Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"If you outlaw encryption, only outlaws will have encryption."


Since this is usually said about guns, it reminds me of https://xkcd.com/504/


The supreme court's definition of "arms" is not something that can be changed by passing a law. Just like you couldn't hack the second amendment by defining arms to be muskets.


I don't understand what you're saying. Did you miss the entire reference that XKCD strip was about? You do know that we had to fight to remove encryption as being classified as a weapon and instead protected as free speech, right?

https://en.wikipedia.org/wiki/Bernstein_v._United_States


We shouldn't have had to argue that. If it's either speech or an arm (and it's both), it's inalienable.


Only works in the US of A.


And if they mandate escrow keys for communication, who's to say they won't push for the same thing for package signing keys? I'm sure the three letter agencies would love to be able to ship compromised binaries to their targets' computers.


They might actually do stuff like that, but that's just smoke and mirrors.

It is much easier to mandate a way to run code on modern systems, in the "SMM" style, upon seeing a cryptographic signature which the NSA holds the key across the memory bus. About 20 people in each of Intel, AMD, nVidia, Qualcomm, Apple need to know about it (well paid and NSLd to shut up; perhaps even NSA employees embedded in these companies and the companies themselves none the wiser), about 3000 transistors which would be lost in today's many-billion transistor CPUs. It doesn't have to be fast, and not even perfectly reliable - it just needs to work.

In fact, I'll be astonished if in the future it turns out that such a thing is not already implemented today. Do you really thing the NSA doesn't yet have a copy of Intel's microcode signing keys?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: