Live data from Hacker News

Civics is boring, so, let's encrypt something (2024)

queue.acm.org

11–20 of 74 posts

Re: Civics is boring, so, let's encrypt something (2024)

#11
Any online service typically keeps some amount of logging. A fully encrypted online service can certainly hand over some amount access and account information, and in my experience that's plenty enough for law enforcement to go and do the normal police detective work they're used to doing.

Re: Civics is boring, so, let's encrypt something (2024)

#13
post #4

I’m trying to skim this but there is a lot of meandering and I’m still not sure what their main point is.

It is not easily skimmed. The author is describing a substantially new and different way of thinking about the problems of strong cryptography under the rule of law that you may not have come across before. Consider reading it and then returning if you have more specific questions than ‘tl;dr please?’

Re: Civics is boring, so, let's encrypt something (2024)

#14

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

Harkens back to the days when we could only export 40 bit encryption due to ITAR (which still applies to a lot of stuff... just not the 40 bit part)

https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...

Re: Civics is boring, so, let's encrypt something (2024)

#15
post #8

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

At minimum, bad actors inside the government could always use the access mechanism. What's your concept for preventing other bad actors from getting it though?

Re: Civics is boring, so, let's encrypt something (2024)

#16

This article frames a false choice of either designing a system that allows government access to everything you do digitally (which is now almost everything), or having the government design such a system. In reality the choice is between such a totalitarian surveillance state without the possibility of digital security guarantees, or one where police can’t read your digital mind but can do good old fashioned police…

Nah, you forgot the choice when you naively think corporations can provide a simulacrum of privacy, when in reality they're indistinguishable from any other large org.

Re: Civics is boring, so, let's encrypt something (2024)

#17
post #8

Earlier quoted context omitted.

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

At minimum, bad actors inside the government could always use the access mechanism. What's your concept for preventing other bad actors from getting it though?

"What if 'us' is bad" is a separable question from "is NOBUS possible".

I'm not advocating for it, I'm just saying the computer science of this matters, and a lot of people have objections to the concept of NOBUS that are more ideological than empirical.

Re: Civics is boring, so, let's encrypt something (2024)

#18
post #17

Earlier quoted context omitted.

At minimum, bad actors inside the government could always use the access mechanism. What's your concept for preventing other bad actors from getting it though?

"What if 'us' is bad" is a separable question from "is NOBUS possible". I'm not advocating for it, I'm just saying the computer science of this matters, and a lot of people have objections to the concept of NOBUS that are more ideological than empirical.

I think any practical implementation needs to have an "us" that's like "with a valid warrant" or secured on the govt end anyway, right? Otherwise you have to deal with "what if someone in the govt leaks the keys" or "what if someone in the govt is a spy". I consider those outcomes the same as foreign governments getting backdoor access basically.

Re: Civics is boring, so, let's encrypt something (2024)

#19
post #8

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

If 100 different governments think "nobody but us have access", between 99 to 101 governments are wrong. O:-)

(I will grant number 101 is the hard one to defend.)

Re: Civics is boring, so, let's encrypt something (2024)

#20
post #8

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

I don't buy it. These systems are always multiparty. In a single party cryptosystem we can have internal integrity. We know we're not the bad guys and we didn't share the private information with the bad guys, therefore the bad guys don't have the data.

Once you're multiparty that goes away, any other party can definitely betray you and then it's game over, your own integrity doesn't matter.

Historically NOBUS was about having a particular technological lead, that's very fragile and didn't work out long term. If anybody has that lead today it's the Chinese, but realistically nobody has such a lead.

Post reply on HN