Live data from Hacker News

Encryption Is Not a Crime

privacyguides.org

171–180 of 222 posts

Re: Encryption Is Not a Crime

#171

Earlier quoted context omitted.

I'm not sure how this is answers my question at all. How many whistleblowers would have been killed without a secure way to blow the whistle? How many journalists and journalist sources would have been killed? Etc. These people aren't using the USPS for good reason. Point being, you are only doing one side of your calculation and presenting it as a full argument. But it's just a bad argument unless you calculate both…

That's a different question. You asked how many people would have been harmed if weaker/no encryption was the standard. The USPS is a message system where federal employees are able to intercept suspicious content, and there is no built-in encryption for mail. Voting by mail is a great example of how a critical message can be sent without relying on encryption. Whistleblowers can still encrypt documents on a flash dr…

I don't really want to hash this same thing out for the... At least hundredth time. You're not going to convince me, I'm not going to convince you, and we'll both just leave less happy if we keep going.

>Whistleblowers can still encrypt documents on a flash drive, and drop it into a mailbox. There is nothing stopping them from doing so.

The only thing I want to highlight for your consideration is that the USA is not the entire world. The USPS, even if it were perfect, does not exist in the overwhelming majority of the world. People talk to people across borders.

(Also, with some of the proposed laws, encrypting the USB would be illegal)

Re: Encryption Is Not a Crime

#172
post #160

Earlier quoted context omitted.

So will a hardware backdoor planted by your maid, or a telescopic lens pointed at your screen, or laser microphone on your window, get them into your e2e encrypted chats.

Huh? The encrypted data is at rest and the only person who knew the key is dead. Your plan makes no sense.

Is encrypted data at rest belonging to dead people such a problem, that it's worth sacrificing everyone's privacy?

Re: Encryption Is Not a Crime

#173
post #160

Earlier quoted context omitted.

Huh? The encrypted data is at rest and the only person who knew the key is dead. Your plan makes no sense.

Is encrypted data at rest belonging to dead people such a problem, that it's worth sacrificing everyone's privacy?

> that it's worth sacrificing everyone's privacy?

Is the appeal to emotion really necessary? Surely we can discuss the facts without devolving into some kind of "But I want that!!!" toddler behaviour?

Re: Encryption Is Not a Crime

#174
post #142

Earlier quoted context omitted.

Legislation is currently in the works (and likely to pass): https://leg.colorado.gov/bills/hb25-1312 "Lose custody of your child" is very much a "legal repercussion."

You are suggesting that family courts in Colorado should be barred from hearing info from psychologists about the impact of dead-naming?

> You are suggesting that family courts in Colorado should be barred from hearing info from psychologists about the impact of dead-naming?

Classic strawman argument. Where was anything like this suggested? Are they barred today under existing legislation?

The eventuality of this line of reasoning is that: "special interests who control the DSM (or whatever standards body governs these soft sciences) can influence and determine the outcome of custody battles."

DSM-4 defined "gender-identity disorder" as a thing, that's now been de-pathologized to "gender dysphoria."

Under your framework, a body of unelected, politically and financially-motivated "experts" can now determine the imposition of legal consequences on a whim.

Re: Encryption Is Not a Crime

#175
post #66

Earlier quoted context omitted.

I don’t think this particular devil needs more advocacy. Law enforcement agencies currently have more data about each of us and more sophisticated tools to investigate crimes than at any time in human history. > Politicians are (mistakenly) asking for a master key - but what I feel we should as a community support is some fine-grained legal process that would allow limited access to user information if justified by a…

Well that's your view - but these demands aren't going to go away, and what I think is sensible is for us a technical community to consider reasonable alternatives. Every society is a compromise between anarchic freedom and authoritarian tyranny, and this is another discussion about how a (relatively) new set of technologies can fit into that compromise in a way that is acceptable and reasonable. I acknowledge the pr…

> but these demands aren't going to go away

To me, this just means that we must remain vigilant. The slow creep towards authoritarianism isn’t going to go away either. The solution is not to look for reasonable ways for authoritarian rules to exist. Continuous harmful pressure must be met with continuous resistance.

> Every society is a compromise between anarchic freedom and authoritarian tyranny

Except not every society is such a compromise. Some are fully under authoritarian control, and serve as a warning for others who are tempted by authoritarian ideas.

> this is another discussion about how a (relatively) new set of technologies can fit into that compromise in a way that is acceptable and reasonable.

Breaking encryption need not inherently be part of that compromise. And until someone can explain how breaking encryption will actually stop the kind of bad actors used to justify such a direction (vs. driving them deeper underground, i.e. even if you outlaw encryption, it’s not as if law breakers will obey such a law), I see no merit in entertaining such a compromise. The crimes being committed are already illegal.

> It's frankly a bit of an article of faith in our community that encryption == unalloyed good

I don’t think most people in our community see it as inherently/perfectly good, but as extremely important and necessary. This is a critical distinction. As with everything, there are harms that come with the good, and such is the nature of all things. The question becomes: are the harms allowed worse than the good that is preserved? And would the new harms of disallowing the status quo be potentially worse than the harms supposedly prevented?

> I think we'd be right to think more critically about that position.

I agree that we need to think critically about this. But clearly we disagree about what one should conclude from such a critical analysis. I’d argue that taking the position that the government needs more power - especially at this moment in history - is the result of not thinking critically enough.

Re: Encryption Is Not a Crime

#176

Earlier quoted context omitted.

>Put more simply: the modern internet doesn’t work without encryption being pandantic that should read - the modern usage of the internet.. the internet does work ok without encryption, has it has done from a long time ago

That’s exactly the pedantry that muddies the water and confuses people on this issue. Colloquially, it is a distinction without a difference. The internet as normal people know it does not work without encryption.

I do agree, it depends on the context, eg talking to my family vs this forum

This site is not full of "normal people" and it shouldn't confuse people/ muddy the water if being dicussed here

Re: Encryption Is Not a Crime

#177
post #173

Earlier quoted context omitted.

Is encrypted data at rest belonging to dead people such a problem, that it's worth sacrificing everyone's privacy?

> that it's worth sacrificing everyone's privacy? Is the appeal to emotion really necessary? Surely we can discuss the facts without devolving into some kind of "But I want that!!!" toddler behaviour?

There was no emotion, only an accurate description of the consequences of the proposed policy.

Re: Encryption Is Not a Crime

#178
post #135
post #120

Earlier quoted context omitted.

> Transitioning gender is also free speech, freedom of expression. Is a legal requirement for others to affirm this expression also "free speech?"

Has there been a single instance where someone faced legal repercussions for not affirming someone's gender?

[deleted]

Re: Encryption Is Not a Crime

#179
post #30

Earlier quoted context omitted.

> You should engage with the arguments the other side makes. The arguments are "Protect the children.", "Catch terrorists.", "Catch criminals.". Those arguments have been engaged with for decades. They are purely emotional arguments. Anyone who still pushes those arguments forth is most likely doing so with ulterior motives and cannot be reasonably "engaged" with.

Let's not ignore the full history here. That is a bad faith argument. It was a crime to use expensive encryption 30 years ago, but a lot of decisions were made to allow it. Today, every single one of those old caveats about child porn, drugs, money laundering, terrorism, (both domestic and international) and criminal acts in general all have stories where weaker encryption would have saved hundreds and hundreds of li…

A bit of a nit-pick. 30 years ago was 1995. It was not a crime to use PGP in the US in 1995. What PKZ was charged with was exporting the encryption technology (or allowing it to export itself by putting the code on an anonymous FTP server.) The Bernstein case was similar in that it was the export of the machine-readable code the government objected to, not it's domestic distribution. The right for researchers to publish text describing algorithms had earlier been recognized by the court (which is why Martin Gardner could describe the RSA cryptosystem in Scientific American in 1977.)

Re: Encryption Is Not a Crime

#180
post #169
post #168

Earlier quoted context omitted.

> The question specifically asked which one you are talking about, not about your dreams. Which one is like that? After your five ninja edits, it's been hard to keep up: Glass relocker mechanisms have existed (in reality) on safe doors for decades and will often result in the destruction of contents if triggered and opening is still required. Governments are normally seeking evidence : a stack of cash or a quantity o…

> After your five ninja edits, it's been hard to keep up No need to reply within the first second. Take your time. In fact, consider taking a lot more time as you still haven't named the specific vault, or set of vaults, that is causing such a big problem for the government. If we don't know what vault it is, even if your description is vague, how would anyone come to think of it as a problem? Laws are not created by…

> as you still haven't named the specific vault

Vaults and safes are boutique products. Glass relockers have been sold for decades - can you not extrapolate that heat and impact might destroy something inside of a highly thermally-conductive container?

HSMs and similar tech have had tamper detection systems for decades with internal battery backups.. these aren't illegal yet. My server cases from 20 years ago had tamper switches for exactly this purpose. How hard is this stuff to engineer?

Post reply on HN