Live data from Hacker News

Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

feinstein.senate.gov

151–160 of 275 posts

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#151

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

While it's convenient to paint this as "the government," many people, the ones who elect most officials, are also of the opinion that if authorized (by some manner) that encrypted data should be made available in plaintext. For the common people this comes in the form "I believe my dead relative's phone has information which will expose their killer, I want the carrier or manufacturer to make that data available, it's legally my phone, not Apple's or Samsung's, I want that data."

You may disagree with a perhaps naive perspective like that, but that interpretation does not make it any less real. There are plenty of common folk who would agree in the above scenario data in plain text should be made available upon lawful request by either carrier or mfg. That's not "the government" and to think so kind of misses the mark.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#152

I'm getting pretty deep into bets on Twitter AGAINST this bill having a chance of passing. My logic is simple: this bill outlaws all sorts of things huge corporations use to protect their networks. No big company I've ever done security work for has ever been OK with crypto keys being escrowed by vendors; in fact, we were often instructed to look for exactly those kinds of features as disqualifiers for products. I do…

I wouldn't count on that. They could go with a licensing system where you need to pay big bucks to use crypto without escrow. This scheme, of course would be beneficial for incumbents, because it raises the barrier for entry and pushes out the smaller players who can't afford such costs.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#153
Secure communication between terrorists is impossible to stop if they show any inclination to do so. This will only impact normal people using major online services.

Right off the top of my head a few ways terrorists would thwart this:

- Use end-to-end encryption that's easy to overlay on an existing medium (e.g. PGP).

- Create or use an app that doesn't comply with this law and use that for communication. At least on android all you need to do is allow 'Unknown sources' and you can install apps outside of the play store.

-Use something other than text. Go in an online game and spell something out on the wall.

By repeatedly trying to start this "conversation" it really seems the politicians don't want to accept that it's impossible to prevent encryption at the long tail of users (where the terrorists would be). Instead they're going to stick their heads in the sand. It could be a deliberate attempt to gather session keys for the intelligence services to do their bulk harvesting, but what it definitely won't do is stop terrorism.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#154

Earlier quoted context omitted.

I don't know about her voting record to know if that's true or not, but again, I'm talking about her reputation, which is partially shaped by fact but also shaped by public perception. And she's not really perceived as anti-tech.

Wow. Us geezers need to bring you whippersnappers up to speed about how this went 20 years ago, because it's your turn to fight this battle again. Fetch my geritol before you gear up, sonny.

I'm aware of the encryption wars of the 90s, but that's my point. It's been forgotten about.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#155
post #96

Earlier quoted context omitted.

When guns are outlawed, only lawmen and outlaws will have guns. Good. That's the state of affairs in every developed country except one and it's demonstrably better in every way.

except for all of these demonstrable ways: http://www.amazon.com/More-Guns-Less-Crime-Understanding/dp/...

(Dunno what's in the book)

I hear hand guns in particular are quite accident prone. Even if there's less crime, we might still have more deaths.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#156

Earlier quoted context omitted.

Slight digression, but does that mean owning assault weapons is a ok again in the US? Just curious.

Oh yeah, has been since Bush the second let the ban lapse.

> Oh yeah, has been since Bush the second let the ban lapse.

The ban expired because that's what was in the original law. There were efforts to pass a new ban, but they didn't even make it out of committee[0]. Perhaps a presidential endorsement could have helped it go farther, but one can't hold the president responsible for what happens in the Senate and House committees.

[0] https://en.wikipedia.org/wiki/Federal_Assault_Weapons_Ban

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#157

Earlier quoted context omitted.

> especially as it comes from the same people who think that government interfering with their firearms is the end of society. Senator Feinstein, who co-released this draft bill, is also the senator who introduced the assault weapons ban which was law from 1994 to 2004. https://en.wikipedia.org/wiki/Dianne_Feinstein#Political_pos... On the opposite side of things, Senator Paul opposes gun control but supports strong…

Slight digression, but does that mean owning assault weapons is a ok again in the US? Just curious.

What do you consider an assault weapon? Fully automatic guns have been and still are illegal without proper permits. The problem with the ban referred to in the GP, is that it was mostly a superficial feel good law. Take a normal hunting rifle, add some cosmetic changes and suddenly it is an assault weapon under the old ban. Add that most gun crimes are committed with hand guns, and the ban amounted to nothing more than a news soundbite.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#158

Government is trying to make it illegal for one person to keep secrets and whisper them into another's ear. We can argue all day about how the law doesn't prevent criminals from using technologies (it doesn't, which makes the law idiotic, from a logic perspective), but that's not the important part. The important part is that this group of folks we're calling Government is trying to prevent us from being allowed to h…

> These laws are not for "terrorists". They're for us.

Yes. This is a great way of saying this.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#159
Yikes, "license distributors" are covered entities:

"c) LICENSE DISTRIBUTORS. - A provider of remote computing service or electronic communication service to the public that distributes licenses for products, services, applications, or software of or by a covered entity shall ensure that any such products, services, applications, or software distributed by such person be capable of complying with subsection (a)."

I suspect it would practically impossible for FOSS projects to comply, and everyone who creates or distributes free and open source software that is capable of encrypting anything would fall under this definition. Also I don't see any provision for existing software... if this bill passes, are we just supposed to stop distributing software on Day 1 until it can be rewritten to make it possible to comply?

This bill is astonishingly stupid, even when compared to the unusually high level of stupidity of federal legislators.

Re: Intelligence Committee Leaders Release Discussion Draft of Encryption Bill

#160

What this does and doesn't do: This bill effectively makes it illegal for US companies and persons to build or use secure enclaves / TPMs and to publish cryptosystems without either including backdoors or retaining and storing keys. It also implies that companies would need to store keys indefinitely, otherwise they would not be able to decrypt data, as no time limitations are set on the capability of accessing data.…

Respectfully, I disagree WRT SSH/TLS

Section 2 (4) spells it out: communication service and software providers. That's the maker of every app on your phone, the phone manufacturer, your phone company, emails provider, retailer (they're communicating your data to their data warehouses).

The summary clearly says "software manufacturers" (aside: manufacture software? facepalm), "providers of wire...electronic...[or] remote communications services, or any person that provides a product or method to facilitate a communication or to process or store data" are all "covered entities" and that they're responsible when they or "another party on their behalf" have made data unintelligible.

The bill, in section 3 (c) includes "license distributors", e.g. thr App Store and Google Play.

Now that I've typed all that out, and please pardon the profanity, but:

What. The. Actual. Fuck.

"No one is above the law", except clearly the legislators and enforcers themselves. "Protect ... Privacy with strong data security", which doesn't exist with the sort of recovery mechanism the bill would require.

If the data is made intelligible again by a party other than the person who uttered it and their intended recipient, it has, by definition, been breached. You've been pwned. Game over. Full stop. You've lost control of your data.

(Edit: clarity)

Post reply on HN