4 ms·
You're off by several orders of magnitude on your crime statistics. In 2013, 2.3% of households were victims of violent crime, while 13.1% were victims of prope
by csandreasen 11y ago
You're off by several orders of magnitude on your crime statistics. In 2013, 2.3% of households were victims of violent crime, while 13.1% were victims of property-related crime[1]. Do you have evidence to suggest that courts are handing out search warrants like candy to intimidate journalists? Crime is an everyday problem; harassing journalists and activists is not. A solution that prevents police from investigating a crime just because a cell phone is involved in order to further protect rights that largely weren't being violated to begin with isn't a particularly good solution.
[1] http://www.bjs.gov/index.cfm?ty=pbdetail&iid=5111 http://www.bjs.gov/index.cfm?ty=pbdetail&iid=5111
- 4bpp 11y agoSorry, I didn't mean to imply that the probability that you will become the victim of /any/ crime is that low - rather, I argue that the sort of emotion-arousing crime that almost invariably gets thrown around as an example to argue against ubiquitous encryption (like an abductee being driven around multiple states and raped for weeks) is actually rare. I would imagine that your typical story of being mugged or having your picket fence demolished (what does it take for a mugging to count as violent crime?) would be far less likely to arouse feelings of "this is so terrible, how can we possibly allow encryption on iPhones if people doing this will get to walk free because of it". If you think that helping some small additional fraction of those 2.3% of households or 13.1% of people a conviction of the perpetrators is a more valuable thing than strong encryption, then it would be more intellectually honest to evoke a typical case in your argument than an extremal one.
- csandreasen 11y agoI'm not advocating for no encryption on phones. There are schemes that would allow for your data to be encrypted and secure from even the cops except in cases where they have a acquired a warrant. The argument that there is no way to do so is more political than technical. This is a solved problem, cryptographically speaking. I think it's intellectually dishonest to wave away legitimate criminal investigations but prop up harassment of activists. I think it's a dangerous precedent when just months after the Supreme Court strikes a major win for privacy advocates by saying that all cell phone searches require a warrant, Apple turns around around and essentially says that isn't good enough - now people who don't even know what encryption is will be immune from any search, with or without a warrant. When a popular tech company can make a Supreme Court ruling moot, I think there needs to be a bit more discussion on the matter.
- AnthonyMouse 11y ago> There are schemes that would allow for your data to be encrypted and secure from even the cops except in cases where they have a acquired a warrant. The argument that there is no way to do so is more political than technical. This is a solved problem, cryptographically speaking. It very much is not. All of the schemes that purport to do so involve a systemic risk that the master key is lost to a hostile foreign government or criminal organization, and they inherently prohibit forward secrecy.
- csandreasen 11y ago> All of the schemes that purport to do so involve a systemic risk that the master key is lost Look up 'secret sharing schemes' and 'threshold cryptosystems'. The idea that any scheme allowing law enforcement to decrypt a cell phone must inevitably involve a single master key is a strawman argument. > and they inherently prohibit forward secrecy. This is a non-issue for encrypted disks, which is what law enforcement has an issue with.
- AnthonyMouse 11y ago> Look up 'secret sharing schemes' and 'threshold cryptosystems'. The idea that any scheme allowing law enforcement to decrypt a cell phone must inevitably involve a single master key is a strawman argument. I'm aware of these things. But splitting a master key into five parts doesn't make it any less of a master key. The vulnerability is not in how many keys you need to open a lock, the vulnerability is in requiring the same keys to open all locks. > This is a non-issue for encrypted disks, which is what law enforcement has an issue with. Forward secrecy for encrypted disks is implemented by regularly changing your encryption key and destroying all copies of the old key. An attacker who can copy the encrypted contents of your disk and later compromises your key then won't be able to decrypt the copied data with it, because the current key won't decrypt the old ciphertext. This inherently doesn't work if the government keeps a key that will decrypt the old ciphertext because the attacker with the old ciphertext can still compromise the government's key(s) to decrypt it.