5 ms·
It's not just chilling, it's insane. A crypto-secured digital communication should be analogous to sending an untampered with letter, or having a private conve
by cb18 11y ago
It's not just chilling, it's insane.
A crypto-secured digital communication should be analogous to sending an untampered with letter, or having a private conversation in a secure location.
Just because the medium being communicated over changes, doesn't mean we should adopt wildly regressive policies.
By proposing that all this 'cryptographically secured'[0] communication can be accessed at a later date, they're basically saying that the contents of all snail mail letters should be photo copied, and all private conversations should be recorded.
[0] If there is a possibility of 'technical assistance,' then it is not cryptographically secure.
- rayiner 11y ago> A crypto-secured digital communication should be analogous to sending an untampered with letter, or having a private conversation in a secure location. I don't think anything in the bill requires a provider to keep around copies of information they don't already keep. They need to be able to provide access contemporaneously with transmission (i.e. basically a wiretap), or if they have stored it or can access it on the device. If you receive a sealed letter and the police get a warrant, they can search your drawer and open that letter. If you have a private conversation with someone, a prosecutor can subpoena that person and force them to testify about what you told them. I'm amenable to the argument that the law shouldn't stand in the way of progress; it's possible to communicate much more securely now than it ever was in the past and the law shouldn't stand in the way of people taking advantage of those advances. But the bill isn't "regressive"--it's attempting to maintain powers the police already have with traditional means of communication.
- newjersey 11y ago> If you receive a sealed letter and the police get a warrant, they can search your drawer and open that letter. If you have a private conversation with someone, a prosecutor can subpoena that person and force them to testify about what you told them. If you are a bank with a lock box, are you required to have a key to a safe that a customer installs inside the lock box to store their valuables? Of course, a court can order you to give what you have but how can they order you to give them something you don't have?
- rayiner 11y agoThe bill only imposes obligations to the extent the service provider offers the feature that makes information unintelligible. So it would not apply to encryption the customer uses themselves that aren't provided by the service. And yes, courts regularly order banks to drill into their safe deposit boxes.
- woodman 11y ago> ...to the extent the service provider offers the feature that makes information unintelligible... Hardware manufacturers as well. Say goodbye to bios passwords, hard drive smart locks, SSD encryption that permits instant formats and the only way to ensure that bad blocks don't leak your data to ebay buyers.
- newjersey 11y agoSo this is pretty much a ban on encryption. So would gpg4win be required to take a copy of everyone's private key who uses their software to generate private keys? Have they thought this through?
- cb18 11y agoHow do you feel about encryption? Do you think it is a good and worthwhile thing for the modern world? If multi-billion dollar companies were mandated to spend their development efforts on ineffective, insecure cryptographic systems, do you think that would be a positive or negative thing in terms of the availability and proliferation of the kind of effective and secure cryptographic systems that 'customers use themselves'?
- etjossem 11y agoThe way the bill would accomplish that goal is the problem. A warrant is a court order allowing police to work within a very narrow scope - a single tapped line or residence to be searched. It doesn't force the phone company to build a machine that can tap every phone call in the city at once. If that's what wiretapping entailed, bad guys would have stolen a lot of mass-surveillance boxes by now. This is broad-scope. It would compel encryption providers to maintain a master key to decrypt all traffic running through them. A single security incident with one of those providers would be enough to compromise the data of every customer. Communications providers to large American businesses with foreign competition would immediately become incredibly high value targets for bad actors.
- chris_wot 11y agoI also gather that "technical assistance" means "backdoor". If that's the case, then it's ridiculous and it appears nobody in the U.S. Government has learned from history. When they did this with export controls on encryption the only people overseas who had access to proper encryption were those who were outside the law, and those who developed encryption in countries that don't have restrictions. Of course, I may not be following what is meant by "technical assistance". However, if such a term doesn't mean implementing a backdoor, then if unbreakable encryption is implemented then it won't matter how much technical assistance is rendered by U.S. companies, nothing will have been achieved except wasting a lot of company dollars on a futile effort!
- woodman 11y ago> I don't think anything in the bill requires a provider to keep around copies of information they don't already keep. Password hashes, if this were to become law then you'd have to store them in clear text or encrypt them with a controlled key. You frequently see that sort of practice turn up in massive security breaches. Also, homomorphic databases are out - you can't provide a service without being able to deliver plaintext to the state. So no decentralized security, you'd be forced to choose, during the handshake, between clear text or a CA model that offers no protection from state level attackers - which is no coincidence. > But the bill isn't "regressive"--it's attempting to maintain... Device manufacturers are covered. So even if it is unrelated to an ongoing service, it is still required to render assistance in compromising the product. That is regressive. And I've only mentioned the primary impact, this thing would make the manufacture of end user serviced devices economically impossible. Unless we had a less horrible alternative... what if manufacturers where offered the alternative of installing a key escrow chip? I could swear that I've heard that idea proposed before. Edit: I forgot to include software developers, so let your imagination run over that. That bitlocker feature offered by Microsoft? That is covered.
- rayiner 11y agoI'm referring to the analogy to "photocopying snail-mail letters." I don't read anything in the bill to require companies to keep a history of the communications. It contemplates situations where the government has obtained the encrypted communications by some other means. > So even if it is unrelated to an ongoing service, it is still required to render assistance in compromising the product. That is regressive. "Regressive" means stepping backward from the status quo. The government can already compel your bank to drill your safe deposit box; it can subpoena your accountant to spill the beans on the complex financial transactions he arranged for you; etc. Compelling assistance from tech companies might be a bad idea, but it's an extension of the status quo.
- woodman 11y ago> I don't read anything in the bill to require companies to keep a history of the communications. That isn't what I said or what I addressed. You said "...keep around copies of information they don't already keep.", that isn't true - for the reasons I previously explained. It isn't restricted to "communications", it is for any stored data - if you get it in plain text then you are required to render on demand in plain text. You are not allowed to use forward security as a feature of your product. > "Regressive" means stepping backward from the status quo. I know what the word means, you've misused it. The USG making it illegal to render information unusable to them for some theoretical future investigation is not the status quo. That logic would make manufacture of paper shredders illegal.
- cb18 11y agoIf you receive a sealed letter and the police get a warrant, they can search your drawer and open that letter. Also, if you have a letter, you can discard of it as you see fit, and the information therein vanishes into the aether. This agency is removed when we move into the realm of bits over digital networks, where information can be copied and retained without one's authorization. The agency to discard of the letter as you see fit, at a time of your choosing is in effect restored through the use of strong cryptography. If you have a private conversation with someone, a prosecutor can subpoena that person and force them to testify about what you told them. Having an unauthorized recording of an event, and asking someone to recount an event are very different things. attempting to maintain powers It's not about the 'police maintaining powers they already have' because the situations are different. If the situations were the same, the powers would be the same, and this conversation wouldn't exist. The situations may seem similar to you, because we make sense of the world through analogy, but there are important differences. The essentially instant and infinite nature of bits and digital data allows for all those 'warrants' and 'subpoenas' to be 'served' before they have even seen a judicial system. I.e. governments can suck up all the 'locked' data into giant 'pre-crime' databases. Or, require that communication networks retain data, when it's not already happening as a matter of course. If governments are then given the key to that locked data they essentially have a time machine to attempt to dredge up any evidence, or whatever they want from people's personal effects. There's nothing similar about that to anything. Nothing like that has ever existed in the history of the world. So we have a new situation, and with it a new choice to make. This choice requires we ask ourselves, Do we want to lean towards tyranny or lean towards liberty? Terms like 'progress' are relative and subjective, but still useful when there is mutual understanding. What is being progressed towards? A freer society with less potential for government overreach and tyrannical actions. So in that case, yes this bill is regressive. And, that's just one aspect of what makes this bill objectionable, and frankly, retarded. Anyone with an inkling of how the modern economy works and it's reliance on cryptography, knows that this bill is ridiculous. The simple matter is that you can't have modern strong cryptography with 'backdoors,' or whatever doors. It doesn't exist, it never will, the two are mutually exclusive. And further, the cryptography genie is not going back in the bottle, that is just as inconceivable. So it would be best for everyone if governments educated themselves on these matters and stopped wasting everyone's time and money on this.
- AnthonyMouse 11y ago> it's attempting to maintain powers the police already have with traditional means of communication. I recently watched the first season of The X-Files, circa 1993. Someone kidnaps Scully. Mulder traces the kidnapper's call to Scully's cell phone, which as a cell phone was then considered impossible to locate. The protagonists repeatedly bought airline tickets with cash under assumed names to avoid government surveillance. Mulder is at one point punished by being assigned to transcribe many hours of audio surveillance. That was the state of the art not so long ago. There was no CALEA. Surveillance was an extremely labor intensive process. Mass surveillance was unfathomable. There was no after-the-fact record of the contents of realtime communications. You either had a warrant ahead of time and planted a bug in the suspect's house and paid for many overtime hours for agents to sit in a van listening to the suspect talk, or everything the suspect said was gone as soon as they closed their mouth. And there is still nothing that stops them from doing exactly that. Except now the bug is smaller and less expensive and they don't need a van to be in range of the transmitter and there is software to do the audio transcription and other software that will convert an audio recording of key presses into the text of the key presses and on and on. People could encrypt 100% of everything in the world and the police would still be a thousand light years in front of where they were back then. If this "maintenance of traditional powers" argument is to mean anything then it has to go both ways. It can't be that technologies that make privacy invasion easier are allowed and technologies that make it harder are prohibited. And it seems like it would make a lot more sense to let both citizens and police-with-a-warrant use whatever technology each can devise rather than hampering both to the detriment of everyone in an attempt to artificially maintain some largely subjective measure of balance.
- visarga 11y agoLaws don't matter so much because it's mostly a technical matter. 1. Surveillance tech advancement will guarantee that in the future there will be even more of it, cheaper and more accessible through search and machine learning analysis; even if you don't use the internet, your face is still recorded on surveillance cameras, your financial transactions reported, and so on. Even if your state does not do internal surveillance, various companies and foreign states will. 2. The nature of social networks makes it very very expensive to maintain communication private, and in some cases impossible. Even if you use Tor, you still can't post on your regular FB page, or connect to any of your online accounts without disclosing your identity 3. They still can't stop people from communicating in secret, especially with a combination of steganography and cryptography, but that will be increasingly more difficult 4. People will increasingly self censure, with devastating effects on the balance between political class and the rest of society So it's a defiant march of technology, nothing can stop it at this point. Privacy is dead, it died around year 2000 with the apparition of digital cameras, mobile phones and huge data centers. I think part of the solution will require that we create new social standards around privacy and tolerance for various indiscretions we will do inevitably. Otherwise, it will be worse than the inquisition. Everyone watching you, all your actions judged by the mob or the powerful, blackmail material for everyone.
- mtgx 11y agoFeinstein and Burr have forgotten (or maybe never knew it) that their role in the Intelligence Committee is to act as oversight for the NSA and CIA, not as their PR department. It's as if they think their role in the Intelligence Committee is to do the intelligence agencies' bidding - not the other way around. That's what's insane and what has already gotten too far. There is no intelligence oversight in the U.S. The intelligence agencies seem to be running the Senate, or at least the Senate Intelligence Committee.
- alsetmusic 11y agoWhen I wrote to Feinstein in the past, I received a form letter telling me that her mind was already made up and that she knew was was in my best interest. She didn't even have the courtesy to lie and say that she would consider my opinion. I'm in her district, and I lost a lot of hope at that moment.
- vamega 11y agoAny chance you'd be willing to post the form reply?
- lern_too_spel 11y agoShe's a senator. She has a state, not a district.
- bdhess 11y agoIn fairness, there are 40 million people in her 'district', so your chances of an individualized reply and/or influencing her opinion on any controversial matter would have to be quite low.
- alsetmusic 11y agoThe point of my comment was not that I received a form letter but that it's tone was condescending.
- visarga 11y ago> and all private conversations should be recorded. When they realize people can talk to each other in private, they will surely outlaw private space.
- anexprogrammer 11y agoThere is a long history of tampering with the mail. It wasn't merely the preserve of the Stasi et al. It's one of the reasons most countries sought to retain government monopoly until comparatively recently. https://en.wikipedia.org/wiki/Postal_censorship https://en.wikipedia.org/wiki/Postal_censorship