Live data from Hacker News

DOJ plans to strike against encryption while the Techlash iron is hot

cyberlaw.stanford.edu

211–220 of 347 posts

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#211
post #2

You first DOJ. These folks want back doors so they can read everyone's traffic, but once you put a back door in an encryption standard, it affects everyone.

My favorite interview over the last few weeks is from NPR when a guy in law enforcement said that police don't even use that type of encryption (that normal people use) as if he forgot that his police radio, payroll, camera footage, information storage, are all most certainly protected via encryption.

I found this exchange amusing as well, for a slightly different reason. The gist of his point was that "who needs this level of encryption, other than maybe the military?".

Substitute guns instead of encryption and see how that fits.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#212

This will just push people to open source applications and peer to peer networking. Basically, devolve back to the early days of the internet with regard to person to person communications. How is the DoJ going to force Signal or even Telegram to add a back door?

A method I've seen tossed around is that they'd just add a "ghost" user as a silent participant to all conversations.

I'd like to think this is difficult with Signal's model, though.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#213

Earlier quoted context omitted.

> I’ve been downvoted to oblivion simply for stating my view; also not necessary. I personally downvoted because I believe your statement is wrong in fact and problematic in opinion. > Secret police worked when criminals were put away with parallel reconstruction, for instance. Parallel construction is a morally dubious method of hiding illegal and unconstitutional activity on law enforcement's part. What crime was t…

Thanks for responding. Which part was factually inaccurate?

The part about tech geniuses being able to solve a problem that can't be solved without violating principles of mathematics.

You probably don't think you said that though, because you missed the point yourself. It's a common mistake. You're in good company, plenty of smart politicians and national leaders have the same misconception. It's often stated in terms like "if we could put a man on the moon, all the smart people in Silicon Valley should be able to put their heads together and figure this out." But it doesn't work that way.

Aside from being wrong, which in itself doesn't deserve a downvote, it's also poorly thought out and a seductive yet destructive line of thinking, which arguably does deserve one.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#214
post #57

Earlier quoted context omitted.

Everything technological is impractical to use for average people until people like us go out and build a practical solution. OTP is not a very complicated scheme. All you need is a good source of entropy, a place to store a big fat array of it all, some XOR operations, and a safe way to hand the codebook to your trusted parties (e.g. phone-to-phone transfer options).

One time pads are not secure by modern cryptographic standards. Elaboration: https://news.ycombinator.com/item?id=6008695

Huh?

First off citing yourself isn't an elaboration. Second if you are arguing that one-time-pads don't work / won't work in modern times that goes against our entire understanding of certain bits of cryptography.

You'll need to yield some real sources first.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#215

Earlier quoted context omitted.

> I’ve been downvoted to oblivion simply for stating my view; also not necessary. I personally downvoted because I believe your statement is wrong in fact and problematic in opinion. > Secret police worked when criminals were put away with parallel reconstruction, for instance. Parallel construction is a morally dubious method of hiding illegal and unconstitutional activity on law enforcement's part. What crime was t…

Thanks for responding. Which part was factually inaccurate?

> Secret police worked when criminals were put away with parallel reconstruction, for instance.

It wasn't the secret police which worked. It was the parallel construction.

> “You can’t stop math.” Not true, strictly anyway.

You can't stop math.

> Backdoors are an antiquated way of implementing exceptional access. The proper way is to provide third party access that is truly exceptional (living up to the name), and not based on flaws that a malicious actor or rogue nation can break.

This statement is a fantasy. There is no way to provide third party access that is "truly exceptional" that a malicious actor or rogue nation can't break.

> Instead of E2EE, how about building E2E2EE. Doesn’t need to be measurably weaker.

Anything weaker than E2EE is measurably weaker than E2EE. E2E2EE is measurably weaker than E2E2EE.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#216
OK, so how have things been going for the UK and Australia? Has anything concrete actually happened as result of the legislation that has helped law enforcement get access to encrypted communications?

In other words; does legislation actually make a difference in practice? Or is it just some sort of pointless political signalling?

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#217
post #57

Earlier quoted context omitted.

Everything technological is impractical to use for average people until people like us go out and build a practical solution. OTP is not a very complicated scheme. All you need is a good source of entropy, a place to store a big fat array of it all, some XOR operations, and a safe way to hand the codebook to your trusted parties (e.g. phone-to-phone transfer options).

One time pads are not secure by modern cryptographic standards. Elaboration: https://news.ycombinator.com/item?id=6008695

So the concern then is that the message might be tampered with on the wire?

Is there some hypothetical reason we can't just append the SHA256 of the message to the message before encrypting it? It should be impossible for an attacker to alter any message bits undetected with this scheme.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#218

This will just push people to open source applications and peer to peer networking. Basically, devolve back to the early days of the internet with regard to person to person communications. How is the DoJ going to force Signal or even Telegram to add a back door?

Well, during the Cold War the feds declared encryption to be "Auxiliary Military Equipment," listed on the USML [1]. It was illegal -- prison time illegal -- to ship software which could encrypt communications outside the USA up until 1992 [2].

I'm old enough to remember the tail end of this and it was absolutely absurd, yet still very real. I remember Zimmermann being investigated by the feds [3]. Zimmermann was smart to tie publishing PGP to the First Amendment. Something like Signal in those days may well have resulted in charges and a conviction.

Never underestimate the potential for folly when it comes to government regulation.

[1] https://en.wikipedia.org/wiki/United_States_Munitions_List

[2] https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...

[3] https://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_i...

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#219
post #52
post #14

Why does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip . And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide eve…

> Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. Why would it not be possible to create a system that required several manual and offline steps in order to break the encryption? For example (and perhaps similar to offline cold storage of bitcoin) why couldn't a system be designed whereby 3 or more people in geographically diverse areas were…

No, it's not possible to create such a system without fatally compromising safety.

Take Bitcoin cold storage: People use offline storage and specialized hardware wallets to store their keys more safely. Now imagine there were some privileged keys that would allow the holder to just take anyone and everyone's bitcoins. It doesn't matter how geographically distributed it is, how elaborate the key ceremonies and oversight is. The system could never be trusted if such a backdoor existed.

Re: DOJ plans to strike against encryption while the Techlash iron is hot

#220

Earlier quoted context omitted.

Thanks for that. The goal is to design a system that prevents abuses. A technological solution to the ape problem would be helpful.

Current systems prevent most abuses, and many people are working on improving it to prevent more abuses. As an excellent example, Certificate Transparency has almost completely mitigated the potential abuse of compromising a certificate authority and using it to MITM traffic. Similarly, "binary transparency" or "software transparency" will hopefully eliminate the abuse of delivering a "special binary" to just one per…

Minimize or eliminate misuse through fundamental rethink of the solution.
Post reply on HN