Live data from Hacker News

Attorney General William P. Barr Delivers Address Conference on Cyber Security

justice.gov

101–110 of 230 posts

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#101
post #43

Earlier quoted context omitted.

I'm no fan of Bill Barr, but I don't read this that way, no. It reads to me more like he's saying that from a planning perspective it's better to figure the worst thing that could happen and have a plan already developed that could handle that, rather than being caught by surprise and then having law and policy made in a mad, panicked rush. (In other words, let's not do with cybersecurity policy what we did with coun…

> have a plan already developed that could handle that But... we do have a plan, which is to just not do it in spite of any crisis or whatever. He is misleadingly framing it here like we don't have the ability to backdoor encryption which has never been the problem. He clearly states that what we need to be weary about is public opinion changing , which is basically like saying that we should just get ready to compro…

San Bernardino also already happened. And it wasn't a big deal. They eventually got the phone broken, and there was nothing of value on it. But that's besides the point, it's an example of the type of thing they are talking about.

From my perspective life would not have been any meaningfully different either way if that phone stayed locked. I also can't image some future scenario where it makes such a big deal. What type of information is going to be on some laptop or smartphone that is so important it's worth compromising our general civil rights? There is almost always a hundred human errors around the crime already that they can piece it all together without godmode on every electronic device. A smartphone is rarely an all encompassing security mechanism for any big evil plot.

There is no 'backdoor' technology solution here that makes sense and they need to get used to it.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#102

Earlier quoted context omitted.

Sure, but I can just refuse to decrypt my data. They can just break physical locks.

Sure, you can also destroy evidence! This is already a crime we deal with. Encrypting and throwing away the key is deleting with more steps - in fact it is often an implementation detail of deletion in some software systems. It is already illegal, and already something our justice system deals with. No power grabs necessary.

> Sure, you can also destroy evidence! This is already a crime we deal with.

That is just assuming the premise. Destruction of evidence is a crime, but destruction of private lawful communications is not. The FBI has no right to a married couple's sexting.

The usual case for destruction of evidence is one of two things. Either they produce some emails where you're conspiring to destroy evidence, or that they catch you in the act, seize the evidence you were destroying, and then use it to prove that what you were destroying was evidence.

Finding someone with a bucket full of confetti or an encrypted drive but no key isn't evidence of a crime, and it's unreasonable to be able to put anybody in jail just because they shredded their old credit card statements or can't remember the password for an old device that has been in a closet for three years.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#103
post #93
post #84

Earlier quoted context omitted.

The problem with this line of argument is that it is a general argument against government and not specific to this issue. You could use the exact same argument for why you shot a police officer who broke down your door after securing a warrant. It would quickly be dismissed in that instance so it should carry little weight in the discussion of encryption. If you want the government to completely give up this line of…

> You could use the exact same argument for why you shot a police officer who broke down your door after securing a warrant. No, I couldn't. The operative word there is not "shoot", it's "warrant." The fourth amendment explicitly makes an exception for warrants. If the government has a warrant then I am legally bound to hand over my keys. If I don't, they can put me in prison for that.

Your initial comment seemed to imply that a warrant to break the encryption was "government overreach". If not, I don't see how what you originally posted is an argument against ways around encryption. The question is whether the government should be able to access this information and not whether the government can be trusted with access to that information. If your argument is the latter, than you are arguing against warrants in general.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#104

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

Key escrow has a number of problems, not the least enforcement that keys are valid and validated. (something that there's not a good history of, and international issues come up)

Back doors are worse though - build a back door and it will be used, just not necessarily by the agency it was built for. There are a lot of groups with a lot of resources oriented around taking advantage of this, and few are legitimate. (and some are enemy nations).

There's a third problem - doing it in such a way that it can't be blocked from monitoring. (see "clipper chip" for more on that).

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#105
post #79

Earlier quoted context omitted.

This is all true, but I think encryption backdoors are more possible than people think. The target here is not nerds able to pull code from GitHub or run open source or enterprise software. The target here is consumer stuff by companies like Apple and Google. The government doesn't want it to be easy to do end-to-end encryption. For the average user, easy equals possible. The average user has neither the time nor the…

The scenario you described accomplishes both goals. By banning 'the masses' from using encrypted communications, it'll sort the haystack and everyone who continues to do so can be profiled, plus they're already involved in illegal behavior.

How so? Couldn't we come up with a way of disguising encrpyted message streams so that they did not stand out? It would be more expensive, and given enough analysis they could probably detect them anyway, but it strikes me as an arms race.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#106
post #79

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

This is all true, but I think encryption backdoors are more possible than people think. The target here is not nerds able to pull code from GitHub or run open source or enterprise software. The target here is consumer stuff by companies like Apple and Google. The government doesn't want it to be easy to do end-to-end encryption. For the average user, easy equals possible. The average user has neither the time nor the…

> That being said I still don't think it'll work. Just pointing out the thinking that's going on here.

The problem is that this either shows a stunning amount of ignorance or deliberate malice.

Let's just go back and consider that the government does not want the average user to have strong encryption. What is the play here? The average user is almost by definition not the bad guy, unless we consider the population at large to be criminals by default. Is the government trying to dragnet the entire population and keep everyone under the thumb for minor infractions? Because that's the only feasible target here. Barr can froth at the mouth, mad as the dickens, it won't prevent Bad Guys from using strong encryption. So his only feasible target is the (mostly) law abiding population.

The other point, preventing the likes of Google, IBM, Apple, et. al. of selling devices with strong encryption to blacklisted countries again shows either ignorance or malice. As parent wrote, encryption is just math. Are the government agencies so shockingly uninformerd that they think that in absence of secure IDevices, north korea will be forced to use backdoored technology?

The spread of physical goods can be controlled (to some degree), but the spread of information can at best be slowed down, but not stopped. Doubly so if there are already existing methods of secure communications that the government cannot efficiently crack.

The only conclusion I can come to is that they are well aware that they cannot catch any serious Bad Guy using mandated backdoors. Serious Bad Guys will use strong encryption anyway, they will cover their tracks and won't care what is legal or illegal (in the US). Furthermore, against targets like these, there are already time proven methods of infiltration, social engineering and good old fashioned bribery.

This only leaves the option of taking secure communications away from the population at large, perhaps because the government feels threatened from too many people being able to share ideas? I was never one for tinfoil hattery, so my hope is that I'm wrong.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#107

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

I totally get what you are saying, but it is quite the rabbit hole if we determine that 'we can't have any illegal number... everyone should be able to share any number with anyone else'

That basically means we have to entirely get rid of copyright, since all data (books, movies, software, corporate secrets, state secrets, etc) are just very large numbers.

Do we believe that there should be no restriction on the sharing of any data? I can see the appeal, but there are far reaching consequences if we say that.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#108
post #79

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

This is all true, but I think encryption backdoors are more possible than people think. The target here is not nerds able to pull code from GitHub or run open source or enterprise software. The target here is consumer stuff by companies like Apple and Google. The government doesn't want it to be easy to do end-to-end encryption. For the average user, easy equals possible. The average user has neither the time nor the…

This idea represents the best possible compromise to the situation outlined here. I think we should all be crypto hardliners in the sense that we refuse to allow laws against certain kinds of math, but at the same time, we may have to compromise on government access to keys once they have been handed over to a third party.

If you have not handed your private keys over to anyone, they should be yours alone, but once you have uploaded your private keys to a coroprate cloud server, you may have to accept that law enforcement will be able to get warrant access.

This won't solve the problem for law enforcement, but it will make it easier to catch lazy people while preserving the option for full security for those who want to control their own data.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#109

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

>are we, in effect, suggesting that certain math be made illegal? If that's really what's being proposed, I'd urge people to consider "Illegal Numbers" and how effective that's been.

I keep seeing this "implausibility" of enforcing illegal encryption brought up, and I really think it's wishful thinking. If such encryption algorithms ever are made illegal in some manner, it will be trivial for the government to get the result they want.

It won't be about completely stopping people from using AES, nor will it be about imprisoning every person who continues to use it. What it will be about is turning "this target of our investigation is using illegal encryption" into an immediate cause for search/arrest warrant. And that will be more than enough for 95%+ of the purposes they're looking for.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#110
post #88

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

Breaking encryption for the government is so furiously stupid it blows my mind every time it is suggested. Especially here, where people actually give the idea merit. It makes me miss oldschool /. where 100% of everyone was on the same page. Your point illustrates a huge reason as to why. Backdooring stupid.crypt and forcing law abiding people to use it just insures that big badguys will use any other kind of encrypt…

> Breaking encryption for the government is so furiously stupid it blows my mind every time it is suggested.

Yeah. There's no distinction whatsoever between encryption with backdoors and no encryption at all. Imagine our current web with no encryption. Your logins are all effectively plaintext; your online shopping is effectively plaintext; your emails are all effectively plaintext. "Furiously stupid" is a good way to describe this whole proposition.

Post reply on HN