A Back Door to Encryption Won't Stop Terrorists
bloombergview.com
bloombergview.com
It more or less proves (to me at least) that the government(s) and the various secret services have absolutely no idea who to monitor specifically. So instead of targeting their operations they want to monitor all of us, just in case something of interest pops out that then allows them to focus their attention.
It's a pretty scary thought: just imagine, all that money, all those resources and still they can't do anything other than to put their ear to the ground and hope that someone messes up in plaintext so they can then try to backtrack and see what they might have missed.
In all these attacks it never happened that everybody was under the radar. Always one or more of the attackers that were technically known or even already under surveillance. And yet the attacks happened anyway. Too many targets make for a very thinly deployed service, which then has to be automated to make it work at all.
It's a pretty sobering thought, it also suggests via yet another route that mass surveillance is indeed meant to attempt to 'keep us safe', and that it fails miserably. The road to hell is paved with the best of intentions.
Terrorists have it so easy, all they need to do is to be just a little bit unpredictable or simply old-fashioned (in person) and there won't be anything whatsoever that we can concretely do to stop them. The only thing that actually gives a bunch of actionable data is when an attack is executed or when an attack goes sour (or rather: sweet as in, it does not work) from which direct evidence of contacts or plans is gained. This will then lead to a relatively short lived number of arrests clustered around the people caught or implicated and then it burns out again where the data ends.
And so then we get to wait for the next attack...
Except that most of the recent terror attacks have involved at least one person known to the authorities. One of the Paris attackers even had an international arrest warrant out for him.
Edit: Some more on that: the best way to attack a high-tech society is using low-tech means and vv. We're totally blinded by our trust in technology.
Accepting that means we can throw those wasted resources at things that have a better chance of working - throw the tech that detects copyright infringements at detecting pro-ISIL sites, and use DCMA-style tactics to take them down. Fund new research to put effective bomb and weapon detectors into every doorway. Because protecting borders doesn't work either (crunchy on the outside, soft on the inside). Build schools, instead of bombing them. Stop selling weapons to the very people that shouldn't have them. Teach politicians to value non-American lives as much as American ones. Stop honouring violent death, and honour the deaths of people who move humanity forward instead.
There's an endless stream of ideas of what we could do, if only we actually wanted it.
I don't think surveillance is very good at preventing terrorism, but I think it could be useful to law enforcement after the fact to round up co-conspirators. I bet that once the identity of the Paris attackers was learned, the NSA pulled up a graph several levels deep of everybody they communicated it or associated with. It could very well help them figure out who else is involved and should be watched.
For the record, I'm opposed to surveillance and would be even if it were shown to be very effective. Privacy is important and is worth more than the lives that have been or will be lost to terrorists and other criminals.
All these guys were already on watch lists for fighting in Syria and returning just nobody seems to ever watch the watch list.
Each and every operation of this magnitude leaves a trail. The party perpetrating it will try what they can to erase that trail but that will always be an imperfect process.
Maybe next time the phone will be secured, they will scrub themselves of parking tickets, they will burn up their escape vehicle after a few minutes ride and so on. All the media has succeeded in doing is educate the terrorists about how to be more successful in evading capture and possibly being more successful in carrying out the attack in the first place.
But then, if they'd used a CB radio, there'd have been no records on the device at all. You can go both lower and higher tech to avoid leaving a trail.
The fundamental issue our society faces is that the world people thought existed, pre-Snowden, wasn't all that bad. There are controls, a system of laws and warrants, judges have to approve requests for data, and companies hand it out only in cases where it's really justified. Terrorist used WhatsApp to send a message to his buddy before blowing up a football stadium? It is - literally - warranted.
Post Snowden we know that world didn't really exist, it was more a sort of theatre governments put on when they didn't care much about the outcome. So now the data is disappearing so nobody has it. It's not obvious that this is an improvement over restoring the world that was previously thought to exist, but that was apparently too unstable to survive.
No bulk surveillance required, just honest police work within the confines of a valid and acceptable legal framework.
My point was that collecting it all isn't necessarily about stopping incidents, it's about instantly knowing everything about a terrorist once they are identified through other means. There's certainly value there and the debate is whether or not the cost is too high.
That means the DGSI would need 230,000 staff to follow all of the extremists all of the time
"The problem is that we have forgotten the power of ideology and the way that you cultivate civilized discourse and expectations. In the Western world, we've spent the last 40 years shitting all over the best weapons we have to address ideology: philosophy, literature, poetry, art, music and religious discourse. We've marginalized the way to talk about the abstract elements of human experience, and now we find that we have nothing to say."
I don't want to live in a world that has bomb detectors in every doorway.
I think that when terror is something that can happen constantly for months at a time, people learn to keep living their lives without fear, but also to take measurable actions that really prevent the next attack.
I think the response should be a careful, cursory action that acknowledges the public demand for retaliation, but all else put into the long game of building resistance to radicalised violence - working on education, poverty, etc amongst the communities where agitators source members. We should be encouraging people to find common ground rather than react aggressively, even if that is the gut response.
I am very irreligious, but there was a great comment on HN the other day about a fairly orthodox Christian finding that they had more in common with a fairly orthodox Muslim colleague than with other atheist co-workers.
Often the political and public reaction after an event like this is to focus on differences (language, clothing like burkas, etc) rather than things like a love of family, of food, sport, music and so on.
I live in Australia and our new prime minister is far, far better at this than the previous us-vs-them dog-whistler.
All those have a higher percentage of Christians in their populations than the US or anywhere in Western Europe, and they don't have the same level of anti-terrorism focus so are presumably easier targets.
Could it simply be that those countries haven't been bombing and invading places in the Middle East?
These countries have negligible numbers of Muslims.
There have been multiple Islamic terrorist attacks in Tanzania (which borders Zambia) and Kenya, both of which have significant Muslim minorities. Not to mention the frequent attacks by Boko Haram et al in Nigeria and the perpetual civil war in Somalia, which is overwhelmingly Muslim.
Even the threats and attacks against cartoonists, as mentioned by another commenter, go beyond the simplistic "kill all infidels just because they exist".
To put it more simply: when Danish cartoonists are threatened for offending Islam, is that also because of imperialism?
And why would you believe them? What they say on TV is also a weapon. People who don't come and negotiate but go straight to killing won't be posting their real goals on their website, they'll rather post something that helps further those goals.
But let's take at face value that that's possible, you'd still have to assume that all terrorists have a) some rational set of demands; and b) even if they did, that we'd be willing to meet those demands.
What ISIS believes is incompatible with Western democracy. There is nothing we could do to eliminate their desire to attack us that wouldn't mean our own destruction, anyway.
No, the goal should be to improve the living conditions, infrastructure, access to education, etc of impoverished regions where terrorist sentiment typically appears and festers.
To give an extreme example, there is a reason the Saudi royalty aren't walking into the middle of a marketplace and blowing themselves up: they already have everything they want/need. I'm not saying we should make everyone royalty, but that there is a clear correlation between standard of living and terrorist sentiment.
Standard of living is a continuous curve which has absolutely nothing to do with mass murder. There is a binary switch which occurs separately from any experience which is measured in terms of 'standard of living'. Now maybe there are some experiences which can drive a person to commit terrorism, but I think more likely, this terrorism is not a consequence of some action, but rather, these are a group of people who use terrorism as a tool to wage war. Why are they at war with the West? It's not because of standard of living, I'm pretty sure it's because they hate everything the West stands for and wants it to burn.
You mean the United States of America, terrorizing Pakistanis for years now?
There's no binary switch. There are tactics effective for given goals and circumstances. Mass shootings and suicide bombings are a perfect strategy if you want to make a country destroy itself. The question is - why would you like to make that country destroy itself? The answer is not:
> It's not because of standard of living, I'm pretty sure it's because they hate everything the West stands for and wants it to burn.
That's not only bullshit but, if it were true, it would be the best argument to just ignore those attacks and treat them as any other murder done by organized crime. Because if they "hate our freedom", then by overreacting and turning ourselves into police states, we're doing their job for them - we're putting our economy and industry into dismantling everything the West stands for.
You look for a second at the people who actually carried out recent attacks, you will see what I mean. Who said anything about police state?
The thing which has impressed me is apparently this guy was a prolific attack planner. Known and poorly tracked. I'd say a major intelligence failure.
Far as intelligence agencies, they've not just failed: they've often tried to cover it up, mislead other authorities, or even destroy evidence. The result of incompetent organizations not capitalizing on what they have even when it's obvious should be a net reduction of power and increase of accountability. Instead, they always ask for and often get the opposite.
The technically literate of us following the details should just keep reiterating to anyone that will listen the key detail: almost everyone whose launched an attack did it while already being under surveillance. It doesn't work. End of story.
Note: If it did, they just go back to doing what pro's already are in using human go-betweens and other low-to-no-tech methods like Osama did for years to dodge NSA. They didn't get him until someone tipped them off for the bounty per Hersh.
How do I convince someone they should try to not feel fear if they strongly believe their fear is valid and that attempts to invalidate their fear are an insult.
I don't think that you'll find many exceptions to that.
> E.g. I know that there is almost no chance that I'll be the victim of gang violence. But that doesn't mean I have to just accept the existence of gang violence in my community.
So, as a member of that community you then have the option to go out and do something about it. You can also move out, you can pay someone else to do something about it (which you already do through your taxes, hopefully they do enough). You can also keep your eyes open if you see anything suspicious and report it. You can rally support for better pay for the police so the chances of corrupt police interacting with gangs goes down.
And finally, it may actually mean that yes, you will have to accept the existence of gang violence in your community if that community is incapable of changing from within.
Gang violence takes a while to establish itself, and it - even with the best of the best working to get rid of it - can't be gotten rid overnight. Problems of this kind usually take roughly as long to fix as it takes to solve them.
Note: The 100-1,000 years is to represent the fact that virtually nobody dies from terrorist attacks. It's so rare that bathtubs and bee stings kill more people each year in the U.S.. I'd imagine it's not a leading cause of death in France either despite the recent attack. So, for your gang thing with 100-200 people in a neighborhood, they'd go through many generations before one person died from gang violence. Sounds like the high risk that should keep them up at night, eh? ;)
We have no idea how many attacks have been prevented (everyone likes to claim this is zero....but they do so without any evidence to support that, as relevant information is surely classified beyond Top Secret).
We have only the slightest, tiniest, smallest idea of what the NSA and other intelligence organizations are capable of.
British intelligence took how long to tell people that they cracked enigma? 50 years?
Out of the THOUSANDS of documents that Edward Snowden leaked to reporters, the public has access to what? on the order of 50?
Yeah....we know nothing...so saying one way or the other is kind of ridiculous at this point.
My point is entirely aimed at the linguistic use of "proves" than anything else.
The person I was commenting to, however, IS making a claim. Maybe your burden of proof applies to him?
This argument is actually subject to Russel's Teapot, if you cant prove or disprove anything the burden of proof is on proving the thing. I have yet to see any evidence.
We as a society do not have that power, and that should be obvious by now.
When a court decided what they were doing was illegal, less than a day later (probably the fastest anything has EVER happen in the legal system), another bench decided that what the NSA was doing was TOO BIG TO STOP. Like seriously, their argument for not stopping something UNCONSTITUTIONAL was that they were doing too much of it.
You and I, and every other civilian who actually understands what they're doing have ZERO power to stop them, so they have ZERO incentive to convince US what matters.
You know who they DO have to convince? The exact people that keep voting to KEEP THEM IN POWER.
I don't care what Obama and his administration claims, like I said, they have no incentive to prove anything to the American public.
"Is mass surveillance useless? Unless you can prove it, it's obviously useful. See Russell's teapot."
(Russell's teapot doesn't apply anyway, because the thing to prove is falsifiable: governments /could/ release information about thwarted attacks, in case there are any.)
Yes, we do. We know ALL of the FBI's high profile terrorism cases. Apart from the Tsarnaev brothers, it has been all cases where one or more fools got snared by a provocateur.
So unless you believe that there is a secret system of arrest, a secret court that hears terrorism trials, and secret prisons all operating inside the US, we know exactly how effective mass surveillance of the US population has been in preventing terrorism.
We already know there are secret courts that hear secret arguments that can't be refuted by defendants/targets. Oh, and if that court involved you, you're legally not even allowed to tell anyone.
We already know that the NSA/FBI/CIA/DEA uses parallel construction to actually prosecute crimes against US citizens.
How do we know this stuff? Someone with clearance risked his life, and gave up his freedom to tell the world. Oh, and the US said they MIGHT NOT waterboard him if he ever came back to the US to face his crimes.
And out of the thousands of documents he had, how many do we have access to? A few handful?
Sure...we know everything </sarcasm (as if you couldn't tell)>
If I was slightly more conspiratorial I would suggest that that is the 64 million dollar question.
In reality though, I think we are talking about two different types of knowledge here.
When I say knowledge is power, I'm talking about power over individuals. The type of knowledge that allows you to say "Hmm, those are some interesting emails you sent, Senator. Let's see if we can come to an agreement to make sure nobody else sees these." The type of knowledge that makes the average citizen think twice before making that Google search, or before posting a comment online.
Even with total info awareness, to stop attacks you need the ability to filter and flag the data you have to sound the alarm when needed. Fundamentally, that's a data processing problem and not specifically what I am talking about.
There is way too much volume and noise to find threats in the hurricane of hay flying past to find the needles in real time.
But if you have someone specific to start targeting, you can quite easily take their whole life apart and find their friends and make all these connections after the fact.
The goal isn't to stop attacks, it's to ensure that nobody goes unpunished.
Another reason not to publicise their successes is that may give an indication of how they are tracking and if the terrorists know how they are being tracked they can change how they operate. For example perhaps they always call directory enquiries to get a number/address and if that is the way in it's in the interest of the spies to not let them know that so they can continue to use that chink.
We all know that while terrorism gives these initiatives fuel, they ultimately have little to do with terrorism and much more to do with governments wanting as much surveillance and control over their populations as possible. The odds of dying in a terrorist attack are approximately 1 in 20 million; for comparison, you are 25X more likely to die by drowning in a bathtub and 1,000X more likely to die in a car crash [1]. If terrorists are 1/25th as effective at killing people as bathtubs, how many of our civil liberties should we be willing to give up to stop them?
There are currently at least 3,278 prisoners in the US serving life without parole for non-violent offenses [2]. Perhaps we should stop terrorizing our own citizens before we worry about foreign terrorists that can't even keep up with bathtubs.
[1] https://reason.com/archives/2011/09/06/how-scared-of-terrori...
[2] https://www.aclu.org/files/assets/111813-lwop-complete-repor...
You are proposing that public spaces be fitted with some kind of system that can reliably detect bullets based on their "speed, size, and shape" profile.
How do you propose to do this without using a bunch of sensors?
> and much more to do with governments wanting as much surveillance and control over their populations as possible
Outfitting all public spaces with sound and vision recording/analysis devices seems like the very definition of mass surveillance and control.
> Anyway, generally you're referring to technical challenges, all of which could be readily solved.
Of course, we should not get bogged down in the technical implementation detail, but you can't just brush away these - very valid - technical criticisms of your idea.
You want to hash out the design of a complex idea in an HN comment thread?
Think through something like this, outside of your expertise, that you think the powers-that-be should just do. Maybe it's something with your local municipality's approach to road resurfacing, maybe it's the quarterback on your favorite football team, maybe it's your local zoning board.
Chances are better than even that there is a decent technical reason why they don't do what they do. Looking at things that way will save you a lot of headache in your life, and set you on the path to getting on someone's side to affect change, rather than just being another shrill voice yelling against them.
So politicians and intelligence services calling for encryption want, institutionally, to keep people safe. How can tech companies do that without breaking or backdooring encryption? That's the real problem to solve, and the first person to figure out how to do that will be way ahead.
Isn't that the entire purpose of agencies like the CIA?
It just bothers me when privacy is treated as a negative thing, for the greater good or not. Encryption is a tool to create privacy. The ability to create privacy should be a point of pride as not everyone has that luxury. It should be a human right.
This is the primary reason why I feel things like CISA/CISPA/etc take society in the wrong direction. It doesn't matter if the intentions are good or bad when everyone loses.
I agree; so does the UN in The Universal Declaration of Human Rights:
Article 12. No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.
Article 18. Everyone has the right to freedom of thought, conscience and religion; this right includes freedom to change his religion or belief, and freedom, either alone or in community with others and in public or private, to manifest his religion or belief in teaching, practice, worship and observance.
Without power to back it up it means nothing.
"In the exercise of his rights and freedoms, everyone shall be subject only to such limitations as are determined by law solely for the purpose of securing due recognition and respect for the rights and freedoms of others and of meeting the just requirements of morality, public order and the general welfare in a democratic society."
The bad guy may have told someone in person where the location is... or sent an encrypted email. But unless you were involved in either conversation, you are still in the dark.
Information about the uncrackable padlock is widely available. Bad guys will always be able to get these padlocks from the black market. The question is whether we want the good guys (i.e. us) to have the padlocks too.
Back to HN's world, one of the basic principles of human factors is "make the right thing easy and the wrong thing hard." You might not be able to prevent people from doing the wrong thing, but there is still value in making it harder to do.
1. Depriving the the public of decent encryption does a lot of harm. If you let some people in through the backdoor you're going to let bad people in too.
This is different from nuclear bombs. It doesn't harm the public to deprive them of nuclear weapons. I like having my financial information encrypted, but I don't want a personal nuclear bomb.
2. Non-proliferation of encryption wouldn't work. The algorithms and ideas are already widespread. Every university teaches it. Millions of computers have the code already. The code and ideas can be proliferated anonymously, instantly, undetectably and cheaply.
This is different from nuclear bombs. Nuclear bombs are much more complex and expensive to transport, manufacture and hide.
(I haven't mentioned AK47s, but I'd say they fall somewhere between between encryption and nuclear bombs in benefit vs harm to the public and in ease vs difficulty of non-proliferation, which is why there are more of them around than there are nuclear bombs.)
All you need to write an encryption program is an explanation of the concept behind a single algorithm, someone with math smarts, and almost any computer.
But honestly, I think it'll result in bad guys using the same backdoored crypto that everyone else will be using, relying on steganography and disappearing in the noise - so basically, they'll do things in the same way as they always did, since assuming all communications is broken by the government is simply good OPSEC.
Clever locksmiths will always be able to make powerful padlocks using that research.
Not really. It secures long distance communication, but I've always had the option of just talking to someone privately if I want something to be secret.
It actually is a human right.
The right to privacy is one of the most fundamental ones that we have.
Why do you say this? It seems you are accusing parent of making a big leap in logic and then doing the same type of leap yourself.
Do you have any evidence that they want to do more than keeping people safe?
I've worked with and talked to many who work in the DoD space and while there were some who didn't seem to understand how technology worked I never met one who didn't seem genuine in wanting to keep people safe. Sure plenty of contractors just want the money and don't give two shits either way and sure this is only anecdotal but do you have anything better?
Seems the easiest, least complex reasoning is people who are not well enough versed in the technology but have good intensions are trying to do what they think is most correct when it may not be.
This is one reason I tend to think intelligence agencies should be disbanded and their best people merged into police forces. The police have a clear and (relatively) focused mission: fight crime. Most of those criminal investigations are about keeping people safe in one form or another. Police forces aren't tasked with economic wellbeing or "cyber defence" or any of the other crap that the intelligence community has tried to take on for itslf.
Bonus points if you show the risk to them personally: makes them most likely to act against it politically. :)
Given:
Things like mass phone surveillance, passively breaking legitimate encryption used by non criminals, introducing vulnerabilities, and other plainly illegal behavior is being deployed against citizens
..with no recourse..
..which are answered with outright lies when challenged (c.f. Snowden, Clapper's lies before Congress)..
..and the methods are of dubious actual effectiveness when it comes to "keeping people safe"
..and they in fact reduce safety when it comes to introducing vulnerabilities which can be misused by criminals
Therefore:
The aims of said behavior is plainly not to "keep people safe", but some other alterior motive. Simple statistics show that garden variety cybercriminals are a more real threat to the average person than terrorists - so do no statisticians work for the feds, or is there a different plan we're not seeing?
Lets say we do manage to come up with an alternative that would keep people safe without requiring mass surveillance then it would not remove any of the other motivations (say business espionage). I think appealing to a technical solution for a political problem is unlikely to work, but it could be possible.
That's the public face. The underlying motives are much more closely aligned to the power structure and the flow of money and votes than keeping folks in suburbs "safe".
I don't think this is a technical problem, and I don't think it's our responsibility to solve it.
If the US wants to stop terrorism they need to stop creating terrorists. The US created terrorists by starting economic wars, supporting violent dictators, creating economic that harm the common people and not the national leaders they purport to, providing conditional and earmarked aid that is sometimes actually harmful, and a wide variety of other internationally sociopathic behaviors. If we want to stop being attacked by people from other countries, we need to stop harming other countries.
Just because some politician claimed that it's tech's people responsibility to fix their flaws, it does not make it true.
It's repetitive, but the police did have all the information they needed to go after such people even before the murdering. What does the GP want? A machine that queries the news from the day after tomorrow? (Because tomorrow won't do - the police had warning that it would happen at the previous day.)
If the Paris police had all the information they needed to go after such people, but didn't, that's the technical problem that really needs solved, not an encryption backdoor.
Better data organization tools are another (a family member is studying forensic science and has done internships with large-ish police departments that still largely use printed and hand-written documents to manage cases)
But that's my point. I haven't done much thinking on this either, so I can't see around the corners of time to see what it could be. But just more yelling back and forth about encryption isn't accomplishing much.
Maybe it's not a bits and bytes technical problem, but it's technical according to the definition of the adjective, "of or relating to a particular subject, art, or craft, or its techniques." If the Paris police had the information, but were unable to properly analyze it, that's completely a technical problem.
But I still don't think this should distract from a conversation about encryption. Encryption has very importat implications for free press and privacy far outside of preventing terrorism, and it's important that it stay legal and accessible to normal people. Experts need to make their voices heard so that legal decision isn't made by people unconcerned with these important issues.
That being said, could you provide examples as to how the Middle East has reacted to meddling as opposed to South East Asia?
Speak for yourself. I'm an American citizen and I don't want to start economic wars, support violent dictators, create economic sanctions that harm the common people and not the national leaders they purport to, provide conditional and earmarked aid that is sometimes actually harmful, and a wide variety of other internationally sociopathic behaviors. I think most people would agree if they actually understood that that's what's happening. But most people think we're spreading peace and freedom and protecting human rights.
People are good at having enemies, whether they deserve them or not. There are people who would kill me right now having done nothing particularly wrong. There are even places where it is legal and encouraged to do so.
Additionally, notice that what jacquesm said is never brought up in these debates much like what U.S. did in Operation Ajax or sanctions that followed wasn't factored into recent Iran debates. Much easier to pretend all this stuff happens in a vacuum that requires a surveillance or police state. Which doesn't work anyway:
https://news.ycombinator.com/item?id=10591617
https://www.schneier.com/essays/archives/2006/08/refuse_to_b...
You know who is involved in these regions? Countries with money. Because without money, you can't do anything but let dictators and mass-murderers trample around like vicious kings. Turning a blind eye to your abused neighbors isn't a way to prevent terrorism, either. You might reduce anti-US terrorism by ignoring the rest of the world, but a lot of people will die, and you're still going to have enemies. It's a factor, not a solution.
Though I suppose if the US were poor as dirt, we wouldn't have to worry about terrorism. Just civil war and invasion.
And so on and so forth. Vast majority of terrorism against the U.S. is by actors whose activities or capabilities are directly tied to U.S.'s own imperialism abroad. Not our money, democracy, religion, anything. Just doing evil dangerous stuff over there and funding/equipping those that do the same often to rip off resources.
Far from a mere "factor," it's been the single most consistent and driving force behind all terrorism against us. That means... that eliminating that while working to improve the situation over time might eliminate most terrorism against us? Well, let's do that then!
That's a stupid and suicidal policy.
>Far from a mere "factor," it's been the single most consistent and driving force behind all terrorism against us.
So you say. But I can't distinguish that whether that statement is fact or ideology. So I don't believe you, and I shouldn't until you've got some convincing evidence that it's true. You can tell me a story. I don't want a story.
And I really don't see how people committing acts of terrorism are making good decisions that we should support by giving them what they want for doing so. Seems like a bunch of grudge-holders that need to grow up before negotiations become an option.
So you're saying we should have committed mass murder and armed terror groups throughout the Middle East in the name of stealing resources or manipulating politics? Did you do any research to back this or are you writing up some far-fetched, sophist comment since you can't counter my points?
"And I really don't see how people committing acts of terrorism are making good decisions that we should support by giving them what they want for doing so."
Last I checked, the U.S. was still trying to screw with and control much of the Middle East instead of support them. The regions where we have the most meddling are among the least stable. Doing good over there instead of evil might actually accomplish something. Further, areas with groups like ISIS aren't terrorism vs Some Good Government rather than a group of competing evil groups all set on controlling and oppressing the area. So, fighting one isn't fighting terrorism so much as fighting one group while putting another into power.
You won't see the U.S. truly fight oppression over there because it's not in power-players financial and political interests. There's benefits to be had from continued partnerships with dictators and theocracies. Just ask Saudi Arabia.
>Did you do any research to back this or are you writing up some far-fetched, sophist comment since you can't counter my points?
No, I didn't do any research. I took a class on West Asia and North Africa in school. I lived in Iraq for a year.
But I don't think you've done any research, either. You're just saying talking points.
>Last I checked, the U.S. was still trying to screw with and control much of the Middle East instead of support them.
You checked? Let me know what you checked. Where you checked. Who you checked with.
>You won't see the U.S. truly fight oppression over there
Truly? Isn't there a term for this kind of waffling? "No true scotsman" or something?
> So, fighting one isn't fighting terrorism so much as fighting one group while putting another into power.
That's what fighting is. Any fight you do is going to put someone in power. It doesn't matter if you're fighting terrorism or not; that's the whole point of fighting.
The point of the discussion is U.S. government and a chunk of America wants to stop foreign terrorists from trying to blow us up. The foreigners doing that have exclusively done it due to interference, often violent and imperialistic, in the Middle East. So, many of us draw the logical connection that this was the cause of actual attacks against us rather than terrorism in general which we don't care about. So, to reduce number of attacks, we must stop doing what caused them and modify our strategy of dealing with the mess we're in to account for this. Otherwise, our actions over there, esp collateral murder (err damage) & weapons distribution, will likely just create the next wave of terrorists like Bush/Cheney Administration just did with ISIS.
That's my claims. Now, do you have any counter to those specific points or would you like to add to them? To be extra clear, given your sophistry, I've claimed the following:
1. The U.S. takes overt and covert action against Middle Eastern countries for financial and political reasons rather than for survival. So, it shouldn't have taken that action and should reconsider future behavior like that.
2. Disruptive U.S. actions in the Middle East creates opponents, including the organizations that attacked us. So, they should stop doing that and fewer terrorists that attack us would be created.
3. Previous handling of opponents equipped and trained likely long-term foes before abandoning them. They consistently ended up turning into problems: Taliban; Saddam; ISIS. The U.S. needs to stop doing that. Throw their best minds on fresh strategy before doing any major interventions and with much focus on long-term effects with regard to terrorism blowback.
Surely you can discern why disagreeing with someone on HackerNews is different from invading their country, seizing their resources, and killing their family members.
> So you say. But I can't distinguish that whether that statement is fact or ideology. So I don't believe you, and I shouldn't until you've got some convincing evidence that it's true. You can tell me a story. I don't want a story.
And you can distinguish fact from ideology when people say that the solution to terrorism is more of what we're already doing?
I can understand you discarding information because you don't believe it's reliable. What I don't understand is that in the absence of information you believe to be reliable, you've still decided to form an opinion and argue for it. If you don't have enough information, it's okay to admit you don't know.
> And I really don't see how people committing acts of terrorism are making good decisions that we should support by giving them what they want for doing so.
I really don't see anyone proposing that.
But with money, you can arm those dictators and mass-murders so that they can become actual vicious kings.
> Turning a blind eye to your abused neighbors isn't a way to prevent terrorism, either.
That's true, which is why it's so puzzling that we so frequently turn a blind eye to our abused neighbors and fund the abusers.
I'm definitely not proposing isolationism. I'm proposing we spend aid money actually helping the populations of nations instead of funding whatever militant promises to protect US interests.
Bingo!
This statement would have more resonance if the US fell into the "or not" category. ISIS is basically America's Frankenstein[1].
[1] Yes, yes it was the doctor's name.
Why are they knowingly allowing people who fought for ISIS to return to Europe?
People don't lose their rights just because they travel to the Middle East...
Toss them in jail when they get home, but they still get to come back.
Its not a tech problem or a solvable problem in the way you imply. It sounds reasonable but it is like solving lightning strikes. You can't actually "solve" lightning.
You can reduce the causalities through reasonable precautions but people are still going to die.
Its frankly irrational to talk about this problem as an actual problem. Terrorism is less dangerous to me than preventable medical errors for fuck's sake.
http://www.propublica.org/article/how-many-die-from-medical-...
> In 1999, the Institute of Medicine published the famous “To Err Is Human” report, which dropped a bombshell on the medical community by reporting that up to 98,000 people a year die because of mistakes in hospitals. The number was initially disputed, but is now widely accepted by doctors and hospital officials — and quoted ubiquitously in the media.
> In 2010, the Office of Inspector General for Health and Human Services said that bad hospital care contributed to the deaths of 180,000 patients in Medicare alone in a given year.
> Now comes a study in the current issue of the Journal of Patient Safety that says the numbers may be much higher — between 210,000 and 440,000 patients each year who go to the hospital for care suffer some type of preventable harm that contributes to their death, the study says.
Shaving 1% off 98,000 deaths a year will save more people than preventing the Paris attack.
How the fuck is it rational to be focusing on anything other than major causes of preventable deaths?
Sorry, honestly, at this point I'm just disgusted with anyone who suggests terrorism is a threat worth throwing billions of dollars and lives away on while they casually ignore far more dangerous sources of human deaths.
Get back to me when funding preventable harm in medical care is worth hundreds of billions of government funding.
People aren't scared of dying in traffic or by a preventable medical error. Maybe they should, but they aren't. Those risks are real, but they don't affect how people go about their lives. Terrorism is a tiny risk of death but an enormous cost in terms of percieved safety.
Its a cliché to say "defend our way of life", but throwing money at creating the illusion of safety so I dare go to the football stadium is just that. I wish we didn't have to spend millions securing a football match, but one can't dismiss it as a waste without assigning a zero value to the idea of going to watch the match. Times many thousand spectators.
The perception stems from the difference in media coverage and political grandstanding imho.
At least you have a legitimate objection, I just don't agree with it.
It's often used as code for "a woman is speaking, plz ignore" the same way bitch is.
I would just politely suggest you use a more descriptive word for what you were alluding to.
In any case, in the above comment it is used to refer to the way the pitch of male and female voices rises when frightened or exited and is far from being a gender-specific slur.
130 people were killed in those attacks. 361 people died in automobile accidents in Minnesota in 2014, to find a random statistic. Terrorism is simply not a real threat, and eliminating it will not make anyone any safer.
That's the problem: they can't. The tech just moves information around in ways that are visible and can be invisible. Even the subtle timing of the signal can be used to communicate. What you're asking is that tech companies do two things:
(a) Ensure every tech with communication mechanisms can only work in a way known perfectly ahead of time and controlled to prevent all leaks.
(b) Ensure that every message, regardless of its words or properties, isn't aiding evil somewhere.
(c) Ensure that it's impossible for a user to put obstacles between their identity and a communication tech so we know exactly who the evil-doer was.
That's simply impossible. It can't be done at all. Talking about lay terms, North Korea has the most totally controlled Internet and country locked down by both technology and terror. Possession of a cell phone can get you locked up and leaving can get them after your family. Yet, there's regularly communication from small numbers of courageous people coming out of that country. If that ideal surveillance setup won't work, how on Earth could any tech accomplish the same thing with the diversity of sites, language, interactions, and tech that exist in Western countries like America?
It just can't because it can see bits and read the minds/hearts of those that create them. That's what the government wants. It's not possible. Otherwise, they'd probably have eliminated most crime already looking at people's homework in school or text messages divining their character. ;)
Also, the problem's been known so long there's even a meme for it:
I think the need for strong encryption and no backdoors (which has Schneier explains, are always a double-edged sword) are very important and I support them, but that those on the side of it who also have in-depth knowledge about the finer details don't deign to articulate just what exactly the policy looks like without resorting to just a list of what we shouldn't do and vague allusions to "just go old-school" or "utilize human assets more."
A coherently articulated, normative counterfactual security platform would be a better place to argue from.
It's a cousin to the negative liberty arguments: they only list what not to do to in order to avoid hurting people, rather than what we can do to help them (positive liberty.)
Maybe we could frame the question as "If we let the EFF and Bruce Schneier redesign the United States security apparatus from scratch, what would it look like?"
Strong encryption cannot be back doored in an effective way, this is just a fact. Ignoring that fact because we wish it were otherwise, or asking the people that point out that fact what we're supposed to do in light of that fact, doesn't change that fact.
The group constantly pushing for backdoored strong encryption fails to realise that they are asking for regulations to ensure that all water is only ever sold in ice form. This does not, and cannot, mean that all water will only be available as ice. This needs to be realised, accepted and moved on from.
Only then we can start actually trying to formulate a coherent asymmetric warfare strategy, cognisant of the actual facts on the ground rather than wishful thinking and ignorance.
And from then on, ONLY use surveillance on specific targets under investigation.
And while at it, maybe even have a limit on the number of targets each agency can investigate, so they chose them wisely.
Edit: lots of people saw Atta being a POI as a sign of a "let it happen" conspiracy, but the much more likely explanation is that he was on a very long list of watched persons. Being of interest for whatever reason is not a crime (and shouldn't be), so there is nothing the FBI or anyone else can do until someone actually does something. Of course then it's too late.
Police can rarely stop crime unless they happen to luck out and be at exactly the right place at the right time. They can only catch criminals and take them off the street so they can't commit more crimes.
Just like American prisons where petty criminals learn to become more violent and escalate their crimes when they get out because prison offers nothing else for them.
Yep. Its a prime example of why these surveillance powers simply don't function the way their proponents claim in public.
A large part of the reason there are these conspiracy theories is because their failures seem to be spun so well they might as well have been planned for all intents and purposes. They immediately blame other people and clamor for money and power to further their interests ... and people actually take them seriously which to me is the scary part.
France has the most extensive mass surveillance capability of any first world Democracy and the ability to act without the permission of the courts or legislature ... yet it wasn't enough.
I don't see how "more power" is the answer. It seems to be me that suicidal people are going to be successful at taking other people with them no matter what we do. So we take reasonable precautions that don't infringe on everyone's liberty. Then we make sure people who ignore actionable intelligence have career ending consequences to make them accountable.
This is an insanely bad idea. I understand where you're coming from, but think about how that would play out in real life. I was going to write it out, but I really think that you can probably figure it out if you do think it through. From the perspective of the intel/policing agency, and from a political side, there are too many good reasons why we should not limit the number of targets an agency can investigate.
(a) Magic, AI, pixie dust tech that spots the evil, relationships, and all key information in nearly unlimited, streaming data.
(b) Eliminating bulk collection (except maybe metadata) while forcing them to focus on the results of targeted investigations on accounts or individuals. Also, forcing them to follow-up on solid, red flags rather than BS around trying to find reasons everyone else might be guilty.
I think pushing for option B is a rational choice. Also, ensuring the greatest accountability possible given all the main players have a history of using their police and intelligence for matters that have nothing to do with protecting citizens.
I think that anyone that's had to deal with arbitrary limits imposed from above understands the perverse incentives that they create. This would be another example of administrators trying to fix something that they don't understand.
https://theintercept.com/2015/04/15/fbi-informant-stung-fbi/
So, I'm pushing for more than an arbitrary limit on number of investigations. I'm pushing for them to switch their focus back to pre-9/11 where they leave most of America alone, keep good red flags, and focus their investigators on those. The barriers to intelligence sharing have been knocked down and local LEO's are integrated so dots should be connected faster than ever. With this focus, the limit will be the number of cases they're working simultaneously rather than on the books in general. It can be a multiple of the number of agents they have. Because it's hard for me to imagine one investigator effectively working ten, time-critical cases simultaneously. That's just overstretched although exceptions can be made for elite, multitasking, savant investigators if and where they exist.
So, we start with non-hypothetical stuff: the current surveillance dragnet that treats a whole country as guilty and watches every communication/association is an utter failure, a waste of money, and imposes chilling effects on democracy. The alternative is the original model of presumption of innocence, trained investigators following leads, prioritizing for most serious, and following through with good policework. Interestingly, the alternative already exists and runs in parallel with the surveillance state. Most convictions come from the alternative method. So, I don't have to justify it so much as point out that one is field-proven, it harms fewer innocents, and its cheaper. Ditching the failed method for that one is a no-brainer.
Unless, it's about money for defense sector and power over dissidents/competition for the nation that wields it. In that case, they'd try to keep the surveillance tech while continuing to lie about its purpose of protecting citizens from stuff it can't catch. Like we're seeing. ;)
What about that? They could have a limit in the tens of thousands or so. As long as they don't waste it on BS, they could follow all the promising cases they want.
The idea is not to let them follow everybody, just for the fun of it.
Make it a sane number, and it's not gonna play that bad at all. The only problem would be them claiming "if I had more allowable targets I would have caught this or that case before it happened" etc. Which we should just ignore.
After all, before they got these modern toys, they used to be content with 1/1000000 the available targeting that they have now.
In the seventies and eighties even, to target somebody involved lots of people actually in the streets, a semi-manual process to record his phonecalls (and you had to go through them with a real person, no keyword triggering etc), no "web" and other records automatically available etc. Checking half or all of the US at once at the scale we do today was not an option, not even 1/100000 that. You could ask for phone records and a couple other items at best.
According to the newspaper Liberation [1], they sent a text message at 9:42pm telling: "we're out we begin".
[1] http://www.liberation.fr/france/2015/11/18/la-piste-du-sms-e...
What "debates"? there is absolutely nothing they can do to enforce terrorists to use backdoored encryption, any debate is just a waste of time, money, and maybe even lives. What are they thinking??
I suppose they could deceive the public and put something in without telling us. That would be a real improvement! Oh wait,...Snowden...
The more I hear about what Diane Feinstein proposes in areas outside her expertise, the more I wish someone would defeat her in an election. She keep proposing stupid stuff that sounds good to uninformed rubes.
I can't believe the CIA is this stupid, it's not possible, they want something else from all this anti-cryptography talking.
http://www.nbcnews.com/nightly-news/video/is-isis-video-abou...
This comment is amazing self parody.
So what, we should we let people cook up nerve gas and anthrax and build surface-to-air missile launchers in their garages, to make sure they have competitive parity with the bad guys?
And yes, people should be able to build "surface to air missile launchers" in their garages. It's called amateur rocketry, and last I checked it was quite a popular (and legal) hobby.
The vast majority of encryption is used in a lawful way to protect important things (information). The vast majority of firearms (in the USA at least) are used in a lawful way to protect, deter, as a hobby/for fun, and for sport/hunting.
They are very similar arguments, for a number of reasons, including the utter stupidity of attempting to make law-abiding citizens jump through even MORE hoops whilst accomplishing absolutely nothing in "preventing the bad guys from making use of" said technologies.
The difference is that regular people do have a need for secure communication channels. Even things other than what you typically think of as "communicating" like bill payments and shopping. Encryption is a defensive tool. It keeps people from stealing all your money.
Trying to ban strong encryption because terrorists use it is not like trying to ban nerve gases because terrorists use them. It's more like trying to ban pickup trucks because terrorists use them.
We restrict people’s use of technology in all sorts of ways to protect the basic order of society. For instance we restrict people from driving 150mph rocket cars or armored tanks with cannons on residential streets, we disallow radio jammers, we carefully regulate access to radioactive material, we don’t let unlicensed doctors implant untested medical devices, and so on.
More generally, gun control is almost entirely irrelevant to encryption. It’s an emotionally charged non sequitur which derails the discussion.
There is a huge difference between https://gmail.com type encryption and true end to end encryption. Pretending there isn't will get us nowhere. The first type is sufficient to keep out ordinary criminals, competitors, even some governments. It is not sufficient to keep out the local government itself, which can still go serve an interception order on the service provider without the target being aware of it.
The upgrade in security between true end to end crypto and user-to-service-provider crypto is essentially, that governments can no longer do that. This is a positive for avoiding 1984 style dystopias, but obviously it's rare or governments to worry about that risk (as they "know" they aren't dystopian ... and don't care to think about the future). When western governments talk about banning encryption, the only type they are really talking about is the type where they can't go to some big corporation and get the data when they want it. And that type is still pretty rare. Actually almost nobody uses it.
If we allow a ban on secure end-to-end encryption, are we setting ourselves up for a future government to go back and demand access to everything we've ever done? Do I want to have somebody in 2060 datamining my entire life? It's worrying to me.
Short of putting better end-to-end encryption everywhere, I'm not sure how we prevent that. As you say, that sort of encryption is pretty uncommon, so maybe this is what we're headed toward either way. I think it's worrying.
But I'm not an expert on cryptography. Are there are other solutions?
Secure communication does not kill other people, it protects yourself. We should allow everyone to have that because by taking it away the only thing we will do is harm law abiding people.
You are saying that you can't tell people not to use something.
EDIT I should have said mass shootings incidents in the UK are extremely rare, but of course not impossible because people can still legally keep shotguns and rifles.
Just ask all the gun control states also attempting to prevent crime and track dissidents via mass surveillance. Their failure rate is through the roof except for the most incompetent or uneducated targets. And even some of them slip through.
Of course there's the issue of steganography ,but i think it's technically and theoretically much harder than encryption - so maybe the balance of power there benefits intelligence agencies more than encryption.
https://theintercept.com/2015/11/18/signs-point-to-unencrypt...
How about that? Hopefully now the blame will be put where it should be: the wastefulness of mass surveillance, which dramatically increases the "noise" compared to the signals, since the agencies have to "look" at many more innocent people and waste time and resources doing so.
> Almost all the attackers were known to the authorities, and if they had been watched, their use of encryption programs would have itself invited closer scrutiny.
This is precisely the scenario that Phil Zimmermann (creator of PGP) and others have been warning about (and working against) for decades. As Zimmermann said in a 1999 essay linked here not long ago, "What if everyone believed that law-abiding citizens should use postcards for their mail?" (https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html) The scary part to me is not just that it's our present reality, but that it's so readily accepted. Crypto advocates need better PR. (And to be fair, better UI.)
You wouldn't even need the brightest engineers. In fact so many encryption algorithms have been opened sourced and / or in library form for so long that it's easy for practically any developer to do.
So, if the thing's to slap some nice GUI upon an existing library that implements the security bits, then almost no knowledge's required. But if one has a library full of primitives but still has to combine them in a meaningful way - it's a damned minefield.
Books most people making "private" apps still haven't read. ;)
The tactic you're suggesting has been tried before (the software was called Asrar, I think). It doesn't work well for them, for a couple of reasons:
1) Custom terrorist software is no easier to use than something more mainstream like PGP, but is a lot more incriminating if you're found to be using it.
2) Is it really made by fellow jihadis? Or is it a backdoored plant by western intelligence? How can you know?
The latter question is a bigger issue than you'd expect. Terrorists don't like to helpfully announce their real names and backgrounds on their websites, so the provenance of jihadi software is frequently unknown. It just sort of floats around on the internet. So it can be much harder to trust than just a plain old copy of PGP.
You might think that IS can solve these problems because it's bigger and more organised than a group like al-Qaeda. But it's not like IS has an official website with a nice SSL certificate and a big download button (CA's will generally not sell to sanctioned entities). They use networks of ad hoc and quickly suspended twitter accounts to communicate, and apparently, Telegram. So for them to distribute custom crypto software wouldn't be easy.
But those are interesting points.
Wow, how do you define that? So, start banning math now?
Why do they think they can put the Genie back in the bottle? The answer is they know that they can't, the backdoor only effects the people who don't care they are being tracked. It's not for terrorists, it's for people who carry smartphones. Which is almost everyone, so good enough for them. But the argument is absolutely nothing to do with "preventing terrorism".
Replace X with basically anything.
I think your grand unifying theory needs more nuance.
(EDIT: Previously said "making something illegal", which I realised was ambiguous.)
Obviously banning encryption is ridiculous, but the "Only criminals will have X" argument is just silly rhetoric.
EDIT: I just noticed the ambiguity you're more likely responding to in my original post. I'll reword it.
When not only the criminals have X, then X is not illegal.They already do that[0].
0. http://arstechnica.com/business/2012/05/steganography-how-al...
Too much surveillance
- General public feels incredibly uncomfortable due to lack of privacy
- An incredibly scary amount of power in the hands of whoever has access to that information ( and who knows what they will do with it )
- Reduced risk of terrorism and security concerns
Too little
- Increased risk of terrorism + massive security concerns due to lack of intelligence ( it's like trying to find a needle in a huge haystack )
- Public feels safe due to perceived increased privacy and yet feels unsafe due to ( potentially ) increased number of terrorist incidents.
It's a rather difficult problem to solve. How can we extract critical security information without invading people's privacy?
http://www.cnn.com/2015/11/16/europe/paris-terror-attack-mas...
I am sure they have at least a few engineers kicking around what amounts to be an entire country. I haven't heard many people harping on about encryption, TBH, except people defending it here and that idotic NYT article.
However, if you had 10 amazing engineers you would likely have strike capabilities orders of magnitude higher than a few suicide bombers. So sure, gather surveillance, but let's play some defense. Shore up our infrastructure much better than we do now, because after they make their own apps and networks, they are going to come for ours potentially.
First sentence is already wrong.
They recovered smartphones that had encrypted messaging apps.
Still no excuse for government backdoors which will be stolen by all kinds of entities within months of their creation and allow the wrong people to spy on law enforcement itself.
Government had a 10 year headstart before all this, where are all the terrorists they stopped before this?
But you are right, it could just be someone overstating something where apps have the ability to be encrypted, not that they were used that way.
Still all these people were already known to their secret services. Some even had phone taps already. It was yet another intelligence failure like we saw on 9/11
Well, unless they were using WhatsApp or iMessage, which almost everyone uses.
It' not like terrorists use Twitter