Live data from Hacker News

Attorney General William P. Barr Delivers Address Conference on Cyber Security

justice.gov

191–200 of 230 posts

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#191
post #88

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

Breaking encryption for the government is so furiously stupid it blows my mind every time it is suggested. Especially here, where people actually give the idea merit. It makes me miss oldschool /. where 100% of everyone was on the same page. Your point illustrates a huge reason as to why. Backdooring stupid.crypt and forcing law abiding people to use it just insures that big badguys will use any other kind of encrypt…

> When people are against gun control, a common thread is "make guns illegal and only criminals will have guns." This argument has merit, but if we DID amend out #2 and make guns illegal, over time firearm proliferation would decrease.

Even if that is true, "decrease" is not remotely equivalent to "eliminate".

The problem is that as law-abiding citizens, and those who have their weapons forcibly taken by law enforcement are left completely unable to defend themselves; while criminals are not completely unable to acquire firearms.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#192

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

I totally get what you are saying, but it is quite the rabbit hole if we determine that 'we can't have any illegal number... everyone should be able to share any number with anyone else' That basically means we have to entirely get rid of copyright, since all data (books, movies, software, corporate secrets, state secrets, etc) are just very large numbers. Do we believe that there should be no restriction on the shar…

We are talking about functions, not data.

In that sense, copyright = data, and encryption = functions.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#193

Modern encryption is really just math. Cryptography in consumer and off-the-shelf products (which Barr is targeting with his discussion) theoretically _could_ be modified in such a way that the government could decrypt it. The two ways of which I can think are (1) Encryption "backdoors" -- fancy math known only to the government; this would require new encryption ciphers or (b) key escrow. Both approaches have their…

>In these discussions about the government being able to decrypt stuff, are we, in effect, suggesting that certain math be made illegal? All images are binary. All binary is just a number. We have made many such numbers illegal and even have software that will detect them and report you when you share the number with such number sharing services (dropbox, facebook, etc). So making math illegal sounds entirely possibl…

You are talking about data, so following that logic, what would be made illegal would be implementations not algorithms.

Math can be represented in a variety of ways, but the pattern being described is immutable.

What A.G. Barr is insinuating is not that we make implementations illegal, but that we make the use of algorithms categorically illegal.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#194
post #56

Earlier quoted context omitted.

Except it’s not a discussion worth having. If you have a back door, it’s there for everybody not just the people it’s intended for. Additionally, there’s not going to be a way to force people to use the encryption that happens to have a backdoor. It’s an algorithm. People who don’t obey the rules will just use a more secure method when they need to protect something. This is why there’s no point to having the convers…

Do you realize how condescending it is when someone comes to you with a problem and your answer is that "is not a discussion worth having"? Warrants losing their power in the digital age is a problem and our community's refusal to recognize that just pushes the government down alternative routes to something like PRISM. Also focusing on enforcement is making the perfect the enemy of the good. What percentage of commu…

I do. And yet, there’s no other way to approach it.

You either protect everybody or you make the compliant vulnerable.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#195
post #183

Earlier quoted context omitted.

Ok, I believe we are in the middle of arguing OP's point about how the pro-gun people are wrong when using the argument "only the criminals will own them", and how the pro-encryption people are right when using the same argument about encryption. And, I think what you're adding here is that I've got an error in my statement that both parties will happily build their own firearms/encryption because the physical gun is…

My point wasn't that "pro-gun people" are wrong. The argument is a tautology, it can't be wrong! If guns ownership is a crime, then owning a gun makes you a criminal. The tautology is compatible with the hypothesis that if guns were confiscated and illegal, eventually there would be a decrease in the amount of people getting shot. Probably an increase for a while as confiscation attempts resulted in agents getting in…

Sure, the saying has broad appeal because the tautology of it is interesting. The actual debate, however, centers on whether laying down your weapons makes you vulnerable to those that hold onto theirs.. and that was the lens I was looking through.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#196
post #36

Earlier quoted context omitted.

Sure, but I can just refuse to decrypt my data. They can just break physical locks.

This is what a lot of people in our community seemingly refuse to recognize. For all intents and purposes, encryption is a unbreakable lock that can serve to perfectly hide valuable criminal evidence. Such a thing wasn't possible when our laws were written and has never before been possible in the physical world. Its existence has potential to be a huge shift in how we enforce the law. Regardless of our views on encr…

If we are going to continue with this metaphor of encryption being a lock...

If you obtain a warrant to bypass that lock, then you have the right to compel me to hand over the keys. In this case, that metaphorical "key" would be my "private encryption key".

The point where this metaphor breaks is when I either refuse to provide that key, or have lost/destroyed it. On one hand, it's trivial for a physical lock to be bypassed, either by picking it or destroying it, thereby allowing you to "get inside" and (the end goal) "search". Of course, to "search" encrypted data does not involve "getting inside". It involves decryption.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#197
post #188
post #177

Earlier quoted context omitted.

> you can't trust the government regardless of whether they have a warrant If they have a warrant, what exactly is it that you think I need to trust them about at that point?

A warrant is a check and balance designed by one arm of the government to give another arm of the government oversight into the actions of a third arm of the government. If you don't trust the government, your trust in the entire system should logically fall apart.

Very different kind of trust. To serve a warrant at my home, agents of the government have to be physically present, and they have to give me a copy of the warrant printed on a sheet of paper. The physics of that situation provides auditability. If the warrant was not genuine, the people who served it would go to prison.

Cryptographic back doors are totally different. It is not possible to build a back door that has auditability built into its basic physics the way warrants do. That the thing that William Barr doesn't understand. His mindset is something like, "If we can send a man to the moon, surely we can make a way for law enforcement to break encryption that doesn't threaten people's rights." Well, no, we can't. Sending a man to the moon is merely difficult. A back door that only "the good guys" can use is actually impossible.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#198

Earlier quoted context omitted.

>are we, in effect, suggesting that certain math be made illegal? If that's really what's being proposed, I'd urge people to consider "Illegal Numbers" and how effective that's been. I keep seeing this "implausibility" of enforcing illegal encryption brought up, and I really think it's wishful thinking. If such encryption algorithms ever are made illegal in some manner, it will be trivial for the government to get th…

True, and this should frighten everyone. You'd be a suspected terrorist or criminal for using a VPN or tor or any foreign service that doesnt use the gov approved crypt. As long as you stayed out of the limelight and kept your head down you'd be fine. But if anyone looked into your activity, it would be easy to determine that you weren't using gov-crypt. This is inheritely authoritarian.

I can think of a few ways to make this a real pain for law enforcement. Sure I use my crypto to encrypt a tunnel then you use yours to encrypt a tunnel etc.... Make an onion out of the cryptosystem and law enforcement has got to get piles of warrants to cut through the various layers.

It's stupid, sort of like a fourth ammensment onion router

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#199

Earlier quoted context omitted.

We don’t need to use copyright as an example. Words are just data. Are there illegal combinations of words to exchange? The law says, YES. Some speech is absolutely illegal, including making credible death threats, conspiring to break other laws, or disclosing certain state secrets to foreign powers. Very few people argue that since words are easily available to everyone, that it is futile to make some combinations o…

Words are not illegal per se. Words uttered in a situational context that renders them of immediate harm are illegal. I can say "Fire!" in a theater while giving a lecture or putting on a show. I cannot knowingly claim the theatre is on fire when it isn't to cause a panic. Point is, it is not the Word or content that is illegal. It is the union of word and context that is illegal. Subtle difference, but it's the only…

I agree with you, and make the same point about numbers.

The number is not illegal, it’s the number in conjunction with a situational context that is illegal.

We may disagree with the intent of the law, but the argument that we are making numbers illegal, or math illegal, is parallel to the argument that other laws make words illegal.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#200

There’s no discussion of how to build exceptional access encryption that solves the weakening issue, just that it “can’t be done”. The spirit of this initiative in 2019 is likely more about stopping strong encryption at scale, which is certain to be a frustrating black hole for LEO and the IC. Perhaps HN would do well to ask how to solve the problem from a technical perspective, given the requirements. This includes…

> This includes both how to build a better mousetrap (one that doesn’t have a “backdoor” or significantly weakens the encryption mechanism), and how to solve concerns about abuse of exceptional access.

There is a simple way to solve concerns about abuse of "exceptional access": Not to include any "exceptional access" mechanisms. Securely implementing a cryptosystem is a daunting task almost never achieved. Intentionally creating a human-controlled mechanism to access plaintext makes the problem much, much worse.

> There’s no discussion of how to build exceptional access encryption that solves the weakening issue, just that it “can’t be done”.

Please consider that there is fundamentally no way to solve concerns about exceptional access. "Exceptional access" means that there is necessarily a human attack vector: Those humans who control whatever mechanism exists to provide LEO access to plaintext. This necessarily weakens any cryptosystem. If those people are compromised, "exceptional access" will simply be "routine access". Further, because decryption of data emits no obvious signs of physical tampering, even citizens who trust that "exceptional access" is not being abused cannot verify that.

I actually appreciate the name of your 5 hour old account. You're correct. We are experiencing mass hysteria over cryptography. However, it is not security professionals who are hysterical: it's people like you, who apparently never met an argument against liberty that they didn't like.

Post reply on HN