3 ms·
This has been discussed in many ways before but I'd like to try to phrase it my own way. When police get a warrant to search your home, after they are done you
by ninjanomnom 5y ago
This has been discussed in many ways before but I'd like to try to phrase it my own way.
When police get a warrant to search your home, after they are done you can get a new lock and recover anything taken as evidence eventually.
When an investigation gets permission to surveil you, it's a temporary affair and records can be stripped of irrelevant personal data before any sort of release or duplication.
Even in the best case scenario, encryption is used in cases where incidental damage cannot be recovered from like above. Encryption is an attempt to restrict an easily accessible, indefinite lifetime, and infinitely duplicatable piece of information to only be meaningful to intended owners.
Let's imagine a very generous scenario, a chat program has encrypted chat such that every message can be unlocked with either the participants' keys or a unique key per message stored and kept safe by the service owner. Law enforcement can request chat logs and the service can return them the keys needed to read the requested logs from the interval specified.
Similar to the second scenario above it is possible after the investigation to cleanse the records law enforcement has, but in this case they are not the primary or secondary source of that information and cannot ensure that all records are permanently safe from outside parties. Anyone can easily get copies of the encrypted versions of communication done over the internet with minimal effort, this means someone can hold on to encrypted information in massive dumps and await inevitable breaches in company security that retroactively reveal all previous communication.
This is the best case scenario, it completely ignores things such as how any investigation is one day inevitably going to be a malicious actor. I don't mean whatever group of people are in charge right now going bad, I mean how all countries/groups inevitably change over time for better or worse. If a bad actor is in a position of power for even a moment, they can retroactively spy on you at all points in the past you use a weakened encryption. Imagine an extreme vegan political group making eating meat a crime punishable by death even if in the past. Your chat logs about going for burgers are easily accessible. Or similarly a retroactive law against abortion.
In the case of well encrypted chat, only the participants have control over the keys and if you want to be sure something is gone you can discard the key. This is no longer the case for encryption with a backdoor.
- 1337shadow 5y agoThanks, I understand your arguments and have held them for ~15 years, I have changed my mind: I don't believe "any investigation is one day inevitably going to be a malicious actor", that could happen with any kind of evidence anyway, encrypted evidence is no exception, I also don't believe about retroactive laws like that, and I do want something to be done about the thriving criminality, because I don't want protection from what could happen if reality became scifi, I want protection from the threats we are actually facing in the present reality. That said, your comment reflects an above standard kindness which I deeply appreciate.
- charcircuit 5y ago>Anyone can easily get copies of the encrypted versions of communication done over the internet with minimal effort, this means someone can hold on to encrypted information in massive dumps How, if you aren't the person I'm chatting with, then you will never see my encrypted messages. How would anyone magically get all of the messages? >Imagine an extreme vegan political group making eating meat a crime punishable by death even if in the past. Your chat logs about going for burgers are easily accessible. Or similarly a retroactive law against abortion. Ignoring how common law does not allow for retroactive laws, you are arguing for people to be able to hide the evidence of the crimes they have committed. I imagine how you can see how governments would not be a fan of this. You are just being an example of a person who has something to hide. Killing your citizens on such a large scale is really not in your interest as a government and would not go over well in the global community. >This is no longer the case for encryption with a backdoor. I never said to add a backdoor. I said that the cryptosystem should be designed such that law enforcement with a valid warrant will also be able to decrypt the message. Having a cryptosystem where only the participants or someone with a warrant can read messages is still an upgrade over unencrypted messages where a MITM can store, read, and modify your guys' messages.