would that matter, if source code is protected speech anyway? And why is it more "clear" with a printed book vs. an emailed text file?

> source code is protected speech

That wasnt the case at the time.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#199

Earlier quoted context omitted.

A backdoor, which works anywhere and way better than the wrench option.

They don't need it, which was my point. They have all the tools the need right now to get what they want. Why should anyone grant them more?

The problem with using a wrench is that the person you use it on knows you have their data. Having a backdoor means they can see your stuff without you knowing it's been compromised.

Re: A brief history of the U.S. trying to add backdoors into encrypted data (2016)

#200

Earlier quoted context omitted.

Would be interesting what similar companies are (in parts) most likely agency fronts. My guess would be quite a few in the soft privacy selling business, such as VPN or email providers.

Proton mail is a CIA front email provider

That is a false statement: https://www.reddit.com/r/ProtonMail/comments/14demhj/debunki....

To address the broader topic of this thread, there is no comparison between Crypto AG and us. Our encryption occurs client-side, our cryptographic code is open source ( https://proton.me/community/open-source ), and our tech can and has been independently verified. More about this here: https://proton.me/blog/is-protonmail-trustworthy.

Post reply on HN