Live data from Hacker News

A Few Thoughts on Ray Ozzie’s “Clear” Proposal

blog.cryptographyengineering.com

61–70 of 77 posts

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#61

Earlier quoted context omitted.

"Should she have the right to control where this picture of her naked is being used? Yes." This is the hard question, I argue the group should not give her the right to censor this image. Imagine she had the power to censor that image, then she might be bribed into censoring it. I think taxpayers have a right to know what happens with their money. I think the next generations have the right to know what happened, and…

Imagine we could all simply watch who how and when the double spy & daughter in Britain were possibly poisoned if so. If they were, we can try to catch them if they are still on soil, or else publicly verifiably convince people elsewhere of what happened, and then continue with higher priorities like Grenfell Tower and how to prevent such events (where many more actually died, and never even worked for the Russians,…

> It would also generate unity within the community of citizens, instead of this constant contrarianism and doubt.

Yes, it would. Via oppression. Humanity has tried that lots of times. I doubt you would want to live in any of those societies.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#62

Extremely exceptional access only, in cases where thousands of people's lives could be at stake or millions. Since we can't create a fully unbreakable software/hardware security systems anyway, if ever, companies can use technology + psychology. Unintentionally create an extremely difficult to find bug that requires extremely talented engineers and large hardware resources to break, then unintentionally share it with…

> Extremely exceptional access only, in cases where thousands of people's lives could be at stake or millions.

And how do we determine when that's actually the case and when it's overhyped or flawed intelligence?

> We don't live in a perfect world and we don't have a perfect solution.

Exactly, so focusing on phone encryption is probably a waste of time.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#63

Earlier quoted context omitted.

Imagine we could all simply watch who how and when the double spy & daughter in Britain were possibly poisoned if so. If they were, we can try to catch them if they are still on soil, or else publicly verifiably convince people elsewhere of what happened, and then continue with higher priorities like Grenfell Tower and how to prevent such events (where many more actually died, and never even worked for the Russians,…

> It would also generate unity within the community of citizens, instead of this constant contrarianism and doubt. Yes, it would. Via oppression. Humanity has tried that lots of times. I doubt you would want to live in any of those societies.

When has humanity ever used community cameras with treshold cryptography to make a provable society?

I do not propose to eliminate critical thought, I propose to eliminate the needles diversion of baseless claim and baseless counterclaim. Exactly such that critical thought is freed up to think about other problems!

We like to proud ourselves on having a system where everyone is innocent until proven guilty, but in practice innocent people are regularly convicted and guilty people regularly declared not guilty. There exists no correct a priori stance of being harsher or less harsh on false positives vs false negatives. The only way to eliminate both is relevance: gather more faithfull evidence. I believe decentralized mass surveillance to be the way out.

By removing the need to criticize questions of fact in the domain of meat space human interactions, we free up attention and critical thought to consult our feelings (ethics) about proposals and governance of our society!

I consider this the opposite of opppresion.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#64

But why? Why give the government such a ripe target for abuse? Why tilt the balance of power even further in its favor?

Many people, especially those outside the tech community, do not view law enforcement as an adversary. In the US, the balance that we have struck is that the government cannot search our property, except upon probable cause (fourth amendment). While I personally don't like it, I think that warrant-based key escrow is reasonable from a policy perspective.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#65

Can anyone explain why the government wouldn't just mandate that they be given all the keys from the start? Why would they put up with Apple as a middleman who could potentially refuse their requests? Also, this key escrow scheme is near impossible to scale to more than one government. Now we need a way to authenticate government agents, good luck with that.

The government would be a single point of failure so it's cheaper and more secure to privatize. Also, private control of keys acts as a check upon government abuse.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#66

Just a nitpick. Matthew Green uses the analogy of signing keys being leaked often as evidence that Ozzi’s proposed system would be similarly not secure. This is a weak analogy: signing private keys are often leaked because their use case requires them to be “online” in some fashion (code must be signed with the private key so it can be verified with the public key). Similarly, CAs must use private keys operationally…

Code signing and decryption both require access to the private key, possibly through a hardware security module. I don't see why decryption has less exposure.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#67

Earlier quoted context omitted.

"Should she have the right to control where this picture of her naked is being used? Yes." This is the hard question, I argue the group should not give her the right to censor this image. Imagine she had the power to censor that image, then she might be bribed into censoring it. I think taxpayers have a right to know what happens with their money. I think the next generations have the right to know what happened, and…

> This is the hard question, I argue the group should not give her the right to censor this image. Sacrificing people's dignity for the supposed common good it very much not a road I am willing to go down. If we are willing to sacrifice an individual's dignity, there is nothing left worth sacrificing it for. Mind you that this is distinct from limited use for the purposes of prosecution. > Imagine she had the power t…

First, I wish to thank you for keeping this discussion alive, I really value the opinions of others on this idea (which is also the result of refining earlier formulations by the opinions of others)

"Sacrificing people's dignity for the supposed common good it very much not a road I am willing to go down."

I don't see how my system sacrifices a person's dignity? Could you describe how my proposals would destroy dignity in your view? Here are some definitions of dignity:

* The quality or state of being worthy of esteem or respect.

* Inherent nobility and worth: the dignity of honest labor.

* Poise and self-respect.

Or are you talking about the dignity of people previously working in centralized law enforcement systems who would then appear superfluous/ineffective/archaic/unproductive/dangerous to citizens in my system? Like we view say slave-holders today?

"Yeah, and then imagine I could strip you of your human rights because I value a common good higher than your human rights."

I don't see how you could do that to me in my system. Or rather, you could, but you couldn't get away with it. Either you let me go at some point and I report the time and place of the events, so you get caught and do prison time. Or you don't let me go or kill me and my friends and family report me as missing, at which point I get tracked down and they find us alive, or me dead, and then later you get caught and do prison time.

"Also, no matter what the law, you cannot completely prevent that people will try to put pressure on other people."

I am not trying to prevent pressure in general, i.e. price communication is pressure too, I am specifically trying to design a system such that illegal pressure can be provably adressed. Say you hold a knife to my throat and pressure me to give my wallet, I can then report and prove that.

"For one, the checks and balances we have today are a sort-of implementation of the same fundamental idea of decentralizing power"

I totally disagree, my goal is a provably law enforcing society, not a trusted law enforcing society.

This provable/verifiable decentralized mass surveillance I proposee stands to the current trusted law enforcement systems in an analogous way as the concept of provable/verifiable cryptocurrencies stand to the current trusted financial system.

I also saw you used the phrase "democratized mass surveillance": note I systematically used the word decentralized, not democratized, there is a difference there, for example we don't directly vote on a trial, nor on wheither or not to decrypt imagery when something is reported, democracy is for the legislative branch, this proposal describes a decentralized executive branch or law enforcement (treshold crypto + cameras + client software + properly trained citizens in occasional police role)

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#68

Personally I believe real world actions should be the focus of surveillance. The empires are simply trying to cheap out by focusing on surveillance of computer activity. This is the most profound part of Matthew Green's piece in my opinion: "While this mainly concludes my notes about on Ozzie’s proposal, I want to conclude this post with a side note, a response to something I routinely hear from folks in the law enfo…

Regarding your distinction between real and cyber crimes, digital evidence can certainly be relevant in a murder case, e.g. iMessages, location history, search history. Also, the read-only bricking chip tries to allow search but exclude ongoing surveillance, though I don't think it's technically feasible.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#69
post #56

Bricking the phone works against law enforcement by only allowing raw access to the data. Even if Clear worked correctly, law enforcement couldn't open apps and see the data in the correct context. They'd have raw data files full of indexes, hashes, and cached data. Worse, apps would start to encrypt data on the client specifically to avoid Clear. The only significant change between plain key escrow and Clear (bricki…

Apps could potentially work in read-only mode. Plus it's pretty easy to design a tool to pretty print iMessages given raw data, and that alone would be very useful for law enforcement.

Re: A Few Thoughts on Ray Ozzie’s “Clear” Proposal

#70
I don't want this scheme. I don't want key escrow. But, a critique in the document is a 'if lost, lost forever' moment. If the escrow DB is compromised, the article says all phone are now pwned. For that point in time, true.

But phones are online devices. why does the escrow key have to be a constant, which if the central store is compromised means all phones prior to that date are compromised forever?

eg, re=spin the per-phone keygen on some cycle, and you define a window of risk, but it passes. re-spin clearly has to pass through some protocol, but we've been doing ephemeral re-key forever with websites.

Post reply on HN