Live data from Hacker News

Encryption Is Not a Crime

privacyguides.org

81–90 of 222 posts

Re: Encryption Is Not a Crime

#81
post #35

Earlier quoted context omitted.

Under what law? High security vaults are not legally controlled or prohibited in the US.

Which high security vault can the government not gain access to under any circumstances? I expect you'll find decent explosives or a bulldozer will get them in just fine.

With physical access, global superpowers can break both vaults and strong encryption.

Re: Encryption Is Not a Crime

#82
post #56
post #34

I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult". It puts the idea into the world that it could be a crime and maybe that it is the status quo. Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on. Maybe "Don’t let them take your right to privacy."

It's also, unfortunately, not literally/universally true. There are plenty of jurisdictions and contexts in which it is a crime.

A friend of mine had to swear on a holy book to not use VPN upon returning to their country of origin.

Re: Encryption Is Not a Crime

#83

Earlier quoted context omitted.

Which governments are the good ones? Is Indian government a good one, or Hungary's, or Turkish, German, or British, or the US? In the last case (well, in all cases), does "goodness" of a government depend on the current incumbent? What if a previously "good" government turns into an atrocious one? See also: the detailed Dutch census, which was mostly harmless, until it fell into hands of the Nazis in 1940 and helped…

Every system of authority carries with it the risk of abuse; but we still accept legitimate authorities carrying out breaches of personal privacy for the sake of law enforcement - the warrant system being the obvious one. That's part of the compromise we make in society. Good governments ensure that a breach of personal privacy has to travel through a legitimate process with an independent judiciary to limit the risk…

Do you think that this can be done without introducing massive security weaknesses into systems that cannot have them?

Also, there is a question if you believe the authorities that without decrypting data, they can't investigate crimes.

Imagine an analogical assertion that without torturing suspects, law enforcement is stymied. Someone might assert that, but we still say no, for all sorts of fundamental reasons. Same with American Miranda rights and others.

Myself, I don't believe in that assertion at all. Most crimes leave a massive real world trace that cannot be encrypted. The ones that don't, maybe should not be crimes in the first place.

Re: Encryption Is Not a Crime

#84
post #56
post #34

I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult". It puts the idea into the world that it could be a crime and maybe that it is the status quo. Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on. Maybe "Don’t let them take your right to privacy."

It's also, unfortunately, not literally/universally true. There are plenty of jurisdictions and contexts in which it is a crime.

I don’t understand this. If you live in the US and use a service like ProtonMail, has a crime been committed? Are there any examples here in the US or anywhere else of arrests/prosecutions being made over encryption? I’ve never heard of any??

Re: Encryption Is Not a Crime

#86

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

> Governments (good ones!) are rightly complaining that criminals are using encryption to commit particularly awful crimes.

For starter I don't know a lot of good governments. So you'll have to define how you differentiate between a good one and a bad one.

> Governments (good ones!) are rightly complaining that criminals are using encryption to commit particularly awful crimes.

Secondly, criminals use public transport and roads built with taxpayer money to commit crime. Some even say that they breathe the same air as us honest citizens.

They also live in homes with 4 walls that you can't see through either.

I am being facetious but you can see where I am going with this.

If you think that the governments will stop at spying on criminals once this backdoor is in place, then I have a bridge to sell you.

Do you want your kids to grow in world were everything they do online will be analyzed, categorized and reviewed by some random government employee somewhere?

What if this government turns bad in the future as it has happened countless times in the past? What do you do then?

> I feel we should as a community support is some fine-grained legal process that would allow limited access to user information if justified by a warrant.

The problem with this line of thinking is that it doesn't hold up in the real world. Once you grant access to something like say your browser history to the government or any entity, what's to stop them to ask for more next time?

It's not a big deal right, they can say, well you gave us access to A, now we want access to B. Then in 3 years they will come back demanding access to C, D and E until your entire privacy has been taken away from you.

And every time, they will use the same excuses, fighting crime, fighting drugs, child grooming and terrorism.

> Competent jurisdictions allow this for physical search and seizure.

That is not even remotely comparable.

In those cases, you need a judge or someone to approve the seizure. With a backdoor that can be opened at any time, you should consider that nothing will be private because there is no one who is going to be monitoring it 24/7 to make sure that there are no abuses.

Re: Encryption Is Not a Crime

#87

Earlier quoted context omitted.

Am I allowed to keep a secret? Maybe I am not allowed to write it down and also keep it secret.

Yes, but if a court decides you have committed a crime, and law enforcement show sufficient cause to obtain a warrant, they can seize your secret and - if it's relevant - use it to show your state of mind when the crime was committed.

Did you not read 1984?

Re: Encryption Is Not a Crime

#88

Earlier quoted context omitted.

Certificates expire right now. It's in the schema for how PKI works. Why can't the issued cert expire in the same way?

Users can ignore the expiration date on a TLS cert. Cryptography doesn't enforce time constraints, business logic does. somewhere a piece of code would have to say "here I've got this key, which can decrypt this text, but I'm not going to" and that decision is not protected by math.

I'm not sure I follow. Obviously the application itself needs to support the business logic described, in the same way as your web browser needs to notice that a certificate has expired and tell you there's a problem with a website you're visiting. What I'm exploring is why requiring certain applications to support the same sort of thing to decrypt user data in certain circumstances to support law enforcement is a problem.

Re: Encryption Is Not a Crime

#89
post #15

Something is a crime if society determines that it should be so. Nothing more. Clearly the pressure on government to write these laws is coming from somewhere. You should engage with the arguments the other side makes.

> Clearly the pressure on government to write these laws is coming from somewhere

Software surveillance vendors.

> Chat control: EU Ombudsman criticises revolving door between Europol and chat control tech lobbyist Thorn

> Breyer welcomes the outcome: “When a former Europol employee sells their internal knowledge and contacts for the purpose of lobbying personally known EU Commission staff, this is exactly what must be prevented. Since the revelation of ‘Chatcontrol-Gate,’ we know that the EU’s chat control proposal is ultimately a product of lobbying by an international surveillance-industrial complex. To ensure this never happens again, the surveillance lobbying swamp must be drained.”

https://www.patrick-breyer.de/en/chat-control-eu-ombudsman-c...

Post reply on HN