Live data from Hacker News

More encryption means less privacy

queue.acm.org

131–140 of 221 posts

Re: More encryption means less privacy

#131
post #29
post #2

> Slapping unbreakable crypto onto more and more packets is just going to make matters worse. The only way to retain any amount of electronic privacy is through political engagement. While political engagement is an alternative to "slapping unbreakable crypto" onto things, this article establishes no precedent for political engagement actually helping! I see the technical as political, direct action as engagement. An…

Direct action is a pretty terrible form of engagement. There's a real process and it should be used. People are starting to realise this with the Sanders campaign, although they've still gone about it pretty badly. Engagement has to be institutional and ongoing. The EFF/ACLU approach is pretty good. If the 4th amendment lobby was anywhere near as good as the 2nd amendment lobby, you would be in a far better place. Ed…

The main thing they have is a very large, very profitable industry whose income rises and falls with minor changes in legislation. If the fourth amendment were the freedom to eat sugar, I guarantee that their advocacy would be just as effective.

Direct action is the only effective form of engagement other than direct payments.

Re: More encryption means less privacy

#132
post #113

Earlier quoted context omitted.

Rarely does encryption exist in a complete vacuum. Just as we cannot necessarily listen to every one on one conversation, those conversations become important when related to something occurring withing the "physical" world. I think we've seen that Tor does not protect you from someone who's determined to find you (see: Silk Road).

Indeed, at least with Tox, all I need is a separate key exchange, somewhere. In person works wonders. So does random email, or instant message, or you name it. At least for communications that need that layer of security and anonymity, it's certainly there. And as I implied, rubber hoses won't work on anonymous and encrypted digital identities "somewhere else". At least regarding Silk Road, that's because he made ama…

> And that was the beginning of his fuckups, with the final one by paying for an assassination attempt.

That's my point. At some point he needed to leave the digital world and live in the real world. There is no perfect false identity, not one that does anyone any good. Whether you are looking to overthrow a regime, sell drugs, or just keep your recent pregnancy on the down low, at some point that leaves the digital space and enters meat space. It's at that point that powerful actors can get what they want from you.

Encryption might help you evade detection, but it is not a guarantee of privacy, even for a regular person.

Believe it or not, I expect we agree in the end. The existence of encryption is precisely why dragnetting doesn't work for catching actual bad guys. What brought down Silk Road was old fashioned police work. Get people on the inside, record some chats, get some warrants and so on. They seized him after he had decrypted his laptop, even. It's also precisely why I think political solutions are going to be the most effective in the end. The expectation of privacy we have established outside the digital space (say, no wiretapping, no illegal searches or arrests) still gives tools for protecting the public. Perhaps we need to somewhat tweak those tools for the digital world, but that doesn't mean we need to give the government the keys to our house.

Re: More encryption means less privacy

#133
post #80

It sure makes for a nice contrarian opinion, but fighting politically vs technically is a needless dichotomy. At least this post attempts to back up this assertion, but it seems a quite handwavey to assume that because eg a protocol contains key escrow, that governments aren't still going to want to preemptively read, archive, and datamine the cleartext. Yes, all governments. Because governments, even democratic ones…

> The problems are centered around naming. What's that expression? "All problems in computer science are ultimately about naming."

There are only two hard things in Computer Science: cache invalidation and naming things. -- Phil Karlton

Variant: There are only two hard things in Computer Science: cache invalidation, naming things and off-by-one errors.

Re: More encryption means less privacy

#134
Mr. Camp has written about this topic before, see

More Encryption Is Not the Solution (2013) https://queue.acm.org/detail.cfm?id=2508864

http://www.techrepublic.com/blog/it-security/escaping-the-dr...

"The recent exposure of the dragnet-style surveillance of Internet traffic has provoked a number of responses that are variations of the general formula, ‘More encryption is the solution.' This is not the case. In fact, more encryption will probably only make the privacy crisis worse than it already is."

https://lists.w3.org/Archives/Public/ietf-http-wg/2013JulSep... Re: Mandatory encryption is theater

" Correct, but if you make encrypt mandatory, they will have to break _all_ encryption, that's what the law tells them to.

As long as encryption only affects a minority of traffic and they can easier go around (ie: FaceBook, Google etc. delivering the goods) they don't need to render _all_ encryption transparent. "

Re: More encryption means less privacy

#135
post #117
post #8

Earlier quoted context omitted.

No its not. The reality is the biggest threat to privacy is due to political engagement. Stronger encryption that no one can break is really the only viable option.

You fail to grasp the key point here: If the state cannot break your encryption, they will break you instead.

Which makes your whole argument sound like:

"I'm such a coward! Please take my private data, just don't hurt me!"

Belive it or not, but some people actually have balls to fight evil governments.

Re: More encryption means less privacy

#136

Earlier quoted context omitted.

it's easy to design cryptosystems to be [...] unbreakably strong against mass eavesdropping by governments, yet still provide access on a case by case basis. Is it? How? Because that's certainly not the default that you referred to.

It's absolutely the default. Imagine you own a webmail company. You secure your SMTP relays with SMTP-TLS (let's pretend it works well) and your client connections with TLS again. Now your users are safe from random creepy flatmates, criminals with wifi sniffers, your telco and even mass government surveillance. But, governments can still serve a warrant on you to get email in a targeted manner, assuming they have a…

GP already replied to this exact claim:

But that's the point: we've seen that this balance doesn't exist, because if the service providers have access to the plaintext, the State will not contain itself to issuing case-by-case warrants - see Room 641A, "SSL added and removed here", etc.

The current move to encrypt everything is a reaction to the realization that the balance that was thought to exist, does not, and political participation is not sufficient because the information is kept hidden, so no informed political discourse is possible.

Re: More encryption means less privacy

#137
post #25

Earlier quoted context omitted.

I'm actually curious: can anyone cite a serious win for privacy that was wholly political? I frequently see pieces criticizing over-reliance on crypto as solutionism and political apathy, but I don't understand what they expect. The people fighting for strong cryptography have also led the political fight for privacy, but their nontechnical efforts have been ignored or circumvented at every turn. At this point it's h…

Well, there was a declassification of cryptography as munitions, which was very important. But that kind of proves the point, doesn't it?

"there was a declassification of cryptography as munitions"

That's the popular tale. It was partial. Lots of stuff, including high-assurance systems and custom, stayed under old classification. Such export uncertainty was a consideration in the cancellation of A1-class, VAX, Security Kernel. Here's excerpts and links from a write-up I did on it after I dug into the actual export laws:

http://pastebin.com/GHmHJASm

Still like some help from professionals to confirm or reject my analysis. People dealing with export on Schneier's blog gave feedback indicating they never ran into trouble. Yet, they might have been under the mass-market classification. So, I don't know if the other one is enforced or under what circumstances.

Re: More encryption means less privacy

#138

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

To "backwards nations" you can add the following, all of which have floated laws to weaken/backdoor/ban crypto:

France

UK

USA

Russia

Re: More encryption means less privacy

#139
post #91
post #30

Earlier quoted context omitted.

I think a very important point was raised though. Before crypto, basically all guarantees where conditional on a judge's say so. With crypto this changes. The issue also comes up, in a clearer way, with crypto currencies. There is no way to deal with fraud or mistaken tranfers in bitcoin. That loss of intervention hurts, and we gotta think about it. Even though no government has given a satisfactory solution, that do…

Until very recently 99.99% of conversations where completely private and society functioned just fine. Even with crypto everywhere the governments have far more access to what people say and do than they had for thousands of years. People with power pretend if they just had more power everything would be better. But, reality is if everything on a computer where private not much would change.

> Until very recently 99.99% of conversations where completely private and society functioned just fine.

In fairness, until very recently it was also extremely difficult for two people to privately plot to murder hundreds. Technology has changed the balances on a lot of scales.

To be clear, I'm not advocating for government back doors in encryption here. But I am saying we should not pretend that encryption just puts things back "the way they were". It most definitely does not.

Re: More encryption means less privacy

#140
post #117
post #8

Earlier quoted context omitted.

No its not. The reality is the biggest threat to privacy is due to political engagement. Stronger encryption that no one can break is really the only viable option.

You fail to grasp the key point here: If the state cannot break your encryption, they will break you instead.

In other words: https://www.xkcd.com/538/
Post reply on HN