Live data from Hacker News

Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

cyber.law.harvard.edu

31–40 of 82 posts

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#31
post #21

Earlier quoted context omitted.

Incorrect, if the key is shared the encryption is breakable. If you're just doing one round of XOR it's pretty easy to break the key given a known plaintext, in the same way that AES is very breakable in ECB mode. For unbreakable encryption, I'd suggest XORing with the contents of /dev/random (assuming /dev/random is unknowable). Of course decryption may be an issue.

Wrong. It's just not secure in all contexts e.g. your example where you have a known plaintext that you can use to crack the key which then lets you decrypt something encrypted with the same key. You're discovering why XOR isn't widely used in a real-world setting.

[deleted]

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#32
post #23
post #21

Earlier quoted context omitted.

Incorrect, if the key is shared the encryption is breakable. If you're just doing one round of XOR it's pretty easy to break the key given a known plaintext, in the same way that AES is very breakable in ECB mode. For unbreakable encryption, I'd suggest XORing with the contents of /dev/random (assuming /dev/random is unknowable). Of course decryption may be an issue.

In context, I'm sure the parent commenter meant "a random key the same length as the plaintext", not a repeating key or a reused key.

Some people when faced with an encryption problem think 'I know, I'll use a non-repeating random text to XOR against the plain text', now they have two encryption problems.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#33
post #22

This fake crisis of "Going Dark" as if we haven't been that way for all of time before the Internet is dangerous. The "scary" notion that the police won't be able to read everything about everyone is being recast by the Feds as if it really is national crisis. Benjamin Wittes suggests on Lawfare we make Common Carrier Immunity conditional on the company being able to make all data available in the clear to the govern…

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

Warrants have never enabled truly limitless powers of search. Aerial search, blood tests, etc are new inventions, and nothing says that technology always favors the searcher. "Unprecedented" just means "get used to it."

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#34
post #22

This fake crisis of "Going Dark" as if we haven't been that way for all of time before the Internet is dangerous. The "scary" notion that the police won't be able to read everything about everyone is being recast by the Feds as if it really is national crisis. Benjamin Wittes suggests on Lawfare we make Common Carrier Immunity conditional on the company being able to make all data available in the clear to the govern…

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

"While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text."

That would be mildly interesting - if this were a 4th amendment issue. It's not.

It is a first amendment issue. If I choose to communicate with you with a (seemingly) random stream of numbers, that is protected by the 1A of the Bill of Rights. Just like a KKK rally.[1] Just like burning a cross.[2] Just like Piss Christ.[3]

[1] https://en.wikipedia.org/wiki/Brandenburg_v._Ohio

[2] https://en.wikipedia.org/wiki/Virginia_v._Black

[3] https://en.wikipedia.org/wiki/Piss_Christ

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#35
post #22

Earlier quoted context omitted.

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

Prior to the Internet, cipher schemes existed that could delay or foil the best government analysts, and that took significant government efforts to even attempt to crack. It was never illegal to use such a code and transmit the result on a letter, postcard, or phone. And a government warrant would not compel the decipherment of such a scheme, unless someone had possession of a physical key usable for decipherment. T…

It's mostly not about banning encryption though. The debate mostly centers on regulating the products and services companies can provide to facilitate such communications. If there was a precursor to companies promising to make it easy for regular joe criminal to encrypt his postal mail, it's conceivable that the government would have fracked down on those companies.

> It's one with only one right answer, but it's a "crisis" in the sense that no possible path forward will make both parties happy, so we fundamentally need the government to either realize they're wrong or to lose. Government positions don't change easily, and governments do not like to lose.

It's not the "government" versus "the people." It's a small group of people who strongly support surveillance, a small group who strongly oppose it, and a mushy middle that tends to lean towards whatever makes them feel safe. People in each group are represented within government, though for obvious reason people in the first group tend to gravitate toward positions involving national security or defense.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#36
post #34
post #22

Earlier quoted context omitted.

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

"While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text." That would be mildly interesting - if this were a 4th amendment issue. It's not. It is a first amendment issue. If I choose to co…

[deleted]

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#37
post #22

This fake crisis of "Going Dark" as if we haven't been that way for all of time before the Internet is dangerous. The "scary" notion that the police won't be able to read everything about everyone is being recast by the Feds as if it really is national crisis. Benjamin Wittes suggests on Lawfare we make Common Carrier Immunity conditional on the company being able to make all data available in the clear to the govern…

While I oppose things like encryption backdoors, I think it's disingenuous to say this is a "fake crisis." The 4th amendment has always required balancing security and privacy--that's why the distinction between "unreasonable searches" and reasonable ones appears right there in the text. And society has always balanced those two interests with a simple mechanism: the police can only search with a warrant, but once th…

What's unprecedented to an even greater degree is the scale at which mundane communications are now recorded. In the past, the bulk of private communications were opaque to the government, even with a warrant, because people exchanged private information mostly verbally, face to face.

Today many analogous conversations take place online, in instant messages, in email, and in other persistent media. Even when the content of a communication isn't recorded as an artifact of its medium of expression and transmission, there's almost always a record left behind to indicate that the communication took place, revealing associations and hinting at what was said.

So by emphasizing the legal history of searches of "long-distance communications", you've moved the goalposts by a mile. Changes in the way we communicate with one another, reflecting changes in communications technology (and changes in society), mean that governmental powers in searches and surveillance, powers which formerly applied only to relatively rare forms of communication, now apply very broadly. At the same time the government's cost of performing such searches and surveillance has plummeted, multiplying the power of police and spies to monitor our words and use them against us.

It's an unprecedented state of affairs, indeed.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#38
Why do we need to agree? That's how this works. You compromise a bit, and they don't budge. Then you compromise again. Repeat the process until all liberties are gone.

Also, why is this framed as "going dark"? That's the ignorant people's wording. Why doesn't the author call it what it is: key escrow, or back-dooring? Use the terms of the industry you are talking about.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#39
post #35

Earlier quoted context omitted.

Prior to the Internet, cipher schemes existed that could delay or foil the best government analysts, and that took significant government efforts to even attempt to crack. It was never illegal to use such a code and transmit the result on a letter, postcard, or phone. And a government warrant would not compel the decipherment of such a scheme, unless someone had possession of a physical key usable for decipherment. T…

It's mostly not about banning encryption though. The debate mostly centers on regulating the products and services companies can provide to facilitate such communications. If there was a precursor to companies promising to make it easy for regular joe criminal to encrypt his postal mail, it's conceivable that the government would have fracked down on those companies. > It's one with only one right answer, but it's a…

> The debate mostly centers on regulating the products and services companies can provide to facilitate such communications.

You're calling them products but the relevant thing they want to regulate is still more speech.

If you want to communicate with your friends in code then you first have to communicate the code itself. In this context the code is code, but code is speech.

Re: Don't Panic: Seeking Points of Agreement on the “Going Dark” Debate

#40
post #35

Earlier quoted context omitted.

Prior to the Internet, cipher schemes existed that could delay or foil the best government analysts, and that took significant government efforts to even attempt to crack. It was never illegal to use such a code and transmit the result on a letter, postcard, or phone. And a government warrant would not compel the decipherment of such a scheme, unless someone had possession of a physical key usable for decipherment. T…

It's mostly not about banning encryption though. The debate mostly centers on regulating the products and services companies can provide to facilitate such communications. If there was a precursor to companies promising to make it easy for regular joe criminal to encrypt his postal mail, it's conceivable that the government would have fracked down on those companies. > It's one with only one right answer, but it's a…

> It's mostly not about banning encryption though. The debate mostly centers on regulating the products and services companies can provide to facilitate such communications.

Banning effective encryption, or banning commercial encryption, is still effectively banning encryption, or forcing it underground and casting suspicion on it.

> It's not the "government" versus "the people." It's a small group of people who strongly support surveillance, a small group who strongly oppose it, and a mushy middle that tends to lean towards whatever makes them feel safe. People in each group are represented within government, though for obvious reason people in the first group tend to gravitate toward positions involving national security or defense.

The people within government who oppose backdoors have yet to be very vocal, or effective. I'd certainly love to see a large outpouring of support from government, to counter the level of support for the pro-backdoor position.

Post reply on HN