11 ms·
Why the fear over ubiquitous data encryption is overblown
- ams6110 11y agoThis could lead to a perverse outcome in which law-abiding organizations and individuals lack protected communications but malicious actors have them. That's it in a nutshell. The tools are out there. You can't put the genie back in the bottle.
- userbinator 11y ago"If you outlaw encryption, only outlaws will have encryption."
- rhinoceraptor 11y agoAnd if they mandate escrow keys for communication, who's to say they won't push for the same thing for package signing keys? I'm sure the three letter agencies would love to be able to ship compromised binaries to their targets' computers.
- beagle3 11y agoThey might actually do stuff like that, but that's just smoke and mirrors. It is much easier to mandate a way to run code on modern systems, in the "SMM" style, upon seeing a cryptographic signature which the NSA holds the key across the memory bus. About 20 people in each of Intel, AMD, nVidia, Qualcomm, Apple need to know about it (well paid and NSLd to shut up; perhaps even NSA employees embedded in these companies and the companies themselves none the wiser), about 3000 transistors which would be lost in today's many-billion transistor CPUs. It doesn't have to be fast, and not even perfectly reliable - it just needs to work. In fact, I'll be astonished if in the future it turns out that such a thing is not already implemented today. Do you really thing the NSA doesn't yet have a copy of Intel's microcode signing keys?
- scintill76 11y agoSince this is usually said about guns, it reminds me of https://xkcd.com/504/ https://xkcd.com/504/
- eru 11y agoOnly works in the US of A.
- animefan 11y agoThe supreme court's definition of "arms" is not something that can be changed by passing a law. Just like you couldn't hack the second amendment by defining arms to be muskets.
- feld 11y agoI don't understand what you're saying. Did you miss the entire reference that XKCD strip was about? You do know that we had to fight to remove encryption as being classified as a weapon and instead protected as free speech, right? https://en.wikipedia.org/wiki/Bernstein_v._United_States https://en.wikipedia.org/wiki/Bernstein_v._United_States
- jakeogh 11y agoWe shouldn't have had to argue that. If it's either speech or an arm (and it's both), it's inalienable.
- scintill76 11y agoBanning encryption or making commonly-used encryption systems crippled might have some value in their book: * You can still catch some criminals too dumb/lazy/small-time/poor to use better encryption. * You can find evidence on people who didn't use better encryption because they didn't realize they were breaking the law. * You can use hints/metadata found in unsecure channels (that you forced to be unsecure.) * You can identify encrypted devices/communications as suspect (even more so than today) and investigate them especially. * You can prosecute people just for using encryption and sleep fine at night because it means "they have something to hide", and are probably breaking the law in some other way.
- nindalf 11y agoThese are compelling points for backdoors. A lot of low level crime could be eliminated if people's communications could be accessed at will by law enforcement. However, as Edward Snowden points out here [1], its not in society's best interests to eliminate all crime. [1] - https://np.reddit.com/r/IAmA/comments/2wwdep/we_are_edward_snowden_laura_poitras_and_glenn/courx1i?context=3 https://np.reddit.com/r/IAmA/comments/2wwdep/we_are_edward_s...
- guard-of-terra 11y ago"A lot of low level crime could be eliminated if people's communications could be accessed at will by law enforcement" Such as? Keep in mind that eliminating low level crime is often very low priority for law enforcement: they only do this under pressure or when expecting some bonus for it. There's a lot of crime that they could fight but virtually don't. Also, most endemic low-level crime is best fought with policies and eliminating poverty, not by pinning petty criminals after the damage is already done.
- michaelt 11y agoSuch as? It would be trivial to use GPS data from cell phones to issue automatic fines for speeding. Profitable too - such a project could certainly pay for itself.
- icanhackit 11y agoPutting the contents of the article aside - it's an important topic but most of us are on the same page: Given the Washington Post is owned by Nash Holdings LLC/Jeff Bezos, would it be fair to presume that Jeff realizes the success of Amazon's web services internationally is important and strong security plays a big part in whether the division will be supported by tech businesses internationally? Or do you think Jeff believes encryption is important on a moral basis? Alternate but less interesting considerations: Jeff had nothing to do with the article or Jeff prefers the government stays out of his business.
- snowwrestler 11y agoJeff Bezos undoubtedly had nothing to do with this op-ed. He's a busy guy with Amazon, and has made it clear that he will stay out of the editorial decision-making at the post. In addition, the authors of this piece are not folks who Bezos could push around even if he wanted to. The only way they would write this piece is because they wanted to. Politically, this piece is a big deal. These are "national security establishment" type folks, directly disagreeing with their successors in government today.
- bediger4000 11y agoI agree with your assessment that this piece is a big deal, politically. I disagree with your "undoubtedly". I think there's a fair to middling chance Bezos did some meddling in the editorial process - made a few phone calls, dropped some hints, bent the ears of an editor or two. Newspapers always protest that financial interests don't interfere with their reporting, but time and again, we find out otherwise.
- natch 11y agoIf he's influencing things, let's hope he didn't influence their previous editorial board editorial on this, because it's downright naive and stupid. See link in my other comment in this thread.
- guard-of-terra 11y agoThey also can't get in my head even with "lawfully authorized access", nor can they intercept snail mail after it was delivered, read and burned. What makes them think they're entitled to my digital communications and data?
- davidgerard 11y agoBecause they think they can.
- guard-of-terra 11y agoThis is the war they'll surely lose, but in process they will destroy a lot of lives and careers, including their own. They might also weaken the position of their country in the world (as export restrictions on crypto surely did for the US) What makes them start it?
- anon4 11y agoBecause they think it will be different for them.
- noir_lord 11y agoShrugs, when the US Gov can keep it's highly sensitive OPM database from been stolen and can go breach-free for more than 15 minutes then I might believe they might be able to keep the third party keys secure. However I still then don't think they should have the key anyway.
- deleted 11y ago[deleted]
- natch 11y agoGlad to see someone in Washington speak some sense. But wow what a disturbingly weak "The Post's View" editorial it has in the related links: https://www.washingtonpost.com/opinions/compromise-needed-on-smartphone-encryption/2014/10/03/96680bf8-4a77-11e4-891d-713f052086a0_story.html https://www.washingtonpost.com/opinions/compromise-needed-on... It argues that people concerned about privacy "can rest assured" because keys will be protected by due process. Where to even begin, right? This editorial (talking about my link, not the OP link) has undermined my respect for the Washington Post. Is this really still their view?
- alistproducer2 11y agoIf the plebs want to hand over the keys, go right ahead. Those of us in the know will always be able to encrypt so whatever.