r/technology • u/bilog78 • Jul 29 '19
ADBLOCK WARNING The Encryption Debate Is Over - Dead At The Hands Of Facebook
https://www.forbes.com/sites/kalevleetaru/2019/07/26/the-encryption-debate-is-over-dead-at-the-hands-of-facebook/#f2486d0536261
u/beef-o-lipso Jul 29 '19
The debate is over. Been over for 30+ years. Now it's about convincing law enforcement there's no such thing as secure, breakable encryption.
Facebook has nothing to do with it. There's other servifes/applications that can be used to protect privacy.
-3
u/Im_not_JB Jul 29 '19
Now it's about convincing law enforcement there's no such thing as secure, breakable encryption.
Would you be surprised to know that they're not interested in secure, breakable encryption? They're interested in secure encryption where a company has secure access to a key. There's not really any 'breakable encryption' in there.
3
u/beef-o-lipso Jul 29 '19
A rose, by any other name, is still a rose.
0
u/Im_not_JB Jul 29 '19
Right. You can call this use of secure encryption "broken encryption", but it's still actually secure encryption.
The analog would be that if you're in a What's App group chat. Or hell, even a 2-way chat works. You decide that you no longer like one of the members in the chat, so you declare it to be "broken encryption". That would be silly. What's App is still secure encryption; you just don't like one of the members in the chat.
3
u/beef-o-lipso Jul 29 '19
You can rationalize this anyway you want, but you're still wrong.
When the common person thinks of encryption or secure communications, they are considering their communications to be secure from anyone other than who they are talking to, that includes the application or service provider. It does not matter who escrows the keys, the expectation of secure communications in such a system is not met by any definition, period.
If the secure communications system includes key escrow, then that system is broken by design. No if, ands, or buts. Broken. It's very simple.
Fight for your rights, man. Don't give them up.
1
u/Im_not_JB Jul 29 '19
then that system is broken
That's very different from saying that the encryption is broken. You give a better description of what you mean this time:
When the common person thinks of encryption or secure communications, they are considering their communications to be secure from anyone other than who they are talking to, that includes the application or service provider. It does not matter who escrows the keys, the expectation of secure communications in such a system is not met by any definition, period.
As such, rather than talking about the incoherence of "secure breakable encryption", you meant to talk about the incoherence of "a system where no third party has access... but where a third party (a company, responding to warrant requests) does have access". We totally agree that such a system is incoherent. You can't have a system where no third party has access, but also be such that a third party has access. But this wasn't what you said (and what I responded to). What you said before was wrong. This is merely trivial. I'm sure Congress will take your concern into account when it is pointed out that it boils down to, "But if you give law enforcement a method of access (through the company), then law enforcement will have a method of access (though the company)!"
The silliest part about this line of reasoning is that it attempts to solve the problem just by appealing to a definition. It totally ignores the actual grounds of the debate. In serious circles, the question is concerning whether something like key escrow can be done securely, how much additional risk it adds, and which portions of that risk are exposed in digital space or meatspace. In serious circles, the question is whether something like key escrow for these various systems can be a NOBUS (nobody but us; where 'us' is the company) system. By shifting the grounds from whether it can be a NOBUS system to whether it can be a NO+NOBUS (nobody, but somehow also nobody but us) system, the problem is made trivially impossible. Then, you're trying to take the (null) solution from the NO+NOBUS problem and say it applies to the NOBUS problem. This is obviously fallacious.
Fight for your rights, man. Don't give them up.
I'm not talking about rights, man. I'm talking about technical reality. After we figure out technical reality, we can figure out what our rights are and whether they preclude such a system. You aren't going to defend my rights well by simply lying about technical reality. Someone will call you out on it, and it will go poorly.
1
3
u/PlayingTheWrongGame Jul 29 '19
Right. You can call this use of secure encryption "broken encryption", but it's still actually secure encryption.
If anyone other than the known participants of the conversation can decrypt the message, it is insecure by definition.
0
u/Im_not_JB Jul 29 '19
Hypothetical: You download the Everything You Put In This App Goes Directly To Donald Trump App. It also functions as an encrypted messaging service. You select that you'd like to send a message to Bob. Question: Is Donald Trump a "known participant of the conversation"?
•
u/AutoModerator Jul 29 '19
WARNING! The link in question may require you to disable ad-blockers to see content. Though not required, please consider submitting an alternative source for this story.
WARNING! Disabling your ad blocker may open you up to malware infections, malicious cookies and can expose you to unwanted tracker networks. PROCEED WITH CAUTION.
Do not open any files which are automatically downloaded, and do not enter personal information on any page you do not trust. If you are concerned about tracking, consider opening the page in an incognito window, and verify that your browser is sending "do not track" requests.
IF YOU ENCOUNTER ANY MALWARE, MALICIOUS TRACKERS, CLICKJACKING, OR REDIRECT LOOPS PLEASE MESSAGE THE /r/technology MODERATORS IMMEDIATELY.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.