Earlier quoted context omitted.
If an OEM could decrypt a users data, a government typically won’t bother to do it themselves. They’ll just use legal mechanisms to require the OEM to do the work for them.
Again, as a thought experiment, what legal protections can we put in place - an encryption ombudsman or independent authority - that would allow an arms length, controlled and expiring mechanism that allows limited access to a user's data? What would we as a society be happy to accept? I don't think the demand is an unreasonable one, but I'm trying to figure out what a reasonable collection of mechanisms looks like.
Encryption Is Not a Crime
141–150 of 222 posts
Re: Encryption Is Not a Crime
#142Earlier quoted context omitted.
> Transitioning gender is also free speech, freedom of expression. Is a legal requirement for others to affirm this expression also "free speech?"
Has there been a single instance where someone faced legal repercussions for not affirming someone's gender?
"Lose custody of your child" is very much a "legal repercussion."
Re: Encryption Is Not a Crime
#143Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…
This requires the device manufacturer to have the capability to decrypt the data (to be able to do so when all this process is properly observed) If they have the capability to decrypt the data, a court can compel them to do so, disregarding the process you suggest. A cyberattack could achieve it without a court order. This can't be solved technically.
I suspect that there are many ways that can be achieved, all technical ;-)
Re: Encryption Is Not a Crime
#144Earlier quoted context omitted.
> You should engage with the arguments the other side makes. The arguments are "Protect the children.", "Catch terrorists.", "Catch criminals.". Those arguments have been engaged with for decades. They are purely emotional arguments. Anyone who still pushes those arguments forth is most likely doing so with ulterior motives and cannot be reasonably "engaged" with.
Let's not ignore the full history here. That is a bad faith argument. It was a crime to use expensive encryption 30 years ago, but a lot of decisions were made to allow it. Today, every single one of those old caveats about child porn, drugs, money laundering, terrorism, (both domestic and international) and criminal acts in general all have stories where weaker encryption would have saved hundreds and hundreds of li…
Can you do the same thing, but in the other direction? How many people would have been harmed if weaker/no encryption was the standard?
Re: Encryption Is Not a Crime
#145I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult". It puts the idea into the world that it could be a crime and maybe that it is the status quo. Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on. Maybe "Don’t let them take your right to privacy."
I wish Americans still believed in American freedoms Encryption is free association and free speech. Talking to someone about what I like without eavesdroppers Transitioning gender is also free speech, freedom of expression. Presenting how I like and not how some wannabe king wants me to
I wish people understood the American system at a philosophical level. What you call "American freedoms" are largely based off of negative rights, i.e. John Locke. Our bill of rights use specific language like "Congress shall make no law", "shall not be infringed", "shall not be violated". It's inherently freedom from state action.
Over the past 100 years a different interpretation of rights has emerged, so called positive rights as exemplified in FDRs second bill of rights; e.g. "the right to a good education" or "the right to earn enough to provide adequate food and clothing and recreation". This requires state action to facilitate freedoms for its citizens.
Unfortunately these systems are incompatible. I think a lot of the friction we are seeing in modern times can partially be traced to this contradiction.
Re: Encryption Is Not a Crime
#146Earlier quoted context omitted.
My favorite version of it is "Let's ban air because terrorists breathe".
I've usually seen it phrased as "let's ban wheels|cars so bank robbers can't escape!". But well, even that rebuttal is getting tiresome. It's the same people that keep pushing for banning air again and again. They control all the communication channels, so nobody can ever rebut them in a forum that matters, they control the governments, and they are still not popular enough to make that thing pass. Yet, they keep pus…
Re: Encryption Is Not a Crime
#147> It's not a crime to lock your home's door for protection, why would it be a crime to lock your digital door? A locked home's door is still trivially opened. You can pick the lock or even apply simple brute force, neither of which all that difficult, and open happily it will. Similarly, I don't suppose anyone would be concerned about you using rot13 encryption. If a home could be sealed to the same degree as strong…
That analogy breaks because a home's locked door as the constaint that it can effectively only be visited by someone coming to that door physically. On the internet, multiple crimimals can attack all doors at all times https://www.youtube.com/watch?v=VPBH1eW28mo
Re: Encryption Is Not a Crime
#148Something is a crime if society determines that it should be so. Nothing more. Clearly the pressure on government to write these laws is coming from somewhere. You should engage with the arguments the other side makes.
> You should engage with the arguments the other side makes. The arguments are "Protect the children.", "Catch terrorists.", "Catch criminals.". Those arguments have been engaged with for decades. They are purely emotional arguments. Anyone who still pushes those arguments forth is most likely doing so with ulterior motives and cannot be reasonably "engaged" with.
> The arguments are "Protect the children.", "Catch terrorists.", "Catch criminals.".
> Those arguments have been engaged with for decades. They are purely emotional arguments. Anyone who still pushes those arguments forth is most likely doing so with ulterior motives and cannot be reasonably "engaged" with.
Oh come on. Why do you think a "purely emotional arguments" are illegitimate? Are you some galaxy brain, coldly observing humanity from some ivory tower constructed of pure software?
Nearly all positions people take are, at their core, "emotional." And the disagreements that result in "arguments" are often really about differing values and priorities. You might value your "freedom" more than anything and are willing to tolerate a lot of bad stuff to preserve strong encryption, some other guy might be so bothered by child sexual abuse that he wants to give it no encrypted corner to hide in. You're both being emotional.
Re: Encryption Is Not a Crime
#149Earlier quoted context omitted.
Let's not ignore the full history here. That is a bad faith argument. It was a crime to use expensive encryption 30 years ago, but a lot of decisions were made to allow it. Today, every single one of those old caveats about child porn, drugs, money laundering, terrorism, (both domestic and international) and criminal acts in general all have stories where weaker encryption would have saved hundreds and hundreds of li…
> where weaker encryption would have saved hundreds and hundreds of lives. Can you do the same thing, but in the other direction? How many people would have been harmed if weaker/no encryption was the standard?
Re: Encryption Is Not a Crime
#150Earlier quoted context omitted.
> where weaker encryption would have saved hundreds and hundreds of lives. Can you do the same thing, but in the other direction? How many people would have been harmed if weaker/no encryption was the standard?
Let's go with the USPS. They have been sending daily communications where unencrypted info is the standard since 1775.
How many whistleblowers would have been killed without a secure way to blow the whistle? How many journalists and journalist sources would have been killed? Etc. These people aren't using the USPS for good reason.
Point being, you are only doing one side of your calculation and presenting it as a full argument. But it's just a bad argument unless you calculate both sides.