Nanny State of the Week: New York plans to ban iPhones

tin+foil+hat.jpg
 
“They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety.” ”Those Who Sacrifice Liberty For Security Deserve Neither.”


some old dude said that. and I agree with it.
 
“They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety.” ”Those Who Sacrifice Liberty For Security Deserve Neither.”
This is one of the dumbest things quoted when you intended it for todays political climate and I don't think you really know what Ben was saying here. Research it.
 
This is one of the dumbest things quoted when you intended it for todays political climate and I don't think you really know what Ben was saying here. Research it.

i did. and I don't give a damn what he was trying to say, I agree with the exact quote.

YOU are willing to give up MY liberty for YOUR security.
I am 100% NOT OK with that.
 
Yes, back doors and crippled encryption are bad ideas.

That's exactly why Tim Cook needs to soften his stance so his intractability doesn't insure that we DO end up with something that bad.

Nothing else is exempt from legal search warrant inspection. It could be done in ways that preserve the integrity of encryption. Something like a warrant and a phone being delivered to Apple where a random key is applied to enable a single, non-replicable inspection event.

It's understandable that Apple would not want that responsibility, but by resisting it, Apple risks forcing a legal hand that may put something truly bad (and not just inconvenient to Apple) into place.

Responsibility doesn't lie only with stupid legislators.
 
Yes, back doors and crippled encryption are bad ideas.

That's exactly why Tim Cook needs to soften his stance so his intractability doesn't insure that we DO end up with something that bad.

Nothing else is exempt from legal search warrant inspection. It could be done in ways that preserve the integrity of encryption. Something like a warrant and a phone being delivered to Apple where a random key is applied to enable a single, non-replicable inspection event.

It's understandable that Apple would not want that responsibility, but by resisting it, Apple risks forcing a legal hand that may put something truly bad (and not just inconvenient to Apple) into place.

Responsibility doesn't lie only with stupid legislators.

It is all or none here. Encryption does not work like the way you stated. Either there is a backdoor (aka key to unlock phone by OEM) or there is not (aka key is with the USER, not Apple/Google). IF the key is with OEM (Apple/Google), then that key can be hacked by 3rd party.

Again, someone who hacks Google or Apple or Microsoft (been done before) will have access to EVERYTHING. I am not so concern about NSA, but there are plenty of super smart hackers out there!

Again, if you think Google or Apple is un-hackable, then please see my China example above. Look at Home Depot hack. Target hack. Sony hack. How many times has YAHOO emails been hacked?!

There is no such thing as allowing just NSA to use the key.

On a side note, remember the story where Google employees were laughing at email attachments of some of their users? Remember the story where Microsoft used Hotmail to spy on a media member SUSPECTED of leaking Window 10 details?

Did ANY of these hacks or invasion of privacy had court search warrants???????
 
Last edited:
i did. and I don't give a damn what he was trying to say, I agree with the exact quote.

YOU are willing to give up MY liberty for YOUR security.
I am 100% NOT OK with that.
Well whether you like it or not, we all live in a society where our actions and perceived liberties can and routinely do, effect those around us. When your decisions threaten my security I'm sure you'll understand that I'm not going to sit idly by and let that continue.
 
Well whether you like it or not, we all live in a society where our actions and perceived liberties can and routinely do, effect those around us. When your decisions threaten my security I'm sure you'll understand that I'm not going to sit idly by and let that continue.

So, you are in support of having the encryption key be with the manufacturer of software/hardware?? This way, IF the government comes knocking, then the manufacturer can unlock the phone.

Again, you are AGAINST end-to-end encryption where the encryption key is in the USER'S hands, not with the OEMs.

I just want to make sure that i see your stand on the issue.
 
Well whether you like it or not, we all live in a society where our actions and perceived liberties can and routinely do, effect those around us. When your decisions threaten my security I'm sure you'll understand that I'm not going to sit idly by and let that continue.

sadly, an un-American stance.
 
So, you are in support of having the encryption key be with the manufacturer of software/hardware?? This way, IF the government comes knocking, then the manufacturer can unlock the phone.

Again, you are AGAINST end-to-end encryption where the encryption key is in the USER'S hands, not with the OEMs.

I just want to make sure that i see your stand on the issue.
I'm fine with security agencies being granted limited access for reasons of high importance.
I support e2ee for regular circumstances.
 
I'm fine with security agencies being granted limited access for reasons of high importance.
I support e2ee for regular circumstances.

I am not sure you understand end-to-end encryption. See my post to JB below.

It is all or none here. Encryption does not work like the way you stated. Either there is a backdoor (aka key to unlock phone by OEM) or there is not (aka key is with the USER, not Apple/Google). IF the key is with OEM (Apple/Google), then that key can be hacked by 3rd party.

Again, someone who hacks Google or Apple or Microsoft (been done before) will have access to EVERYTHING. I am not so concern about NSA, but there are plenty of super smart hackers out there!

Again, if you think Google or Apple is un-hackable, then please see my China example above. Look at Home Depot hack. Target hack. Sony hack. How many times has YAHOO emails been hacked?!

There is no such thing as allowing just NSA to use the key.

On a side note, remember the story where Google employees were laughing at email attachments of some of their users? Remember the story where Microsoft used Hotmail to spy on a media member SUSPECTED of leaking Window 10 details?

Did ANY of these hacks or invasion of privacy had court search warrants???????

Either the encryption key is with manufacturer or with user. There is no in-between.

So, which position do YOU support?
 
If the government does something illegal and prevents a major act of terrorism as a result, then that's fine with me.

Lol, taking or supporting action against threats to ones security (self defence) is about as American as it gets.
Are you into the 'sovereign citizen' movement by any chance?

what you are talking about is the exact opposite of SELF defense.
 
@Thai
My understanding is that end to end encryption where users/endpoints only have the decipher keys, is that they are still somewhat vulnerable to security breaches if the endpoint has been compromised. I think it's called man in the middle attack. Regardless, I would say it is way more secure than a third party or oem holding the keys and that's why I say I support it.
 
@Thai
My understanding is that end to end encryption where users/endpoints only have the decipher keys, is that they are still somewhat vulnerable to security breaches if the endpoint has been compromised. I think it's called man in the middle attack. Regardless, I would say it is way more secure than a third party or oem holding the keys and that's why I say I support it.

By definition, if only the endpoints have the encryption keys then the only way in is through one endpoint (the writer) or the other (the reader). No way for a "man-in-the-middle" to get in unless the maker of the device leaves a backdoor, which is a terrible idea. I would rather society accept some risk associated with living in a modern world, than risk giving up their freedom.
YMMV
 
@Thai
My understanding is that end to end encryption where users/endpoints only have the decipher keys, is that they are still somewhat vulnerable to security breaches if the endpoint has been compromised. I think it's called man in the middle attack. Regardless, I would say it is way more secure than a third party or oem holding the keys and that's why I say I support it.

Link: Apple Explains Exactly How Secure iMessage Really Is | TechCrunch

Using public-key cryptography, activating iMessage generates an RSA 1280-bit keypair for encryption. The public key is shared to the Apple directory service (IDS), but the private key is held on the device.

Unless the attacker can get the device private key, the message is indecipherable if intercepted in transit.

I guess that Apple can change the whole infrastructure regarding the public key exhange to read on-going conversation (very unlikely), but it won't be able to read old texts (unless you opt for texts to be stored on iCloud servers).

Here is more on what Apple does: http://www.apple.com/business/docs/iOS_Security_Guide.pdf

In other words, it is very secure. Man-in-the-middle attack/intercepting is unlikely unless Apple itself fully participates in it. And even then, that would require a court order for sure and so far Apple has been protected by law against helping the government.
 
Man in the middle attack involves the hacker providing his public key to one or both endpoints, that's how he gets in. Key management can be hard, regardless of where they are.
The other hacking way is to have gained access to the device/computer prior to the message being encrypted.

It's pretty interesting stuff.
 

Members online

No members online now.

Forum statistics

Threads
278,315
Messages
3,554,131
Members
248,016
Latest member
Advally Service

Trending content

Back
Top