Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

111–120 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#111

Here's my biggest complaint with this debate - people are confusing literal with metaphorical. They make the analogy of the unbreakable safe. Encryption isn't that. You can still recover the physical phone and all of the storage chips on it. That the patterns of bits in the chips make up some unrecognizable utterance is seemingly immaterial. I could write gibberish in my journal at home if I wanted to, and I think we…

His comment makes sense to 99% on non-tech people, and if it was possible it would make sense to all. Would we want to open Bin Laden's iPhone? He wants you to have your home with 100 locks, guard dogs and armed guards. BUT if a court orders you, you have to let the police in to check x, y and z. Now I don't think that a secret key can be somewhere and stay safe for a long time. It will be leaked or hacked. This plac…

> if it was possible it would make sense to all.

That's not true; it doesn't make sense to me even if it were possible to guarantee proper handling. The risk of the government abusing it's power in a completely legal way is greater than some crimes going unsolved because documents remain secret.

What matters to me is the power imbalance; with few exceptions whatever the government can do, normal people should be able to do to.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#112
post #24

The government has demonstrated that they will abuse every power given to them, and even those that weren't. I would not entrust every aspect of my personal information to the very same organizations that indefinitely detains people, including American citizens, without access to a lawyer while commiting acts of torture; and the ones that said the Patriot Act could never be used for domestic surveilance; that lied ab…

Also, if they can't even properly secure their own cyber offensive tools. How long until other actors get hold of the backdoor keys? It would basically render the effort of encryption moot.

They shouldn't even be asking for this power if they can't at least academically prove that they can't mess it up.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#113
post #36
post #20

Earlier quoted context omitted.

> key escrow with access controlled by a multilevel secret sharing system that requires consensus among a diverse international group of shareholders to release the key from escrow. The shareholder group is chosen so that it includes a mix of public and private entities in a variety of jurisdictions, including anonymous shareholders, so that no entity can acquire enough power or influence to force a key to be reveale…

The probability of that can be made arbitrarily low by proper choice of parameters for the secret sharing system, at least against realistic threats over realistic timeframes.

I think you vastly underestimate what intelligence agencies operating outside the bounds of the law are capable of doing.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#114
post #41

It's hard to know where to even begin in arguing against this. There's the freedom/privacy argument, but I guess this is debatable depending on if you view computer files as an extension of your ideas/knowledge, or an extension of your physical possessions. Someone brought up the entire "risk of overreach and abuse" argument. There's also the likelihood of any tools the government has being leaked and used by bad act…

Consider these two points as a start: - They solved crimes before iPhones. Encryption is not a roadblock - In many countries guns are illegal. Yet criminals do own them. If encryption becomes illegal, criminals would still use it

I think their intent is not so much to make criminals not use it, but have companies use backdoored encryption, so they can get Apple's keys to a device with a warrant.

The problem remains that they constantly abuse their power and are able to even circumvent the warrant part once they know that those keys exist.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#115
post #78

Earlier quoted context omitted.

That's not the point. Like a body buried in the desert, there is nothing that can force a person to reveal anything. Silence is encryption enough when it comes to secrets. Torture doesn't work either. So it's business as usual. It's obstruction of justice. Book'em. And of course, "I can't remember" is always the greatest defense. This whole thing is about the government endangering the public in exchange for abusing…

Can't remember is a statement that can be disproven. Pleading non self incrimination laws (as per Miranda) is more effective. Even if you have nothing incriminating. This is what DoJ wants to close by making just possession of encrypted documents criminal. (Note: not a lawyer.)

>Can't remember is a statement that can be disproven

It is? I'm not sure how you'd disprove it. Anecdotally (which I suppose actually matters in this case!) I've had a case where a (fairly long, 26 character) password I used regularly suddenly (and thus far, permanently!) went out of my head. I can remember some fragments of the password but not the whole thing.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#117

Earlier quoted context omitted.

His comment makes sense to 99% on non-tech people, and if it was possible it would make sense to all. Would we want to open Bin Laden's iPhone? He wants you to have your home with 100 locks, guard dogs and armed guards. BUT if a court orders you, you have to let the police in to check x, y and z. Now I don't think that a secret key can be somewhere and stay safe for a long time. It will be leaked or hacked. This plac…

> if it was possible it would make sense to all. That's not true; it doesn't make sense to me even if it were possible to guarantee proper handling. The risk of the government abusing it's power in a completely legal way is greater than some crimes going unsolved because documents remain secret. What matters to me is the power imbalance; with few exceptions whatever the government can do, normal people should be able…

100000000000000% wrong. Store a file from your offshore account--showing that you avoided $1.78b in taxes--at home and IRS can raid it at any time with a court order. The same applies to all your documents, papers.

The 4th amendment doesn't mean you can do every illegal thing in the world and never fear the state...simply the state cannot engage in fishing expeditions. If 5 kids are reported missing from your neighborhood, and a day later you have a backhoe digging on your backyard, be ready to answer a few questions--that may lead to other questions and warrants.

>>The risk of the government abusing it's power in a completely legal way

No such thing in a western /democratic society. After you go all the levels, you must obey. Sometimes it sucks, but...

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#118
"law enforcement equities"

What an odd phrase.

We have a criminal justice system in this country that is adversarial and is tilted in favor of the accused. That's because our founders realized the immense power of the state could easily overrun any person it wanted to unless there were strict and tight guards on what they could do.

These lawyers, who presumably should know much more about all of this than I do, continue to make cases that strike me as "There are bad people! Because they are really bad, we need to change the game to give us more power"

But there have always been bad people. There always will be. There is no stopping that fact. It is part of being human.

I wonder if these people realize that even if they continue to get their way, the only thing they'll end up doing is moving the really bad people from the private sector to the government. I get the feeling they slept through a large part of world history.

I continue to hear arguments than sound reasonable. I continue to hear wonderfully-intricate arguments. What I've yet to hear is any of these yahoos recognize exactly what kinds of trade-offs they're pitching. I get the feeling I'm watching very poor workmen, focused on the tiny job in front of them instead of the ramifications of that job. I don't think we need to argue that many of these people are wrong as much as we need to argue that many of these people are incompetent. It doesn't bode well for the future.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#119
post #65

The argument here is extremely simple. Encryption is the only way to secure information. This is true for criminals and non-criminals alike. To deny encryption is to deny security to everyone. Presuming it's the criminals who will look to exploit these vulnerabilities, denying security is making every non-criminal susceptible to attack. So the only question that needs to be answered is this. Do we want to protect our…

> Encryption is the only way to secure information.

I am not sure that this argument is simple at all.

Encryption only provides theoretical security. In practice even if strong encryption can't be broken it can almost always be bypassed rather trivially if data is being accessed on a regular basis.

If data is encrypted and left cold then that can be difficult or impossible to retrieve if a secure key is used and that key has never leaked anywhere but that is a pretty limited use case.

For average people encryption provides very little real world security because their data is online on buggy insecure devices all the time so there are always easier ways to compromise their data than breaking crypto.

Sophisticated criminals also don't trust encryption and don't use digital devices at all.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#120

Gotta love the fact that the EU seems to think the exact opposite https://www.theguardian.com/technology/2017/jun/19/eu-outlaw...

It's not as simple as that. In the EU there are lots of political factors (like the director of the Dutch intelligence service, to name just one) that are quite vocal about abolishing strong end-to-end encryption; just as there are political factors in the US that wish to grant citizens the freedom to use strong encryption unencumbered.

But apart from the UK, Intelligence services in European countries tend to have less influence and aren't as popular with the general public. Many people have bad experience with intelligence services (Germany in the 30s/40s, Eastern European countries until 1990) so that there's still a lot of mistrust.

That has changed a bit with recent terror attacks (fear of terror outweighs other fears) but in general, data protection is taken much more seriously in Europe than in other regions and that doesn't only include companies but also the state.

Post reply on HN