Live data from Hacker News

Civics is boring, so, let's encrypt something (2024)

queue.acm.org

51–60 of 74 posts

Re: Civics is boring, so, let's encrypt something (2024)

#51
post #46

There are a few ideas so basically evil that just holding them, regardless of deeds, renders the speaker forfeit of the basic "shared humanity" level of comradery that I share with the vast majority of other people. This may be one of the few examples I've come across that fit that description while not falling under the normal umbrella categories of bigotry or unjustified calls for violence. This proposal isn't just…

I'm still reeling that someone had the gall to write a sentence like this and call it "good civics." It's a love letter to totalitarianism. > Then, fourth and finally (drum roll, please!), they'll need to allow courts to jail the accused until: (a) the communication has been decrypted by someone; (b) the maximum penalty for the charged crime has been exceeded; or (c) the court decides to release the accused.

IIRC studies show that people with authoritarian personalities don't see anything wrong with authoritarianism - it just feels normal to them.

Re: Civics is boring, so, let's encrypt something (2024)

#52
post #48

”So, a judge who is convinced you're about to kill somebody can unleash the police to follow you everywhere in hopes of preventing that crime. Similarly, a judge who thinks your computer system contains information related to financial crimes can allow the police to hack that system. Likewise, a judge who thinks you're stalking your ex can order you to stay out of a certain part of town.” One of these things is not l…

I don't see how

Information gathering, information gathering, restriction of physical presence.

It raises eyebrows because it’s almost as if it wasn’t a random example.

Re: Civics is boring, so, let's encrypt something (2024)

#53
post #50

So, if we were to implement what this author is proposing, governments would be allowed to jail people indefinitely simply because they used effectively unbreakable encryption- regardless of whether what they encrypted was illegal (or evidence of a crime)? Because if so, that is absolutely unacceptable in any society that would call itself free.

[dead]

I don't know what country you think that is true in, but citation needed.

In the US at least, criminal convictions must be proven "beyond a reasonable doubt", they can't just say that they think there's information there, it must be proven that they already know it's there.

Re: Civics is boring, so, let's encrypt something (2024)

#54
This was hard to tolerate.

Can someone explain to me why wiretapping can't just.. evolve? Upon a court order, send a guy to bug someone's house with cameras and watch him put in his password. Use a microphone to listen to him type in his password, perhaps even from a distance, then use some open source tool to convert the audio data into keypresses & similar. Order the ISP to copy the packets for you so you can do traffic analysis. Order companies the guy has accounts on to cough up whatever data they actually have access to. Intercept his mail. Follow him around.

Encryption doesn't prevent any of these things, so what's with all the focus on it? Wiretapping was never zero cost, and we the people only consented to the norm of court ordered wiretapping in a world in which it took some effort to do. It ought to stay difficult.

Re: Civics is boring, so, let's encrypt something (2024)

#55
post #35

Earlier quoted context omitted.

That was a Juniper supply-chain backdoor, not a compromise of the Dual EC keys.

Exactly. They built a backdoor that "only they" could get into and then somebody else slipped into it anyway. The backdoor is a vulnerability even if you don't have the keys because it requires the trappings of third party access. If you try to get something in the shape of a backdoor through code review, you should get knocked back. But if something in the shape of a backdoor is required then a change in who has the…

No, that's exactly what didn't happen here. The attackers in this case got and maintained for years the ability to slip code into Juniper/Netscreen releases. That the backdoor they chose happened to replace NSA's NOBUS backdoor is just a funny detail.

Re: Civics is boring, so, let's encrypt something (2024)

#56

It takes a refined form of cynical misanthropy and tanky statism to believe that on balance, people are undeserving of even having the option of their private affairs being unexamined by the authorities, and that to even attempt to hide something from their eyes is to become a criminal. There is already a tenuous balance in terms of power and consent between the governing and the governed. On balance, more harm is do…

This quote from the original article reveals its author's fruitless strain to justify his ridiculous idea:

"(Note that IT liberalists who claim encryption is a human right never realize this should also include the right not to be forced to use encryption against one's will.)"

It would be true in context only if the users were given two options, like two buttons: "Click here for strong encryption" and "Click here for breakable stuff".

Who would click the breakable stuff? Yeah, me neither.

Re: Civics is boring, so, let's encrypt something (2024)

#57

It takes a refined form of cynical misanthropy and tanky statism to believe that on balance, people are undeserving of even having the option of their private affairs being unexamined by the authorities, and that to even attempt to hide something from their eyes is to become a criminal. There is already a tenuous balance in terms of power and consent between the governing and the governed. On balance, more harm is do…

This quote from the original article reveals its author's fruitless strain to justify his ridiculous idea: "(Note that IT liberalists who claim encryption is a human right never realize this should also include the right not to be forced to use encryption against one's will.)" It would be true in context only if the users were given two options, like two buttons: "Click here for strong encryption" and "Click here for…

Yeah, utterly laughable.

I'm not even sure who he's railing against with that. Is it violation of my human rights that I'm "forced" to use IPv4 or TCP/IP by my ISP, or HTTPS by my bank?

As far as being "forced" to use encryption; unless I'm missing something, I can't think of a law that would preclude my transmission of communications with another individual in plaintext. I'm free to use HTTP instead of HTTPS on my website, should I so choose.

And even if there were such a law, I'd be hard-pressed to figure what harm is being done to me (much less deprivation of human right).

Re: Civics is boring, so, let's encrypt something (2024)

#58
post #55

Earlier quoted context omitted.

Exactly. They built a backdoor that "only they" could get into and then somebody else slipped into it anyway. The backdoor is a vulnerability even if you don't have the keys because it requires the trappings of third party access. If you try to get something in the shape of a backdoor through code review, you should get knocked back. But if something in the shape of a backdoor is required then a change in who has the…

No, that's exactly what didn't happen here. The attackers in this case got and maintained for years the ability to slip code into Juniper/Netscreen releases. That the backdoor they chose happened to replace NSA's NOBUS backdoor is just a funny detail.

I don't think it's actually irrelevant; there's a reason they did it that way. Getting commit access and being the only one who can even read the code are two very different things. Even if you can modify the code, the less obvious it is that the change is adding a backdoor the less likely someone else is to catch you.

Re: Civics is boring, so, let's encrypt something (2024)

#59
post #55

Earlier quoted context omitted.

No, that's exactly what didn't happen here. The attackers in this case got and maintained for years the ability to slip code into Juniper/Netscreen releases. That the backdoor they chose happened to replace NSA's NOBUS backdoor is just a funny detail.

I don't think it's actually irrelevant; there's a reason they did it that way. Getting commit access and being the only one who can even read the code are two very different things. Even if you can modify the code, the less obvious it is that the change is adding a backdoor the less likely someone else is to catch you.

I think it would be so difficult to convince me that a state-level adversary who has obtained persistent access to Netscreen's builds can't hide arbitrary backdoors that it isn't really worth hashing this out. I'm just going to point out again that the Netscreen attack didn't break the "NOBUS" property of Dual EC --- so far as we know, the Dual EC private keys have never leaked.

Re: Civics is boring, so, let's encrypt something (2024)

#60
post #45
post #44

Earlier quoted context omitted.

NOBUS is only NOBUS until a spy gets their hands on the escrow master key (or until Donald Trump shares it at a dinner party on a lark, for that matter). If RSA's signing keys can be compromised¹, anything can be compromised. [1]: "The Full Story of the Stunning RSA Hack Can Finally Be Told," https://www.wired.com/story/the-full-story-of-the-stunning-r...

I don't understand the latter assertion. What's so special about RSA getting compromised?

They're a world-class security organization. If a nation-state actor can get access to their most important keys the hard way, then a nation-state actor has a decent shot at compromising any private key on the planet, if they're willing to put enough money into it.
Post reply on HN