Live data from Hacker News

Civics is boring, so, let's encrypt something (2024)

queue.acm.org

21–30 of 74 posts

Re: Civics is boring, so, let's encrypt something (2024)

#21
post #8

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

> "NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

Have any such system been built?

Re: Civics is boring, so, let's encrypt something (2024)

#22
So, if we were to implement what this author is proposing, governments would be allowed to jail people indefinitely simply because they used effectively unbreakable encryption- regardless of whether what they encrypted was illegal (or evidence of a crime)? Because if so, that is absolutely unacceptable in any society that would call itself free.

Re: Civics is boring, so, let's encrypt something (2024)

#23

This article frames a false choice of either designing a system that allows government access to everything you do digitally (which is now almost everything), or having the government design such a system. In reality the choice is between such a totalitarian surveillance state without the possibility of digital security guarantees, or one where police can’t read your digital mind but can do good old fashioned police…

PHK’s piece assumes that there’s a clear and effective distinctions between the government and the juducial system: The police can’t wiretap unless authorized by a judge (this could be backed by certificates/whatnot, and not just “ok, go ahead” as it is now.)

However: Not all countries have this effective separation/independence between branches, and some countries which have so far enjoyed such separation are perhaps not so certain anymore.

Even so: I think the point still stands - there is a choice to make, and the current trajectory (EU’s ChatControl, and UK’s encryption ban), is what we’ll risk getting instead.

Re: Civics is boring, so, let's encrypt something (2024)

#24
post #8

Earlier quoted context omitted.

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

> "NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS. Have any such system been built?

China iCloud? Not sure it is actually a NOBUS or just key escrow mechanism with administrative controls.

Re: Civics is boring, so, let's encrypt something (2024)

#25
post #8

Earlier quoted context omitted.

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

I don't buy it. These systems are always multiparty. In a single party cryptosystem we can have internal integrity. We know we're not the bad guys and we didn't share the private information with the bad guys, therefore the bad guys don't have the data. Once you're multiparty that goes away, any other party can definitely betray you and then it's game over, your own integrity doesn't matter. Historically NOBUS was ab…

The other party doesn't even need to betray you, just have their systems compromised. See also, eg. : Salt Typhoon.

* https://en.wikipedia.org/wiki/2024_global_telecommunications... "The hackers were also able to access wiretapping systems used to conduct court-authorized wiretapping."

Re: Civics is boring, so, let's encrypt something (2024)

#26

This article frames a false choice of either designing a system that allows government access to everything you do digitally (which is now almost everything), or having the government design such a system. In reality the choice is between such a totalitarian surveillance state without the possibility of digital security guarantees, or one where police can’t read your digital mind but can do good old fashioned police…

Nah, you forgot the choice when you naively think corporations can provide a simulacrum of privacy, when in reality they're indistinguishable from any other large org.

> corporations [...a]re indistinguishable from any other large org

Presumably a Freudian slip for "governments"?

Re: Civics is boring, so, let's encrypt something (2024)

#27
This is, far and away, the most authoritarian proposal for the regulation of encryption that I have EVER seen. As far as I know, no nation on Earth has legal provisions so explicitly authoritarian as to require every civilian to maintain copies of all their communication in a form that cops can access after the fact.

If I send you a letter and you promptly burn it, that does not entitle the police to imprison either of us, no matter what sorts of subpoenas they obtain after the fact. But if I send you an encrypted message, we both throw away the key, and the police later subpoena our communications, this proposed law would permit one or both of us to be jailed for the ENTIRE term of whatever crime we are ACCUSED of:

> Then, fourth and finally (drum roll, please!), they'll need to allow courts to jail the accused until: (a) the communication has been decrypted by someone; (b) the maximum penalty for the charged crime has been exceeded

Unless this is a joke that's gone over my head, this is an open embrace of totalitarian surveillance. Either way, it's farcical. Fortunately it would not survive basic constitutional challenges in any liberal democracy.

---

Here's another silly detail. (Ugh, this article is bad on so many levels.)

> Then the legislators can get to work. First, they'll need to make it a crime to force or trick anyone into using stronger encryption than they consent to, no matter how that might be done. (Note that IT liberalists who claim encryption is a human right never realize this should also include the right not to be forced to use encryption against one's will.)

This means, if you start a conversation with me in plaintext, I'm obliged to continue exactly as I would if we were talking through encryption. This compels speech, which is both unconstitutional in most places and completely untenable in practice. (And why would there be a human right not to be "forced" to use encryption? There's no human right precluding "no shirt, no shoes, no service" policies. People who don't use encryption do not constitute a protected class!)

Re: Civics is boring, so, let's encrypt something (2024)

#28
post #8

Earlier quoted context omitted.

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

> "NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS. Have any such system been built?

Have the private keys for Dual EC ever been disclosed, or is there any evidence of them having leaked?

Re: Civics is boring, so, let's encrypt something (2024)

#29
post #8

Earlier quoted context omitted.

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

I don't buy it. These systems are always multiparty. In a single party cryptosystem we can have internal integrity. We know we're not the bad guys and we didn't share the private information with the bad guys, therefore the bad guys don't have the data. Once you're multiparty that goes away, any other party can definitely betray you and then it's game over, your own integrity doesn't matter. Historically NOBUS was ab…

The argument about who the trustworthy "us" is is deeply uninteresting to me. I just care that there's precedent that if you stipulate the existence of such an "us", computer science does allow for NOBUS-y access mechanisms.

Re: Civics is boring, so, let's encrypt something (2024)

#30
post #17

Earlier quoted context omitted.

At minimum, bad actors inside the government could always use the access mechanism. What's your concept for preventing other bad actors from getting it though?

"What if 'us' is bad" is a separable question from "is NOBUS possible". I'm not advocating for it, I'm just saying the computer science of this matters, and a lot of people have objections to the concept of NOBUS that are more ideological than empirical.

I don't think it's a computer science claim to begin with. To my knowledge nobody has ever broken 256-bit AES, but that's not the part of the system that fails. There are two things that prevent it from working in practice:

The first is that "us" would be something like "governments in the US"; but then that's too big of an organization to sustain as free from compromise. There are tens of thousands of judges in the US, well over a million police and military. All it takes is one of them to be corrupt or incompetent or lazy and the bad guys get to use the skeleton keys to everything in the world, which can unlock secrets worth billions or get people killed. And that's assuming they only compromise the authorization system; if they actually gets the keys it's practically armageddon.

And the second is that it's not just one government. If the UK makes Apple and Google build a system to unlock anybody's secrets, is Australia not going to want access? Is China? Let's suppose we're not going to give access to Russia; can the fallible humans operating this system fend off every attack once the FSB has been ordered to secure access by any mean necessary?

It's a system that combines many points of compromise with an overwhelming incentive for everyone from state-level attackers to organized crime to break in and severe consequences when they do.

Post reply on HN