Live data from Hacker News

Encryption Is Not a Crime

privacyguides.org

41–50 of 222 posts

Re: Encryption Is Not a Crime

#41

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

That expiration is impossible to enforce. If you have the data and the cert, you can use it whenever you'd like, and the only thing preventing you from doing so is some piece of software voluntarily choosing to comply.

What that means is, there exists a master key in your scheme.

Re: Encryption Is Not a Crime

#42
post #23

If we had trustworthy governments, or trustworthy police agencies, then maybe mandated backdoors wouldn't be all that bad. But if anything, recent events that clearly demonstrated that governments are not trustworthy, even if one is trustworthy today it couldn't become an evil regime tomorrow, and handing all your power over literally anything to such an organization does not seem wise.

It doesn't seem like trustworthy governments is the issue. You can't have backdoors period because they'll be leaked / discovered and used by bad actors. https://www.youtube.com/watch?v=VPBH1eW28mo

That too. But even if the government was perfect and trustworthy and free of leaks, that can still all go out the window as soon as a less trustworthy government is elected.

Re: Encryption Is Not a Crime

#43

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

Prior to expiry would suggest the encryption is broken from the start.

Although I do disagree on the reasonable/unreasonable angle, because I don't tend to analogize the contents of your phone to the contents of your safe, but rather to the contents of your mind.

Re: Encryption Is Not a Crime

#44

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

That sounds like a golden key approach, and the problem is your communication is no longer protected by math, it's only protected by the will of a stranger to be tortured by the government to protect you

https://www.rsaconference.com/library/blog/a-golden-key-to-u...

The back and forth discussion on cryptography is happening because there just isn't much middle ground. Either someone else can read your messages, or nobody else can. If one person can read them, the government will push on then until they crack.

Re: Encryption Is Not a Crime

#45

This is too many words to convince someone who already doesn’t believe this. Put more simply: the modern internet doesn’t work without encryption, it is a fundamental part of the technology. Without it, anyone could log into any of your accounts, take your money, messages, photos, anything.

>Put more simply: the modern internet doesn’t work without encryption

being pandantic that should read - the modern usage of the internet..

the internet does work ok without encryption, has it has done from a long time ago

Re: Encryption Is Not a Crime

#46
post #23

If we had trustworthy governments, or trustworthy police agencies, then maybe mandated backdoors wouldn't be all that bad. But if anything, recent events that clearly demonstrated that governments are not trustworthy, even if one is trustworthy today it couldn't become an evil regime tomorrow, and handing all your power over literally anything to such an organization does not seem wise.

I am against it as a matter of principle.

Even if you trust someone with your life and you know this person is never going to betray you and will always have your best interests at heart, that doesn't mean that they automatically get a free pass to view and inspect everything I do every minute of every day until I die.

Unfortunately, that is what these governments want.

Re: Encryption Is Not a Crime

#47

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

Well if decryption is so justified then brute force breaking that takes significant resources so it's hard to unnoticeably misuse would be a good approach. When you can only break into 100 phones a year, then there's no slippery slope or fascist governments that could wildly misuse it for their own gain because it's not physically viable.

Re: Encryption Is Not a Crime

#48

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

> issued by the device manufacturer or application creator The problem is that if the application has the power to do this then the rest is irrelevant The means hackers/governments/the CIA can force the application creator to do their bidding and enable mass surveylance

I don't accept that. We have "master keys" for some forms of encryption right now in the form of root certificates; knowing that root cert authorities could issue certificates that might allow people to sniff my network traffic doesn't keep me awake at night.

Re: Encryption Is Not a Crime

#49
post #28

Earlier quoted context omitted.

My favorite version of it is "Let's ban air because terrorists breathe".

Guantanamo Bay was a thing though. Remember you are not banning all air. And of course the definition of terrorist is will vary based on what politicians want. US recently sent some "Terrorists" to a gulag for example.

> Remember you are not banning all air.

Nope, it's about exactly that. This policy would work only for law-abiding citizens which terrorists are not, that's the point.

Added: The current gulag expeditions in US nor Guantanamo have nothing to do with US citizens, which is a big difference from GGP's comment.

Re: Encryption Is Not a Crime

#50
post #41

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

That expiration is impossible to enforce. If you have the data and the cert, you can use it whenever you'd like, and the only thing preventing you from doing so is some piece of software voluntarily choosing to comply. What that means is, there exists a master key in your scheme.

Certificates expire right now. It's in the schema for how PKI works. Why can't the issued cert expire in the same way?
Post reply on HN