Live data from Hacker News

FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

rietta.com

111–120 of 184 posts

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#111
post #14

Earlier quoted context omitted.

How many people can be bothered if it's not a turnkey solution?

Like I said it's not about the average person, it's about someone with something to hide. Those with something to hide will always go the extra distance. The issue I take with the FBI approach is it will have no effect on those that have stuff to hide but destroy any semblance privacy for those that don't. Terrorists will use GPG, citizens will use their backdoored iPhone full disk encryption and everyone but the ter…

>Always

I gave some sources in https://news.ycombinator.com/item?id=10582206 that might change your mind. Changing the default makes a difference.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#112
post #13
post #4

So... the FBI is essentially arguing we should all keep our doors unlocked because they have had to do some investigations in the past where they came to a home that was locked and it was hard for them to enter the home.

The FBI want to have a giant warehouse that houses a copy of every house key but we don't need to worry because no one will ever manage to break in to the warehouse.

I hate how we always have to tiptoe around saying that the primary threat would be a non-government actor breaking into the warehouse. I'm much more worried about the FBI itself having the keys.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#113

I think an interesting approach that could be taken by Apple is to concede to letting the FBI have a master key, so long as they hold an insurance policy that covers the damages in the case of a key leak, including but not limited to the potential damage to Apple's brand and market value, and the same damages to all of Apple's customers that relied on their security. That would force the FBI to reconcile the costs of…

I, for one, would gladly enjoy having to pay for the insurance policy in the form of taxes out of my paycheck to cover the stupidity of having a master key system in place, not to mention when the premiums skyrocket after said key gets stolen and all of our iPhones get breached. /s

That's exactly the point. Apple agreeing to their demands in exchange for a reasonable insurance of the potential risks would force the FBI to reconcile their unreasonable demands with the public.

I would imagine that the biggest cheerleaders of the FBI's side in the general public are Republicans. Can you imagine them ever supporting this?

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#114
post #79

Earlier quoted context omitted.

If only good guys used guns, nobody would need them. It actually is "we know bad guys already have guns, so better if good guys have them too". Same with crypto, btw.

That's not completely true. If bad guys didn't have guns, we'd still want good guys to have them. I don't want police having to take on a guy with knives and a baseball bat, themselves only armed with knives and a baseball bat.

I do. The police shouldn't have access to weaponry that citizens cannot obtain except in very specialized circumstances, like say a particular unit in a city like Detroit or Chicago.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#115
post #79

Earlier quoted context omitted.

If only good guys used guns, nobody would need them. It actually is "we know bad guys already have guns, so better if good guys have them too". Same with crypto, btw.

That's not completely true. If bad guys didn't have guns, we'd still want good guys to have them. I don't want police having to take on a guy with knives and a baseball bat, themselves only armed with knives and a baseball bat.

Why not? It works.

Cops without guns: https://youtu.be/cX5CPx4RKWw

Cop with gun: https://youtu.be/RdoeBXt06Bc

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#116
post #79

Earlier quoted context omitted.

If only good guys used guns, nobody would need them. It actually is "we know bad guys already have guns, so better if good guys have them too". Same with crypto, btw.

That's not completely true. If bad guys didn't have guns, we'd still want good guys to have them. I don't want police having to take on a guy with knives and a baseball bat, themselves only armed with knives and a baseball bat.

British cops do that quite regularly.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#117
post #69

Earlier quoted context omitted.

I see this objection raised so frequently, and I feel it really misses the point badly. The tech community tells itself that it won the first "crypto wars". You cannot win "wars" against governments in that sort of sense and the first crypto war was never actually won at all. I think in light of events in recent years we need to reinterpret the events of the 90's in a new light - the tech industry didn't win, rather,…

Yup. By analogy the lawyers can outlaw six egg omelets with butter and orange flavor. So, then McDonald's won't be able to sell them, but I can still make them in my own kitchen. The lawyers can outlaw strong encryption on products from Apple, Google, Microsoft, etc. and, then, crooks who use those products can more easily be caught, and that will amount to nearly all the common crooks. But I can still get some simpl…

> Then copy that file to the smartphone or whatever and send it, with no attempt at security. Done.

They still know who you are communicating with. There are ways to communicate without disclosing with who you are communicating.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#118

Earlier quoted context omitted.

People challenging this anti-crypto movement should really push this example because it is really perfect. Before we consider key escrow, please explain exactly how physical key escrow was breached in New York and tell us how that will be prevented when the key in question isn't even something you have to physically get.

This should always be presented as an additional argument, though, not the only argument. Because an argument based solely on securing the backdoor implies that if it could be kept secure enough, there's no other reason not to do it. Even if we could somehow guarantee absolutely that the backdoor will only be used by the intended users, backdoors are still not acceptable. For much the same reason that it's not accept…

The answer to the begged question of the New York key escrow example is that it is impossible to guarantee a backdoor is 100% secured and only accessible by the intended users.

I'm not sure the camera analogy will carry weight. It sounds hyperbolic to most people as it tries to equate actually being recorded in your private affairs to the possibility of materials being accessed when a warrant is issued.

Most people have no problem with law enforcement accessing evidence when a warrant is issued. The only way to win over the general population is to demonstrate encryption is fundamentally different then simple access.

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#119

Earlier quoted context omitted.

People challenging this anti-crypto movement should really push this example because it is really perfect. Before we consider key escrow, please explain exactly how physical key escrow was breached in New York and tell us how that will be prevented when the key in question isn't even something you have to physically get.

This should always be presented as an additional argument, though, not the only argument. Because an argument based solely on securing the backdoor implies that if it could be kept secure enough, there's no other reason not to do it. Even if we could somehow guarantee absolutely that the backdoor will only be used by the intended users, backdoors are still not acceptable. For much the same reason that it's not accept…

[deleted]

Re: FBI Wants It to Be Impractical to Deploy Strong Encryption Without Key Escrow

#120
post #3

I wonder if anyone has explained to them there is this thing called open-source software. Sure you may be able to convince/force Apple to give you some sort of key escrow system but do you think you can convince the GPG developers? If you implement key escrow and it's public knowledge that encryption systems that implement it are useless then people that actually want to hide stuff will simply use GPG and other uncom…

It has been explained to them multiple times in congressional hearings. If you have a long time, the recent House Judiciary Committee Hearing is worth the watch:

The Encryption Tightrope: Balancing Americans’ Security and Privacy https://www.youtube.com/watch?v=g1GgnbN9oNw

There was another one that I watched back in June, but I cannot find the video at the moment. Should have bookmarked it!

In the rietta.com article, I linked the this hearing, starting with Susan Landau's testimony starting at https://www.youtube.com/watch?v=g1GgnbN9oNw&t=3h35m50s. But there is more must watch portions of the hearing.

I like GnuPG and I use it regularly with work as does my team. And some of our clients do too, but not nearly enough. But my mom and dad are never going to use it. They do both use iPhones though. So being able to protect them is important.

Post reply on HN