6 ms·
Is it? You kind of lost me. Isn't the actual issue math?
by seorphates 8y ago
Is it? You kind of lost me. Isn't the actual issue math?
- tomatotomato37 8y agoThe issue is the government wanting to strip the encryption going forward. In other words, even the most decentralized & encrypted app can still have NSA_RemoteConn.Log(dat) written into it's source code
- noobermin 8y agoStripping encryption is one thing, sure. But for the backdoor, you'd have to have the clients phone nsaserv.spy/writeremoteconnlog then or sure, write some record on the client's device. You can't "tap" encrypted communications unless you can figure out how to factor integers then you'd get a Field's medal. Or, ofc, get people to adopt insecure protocols. That we know (or have good suspicion) they've tried.
- madeofpalk 8y agoThe issue is laws. A country that's going to mandate backdoors/access to such communications, are going to outlaw communication methods they can't backdoor. Say Apple makes a federated end-to-end encrypted messenger app, the government will still go to Apple and say "let us read all the messages, otherwise you can't sell your devices". THAT is the problem, and it can't be solved by more technology and shouting "BLOCKCHAIN!"
- joe_the_user 8y agoLaws are an issue and enforceability is an issue. If a largish group of users could create end-to-end encryption not with a single company but with "readily available materials", then stopping it could be harder. So it's a combination of state dictate and the practical ability of users to defy that. This isn't saying I'm optimistic, I'm rather pessimistic on any ability of a wide home-grown encrypted-messaging milieu to appear - if few are aiming for this, those few can easily be picked-off. But I don't think we should just give up on any part of this.
- croshan 8y agoAnd who would use that system, if it were so closely associated with status as a federal criminal? You're forgetting that the average user doesn't care enough to sacrifice ease of use for greater political benefit.
- ethbro 8y agoThere's a difference between running a Tor exit node and encrypting a personal conversation. At least in the US, if a US citizen is part of a potentially incriminating conversation, the government's going to have a hard time forcing a court to force the citizen to decrypt the conversation. Lawyers, correct me if I'm wrong, but it seems like a conversation wouldn't be subject to the vagaries of "combination to a safe"-production loopholes.
- merinowool 8y agoPossession of encryption software could be treated the same as possession of drugs. On the next stop and search you would only had to handover your phone. If police password will not work it will be confiscated. If encryption software is found you go in the dock. It is the future. Society accepted ridiculous laws to jail people for having a plant, they'll accept jailing for programs. Only terrorists, thieves and adulterers encrypt their messages ;-)
- joe_the_user 8y agoPossession of encryption software could be treated the same as possession of drugs. Well, then clearly it would quickly become ubiquitous. I mean, if a war on encryption that was just like the war on drugs were to be launched, why my local stream bed might "place burned passwords here" on the tin-can that currently reads "used needles here." (put there by the other homeless people).
- realusername 8y ago> Possession of encryption software could be treated the same as possession of drugs It's too late for that, every machine, every browser, every user is using encryption software all the time.
- ekianjo 8y agoIts not laws since the US government and probably others have already shown with the NSA and the like that they have no respect whatsoever for the existing laws and nobody actually seemed to care one bit about that.
- philipov 8y agoIt's this: https://xkcd.com/538/ https://xkcd.com/538/
- seorphates 8y agoThis actually feels more like what I would expect police work to be like given the situation. They most certainly do not have cause to demand access to swaths of comms no matter whose comms they're after and most assuredly when that access actually entails enabling access to all of the comms. I posit there is no authority that should be able to demand this as a matter of the right to human existence. Law, order, society and government should not have ultimate authority on private communications no matter what the tech is capable of. We, as humans in a modern world, can speak and if desired do so in private. This is our right as individuals and if encryption helps us accomplish and enforce that right then so be it. If they have probable cause then they need to beat feet or beat heads but either way they need to get to work. And by work I do not mean trying to impose a different reality than the one that we currently have - where math is fact, compute is cheap and source is open. What's it going to be? 100 go free or six lines from everyone?
- dylan604 8y agoset up the device to wipe itself after $x number of incorrect attempts. keep giving the wrong password after every whack from the wrench. then you have plausible deniability. "how can i possibly think straight when you keep hitting me with that wrench?" just need to make $x a value small enough that you can survive the wrench.
- wdh505 8y agoNo good, it is already standard for forensic teams to clone and checksum a hardrive before attempting to look through files. The clone is sent to evidence and any password attempts will be made on a copy. The "original" copy will be kept safe and any number of passwords can be used against nth iteration of copying the clone.
- josephagoss 8y ago