Live data from Hacker News

More encryption means less privacy

queue.acm.org

91–100 of 221 posts

Re: More encryption means less privacy

#91
post #30

I think this point of view isn't just wrong it's actively harmful . It completely ignores what happened - which is that various government agencies skirted around constitutional law, subverted public discussion of the matter [0] and have still not been brought into adequate compliance (Since it's incredibly hard to demonstrate standing and not have the case squashed [1]). And after all this the author is saying the p…

I think a very important point was raised though. Before crypto, basically all guarantees where conditional on a judge's say so. With crypto this changes. The issue also comes up, in a clearer way, with crypto currencies. There is no way to deal with fraud or mistaken tranfers in bitcoin. That loss of intervention hurts, and we gotta think about it. Even though no government has given a satisfactory solution, that do…

Until very recently 99.99% of conversations where completely private and society functioned just fine. Even with crypto everywhere the governments have far more access to what people say and do than they had for thousands of years.

People with power pretend if they just had more power everything would be better. But, reality is if everything on a computer where private not much would change.

Re: More encryption means less privacy

#92

Earlier quoted context omitted.

I'm actually curious: can anyone cite a serious win for privacy that was wholly political? I frequently see pieces criticizing over-reliance on crypto as solutionism and political apathy, but I don't understand what they expect. The people fighting for strong cryptography have also led the political fight for privacy, but their nontechnical efforts have been ignored or circumvented at every turn. At this point it's h…

How far back are you willing to look? "The Video Privacy Protection Act (VPPA) was a bill passed by the United States Congress in 1988 ... to prevent what it refers to as "wrongful disclosure of video tape rental or sale records..." Congress passed the VPPA after Robert Bork's video rental history was published during his Supreme Court nomination." [1] I thought there were also some U.S. privacy laws around library r…

Interesting, thanks. 1988 is a while back, but it's far more relevant than the people citing the Fourth Amendment!

That's actually a pretty solid win for privacy, although it doesn't alleviate my sense that the government stance is "we can read everything as long as we don't tell anyone about it". The last I heard about library records was the Patriot Act opening them to government investigation, but things may have changed since them.

Still, this one is news to me, I appreciate it.

Re: More encryption means less privacy

#93
post #7

The article seems to make the fundamental error of assuming that there is any middle ground between "unbreakable crypto" and "effectively no crypto at all". If crypto can be broken, it will be broken, whether that's by state actors or by some kid in Mongolia who wants to make a quick buck by ransoming all your files.

Because it's not a fundamental error or indeed an error at all. What you've just expressed is one of those fascinating pieces of mental junk that clutters up social groups, a political desire that's so strongly held you've managed to rationalise to yourself that it's a fact and not a personal desire at all. But it's still not a fact. It is trivial to use cryptography in ways that yield some sort of balance between pe…

  Client-to-server encryption with central message routing [..]
will be abused by the NSA and anyone else that can get their hands on access. And no amount of politicking is going to change that, as it hasn't changed anything about their blatant disregard of the law thus far. BTW, 'anyone else that can get their hands on access' will include foreign nations and criminals.

  [..] can easily be given a backdoor [..]
that magically does manage to stay out of the hands of foreign nations and criminals, where all other backdoors thus far have been discovered and abused?

These arguments have a huge track record against them and I downvoted you for either acting wilfully ignorant.

Re: More encryption means less privacy

#94
Crypto is just bringing back real-life privacy options into digital space.

IRL, two people could go to some quiet place and have a private talk. If they feel suspicious, they might have checked the place for not being bugged (hard, but possible).

In the Internet, the default communication mode was public, which was exploited by NSA and other surveillance organizations. But now, thanks to usable crypto, two or more people can also have a private conversation, and if suspicious, they can check for not being MITMed (also hard, but possible).

Therefore, crypto brings nothing new to expectations of privacy, and the entire premise of this article is wrong.

Nice try, NSA.

Re: More encryption means less privacy

#95
post #9

Nobody really knows the correct answer and I think that's the reason communication is failing between the government and the tech sector. I think we have to realize that some transparency into private lives is needed to have a proper society, and the anarcho-capitalists want full privacy from the get go and then increasing transparency as needed for society, while government is kind of hovering on the "we need transp…

A third possible position would be the government stating "we need transparency everywhere, including for ourselves"--I would be that people would be much more accepting of transparency when government is totally transparent in return. For many reasons, governments are reluctant to take this position.

Re: More encryption means less privacy

#96

Crypto is just bringing back real-life privacy options into digital space. IRL, two people could go to some quiet place and have a private talk. If they feel suspicious, they might have checked the place for not being bugged (hard, but possible). In the Internet, the default communication mode was public, which was exploited by NSA and other surveillance organizations. But now, thanks to usable crypto, two or more pe…

Given the pitch in the article, I think they may be switching up for "Ministry of Truth".

Re: More encryption means less privacy

#97

This is a disappointingly defeatist perspective on the new crypto wars: unbreakable encryption is why we can't have nice things. I would rephrase most of his examples with the old saw: if you outlaw encryption, only outlaws will have encryption. Since Snowden we've increasingly realized that our own governments are the adversaries, but hopefully incidents like the DNC hack will shift the narrative from the terrorism…

Those hats might be a dingy shade of gray, but I appreciate their shedding some light on our political process. The DNC is the adversary of decent citizens, in this case.

Re: More encryption means less privacy

#98

Earlier quoted context omitted.

I do IT for a think tank in DC. I've seen people across the political spectrum fail to enact their particular agenda for their entire multi-decade careers. Changing policy is slow and, quite often, impossible.

If only there was some way of contiuing policy through some other means... That's the importance of technology (and arms).

Arms are now, and have been since the days before the ass' jawbone, just a kind of technology. I think increasingly the value lies in technology which doesn't have killing someone as its primary function. That's true for you and me, and it's true for a government that seems perpetually fascinated with "Less Lethal" options.

Electroshock devices have shown the world just how much people will take from their government, if it has almost no chance of killing or visibly scarring them.

Re: More encryption means less privacy

#99
post #83
post #79

So what does he suggest? I think we are supposed to read between the lines, but I am not sure what that is yet. Is it just pointing out an interesting contradiction and we should enhance and improve existing products, or there a message about moving back and reverting to using weak encryption like before or treating it like "munitions" for purposes of export control. So you you end up in prison just as long long for…

> So what does he suggest? I think we are supposed to read between the lines, but I am not sure what that is yet. I think the larger implication of the essay is to consider addressing privacy from a systemic/game theory perspective. The underlying threat isn't technological, but in the response to technological capabilities. Encryption is just another capability that provokes a response.

That's valid. I think they way it is presented it is easy to mis-read it. I kind of hinted at finding a better way to respond to the problem in the PR domain.

However,a technological solution can still help. For example, focusing on plausible deniability, traffic hiding, dead man switches and so on. Technology is just another approach and for some it might be easier to work with for some and easier to disseminate.

Re: More encryption means less privacy

#100

Earlier quoted context omitted.

You're arguing with something different to what I said. I pointed out that it's easy to design cryptosystems to be unbreakably strong against all adversaries except governments, and indeed can be unbreakably strong against mass eavesdropping by governments, yet still provide access on a case by case basis. And in fact this is the outcome of all kinds of natural and widely adopted designs. You're arguing that governme…

it's easy to design cryptosystems to be [...] unbreakably strong against mass eavesdropping by governments, yet still provide access on a case by case basis. Is it? How? Because that's certainly not the default that you referred to.

It's absolutely the default.

Imagine you own a webmail company. You secure your SMTP relays with SMTP-TLS (let's pretend it works well) and your client connections with TLS again.

Now your users are safe from random creepy flatmates, criminals with wifi sniffers, your telco and even mass government surveillance. But, governments can still serve a warrant on you to get email in a targeted manner, assuming they have a working MLAT process.

All you did was apply ordinary encryption to an ordinary website and you have that middle ground between "unbreakable to everyone" and "totally useless".

Post reply on HN