Live data from Hacker News

Attorney General William P. Barr Delivers Address Conference on Cyber Security

justice.gov

161–170 of 230 posts

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#161

In general, I agree with the government stance that "warrant proof" communication is not in the best interests of US citizens. I believe that there is some precedent and established law that can be built upon to provide a compromise that allows for encryption to remain a strong privacy tool for society but one that does not hinder the state from lawful access. I believe that the US should establish a court similar to…

Warrant proof communication is absolutely in the best interests of the citizens for exactly the same reason it's not in the best interest of the ruling government.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#162

Earlier quoted context omitted.

https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...

It’s important to point out in this case the stated reason for the contempt charge is the “foregone conclusion” that there IS child porn on those encrypted drives, not the mere existence of encrypted drives with what could contain anything. Police can’t compel you to provide a combination to a lock (encryption key) to go on a fishing expedition, but if they KNOW the safe contains illegal contents then you can be held…

If the prosecution has such convincing evidence that the drives contain the images they say, then why do they need to compel the defendant to do anything at all? If it's such a foregone conclusion, why not just go ahead and try him on the child porn charge?

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#163
post #84
post #55

Earlier quoted context omitted.

Fine. Here's my contribution to the conversation: Mr Barr, your entreaties in this regard are based on the presumption that the government can be trusted. But our nation was founded on a mistrust of government, and your own actions demonstrate that the government cannot be trusted. Your own special counsel has issued a report that implicates the president in a felony (obstruction of justice) but you have failed to fo…

The problem with this line of argument is that it is a general argument against government and not specific to this issue. You could use the exact same argument for why you shot a police officer who broke down your door after securing a warrant. It would quickly be dismissed in that instance so it should carry little weight in the discussion of encryption. If you want the government to completely give up this line of…

Sort of a side note, if police kick down the wrong door (this happened not long ago) they're not justified in pursuing murder charges in that case. If they served the right warrant at the right address than yes, that is justified.

This entire write up stinks and I don't trust the government to implement this overreach in any sort of way which benefits the average American citizen. :(

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#164
The cost-benefit analysis is interesting:

> If one already has an effective level of security — say, by way of illustration, one that protects against 99 percent of foreseeable threats — is it reasonable to incur massive further costs to move slightly closer to optimality and attain a 99.5 percent level of protection even where the risk addressed is extremely remote?

> if the choice is between a world where we can achieve a 99 percent assurance against cyber threats to consumers, while still providing law enforcement 80 percent of the access it might seek; or a world, where we have boosted our cybersecurity to 99.5 percent but at a cost reducing law enforcements access to zero percent — the choice for society is clear.

One issue with all proposals around this, is risk = probability X impact. While the above speaks to the risk, the impact of malicious actors having their hands on masterkeys would be insta-access to any & all gov-mandated communication channels, to the exact same access level as warrants would afford.

While the attorney is right, that so far most corp master certificates have not been compromised, none of those had this pricetag attached to it. And the impact of this would be retroactively applicable -ie for any present-day communication, we'll be taking on faith that no future masterkeys will be leaked, ever.

I would not take that bet; and so far, neither did insurance companies.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#165
post #22
post #17

Earlier quoted context omitted.

isnt that a bad example though, because the counter-terrorism policy was already prewritten before the event. it wasnt a hasty reaction.

That's how you're supposed to do things, though. You want to write the policies before the event, when you can think things through slowly and carefully. There's nothing wrong with this part of what he has to say...only the other parts.

im saying 9/11 is an example of writing the policy ahead of time, and waiting for when you need it NOT throwing a proposal together after a stimulus.

9/11 is an example of what hes proposing, not a counter example.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#166

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

For centuries, the law has recognized information as property. Encryption is just a transform of information. The government can argue that they're simply banning certain types of property - something they've done for at least 100 years, maybe longer.

Can you explain how this actually solves the main problems? I can see this form of encryption catching unsophisticated "bad hombres". Unsophisticated here meaning, either ignorant of weaknesses in the technology they use, or aware, but unable to improve upon it. The most motivated adversaries will make use of other schemes.

Worse, for secrets we actually care about (nuclear codes?) we must still research proper encryption schemes since backdoors are admissions of weakness in a security protocol fundamentally as far as I've come to understand.

> We are confident that there are technical solutions that will allow lawful access to encrypted data and communications by law enforcement without materially weakening the security provided by encryption. Such encryption regimes already exist. For example, providers design their products to allow access for software updates using centrally managed security keys. We know of no instance where encryption has been defeated by compromise of those provider-maintained keys. Providers have been able to protect them.

This quote from the article seems to contradict itself. First it claims "... without materially weakening the security provided by encryption" then goes on to state "We know of no instance where encryption has been defeated by compromise of those provider-maintained keys" implying that there is a possibility of this kind of breach.

This whole thing seems like an oligarch's attempt to spy on it's people pretty plainly to me. Where is the liberty and freedom in this?

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#167
post #162

Earlier quoted context omitted.

It’s important to point out in this case the stated reason for the contempt charge is the “foregone conclusion” that there IS child porn on those encrypted drives, not the mere existence of encrypted drives with what could contain anything. Police can’t compel you to provide a combination to a lock (encryption key) to go on a fishing expedition, but if they KNOW the safe contains illegal contents then you can be held…

If the prosecution has such convincing evidence that the drives contain the images they say, then why do they need to compel the defendant to do anything at all? If it's such a foregone conclusion, why not just go ahead and try him on the child porn charge?

Dunno, I’m just an armchair lawyer who watches too many Leonard French videos. Like I said in my original comment, I haven’t read the case record in detail, nor am I familiar enough with the Federal Rules or Criminal Procedure to know if there’s some evidentiary requirement they cannot meet without the contents of the drive or whatever.

I’m guessing it’s because they are operating off testimony of a witness (defendants sister) claiming she was shown the alleged images, and since they weren’t on the unencrypted internal drive they MUST be on the encrypted external drives. That combined with the knowledge that these files were in fact purportedly known to be downloaded via his internet connection is enough for something, but all they have without the drives is hearsay, hence the compulsion to decrypt then?

Personally I think in this instance with recent rulings that an individual cannot be identified by an IP address and a single witness that there isn’t enough to KNOW anything, otherwise I could wardrive around, download a bunch of CP on somebodies connection and say I saw them looking at it through a window or something.

All I know is that we do have precedent for this in the physical world, so it’s not a logical leap to require disclosure of cryptographic keys when we KNOW what they unlock.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#168

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

> We are confident that there are technical solutions that will allow lawful access to encrypted data and communications by law enforcement without materially weakening the security provided by encryption.

False.

Also "technical solutions" makes it sound like the issue is in inventing the correct encryption scheme. Whereas in reality the issue exists because we have discovered (currently) unbreakable codes, and the invention of broken (backdoored) schemes does little to change that.

If we break all known forms of encryption, and find a reasonable proof that they are no longer possible, then I'll be more interested in this line of reasoning. And that's a pretty big if.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#169

Earlier quoted context omitted.

> This argument has merit, but if we DID amend out #2 and make guns illegal, over time firearm proliferation would decrease. Hmm, then wouldn't some people just make their own firearms, just as you are describing with encryption, right?

Some people would, yes. Especially rudimentary single shot weapons. However, its much harder to make a reliable gun than it is to make reliable tough encryption. There are designs available for both and there always will be, illegal or not. But making a gun is manufacturing whereas using encryption would just require installing some software. Trivial.

Given that I have many, many crypto libraries in many many devices, some of which are heavily modified, chances of me even being able to replace those with broken crypto libraries is like... 0. Many people are in a similar situation, so I don't understand how we could even comply with a law like that if we wanted to (which we don't). So yeah, not only trivial to retain unbroken crypto, but nearly impossible to get rid of it.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#170

Earlier quoted context omitted.

For centuries, the law has recognized information as property. Encryption is just a transform of information. The government can argue that they're simply banning certain types of property - something they've done for at least 100 years, maybe longer.

Can you explain how this actually solves the main problems? I can see this form of encryption catching unsophisticated "bad hombres". Unsophisticated here meaning, either ignorant of weaknesses in the technology they use, or aware, but unable to improve upon it. The most motivated adversaries will make use of other schemes. Worse, for secrets we actually care about (nuclear codes?) we must still research proper encry…

> Can you explain how this actually solves the main problems?

a lot of weight rests on those two words: "main problems". The main problems for the government are that criminal investigations are being impeded. By banning certain forms of encryption, they can criminally charge a suspect for merely refusing to decrypt data. And you can bet that the penalties will be stackable, allowing the government to use its discretion and perhaps charging someone with separate counts for each file he refuses (or is unable ...) to decrypt. I'm NAL, but I've also heard of the "forgone conclusion" doctrine, which somehow allows the constitution to fly out the window and allows the gov to imprison someone indefinitely until they decrypt the files. So, sadly, this ban does solve the main problems at considerable expense to citizens' liberties.

Conjecturing further:

- citizens would be allowed to encrypt, but they'd be required to keep a set of the keys used or else they could risk prosecution.

- There could be a government cloud server where you "securely" upload whatever keys you use (or, realistically, probably outsourced to companies like equifax which would then charge you a fee to do so),

- existing cloud providers would be required to detect when clients were using encryption-looking libraries/subroutines and store a copy of the keys into some registry.

- this could ultimately lead to "whitelist-only" software libraries, so that you cannot run anything on the cloud without building it with their dev environment so they can be sure you're not secretly encrypting things.

- going even further, this could lead to deep packet inspection that simply detects encrypted transactions and queries them against the gov key registry to "make sure" they are properly decryptable. Any failures to decrypt could trigger an investigation.

Post reply on HN