Live data from Hacker News

Civics is boring, so, let's encrypt something (2024)

queue.acm.org

1–10 of 74 posts

Re: Civics is boring, so, let's encrypt something (2024)

#2
”So, a judge who is convinced you're about to kill somebody can unleash the police to follow you everywhere in hopes of preventing that crime. Similarly, a judge who thinks your computer system contains information related to financial crimes can allow the police to hack that system. Likewise, a judge who thinks you're stalking your ex can order you to stay out of a certain part of town.”

One of these things is not like the others…

Re: Civics is boring, so, let's encrypt something (2024)

#3
If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments.

No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unless it's their parents maybe,... that one is debatable).

ps the term "NOBUS fallacy" is apparently not a thing yet. (I thought it was!)

Re: Civics is boring, so, let's encrypt something (2024)

#5
This article frames a false choice of either designing a system that allows government access to everything you do digitally (which is now almost everything), or having the government design such a system.

In reality the choice is between such a totalitarian surveillance state without the possibility of digital security guarantees, or one where police can’t read your digital mind but can do good old fashioned police work.

Re: Civics is boring, so, let's encrypt something (2024)

#6
post #4

I’m trying to skim this but there is a lot of meandering and I’m still not sure what their main point is.

"Give governments broken encryption before they force you to", with various unimportant technical details of how specifically to give up.

The civics lesson is almost useful, except for the part where it treats the current demands as immutable rather than an adversary to be fought and defeated.

Re: Civics is boring, so, let's encrypt something (2024)

#7
post #4

I’m trying to skim this but there is a lot of meandering and I’m still not sure what their main point is.

I didn’t finish reading to the end but by halfway through it’s about building protocols in advance to weaken encryption for government benefit, before the government mandates it, and framing encryption strength has the length of time users are willing to rot in jail. It’s framing breakable encryption as necessary for operation of any government built on laws.

Re: Civics is boring, so, let's encrypt something (2024)

#8

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

"NOBUS" isn't a fallacy. We can build systems that have access mechanisms that are for all intents and purposes NOBUS.

Re: Civics is boring, so, let's encrypt something (2024)

#9
Two quick hits:

(1) It's important to remember that part of why Telegram is in this pickle is that they deliberately designed a system that increased the surface area of what governments could demand from them, because they're not fully (or even mostly) end-to-end encrypted (in fact, they were openly dismissive of end-to-end encryption). We get these kinds of interventions in part because governments know they can work; we know how to design systems where they can't work.

(2) The idea that governments worldwide will uniformly solve this through international agreements seems fallacious, because some of the largest countries in the world have sharply different legal and political standards. For an agreement on lawful intercept to work, you need to foreclose on products that refuse lawful intercept. There are countries you can do that in, and others where you can't.

I think there is a well-taken point that cutting off law enforcement access to data isn't a long-term stable equilibrium; something will give eventually. But I think PHK is way overshooting how strong that argument is today.

Re: Civics is boring, so, let's encrypt something (2024)

#10

If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…

You don't have to weaken your encryption to your bank though. The author proposes extending the TLS protocol so that the bank declares themselves responsible for the contents of communication and full strength encryption can be used.
Post reply on HN