18 ms·
A Back Door to Encryption Won't Stop Terrorists
- api 11y agoA back door to encryption would be a great tool for terrorists if it were leaked.
- kwhitefoot 11y agoWhen not if.
- ck2 11y agoThere's no evidence the plotters of the Paris terrorist attacks used encrypted communications First sentence is already wrong. They recovered smartphones that had encrypted messaging apps. Still no excuse for government backdoors which will be stolen by all kinds of entities within months of their creation and allow the wrong people to spy on law enforcement itself. Government had a 10 year headstart before all this, where are all the terrorists they stopped before this?
- swiley 11y agoMy phone has at least two encrypted messaging apps on it that I've been meaning to learn how to use. Everyone I know uses Kik though and has 0 desire to switch. So we really don't know that they where actually using them if that's all they really found.
- ck2 11y agoWell unless they factory reset the phones, which they obviously did not, android keeps usage stats on app so it would be obvious if the apps were used or not. But you are right, it could just be someone overstating something where apps have the ability to be encrypted, not that they were used that way. Still all these people were already known to their secret services. Some even had phone taps already. It was yet another intelligence failure like we saw on 9/11
- pera 11y ago> but debates about whether the technology should have a "back door" for intelligence services are heating up again What "debates"? there is absolutely nothing they can do to enforce terrorists to use backdoored encryption, any debate is just a waste of time, money, and maybe even lives. What are they thinking??
- stcredzero 11y ago> there is absolutely nothing they can do to enforce terrorists to use backdoored encryption, I suppose they could deceive the public and put something in without telling us. That would be a real improvement! Oh wait,...Snowden... The more I hear about what Diane Feinstein proposes in areas outside her expertise, the more I wish someone would defeat her in an election. She keep proposing stupid stuff that sounds good to uninformed rubes.
- pera 11y agoThe NIST curve (for instance) was not exposed by Snowden, he just confirmed what everybody already knew. I can't believe the CIA is this stupid, it's not possible, they want something else from all this anti-cryptography talking.
- uptown 11y agoWatch this clip around 1:48. According to Diane Feinstein, she seems to imply that she sensed 9/11 was coming: http://www.nbcnews.com/nightly-news/video/is-isis-video-about-an-attack-on-washington-a-real-threat-or-propaganda--567962691641 http://www.nbcnews.com/nightly-news/video/is-isis-video-abou...
- mangeletti 11y agoExactly. This is the same as gun control. If a technology exists, you cannot tell people to not use it; otherwise, all you've done is put law-abiding citizens at a competitive disadvantage while arming the bad guys. To argue otherwise is absolute ignorance.
- jacobolus 11y ago
- conwaytwitty 11y agoWhen X is illegal, only the criminals will have X. Replace X with basically anything.
- aero142 11y ago"When nuclear bombs are illegal, only the criminals will have nuclear bombs." I think your grand unifying theory needs more nuance.
- coldtea 11y agoI hope we don't depend on the unavailability of nuclear bombs to the bad guys on them being "illegal".
- aninhumer 11y agoNo, we depend on the enforcement of that illegality, which is usually assumed when people discuss banning something. (EDIT: Previously said "making something illegal", which I realised was ambiguous.)
- marcosdumay 11y agoWhat, do you plan to make talking about crypto illegal too?
- aninhumer 11y agoI was replying to the general sentiment, not the specific. Obviously banning encryption is ridiculous, but the "Only criminals will have X" argument is just silly rhetoric. EDIT: I just noticed the ambiguity you're more likely responding to in my original post. I'll reword it.
- Quinner 11y agoI think your nit-picking needs more thought, nuclear bombs are illegal for an individual to possess, and if someone had managed to obtain a bomb from say the former USSR, they would most definitely be considered a criminal.
- fapjacks 11y agoThis isn't about terrorists using encryption. It's about a culture of control, violence, and domination trying to extend its power to encrypted communiction.
- russnewcomer 11y agoEncryption backdoors are a lightning-rod topic on HN, but instead of repeating all the common-talking points, I'd suggest the following: Think through something like this, outside of your expertise, that you think the powers-that-be should just do. Maybe it's something with your local municipality's approach to road resurfacing, maybe it's the quarterback on your favorite football team, maybe it's your local zoning board. Chances are better than even that there is a decent technical reason why they don't do what they do. Looking at things that way will save you a lot of headache in your life, and set you on the path to getting on someone's side to affect change, rather than just being another shrill voice yelling against them. So politicians and intelligence services calling for encryption want, institutionally, to keep people safe. How can tech companies do that without breaking or backdooring encryption? That's the real problem to solve, and the first person to figure out how to do that will be way ahead.
- deleted 11y ago[deleted]
- lholden 11y agoThe best backdoor to encryption has always been social. Talk the right way to the right people... and it doesn't matter what type of security you have. Isn't that the entire purpose of agencies like the CIA? It just bothers me when privacy is treated as a negative thing, for the greater good or not. Encryption is a tool to create privacy. The ability to create privacy should be a point of pride as not everyone has that luxury. It should be a human right. This is the primary reason why I feel things like CISA/CISPA/etc take society in the wrong direction. It doesn't matter if the intentions are good or bad when everyone loses.
- A_Beer_Clinked 11y ago>The ability to create privacy should be a point of pride as not everyone has that luxury. It should be a human right. I agree; so does the UN in The Universal Declaration of Human Rights: Article 12. No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks. Article 18. Everyone has the right to freedom of thought, conscience and religion; this right includes freedom to change his religion or belief, and freedom, either alone or in community with others and in public or private, to manifest his religion or belief in teaching, practice, worship and observance. http://www.un.org/en/universal-declaration-human-rights/ http://www.un.org/en/universal-declaration-human-rights/
- mtgx 11y agoOh and by the way - the Paris terrorists didn't even use encryption: https://theintercept.com/2015/11/18/signs-point-to-unencrypted-communications-between-terror-suspects/ https://theintercept.com/2015/11/18/signs-point-to-unencrypt... How about that? Hopefully now the blame will be put where it should be: the wastefulness of mass surveillance, which dramatically increases the "noise" compared to the signals, since the agencies have to "look" at many more innocent people and waste time and resources doing so.
- coldtea 11y agoHow about this: we assume terrorists can fucking talk covertly whenever they like (since there are myriads of channels and codes that they can use) and that mass surveillance is not the way to catch them plotting their next act. And from then on, ONLY use surveillance on specific targets under investigation. And while at it, maybe even have a limit on the number of targets each agency can investigate, so they chose them wisely.
- ck2 11y agoThey already knew about most of these people and had wiretaps on a couple of them.
- api 11y agoMohammed Atta was also a person of interest. This has always been the case and was the case all the way back to 9/11, and it illustrates why mass surveillance won't stop terror. How do you tell the difference between someone who will actually act and someone who holds beliefs that overlap with terrorist ideologies or who simply talks trash on the Internet and is never going to do anything? Any dragnet will simply drown you in more false positives. Edit: lots of people saw Atta being a POI as a sign of a "let it happen" conspiracy, but the much more likely explanation is that he was on a very long list of watched persons. Being of interest for whatever reason is not a crime (and shouldn't be), so there is nothing the FBI or anyone else can do until someone actually does something. Of course then it's too late. Police can rarely stop crime unless they happen to luck out and be at exactly the right place at the right time. They can only catch criminals and take them off the street so they can't commit more crimes.
- ck2 11y agoMany of them are recruited in prison. Just like American prisons where petty criminals learn to become more violent and escalate their crimes when they get out because prison offers nothing else for them.
- fweespeech 11y ago> lots of people saw Atta being a POI as a sign of a "let it happen" conspiracy, but the much more likely explanation is that he was on a very long list of watched persons. Yep. Its a prime example of why these surveillance powers simply don't function the way their proponents claim in public. A large part of the reason there are these conspiracy theories is because their failures seem to be spun so well they might as well have been planned for all intents and purposes. They immediately blame other people and clamor for money and power to further their interests ... and people actually take them seriously which to me is the scary part. France has the most extensive mass surveillance capability of any first world Democracy and the ability to act without the permission of the courts or legislature ... yet it wasn't enough. I don't see how "more power" is the answer. It seems to be me that suicidal people are going to be successful at taking other people with them no matter what we do. So we take reasonable precautions that don't infringe on everyone's liberty. Then we make sure people who ignore actionable intelligence have career ending consequences to make them accountable.
- helicon 11y agoThe IRA were known to recruit top stem students from universities in Ireland during their campaign to make bombs. Surely an entity as large and as well financed and ISIS would have little trouble finding bright young engineers & technologists sympathetic to their cause to simply build their own encrypted services? And then so much for the spooks 'backdoors'
- BinaryIdiot 11y ago> Surely an entity as large and as well financed and ISIS would have little trouble finding bright young engineers & technologists sympathetic to their cause to simply build their own encrypted services? You wouldn't even need the brightest engineers. In fact so many encryption algorithms have been opened sourced and / or in library form for so long that it's easy for practically any developer to do.
- drdaeman 11y agoJust having a library that does something doesn't magically bring security. The issue is, engineer still needs to know a lot of stuff (or strictly conform to the instructions) to use the thing correctly. There are too many ways to screw the thing up without even knowing it. So, if the thing's to slap some nice GUI upon an existing library that implements the security bits, then almost no knowledge's required. But if one has a library full of primitives but still has to combine them in a meaningful way - it's a damned minefield.
- nickpsecurity 11y agoThat statement shows you haven't spent any time researching the security of secure messaging solutions. Or security software in general. Virtually all of them had protocol or implementation flaws with most having flaws so severe that cryptographers and top programmers saw fit to write books detailing how to do it right. Books most people making "private" apps still haven't read. ;)
- mike_hearn 11y agoBecause PGP has been so successful? The tactic you're suggesting has been tried before (the software was called Asrar, I think). It doesn't work well for them, for a couple of reasons: 1) Custom terrorist software is no easier to use than something more mainstream like PGP, but is a lot more incriminating if you're found to be using it. 2) Is it really made by fellow jihadis? Or is it a backdoored plant by western intelligence? How can you know? The latter question is a bigger issue than you'd expect. Terrorists don't like to helpfully announce their real names and backgrounds on their websites, so the provenance of jihadi software is frequently unknown. It just sort of floats around on the internet. So it can be much harder to trust than just a plain old copy of PGP. You might think that IS can solve these problems because it's bigger and more organised than a group like al-Qaeda. But it's not like IS has an official website with a nice SSL certificate and a big download button (CA's will generally not sell to sanctioned entities). They use networks of ad hoc and quickly suspended twitter accounts to communicate, and apparently, Telegram. So for them to distribute custom crypto software wouldn't be easy.
- oppositelock 11y agoBack doors are very useful to tracking down tax evaders, political opponents or dissenters, or any other number of things which increase government revenue or power. Terrorism is just one excuse used to justify the rest of it. Crypto backdoors will be mandatory one day, it's inevitable.
- RankingMember 11y agoIt's inevitable only with an attitude of "it's inevitable".
- reddytowns 11y agoIf you believe it, it will come true!
- sliverstorm 11y agoI like how we are lumping together tax evaders and political opponents, as if it was equally wrong to apprehend both.
- Steuard 11y agoThe line at the end that really hit me was this: > Almost all the attackers were known to the authorities, and if they had been watched, their use of encryption programs would have itself invited closer scrutiny. This is precisely the scenario that Phil Zimmermann (creator of PGP) and others have been warning about (and working against) for decades. As Zimmermann said in a 1999 essay linked here not long ago, "What if everyone believed that law-abiding citizens should use postcards for their mail?" (https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html) The scary part to me is not just that it's our present reality, but that it's so readily accepted. Crypto advocates need better PR. (And to be fair, better UI.)
- giancarlostoro 11y agoBetter UX as well, but I guess you implied it. The only apps I can convince friends to use that support encryption are the seamless ones.
- randyrand 11y agoIf they know there's a backdoor to one type of encryption wont they just use a different form of encryption?
- tw04 11y agoI've gotta believe these organizations can find one or two developers among the billions of muslims on this planet. Why wouldn't they just write their own apps for android and call it a day?
- vonklaus 11y agoThe Mexican cartels captured and paid engineers to build them there own private cell network[0], so it isn't out of the realm of possibility that ISIS is doing something similar. I am sure they have at least a few engineers kicking around what amounts to be an entire country. I haven't heard many people harping on about encryption, TBH, except people defending it here and that idotic NYT article. However, if you had 10 amazing engineers you would likely have strike capabilities orders of magnitude higher than a few suicide bombers. So sure, gather surveillance, but let's play some defense. Shore up our infrastructure much better than we do now, because after they make their own apps and networks, they are going to come for ours potentially. [0]http://www.wired.com/2012/11/zeta-radio/ http://www.wired.com/2012/11/zeta-radio/
- jacquesm 11y agoThey could and they did. They have recruited quite a few people with more than just basic IT knowledge.
- kmonsen 11y agoThis is to control the population, and it will get asked for every time there is a nice excuse.
- hbbio 11y agoApparently, the terrorists that attacked the concert hall in Paris last week were using... unencrypted text messages to communicate between themselves and/or their "boss". According to the newspaper Liberation [1], they sent a text message at 9:42pm telling: "we're out we begin". [1] http://www.liberation.fr/france/2015/11/18/la-piste-du-sms-envoye-par-un-des-terroristes-du-bataclan_1414317 http://www.liberation.fr/france/2015/11/18/la-piste-du-sms-e...
- l0stb0y 11y agoI always assume these types of stories are red herrings and intelligence agencies already have back doors or decryption methods that they want to keep hush. Make a big song and dance about how encryption is secure and push criminals towards it, meanwhile its a trap. Look at all the Tor takedowns as evidence. It's all fine by me really.
- nickpsecurity 11y agoLike they did with iPhone, etc before Snowden showed they had compromised it all? ;)
- yourepowerless 11y agoAmazing, a government apologist is top comment, I'm sure there's no astro turfing going on here! Ask people who work in policy, the reason things are a certain way is rarely technical, its usually political, which is a qaint way of saying decisions are made by corrupt power brokers.
- jacquesm 11y ago> a government apologist That's entirely uncalled for. Just because you disagree does not make someone a government apologist. I guess you'll call me a government apologist next.
- yourepowerless 11y agoHe is defending a corrupt institution which has repeatedly lied, tortured and murdered. Also,what he wrote is wrong, chances are not better than even that some random issue is a certain way because of some complex technical reason, most decisions in DC are made through the lens of politics, ask anyone who works in policy and they will say the same.
- jacquesm 11y agoI might even agree with you. But that's no reason to resort to name-calling. Attack the reasoning, not the person.
- yourepowerless 11y agoAn apologist is one who defends a particular view, I really am struggling to understand what you intending to express. The OP wrote is wrong, just plainly wrong, he also dismisses out of hand the real concerns of state overreach. I've seen astro turfing on HN before, unfortunately mods seem more interested in sweeping such incidents under the rug than being upfront with the community. Or perhaps HN really isn't very sophisticated if his comment gets top spot, but more than likely comments in politically sensitive topics are heavily manipulated. EDIT: then link me to where mods have an open discussion with the community concerning government astro turfing. And tell us what is occurring to mitigate such incidents.
- jacquesm 11y agoSo, here's my take on all this 'surveillance is good for you'. It more or less proves (to me at least) that the government(s) and the various secret services have absolutely no idea who to monitor specifically. So instead of targeting their operations they want to monitor all of us, just in case something of interest pops out that then allows them to focus their attention. It's a pretty scary thought: just imagine, all that money, all those resources and still they can't do anything other than to put their ear to the ground and hope that someone messes up in plaintext so they can then try to backtrack and see what they might have missed. In all these attacks it never happened that everybody was under the radar. Always one or more of the attackers that were technically known or even already under surveillance. And yet the attacks happened anyway. Too many targets make for a very thinly deployed service, which then has to be automated to make it work at all. It's a pretty sobering thought, it also suggests via yet another route that mass surveillance is indeed meant to attempt to 'keep us safe', and that it fails miserably. The road to hell is paved with the best of intentions. Terrorists have it so easy, all they need to do is to be just a little bit unpredictable or simply old-fashioned (in person) and there won't be anything whatsoever that we can concretely do to stop them. The only thing that actually gives a bunch of actionable data is when an attack is executed or when an attack goes sour (or rather: sweet as in, it does not work) from which direct evidence of contacts or plans is gained. This will then lead to a relatively short lived number of arrests clustered around the people caught or implicated and then it burns out again where the data ends. And so then we get to wait for the next attack...
- JupiterMoon 11y ago> It more or less proves (to me at least) that the government(s) and the various secret services have absolutely no idea who to monitor specifically. So instead of targeting their operations they want to monitor all of us, just in case something of interest pops out that then allows them to focus their attention. Except that most of the recent terror attacks have involved at least one person known to the authorities. One of the Paris attackers even had an international arrest warrant out for him.
- jacquesm 11y ago
- staunch 11y ago"I was able to leave and come to Shām (Syria) despite being chased after by so many intelligence agencies. My name and picture were all over the news yet I was able to stay in their homeland, plan operations against them, and leave safely when doing so became necessary," Abaaoud claimed in the interview, according to ISIS." http://www.cnn.com/2015/11/16/europe/paris-terror-attack-mastermind-abdelhamid-abaaoud/index.html http://www.cnn.com/2015/11/16/europe/paris-terror-attack-mas...
- p01926 11y agoThis is like in WWII, when Churchill and Turing gave so many newspaper interviews re: how awful it was they couldn't crack Hitler's encryption anymore that he finally gave in, went back to the 3-rotor Enigma machines and we won the war.
- jiantastic 11y agoAs with most things, I think that it is a trade off. There is a very delicate balance between security and privacy. Too much surveillance - General public feels incredibly uncomfortable due to lack of privacy - An incredibly scary amount of power in the hands of whoever has access to that information ( and who knows what they will do with it ) - Reduced risk of terrorism and security concerns Too little - Increased risk of terrorism + massive security concerns due to lack of intelligence ( it's like trying to find a needle in a huge haystack ) - Public feels safe due to perceived increased privacy and yet feels unsafe due to ( potentially ) increased number of terrorist incidents. It's a rather difficult problem to solve. How can we extract critical security information without invading people's privacy?
- MarkMc 11y ago"Almost all the attackers were known to the authorities, and if they had been watched, their use of encryption programs would have itself invited closer scrutiny." Well, unless they were using WhatsApp or iMessage, which almost everyone uses.
- MarkMc 11y agoGovernments regularly intercept plain old SMS messages. If the government can demonstrate cases where this has prevented a terrorist incident in the past, wouldn't that suggest that similar snooping on iMessages would prevent terrorism in future?
- zaroth 11y agoI think this article misses the most obvious point. Encryption is widely available for free and in the open. It's not about listing the devices or code they might not trust, if there's even one that they do trust, then you can backdoor everything else and it won't matter. Why do they think they can put the Genie back in the bottle? The answer is they know that they can't, the backdoor only effects the people who don't care they are being tracked. It's not for terrorists, it's for people who carry smartphones. Which is almost everyone, so good enough for them. But the argument is absolutely nothing to do with "preventing terrorism".
- TeMPOraL 11y agoI think the entire discussion misses the even more important point - terrorists won't care whether encryption is backdoored or not. It's a good OPSEC to assume all communication is being listened to anyway, and to rely on steganography and disappearing in the noise. Bad guys will simply use the same backdoored crypto everyone else will be using, communicating in the same way they do today, because using the unbroken crypto will be easily detected as suspicious action.
- kbart 11y ago"rely on steganography and disappearing in the noise." They already do that[0]. 0. http://arstechnica.com/business/2012/05/steganography-how-al-qaeda-hid-secret-documents-in-a-porn-video/ http://arstechnica.com/business/2012/05/steganography-how-al...
- TeMPOraL 11y agoYes. My point is, they'll keep doing that, so backdooring encryption doesn't really help in any way.
- mrmondo 11y agoTerrorism, anarchy, and general mischief all existed long before the Internet and will undoubtably outlive it.
- akerro 11y ago> A Back Door to Encryption Won't Stop Terrorists It' not like terrorists use Twitter
- Khaine 11y agoI think one thing we as a tech community overlook is the expectations on the intelligence community. The broader community expects the intelligence agencies to stop ALL terrorists attacks, and thats just not feasible. This drives the intelligence agencies to do more, which is why I think there is a big push for broad dragnet activity.