Live data from Hacker News

Civics is boring, so, let's encrypt something (2024)

queue.acm.org

31–40 of 74 posts

Re: Civics is boring, so, let's encrypt something (2024)

#31
post #28

Earlier quoted context omitted.

> "NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS. Have any such system been built?

Have the private keys for Dual EC ever been disclosed, or is there any evidence of them having leaked?

Sort of:

https://blog.cryptographyengineering.com/2015/12/22/on-junip...

But also, Dual EC was suspected of being backdoored from day one, was slower than existing CSPRNGs, and was therefore avoided like the plague. Whereas the premise is that if you put all the world's secrets behind one set of keys, there doesn't exist a level of defense that can withstand the level of attacks that will attract. Which doesn't apply when it isn't widely used.

On top of that, the attackers would be the likes of foreign intelligence agencies, and then them not getting it and the public not hearing about them getting it are two different things.

Re: Civics is boring, so, let's encrypt something (2024)

#32
> The United Nations' new "cybercrime" treaty, readied for signatures at the time of this writing, is very much focused on how to get court orders to work quickly and efficiently across borders. Bear in mind that international bodies don't fashion treaties like this unless they think an urgent response is vital.

Truly there is no process as quick and urgency-aware as creating and signing international treaties.

Re: Civics is boring, so, let's encrypt something (2024)

#33
There are a few ideas so basically evil that just holding them, regardless of deeds, renders the speaker forfeit of the basic "shared humanity" level of comradery that I share with the vast majority of other people. This may be one of the few examples I've come across that fit that description while not falling under the normal umbrella categories of bigotry or unjustified calls for violence.

This proposal isn't just evil, it's evil in a remarkably novel way. I'm disgusted in ways normally reserved for stumbling upon a group of neonazis chatting amongst themselves.

Re: Civics is boring, so, let's encrypt something (2024)

#34
post #8

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

And then Salt Typhoon happens and suddenly it isn't NOBUS anymore and we are hosed.

Re: Civics is boring, so, let's encrypt something (2024)

#35
post #28

Earlier quoted context omitted.

Have the private keys for Dual EC ever been disclosed, or is there any evidence of them having leaked?

Sort of: https://blog.cryptographyengineering.com/2015/12/22/on-junip... But also, Dual EC was suspected of being backdoored from day one, was slower than existing CSPRNGs, and was therefore avoided like the plague. Whereas the premise is that if you put all the world's secrets behind one set of keys, there doesn't exist a level of defense that can withstand the level of attacks that will attract. Which doesn't apply…

That was a Juniper supply-chain backdoor, not a compromise of the Dual EC keys.

Re: Civics is boring, so, let's encrypt something (2024)

#36

This article frames a false choice of either designing a system that allows government access to everything you do digitally (which is now almost everything), or having the government design such a system. In reality the choice is between such a totalitarian surveillance state without the possibility of digital security guarantees, or one where police can’t read your digital mind but can do good old fashioned police…

PHK’s piece assumes that there’s a clear and effective distinctions between the government and the juducial system: The police can’t wiretap unless authorized by a judge (this could be backed by certificates/whatnot, and not just “ok, go ahead” as it is now.) However: Not all countries have this effective separation/independence between branches, and some countries which have so far enjoyed such separation are perhap…

Even in the US which has those systems, they are not robust enough for me to trust handing over the state this kind of power over all modern communication. Never have the police had this power before, even with warrants.

Backdoored encryption makes everyone unsafe while not stopping bad guys from using actual encryption. And when the bad guys use real encryption, the police can still catch them- see the case of Ross Ulbricht.

The point doesn’t stand because the magic system that only lets the good guys decrypt if only the engineers would think harder simply does not exist, and framing it this way obscures that fact and paves the way for ChatControl or encryption bans, not user freedom. We had this debate before with the Clipper chip, and reason mostly prevailed. Now we’re having it again with even higher stakes and people are arguing to give in to a framing that assumes defeat.

Re: Civics is boring, so, let's encrypt something (2024)

#37
It takes a refined form of cynical misanthropy and tanky statism to believe that on balance, people are undeserving of even having the option of their private affairs being unexamined by the authorities, and that to even attempt to hide something from their eyes is to become a criminal.

There is already a tenuous balance in terms of power and consent between the governing and the governed. On balance, more harm is done to me by those in political / financial power than by the average criminal.

I'm not convinced handing governments omniscient surveillance is worth the price it exacts.

Re: Civics is boring, so, let's encrypt something (2024)

#38
post #27

This is, far and away, the most authoritarian proposal for the regulation of encryption that I have EVER seen. As far as I know, no nation on Earth has legal provisions so explicitly authoritarian as to require every civilian to maintain copies of all their communication in a form that cops can access after the fact. If I send you a letter and you promptly burn it, that does not entitle the police to imprison either…

> This means, if you start a conversation with me in plaintext, I'm obliged to continue exactly as I would if we were talking through encryption. This compels speech,...

I think the author would say that if you don't want to continue in plaintext, you can just not respond.

Re: Civics is boring, so, let's encrypt something (2024)

#39
post #17

Earlier quoted context omitted.

At minimum, bad actors inside the government could always use the access mechanism. What's your concept for preventing other bad actors from getting it though?

"What if 'us' is bad" is a separable question from "is NOBUS possible". I'm not advocating for it, I'm just saying the computer science of this matters, and a lot of people have objections to the concept of NOBUS that are more ideological than empirical.

The logistics are non-trivial. If you have to be nation-state intelligence level of scale then no, you cannot maintain NOBUS level of secrecy because you have too many people involved. That sounds pretty damn empirical to me. The objections to NOBUS aren't ideological, they are moral by the way. They are literally choosing to keep vulnerabilities in place for others to discover under arrogant assumptions that they will be the only ones who will know.
Post reply on HN