Live data from Hacker News

Obama Encryption Policy Rejects Laws Mandating Backdoors

eff.org

71–78 of 78 posts

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#71
post #69
post #35

> the administration will continue trying to persuade companies that have moved to encrypt their customers’ data to create a way for the government to still peer into people’s data If you are one of these companies that are informally cooperating with the government on this, please state so publicly, in the signup process and by message to current users, so that we can avoid using your services now, or at least when…

Well put. We tried to take a very privacy-protective stand when building Recent News ( https://recent.io ) because of the amount of personalization we do. This warrant canary is part of our privacy policy: As of [date], we have not received any legal process or demand from any federal, state, or local government that includes a gag order. We have received no National Security Letters, civil subpoenas, search warrants…

IANAL, but the judge may order you to keep the warrant canary or find you in contempt. Law is based on intent and if your intent in removing that clause is in broadcasting you are under gag order, when the gag order restricts you from doing exactly that, you may find that will be taken as a breach.

This should not be taken as legal advice, YMMV, yadda yadda.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#72

Earlier quoted context omitted.

I think the general opinion from the 'cryptowars' in the 90s is that there is no such scheme that does't cripple the actual security of encryption. Key escrow came up back then though I don't think it included needing multiple keys in order to decrypt - not sure if that's mathematically possible or if there's another reason that never came up. I suppose to the government that's not much different than still needing t…

> needing multiple keys in order to decrypt - not sure if that's mathematically possible As a matter of interest Shamirs Secret Sharing algorithm ( https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing ) is quite nice in that respect. The "secret" would be the decryption key. Using Shamirs Secret Sharing algorithm you could split the key into two so you would need both parts in order to work out the decryption key. T…

That's a cool algorithm - and while it does reduce the risk of a hack succeeding I think it still could be considered a 'backdoor'. It's just a backdoor that requires to people to work together to open, harder to compromise yes - but I'd argue still not really secure.

If you have a government entity routinely breaking into companies and taking over access to things (targeting sysadmins) then the scheme doesn't work very well. I think most of the argument behind encryption falls on this idea that it either is secure (no backdoors) or it isn't. You have a spectrum of insecure things you can do that are arguably better than nothing, but they're not secure.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#73

Earlier quoted context omitted.

I'm not arguing to break encryption. And neither is the white house. They want ways around this stuff- ways that don't break encryption, but if the information is available, then the ability to get to it if necessary. Backdoors don't work because yeah, it breaks the whole system. But not everything is encrypted with these companies, that's just plain.

Perhaps I am not versed well enough in the subject, but I have a hard time envisioning any kind of system that allows government officials to get around the encryption and peer into the contents but not hackers. There will always be some sort of secret only the government has access to, and once that secret is leaked it's game over.

You don't give the government access to their own door. The company simply retains the right to access things- you know, the same way we have it now.

All it's arguing, is to say "You don't have to encrypt literally every part of your system and delete the rest" a la what Snapchat suggests they're doing(though we don't have proof).

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#74
post #60

Earlier quoted context omitted.

I've always been curious, what's the rationale for opening luggage? If there is an issue, should the person be summoned before the plane is loaded and boarded? If they think it's explosive, shouldn't the NOT TOUCH IT?

Not just bombs but every other type of contraband. Guns and drugs are the ones you commonly think of, but animals and plants can be a bigger problem, especially when you look at it in the international level.

But again, why aren't I brought to be present?

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#75
post #44

Earlier quoted context omitted.

> Crypto is all or nothing. You can't have "backdoors" into crypto algorithms that are secret only to the government. It is literally impossible. You don't backdoor the algorithm. You backdoor the use of the algorithm--except it is more of a front door than a back door. For instance, when the device encrypts data with a symmetric cipher, encrypt a copy of the symmetric key via a public key cipher using the FBI's publ…

Are you also going to make all other forms of encryption illegal? If not, I'll just pre-encrypt the message with an actually secure mechanism before sending it through the backdoored system.

Yes, that is usually what the proposal is.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#76
post #67
post #58

Earlier quoted context omitted.

Not all that rare (see: OPM leak, any of the other leaks that happen daily) especially with such an incredibly high value target. If it's a symmetric key style system, then wouldn't all previously encrypted communications be vulnerable if they've been recorded someplace? Email, ecommerce, server logs, everything.

Leaks in general aren't rare. Leaks of high value private keys are very rare. Offhand the only ones I remember are D-Link's leak of a code signing key this year and AMI's leak of a BIOS signing key a couple years ago. I've probably forgotten some. Keys of this value are generally not stored online, and are often split using a secret sharing system among several people. It's not hard to set up a system where all of th…

RSA had to recall its SecurID tokens after Chinese hackers stole its keys, cloned tokens, and used them to break into defense contractors. So: it does happen.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#77
post #2

Deceptive title, unintentionally. FTA: "Instead, the Post reports, the “administration will continue trying to persuade companies that have moved to encrypt their customers’ data to create a way for the government to still peer into people’s data when needed for criminal or terrorism investigations.” While eschewing attempts to legislatively mandate that tech companies build backdoors into their services, the preside…

We've agreed as a country that the ability to get a warrant in the case of probable cause is a good thing. How is this not just maintaining that? I find it hilarious how often privacy advocates manage to forget that we've had this conversation before, and while the government can and has overstepped in many ways, lets not throw out the ability to investigate at all along the way.

I think what you're not understanding is that computers are literal extensions of brains and minds. We have outsourced our memories and our thought to these devices, and we must have the same assurances over them as we would over ourselves. This will become only more clear as the line between a biological memory storage device and a digital memory storage device blurs into nonexistence.

And that is also a conversation we've had before. There is no warrant you can get to force a suspect to testify against himself.

Though, it's cute that you think these "conversations" are meaningful. If the American government thinks you're too interesting to not know more about, they'll black-bag you and ship you off to a secret CIA dungeon where you'll be tortured for the rest of your life. Even if you end up being held without charge in a cushy place like Guantanamo, you'll never be released because you were held without charge and that makes you a terrorist.

I find it hilarious how surveillance advocates manage to forget that your government does not respect rule of law, it rules by law. It is the law.

Re: Obama Encryption Policy Rejects Laws Mandating Backdoors

#78
post #22
post #5

Earlier quoted context omitted.

Agreed, but it's still a massive improvement over mandating that all encryption used by citizens be thoroughly crippled. The status quo should be that the degree to which Government can intrude into citizens privacy is limited by law and subject to open public debate. We're not quite there yet, either in the US or here in the UK, but dropping the idea of crippled encryption is at least a step back from the brink even…

I think threatening to ban all secure communication in a psychotic unrealistic policy position and having important "serious" people like the director of the FBI push for it isn't really intended to get it codified into law, rather to elicit responses like yours -- it's designed to massively push the Overton window against privacy so that we can feel okay about how bad things currently are -- at least the insane unre…

No, unfotrunately I think our 'security' establishment really are so divorced from reality that they think crippling encryption is a good idea. It would be nice to think that they're actualy technically competent and it's all a ploy, but the truth is depressingly mundane. They handed the Chinese government and other authoritarian states cover for demanding back doors in encrypted products on a platter, and sold out our privacy, without any clue how utterly stupid and self defeating an idea it is.
Post reply on HN