Live data from Hacker News

Encryption Is Not a Crime

privacyguides.org

91–100 of 222 posts

Re: Encryption Is Not a Crime

#91

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

Playing devil's prosecutor, I would say that technology has simultaneously made telecommunication a nearly constant part of life while also enabling mass surveillance on a global scale, and the process hasn't reached an endpoint. The result is an extremely slippery slope from "targeted lawful intercept" to "AI assisted sentiment analysis of every iMessage". Or in the future, everything seen by your AR glasses, every thought encoded by your neuralink chip...

Your limited lawful intercept example is reasonable to most, but as you yourself acknowledged, that's not what politicians are seeking. Therefore even if the community supports and enables "just that", politicians will eventually demand their wildcard cert. It will be a national emergency, after all.

Re: Encryption Is Not a Crime

#93
post #56

Earlier quoted context omitted.

It's also, unfortunately, not literally/universally true. There are plenty of jurisdictions and contexts in which it is a crime.

I don’t understand this. If you live in the US and use a service like ProtonMail, has a crime been committed? Are there any examples here in the US or anywhere else of arrests/prosecutions being made over encryption? I’ve never heard of any??

He's probably talking about authoritarian regimes like China or whatever.

Re: Encryption Is Not a Crime

#94
post #56

Earlier quoted context omitted.

It's also, unfortunately, not literally/universally true. There are plenty of jurisdictions and contexts in which it is a crime.

I don’t understand this. If you live in the US and use a service like ProtonMail, has a crime been committed? Are there any examples here in the US or anywhere else of arrests/prosecutions being made over encryption? I’ve never heard of any??

There are places that are not the United States.

Re: Encryption Is Not a Crime

#95

Playing devil's advocate here... What is wrong with: * an expiring certificate * issued by the device manufacturer or application creator * to law enforcement * once a competent court of law has given approval * that would allow a specific user's content to be decrypted prior to expiry There are a million gradations of privacy from "completely open" to "e2e encrypted". Governments (good ones!) are rightly complaining…

> Governments (good ones!) are rightly complaining that criminals are using encryption to commit particularly awful crimes. For starter I don't know a lot of good governments. So you'll have to define how you differentiate between a good one and a bad one. > Governments (good ones!) are rightly complaining that criminals are using encryption to commit particularly awful crimes. Secondly, criminals use public transpor…

> In those cases, you need a judge or someone to approve the seizure. With a backdoor that can be opened at any time, you should consider that nothing will be private because there is no one who is going to be monitoring it 24/7 to make sure that there are no abuses.

I'm not sure you've read what I wrote correctly. My hypothetical system would not allow the backdoor to be opened at any time, but it would require a certificate to be issued (derived from the manufacturer / application creator's root) that gives limited, expiring access on the production of court-authorised warrant, in exactly the same way a judge gives the police permission to enter your physical property.

Re: Encryption Is Not a Crime

#96
post #30

Earlier quoted context omitted.

> You should engage with the arguments the other side makes. The arguments are "Protect the children.", "Catch terrorists.", "Catch criminals.". Those arguments have been engaged with for decades. They are purely emotional arguments. Anyone who still pushes those arguments forth is most likely doing so with ulterior motives and cannot be reasonably "engaged" with.

For what its worth the anti-encryption/anti-privacy laws have caught terrorists in the UK. My company provides data storage for their dragnet and handles various requests and Ive seen first hand 4 different instances where the UK gov watching everyones internet activity led to terrorists being caught.

That same government can use that same dragnet in the suppression of accountability for the war crimes and atrocities it is engaged in.

Re: Encryption Is Not a Crime

#97
post #56

Earlier quoted context omitted.

It's also, unfortunately, not literally/universally true. There are plenty of jurisdictions and contexts in which it is a crime.

I don’t understand this. If you live in the US and use a service like ProtonMail, has a crime been committed? Are there any examples here in the US or anywhere else of arrests/prosecutions being made over encryption? I’ve never heard of any??

I don't live in the US

Re: Encryption Is Not a Crime

#98

Earlier quoted context omitted.

I wish Americans still believed in American freedoms Encryption is free association and free speech. Talking to someone about what I like without eavesdroppers Transitioning gender is also free speech, freedom of expression. Presenting how I like and not how some wannabe king wants me to

"I wish Americans still believed in American freedoms" Yeah, as someone who's viewed America from the outside for decades tragically it's no longer the country I once knew.

The big issue right now is that they can't seem to agree on what those freedoms even mean.

Re: Encryption Is Not a Crime

#99
post #34

I do not like these framings of "not a" because it always sounds so suspicious like "we are not a cult". It puts the idea into the world that it could be a crime and maybe that it is the status quo. Much better IMHO is something like "Encryption is a fundamental right.", "Encryption protects everyone.", "Without encryption there is no democracy." and so on. Maybe "Don’t let them take your right to privacy."

Also, I've heard it said that people have a tendency to subconsciously flush "not" and remember that sort of statement as "encryption is a crime". It is slightly better to put things positively (eg, "Encryption is the reasonable default").

Re: Encryption Is Not a Crime

#100
post #69

Earlier quoted context omitted.

To reduce any risks, almost everything PKI-related is conducted in public, is auditable by anyone, and is a cooperation between dozens of distinct entities located globally. This is not analogous to a single government having non-transparent, non-auditable access to decrypt communications of its own citizens.

Then setup the system to be more analogous. Make the publication of key issuance under this mechanism public after a period of time. Again, I see us falling back into an "all or nothing" view of privacy and I just don't think those are the only options.

>Then setup the system to be more analogous. Make the publication of key issuance under this mechanism public after a period of time.

That (somewhat, barely) addresses one of ~dozen issues with the proposal.

>Again, I see us falling back into an "all or nothing" view of privacy

Not to be too pedantic, but I think the distinction between privacy and encryption is incredibly important: almost everyone agrees that privacy is a gradient. The disagreement is whether or not encryption can be a gradient. Most people do not think it can reasonably be without undermining ~everything relying on it.

Post reply on HN