Live data from Hacker News

Encryption Is Not a Crime

privacyguides.org

111–120 of 222 posts

Re: Encryption Is Not a Crime

#111

Earlier quoted context omitted.

For what its worth the anti-encryption/anti-privacy laws have caught terrorists in the UK. My company provides data storage for their dragnet and handles various requests and Ive seen first hand 4 different instances where the UK gov watching everyones internet activity led to terrorists being caught.

This number by itself means nothing as the other variables are unknown. How many terrorists were not caught by these systems? How many would have actually done these actions instead of just talking about it? How many could have been caught with just standard police work? Without knowing these variables then there is no way to say if these systems are particularly good at catching terrorists.

I wouldnt go as far as saying it means nothing, but I agree that the story certainly isnt simple. Was just pointing out that "catch terrorists" isnt a purely emotional argument. Would the terrorists be caught anyway? We'll never know, but theres no way you can say they would for certain. Personally I dont think catching a few terrorists is worth giving up privacy but other people disagree.

> Without knowing these variables then there is no way to say if these systems are particularly good at catching terrorists.

I dont think we can ever figure this out since no one is willing to run an rct when it comes to counter terrorism

Re: Encryption Is Not a Crime

#112
post #56
post #34

I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult". It puts the idea into the world that it could be a crime and maybe that it is the status quo. Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on. Maybe "Don’t let them take your right to privacy."

It's also, unfortunately, not literally/universally true. There are plenty of jurisdictions and contexts in which it is a crime.

Which were you thinking of?

I can imagine Iran has some effort to discourage use of VPNs, though of course everyone does.

I thought China simply made it easy to stay within the Great Firewall, and moderately difficult to get out.

Re: Encryption Is Not a Crime

#113

Earlier quoted context omitted.

If the OEM can issue such a certificate, it probably isn’t necessary, because they can access the data and be subpoenaed directly, no?

Yes, I am arguing for is requiring OEMs to implement this mechanism. Frankly, if the NSA wanted to have Apple build a custom iOS version for a criminal so they could sniff his network traffic and flash content from the comfort of Maryland I don't believe that would be impossible today.

If an OEM could decrypt a users data, a government typically won’t bother to do it themselves. They’ll just use legal mechanisms to require the OEM to do the work for them.

Re: Encryption Is Not a Crime

#114

Earlier quoted context omitted.

That sounds like a golden key approach, and the problem is your communication is no longer protected by math, it's only protected by the will of a stranger to be tortured by the government to protect you https://www.rsaconference.com/library/blog/a-golden-key-to-u... The back and forth discussion on cryptography is happening because there just isn't much middle ground. Either someone else can read your messages, or n…

No, I don't accept that this is the case any more than the root certificate system is a golden key. I'm quite sure that Apple can issue me a certificate that allows me to build a custom version of iOS that can be flashed onto my phone; why doesn't the same thing apply to other things?

The two things you are talking about are very different. One is signatures and one is encryption.

Re: Encryption Is Not a Crime

#115
post #66

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

I don’t think this particular devil needs more advocacy. Law enforcement agencies currently have more data about each of us and more sophisticated tools to investigate crimes than at any time in human history. > Politicians are (mistakenly) asking for a master key - but what I feel we should as a community support is some fine-grained legal process that would allow limited access to user information if justified by a…

Well that's your view - but these demands aren't going to go away, and what I think is sensible is for us a technical community to consider reasonable alternatives. Every society is a compromise between anarchic freedom and authoritarian tyranny, and this is another discussion about how a (relatively) new set of technologies can fit into that compromise in a way that is acceptable and reasonable.

I acknowledge the problems you raise, but it does seem to me that we have a good set of systems in place in the form of PKI that has a remarkable amount of flexibility.

It's frankly a bit of an article of faith in our community that encryption == unalloyed good and I think we'd be right to think more critically about that position.

Re: Encryption Is Not a Crime

#116
The problem is the average person doesn't care very much or understand it.

If you ask anyone if privacy matters they will of course say yes. If you ask them why they use software with telemetry or websites with Google Analytics they will simply shrug.

If you ask them if it's alright for the NSA to collect and analyze data from everyone they will say yes and they have nothing to hide.

People don't know what privacy is. They don't know what they are fighting for or where the fight is taking place.

If you take that and then add encryption to the mix... and you have politicians and agency plants talking about "saving the children from online pedos" by banning these "encryption apps and technology"....

Re: Encryption Is Not a Crime

#117

This is too many words to convince someone who already doesn’t believe this. Put more simply: the modern internet doesn’t work without encryption, it is a fundamental part of the technology. Without it, anyone could log into any of your accounts, take your money, messages, photos, anything.

>Put more simply: the modern internet doesn’t work without encryption, it is a fundamental part of the technology. Without it, anyone could log into any of your accounts, take your money, messages, photos, anything.

I'm pretty pro encryption, but even this is pretty dishonest. Phones (ie. PSTN, not iPhones) aren't "encrypted" by any means, but there's plenty of sensitive information sent over it. Lawyers fax each other important documents, and doctors fax each other medical recorcds. There was (is?) even telephone banking where you could do basic transactions over the phone. Even today, some banks/brokerages require you to phone in to do certain high risk operations (eg. high value transfers or account resets). All of this happens without encryption. While that's less security that I'd like, it's safe to say that "anyone could log into any of your accounts, take your money, messages, photos, anything" isn't true either.

Re: Encryption Is Not a Crime

#118
post #15

Something is a crime if society determines that it should be so. Nothing more. Clearly the pressure on government to write these laws is coming from somewhere. You should engage with the arguments the other side makes.

The problem is LEOs (and associated industry) claiming that enforcement is impossible without the ability to obtain cleartext.

This is a lie: obtaining cleartext just makes enforcement vastly easier and more scalable. If crims have encrypted mobile phones, you can still point a microphone at them.

Scalability is the big issue.

Re: Encryption Is Not a Crime

#119

Earlier quoted context omitted.

Yes, I am arguing for is requiring OEMs to implement this mechanism. Frankly, if the NSA wanted to have Apple build a custom iOS version for a criminal so they could sniff his network traffic and flash content from the comfort of Maryland I don't believe that would be impossible today.

If an OEM could decrypt a users data, a government typically won’t bother to do it themselves. They’ll just use legal mechanisms to require the OEM to do the work for them.

Again, as a thought experiment, what legal protections can we put in place - an encryption ombudsman or independent authority - that would allow an arms length, controlled and expiring mechanism that allows limited access to a user's data? What would we as a society be happy to accept? I don't think the demand is an unreasonable one, but I'm trying to figure out what a reasonable collection of mechanisms looks like.

Re: Encryption Is Not a Crime

#120
post #34

I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult". It puts the idea into the world that it could be a crime and maybe that it is the status quo. Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on. Maybe "Don’t let them take your right to privacy."

I wish Americans still believed in American freedoms Encryption is free association and free speech. Talking to someone about what I like without eavesdroppers Transitioning gender is also free speech, freedom of expression. Presenting how I like and not how some wannabe king wants me to

> Transitioning gender is also free speech, freedom of expression.

Is a legal requirement for others to affirm this expression also "free speech?"

Post reply on HN