Live data from Hacker News

Civics is boring, so, let's encrypt something (2024)

queue.acm.org

41–50 of 74 posts

Re: Civics is boring, so, let's encrypt something (2024)

#41
post #17

Earlier quoted context omitted.

"What if 'us' is bad" is a separable question from "is NOBUS possible". I'm not advocating for it, I'm just saying the computer science of this matters, and a lot of people have objections to the concept of NOBUS that are more ideological than empirical.

The logistics are non-trivial. If you have to be nation-state intelligence level of scale then no, you cannot maintain NOBUS level of secrecy because you have too many people involved. That sounds pretty damn empirical to me. The objections to NOBUS aren't ideological, they are moral by the way. They are literally choosing to keep vulnerabilities in place for others to discover under arrogant assumptions that they wi…

> The objections to NOBUS aren't ideological, they are moral

“ideological” and “moral”, as bases for objection, mean exactly the same thing, though people will often use “ideological” to mean “based in principles of right and wrong that I don’t agree with” and “moral” or “ethical” to mean “based in principles of right and wrong that I agree with”.

Re: Civics is boring, so, let's encrypt something (2024)

#42
post #27

This is, far and away, the most authoritarian proposal for the regulation of encryption that I have EVER seen. As far as I know, no nation on Earth has legal provisions so explicitly authoritarian as to require every civilian to maintain copies of all their communication in a form that cops can access after the fact. If I send you a letter and you promptly burn it, that does not entitle the police to imprison either…

> If I send you a letter and you promptly burn it, that does not entitle the police to imprison either of us

Aside: The fact that someone (legally) deleted data or (legally) switched to an encrypted channel may still be used against them, when establishing mens rea regarding some other actual crime.

That said, I don't want to dissuade anyone from taking steps to be safe.

Re: Civics is boring, so, let's encrypt something (2024)

#43
post #27

This is, far and away, the most authoritarian proposal for the regulation of encryption that I have EVER seen. As far as I know, no nation on Earth has legal provisions so explicitly authoritarian as to require every civilian to maintain copies of all their communication in a form that cops can access after the fact. If I send you a letter and you promptly burn it, that does not entitle the police to imprison either…

> This means, if you start a conversation with me in plaintext, I'm obliged to continue exactly as I would if we were talking through encryption. This compels speech,... I think the author would say that if you don't want to continue in plaintext, you can just not respond.

I don't think so. If you run a server that won't respond to unencrypted requests, I think that would be considered a form of forcing people to use encryption. That's the only way I can interpret "they'll need to make it a crime to force or trick anyone into using stronger encryption than they consent to, no matter how that might be done."

Refusing to respond to unencrypted requests is honestly the only thing I can think of that would really constitute "forcing someone to use encryption." (Unless they mean forcing via threats, but why would they mean that? Who's going around forcing people at gunpoint to encrypt messages?)

Re: Civics is boring, so, let's encrypt something (2024)

#44
post #8

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

NOBUS is only NOBUS until a spy gets their hands on the escrow master key (or until Donald Trump shares it at a dinner party on a lark, for that matter). If RSA's signing keys can be compromised¹, anything can be compromised.

[1]: "The Full Story of the Stunning RSA Hack Can Finally Be Told," https://www.wired.com/story/the-full-story-of-the-stunning-r...

Re: Civics is boring, so, let's encrypt something (2024)

#45
post #44
post #8

Earlier quoted context omitted.

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

NOBUS is only NOBUS until a spy gets their hands on the escrow master key (or until Donald Trump shares it at a dinner party on a lark, for that matter). If RSA's signing keys can be compromised¹, anything can be compromised. [1]: "The Full Story of the Stunning RSA Hack Can Finally Be Told," https://www.wired.com/story/the-full-story-of-the-stunning-r...

I don't understand the latter assertion. What's so special about RSA getting compromised?

Re: Civics is boring, so, let's encrypt something (2024)

#46

There are a few ideas so basically evil that just holding them, regardless of deeds, renders the speaker forfeit of the basic "shared humanity" level of comradery that I share with the vast majority of other people. This may be one of the few examples I've come across that fit that description while not falling under the normal umbrella categories of bigotry or unjustified calls for violence. This proposal isn't just…

I'm still reeling that someone had the gall to write a sentence like this and call it "good civics." It's a love letter to totalitarianism.

> Then, fourth and finally (drum roll, please!), they'll need to allow courts to jail the accused until: (a) the communication has been decrypted by someone; (b) the maximum penalty for the charged crime has been exceeded; or (c) the court decides to release the accused.

Re: Civics is boring, so, let's encrypt something (2024)

#47
post #35

Earlier quoted context omitted.

Sort of: https://blog.cryptographyengineering.com/2015/12/22/on-junip... But also, Dual EC was suspected of being backdoored from day one, was slower than existing CSPRNGs, and was therefore avoided like the plague. Whereas the premise is that if you put all the world's secrets behind one set of keys, there doesn't exist a level of defense that can withstand the level of attacks that will attract. Which doesn't apply…

That was a Juniper supply-chain backdoor, not a compromise of the Dual EC keys.

Exactly. They built a backdoor that "only they" could get into and then somebody else slipped into it anyway.

The backdoor is a vulnerability even if you don't have the keys because it requires the trappings of third party access. If you try to get something in the shape of a backdoor through code review, you should get knocked back. But if something in the shape of a backdoor is required then a change in who has the keys to the lock is much smaller, more subtle and easier to sneak in.

Re: Civics is boring, so, let's encrypt something (2024)

#48

”So, a judge who is convinced you're about to kill somebody can unleash the police to follow you everywhere in hopes of preventing that crime. Similarly, a judge who thinks your computer system contains information related to financial crimes can allow the police to hack that system. Likewise, a judge who thinks you're stalking your ex can order you to stay out of a certain part of town.” One of these things is not l…

I don't see how

Re: Civics is boring, so, let's encrypt something (2024)

#49
post #35

Earlier quoted context omitted.

Sort of: https://blog.cryptographyengineering.com/2015/12/22/on-junip... But also, Dual EC was suspected of being backdoored from day one, was slower than existing CSPRNGs, and was therefore avoided like the plague. Whereas the premise is that if you put all the world's secrets behind one set of keys, there doesn't exist a level of defense that can withstand the level of attacks that will attract. Which doesn't apply…

That was a Juniper supply-chain backdoor, not a compromise of the Dual EC keys.

Why are all of your comments consistently just nonconstructively calling other people wrong?

Re: Civics is boring, so, let's encrypt something (2024)

#50

So, if we were to implement what this author is proposing, governments would be allowed to jail people indefinitely simply because they used effectively unbreakable encryption- regardless of whether what they encrypted was illegal (or evidence of a crime)? Because if so, that is absolutely unacceptable in any society that would call itself free.

[dead]
Post reply on HN