Live data from Hacker News

The Moral Failure of Computer Scientists

theatlantic.com

21–30 of 49 posts

Re: The Moral Failure of Computer Scientists

#21
post #4

Earlier quoted context omitted.

There are many counter-examples. The important part isn’t that the answer is “no”, as the Law states, but that the story is tired enough to need a question in its headline in the first place. Andrew Marr’s explanation focusses especially on this aspect of the Law: “A headline with a question mark at the end means, in the vast majority of cases, that the story is tendentious or over-sold. It is often a scare story, or…

the title has been changed to include a ? when posting here it seems, (or they changed it on theatlantic.com). Nevertheless your comment about ? equalling clickbait really made me think. Edit: ok I just realized that the summary at the top was used as the title when posting here. I don't feel there is anything wrong with this.

Agreed.

Re: The Moral Failure of Computer Scientists

#22

Earlier quoted context omitted.

"Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen." It actually prevents many things when the law is clear. Your email example misses the entire point. So, let's use it to illustrate the point. I create an encryption system to protect email. It gets large uptake to point N…

Pointers to (seemingly) frivolous prosecutions (3) and pointers to anything resembling 4 or 6 would make them a lot more interesting. Without just a little bit of evidence, they are like saying the NSA will shoot your dog. My naive, facile reading suggests that systems like Signal, Pond and Tor tend to be more effective at actually securing communications, so it would be especially interesting to hear about the jackb…

The technique used for No 3 is here and other documents suggest they work with many agencies rather than just DEA:

http://www.huffingtonpost.com/peter-van-buren/parallel-const...

Number 4 we're not going to get examples of: TAO & TAREX operate in a bubble. There are two known efforts to do this sort of thing but tactics are unknown. One is BULLRUN:

http://securityaffairs.co/wordpress/17577/intelligence/nsa-b...

Additionally, the ECI leaks mention that the "FBI compels" firms to "SIGINT-enable" their stuff. This means the FBI has some way of coercing companies to backdoor things. The specifics were left out. That they've been doing it for years with no details public indicate even talking about it must be a crime. Like the other stuff.

IRS, SEC, whoever being used against people is a tactic with a long history. My bookmarks aren't giving me a link right now. I do recall Nacchio of Qwest claiming government came after him for being only ones not helping NSA. A quick Google had Binney saying IRS and NSA worked tight together albeit with speculation on Tea Party rather than obstacles to SIGINT as target.

http://www.wnd.com/2014/07/whistleblower-irs-in-cahoots-with...

And FBI raiding and seizing opponents stuff is well-known, happening to most leakers, too. Civil forfeiture is another weapon with a long history at FBI and DEA especially. Some journalists during Bush-Cheney Administration ended up on Do Not Fly list. Tor project people like Applebaum get harrassed at borders. So on and so forth. Many methods they can use without ever doing time for the abuse.

What they will do to you depends on who you are, what you're doing, what dirt they have on you, your resources, and so on. The uncertainty is one of their most powerful weapons. Never know when hammer will drop on you or how hard.

Re: The Moral Failure of Computer Scientists

#23

In short: no. This is a political problem that must be solved by laws that people push for. People have been supporting surveillance state or apathetic. Hence, it's winning and their combo of police power + secrecy + immunity is stronger than crypto.

The legal aspect was taken care of by the Bill of Rights. The govt is trying to erode them and so now we need to "fight" against it.

It wasn't: that was only the beginning. Democracy, like security, is a process rather than a thing you do once. So, people have to be "eternally vigilant" fighting off advances against their established rights in legislature and in court rulings. People can sit on the sidelines of corruption and have a democracy. That's what's happening now. It's why we're pretty far from the Bill of Rights in practice but still have enough to reform with.

People just got to put it to use.

Re: The Moral Failure of Computer Scientists

#24

Earlier quoted context omitted.

Pointers to (seemingly) frivolous prosecutions (3) and pointers to anything resembling 4 or 6 would make them a lot more interesting. Without just a little bit of evidence, they are like saying the NSA will shoot your dog. My naive, facile reading suggests that systems like Signal, Pond and Tor tend to be more effective at actually securing communications, so it would be especially interesting to hear about the jackb…

The technique used for No 3 is here and other documents suggest they work with many agencies rather than just DEA: http://www.huffingtonpost.com/peter-van-buren/parallel-const... Number 4 we're not going to get examples of: TAO & TAREX operate in a bubble. There are two known efforts to do this sort of thing but tactics are unknown. One is BULLRUN: http://securityaffairs.co/wordpress/17577/intelligence/nsa-b... Addit…

Specific examples are more interesting than raising the specter. You've doubled down on raising the specter.

Re: The Moral Failure of Computer Scientists

#25
Whoah: this title sucks all the oxygen out of what is a very interesting article centering on an interview with Phil Rogaway, one of the world's great cryptographers.

The title should instead be the one The Atlantic chose, which closely mirrors Rogaway's recent paper: "The Moral Failure of Computer Scientists".

Submitters to HN are meant to use the original title from the article where possible, unless that title is so bad it detracts from the article.

Re: The Moral Failure of Computer Scientists

#26
post #3

I wish this article were more particular about what cryptologists are doing wrong? What exactly could they have done instead? Without that info, it just seems like pointing a finger at cryptologists and saying, “This is your job! Do something!”

That's probably not a fair criticism. This is reporting about an extremely famous cryptographer pointing his finger at other cryptographers.

Here's more about it:

https://news.ycombinator.com/item?id=10657540

Re: The Moral Failure of Computer Scientists

#27

In short: no. This is a political problem that must be solved by laws that people push for. People have been supporting surveillance state or apathetic. Hence, it's winning and their combo of police power + secrecy + immunity is stronger than crypto.

The legal aspect was taken care of by the Bill of Rights. The govt is trying to erode them and so now we need to "fight" against it.

I'm not with 'nickpsecurity on this issue, but what you just said is not a valid argument.

Cryptography enables individuals to override the interests of any element of the state, no matter how compelling those interests are.

Any way you read the Fourth Amendment, even the wrong way that implies that the government requires a warrant for any conceivable search, there remains a pathway through which the state can compel the production of data. Congress may have to enact a law to authorize the compulsion, and a judge may need to sign off on the warrant, but at the end of the day, the government has the authority to compel production.

I think cryptography is mostly orthogonal to the Fourth Amendment, but to the extent it isn't, its main implication is that it thwarts the Fourth Amendment.

Re: The Moral Failure of Computer Scientists

#28

In short: no. This is a political problem that must be solved by laws that people push for. People have been supporting surveillance state or apathetic. Hence, it's winning and their combo of police power + secrecy + immunity is stronger than crypto.

Strongly disagree. Legal protection provides a recourse after everything happens. Technological measures don't let it happen in the first place. Or, well, to be more correct - make it significantly harder to happen. Consider: we can send all our email as non-enveloped postcards and rely on the laws that our correspondence privacy is protected. But for some reason we don't. Why we still send send out our Internet corr…

If you're going to use the envelope analogy, also consider that we don't put our mail in envelopes to prevent the police from intercepting it; we put them in envelopes to prevent access by all of the people handling the mail between the sender and intended recipient. A cop with a warrant can rightly get access to a person's mail in transit. The envelope also isn't particularly difficult to get around - we don't secure our mail through technical measures but instead by putting stiff legal penalties on tampering with it.

Re: The Moral Failure of Computer Scientists

#29
post #26
post #3

I wish this article were more particular about what cryptologists are doing wrong? What exactly could they have done instead? Without that info, it just seems like pointing a finger at cryptologists and saying, “This is your job! Do something!”

That's probably not a fair criticism. This is reporting about an extremely famous cryptographer pointing his finger at other cryptographers. Here's more about it: https://news.ycombinator.com/item?id=10657540

Thanks for that pointer. I agree with GP's criticism, though, at least the way the article is written. I was trying to understand it through the lens of the nuclear analogy and failing drastically, because whereas those scientists were developing PRO-nuclear technology, these ones are (a priori, to first order) developing ANTI-surveillance technology.

Re: The Moral Failure of Computer Scientists

#30
post #29
post #26

Earlier quoted context omitted.

That's probably not a fair criticism. This is reporting about an extremely famous cryptographer pointing his finger at other cryptographers. Here's more about it: https://news.ycombinator.com/item?id=10657540

Thanks for that pointer. I agree with GP's criticism, though, at least the way the article is written. I was trying to understand it through the lens of the nuclear analogy and failing drastically, because whereas those scientists were developing PRO-nuclear technology, these ones are (a priori, to first order) developing ANTI-surveillance technology.

Rogaway's paper starts with an extended discussion of the role of scientists in the nuclear arms race.
Post reply on HN