Live data from Hacker News

Interpol plans to condemn encryption spread, citing predators

reuters.com

261–270 of 299 posts

Re: Interpol plans to condemn encryption spread, citing predators

#261

Earlier quoted context omitted.

Authoritarian states tend to be not as advanced technologically (one consequence of authoritarianism!), thus their police forces should be less efficient in general despite the increased powers. But controlling for other factors, why wouldn't enhanced surveillance help catch criminals? It's a pretty logical claim. Perhaps you should look for the evidence and bring back to us. For now, it is reasonable to accept the c…

Given the needle in a haystack effect? Common sense has proven itself wrong repeatedly It was "common sense" that merchants had to be frauds because the value of goods was universal and they had transport labor. Besides just because they can doesn't mean they will. Authoritarians are also infamous for both corruption and finding rooting out dissidents a higher priority than what most would call actual crime. All othe…

Common sense is an useful tool. It helps us estimate outcomes when data is absent or scarce, even if it's frequently unreliable. When I leave my desk to go to the bathroom yet again, I expect it to be there. Can't prove it, but it's a reasonable assumption. Without it, every human action would require scientific studies and high quality measurements.

The way to contest common sense isn't to point out that common sense is often wrong; instead, it's to provide data. My assertion is that when going against a statement strongly rooted in common sense and, YOU are the one who has the burden of proof.

Yes, perhaps authoritarians would do a worse job at catching criminals if they were omniscient? I'm not saying that you ARE wrong, just that you are LIKELY wrong and thus you should provide data to support your claims.

Re: Interpol plans to condemn encryption spread, citing predators

#263

I disagree with the tone of the comments here. Encryption is scary. Of course law enforcement is dismayed by the possibility that certain kinds of crimes could leave behind no trace at all. What these people, who want to regulate encryption, don't seem to understand is that this is the downside of living in a free society. In a free society, people can commit crimes, and sometimes they can get away with them. We've m…

> don't seem to understand is that this is the downside of living in a free society No, what they don’t understand is that the cryptography that protects your bank account is the exact same cryptography that (supposedly) makes law enforcement difficult. There’s no way to separate the two, any more than you can separate the arithmetic that is responsible for updating your bank account from the arithmetic that is respo…

Exceptional access is an architectural issue, and does not need to depend in any way on weakening of encryption. This presumes a logically implemented plan to offer exceptional access. Earlier this year, one commenter on HN pointed out a few trivial schemes to offer exceptional access in a way that doesn't compromise the encryption.

The concerns about exceptional access are about custody and access controls. If you share a secret with a 3rd person (LEO, IC, tech company), the possibility of that secret being leaked has gone up by some non-zero amount. The design of exceptional access mechanisms is therefore not only technological and procedural, but also political, etc.

For the arguments about "you cannot stop math", the concern is about the deployment of strong encryption, without exceptional access -- at scale. Policy dictates implementation of encryption at scale (by major tech companies), not math. Individuals and businesses will still be free to deploy their own encryption that doesn't offer exceptional access. It's unlikely that encryption itself will ever be attempted to be outlawed. If, for instance, you want to xor every bit of your comms with a OTP that you've shared with your overseas partner, it's unlikely that such a thing will ever be outlawed on Western public networks.

Likely, the concerns for LEO and the Intelligence Community are related to "going dark at scale" - meaning that if the big tech companies were to entirely lock out the possibility of exceptional access, the job of the criminal to hide from LEO would become trivial and accessible to all levels of criminals.

Re: Interpol plans to condemn encryption spread, citing predators

#264
post #141
post #23

Earlier quoted context omitted.

It’d probably be some new PKI on top of SSH where your private key would be held in escrow by an identity provider. e.g. Your username is your email address, and your email provider retains your key pair. It’d probably be portrayed as an improved key management solution that allows more frequent key rotations and revocations. Might even start with being required for government projects, resulting in supported impleme…

> It’d probably be some new PKI on top of SSH where your private key would be held in escrow by an identity provider. There's only a small problem here: the SSH private key is not used to encrypt the connection. It's used solely to authenticate the connection. The key used to actually encrypt and authenticate the data is an ephemeral key derived through a Diffie-Hellman key exchange during the connection establishmen…

Great point. I’ll have to dream up another dystopian fate for SSH.

Re: Interpol plans to condemn encryption spread, citing predators

#265

This is a good time to remember that police forces work for governments and not the other way around. Of course it would be easier for the police to catch bad guys if they had full-text search access to all conversations and content, worldwide. That doesn’t mean it is a good idea. They’re asking for something to make their job easier... can’t blame them for trying, and of course who doesn’t want to catch people who h…

> But it’s not their responsibility to account for negative side effects. That’s our responsibility, as citizens who are in charge of our governments. Wait, what? We have a saying in the actions and decisions of our governments (context: EU and US)? No we don't. We don't live in direct democracies. If Interpol or any police force wants to ban encryption and if that benefits who ever is in government, then that ban wi…

At least in the U.S., the reason we don't have backdoors in private encryption systems today is because of public outcry during the first "crypto wars" in the late 1990s/early 2000s.

In general, there is plenty of hard proof that public advocacy works in the U.S. See the entire environmental and union movements, for example.

Feigning helplessness in the face of corruption is not as insightful or clever as you think, and contrary to what you might think, works to suppress citizen engagement rather than spur it. "You have no power" is what your opponents want you to think. What are you helping them convince people it's true?

The reality is that citizens absolutely have the ability to affect their governments, and should make it clear that mandating encryption backdoors is not acceptable policy.

Re: Interpol plans to condemn encryption spread, citing predators

#266

Earlier quoted context omitted.

The article quotes a Unicef report that I can't find a good source for, and the Phillipines being problematic in this respect is something that is not exactly a secret, it is where a lot of 'production' happens. I'm sure if you dig around a bit you'll find lots of corroboration for that datum. Anyway, I'm on the clock and only look at HN during breaks right now, if not for that I'd be more than happy to find better r…

> The article quotes a Unicef report that I can't find a good source for, And what does this Unicef report say? > and the Phillipines being problematic in this respect is something that is not exactly a secret Terms like "problematic" are excellent for persuasion, as they exclude any quantitative component as they invoke fear. > I'm sure if you dig around a bit you'll find lots of corroboration for that datum. Like t…

Minimizing the incidence of digitally-enabled child abuse is not a winning strategy for protecting our right to use strong encryption.

For one thing, it puts you in the position of defining what incidence of child abuse is low enough to be somehow acceptable. Is the Internet helping one person to abuse a child? Any normal person would say that even one is unacceptable.

For another thing, it can easily make you look like an unserious fool because the people you're arguing with--law enforcement--are going to know way more than you do about the actual incidence of these particular crimes. They are privy to every ongoing investigation, and are generally not legally permitted to tell you about them.

We don't need to doubt the good faith of law enforcement--at least on this issue of child abuse--to advocate against encryption backdoors.

Encryption backdoors are a bad idea because they can be later abused or hacked, causing untold harm.

And we get to use strong encryption for the same reason we get to deny the government placing cameras in our houses. We get strong encryption for the same reason we get to be considered innocent until proven guilty. Efficacy or efficiency for law enforcement is not enough, and should not be enough, to supersede our rights to privacy, expression, assembly, etc.

Re: Interpol plans to condemn encryption spread, citing predators

#267

Earlier quoted context omitted.

> But it’s not their responsibility to account for negative side effects. That’s our responsibility, as citizens who are in charge of our governments. Wait, what? We have a saying in the actions and decisions of our governments (context: EU and US)? No we don't. We don't live in direct democracies. If Interpol or any police force wants to ban encryption and if that benefits who ever is in government, then that ban wi…

At least in the U.S., the reason we don't have backdoors in private encryption systems today is because of public outcry during the first "crypto wars" in the late 1990s/early 2000s. In general, there is plenty of hard proof that public advocacy works in the U.S. See the entire environmental and union movements, for example. Feigning helplessness in the face of corruption is not as insightful or clever as you think,…

>the reason we don't have backdoors in private encryption systems today is because of public outcry

I always thought the NSA gave up on its Clipper Chip initiative not because people complained, but rather because of a handful of people with the right skills or the right kind of influence engaged in civil disobedience.

Specifically, Phil Zimmermann wrote PGP and published its source code (under no-commercial-use terms, which at that time were not frowned upon as strongly as they are these days) and enough people demonstrated a resolve to keep the source code on the internet -- by continuing to host it even after being threatened by the US government -- to convince the NSA that it would never persuade enough manufacturers to adopt the Clipper Chip.

Netscape's decision to design and implement SSL and include it in the most popular browser of the day probably had a lot to do with it, too.

Re: Interpol plans to condemn encryption spread, citing predators

#268
post #135

Earlier quoted context omitted.

Sure, but then we're not talking about the vast majority of digital transgressions are we? That is, the simple (re)distribution of child pornography — ghastly enough as that is — not the few who actively seek out and order new abusive material from those who actually produce the stuff. This debate is about proportionality. How many children can live a marginally better live by giving up strong encryption and privacy…

It's easy. Someone uses encryption? Jail him regardless of the content. You can't hide the existence of the message.

Great. Might as well just jack up the consequences to the point that perpetrators realize they have everything to lose and guarantee there is no low-hanging fruit, and that whatever you do end up having to infiltrate will have a "like-your-life-depends-on-it" security posture.

This is how cures become worse than the disease. Life isn't black and white, nor do things tend to be doable without gratuitous unintended consequences.

Encryption is not, nor has it ever been the be all end all to child predation. Effective investigation techniques have been the issue, and awareness have been the problem, because of the ephemerality of any distribution system once its existence is outed to hostiles in the non-pedophilia community at large.

If you want to take these people down, you have to map the logistics. If you want to map the logistics, you have to consume content; once you have the content, you need to analyze the crap out of it for every possible clue you can about how and where it was made in order to try to make some reasonable guesses about how the production industry works, then you have to double down and go deep to figure out what these production rings look like, whether they know each other, and how do they work. I'm talking picking apart the audio for environmental noise that might clue you in, or developing profiles of certain quirks of equipment. Analyzing the medium of exchange to see if you can exploit the financial traceability aspect, etc... All of which can also be sanitized once the opponent knows you look for it by the way. Proper OPSEC on their part will leave as few breadcrumbs as possible for you to find, and the closer you get to the heart of the op, the more heinous the infiltration will likely get.

All of that has zilch to do with e2e encryption. That's all meatspace work. Ugly work, but work that'll need to happen nevertheless.

Re: Interpol plans to condemn encryption spread, citing predators

#269

Earlier quoted context omitted.

It's interesting to note that this abuser was caught precisely because people looked at the images of the abuse and figured out that they had to be from the Netherlands. I suspect that this describes a non-trivial portion of successful prosecutions - especially of those responsible for a lot of abuse, as with this case.

Yes, typically it is a bunch of coincidences that allows these cases to be solved. It's incredible the scale at which they operated and how long they got away with it.

The problem is that perpetrators are not as stereotypical as people assume-- it's not the registered offender down the street, it's not the creepy guy in aviators living out of the panel van. "To Catch A Predator" really fucked up the public's perception of abuse perpetrators.

It's almost always the victim's parent/caretaker or other close relation-- but they always "seem totally normal" so nobody wants to believe it's happening and will excuse or look past all sorts of shitty behavior that, if it were performed by some random, would elicit disgust and antipathy and cause them to be run out of town.

I'm currently dealing with an abuse case. The family is uncooperative because they don't believe the evidence presented, and the victim has been coached into protecting the perpetrator. So the abuse will continue.

Re: Interpol plans to condemn encryption spread, citing predators

#270

Earlier quoted context omitted.

You can't physically abuse over the internet though, that's my point and that's why I separated the two concepts of "removing content from the Internet" and "Protecting children from harm". The digital is an after-effect of the physical.

For starters, we can't globally protect children from poverty. This in turn opens up parents in extreme poverty (such as having to choose which kid gets enough resources to survive) to be willing to make exchanges that we cannot fathom.

We cant globally protect children from shitty parents. Abuse and exploitation happens even in households where the parents are literally given stipends to pay for the child's care and upbringing-- be it in foster care or post-divorce.

Some people just lack humanity.

Post reply on HN