Live data from Hacker News

The Government Is Lying to Us About Cybersecurity

fee.org

11–20 of 27 posts

Re: The Government Is Lying to Us About Cybersecurity

#11
post #6
post #4

At the end of the day, when the police can't get into a room, they can break the door down. Same with guns. The police are okay with gun ownership because they have the right to gun citizens down. Not to judge, but that's the balance. Same with why we tortured. It counterbalances their vulnerability to secrets. If torture didn't work, Kiefer Sutherland would never have gotten anywhere. But if everyone were against to…

Of course there is an answer to unbreakable encryption, the same answer to in person conversations at a private location: bug the location where the communication takes place. You don't need a back door on communications if you are "looking over the shoulder" of someone as they type it in. If the person is a suspect, then they can get a warrant to plant a bug.

There are plenty of options outside torture also. But the fear of unbreakableness is persistent, just as is those who believe torture to work or to be okay.

The fundamental underpinnings of any related correct and incorrect behavior is still emotional though. And that is also why loaded words such as "terrorism" get the ball rolling fast, regardless of which way that ball is rolling...

Re: The Government Is Lying to Us About Cybersecurity

#13
post #10

There are some valid points here. Too bad the author felt like taking the least objective possible tone and liberally using half truths and false equivalence was the way to present them.

Can you give some examples of half-truths?

Sure,

>This is why the U.S. intelligence budget of over $75 billion did not prevent most American’s personal details from being leaked

This was the one that most annoyed me. Why would you expect the US intelligence budget to be spent on security for private corporations?

Edit: > There is nothing the U.S. government can do to improve “cybersecurity” other than prosecuting criminal behavior.

Also ridiculous, there are many things the U.S. government could to to improve cybersecurity including apparently protecting equifax from itself.

edit edit: > U.S. citizens who do not report foreign bank accounts (under FACTA) can be fined $250,000 or 5 years in jail

What does the IRS prosecuting for tax evasion have to do with any of this?

Re: The Government Is Lying to Us About Cybersecurity

#14
post #6
post #4

At the end of the day, when the police can't get into a room, they can break the door down. Same with guns. The police are okay with gun ownership because they have the right to gun citizens down. Not to judge, but that's the balance. Same with why we tortured. It counterbalances their vulnerability to secrets. If torture didn't work, Kiefer Sutherland would never have gotten anywhere. But if everyone were against to…

Of course there is an answer to unbreakable encryption, the same answer to in person conversations at a private location: bug the location where the communication takes place. You don't need a back door on communications if you are "looking over the shoulder" of someone as they type it in. If the person is a suspect, then they can get a warrant to plant a bug.

You can say that taking a preventive action helps against anything. (Cue "Minority Report" by Philip K Dick.)

The problem is that a preventive action usually hasn't been taken, but now, when a problem exists, they have something to do with it, and they can't.

They want a built-in backdoor exactly as a preventive measure, a bug.

The problem, of course, is that those breaking the law would still use the unbreakable version, the same way they use other illegal means, and the law-abiding majority will stay safely vulnerable.

Re: The Government Is Lying to Us About Cybersecurity

#15
post #4

At the end of the day, when the police can't get into a room, they can break the door down. Same with guns. The police are okay with gun ownership because they have the right to gun citizens down. Not to judge, but that's the balance. Same with why we tortured. It counterbalances their vulnerability to secrets. If torture didn't work, Kiefer Sutherland would never have gotten anywhere. But if everyone were against to…

>>> Same with why we tortured. It counterbalances their vulnerability to secrets.

If you study history and interrogation techniques you quickly realize that torture has nothing to do with information. It doesn't work that way. The 24 situation of a terrorist with a secret code in his head that will prevent a nuke going off is so circumscribed that if you think you are entering that situation you should assume that you are mistaken. Torture is about confession. It's about getting someone to say something that you want him to say regardless of whether it is true or not. That's the difference between actual intelligence and "actionable intelligence", the actionable stuff need not be true. If it is enough to justify a warrant or a raid accuracy doesn't matter. This is also why torture is so closely linked to religion. Only a puritan need torture out a confession. It's far easier to forge a signature.

Go through the history. Be it the English rack or American Gitmo, they didn't care about accurate information. What they wanted and got was signatures on documents written almost entirely by the interrogators. (I'll leave aside the other use of torture, as simple punishment, because that's a totally different debate.)

Re: The Government Is Lying to Us About Cybersecurity

#16
post #7
post #3

2 rebuttals listed from Schneier's post mentioned in the article linked here are worth a read. https://www.washingtonpost.com/news/volokh-conspiracy/wp/201... and https://www.lawfareblog.com/thoughts-encryption-and-going-da... Neither are from security professionals, and both really downplay the risks associated with having escrow of keys. The number of leaks and breaches across the various government orgs shows that…

The number of leaks and breaches shows there's a serious problem, but keeping keys secret isn't necessarily implied to be near impossible by consequence of this.

Well, it shows that there is a non-zero probability of the key being leaked or breached. And if the key can open everything, that's a consequence big enough that we need to think seriously about it happening.

"Trust us, we'll keep it secret" has been empirically proven to be not as true as they want us to believe.

Re: The Government Is Lying to Us About Cybersecurity

#17
post #4

At the end of the day, when the police can't get into a room, they can break the door down. Same with guns. The police are okay with gun ownership because they have the right to gun citizens down. Not to judge, but that's the balance. Same with why we tortured. It counterbalances their vulnerability to secrets. If torture didn't work, Kiefer Sutherland would never have gotten anywhere. But if everyone were against to…

Way to present a nuanced issue as a seemingly clear-cut case of governmental oppression. It's pretty solidly ingrained in America that a properly-issued warrant should be enough to get law enforcement whatever evidence it needs. Encryption also breaks this fundamental principle, and contrary to popular belief, not everyone who is against government surveillance is necessarily cool with this implication of law enforcement being unable to do its job through the properly established legal means.

Re: The Government Is Lying to Us About Cybersecurity

#18
My personal guess about why federal law enforcement is obsessed with this issue (if it's not just as irrational as it seems at first glance): secure communications and devices are really an obstacle in prosecuting crimes like insider trading or trade secret theft. Prosecuting crimes that leave plenty of physical evidence behind (like bombings or mass shootings) isn't really hindered if you can't read an attacker's phone. But the difference between "lucky timing" and "insider trading" might hinge entirely on the contents of communications. The public and most legislators aren't going to be scared enough of financial crimes to support backdoors, so LEOs tell nonsensical scary stories about how they need backdoors to stop kidnappers and terrorists.

Re: The Government Is Lying to Us About Cybersecurity

#19
post #7

Earlier quoted context omitted.

The number of leaks and breaches shows there's a serious problem, but keeping keys secret isn't necessarily implied to be near impossible by consequence of this.

Well, it shows that there is a non-zero probability of the key being leaked or breached. And if the key can open everything , that's a consequence big enough that we need to think seriously about it happening. "Trust us, we'll keep it secret" has been empirically proven to be not as true as they want us to believe.

Agree 100% about carefully considering consequences of crafting a skeleton key into our most prized technologies. The tech community, at least the most vocal subset in these parts, can keep pushing back against LE's cries for such a key, and it's clear there is merit to such an argument. It just seems to be somewhat provincial from a neutral perspective, however.

Taken from the "other side", it does not seem universally true that generally deployed strong, unbreakable encryption built into "secure" general-purpose commodity hardware is in the best interests of humanity going forward. It seems to be an open question. It was nice to see rational/objective/neutral discourse on HN in the past that considered all sides. But, such a universal perspective seems to be missing of late, and the more recent parochial attitude seems a natural form of pushback, given the current chaos. Hopefully good comes of this.

"Snow Dawg" is currently partaking in thoughtful discussion arguing against NSA's policies on his twitter, if anyone is interested.

Re: The Government Is Lying to Us About Cybersecurity

#20
post #6
post #4

At the end of the day, when the police can't get into a room, they can break the door down. Same with guns. The police are okay with gun ownership because they have the right to gun citizens down. Not to judge, but that's the balance. Same with why we tortured. It counterbalances their vulnerability to secrets. If torture didn't work, Kiefer Sutherland would never have gotten anywhere. But if everyone were against to…

Of course there is an answer to unbreakable encryption, the same answer to in person conversations at a private location: bug the location where the communication takes place. You don't need a back door on communications if you are "looking over the shoulder" of someone as they type it in. If the person is a suspect, then they can get a warrant to plant a bug.

Their complaint about this is that it's hard to do that.

Well, that's good. I think that law enforcement SHOULD be hard. It should be hard and complicated and time consuming. One of the worst things I can imagine is idle law enforcement officers. Bored cops will find something to do. Whether it's going from car to car and ticketing anyone who is 12.1 or more inches from the curb or ticketing people for spitting on the sidewalk, no good can come from idle police.

Idle prosecutors are every bit as much of a potential nightmare. We see District Attorneys being used as political weapons now. Just imagine if they had the power to go fishing through the electronic communications of every political rival.

If the work is difficult, they'll only do it when they have reason to believe a serious crime has been or soon will be committed. It's easy to justify overtime for surveillance on a suspected drug kingpin, organized crime figure, rapist or murderer. It's not so easy to justify it to monitor some guy from a TEA Party Group, BLM or Occupy just so find out what they're doing.

Post reply on HN