Live data from Hacker News

Re: Obama on Fetishizing Our Phones

jonathanmh.com

91–100 of 337 posts

Re: Re: Obama on Fetishizing Our Phones

#91
In the end, they are going to introduce laws that make it illegal to implement end-to-end encryption. This sucks, but it's going to happen. France is already moving to do it [1], and in the US, John McCain and others are also calling for similar laws [2]. They will all start off saying that it will be controlled carefully etc., as Obama keeps saying, and then it will be used with reckless abandonment.

What this essentially means is a move to Android for criminals, terrorists, and anyone that wants privacy (since Android allows installation of apps that have not been approved by a gatekeeper bound by the laws of the countries it operates in, whereas iOS does not by default). Open source Android apps with strong encryption will be built in countries without such laws. All of this will likely be the downfall of a few lazy drug dealers that don't want to give up their iPhones, but since the cat is out of the bag and apps with end-to-end encryption already exist and will continue to be built, the governments making these moves will not actually catch any reasonably intelligent terrorists that install and use these apps. They will, however, gain exactly what they want: the ability to conduct surveillance on most people in the world whenever they want.

[1] http://fortune.com/2016/03/04/french-law-apple-iphone-encryp...

[2] http://www.digitaltrends.com/computing/senator-mccain-joins-...

Re: Re: Obama on Fetishizing Our Phones

#92
post #21

One strong point that comes out is reference to the transitory nature of governments, just because you trust yours now (!), does not mean you can trust future incarnations, don't give this kind of power to an unknown.

Also asserting that your government has the right to certain powers over its citizens establishes the precedent that any government should have that right. If it's OK for the US or UK governments to have the keys to its citizens encryption, then it's ok for China, Russia, Iran, etc.

Interestingly, the encryption system underlying WhatsApp was developed by the US government for people in oppressive states to use to avoid surveillance and restrictions on access to information.

Re: Re: Obama on Fetishizing Our Phones

#95

Obama, our manipulating word artisan of a president yet again attempting to use strong language (i.e "fetishizing") to polarize our view.

First he accused me of clinging to my guns, but since I didn't own any guns, I was OK with that. Next he accused me of clinging to my religion, but since I was an atheist, I was like, meh, whatever. Then he accused me of clinging to my smartphone, and oh, boy. It's on now, motherfucker.

Oh, please delete this before more people see it and you're further embarrassed.

Or, you know, elaborate on how the federal government has infringed on any of your religious rights whatsoever.

Or, you know, your gun rights... at all...

Really easy to beat strawmen, come on. Have some self respect. Why did you press Enter on that comment? You and I both know that you were aware it was bullshit when you posted it. Did you think we're all just stupid?

Re: Re: Obama on Fetishizing Our Phones

#96
post #9

This is incredibly naive bordering on puerile. To suggest that POTUS' view on this is without nuance is to miss his point. POTUS went on to cite existing warrant mechanisms and their underlying principle: "And we agree on that, because we recognize that just like all of our other rights ... that there are going to be some constraints we impose so we are safe, secure and can live in a civilized society." I'm not sugge…

> We need people advocating for the right balance, not just getting each other frustrated. I don't understand this line of thinking regarding the big encryption debate. Yeah it sounds good if you don't know anything about encryption. "Look, he's being reasonable. Why is everyone saying he's wrong instead of striking a balance". The problem is it's a binary problem. There is zero way to strike any type of balance here…

In that case, perhaps the balance we need to strike is rhetorical, not technical.

I think some people in the tech world are 4th-amendment absolutists. That's not a new thing; in Cryptonomnicon there was the electromagnetic doorframe so strong that it would wipe drives passing through it. I don't know that it's a position I hold myself, but it's one I definitely respect.

But we have a multi-century history of the government being able to read people's documents once they have a warrant. A lot of crime-fighting makes use of this. Whatever the intricacies of the technology, there's a status quo that I think we should at least acknowledge.

So I think the rhetorical balance we need to strike as an industry is along the lines of, "Yes, we totally get why you would want to get into that terrorist's phone. We wish we could find a way to give you access to just that without compromising everything. But it's not like a wall we can put a special door in. It's like a balloon. The moment it loses integrity, it's worthless. We want to help you, but we can't."

When the message instead comes across as absolutist, I think we're in danger of losing public support. Without that, we'll have a very hard time resisting government demands for access.

Re: Re: Obama on Fetishizing Our Phones

#97
post #70

Earlier quoted context omitted.

Encryption is a measure that prevents unauthorized parties from taking part of what is encrypted. If it fails that on such a basic level that a specific unauthorized party can trivially access it, it's not effective encryption. Whether or not it is effective, then, is just a matter of whether you agree that who ever holds the master key is authorized to access whatever it is that you encrypted. It's still not broken…

I don't think that's true at all. If you use gmail your data is pretty safe. Unless you tell me your password I'm going to have a pretty hard time reading your mail. It's encrypted at rest on Google's disks. It's encrypted in transmission over the internet. Google's network is protected with various forms of encryption and security that makes it hard for an unauthorized party to get into. But Google itself can access…

The difference is that by using Gmail you agree with Google's terms of service, which state somewhere in them that they can target ads at you.

With a government-held master key, there is no such contract.

Re: Re: Obama on Fetishizing Our Phones

#98
post #28

Earlier quoted context omitted.

but there is no "balance" when somethig is binary. You either have encryption or you don't.

That's wrong. The government isn't saying that no one should be able to encrypt data. They just thing that, in some cases, it should be done in such a way that certain data can be read by use of a centralized master key. This, of course, presents certain problems. What if that master key leaks? But it's not binary. Data secured this way is absolutely safer than not encrypting something at all. "Is it safe enough?" is…

The fundamental issue is that any back door accessible to "the good guys" will also be accessible to sufficiently-technically-advanced "bad guys". And from the perspective of securing the United States' defense infrastructure, major corporations, etc., there are multiple sufficiently-technically-advanced "bad guys" in the world already (i.e., certain major foreign governments and their intelligence/defense complexes).

So if you're doing US national security, you cannot accept the Obama position; any technology to which our "good guy" law enforcement could get access is guaranteed to also be a technology to which a "bad guy" foreign enemy combatant could similarly gain access.

If you're a major US corporation, you cannot accept the Obama position; any technology to which our "good guy" law enforcement could get access is guaranteed to also be a technology to which a "bad guy" foreign intelligence/espionage agent could similarly gain access.

So as far as that is concerned, it is binary. You can either be secure against foreign threats, in which case you are also as a side effect impenetrable to the local "good guys". Or you can be penetrable by the local "good guys" and also as a side effect penetrable by the foreign "bad guys".

The argument advanced against Obama's position is that A) it fundamentally fails to acknowledge this reality, and B) seems to argue for deliberately compromising national security in order to... preserve national security? In other words, it is not only unrealistic, it is in fact nonsensical and self-contradictory.

Re: Re: Obama on Fetishizing Our Phones

#99
post #88

We're going to fight hard so our grandchildren have really secure email in a world where everything they do and every word they say is uploaded to the internet, transcribed and annotated in realtime by swarms of drones controlled by other kids that, only 50 years earlier, would have been at home doxxing people on Twitter. Privacy will die, not because it's undesirable or a bad idea, it'll die like copyright and DRM -…

I disagree - digital surveillance state will be gone within a decade, or twenty years at most. Already we see programs like Telegram becoming very popular (100 million users) where the opportunity for surveillance is massively reduced. Platforms are going to slowly transition towards encrypted content and data that not even service providers can decrypt (SpiderOak is a good example).

The biggest holdout will be operating systems - Google and Microsoft very much do not want to lose their backdoors (or front doors) into everyone's data. But within ten years, we will finally have a "year of Linux on desktops" in which both grandma and the young university student can both buy an Ubuntu computer and have it work how they need it to. And phones will run an OS that can't be maliciously updated remotely, and doesn't leak user data to apps and OS providers.

The final step will be near anonymous internet usage, which we are currently in the infancy of. There will be a shift to a more decentralized availability (but not necessarily storage) of data in most of the applications we use most often. Essentially Freenet, but without all the usability problems. The Facebook of the future will have open source (and encrypted) data where your info is only viewable to you and your friends. There are currently platforms that exist like this, but they are mostly in "testing" stages and are not ready for widespread use.

Re: Re: Obama on Fetishizing Our Phones

#100

Earlier quoted context omitted.

Metadata has critical value. And private communications are being monitored, recorded, and searched as well. (Many people, myself included, also reject the notion that unauthorized collection and recording is fine as long as the subsequent searches and filters are authorized.) You seem to be taking government descriptions at face value, despite documented evidence to the contrary. Consider the possibility that the go…

Well I certainly don't trust you and your private army's oversight of me, and I'm sure you don't trust me and my army's oversight of you. So we make an agreement and build a third-party that has oversight over both of us. Or do you expect me to trust you?

You seem to be attempting to paint everyone who disagrees with you as someone who stockpiles baked beans and ammo in a bunker. You also seem to have no concept of any middle ground between "absolute trust in the infallibility of government" and "radical anarchist".

Let's make this concrete, instead. Anyone can, today, using off-the-shelf software, store information such that only someone with a passphrase can access it, and such that all the computing power in the world would take centuries to access it without the passphrase.

In such a scenario, I don't expect anyone to "trust" anyone, or to need to. (Modulo the issue of trusting the software to be properly implemented, which is a separate discussion but has some plausible solutions.) Instead, I expect that the software in question will prevent unauthorized access, as it was designed to do.

Post reply on HN