Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…
That sounds like a golden key approach, and the problem is your communication is no longer protected by math, it's only protected by the will of a stranger to be tortured by the government to protect you https://www.rsaconference.com/library/blog/a-golden-key-to-u... The back and forth discussion on cryptography is happening because there just isn't much middle ground. Either someone else can read your messages, or n…
Encryption Is Not a Crime
61–70 of 222 posts
Re: Encryption Is Not a Crime
#62Earlier quoted context omitted.
That expiration is impossible to enforce. If you have the data and the cert, you can use it whenever you'd like, and the only thing preventing you from doing so is some piece of software voluntarily choosing to comply. What that means is, there exists a master key in your scheme.
Certificates expire right now. It's in the schema for how PKI works. Why can't the issued cert expire in the same way?
somewhere a piece of code would have to say "here I've got this key, which can decrypt this text, but I'm not going to" and that decision is not protected by math.
Re: Encryption Is Not a Crime
#63I'm not surprised, UK became literal African/Middle-East hell hole. They've kicked out all working immigrants and replaced them with ultra-religious freaks. And of course, UK being a country, where every form of self-defense is the most serious crime, when attacked you must call police, then lay on the ground and die, is cherry on top.
I wonder where in the UK you live, because up here in the North that definitely doesn't seem right - it's rare to see anyone non-white on the street.
Re: Encryption Is Not a Crime
#64Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…
Re: Encryption Is Not a Crime
#65Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…
Well if decryption is so justified then brute force breaking that takes significant resources so it's hard to unnoticeably misuse would be a good approach. When you can only break into 100 phones a year, then there's no slippery slope or fascist governments that could wildly misuse it for their own gain because it's not physically viable.
Re: Encryption Is Not a Crime
#66Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…
Law enforcement agencies currently have more data about each of us and more sophisticated tools to investigate crimes than at any time in human history.
> Politicians are (mistakenly) asking for a master key - but what I feel we should as a community support is some fine-grained legal process that would allow limited access to user information if justified by a warrant.
The problem with all backdoors is the human element. Master keys will be leaked. A process to gain access to a temporary key is also subject to the human factor. We’ve already seen this happen with telecom processes that are only supposed to be available to law enforcement.
The other issue is one of a legitimately slippery slope. The asymmetric nature of the power dynamic between governments and their citizens makes it even more critical to avoid sliding down that slope.
And finally, in the environment you propose, criminals will just stop using services that are able to provide such services to the government. Criminality will continue while ordinary citizens lose more and more of their rights.
Re: Encryption Is Not a Crime
#67I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult". It puts the idea into the world that it could be a crime and maybe that it is the status quo. Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on. Maybe "Don’t let them take your right to privacy."
Re: Encryption Is Not a Crime
#68Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…
The second thing that's wrong is the practice - despite the "going dark" panic spread by intelligence agencies, we have far, far less privacy than at any prior point in history, and spying on people, even people trying to hide, is much, much easier. So why the hell must we make it even easier still??
Re: Encryption Is Not a Crime
#69Earlier quoted context omitted.
> issued by the device manufacturer or application creator The problem is that if the application has the power to do this then the rest is irrelevant The means hackers/governments/the CIA can force the application creator to do their bidding and enable mass surveylance
I don't accept that. We have "master keys" for some forms of encryption right now in the form of root certificates; knowing that root cert authorities could issue certificates that might allow people to sniff my network traffic doesn't keep me awake at night.
This is not analogous to a single government having non-transparent, non-auditable access to decrypt communications of its own citizens.
Re: Encryption Is Not a Crime
#70Something is a crime if society determines that it should be so. Nothing more. Clearly the pressure on government to write these laws is coming from somewhere. You should engage with the arguments the other side makes.