Earlier quoted context omitted.
Agreed. The question is. Can you perfectly, always and with regard for potential future changes to what may be sensitive information decide which ones to encrypt? One email sent the wrong way when tired. One change in legislation (to e.g. retrospectively criminalise an activity or legalise a certain type of snooping). Now your company's IP is compromised. Or now your in jail. Or now you can be blackmailed. Furthermor…
What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?
Re:publica 15: Google Promotes Privacy, But Not Too Much
51–60 of 79 posts
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#52Earlier quoted context omitted.
What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?
I think you can start investigating Joe for an email he sent 10 years ago and that your scanning algorithm picked up from the archive only now. Maybe you're searching for matches with different keywords (the X in "war on X" changed). That email and the actions could have been lawful at the time and now, but Joe could be marked as suspicious and all sort of unpleasant things can happen to him and his friends.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#53https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html In case anybody hasn't read it yet, Philip Zimmermann's essay on why he wrote PGP is very relevant to this discussion. Google is effectively saying envelopes are not meant for common use. Did you send everything by postcard back in the snail-mail days, only using an envelope when the contents was very-important? If someone saw you mailing an envelope, did the…
Not really a valid comparison. Encrypting a message is more like sending your letter in a titanium safe.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#54Earlier quoted context omitted.
Agreed. The question is. Can you perfectly, always and with regard for potential future changes to what may be sensitive information decide which ones to encrypt? One email sent the wrong way when tired. One change in legislation (to e.g. retrospectively criminalise an activity or legalise a certain type of snooping). Now your company's IP is compromised. Or now your in jail. Or now you can be blackmailed. Furthermor…
What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?
The point is that these email records are permanent not ephemeral. And therefore they have to be viewed in a more nuanced light.
For example something does not have to be a crime to come back and bite you. This could be a job losing issue, an issue that prevents you from running for public office, or even a blackmail issue. For example (and I'm not stating my position on this issue) opposing gay marriage used to in the US be an acceptable moral stance. According to what happened to Brenden Eich this is no longer the case and emails on the topic someone sent 10 years ago might come back to hurt them today.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#55Earlier quoted context omitted.
20 years of history at least provides evidence for you being wrong.
Paper envelopes dating back to 2300 years ago in China at least provides evidence for you being wrong. User-unfriendliness ≠ "not meant for"
For the majority of people, this is too much. People should not be expected to spend time manually checking the signatures on a key, and should likewise not be expected to get signatures for their key. They should not have to worry about key revocation. If a solution is not as easy as email is at the moment, it's not a solution.
So, the problems that need to be solved in an automated manner:
Finding a public key, verifying it to be authentic beyond all reasonable doubt, making it so that a new user can be trusted. Revoking the key if the device is compromised.
These problems are not new - they've been around since PGP was invented. Yet, there is seemingly no compelling answer to them that doesn't involve bringing your passport to a key signing party.
All of the end-to-end encryption systems I've seen either have some complicated handshake process before one can communicate with another, or are unauthenticated.
So, anyone who argues for widespread end-to-end encrypted communication must provide evidence that such a system can actually be produced in a way that is totally transparent to the user.
Google's doing well with this software - they're massively reducing the barrier to entry for PGP; I just don't see why people are complaining about their preaching of security gospel.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#56Earlier quoted context omitted.
I think you can start investigating Joe for an email he sent 10 years ago and that your scanning algorithm picked up from the archive only now. Maybe you're searching for matches with different keywords (the X in "war on X" changed). That email and the actions could have been lawful at the time and now, but Joe could be marked as suspicious and all sort of unpleasant things can happen to him and his friends.
If it was legal when the actions occurred, you cannot be tried. Similarly, if you committed a crime before the law was changed to allow it, then you have still broken the law.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#57Earlier quoted context omitted.
What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?
At least in the US, 'ex post facto' laws are specifically forbidden by the Constitution: http://en.wikipedia.org/wiki/Ex_post_facto_law
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#58Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#59I remember end-to-end vs. point-to-point from my crypto class back in the Pleistocene, so I thought I'd share the analogy my professor used just because I loved it: In WW2, the Allied Navies faced two main naval code strategies: Germany's and Japan's. Roughly, the Japanese Navy sent their routing information in plaintext, while the Kriegsmarin sent it in ciphertext. Because the German routing instructions were encryp…
Why not encrypt the routing separately?
A different key for each vessel would mean several passes through the encryption machine, key tables distributed through several places, and the requirement of specialized workforce where otherwise just typing stuff in a machine would do. And all the errors that come with manually dealing with that, all during a major war.
Re: Re:publica 15: Google Promotes Privacy, But Not Too Much
#60Earlier quoted context omitted.
Unfortunately their services are too convenient. I use them for almost everything I can, my reason being that they already know enough about me from my google searches, so I might as well use every other service they have. Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.
Same here. But I also pay Google for various services, and the lack of privacy bothers me enough that I would readily pay Google the relatively small amount I'm worth to them as a data source in order to get privacy. THAT's where Google's position, or at least this Google spokesman's position is wrong: I'll give up both some convenience and some money to get more privacy.
Paying for more privacy is not and probabably will never be an option.