4 ms·
I actually don't see the contradiction - our security systems are full of holes largely as a matter of convenience. We put in password recovery because we rout
by csandreasen 12y ago
I actually don't see the contradiction - our security systems are full of holes largely as a matter of convenience. We put in password recovery because we routinely forget passwords. We make stupid password recovery processes that involve mothers' maiden names because it would be too much of hassle to do something more secure like show up at Google HQ with three forms of ID. The police don't have the same usability requirements. They only need access to the data on your phone once; they're not opening it every 10 minutes of every day to check your SMS/e-mail/HN posts/etc. In addition, they also have the requirement that they can't be opening your device without a valid search warrant. Any system put in place to allow them access needs to be designed with conditions like these in mind.
With regards to other countries, manufacturers are already required to comply with all laws in any country they operate in. I don't think Americans should have to make a decision as to whether or not their own law enforcement should have the ability to decrypt phones based on what Chinese police might do in their own country.
If you're worried about brownshirts taking over your government, there's nothing preventing you from encrypting the data yourself - nothing prevented you from doing it before. There are legitimate reasons for law enforcement to search a device after being issued a valid warrant; same as your house, place of business, safe deposit boxes, etc. Strong encryption by default on hundreds of millions of devices on which people conduct much of their daily business is something new. Locks and safes will slow down an investigation, but never to the point of bringing it to a halt. Strong encryption will. Given how central these devices have become in our lives, I don't know that it makes much sense to prevent police from searching them when they are legitimately investigating an actual crime.
- j42 12y agoYou are severely misinformed, both about the constitution and the technological implications of the position you are blindly touting. (1) The Mass. Supreme Court ruling/precedent can compel a suspect, with proper legal protocol, to decrypt a device and is NOT an infringement on one's constitutional rights. This makes the entire argument of "responsible disclosure" null and void. (2) You seeing security holes as "forgot password functionality" shows how uninformed and inexperienced you are. When you start seeing everything from CPU fans (measuring audible signals to detect an encryption key) to the latest un-patchable USB bug (arbitrary code execution via invisible controller-chip firmware alterations) as attack vectors you will begin to realize just how wide the potential 'surface' is. Care to venture what could happen if someone were to, say, reverse engineer the baseband and had access to all firmware functions of a device within an environment where the decryption key was being used? A "golden key" is simply creating the largest historical hacking bounty, and a fool would think such keys could be kept secure indefinitely. When you are admittedly an amateur and experts are telling you this is a bad idea, you should listen. Whether human or machine history has PROVEN that there is no "perfect system." Introducing unnecessary holes to accommodate bureaucratic pedantry is wholly unnecessary, and I would venture to say, idiocy.
- csandreasen 12y ago(1) I provided a link to two federal cases elsewhere on this thread that say otherwise[1]. Would you be kind enough to post a URL backing up your assertion. (2) I'm not even going to bother responding to this one since you apparently couldn't be bothered to phrase your argument without an ad-hominem. If you care (which I doubt), I've already responded to a similar argument elsewhere on the thread. [1] https://news.ycombinator.com/item?id=8430501 https://news.ycombinator.com/item?id=8430501