13 ms·
Republicans Push Bill Requiring Tech Companies Give Encrypted Data
- mjparrott 6y agohttps://www.youtube.com/watch?v=UMDXdxQc4SU https://www.youtube.com/watch?v=UMDXdxQc4SU
- dane-pgp 6y agoI hope I'm not spoiling the joke, but the title of the video above is: "Tale As Old As Time - Lyrics - Celine Dion and Peabo Bryson"
- ilstormcloud 6y agoI'm an African. I've lived through fantastically corrupt, despotic, authoritarian rule riddled with nepotism and kleptocracy. I find GOP politics to be disturbingly familiar. And it reeks of regulatory and state capture.
- ensignavenger 6y ago"Republicans" in this case is not the entire GOP, but rather only three politicians who also happen to be Republicans. There are probably plenty of other Republicans who would support this, and plenty who would not. And probably plenty of Democrats who would support it, and plenty who won't. Hopefully the won't category will be much larger than the will category, but I doubt the support will be exactly along party lines.
- deleted 6y ago[deleted]
- dfsegoat 6y agoI don't really think it is that cut and dry. Case in point, a similar bill (as I understand it) - The EARN IT Act was spearheaded by the same people as this bill, plus Dianne Feinstein (Democraft of CA): "The EARN IT Act was introduced by Sen. Lindsey Graham (Republican of South Carolina) and Sen. Richard Blumenthal (Democrat of Connecticut), along with Sen. Josh Hawley (Republican of Missouri) and Sen. Dianne Feinstein (Democrat of California) on March 5." https://www.theverge.com/interface/2020/3/12/21174815/earn-it-act-encryption-killer-lindsay-graham-match-group https://www.theverge.com/interface/2020/3/12/21174815/earn-i... Also: https://www.wsws.org/en/articles/2020/03/17/earn-m17.html https://www.wsws.org/en/articles/2020/03/17/earn-m17.html
- TulliusCicero 6y agoFeinstein is widely despised by progressives for, among other things, being a hawk. That she would also be anti-freedom here is not a huge surprise.
- throwaway0a5e 6y agoThere's plenty of others like her. Neither party seems to have many in congress who want the government to have less dragnets and power to micromanage.
- TulliusCicero 6y agoI think there's quite a few Democrats like that, actually, but certainly not all.
- nickff 6y agoThere are a bunch of Republicans too.[1] [1] https://en.wikipedia.org/wiki/Liberty_Caucus https://en.wikipedia.org/wiki/Liberty_Caucus
- ilstormcloud 6y agoOf course, nothing is ever black and white. I did not mean to imply all of the GOP is terrible and the other side is good. I am merely stating, looking from afar, it's the GOP politics that seems most familiar, in general.
- dependenttypes 6y agoBoth parties push that. This case happened during clinton for example https://en.wikipedia.org/wiki/Bernstein_v._United_States https://en.wikipedia.org/wiki/Bernstein_v._United_States This is the real problem with america. Not that one party is evil but that both parties are, there is no choice.
- season2episode3 6y agoWhile both parties are certainly beholden to big donors, I think the equivalency argument ends there. When it comes to issues of money in politics (e.g. campaign finance), issues of government transparency (e.g. financial disclosures), or environmental protection, the differences are night and day. You do have a point about civil liberties though. Both parties have become pretty extreme (on opposite sides of the ideological spectrum) about where to draw the line between acceptable/unacceptable discourse. I fear that the Dems have become too toothless to take on big tech companies due to the vast sums they receive from said companies. Nevertheless, anti-cryptography legislation still seems to be the GOP's play these days. The Dems of the 1990s are hardly equivalent to the Dems of 2020, especially with an ascendant activist wing running more and more of the show.
- Consultant32452 6y agoDemocrats increased the spying powers and war budget of a President they genuinely believed to be a Russian puppet.
- nickff 6y agoWell, there is also the possibility was that they were exaggerating the degree to which they actually believed he was a puppet.
- Consultant32452 6y agoDemocrats impeached a President over something they didn't really believe was true.
- staplers 6y agoWe've all been shown recently how law enforcement only protects certain segments of society. This will only get worse with draconian surveillance.
- hn_throwaway_99 6y agoI think politicians must win prizes or something for showing who is the stupidest: > The bill also allows the attorney general to create a competition with a prize for anyone who can come up with a way to access encrypted data while protecting privacy and security. Security experts have long noted that this is an impossible request. Why they're at in, why don't they push a bill for permanent rainbows. Also, the article states "The proposed legislation stops short of requiring tech companies to create a backdoor", so if end-to-end encryption is still available, this legislation does nothing. And if lawmakers try to ban end-to-end encryption, well then "banning math" should be the name of this legislation (yes, I realize politicians have tried to do that before). Sure, large companies may comply and average joes may get less E2E encryption, but anyone who knows anything about tech will be able to get access to E2E encrypted messengers.
- tux1968 6y agoDon't attribute to stupidity that which can be explained by malice. It's only stupid if you accept their ostensible rationale, but it makes perfect sense if they're trying to pry open the data of the average citizen, not some mythical terrorist.
- srmatto 6y ago>"a prize for anyone who can come up with a way to access encrypted data while protecting privacy and security." A prize for a cake that can be eaten but will never be consumed.
- solotronics 6y agoI think nanobots could accomplish this. The end result might be unexpected though...
- kevin_thibedeau 6y agoIt should be a square pie.
- fnord123 6y agoEach time you want an encrypted session you need to make a request to the government third party key signing service that, with your public key, the public counterparty's key and a government generated key for your session, a new key for the session is produced. It's possible but potentially expensive and has issues with who gets keys on international communication. And it's also dumb.
- rudolph9 6y agoHere is the senate page on the Bill https://www.judiciary.senate.gov/press/rep/releases/graham-cotton-blackburn-introduce-balanced-solution-to-bolster-national-security-end-use-of-warrant-proof-encryption-that-shields-criminal-activity https://www.judiciary.senate.gov/press/rep/releases/graham-c... > Bad actors exploit warrant-proof encryption to shield dangerous and illegal activity —including terrorism, child sexual abuse, and international drug trafficking — from authorities. Bad actors also exploit warrant proof use of their voice to send sound waves directly at other bad actors ears to shield dangerous and illegal activity —including terrorism, child sexual abuse, and international drug trafficking — from authorities. I realize that end-to-end vs speaking verbally is a bit of a leap but bills like this make it seem like they don’t want US citizens to have a voice.
- AdmiralAsshat 6y agoDang, they were so close to mentioning all four: https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalypse https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp... I guess money-launderers are no longer on the target list. Too much of a white-collar crime, these days.
- season2episode3 6y agoMoney launderers are in command of the Justice Dept at this point.
- drocer88 6y agoHere is the actual bill for those who want to read it: https://epic.org/crypto/OLL20597.pdf https://epic.org/crypto/OLL20597.pdf
- DoubleGlazing 6y agoIf they get such a law enacted, then people who really care about end to end encryption will simply "opt out". There are so many open source crypto tools out there with no backdoors that anyone savvy enough to find them and use them will do so. Of course the average user probably wouldn't care enough to do that, but maybe a few privacy scandals could change all that.
- hundchenkatze 6y agoI agree, but I also think that, if successful, the law could have the knock-on effect of criminalizing all unsanctioned (read functional) crypto tools. edit: *leading to arguments like "Oh, you have Signal on your phone, only criminals use Signal."
- dane-pgp 6y agoUnfortunately such arguments are very likely to be made, given that Chief Justice Roberts already suggested in 2014 that a person carrying two cell phones might reasonably be suspected of dealing drugs: https://www.techdirt.com/articles/20140501/01194327086/supreme-courts-real-technology-problem-it-thinks-carrying-2-phones-means-youre-drug-dealer.shtml https://www.techdirt.com/articles/20140501/01194327086/supre...
- pengaru 6y agoCan't companies already be compelled to push updates to select devices adding a decrypted sidechannel to "e2e encrypted" apps, effectively providing a wiretap when a warrant is in hand? There's no need to weaken the encryption at all when end-users don't actually control the software they run day-to-day. Just replace the software while they're asleep.
- suizi 6y agoPart of the point of end-to-end encryption is that you explicitly don't trust these companies. Would anyone be willing to trust them if they went around pushing malware on a whim?
- jonny_eh 6y ago> Can't companies already be compelled to push updates to select devices Nope. Can you link to an example?
- pengaru 6y agoLavabit shut its doors to not comply with such requests.
- LinuxBender 6y agoI do not have a current link because the software was acquired bty AT&T and intentionally does not have a public name any more, but all phones used to have CarrierIQ. In debug mode, it could intercept any facet of code execution, network communication (pre-tls), log all finger movements, log phone movement and velocity. To put into debug mode, the phone just needs to receive a http header when it checks in for updates. It will log all the data, upload it and disable debug on a follow up header. The software can be installed over the air with no user interaction or notification. This was supposed to move to the firmware module to avoid users rooting the phone and removing it, but I honestly have no idea if or how that progressed.
- dane-pgp 6y agoThat may be the case in Australia at least. From [0]: "if an agency were undertaking an investigation into an act of terrorism and a provider was capable of removing encryption from the device of a terrorism suspect without weakening other devices in the market then the provider could be compelled under a technical assistance notice to provide help to the agency by removing the electronic protection" As for the US, I wouldn't be surprised if the government has sought to achieve something like this using the All Writs Act[1]. However, in the recent case of Facebook helping the FBI with a targeted use of a vulnerability[2], it seems that they cooperated voluntarily, even paying a third party contractor to help. [0] https://www.computerworld.com/article/3460071/encryption-has-the-government-stuck-to-its-no-backdoors-pledge.html https://www.computerworld.com/article/3460071/encryption-has... [1] https://en.wikipedia.org/wiki/All_Writs_Act#Application_to_electronic_devices https://en.wikipedia.org/wiki/All_Writs_Act#Application_to_e... [2] https://gizmodo.com/report-facebook-helped-the-fbi-exploit-vulnerability-i-1843988377 https://gizmodo.com/report-facebook-helped-the-fbi-exploit-v...
- indigochill 6y agoSo... the legislators seem to be targeting "warrant-proof" encryption. Now... correct me if I'm wrong, but law enforcement can use due process to obtain access to a suspect's phone, and that phone will then decrypt the communication for them, right (even if the service provides true end-to-end encryption, which most don't)? So what's the problem?
- slaymaker1907 6y agoOften not if the phone is password protected, though increasingly popular biometrics provide no such protections. The idea is that providing a password is equivalent to providing testimony and is thus protected. The law on this is not fully settled yet and varies by jurisdiction.
- indigochill 6y agoAre there issues with removing that protection from providing passwords? Intuitively, it feels to me like if police can compel an individual to let them search a house with a warrant, the same should be true of a computer (there may be incriminating evidence on it, but there may be incriminating evidence in the house, too, so I don't see this as being any more or less self-incriminating than textbook warrants). Moreover, if this didn't introduce glaring problems I'm overlooking, it would be a great way to cut out the legs from the "let's just backdoor everything" agenda. The key thing being the law enforcement agent has to present their warrant to the suspect.
- chillacy 6y agoSearching your phone might be more like searching your mind, as phone usage is almost an extension of your mind: containing notes, photos, messages, etc. That it's protected with a password which would require compelling self incriminating speech for makes it even more troublesome to acquire.
- indigochill 6y agoI've seen that argument while reading up on the current state supreme court cases, but I disagree that it's more like searching your mind than searching ahouse is. To mirror your examples, a house may have handwritten notes, photos, and voicemail messages (well, if it still has a landline) all of which can potentially contain incriminating evidence. Yet we compel people to grant entry to an officer with a search warrant. As to the protection afforded by a password, a house is protected with a lock and ordinarily someone cannot compel you to grant them access, which is what the warrant is for, stating that they have reason to believe there is evidence on the premises. If we want to say, "But unlocking a door doesn't require speech while telling someone your password does" then fine, silently punch that password into the device. Mainly I'm looking for problems with this in the vein of "If we install backdoors into our software, that compromises security for everyone and grants unprecedented surveillance power to the government". A hand-delivered court-issued warrant to the owner of an individual device seems like a promising compromise to let law enforcement get on with investigating specific crimes without broadly crippling everyone's security in the process.
- slaymaker1907 6y agoLuckily they seem to have no concept of timing. Why they think they can get away with something like this when trust of the police and authorities is so low is beyond me.
- suizi 6y agoThey're hoping we're distracted by the virus / riots / rhetoric of spooky criminals.
- shmerl 6y agoHow often will this stupidity come up? Looks like some never learn.
- suizi 6y agoA criminal could use a service provider which isn't located in the U.S. or peer-to-peer communications. Only stupid criminals and the general public will be hit by this. Is this a last ditch effort for a Law & Order Bill prior to the election?
- tempodox 6y agoI suspect so. Never mind that it wouldn't really work – politics is a game where scammers get away with impunity.
- threatofrain 6y agoWhat's the tally on support? Otherwise it's difficult to know whether this bill is symbolic or serious.
- jeffdavis 6y agoSometimes I wonder if politicians are trying to get us to not vote for them. Like, what problem is this solving? Are there tons of criminals that are running wild, and if only we had their secret correspondence we could catch them? And is social media not already some huge gift to law enforcement? Forget about tapping an encrypted line, just follow them on twitter.
- jeffdavis 6y agoThe original "warrant proof" evidence was just saying something. Whoever was within 30 feet heard you, but otherwise, it was just gone.
- dane-pgp 6y agoExactly. Encrypted phones are "warrant proof" in the same way that past spoken conversations, or suspects' brains are "warrant proof". If memory-enhancing brain implants are developed in the future, it will be interesting to see whether data stored on them will be subject to subpoenas.
- ideals 6y agoThey can't catch domestic terrorists who are in the USAF using their existing overreaching surveillance on non-encrypted traffic. How does breaking encryption get them closer? https://www.washingtonpost.com/nation/2020/06/17/boogaloo-steven-carrillo/ https://www.washingtonpost.com/nation/2020/06/17/boogaloo-st...
- api 6y agoEasy: it's a bad faith argument. Most of the stories I've read about terrorists and mass shooters report that they were using bog standard instant messaging, unencrypted e-mail, and social media. Most of these people are not highly technical and do not practice good opsec. Hell Dread Pirate Roberts was pretty technical and still got busted because of bad/lazy opsec, not (as far as anyone knows) because encryption or Tor were broken. The child porn thing is a bad faith argument too. Child sexual abuse is under-investigated and under-prosecuted already even when the information is there or when actual reports are made. (Adult rape is under-prosecuted too.) They don't do enough to go after child predators using existing tools, so why would more tools matter?
- suizi 6y agoThere are some bad fallacies on their part too. Large amounts of child porn detected equals platform being used on similar scale for producing it / distributing new content / grooming. By playing with equivalence, you can push for tougher policy. It is under-prosecuted for frankly embarrassing reasons. Tech companies can't submit it on the spot. They have to wait for them to come to them, and have to delete it if they take too long.
- oh-4-fucks-sake 6y agoGOV: Is it true that your servers hold encrypted data. AWS: Yes. GOV: Decrypt it, please. AWS: Lol all we have is the public keys, bruh. GOV: Use the public key to decrypt, please. AWS: Uhh...
- jeffdavis 6y ago"If passed, the act would require tech companies to help investigators access encrypted data if that assistance would help carry out a warrant." Isn't that already required? If someone shows up with a warrant (presumably signed by a judge and listing the particular things being searched), then basically you need to do everything you can to help them (as you should). Subpoenas are a little different and there's more room to argue about them, but are also important in general. Regardless, if it's encrypted and you don't have the key, then it's a dead end and that's the way things go. So what is this law really doing? My guess is that it's actually asking tech companies to do something in advance of any specific criminal act, that would somehow preserve private information or prepare it so that it's easier to comply with hypothetical warrants that might be issued in the future against anyone on the platform. That's really a different kind of thing than just assisting in carrying out a warrant.
- alkonaut 6y agoHanding over data, with a warrant, seems fair. The question is if a law makes it illegal to keep data that you can't decrypt.
- xxpor 6y agoIt's much worse than the article describes. From the press release: "Senate Judiciary Committee Chairman Lindsey Graham (R-South Carolina) and U.S. Senators Tom Cotton (R-Arkansas) and Marsha Blackburn (R-Tennessee) today introduced the Lawful Access to Encrypted Data Act, a bill to bolster national security interests and better protect communities across the country by ending the use of “warrant-proof” encrypted technology by terrorists and other bad actors to conceal illicit behavior." https://www.judiciary.senate.gov/press/rep/releases/graham-cotton-blackburn-introduce-balanced-solution-to-bolster-national-security-end-use-of-warrant-proof-encryption-that-shields-criminal-activity https://www.judiciary.senate.gov/press/rep/releases/graham-c... I haven't read the exact text, but to me 'ending the use of “warrant-proof” encrypted technology' means banning end-to-end encryption, not just "requiring the assistance" of technology companies. And according to Eric Geller, who is one of the main cybersec reporters at Politico, it DOES require backdoors: https://twitter.com/ericgeller/status/1275813434123186177 https://twitter.com/ericgeller/status/1275813434123186177 "shall ensure the manufacturer has the ability to provide the assistance"
- jeffdavis 6y agoSometimes I imagine a secret meeting that happened some decades ago between Republicans and Democrats, dividing up the Bill of Rights. "Well, we have to at least look like we're fighting for them. If we all just agree to protect the Bill of Rights, then we aren't really working for them. How about Democrats get 4, 5, 7, 8, and 9; and Republicans get 1, 2, 3, 6, and 10?" "Hey, why do we get the Third Amendment?" "It was our idea." (This comment is not meant to be taken literally and I'm sure that others will have a different mapping between Amendment numbers and parties.)
- Reedx 6y agoBasically everything is neatly divided between the two political tribes now. If one says they're for X, the other is automatically against X. It's become comically predictable. The people endlessly fight amongst themselves as the rich get richer. Divide and rule.
- JohnClark1337 6y agoAbolish the republican party
- triceratops 6y agoWe in tech have to stop thinking that these politicians don't understand or know what they're proposing. Or that they would change their minds "if only we could explain it right". It's not a problem of information. The fact of the matter is some parties (by which I mean groups, not political parties) have an abiding interest in keeping strong encryption and privacy out of the hands of the population at large. Banning E2E encryption either outright, or through the backdoor (EARN IT act) from major Internet platforms will accomplish this. Therefore, arguments like "You can't ban math" or "The real criminals will just move to platforms that use E2E encryption" don't work. What's worse, they try and pass these laws using Think of the Children[1]. It's tested, and effective. It works because it's an emotional appeal and most voters are emotional creatures (including me, and you). Like a popular Internet meme says "You can't reason someone out of an opinion they didn't reason themselves into." Fortunately we can (honestly) use Think of the Children to fight back. Literally every child in the US uses the Internet to chat with their friends and send pictures, write their journal, do their homework, get their grades, and communicate with their doctors or therapists. Weakening encryption therefore endangers every child, risking exposing their innermost thoughts and conversations to the worst sort of people online. We have to start couching this issue in terms that regular people understand. "Would you lock your backyard gate, where your children play, with a TSA lock?" "What if your pediatrician's office told you their doors and file cabinets have a TSA lock on them? Anyone can just buy a key on Amazon, walk in, and rifle through everything they have." I honestly worry about a future where my children have no privacy. Where any online predator can potentially access everything they say, send, post, or do online. That makes me anxious and frankly, a little angry. 1. https://en.wikipedia.org/wiki/Think_of_the_children https://en.wikipedia.org/wiki/Think_of_the_children
- suizi 6y agoThink of the minority children. Think of the LGBT children who may want to speak to a safe and established community / therapist confidentially about problems in an abusive household which rejects them for what they are. Think about all the children who may need counselling during the COVID-19 outbreak who do not need secrecy from family but can't physically attend and don't want strangers peeking in.
- Gollapalli 6y agoDo these dolts not realize that their supporters also use encrypted platforms (like signal and telegram) to communicate, especially things that are considered fringe or dissident. One might expect such cluelessness from someone like Lindsey Graham, who is a neocon's neocon, but from Tom Cotton, who is on the Right-wing's preferred side on immigration? Especially, when that position is the sort of position that can get you fired these days? Madness. I wonder what would happen if the NRA started defending encryption as a second amendment issue, as encryption technology has historically fallen under munitions export control legislation.
- dang 6y agoAlso posted yesterday: https://news.ycombinator.com/item?id=23622169 https://news.ycombinator.com/item?id=23622169