So terrorists will use one-time pads and other strong encryption and everyone else will have their information exposed on a massive scale when the backdoors inevitably are exploited.
I look forward to the day when one time pads are the norm for general encryption. A scifi novel I read, "A Deepness in the Sky" described how the pads themselves were a valuable item of trade. I don't think it's farfetched to imagine purchasing OTP data to use with internet browsing, the way we buy yubikeys to use with passwords. It would be a far simpler encryption scheme than those we currently use, and that simpli…
DOJ plans to strike against encryption while the Techlash iron is hot
251–260 of 347 posts
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#252Earlier quoted context omitted.
Watching old movies from 60s/70s sometimes have scenes where the characters are worried about calls being recorded or otherwise having no privacy. The typical response is “What is this, Russia?” or something similar. Privacy is really important. I will always error on the side of privacy even if that means not everyone bad is caught.
Freedom isn't free. I think people have just ought to realize that. People have this idea that free countries are more efficient, which is probably true in the long run, but it's a cop-out to just call it a day there. Once I was in Belarus. It's a heavily authoritarian country, make no mistake. When they had protests against their rigged elections, they traced the phones of everyone who went, then brought them in for…
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#253Earlier quoted context omitted.
I've worked on both sides of that, I think you'd be surprised. I also suspect that it's worse at the TLAs and any organization with access to FBI, license plate and various criminal databases. Obviously CCard databases and stuff are off limits as their use is outright fraud, but stuff like traffic cameras, imaging systems, etc.
I don't know about US, but many European countries have access logging in police and health databases, which checks to see for unwarranted snooping. With actual convictions taking place when someone gets too interested in, say, the behind-the-scenes data of the latest celebrity news.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#254This will just push people to open source applications and peer to peer networking. Basically, devolve back to the early days of the internet with regard to person to person communications. How is the DoJ going to force Signal or even Telegram to add a back door?
Well, during the Cold War the feds declared encryption to be "Auxiliary Military Equipment," listed on the USML [1]. It was illegal -- prison time illegal -- to ship software which could encrypt communications outside the USA up until 1992 [2]. I'm old enough to remember the tail end of this and it was absolutely absurd, yet still very real. I remember Zimmermann being investigated by the feds [3]. Zimmermann was sma…
Many of the arguments I've seen here defending encryption are basically the same as those defending guns.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#255Earlier quoted context omitted.
> Secret police worked when criminals were put away with parallel reconstruction, for instance. It wasn't the secret police which worked. It was the parallel construction. > “You can’t stop math.” Not true, strictly anyway. You can't stop math. > Backdoors are an antiquated way of implementing exceptional access. The proper way is to provide third party access that is truly exceptional (living up to the name), and no…
It was the secret police with pr You can stop math. Legally stop fb from using E2EE. You’ve stopped math. You haven’t stopped some people from using it. But you’ve prevented common people from having default usage of that math. Disagree. Don’t use key escrow. Find a better way. Two parties or three parties; three doesn’t have to be significantly more susceptible than two Apologies on the wording. Significantly weaker…
No, you haven't "stopped math". You've enacted a law and stopped Facebook from using end-to-end encryption.
Math is universal. Math is something that should never be outlawed. Math is a fundamental right, an irrevocable truth based solely in fact. You can sooner stop alcoholism by outlawing alcohol than you can stop encryption by outlawing math. The idea of outlawing math would put us hundreds of years behind today; to enact a truth based on the church's "do this because I tell you it's true" instead of "understand this for yourself, I cannot tell you what is true". Outlawing math is dangerous and I cannot believe you are trying to make such an argument in good faith.
> Find a better way.
I do not believe there is a better way. You don't understand the math behind it. Instead of even trying to understand the math which is already widely understood by many, you instead want to make that math illegal and create your own. You don't even want to spend the mental effort to do that much: you demand others to do it for you.
> Two parties or three parties; three doesn’t have to be significantly more susceptible than two
This is factually false. The third party is a moving party which changes every moment. You can not meet that and still be "secure". It is antithetical to the very notion of encryption.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#256> the “techlash” by Congress and the public “in the wake of myriad privacy scandals” and the 2016 election This just makes my head explode. Because tech companies tend to be poor at privacy, let's use that logic to make it so the government can invade your privacy anytime they want?
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#257Earlier quoted context omitted.
Why should Law Enforcement have a seat at the table in the design of anything? Should my sneakers be made more uncomfortable so I can't run away too fast? Should they be able to remotely disable my car? Remotely open the blinds to my home's windows? Should I not be able to install a front door that resists attempts at forced entry? What's the line where Law Enforcement's wants merit consideration?
If it comes to pass that the department of justice insists on implementation of Exceptional access it would be who’ve the civil libertarians to work towards a better compromise. Hedge your bets.
Why do you view it as unethical to not consider Law Enforcement needs wrt strong end-to-end encryption?
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#258Questions to the public should be phrased: “Do you want Chinese style surveillance to be advanced in the United States?”
+1. This is something tech bros don't seem to get, while politicians get very well: the majority is driven by emotions and has small cognitive ability, but they vote and thus arguments to win their vote must be trivial emotionally charged ideas. A politician says "encryption is a tool of criminals!" and those who start arguing in the rational plane have already lost; instead, the answer should be "lack of encryption…
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#259Earlier quoted context omitted.
One time pads are not secure by modern cryptographic standards. Elaboration: https://news.ycombinator.com/item?id=6008695
If integrity is an issue you can just add a poly1305/ghash tag to the message. They are not encryption algorithms so it is unlikely that they are going to be banned, and just like OTP they are provably secure. In addition they are not difficult to implement (or execute by hand).
Once we're past the point of users doing something beyond downloading an app from a corporate app store, all secure encryption would be back on the table.
Of course we can foresee a true ban on encryption some years out, but at that point XOR has the exact same signature as AES. Steganography is the corresponding approach for that attack.
Re: DOJ plans to strike against encryption while the Techlash iron is hot
#260A small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 6…
I think we in the tech community tend to vastly under-estimate the threat of legal restrictions on encryption. When the public gets scared, they look to governments to "do something", whether that something is really a smart thing or not. If we're unlucky and we get caught unprepared, we run the risk of getting stuck with a backdoor or "exceptional access" mechanism that provides little or no technical safeguards aga…