Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

241–250 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#241
Unpopular view, but unrecoverable encryption deployed at web scale is a cancer on society. While unrecoverable encryption provides additional privacy to law abiding citizens, it normalizes low level criminal activity at scale.

There has to be a better trade-off here that minimizes the risks of 3rd party access, and gives law enforcement and the intelligence agencies the tools they need to do the best possible job.

If I had to choose, I’d rather my consumer endpoints be hardened but have vetted and protected exceptional access mechanisms on the encryption.

In practice, this bill is likely to lead to cut corners by big tech, who won’t be legally mandated to actually build increasingly responsible encryption recovery mechanisms for LEO. This will enable big tech to say, “I told you so”, because they were simply doing the minimum amount that was required of them legally.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#242

Back in late medieval europa most postal services had a back room, called cabinet noir where letters where carefully opened, read and resealed to check them for signs of treason against the crown or cross. These were often abused for what we today would call economic espionage. For these reasons many rich people employed private couriers who traveled to their business partners in person to hand over messages. Those w…

> Today many argue the state has a need to access such correspondence to prevent crime, but such a need is like the need of an addict: nothing good can come from it and the people should not enable these institutions to satisfy an ever growing demand for insight into their private lives. One must remember that democracy is founded on the believe that thoughts and words are not crimes and everyone must be free to expr…

I feel like OP does that 2 sentences later.

> And yes, it is true that these totalitarian methods ar [sic] efficient in fighting street level crime. However for society as a whole, such methods enable a terror of the state that is a crime against humanity itself

Re: Stop the Earn IT Bill Before It Breaks Encryption

#243
post #71

Earlier quoted context omitted.

Do you really see most people leaving the likes of Facebook, Instagram and Twitter? I don't think they care about privacy enough to stop doing what's easy and fun

People have been leaving Facebook in droves. Hardly any of the original users use the platform regularly. Facebook has only remained relevant by buying relevant platforms as they start to take off. Companies that declines an offer or regulation to prevent this buy up behavior is what it takes. Social networks have no monetary buy in to discourage switching the moment your friends aren't on the platform any longer

...and they've been flocking to Instagram (also Facebook is still huuuuge)

Companies that are willing to play dirty are the ones that get investment and also are the ones who retain users. They have an inherent advantage over any platform that tries to be moral -- or alternatively platforms that try to be moral have an inherent disadvantage. As long as privacy and respectful user experience is on the bottom of the list of priorities of most users they are the ones who will be able to build momentum, and I can't imagine what could happen to change that.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#244
post #241

Unpopular view, but unrecoverable encryption deployed at web scale is a cancer on society. While unrecoverable encryption provides additional privacy to law abiding citizens, it normalizes low level criminal activity at scale. There has to be a better trade-off here that minimizes the risks of 3rd party access, and gives law enforcement and the intelligence agencies the tools they need to do the best possible job. If…

Would a bill really eliminate the concept altogether? It might make their business more expensive in certain parts but there are multi-billion dollar criminal empires that invest in things like their own submarine tech. Do you think e2e encryption isn't something they'd develop in-house & resell to each other?

At best it might help catch some street level crime but any serious organized crime (which arguably is a bigger problem because it's organized) will have the tools available anyway. Consider it this way. There's already a black market for security exploits with exploits frequently costing far more than they might actually otherwise be worth (there's a limited time utility before the exploit is patched). How much do you think e2e encryption would cost & do you think there's not going to be buyers & sellers for this? Especially since, unlike exploits, this is an infinitely distributable solution. I can sell to as many buyers as I want without risking my revenue stream.

On the technical side we've observed what happens with this stuff. We'd be one Snowden-style leak away from all websites instantly becoming vulnerable. Do you not think that might be valuable to adversaries of the USA?

Re: Stop the Earn IT Bill Before It Breaks Encryption

#245
post #206

Earlier quoted context omitted.

So to hide a backdoor in a opensource software it's the best solution to tell the world that you (the NSA) is actively working on a Project? Like SELinux? Man do you think they are stupid? They work on those projects to make their own infrastructure more secure, don't you think every one looks on their fingers/commits? >You should also consider as a swiss citizen that US law is increasingly world law That's Bullshit,…

Per the links above, they didn't tell anyone, Snowden outed them. In the cold War it was true of the western world and the USs use was limited because the US wanted to look gentle and reasonable. Today it's true for most of the planet and the US wants to look tough. If you don't like the Assange case (I agree the brits are lap dogs, but that case actually got kicked off in Sweden and was handled under EU law much mor…

>The US ordered Switzerland to arrest and extradite foreign nationals,

No problem with that, from the article:

>With wire fraud, one needs a wire that originates in the US

Sometimes we even ask for it...that's normal international business:

https://www.admin.ch/gov/en/start/documentation/media-releas...

>Proceed at your own risk and don't assume that America banning encryption doesn't make it illegal for you just because you're a Swiss citizen in Switzerland

Yeah i stop here...

BTW from your first article about android:

>So, if it’s not looking to plant backdoors, what’s the NSA’s business with Android? Ironically, the agency has been working to make Android more secure.

AND

>It is just as preposterous to think that the best way to gain access to any operating system is to publicly announce that you are contributing to the OS, and make the tainted code accessible to anyone with an interest in it.

So it was NOT Snowden, but NSA itself.

Second Article about Coreboot:

>Myers published a paper about STM last year on how NSA’s STM implementation could work. All Coreboot code, including all the STM contributions from the NSA, are open source, so anyone could verify that there is no backdoor in there -- in theory.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#246

Earlier quoted context omitted.

> Once the net adopted the platform model, we were screwed. So stop being another brick in the wall: stop using the platforms just because it is convenient. For example: * https://old.reddit.com/r/selfhosted/

There is some irony in this being a reddit link.

Well, if we're talking e-mail:

* https://workaround.org/ispmail

* https://mailinabox.email

If we're talking photos:

* https://www.zenphoto.org

General storage:

* https://owncloud.com

Re: Stop the Earn IT Bill Before It Breaks Encryption

#247
post #214
post #85

Earlier quoted context omitted.

>go after creators and ensure some kind of backdoor is inherent to the project >shut down projects by exerting pressure on developers The developer probably just going to the press with that, no need to damage your own private centric project, sure the NSA can say they never did that so the developers can ignore it OR they openly say it was them, then the project just can change the country. >run some kind of propaga…

What is the developer going to the press with?

Publication

Re: Stop the Earn IT Bill Before It Breaks Encryption

#248

Earlier quoted context omitted.

If you want them to care, stop by their offices and have a really rational talk with their staffers and the representative. If you can explain things with stories (for example, where a backdoor was used to crack ___ resulting in very personal damage to ____), you will change minds. Get 20-30 tech leaders to go meet with Feinstein and discuss how this will affect them. If she won't budge at that point, then maybe y'al…

You're assuming good faith in elected representatives and their staff. I wonder if anyone in the last decade has _ever_ walked into their rep's office, talked to them, and changed their vote on a key issue. I really doubt it.

I have. Multiple times, but not every time. Reps get close to zero direct interaction with constituents. It's usually filtered by a group with an agenda (petitions, campaigns). When you go as a citizen and talk (not scream or debate) about an issue that really matters, you will get their ear. You may not get the vote you want, but you will be take seriously, and the staff and rep will discuss what you are bringing to them. If you have 2-3 people approach your rep with the same problem it will have the same effect as a petition with thousands of signatures.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#249

I don't get the sudden press on this bill. It was introduced in March, and it was added to the Senate calendar in July. There was one hearing back in March, yes, but there isn't even a companion bill in the House at this point. Don't get me wrong, it's bad legislation, but is there some imminent action planned? https://www.congress.gov/bill/116th-congress/senate-bill/339...

Keep trying until it passes. Use distractions from elsewhere to pass it like thieves in the night.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#250

I have been wondering if there is a way to satisfy law enforcement without breaking encryption or adding backdoors. An idea: what if platforms allowed law enforcement (with a warrant) to conduct rainbow table attacks against encrypted content of a specific user? In other words, what if platforms allowed law enforcement to determine whether a specific known object (e.g. a known photo or video) was sent / stored by a u…

There is no situation in which the spread of "content" should be a crime. Any encryption that allows LE to track content is broken.
Post reply on HN