Live data from Hacker News

Encryption Is Not a Crime

privacyguides.org

61–70 of 222 posts

Re: Encryption Is Not a Crime

#61

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

That sounds like a golden key approach, and the problem is your communication is no longer protected by math, it's only protected by the will of a stranger to be tortured by the government to protect you https://www.rsaconference.com/library/blog/a-golden-key-to-u... The back and forth discussion on cryptography is happening because there just isn't much middle ground. Either someone else can read your messages, or n…

No, I don't accept that this is the case any more than the root certificate system is a golden key. I'm quite sure that Apple can issue me a certificate that allows me to build a custom version of iOS that can be flashed onto my phone; why doesn't the same thing apply to other things?

Re: Encryption Is Not a Crime

#62
post #41

Earlier quoted context omitted.

That expiration is impossible to enforce. If you have the data and the cert, you can use it whenever you'd like, and the only thing preventing you from doing so is some piece of software voluntarily choosing to comply. What that means is, there exists a master key in your scheme.

Certificates expire right now. It's in the schema for how PKI works. Why can't the issued cert expire in the same way?

Users can ignore the expiration date on a TLS cert. Cryptography doesn't enforce time constraints, business logic does.

somewhere a piece of code would have to say "here I've got this key, which can decrypt this text, but I'm not going to" and that decision is not protected by math.

Re: Encryption Is Not a Crime

#63
post #60

I'm not surprised, UK became literal African/Middle-East hell hole. They've kicked out all working immigrants and replaced them with ultra-religious freaks. And of course, UK being a country, where every form of self-defense is the most serious crime, when attacked you must call police, then lay on the ground and die, is cherry on top.

>>I'm not surprised, for years UK become literal African/Middle-East hell hole.

I wonder where in the UK you live, because up here in the North that definitely doesn't seem right - it's rare to see anyone non-white on the street.

Re: Encryption Is Not a Crime

#64

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

Because it is not realistic to except a government to always be "good". Courts are just going to rubber-stamp warrants, like they have done with present-day "lawful interception" warrants. And the keys are inevitably going to leak, if they are used routineously to investigate common crime.

Re: Encryption Is Not a Crime

#65

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

Well if decryption is so justified then brute force breaking that takes significant resources so it's hard to unnoticeably misuse would be a good approach. When you can only break into 100 phones a year, then there's no slippery slope or fascist governments that could wildly misuse it for their own gain because it's not physically viable.

Ok! That is a sensible rejoinder. Make a proof-of-work system that limits the authority from making more than n requests in a space of time. A good brake on abuse.

Re: Encryption Is Not a Crime

#66

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

I don’t think this particular devil needs more advocacy.

Law enforcement agencies currently have more data about each of us and more sophisticated tools to investigate crimes than at any time in human history.

> Politicians are (mistakenly) asking for a master key - but what I feel we should as a community support is some fine-grained legal process that would allow limited access to user information if justified by a warrant.

The problem with all backdoors is the human element. Master keys will be leaked. A process to gain access to a temporary key is also subject to the human factor. We’ve already seen this happen with telecom processes that are only supposed to be available to law enforcement.

The other issue is one of a legitimately slippery slope. The asymmetric nature of the power dynamic between governments and their citizens makes it even more critical to avoid sliding down that slope.

And finally, in the environment you propose, criminals will just stop using services that are able to provide such services to the government. Criminality will continue while ordinary citizens lose more and more of their rights.

Re: Encryption Is Not a Crime

#67
post #34

I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult". It puts the idea into the world that it could be a crime and maybe that it is the status quo. Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on. Maybe "Don’t let them take your right to privacy."

It makes sense in this context, as it operates on the idea that it could be a crime: "Contrary to what some policymakers seem to believe, whether naively or maliciously, encryption is not a crime."

Re: Encryption Is Not a Crime

#68

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

The first thing that's wrong is the principle - we should have a right to try to preserve our privacy. When even trying to hide is a crime, you live under tyranny.

The second thing that's wrong is the practice - despite the "going dark" panic spread by intelligence agencies, we have far, far less privacy than at any prior point in history, and spying on people, even people trying to hide, is much, much easier. So why the hell must we make it even easier still??

Re: Encryption Is Not a Crime

#69

Earlier quoted context omitted.

> issued by the device manufacturer or application creator The problem is that if the application has the power to do this then the rest is irrelevant The means hackers/governments/the CIA can force the application creator to do their bidding and enable mass surveylance

I don't accept that. We have "master keys" for some forms of encryption right now in the form of root certificates; knowing that root cert authorities could issue certificates that might allow people to sniff my network traffic doesn't keep me awake at night.

To reduce any risks, almost everything PKI-related is conducted in public, is auditable by anyone, and is a cooperation between dozens of distinct entities located globally.

This is not analogous to a single government having non-transparent, non-auditable access to decrypt communications of its own citizens.

Re: Encryption Is Not a Crime

#70
post #15

Something is a crime if society determines that it should be so. Nothing more. Clearly the pressure on government to write these laws is coming from somewhere. You should engage with the arguments the other side makes.

Kind of impossible when they meet In secret courts and have privileged access to Congress.
Post reply on HN