Live data from Hacker News

Attorney General William P. Barr Delivers Address Conference on Cyber Security

justice.gov

61–70 of 230 posts

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#61
post #36

Earlier quoted context omitted.

Sure, but I can just refuse to decrypt my data. They can just break physical locks.

This is what a lot of people in our community seemingly refuse to recognize. For all intents and purposes, encryption is a unbreakable lock that can serve to perfectly hide valuable criminal evidence. Such a thing wasn't possible when our laws were written and has never before been possible in the physical world. Its existence has potential to be a huge shift in how we enforce the law. Regardless of our views on encr…

> For all intents and purposes, encryption is a unbreakable lock that can serve to perfectly hide valuable criminal evidence.

This doesn't matter. Our rights are not premised on the ultimate physical availability of any given piece of information. There's no "we can always break into the safe" provision of the 4th Amendment.

Fundamentally, the government does not have the right to any piece of your information. A warrant grants them the temporary right to employ certain techniques to try to get it.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#62

He claims encryption is "warrant proof" which is not true. You can have a court order someone to open the lock. They want the ability to dig through people's stuff without them knowing. That's what it's really about.

Sure, but I can just refuse to decrypt my data. They can just break physical locks.

Sure, you can also destroy evidence! This is already a crime we deal with. Encrypting and throwing away the key is deleting with more steps - in fact it is often an implementation detail of deletion in some software systems. It is already illegal, and already something our justice system deals with. No power grabs necessary.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#63
post #2

Did he basically just announce a false flag? "Obviously, the Department would like to engage with the private sector in exploring solutions that will provide lawful access. While we remain open to a cooperative approach, the time to achieve that may be limited. Key countries, including important allies, have been moving toward legislative and regulatory solutions. I think it is prudent to anticipate that a major inci…

More likely transparent opportunism, in my opinion.

Which is also bad and gross.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#66
post #9

Earlier quoted context omitted.

I'm no fan of Bill Barr, but I don't read this that way, no. It reads to me more like he's saying that from a planning perspective it's better to figure the worst thing that could happen and have a plan already developed that could handle that, rather than being caught by surprise and then having law and policy made in a mad, panicked rush. (In other words, let's not do with cybersecurity policy what we did with coun…

This is how I interpreted it. It seems like a wise, level-headed approach.

Yes. But I think it's also a trick. He wants us to accept that we have not already had the debate. He and those who think like him will continue to use this line until they get an outcome they like.

And, by the way, we have had the debate--even, arguably, in the midst of a crisis. This was all over the news for weeks after the shooting in San Bernardino when the FBI told us it was vitally important to gain access to the perpetrator's phone. They didn't get their back door. Legislation was proposed that would have required it, but it was never adopted. (Though, in fairness, FBI did supposedly get a private company to break the encryption. But this was only after a very long delay and after all the public debate had largely dies down.)

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#67
post #8

Matt Blaze spent yesterday discussing this on Twitter: https://twitter.com/mattblaze/status/1153708198718840832 His Twitter feed is well worth a follow if you care about these issues.

You know how every cryptographer and security person feels when this comes up? Like the poor schmuck at NASA who signed up to explore space but instead has to spend their day explaining why the moon landing wasn't a hoax. Again and again.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#68
post #36

Earlier quoted context omitted.

Sure, but I can just refuse to decrypt my data. They can just break physical locks.

This is what a lot of people in our community seemingly refuse to recognize. For all intents and purposes, encryption is a unbreakable lock that can serve to perfectly hide valuable criminal evidence. Such a thing wasn't possible when our laws were written and has never before been possible in the physical world. Its existence has potential to be a huge shift in how we enforce the law. Regardless of our views on encr…

Cryptography has existed for over 3000 years [1], steganography [2] has been documented in use over 2000 years ago and it's possible it has been used much longer (the entire point is we wouldn't know).

If encryption is being used to hide "valuable criminal evidence", how is that different from someone hiding evidence by burying it somewhere or simply destroying it?

We don't detain random people and force them to give up locations of bodies they may or may not have buried, and we don't randomly search people's houses and posesssions -- and we shouldn't be doing the same for encrypted data (and this includes requiring backdoors). If there is other evidence to believe a particular person committed a crime, then get a warrant that compels them to give up the location of the body or the encryption key. If they refuse, then depending on the other evidence used for the warrant it might make sense to hold them in contempt.

In my mind, decrypting data to prove your innocence (in the face of other evidence) is vastly different than decrypting your data because law enforcement is on a fishing expedition (no other evidence).

[1] https://en.wikipedia.org/wiki/History_of_cryptography#Antiqu...

[2] https://en.wikipedia.org/wiki/Steganography

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#69

A specific claim of the AG, and one that I've seen relatively smart people assert before, is that software update systems could be adapted to insert these backdoors into individual phones, securely and reliably, upon receipt of a valid warrant. Software update systems have been successfully exploited to deliver malware: > On a normal day, these servers push out routine updates—bug fixes, security patches, new feature…

> And even then, it's not clear that these software update systems are even capable of targeting patches down to the level of the phone of an individual person. There's no reason for it now.

There is reason against it now, because it makes it impossible to do things like reproducible builds or other security checks like comparing the software being offered to other devices to verify that none of them is being offered compromised updates before installing any of them.

It would also require prohibiting the transparency necessary to implement any of those checks independently, or anyone could do so and then use that to detect the attack regardless of whether or not the attackers are domestic state sponsored.

Re: Attorney General William P. Barr Delivers Address Conference on Cyber Security

#70

If the US Government succeeds in requiring a backdoor then so will every other government. Does anyone really think China won’t immediately demand backdoors?

I thought they already did, but in the layers they control, like Chinese apps and telecoms.
Post reply on HN