13 ms·
Code Specialists Oppose U.S. and British Access to Encrypted Communication
- gnu8 11y agoThe headline belies the utter ridiculousness of the idea. Why would the United States and United Kingdom be singled out to have backdoor access to all communications? To hang onto the tattered remnants of their empires while keeping their own people in line despite their declining political legitimacy.
- happyscrappy 11y agoMaybe you think that China is ascendant, but the fact remains that the West is closely aligned and utterly dominant.
- rm_-rf_slash 11y agoIt is not a simple east/west matter. States themselves are in a period of declining influence after a historically abnormal 400 years of strong states and a state-based order. Their power to influence culture, drive people's decisions, set prices and drive morals is being eaten by multinational corporations, religious institutions, NGO's, online communities like Reddit and HN, name it. State influence is shrinking, and their best answer is to compensate with power.
- wcummings 11y agoGlobalization has weakened The State, in general, though not all states equally.
- Sideloader 11y agoYes, the West is still dominant but geopolitical and economic power is shifting South and East and Western influence and power is waning. China and the U.S. both know that at the moment each nation is dependent on the other and the collapse of one would have serious repercussions for the global economy. Hence we get scenarios where China is claiming islands a thousand miles off its coast as domestic territory and while the US Air Force flies overhead and Obama tut-tuts the whole thing is a boundary pushing exercise (no pun intended) and China continues to do what it wants, within reason. China knows that shooting civilians as in Tiananmen Square in 1989 makes for very unflattering optics and jeopardizes the Western trade and investment it needs. Every day articles and blog posts announces the imminent demise of US and Western power or China's impending economic collapse. It's possible of course but for the moment not very probable. But it is clear that the West is no longer *utterly dominant.
- happyscrappy 11y ago> But it is clear that the West is no longer *utterly dominant Economically, militarily and culturally they are, what metric are you using?
- DamnYuppie 11y agoIf one looks around they will see most political regimes are very interested in keeping their "constituents" in line and maintaining their political legitimacy. As such it isn't a phenomenon specific to the west, it simply appears to be discussed here as we have slightly more open media than in other countries who would dearly love to have the same access to encrypted data.
- jebblue 11y agoThe united States isn't an empire, that's what it was formed to get away from. It's a collection of people, living in different communities called states that strive to stay united to form a more perfect union. It isn't a perfect experiment because people are not perfect but it's the best effort history has seen so far.
- Someone1234 11y agoTell that to the countries the US keeps invading. At the very least Grenada, Iraq (2003), and Panama. But the list is far longer and more complicated (and stretches back fifty years or more). Nobody would call the US an "empire" if all it did was keep in its own territory and stay out of other country's internal affairs. Nobody calls Canada an empire for example. But the US keeps deciding to outright attack other countries or uses the CIA to subvert internal politics (and sometimes to overthrow democratically elected governments e.g. Iran). The US deserves to be accused of having imperial intent, even if just based on their interest in other country's oil.
- vinceguidry 11y ago> The US deserves to be accused of having empirical intent, even if just based on their interest in other country's oil. The word you're looking for is "imperial." "Empirical" means something else entirely.
- joshuapants 11y agoCanada itself isn't an empire, it's just part of one.
- Zigurd 11y agoHeck, tell that to France, who can't manage to root out the US influence in their telcos or their intelligence services, and who are powerless offer asylum to Assange and/or Snowden.
- tinkerrr 11y agoAre you sure about that? http://www.globalresearch.ca/wp-content/uploads/2014/09/waddell-usa_intervention_bleu.gif http://www.globalresearch.ca/wp-content/uploads/2014/09/wadd... http://www.theweeklings.com/wp-content/uploads/US-Military-Bases-Around-The-World.jpeg http://www.theweeklings.com/wp-content/uploads/US-Military-B...
- higherpurpose 11y agoI actually wouldn't be surprised at all if the US and UK governments would be perfectly fine with China, Russia and so on being able to hack and spy most of their citizens and companies as long as they could also do that. From their point of view it might be quite a good trade-off, because they probably think it's far more useful for them to spy and hack US and UK citizens than it is for China and Russia. And they also probably think that they, the elites, could use something better than what everyone else uses, too. So there's no negative to this.
- Titanous 11y agoHere's the actual paper: http://dspace.mit.edu/bitstream/handle/1721.1/97690/MIT-CSAIL-TR-2015-026.pdf http://dspace.mit.edu/bitstream/handle/1721.1/97690/MIT-CSAI...
- conover 11y agoDespite the political element, there is a poor history of keeping these kind of keys/methods secret. See the AACS encryption fiasco, the cable card hacking wars over the last decade, Clipper chip mentioned in the article, etc.
- venomsnake 11y agoI am also not sure that I want to entrust the keys to the internet to the same government that kept its nukes with launch codes of "00000000"
- mikeash 11y agoI don't see the connection. The all-zeroes launch code wasn't an instance of idiocy, it was a deliberate choice by military commanders who felt that codes would make things less safe, not more, because they saw the Soviets as a far greater threat than a rogue launch by their own men, whom they trusted completely. It's not like the code could be entered by random people on the street, if only they had known the power they held. You still needed physical access to the launch control rooms, which had a great deal of physical security and were always staffed by at least two people at any given moment.
- rm_-rf_slash 11y agoBeing HN I'm sure many of us have dreams about future computers that are seamless extensions of our bodies, doing more than we could ever imagine with a phone or a watch. Do we also have nightmares about a hacker stealing a government's back door key and giving us a heart attack in our sleep?
- ionised 11y agoAt this point I'd be more worried about the government giving me a heart attack in my sleep. They can't and shouldn't be trusted with this kind of power.
- logfromblammo 11y agoLet's be realistic here. The government isn't going to give you a heart attack in your sleep. The government is going to give millions of people heart attacks, all at the same time, at 5 pm Eastern time on a weekday. I cite the recent bonehead maneuver, wherein someone--likely backed by a foreign government--managed to access the data for every last person cleared to handle U.S. government secrets, which necessarily includes any embarrassing datum which could be used by foreign governments to apply leverage. This is Murphy's Law in action. If a catastrophe is possible, it will eventually happen. Combine with Acton's Law. Power corrupts; absolute power corrupts absolutely. The result suggests that, for the sake of sane risk management, government should be structured such that no person working in it (or hijacking its infrastructure) can single-handedly do more than one nuclear bomb's worth of damage. This means the fundamental principles that have to be engineered in are robustness, trustworthiness, and voluntary cooperation. Built-in backdoors are completely antithetical to all three.
- gonzo41 11y agoHave you seen Ghost in the Shell? I'm don't more integrated computers are the answer. But on the encryption front, the more the better. If everyone adds complexity then 'they' have to discriminate more. Which is good for everyone.
- 11y ago
- beedogs 11y agoThe way I see it, law enforcement has had it far too easy for far too long. The Snowden revalations finally turned over all the rocks and people saw that they have been grossly overstepping both ethical and legal boundaries, and encryption is finally getting the mindshare it desperately needs. So to their petulant cries of being unable to read our communications anymore, I say: fuck 'em. Time to earn your keep now, boys. You're not going to destroy our Internet just so you can keep feeding the mass-surveillance beast.
- tremon 11y agoI have a lot of trouble viewing anything involving the NSA as "law enforcement". Like the CIA, aren't they specifically created to subvert the law in other countries and not operate in their own jurisdiction?
- kabdib 11y agoCollusion, then things like "parallel reconstruction" and inter-agency agreements to keep things dark. Power always corrupts. The big lie is "No, our motives are to keep you safe, and [list of the usual bad things] can't possibly happen this time."
- beedogs 11y agoI used the term loosely, but the FBI director was the one agitating for crypto legislation recently.
- WildUtah 11y agoThere's no high tech terror for the NSA to fight. So-called intelligence about what Angela Merkel is thinking is of no diplomatic or economic use. The NSA has almost no purpose in practical government. But the NSA does do a lot and has a mission. It's the same mission US law enforcement always invents for itself. The NSA provides lots of leads to cops to arrest innocent drug dealers. Aside from parallel construction, the NSA does the same thing most FBI, DEA, and Border Patrol dollars go to: small time non-violent drug offender persecution.
- phkahler 11y agoThis debate seems like a manifestation of a problem with governments: They think they can legislate anything they want. Need access to some communications - green light for massive data collection. Some of it is encrypted - just mandate a back door. School shooting - new gun laws. Any problem activity - we'll just make it illegal. Something not getting done - we'll just mandate someone take care of it. They really don't know how to stay at a higher level, it's all micromanagement. Some things are just not possible, but they'll try to make it so with the stroke of a pen.
- vezzy-fnord 11y agoNot just with governments, but people's whims in general. To quote G.K. Chesterton [1]: And then, last but the reverse of least, there plunged in all the people who think they can solve a problem they cannot understand by abolishing everything that has contributed to it. We all know these people. If a barber has cut his customer's throat because the girl has changed her partner for a dance or donkey ride on Hampstead Heath, there are always people to protest against the mere institutions that led up to it. This would not have happened if barbers were abolished, or if cutlery were abolished, or if the objection felt by girls to imperfectly grown beards were abolished, or if the girls were abolished, or if heaths and open spaces were abolished, or if dancing were abolished, or if donkeys were abolished. But donkeys, I fear, will never be abolished. [1] https://en.wikisource.org/wiki/The_Flying_Inn/Chapter_IX https://en.wikisource.org/wiki/The_Flying_Inn/Chapter_IX
- magicmu 11y agoThat is a spectacular quote, and really embodies the impetus of the American people to not only blame excessively when things go wrong, but to place blame in a manner which absolves all parties of any (perceived) responsibility.
- vezzy-fnord 11y agoI find this is done universally. Every time some shooting or similar disaster occurs, the actual perpetrator is among the last to take the blame. It's the video games, it's the music, it's the toxic culture of masculinity, it's the pharmaceutical drugs, or it's the Zionist media poisoning our children with Judeo-Bolshevist propaganda. The obsession is with the "one single cause", but more importantly the opportunity for every demagogue to revel in vilifying their preferred scapegoats. Nothing gets fixed, and people wonder why.
- a3n 11y ago> “Such access will open doors through which criminals and malicious nation-states can attack the very individuals law enforcement seeks to defend,” And there's the nut. The concern of law enforcement is not protection of citizens, it's ease of prosecution and resume building. No one can claim credit for a general environment of ongoing secure communication, but cops and prosecutors can definitely claim credit for specific arrests and prosecutions, even if that general security environment is all but destroyed. In fact, the more breaches, the more crimes, the more cops and prosecutors are needed. Job protection.
- a3n 11y ago> The costs to the developed countries’ soft power and to our moral authority would also be considerable.” That moral authority undermined in part from the risk of secure government data being exposed, and government operations then being exposed. Breakable encryption is definitely a double-edged sword.
- hellbanner 11y agoRight - and "the government" isn't a single entity. Members can defect (ala: Snowden and others).
- logfromblammo 11y agoMembers can also corrupt, or even just operate too long without the moderating effects of effective oversight.
- mc808 11y ago"Michael S. Rogers, the director of the N.S.A., has proposed that technology companies be required to create a digital key that could unlock encrypted communications, but divide and secure the key into pieces so that no one person or government agency could use it alone." Conveniently, Microsoft has a patent on just that. http://www.google.com/patents/US8891772 http://www.google.com/patents/US8891772 Michael S. Rogers should disclose any financial interest he may have in Microsoft. Or does he have something to hide?
- michaelt 11y agoShamir's Secret Sharing was published in 1979. I would be surprised if Microsoft has a monopoly on it, given that patent was published in 2011.
- jackgavigan 11y agoThere are other ways of achieving this, e.g. https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing
- higherpurpose 11y agoAs well as one for a Skype backdoor: http://www.computerworld.com/article/2509604/data-privacy/microsoft-seeks-patent-for-spy-tech-for-skype.html http://www.computerworld.com/article/2509604/data-privacy/mi... Microsoft has some interesting project choices.
- d_theorist 11y agoWould it have killed them to link to the paper?
- EGreg 11y agoHow would they feel if China and Russia was given the same backdoors? What would they legislate then? It's not as if internet traffic can be quarantined.
- delinka 11y agoCan't it? The Great Firewall is a shining example. (all irony intended.)
- jackgavigan 11y agoPerhaps governments need to apporach the problem from a different angle: How can we limit the extent to which bad actors (e.g. terrorists, organisaed crime, etc.) can benefit from private/secure communications technologies without compromising civil liberties and our citizens' right to privacy? If anyone can solve that problem, surely it's us - the technologists, the problem-solvers?
- domfletcher 11y agoMy favourite quote on this (from the UK perspective) from Ross Anderson (one of the co-authors): “A point I would like to make to the prime minister and his circle is: whoever put the prime minister up to this should get a complete bollocking. The proposals are wrong in principle and unworkable in practice.” There is no quicker way of alienating people who understand complex things than by pretending that you know better and have thought of a brilliant solution.
- naveen99 11y agoThey already ban encryption on ham radio... :( Maybe somebody can start a pay to broadcast service using namecoin atomic name changes https://wiki.namecoin.info/?title=Atomic_Name-Trading https://wiki.namecoin.info/?title=Atomic_Name-Trading 1. Service announces public nmc pay to address. 2. People mail them a message as a name update transaction combined with payment to that address using snailmail. 3. They broadcast if the perceived risk of broadcasting is less than the value of fee provided. This could be anonymous and encrypted if the source name coins are sufficiently anonymous.
- forgottenpass 11y agoThey already ban encryption on ham radio... :( This bugged me too, but ham is already not general purpose. I've come to accept it as the cost of preventing a disallowed uses of the ham bands inside an impenetrable envelope of allowed use. And besides, it's usually possible (but less fun) to set up (or use existing) radio networking links in different bands.
- StephenFalken 11y agoI wonder if they will ever be able to ban steganography on ham radio. [1] [1] https://en.wikipedia.org/wiki/Steganography https://en.wikipedia.org/wiki/Steganography
- jakeogh 11y agoThe attack on our ability to encrypt is in the end an attack on the right to private thought. Loosing this, while we merge with our digital creations, is an existential threat.
- tptacek 11y agoHere's the paper: https://news.ycombinator.com/item?id=9846414 https://news.ycombinator.com/item?id=9846414
- johanneskanybal 11y agoCan we stop the sharing of pay-walled content please, just pick another source? ot: What do they (cameron and c/o) think the best case scenario is for this folly? Disrupt a few mainstream services while pissing everyone off in the process whilst the real criminals move on to slightly more obscure services?
- graycat 11y agoThey can "oppose" all they want. That's why we have PGP, in open source. And that's why in the US we have: "Amendment IV "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized." I know; I know: Various people working for the people are all wound up about wanting to know and wanting to be sure, wanting to be sure they know just what is in all those e-mail messages. Their thinking might go: "Those messages, they are sending lots of messages, are they planning something? Are those people up to something? Are we at threat? We want to know. Why do they encrypt their e-mail messages if they have nothing to hide? "If they have something to hide, then definitely for the good of everyone we should know about it and they shouldn't use encryption. Else they might be planning something. If they have nothing to hide, then they shouldn't mind our knowing and shouldn't use encryption. "Yes, definitely we should have full access to all e-mail and other communications, computer hard disks, private conversations, private thoughts, etc." That's what some people working for the people think. Sorry, guys, I'm one of the people you are working for, and you will just have to do your job without violating the Constitution. It's an old story, as is encryption, and e-mail, the Internet do not fundamentally change the situation.
- cortesoft 11y agoYour first part is why I always find these talks silly. Encryption (at least the kind they are talking about) is just math - all the laws in the world aren't going to change the math. You can't legislate away the knowledge of that math; even if you force Apple or Google to insert your backdoor into THEIR implementation of the crypto, that doesn't mean that a 'terrorist' couldn't just use their own implementation of the readily available and widely known algorithms. That cat is out of the bag; you can't legislate it back in.
- graycat 11y agoFully correct. I have Bruce Schneier, Applied Cryptography, Second Edition: Protocols, Algorithms, and Source Code in C, ISBN 0-471-11709-9, John Wiley and Sons, New York, 1996. That material's not going away. And, in addition, I have some nicely short, not difficult to read, source code. About all the math needed for PGP is in an elementary number theory book -- I have several sufficient references. > That cat is out of the bag; you can't legislate it back in. Did you mean "The toothpaste is out of the tube"? -- supposedly the phrase used in the Nixon Watergate scandal! When Zimmerman made PGP public, he also gave what I thought was a good description of the issues with the bottom line, whatever the pros and cons, net in plenty of cases it's important for individuals to have access to strong encryption. Yes, no doubt there's no shortage of people in government who don't like PGP. I'll send some people in government some toothpaste and an empty tube and let them try their hand!
- adestefan 11y agoHow is there no mention of CALEA[0] in this document? They even hint at it in the Executive Summary: Indeed, in 1992, the FBI’s Advanced Telephony Unit warned that within three years Title III wiretaps would be useless: no more than 40% would be intelligible and that in the worst case all might be rendered useless [2]. The world did not “go dark.” On the contrary, law enforcement has much better and more effective surveillance capabilities now than it did then. [0] https://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act https://en.wikipedia.org/wiki/Communications_Assistance_for_...