5 ms·
Because breaking encryption breaks it for everyone. If the cops can get your data, so can a hacker. There is simply no way to compromise. You either are encrypt
by drcube 11y ago
Because breaking encryption breaks it for everyone. If the cops can get your data, so can a hacker. There is simply no way to compromise. You either are encrypted, in which case nobody but you can decrypt your data, or you're not encrypted at all.
Remember the "TSA locks" we're all required to use on our luggage at the airport? Nobody but the government was supposed to be able to unlock them. But now anyone who wants to ruffle through your luggage can get universal keys for all TSA locks. What happens when that same scenario plays out with your bank account, your company emails, or any online store you've made purchases from?
- quaunaut 11y agoI'm not arguing to break encryption. And neither is the white house. They want ways around this stuff- ways that don't break encryption, but if the information is available, then the ability to get to it if necessary. Backdoors don't work because yeah, it breaks the whole system. But not everything is encrypted with these companies, that's just plain.
- Zombieball 11y agoPerhaps I am not versed well enough in the subject, but I have a hard time envisioning any kind of system that allows government officials to get around the encryption and peer into the contents but not hackers. There will always be some sort of secret only the government has access to, and once that secret is leaked it's game over.
- quaunaut 11y agoYou don't give the government access to their own door. The company simply retains the right to access things- you know, the same way we have it now. All it's arguing, is to say "You don't have to encrypt literally every part of your system and delete the rest" a la what Snapchat suggests they're doing(though we don't have proof).
- BlackFly 11y agoThe White House is pressuring companies to not implement end to end encryption (see, for example, iMessage). Anything short of end to end encryption is considered broken by many people for communications between two parties. The only way the government can get the equivalent of a wire tap is if there is no end to end encryption. What police do not want is to need to go back to pre-telephone detective work where they need to determine the location at which the parties will communicate (with modern communications there are of course at least two locations) and compromise that location to spy on the supposed criminals.
- obastani 11y agoWhat if there was a way to give only the US government access to the data? For example, somehow have a shared encryption scheme where the user holds a decryption key to decrypt her data, but the government and the company can somehow use their keys in conjunction to decrypt the data as well. (This means company must be complicit in releasing the data, so they have the opportunity to verify/fight the warrant.) If someone came up with such a secure encryption scheme, would that be a palatable approach? I ask this because I'm curious whether you (and people in general) believe that hackability is the only obstacle to giving government access to personal data (with a warrant, of course), or if people would still be uncomfortable with such a system. Personally, I think such a scheme would be a good compromise, but I'm not a crypto expert so I don't know if it's in any way feasible.
- fossuser 11y agoI think the general opinion from the 'cryptowars' in the 90s is that there is no such scheme that does't cripple the actual security of encryption. Key escrow came up back then though I don't think it included needing multiple keys in order to decrypt - not sure if that's mathematically possible or if there's another reason that never came up. I suppose to the government that's not much different than still needing to compel individuals for the key. Your point about companies is interesting since things like iMessage could be MITM currently anyway to get unencrypted content for government requests. I think most people don't necessarily trust the company behavior here though and given the government's recently revealed behavior with National Security Letters and secret, massive, unwarranted data collection I don't think they should get a pass. I'd rather side on the power structure unable to collect some of the information even if they're unable to investigate. I think fundamentally introducing multiple ways to get keys takes a secure system and makes it insecure - the access no longer rests on one individual's knowledge. In general I think that's a bad idea - it also doesn't prevent people who want to actually encrypt their information from doing so (it just harms the regular public and dumber criminals).
- polymatter 11y ago> needing multiple keys in order to decrypt - not sure if that's mathematically possible As a matter of interest Shamirs Secret Sharing algorithm (https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing https://en.wikipedia.org/wiki/Shamir's_Secret_Sharing) is quite nice in that respect. The "secret" would be the decryption key. Using Shamirs Secret Sharing algorithm you could split the key into two so you would need both parts in order to work out the decryption key. The government could have a part. The company could have another. Only when both were combined could anyone work out the decryption key. This would mean neither the company nor the government could decrypt messages until they work together - and therefore reduce the risk of hackers and rogue employees. It wouldn't break the encryption with dangerous backdoors but would allow the authorities to quickly gain access when needed for a specific investigation. I doubt anyone would ever implement anything like that since it would be (slightly more) complex and you would have to trust that the decryption parts are valid. But I thought I would just mention it in case anyone else might find that algorithm as interesting as I do.
- sdenton4 11y agoto obstani's sibling comment: It's not possible to make a secure encryption scheme only accessible by the government. That's the point.
- jimktrains2 11y agoI've always been curious, what's the rationale for opening luggage? If there is an issue, should the person be summoned before the plane is loaded and boarded? If they think it's explosive, shouldn't the NOT TOUCH IT?
- pixl97 11y agoNot just bombs but every other type of contraband. Guns and drugs are the ones you commonly think of, but animals and plants can be a bigger problem, especially when you look at it in the international level.
- jimktrains2 11y agoBut again, why aren't I brought to be present?