Live data from Hacker News

Encryption Is Not a Crime

privacyguides.org

31–40 of 222 posts

Re: Encryption Is Not a Crime

#31
post #23

If we had trustworthy governments, or trustworthy police agencies, then maybe mandated backdoors wouldn't be all that bad. But if anything, recent events that clearly demonstrated that governments are not trustworthy, even if one is trustworthy today it couldn't become an evil regime tomorrow, and handing all your power over literally anything to such an organization does not seem wise.

It doesn't seem like trustworthy governments is the issue. You can't have backdoors period because they'll be leaked / discovered and used by bad actors.

https://www.youtube.com/watch?v=VPBH1eW28mo

Re: Encryption Is Not a Crime

#32

Not a crime, but somehow our dear EU overloads try every year or so to make it a crime in any way possible (eg. chat control). If we want to play in a world with full transparency, let's start with the politicians!

The same people who want to make encryption a crime (like Trump 45[0]) are using signal to discuss sensitive information without an audit trail. It's absolutely rules for thee. 0 - https://www.politico.com/story/2019/06/27/trump-officials-we...

Same with Chat Control. LEO and EU Mps would be exempted from being surveilled because their lives and communications need to be private since they are very important but yours, god no!

And people wonder why democracy is out of style. With democrats such as these, you don't need tyrants.

Re: Encryption Is Not a Crime

#33

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

If the OEM can issue such a certificate, it probably isn’t necessary, because they can access the data and be subpoenaed directly, no?

Re: Encryption Is Not a Crime

#34
I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult".

It puts the idea into the world that it could be a crime and maybe that it is the status quo.

Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on.

Maybe "Don’t let them take your right to privacy."

Re: Encryption Is Not a Crime

#35
post #14

> It's not a crime to lock your home's door for protection, why would it be a crime to lock your digital door? A locked home's door is still trivially opened. You can pick the lock or even apply simple brute force, neither of which all that difficult, and open happily it will. Similarly, I don't suppose anyone would be concerned about you using rot13 encryption. If a home could be sealed to the same degree as strong…

Under what law? High security vaults are not legally controlled or prohibited in the US.

Which high security vault can the government not gain access to under any circumstances? I expect you'll find decent explosives or a bulldozer will get them in just fine.

Re: Encryption Is Not a Crime

#36

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

> issued by the device manufacturer or application creator

The problem is that if the application has the power to do this then the rest is irrelevant

The means hackers/governments/the CIA can force the application creator to do their bidding and enable mass surveylance

Re: Encryption Is Not a Crime

#37
post #25
post #21

Earlier quoted context omitted.

The arguments are mostly that they dislike what can be accomplished via math. “The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia” isn't exactly an 'argument' so much as an insistence. The article does address the flaws in some of their arguments (encryption inconveniences law enforcement, think of the children) by pointing out that the average person and…

You can make gun fairly easily with what can be accomplished with a CNC machine. It is still illegal.

Where that is illegal they don't go making CNC machines illegal because of that.

Re: Encryption Is Not a Crime

#38
post #23

If we had trustworthy governments, or trustworthy police agencies, then maybe mandated backdoors wouldn't be all that bad. But if anything, recent events that clearly demonstrated that governments are not trustworthy, even if one is trustworthy today it couldn't become an evil regime tomorrow, and handing all your power over literally anything to such an organization does not seem wise.

I have yet to see a case against someone that hinged on some data that was encrypted. Almost every tale from some cell needing to be cracked has ended in a fart because they got the information anyway using old-fashioned police investigation.

We went from Patriot Act to literally disappearing people without due process in only 23 years. Imagine if they could also decrypt your phone and plant evidence in advance.

Re: Encryption Is Not a Crime

#39

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

If the OEM can issue such a certificate, it probably isn’t necessary, because they can access the data and be subpoenaed directly, no?

Yes, I am arguing for is requiring OEMs to implement this mechanism.

Frankly, if the NSA wanted to have Apple build a custom iOS version for a criminal so they could sniff his network traffic and flash content from the comfort of Maryland I don't believe that would be impossible today.

Re: Encryption Is Not a Crime

#40
post #4

There's an abstract argument template that I've noticed floating around. It goes like this: 1. There's a thing T in the world, and that thing has negative outcomes X, Y, Z, and positive outcomes A, B, C. 2. Some people believe that Y and Z are so bad, that they want to partly compromise C to diminish them. 3. However that will never work! And they'll definitely also take B if we let them mess with C. 4. Besides, C is…

That's a template, yes. But why is it bad?
Post reply on HN