Live data from Hacker News

DOJ: Strong encryption that we don’t have access to is “unreasonable”

arstechnica.com

231–238 of 238 posts

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#231
post #207

Earlier quoted context omitted.

> but were stolen from you. You're forgetting that the courts are human and would be sympathetic in this case. If it couldn't be shown that you have access to the documents or you could show they were stolen then you would be fine. > Just because you had it yesterday doesn't mean you have it today Right, which is why I prefaced the discussion with the situations where the police can prove beyond a reasonable doubt th…

> You're forgetting that the courts are human and would be sympathetic in this case. If it couldn't be shown that you have access to the documents or you could show they were stolen then you would be fine. But that's the whole problem. How are you supposed to prove that you don't have something? It's completely reasonable that someone can have stolen it from you without you being able to prove it. They can prove that…

> It's completely reasonable that someone can have stolen it from you without you being able to prove it.

I agree and if I was designing the legal theory I would make sure that the burden of proof is on the person claiming an other has knowledge.

> the correct pass phrase and it only proves that they knew it when the video was made, not that they still remember it now.

Right, which is where reasonable doubt comes into play: if the video was months ago it's completely reasonable to forget a password -- if it's two hours later they have a much tougher case to make about spontaneous amnesia.

Applying the 'you can't possibly prove knowledge under any circumstances' argument would be absurd in any other case.

"Did you know she was under 18?"

"No your honor, I forgot, it had been a few weeks since I saw her ID."

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#232
post #133
post #24

The government has demonstrated that they will abuse every power given to them, and even those that weren't. I would not entrust every aspect of my personal information to the very same organizations that indefinitely detains people, including American citizens, without access to a lawyer while commiting acts of torture; and the ones that said the Patriot Act could never be used for domestic surveilance; that lied ab…

> The government has demonstrated that they will abuse every power given to them, and even those that weren't I think this mixes up what is true and what people (myself included) wish was true. Governments don’t have power given to them. Their default state is God-Kings ruling on personal whims. Governments have power taken from them , either by corporations, or by religions, or by other governments — sometimes these…

Governments always gain their power from the governed, and nowhere else. This fact is always resisted by those who know it because it a) makes the people responsible for the actions of their government and b) makes the government responsible for their people.

For as long as we ignore this fact, we'll get corrupt governments. Alas, its also a key reason that governments are corrupt - a government is only as ethical as the people it governs.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#233
post #88

Earlier quoted context omitted.

> Do we want to protect our citizens? The only answer is yes. This is not the right question. It is the one they use but is not the right one. "Do we want our citizen able to protect themselves" is the right question. And as most government have shown, they really don't want it. They want to be in charge of the protecting. Once you see things from their perspective their position makes more sense.

But it's funny that the US is so adament about being able to defend yourself with guns. But with software it's a debate. And it seems that often, the people for guns are against encryption and vice versa. From a european perspective it's so strange.

> From a european perspective it's so strange.

Agreed. To me, it seems that encryption should be uncontroversially accepted from the populations's standpoint, while gun policies have valid arguments for and against.

Basically: it's really hard to shoot someone in the face with pgp.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#234
post #231

Earlier quoted context omitted.

> You're forgetting that the courts are human and would be sympathetic in this case. If it couldn't be shown that you have access to the documents or you could show they were stolen then you would be fine. But that's the whole problem. How are you supposed to prove that you don't have something? It's completely reasonable that someone can have stolen it from you without you being able to prove it. They can prove that…

> It's completely reasonable that someone can have stolen it from you without you being able to prove it. I agree and if I was designing the legal theory I would make sure that the burden of proof is on the person claiming an other has knowledge. > the correct pass phrase and it only proves that they knew it when the video was made, not that they still remember it now. Right, which is where reasonable doubt comes int…

> Right, which is where reasonable doubt comes into play: if the video was months ago it's completely reasonable to forget a password -- if it's two hours later they have a much tougher case to make about spontaneous amnesia.

You're confusing less likely with unreasonable.

A pass phrase long enough not to make the whole question irrelevant is hard to remember.

You may have it in short term memory until it gets displaced by "oh crap I need to hire an attorney and a bail bondsman and call my boss and explain this to my wife" type issues. You may be able to remember it sitting in a familiar environment surrounded by your stuff but not in a jail cell without any of those cues.

It's completely reasonable to forget something you knew five minutes ago. It happens all the time.

Haven't you ever walked into a room and been unable to remember why you did? And that isn't 128 bits worth of context-free random data.

> "Did you know she was under 18?"

> "No your honor, I forgot, it had been a few weeks since I saw her ID."

I'm not sure this is making the point you want it to. The real targets of statutory rape laws are pedophiles who rape eight year olds, and in those cases it isn't a question of memory. You may not have remembered whether the child was 8 or 9 but you couldn't reasonably have thought they were above the age of consent. Which is why nobody objects to putting those pedophiles in jail, or to the laws that make it happen.

It's the cases where there could be a legitimate confusion that create exactly this problem. You can't tell if someone is one year above or below the age of consent just by looking at them, which is why those cases are extremely controversial.

How is it absurd that you could forget someone's age? Do you know the exact age of everyone you've ever been to the birthday party of? You probably knew on the day of the party.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#235
post #104

Earlier quoted context omitted.

Not really. If it is a foregone conclusion that the documents exist, the court can legally compel you to turn them over.

> If it is a foregone conclusion that the documents exist, the court can legally compel you to turn them over. Are you sure? That would imply that you could be compelled to produce documents that are known to exist but were stolen from you. It seems like a faulty premise. If they don't know where the documents are then how could they know they haven't been stolen or destroyed? It's the same problem with encryption ke…

> Are you sure?

Yes. A quick google for "foregone conclusion doctrine" will turn up a bunch of fairly-recent news about this.

> It's the same problem with encryption keys. Just because you had it yesterday doesn't mean you have it today. People actually lose or forget things, especially under stress.

Yes, and that's part of the problem. I'm not saying I agree with how all this works, just stating that's how it is.

There are limits, of course. If the court cannot establish that you know (or at least knew) the password/phrase/key. "I forgot" can certainly be a legitimate defense, but it of course depends on whether or not a judge believes you. If we could use "I don't remember" as an unquestioned excuse, we could get away with anything.

> That's one of the main purposes of protection against self-incrimination -- so that the government can't claim you know something that you don't and then hold you in contempt for not telling them.

That's not what we're talking about here. We're talking about things the government affirmatively knows that you either have or know. Unfortunately, of you no longer have or know that thing, the burden is on you to prove that you don't, which is difficult.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#236
post #41

It's hard to know where to even begin in arguing against this. There's the freedom/privacy argument, but I guess this is debatable depending on if you view computer files as an extension of your ideas/knowledge, or an extension of your physical possessions. Someone brought up the entire "risk of overreach and abuse" argument. There's also the likelihood of any tools the government has being leaked and used by bad act…

> It's hard to know where to even begin in arguing against this.

It's really not.

Encryption is all-or-nothing.

Either encryption works, or it fails. You can't pick and choose for whom it will work, and for whom it will fail.

So that frames the question, "Who is allowed to use encryption?"

This is a dangerous question to be asking, which is why it is hidden behind rhetoric by those who are asking it.

Encryption is speech.

Anyone can create and use a cypher. Such techniques were invented long before modern computing. Encrypted data is indistinguishable from random data, and possibly even unencrypted data.

Encryption is math. Cyphers are mathematical functions, whose derivations are public knowledge.

That brings us to the next question: "How?"

Either you control speech, or make math secret. Neither option is scalable, and neither option is moral.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#237
post #235

Earlier quoted context omitted.

> If it is a foregone conclusion that the documents exist, the court can legally compel you to turn them over. Are you sure? That would imply that you could be compelled to produce documents that are known to exist but were stolen from you. It seems like a faulty premise. If they don't know where the documents are then how could they know they haven't been stolen or destroyed? It's the same problem with encryption ke…

> Are you sure? Yes. A quick google for "foregone conclusion doctrine" will turn up a bunch of fairly-recent news about this. > It's the same problem with encryption keys. Just because you had it yesterday doesn't mean you have it today. People actually lose or forget things, especially under stress. Yes, and that's part of the problem. I'm not saying I agree with how all this works, just stating that's how it is. Th…

> Yes, and that's part of the problem. I'm not saying I agree with how all this works, just stating that's how it is.

You have to keep in mind that judges make rulings that conflict with the rulings of other judges all the time. It means one of them is wrong and it takes a higher court (or legislative action) to sort it out.

Pointing to lower court rulings in the news doesn't mean the issue is settled.

> If we could use "I don't remember" as an unquestioned excuse, we could get away with anything.

That is obviously nonsense. People are regularly convicted without being compelled to say or do anything. The government simply has to prove their case without the defendant's testimony.

> We're talking about things the government affirmatively knows that you either have or know. Unfortunately, of you no longer have or know that thing, the burden is on you to prove that you don't, which is difficult.

But that's the point. They should have to prove that you have it, not that you had it. And when the thing is the contents of your mind, it's impossible for them to prove that without your cooperation, and impossible for you to disprove it.

The burden that something can't be proven in a criminal proceeding is supposed to fall on the government, not the accused.

Re: DOJ: Strong encryption that we don’t have access to is “unreasonable”

#238

Earlier quoted context omitted.

Consider these two points as a start: - They solved crimes before iPhones. Encryption is not a roadblock - In many countries guns are illegal. Yet criminals do own them. If encryption becomes illegal, criminals would still use it

> - In many countries guns are illegal. Yet criminals do own them. If encryption becomes illegal, criminals would still use it Making guns illegal doesn't stop criminals from using them, but it does make it possible to jail someone only because they had a gun. Outlawing encyrption won't stop criminals from using encryption (just look at China) but it does make it possible to jail dissidents only because they were usi…

Very good point!
Post reply on HN