3 ms·
The thing that concerns me about this perspective that everyday use of encryption is bad is that it makes no damn sense. Pandora's box is opened; if you force s
by FungalRaincloud 10y ago
The thing that concerns me about this perspective that everyday use of encryption is bad is that it makes no damn sense. Pandora's box is opened; if you force software solutions to backdoor their technology, someone will just step up who doesn't care about your laws. There are no global treaties on software development, and we aren't going to be signing any such thing any day soon. Even if we could force something like that down the throats of every country on Earth, the knowledge exists, and anyone can roll out their own solution with a high-school level understanding of the topic.
It's absurd to think this can be resolved through legislation or cajoling companies into cooperation. But what really bothers me about this whole issue is that we already have laws in place that handle this situation, at least in the USA. In the USA, if you refuse to hand over an encryption key (or can't) and are being compelled to by a court, you can and will be held in contempt of court, and possibly convicted of destruction of evidence. The only thing that forcing people to backdoor their crypto does is allow government entities to investigate people without having sufficient evidence to compel them to give up their keys, and destroy the marketability of large scale, centralized end-to-end encryption solutions.
I mean, you could make the argument that end-to-end encryption restricts the ability to wiretap people, sure, but a wiretap warrant should require a decent amount of evidence, and at that point, there are most likely other options.
- sergior 10y agoPeople can simply send random binary data to keep authorities busy.
- FungalRaincloud 10y agoThat would be somewhat entertaining, and reminds me of someone I read about years ago who was accidentally added to a watchlist, and no one was willing to remove him, so he started generating as much data as he could, just to keep them busy. I can't find a link, sadly. I don't think it's a good solution, though. This is going to sound like an argument that you hear about privacy by people who don't understand why privacy matters, but I think on this issue, it holds a little more truth: To be honest, I think the people who are likely to care to do this are people who are advocates for privacy and are tech savvy, and people who have something to hide. I don't think it's terribly difficult, with the resources the global Intelligence Community has to build a profile and dump people into those two buckets with a fair degree of accuracy. Everyone who's not generating random garbage data would still be observable, so it wouldn't really change much outside of the group that's acting. But for those acting, suddenly there's a red flag that they can look for, and then when they see it, start building a profile to figure out if you're a tech person with an interest in privacy, or someone doing something they don't want seen, and act accordingly. In the mean time, we waste time generating garbage instead of just using good enough encryption, and making it so easy to use that people don't even have to know they're using it. Now, if we could somehow implant babies with a chip that causes them to generate random noise (something babies are already pretty good at, mind you) from birth, that might be worth something. There's no profile building if the noise is just something that humans make by being alive.