Live data from Hacker News

Encryption Is Not a Crime

privacyguides.org

151–160 of 222 posts

Re: Encryption Is Not a Crime

#151

Earlier quoted context omitted.

I wish Americans still believed in American freedoms Encryption is free association and free speech. Talking to someone about what I like without eavesdroppers Transitioning gender is also free speech, freedom of expression. Presenting how I like and not how some wannabe king wants me to

I'm not sure the US population ever really believed in fundamental freedoms. They had an apartheid up to 60 years ago. There are living people from that time, and you can't believe in any human right and have an apartheid at the same time.

People believe in logical inconsistencies all of the time, it’s practically the default. Also there is no such thing as perfect freedom, it’s best thought of as an optimization problem with many dimensions.

As an example, the civil rights act necessarily curtails the freedom of association.

Re: Encryption Is Not a Crime

#152
post #117

Earlier quoted context omitted.

>Put more simply: the modern internet doesn’t work without encryption, it is a fundamental part of the technology. Without it, anyone could log into any of your accounts, take your money, messages, photos, anything. I'm pretty pro encryption, but even this is pretty dishonest. Phones (ie. PSTN, not iPhones) aren't "encrypted" by any means, but there's plenty of sensitive information sent over it. Lawyers fax each oth…

I’m not saying every layer of the onion is individually encrypted. But there are plenty of layers that are. There is plenty of encryption used when you send any sort of message from an iPhone, even SMS. You can’t even turn the dang thing on and unlock it without encryption. Then when you send it, it’ll be encrypted by the radio before transmission. Then in transit it may or may not be encrypted at various points. And…

>There is plenty of encryption used when you send any sort of message from an iPhone, even SMS. You can’t even turn the dang thing on and unlock it without encryption. Then when you send it, it’ll be encrypted by the radio before transmission. Then in transit it may or may not be encrypted at various points.

If your argument for encryption is "we need encryption because if it's banned overnight all our phones will turn into bricks!", then yeah sure I guess it's true. But even the diehard encryption opponents aren't arguing for this. My point is that you can very much have no encryption, but not "anyone could log into any of your accounts, take your money ...".

Re: Encryption Is Not a Crime

#153
post #37
post #25

Earlier quoted context omitted.

You can make gun fairly easily with what can be accomplished with a CNC machine. It is still illegal.

Where that is illegal they don't go making CNC machines illegal because of that.

Legislators are literally trying to restrict sales of machines that can be used to build firearms. I don't agree with this, but it's happening.

https://www.nysenate.gov/legislation/bills/2025/A2228

Re: Encryption Is Not a Crime

#154
post #117

Earlier quoted context omitted.

>Put more simply: the modern internet doesn’t work without encryption, it is a fundamental part of the technology. Without it, anyone could log into any of your accounts, take your money, messages, photos, anything. I'm pretty pro encryption, but even this is pretty dishonest. Phones (ie. PSTN, not iPhones) aren't "encrypted" by any means, but there's plenty of sensitive information sent over it. Lawyers fax each oth…

1. How often are people saying their bank login on their phone calls? 2. Is there a way for phone call man in the middlers to get that info without wasting a ton of time listening to calls? With internet MITM it is very easy to set up a program that scrapes unencrypted login info.

>1. How often are people saying their bank login on their phone calls?

Have you ever called into a bank or brokerage? Most ask "security questions", often ones that you can't even choose, like your address or how many accounts you have with them. It's arguably far worse than speaking your password into the phone.

>2. Is there a way for phone call man in the middlers to get that info without wasting a ton of time listening to calls?

Automated speech recognition has been around for decades. Even before that signals intelligence agencies have shown that widespread wiretapping/eavesdropping is possible and effective.

Re: Encryption Is Not a Crime

#155
As a software engineer who specialized in cryptography in the 1990s and didn't work for the NSA (working for RSADSI, Bell Canada and Certicom) I feel I have an informed vantage point from which to offer notes.

a) This seems like a decent introduction to the subject of cryptographic regulation in the last 30 years. It's far from exhaustive, however. I do appreciate the collected references from diverse points in the last several decades.

b) I would have mentioned "Sink Clipper" and the ACLU "dotRights" campaigns. Neither are especially easy to find in the increasingly enshittified google cache, but Le Monde Diplomatique has this article, complete with a link to Sink Clipper poster (I think from the mind of Kurt Stammberger) that no collection of CypherPunk oriented ephemera from the era can be without: https://mondediplo.com/openpage/selling-your-secrets

The ACLU dotRights.org site seems to have receded into history, but some of it's content is still available at the archive. For example: https://web.archive.org/web/20100126102126/http://dotrights....

c) Herb Lin presented a very nice paper back in the day comparing PROPOSED encryption regulation with ACTUAL encryption regulation. I think the thesis was through the 90s, proposed regulation was increasingly draconian (clipper, etc.) but actual regulation was liberalizing (effective deregulation of open-source tools.) I found Herb's page at Stanford and heartily recommend it if for no other reason than it's sheer volume of written material: https://herblin.stanford.edu/recent-publications/recent-publ...

d) I was a little surprised the wired article linked to at the beginning of the piece didn't have that issue's front cover, which was sort of a cultural touchstone at the time. But you can see it here: https://pluralistic.net/2022/03/27/the-best-defense-against-... - and this one: https://www.reddit.com/r/Bitcoin/comments/1cgpktp/31_years_a... (dang, look at those non-receding hairlines!)

e) Making the web "secure" or "private" is like putting lipstick on a pig. Modern web technology is designed to de-anonymize and collect identifying information to enable targeted ad delivery. Thought I generally respect Moxie Marlinspike and have no great beef with Signal, there has been a concerted effort to exploit its device sharing protocol and your carrier and national governments can easily extract traffic analysis info from people using it. Were I to add one sentence to this guide, it would be "While these tools are better than nothing, they are far from perfect."

f) The guide seems to conflate encryption with privacy. Encryption technology can enable privacy, but you're not going to get privacy from encryption technology unless you pair it with well reasoned policy (for organizations) and operational guidelines (for both organizations and individuals.)

The extreme example is to say "nothing stops a participant in an encrypted communication from sharing the un-encrypted plaintext after it's recovered." People earnestly trying to maintain message security probably know not to do that, but when talking about exchanging keys and figuring out which keys or organizations you should trust, it's easy for even the well-informed to make privacy-eroding decisions.

So... I think this article is a good jumping off point, covering material I would call "required, but not sufficient." I would just view it as the beginning of a deep-dive instead of the end.

Re: Encryption Is Not a Crime

#156
post #35

Earlier quoted context omitted.

Under what law? High security vaults are not legally controlled or prohibited in the US.

Which high security vault can the government not gain access to under any circumstances? I expect you'll find decent explosives or a bulldozer will get them in just fine.

The issue isn't "gain access to" - it's "gain access to without destroying the contents."

Explosives and bulldozers are likely to harm whatever was motivating the entry in the first place. The vault system can be engineered to ensure this conclusion, as well.

Re: Encryption Is Not a Crime

#157
post #35

Earlier quoted context omitted.

Which high security vault can the government not gain access to under any circumstances? I expect you'll find decent explosives or a bulldozer will get them in just fine.

So will a hardware backdoor planted by your maid, or a telescopic lens pointed at your screen, or laser microphone on your window, get them into your e2e encrypted chats.

[deleted]

Re: Encryption Is Not a Crime

#158

The problem is the average person doesn't care very much or understand it. If you ask anyone if privacy matters they will of course say yes. If you ask them why they use software with telemetry or websites with Google Analytics they will simply shrug. If you ask them if it's alright for the NSA to collect and analyze data from everyone they will say yes and they have nothing to hide. People don't know what privacy is…

"Secrecy of correspondence" is a longstanding legal principle in many countries (e.g. in Germany since the unification in 1871, in the US there was a supreme court ruling in 1877)

The only way to guarantee secrecy is through encryption, preferably e2e.

Re: Encryption Is Not a Crime

#159

Earlier quoted context omitted.

Users can ignore the expiration date on a TLS cert. Cryptography doesn't enforce time constraints, business logic does. somewhere a piece of code would have to say "here I've got this key, which can decrypt this text, but I'm not going to" and that decision is not protected by math.

I'm not sure I follow. Obviously the application itself needs to support the business logic described, in the same way as your web browser needs to notice that a certificate has expired and tell you there's a problem with a website you're visiting. What I'm exploring is why requiring certain applications to support the same sort of thing to decrypt user data in certain circumstances to support law enforcement is a pr…

The problem is that nefarious actors aren't physically barred from the data. If China, Big Balls, Zuckerberg, or anyone else want to access that data then they can just remove that check.

More importantly, the thing you're asking for (law enforcement retroactively snooping without there existing a master key) is always impossible.

For other forms of snooping (like a warrant to tap communications for a single device for a period of time), you have related issues. Suppose you magically make such a thing flawless -- the client can't detect intrusion, a single key is actually time-bound, etc. There still exists a group of people with the power to hand out such keys, and that power, however it's implemented, is still a master key to all future communications over that protocol.

You can partially mitigate the risk in various ways, but you can't eliminate it. Every proposal for weakening cryptography in that way has had glaring flaws, and many known attempts at actually weakening it have later been cracked by nefarious actors. Spying, but only for the "good guys," should be met with extreme skepticism as far as cryptographic protocols are concerned.

For all of these schemes, what happens when the people holding keys and power are physically forced out (DOGE et al)? Even if we assume the thing is implemented flawlessly, the people involved never leak anything, the master keys stay secret, ..., you still have the human problem of transitions in power. Do you want the current US administration, one currently arguing that it can "deport" actual citizens to torture prisons with no recourse or court case, to know that six years ago your daughter confided to her best friend that she got an abortion once? That she doesn't believe Israel should be committing genocide? Or, suppose you approve of the current administration, what about the next one that takes the reins with this new set of powers? It's bad enough without decades of chat history to let 70%-accurate AI comb through and make deportation decisions.

Re: Encryption Is Not a Crime

#160
post #35

Earlier quoted context omitted.

Which high security vault can the government not gain access to under any circumstances? I expect you'll find decent explosives or a bulldozer will get them in just fine.

So will a hardware backdoor planted by your maid, or a telescopic lens pointed at your screen, or laser microphone on your window, get them into your e2e encrypted chats.

Huh? The encrypted data is at rest and the only person who knew the key is dead. Your plan makes no sense.
Post reply on HN