Civics is boring, so, let's encrypt something (2024)
queue.acm.org
Civics is boring, so, let's encrypt something (2024)
1–10 of 74 posts
Re: Civics is boring, so, let's encrypt something (2024)
#2One of these things is not like the others…
Re: Civics is boring, so, let's encrypt something (2024)
#3No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unless it's their parents maybe,... that one is debatable).
ps the term "NOBUS fallacy" is apparently not a thing yet. (I thought it was!)
Re: Civics is boring, so, let's encrypt something (2024)
#4Re: Civics is boring, so, let's encrypt something (2024)
#5In reality the choice is between such a totalitarian surveillance state without the possibility of digital security guarantees, or one where police can’t read your digital mind but can do good old fashioned police work.
Re: Civics is boring, so, let's encrypt something (2024)
#6I’m trying to skim this but there is a lot of meandering and I’m still not sure what their main point is.
The civics lesson is almost useful, except for the part where it treats the current demands as immutable rather than an adversary to be fought and defeated.
Re: Civics is boring, so, let's encrypt something (2024)
#7I’m trying to skim this but there is a lot of meandering and I’m still not sure what their main point is.
Re: Civics is boring, so, let's encrypt something (2024)
#8If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…
Re: Civics is boring, so, let's encrypt something (2024)
#9(1) It's important to remember that part of why Telegram is in this pickle is that they deliberately designed a system that increased the surface area of what governments could demand from them, because they're not fully (or even mostly) end-to-end encrypted (in fact, they were openly dismissive of end-to-end encryption). We get these kinds of interventions in part because governments know they can work; we know how to design systems where they can't work.
(2) The idea that governments worldwide will uniformly solve this through international agreements seems fallacious, because some of the largest countries in the world have sharply different legal and political standards. For an agreement on lawful intercept to work, you need to foreclose on products that refuse lawful intercept. There are countries you can do that in, and others where you can't.
I think there is a well-taken point that cutting off law enforcement access to data isn't a long-term stable equilibrium; something will give eventually. But I think PHK is way overshooting how strong that argument is today.
Re: Civics is boring, so, let's encrypt something (2024)
#10If you weaken encryption so that your government can get access, now other sides can get access too. Including criminals and other governments. No I would not like to weaken encryption for my bank (obviously), my personal information (if only due to spear fishing), cryptographic authentication like passkeys in general and ssh keys in particular, and absolutely no one gets access to any teenager's phone anywhere. (unl…