Live data from Hacker News

Attorney General William P. Barr Delivers Address Conference on Cyber Security

justice.gov

171–180 of 230 posts

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#171
post #159
post #152

Earlier quoted context omitted.

Not including the word "warrant" is exactly why I thought your problem was with warrants specifically. From you original comment: >The fourth amendment to the U.S. Constitution guarantees that the right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and the ninth amendment to the Constitution guarantees that the people retai…

> the second option is basically the government's position The second option is the government's ostensible position. But you seem to have forgotten the central point of my argument which is that the government is not trustworthy. Just because the government says that it will only use its decryption keys when it has a warrant, history shows that the government cannot be trusted to keep its word on matters like this.…

Now we are just going in circles. This goes back to the first sentence of my response to you:

>The problem with this line of argument is that it is a general argument against government and not specific to this issue.

If your argument is that you can't trust the government, you can't trust the government regardless of whether they have a warrant or whether they are operating in the digital or physical world.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#173

Earlier quoted context omitted.

> This argument has merit, but if we DID amend out #2 and make guns illegal, over time firearm proliferation would decrease. Hmm, then wouldn't some people just make their own firearms, just as you are describing with encryption, right?

Some people would, yes. Especially rudimentary single shot weapons. However, its much harder to make a reliable gun than it is to make reliable tough encryption. There are designs available for both and there always will be, illegal or not. But making a gun is manufacturing whereas using encryption would just require installing some software. Trivial.

I want to point out, that manufacturing a gun is not "non-trivial".

Given blueprints, (publicly available) or a template and accurate enough measures, a lathe, and a mill, anyone can make a firearm or parts for one in their garage.

Is there reading involved? Yes. But any argument you make w.r.t. The futility of illegalizing encryption is immediately portable to firearms manufacture.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#174

Earlier quoted context omitted.

Can you explain how this actually solves the main problems? I can see this form of encryption catching unsophisticated "bad hombres". Unsophisticated here meaning, either ignorant of weaknesses in the technology they use, or aware, but unable to improve upon it. The most motivated adversaries will make use of other schemes. Worse, for secrets we actually care about (nuclear codes?) we must still research proper encry…

> Can you explain how this actually solves the main problems? a lot of weight rests on those two words: "main problems". The main problems for the government are that criminal investigations are being impeded. By banning certain forms of encryption, they can criminally charge a suspect for merely refusing to decrypt data. And you can bet that the penalties will be stackable, allowing the government to use its discret…

Ah yes, but then doesn't the problem boil down to proving that a random value is in fact an encrypted secret?

You arrest me, scan my file system and find something named "plan.txt" which is just a bunch of gibberish... what do you do?

EDIT: I'll argue that the "main problem" is that as long as real encryption schemes exist, this is impractical to enforce.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#175

Earlier quoted context omitted.

Then, in the US, you have obstruction of justice and/or interference with police/peace/public officer.

I think it's more of a protest, or am I not allowed to email myself numbers?

You are, up until the point where it's cost a law enforcement officer time to determine that either the numbers are intended to waste their time or that the numbers are a hidden/unbackdoored encryption. Then you're GG SOL

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#176

Earlier quoted context omitted.

Breaking encryption would cause breaches orders of magnitude more catastrophic than encrypted communications between bad guys.

See it this way: we have to know what the bad guys are saying in order to be able to protect the public. The way I see it the US government (and governments around the world) will make this a non-negotiable objective. There's not a lot of pressure now because, as Barr said, the event that will turn the public against encryption hasn't arrived yet. If the parties involved don't find a solution in the meantime they'd b…

> we have to know what the bad guys are saying in order to be able to protect the public

Why do you think that?

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#177
post #171
post #159

Earlier quoted context omitted.

> the second option is basically the government's position The second option is the government's ostensible position. But you seem to have forgotten the central point of my argument which is that the government is not trustworthy. Just because the government says that it will only use its decryption keys when it has a warrant, history shows that the government cannot be trusted to keep its word on matters like this.…

Now we are just going in circles. This goes back to the first sentence of my response to you: >The problem with this line of argument is that it is a general argument against government and not specific to this issue. If your argument is that you can't trust the government, you can't trust the government regardless of whether they have a warrant or whether they are operating in the digital or physical world.

> you can't trust the government regardless of whether they have a warrant

If they have a warrant, what exactly is it that you think I need to trust them about at that point?

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#178

Earlier quoted context omitted.

> Can you explain how this actually solves the main problems? a lot of weight rests on those two words: "main problems". The main problems for the government are that criminal investigations are being impeded. By banning certain forms of encryption, they can criminally charge a suspect for merely refusing to decrypt data. And you can bet that the penalties will be stackable, allowing the government to use its discret…

Ah yes, but then doesn't the problem boil down to proving that a random value is in fact an encrypted secret? You arrest me, scan my file system and find something named "plan.txt" which is just a bunch of gibberish... what do you do? EDIT: I'll argue that the "main problem" is that as long as real encryption schemes exist, this is impractical to enforce.

In theory, yes that's a big part of the problem. In practice, however, once the gov charges you, you're effectively guilty-until-proven-innocent because your court-appointed public defender is likely not going to be trained or equipped to provide a logical defense, much less hire an expert witness in computer forensics. Plus the gov will approach you with a plea "deal" : you can plead guilty to one charge of illegal encrypted data, pay $20k and 2 years' probation, or else risk going to the slammer for decades on the stacked charges with a maximum sentence of 3 years per file, times the 10 files they were "unable to decrypt" on your system.

> arrest me, scan my file system and find something named "plan.txt" which is just a bunch of gibberish... what do you do?

well, start by scanning every executable binary on your system. If they find a custom-rolled program that doesn't impregnate the encrypted files with known headers (for contrast, openssl ads the prefix "Salted_" to any file it encrypts) they can allege that you're using a clandestine encryption scheme and that "plan.txt" is one of the files. So again, the burden of proof would be on you to explain what that file was for, which can come at tremendous legal cost.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#179
post #162

Earlier quoted context omitted.

If the prosecution has such convincing evidence that the drives contain the images they say, then why do they need to compel the defendant to do anything at all? If it's such a foregone conclusion, why not just go ahead and try him on the child porn charge?

Dunno, I’m just an armchair lawyer who watches too many Leonard French videos. Like I said in my original comment, I haven’t read the case record in detail, nor am I familiar enough with the Federal Rules or Criminal Procedure to know if there’s some evidentiary requirement they cannot meet without the contents of the drive or whatever. I’m guessing it’s because they are operating off testimony of a witness (defendan…

I just don't buy that argument. If the evidence is mere hearsay, then how could it be good enough for compelling him to testify against himself?

It isn't hearsay in this case though. Hearsay is when Alice testifies that Bob told her he witnessed Charlie viewing child porn. Generally it should not be considered as fact that Bob witnessed this.

It's not hearsay if Alice testifies that she witnessed Charlie viewing child porn, which seems to be the case here. This kind of testimony is direct evidence.

Then there is the circumstantial evidence: The prosecution can show these encrypted drives exist, belong to the defendant, that he knows how to decrypt them and refused, etc.

I just don't see how it's reasonable to claim that isn't good enough for a jury to decide who to believe. They should just try him, or let him go.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#180

Earlier quoted context omitted.

> This argument has merit, but if we DID amend out #2 and make guns illegal, over time firearm proliferation would decrease. Hmm, then wouldn't some people just make their own firearms, just as you are describing with encryption, right?

Being physical objects, gun distribution is much much more difficult than encryption distribution.

Ok, I believe we are in the middle of arguing OP's point about how the pro-gun people are wrong when using the argument "only the criminals will own them", and how the pro-encryption people are right when using the same argument about encryption.

And, I think what you're adding here is that I've got an error in my statement that both parties will happily build their own firearms/encryption because the physical gun is harder to distribute than a copy of software.

And I agree in principle with this, until I realize that broad distribution of an encryption mechanism is exactly what a bad-acting government would want... crack once and everyone is compromised.

So, no, I think I would argue that its easier to distribute weapons than good, bespoke encryption.

And further, I would argue that if it is true for encryption, it is also true for firearms... that if they are outlawed, the power shifts to criminals as they will still use them.

Post reply on HN