Why the fear over ubiquitous data encryption is overblown
washingtonpost.com
washingtonpost.com
That's it in a nutshell. The tools are out there. You can't put the genie back in the bottle.
* You can still catch some criminals too dumb/lazy/small-time/poor to use better encryption.
* You can find evidence on people who didn't use better encryption because they didn't realize they were breaking the law.
* You can use hints/metadata found in unsecure channels (that you forced to be unsecure.)
* You can identify encrypted devices/communications as suspect (even more so than today) and investigate them especially.
* You can prosecute people just for using encryption and sleep fine at night because it means "they have something to hide", and are probably breaking the law in some other way.
[1] - https://np.reddit.com/r/IAmA/comments/2wwdep/we_are_edward_s...
Such as?
Keep in mind that eliminating low level crime is often very low priority for law enforcement: they only do this under pressure or when expecting some bonus for it. There's a lot of crime that they could fight but virtually don't. Also, most endemic low-level crime is best fought with policies and eliminating poverty, not by pinning petty criminals after the damage is already done.
Such as?
It would be trivial to use GPS data from cell phones to issue automatic fines for speeding. Profitable too - such a project could certainly pay for itself.I mean, you implicitly acknowledged that speeding happens all the time. Yet we don't have a huge death rate from it. It's not a safety problem except in fairly rare situations, it seems to me. It's an administrative problem.
I'd go so far as to say that speed limits themselves are the problem. They're set too low to allow easy money from fines.
People are irresponsible. Many drivers in particular think they're above-average and smarter than the people who designed the traffic signs. Treating speed limits as "just a suggestion" makes it more difficult for people with actual understanding of traffic patterns to design them to ensure optimal flow of cars. Most of the drivers I personally know are textbook cases of https://xkcd.com/277/ (though I do know a few responsible ones, and I respect them deeply for that).
How would that work? Compare the times between shots a large distance apart, like on toll roads?
Goldmine for the government though, just about anybody that drives there the first time thinks they must be the only ones who don't realize that 100 Km/h is a bit slow for a road like that.
http://auto.blog.nl/column/2012/11/16/trajectcontrole-a2-gou...
13 million Euros in the first couple of months. For sure common sense had nothing to do with this.
The situation would be different if, for instance, those limits would be obscured or appeared suddenly, and you'd have police forces enforcing them there on purpose. I've heard of cases like that.
Did anyone actually ask the people who put the limits about their reasoning though? Maybe this is the value that came out of simulations. Maybe it's a part of an environmental strategy (going 120 km/h uses much more fuel than 100 km/h and thus leads to greater emissions). But maybe the simulations were wrong. I'm sure that there are proper channels one could use to dispute the limits. But just disregarding them because they 'look wrong' is pure hubris.
That they change them frequently doesn't help either.
Speeding is most often victimless crime so it's not obvious why it is absolute good for me, the citizen.
Hell if I where inclined I could feed the GPS unit false data showing I was doing 30 in a 30 to deliver food to a nursing home.
None of this stuff is workable or desirable.
What about using your phone as a key? To turn on your car you have to put your phone into a deactivated mode (like a drive dashboard) that has significantly decreased functionality. I'd bet parents would be rather interested in this (and perhaps car companies).
>Speeding is most often victimless crime so it's not obvious why it is absolute good for me...
Not always. The stopping distance from 35 mph to 40 mph is a good bit. I haven't found any numbers on 35 mph, but it seems that 30 mph has a stopping distance of ~75 ft, while 40 mph is ~120 ft. If you're going 5 over in a 35 mph zone (which is normally a city) there is an increase in brake time that could potentially put someone at risk of being hit. Is it victimless if you put someone elses well being at risk by being hit by you? Because you wanted to get somewhere slightly faster?
Edit: readability
It is much easier to mandate a way to run code on modern systems, in the "SMM" style, upon seeing a cryptographic signature which the NSA holds the key across the memory bus. About 20 people in each of Intel, AMD, nVidia, Qualcomm, Apple need to know about it (well paid and NSLd to shut up; perhaps even NSA employees embedded in these companies and the companies themselves none the wiser), about 3000 transistors which would be lost in today's many-billion transistor CPUs. It doesn't have to be fast, and not even perfectly reliable - it just needs to work.
In fact, I'll be astonished if in the future it turns out that such a thing is not already implemented today. Do you really thing the NSA doesn't yet have a copy of Intel's microcode signing keys?
What makes them think they're entitled to my digital communications and data?
However I still then don't think they should have the key anyway.
Alternate but less interesting considerations: Jeff had nothing to do with the article or Jeff prefers the government stays out of his business.
In addition, the authors of this piece are not folks who Bezos could push around even if he wanted to. The only way they would write this piece is because they wanted to.
Politically, this piece is a big deal. These are "national security establishment" type folks, directly disagreeing with their successors in government today.
I disagree with your "undoubtedly". I think there's a fair to middling chance Bezos did some meddling in the editorial process - made a few phone calls, dropped some hints, bent the ears of an editor or two. Newspapers always protest that financial interests don't interfere with their reporting, but time and again, we find out otherwise.
But wow what a disturbingly weak "The Post's View" editorial it has in the related links:
https://www.washingtonpost.com/opinions/compromise-needed-on...
It argues that people concerned about privacy "can rest assured" because keys will be protected by due process. Where to even begin, right?
This editorial (talking about my link, not the OP link) has undermined my respect for the Washington Post. Is this really still their view?