I think "why do you have the right to know?" is a decent answer.
"What level of trust do you think you've earned?"
"What do you want to do with all this information?"
"How will this make things better?'
"Don't you have more important things to spend time and money on?"
"Is this really the best thing the government should be working on right now?"
"How does this help any of society's ills?"
"Will taxes need to be increased to manage, store, and analyse the mountains of information that will be created?"
"How long will you store messages between me and my daughter about her contemplating suicide, and will those messages prevent her from getting a government job later in life?"
"Does the storing of all this data come with a responsibility to make it accessible to defend people who have been accused of a crime?"
"My wife works in law enforcement, will she have access to this trove of data?"
"Will there be a process to remove data from this trove that may be libelous or cause undue harm to an individual or company?"
"Is the government responsible for the complete chain of access to this data, or are there private companies involved that have to be trusted not to sneak a peek?"
"What specific issue, currently facing today's society, does this solve?"
I also think a decent strategy is to start asking for all sorts of specific private information, like their social security number, bank account numbers, and passwords. Ask them to make a copy of their keys so you can enter their house any time you want and watch what they're doing, go through their things, etc. Tell them that you want to put up cameras in their bedroom and bathroom that stream to the internet 24/7.
Keep escalating until they balk. Once that happens: "oh, so you do value your privacy?"
If they actually do share this sort of info with you, give you copies of their keys, and let you put up cameras in their house, it's probably safe to say that they are part of a vanishingly small minority, and you really don't need to care about their views on privacy. (Hopefully this assertion ages well years from now.)
If you are asking what a reasonable person of the public thinks about digital privacy, that ship has already sailed. We have people installing and handing out their data to third parties in the form of:
* Cameras on their front doors (Ring doorbells, etc.)
* Mics all around their house (Alexa's and other digital assistants)
* 3D accurate maps out the entirety of your house's floor plan (Roomba's etc.)
* Digital door locks managed in the cloud
* Real-time position tracking (airtags, Google Maps app & equivalents, etc.)
We already have concrete evidence of some of the above being used / abused against the interest of the owner.
Until you can make a compelling case about why this is bad, I would wager that the default stance of the public is that no privacy is required.
Right, but that apparently isn't happening to enough people, so these different means to erode our reasonable expectation of privacy will continue to grow. As they do governments can hold up Ring cameras for example and say, "look, everybody has one of these on their front porch and they're filming their neighbors. If you let a private company do that then there's nothing legally keeping us from doing the same."
It's pretty blatant in my neighborhood already. Whenever something criminal happens and cops come around one of the first things they ask is if I have a Ring doorbell they could take a peek at.
"IT PROTECTS THE CHILDREN!" they'll scream, while using it to take more power away from society and concentrate it into their own hands.
Surveillance isn't some harmless thing, because you can tell a million lies with a drop of the truth in them for any reason you want.
Imagine you get established in life and decide to run for local politics only to have the fact that you've gone to Vegas 4 times in your life somehow turned into a completely untrue "drug use and prostitution" scandal that destroys your credibility and political career before it even started.
Imagine having your grandkids' college scholarships revoked because you ran an incredibly unprofitable and short lived onlyfans for 3 months in your late teens.
Maybe the results won't be as overt as this. Maybe it will be worse.
Either way, it is invasive and gives complete strangers power over your future and your children's future that they simply should not have and have no reason to ever have.
It's morally repugnant and abhorrent to any person who takes the time to think not of what information will be collected but of what that information will be used for and by whom.
The children of the people who as of today are still talking about how great trump is and how he "brought peace to the middle east" and how "evil demoncrats are running a global cabal to turn humans into monkeys" are the people who at best will be the parents and friends and neighbors of the people who will have finely grained and exacting data of everything you have done from well before the day of the passing of a bill like this.
This bill would make America the equivalent of living in an overly nosy HOA city everywhere for everyone. The people who fit in and don't make waves will get the 1950's nuclear family treatment, and those that don't will get the April 26, 1986 Pripyat nuclear treatment.
> "IT PROTECTS THE CHILDREN!" they'll scream, while using it to take more power away from society and concentrate it into their own hands.
I don't think you're wrong in predicting this, and I actually think you're proven correct by precedent already. The answer to this is many and varied, but one core concept that should always be kept in mind is, much like "with great power comes great responsibility":
With great claims comes great burden of proof
What statistics are you trying to improve, and have you got a baseline you can share with us that can be used in 1 year, 2 years, 5 years to prove the effectiveness of this legislation in "protecting the children"? What's your time frame after which, if no measurable improvement to these statistics has been made, then the legislation will be declared a failure and repealed?
(This is, of course living in some kind of utopian thought experiment, and society just doesn't have the memory to allow such holding the decisions of the powerful to account, but it was therapeutic to write, and it's a worthy goal for long term pursuit).
There is no good answer to this. I suggest not wasting your time trying to argue in good faith with irrational or straight up malicious actors. Better invest in ways to protect yourself, your assets and your anonymity through technology.
I know what you're saying is inescapably true, but I feel the need to point out that the fact that is has gotten to the point that it is inescapably true fucking sucks and there is a lot of work that needs to be done to undo it.
True change lies in policy and legislation, not in technical defence. The ability to change policy and legislation is a sign that 'power' is coming back into balance between the people and the government - and if we can't do that, then the power balance needs restorative work.
Technical defence should always exist, but rarely be necessary, especially against the government of one's own country.
(If one can argue in good faith in public, visibly, the bad faith of the opposition matters less than the ability to make aware as many of the public as possible. Bad faith, irrational, or malicious actors should be able to be backed into a corner with their own arguments)
Ah yes, “protecting the children”. Meanwhile, some of the most paranoid IT data security I’ve seen was at a department of education.
You see, just statistically speaking, they have pedophiles on staff, staff with potential data access. They have ex husbands that want to abduct their kid after the messy divorce where the wife had to get a new identity, but good luck fleeing from your husband who has DB access at the DoE.
The real world is messy and filled with bad actors in positions of power and access to data that enables their abuse.
The less data there is, the less they can abuse it.
Almost like… guns. The less guns are out there… oh. Oh…
You guys in the States are screwed. I’m sorry for you all.
"how do you ensure trust in the providence of the information being stored? - with no direct link to physical proof of an individual typing that message or URL or uploading / downloading that picture at that time, or even necessarily that the individuals device was used to perform the action, what value is there in the data?"
The argument above could really only be used if a case came to court and evidence providence needed to be questioned.
This argument is a poor one in the face of politics or lawyers because the ambiguity is such that it becomes a case of "who do you believe is telling the truth" because a jury is a group of humans, and our nature appears to be to err on the side of guilt over innocence. Hence accusation=at least guilty of "something". It therefore works in favour of the power status quo.
When you step back and look objectively and in an unbiased manner, you see that we (humans) are a species of dominance rather than collaborative partnership. It is a world where individuals must earn the privilege of survival, and by earn I don't mean only in a monetary sense but also a gatekeeper sense. Life is not of precious value; power and control are. This, and the commodification of labour, land, and money are bringing about the disintegration of capitalism with nothing on the horizon to replace it other than anarchy. Welcome to the interregnum.
I really disagree with this. We are not a species of dominance over partnership. We are a species that requires partnership to function, with mostly socially constructed competition for position within our greater society. But fundamentally we need each other equally. We live for two generations so that we can also raise the grandchildren with the parents. We have language to communicate and plan together. Many of us develop empathy and compassion fairly early on, making friends that don’t benefit us except for the delight of a peer. This is our basal nature. I would argue that systems of exploitation are the more unnatural state- racism must be taught from an early age, for example.
Many seem to not realize that privacy is not about having something to hide (I guess that would be secrecy), but about the right to keep things to yourself. Those are two different concepts.
"Privacy is necessary for an open society in the electronic age. Privacy is not secrecy. A private matter is something one doesn't want the whole world to know, but a secret matter is something one doesn't want anybody to know. Privacy is the power to selectively reveal oneself to the world."
--
excerpt from A Cypherpunk's Manifesto,
Eric Hughes,
March 9, 1993
It's funny (not haha-funny) how political policy in 2023 is still trying to catch up to morality understood 30 years ago. I remember being annoyed at newscasters abusing the term "hackers" in the late 90s and extremely broad definitions of "hacking" being applied in court-rulings. It must still be really difficult to comprehend tech and the consequences of these kinds of policies for policy makers. Either that or policy makers really are maleficent towards life, liberty and the pursuit of happiness.
Oh, politics understands that alright, don't you worry about that. Politicians are the enemies of privacy for the masses, because a transparent population is a population that is easier controlled and manipulated.
That's also why terms are being used deliberately incorrectly, to move legitimate positions nearer to criminal activity. Just ask anyone interested in hobbyist chemistry.
The term "illegal aliens" is an invention. "Immigrant" doesn't care about legality; it is literally just someone who has moved from another locale. Labeling one variant "legal" and another "illegal" is perfectly reasonable.
I think it was 1986, as in the Immigration Reform and Control Act of 1986. [1]
> That way build sympathy for the law-breakers, then legitimize them via immigration reforms that only benefit the illegals
it was noted "The legalization provisions in this act will go far to improve the lives of a class of individuals who now must hide in the shadows, without access to many of the benefits of a free and open society. Very soon many of these men and women will be able to step into the sunlight and, ultimately, if they choose, they may become Americans"
I don't really care if somebody entered the country legally or not. Eventually, everybody assimilates. However, I am not ok extending benefits paid for by taxes to non-citizens. As long as there are politicians trying to give tax paid benefits to "illegal" immigrants I will be against illegal immigration.
I agree, but I don't think that's a good example. The only reason for the existence of a bank password is to enable private interactions between yourself and the bank (and the government through their financial surveillance).
In practice your bank password is indeed a secret, and that's a bad thing, because that above definition is wrong, which is why I prefer to think about the U2 lyric (from "The Fly"):
"They say a Secret is something you tell one other person, so I'm telling you, child".
The bank knows your password. Which means they (or more precisely their agents, employees, etc.) can lose it yet they'll probably try to blame you.
It is possible to not have this happen via what's called an Augmented PAKE - the bank wouldn't know your password, but they'd be able to check you still remembered it - however almost certainly none of the systems you use today do this.
>The bank knows your password. Which means they (or more precisely their agents, employees, etc.) can lose it yet they'll probably try to blame you.
Normally banks can't and shouldn't know the password in most jurisdictions. It does pass to their server, but they're supposed to only store a hash of it, so not be able to know what it is.
But if anybody makes this BS argument, just ask them for the credit card number and the 3 digits on the back of the card, telling them you will post it online.
Don't they usually store a hash of it? And doesn't it therefore for the most part work exactly the way you say it ideally should?
Of course leaking the hash of my password might make it easier to crack, to some extent, but if they've done a good job then this is much better than it being something the bank can trivially lose.
> Don't they usually store a hash of it? And doesn't it therefore for the most part work exactly the way you say it ideally should?
Putting aside the banks who literally do store the password because they have security procedures like "Please enter the first and fifth characters of your password" even those that do store a password hash still need you to submit your password to authenticate.
So, like the lyric says, you tell the bank your password. You hope they just use it to authenticate you and immediately discard it, but if bank security lapses are anything to go by they're probably logging it "for security" and there are definitely employees able to snoop the decrypted plaintext passwords from customers on some internal teams.
That is what Augmented PAKEs fix, it's really hard to do well, and of course banks see themselves as infinitely trustworthy so why would they bother.
This mistaken sense of self-worth applies to your credit card PIN by the way also, of course banks and thus bank employees can know your PIN, which means when a purchase is "secured" by the PIN that rules out some local pickpocket having made the purchase, but as well as you it leaves open the possibility that it was a bank employee or their co-conspirator.
This is completely false. You validate any password requirements before salting and hashing the password and then store the salt and hash. Even if you restrict usage of previous passwords, you are just comparing hashes.
If the bank is indeed salting and hashing the password, then what's the rationale of allowing certain special characters like '!', but not '+'? Hashing and salting should be character agnostic.
Some special characters are not processed as one might expect, particularly by implementations of languages such as COBOL, which is still used on the server side by many banks, insurance companies and government agencies where consistency is paramount.
"#" can mean phone number
"+" or "&" can mean concatenate variables
It is vastly easier to screen out possible problems at the user/browser level than rewrite zillions of lines of legacy code.
Except you are giving them the password and trusting them to discard it after validating it. If it's purely client side, then the bank is trusting you to follow the password requirements which is also out of the question.
Whether hashing is happening client side does tell you a little, though in most cases most users are still trusting the client side software to not exfiltrate the password before hashing it.
Even with Client side hashing, the software can still validate password requirements on the client side, you may be able to bypass those requirements by modifying the client side software.
So still no, having password requirements tells you nothing about whether the password is being stored in the clear or not. The statement that I disagreed with is still completely false.
There’s a reason we don’t mandate government cameras inside our homes. No one wants that. But in a world where everyone needs a computer, we shouldn’t take advantage of that obligation by turning our computers into surveillance devices.
The best analogy for this I've seen is this: it's no secret that everybody poops. But that doesn't mean everyone likes having other people watch while they do it (privacy).
Assuming they're adults, offer to set up a camera feed in their bathroom and stream it. They don't mind, and you'd do the work, so it'd be no problem for them and a very specific type of audience would love it. They could likely even earn a bit of money doing it so it's win/win!
Maybe some people even think they believe it when they say it, but I've yet to see anyone who is willing to demonstrate it when pressed, and I've even met a few people who have claimed that they have no concerns at all about their privacy, but who then ended up feeling violated when even small things they assumed were private ended up being exposed.
Well I'd say they're full of shit, haha. Most people have something they care about; them refuting a specific case doesn't refute the general concept. They're either arguing in bad faith or are not very good at thinking logically.
If they truly have no ethical or moral boundaries, then they are probably deviant enough that they won't be able to get into a position to set much policy, anyways, by definition of their lack of fitness to represent the majority of any population.
You go ahead and zen out and, in turn, take those things with grace by going along with it when someone raises a fuss ("oh, I am soooo humiliated! :)"). Or if you're of another archetype, you'll find witty ways to playfully snap back and turn it around on people trying to clown on you (alas, I'm not of this type/talent). Moreover, there are the countless, other not-uncommon approaches that often lead to escalation/hostility/violence.
Then it becomes a drag (and where the issue lies) when it really catches on in wildfire manner, to where it will have practically problematic effects on you personally or professionally, not unlike the lie that makes it halfway 'round the world before the truth can put its pants on.
As far as I see it, all of that is what is trying to be highlighted with the pooping witness analogy. Of course, that should probably be underscored when presenting it.
You'll probably still get a "yeah, that's fine" or "I don't care what anyone else thinks" after you elaborate. And tons of other cans of worms can reasonably be opened as topical offshoots; I'm just trying to concur that the "I don't mind" response doesn't really feel like a response.
At that point you can either call them a pervert and weirdo, or you can ask to film then while they poop and upload it to YouTube with their name attached.
I like this. I added my own parts to clarify and solidify my stance. "Unless I have created a harm, I have a right to choose what to share and who to share it with. I have no interest in the "suspected guilty until proven innocent" mantra.""
Reminder that the same applies to use of crypto. Just because it's use for some illegal activity (it's actually less % than fiat), doesn't mean it should be made illegal as I've seen some comments here advocating for in the past.
If you mean cryptocurrency, then that's wrong, because its primary purpose is to facilitate illegal activity, or grifting. It isn't even good as money, and I still can't buy groceries with Bitcoin, which is like... one of the things money needs to do (buy food).
Also, the statement is itself wrong already at face value in many situations, for example if someone has a credit card or runs an online shop and is contractually required to hide something. For instance, quoting from https://usa.visa.com/legal/checkout/terms-of-service.html:
"You are responsible for protecting the confidentiality of your username and password(s), if any. In addition, if you choose to be remembered on your device or browser, or link your use of the Visa Solution with a digital wallet, on one or more device(s), you are responsible for protecting the safety of and access to such device(s). It is important that you do so since we are not responsible for any losses you incur as a result of unauthorized use of your Eligible Card and, depending on the circumstances, your Issuer may hold you responsible for unauthorized use of your Eligible Card account."
Another example for mandatory secrecy are confidentiality requirements imposed by professional obligations, such as for lawyers and physicians, in order to ensure fair trials, and for the protection of human dignity.
For a society to work properly, yes. If we have zero rules around what a government can or cannot do, can or cannot have access to, and so on we will have created a moral hazard that will be grossly abused.
I’ve found that reminding folks who use the “you have nothing to hide" argument often quickly change their mind if you just remind them the political party they don’t like could use it against them
This worked surprisingly well and without fail for the conservative side of my family. The instant I reminded them who was president at the time (Obama) all of them changed their mind
I don’t love this strategy. It leans into fear mongering a bit much, but if none of the other very helpful rhetorical techniques folks have shared here don’t work. This one has some staying power.
The balance between privacy and the authority is just that. We outsourced the rule of law to the state in order to have a fair and just society. Ipso facto the government should be fair and just to have the right to invade some amount of privacy in order to keep a society free, fair and just.
That’s why the judicial branch exist: to see if what the government (or anyone) did was playing by the rules.
Which brings us back to politics being a danger to a society if people vote in unjust or unfair people.
To my mind, another problem is the one-sidedness of this effort. Why is someone privileged to scan my data but I can’t write a scanner and parse theirs? There seems to be a fundamental injustice here.
Completely ignoring privacy as a concept for a moment, a fair trade should be like for like, value for value.
Imho, sponsors of this bill want to collect dossiers and use them to blackmail opponents in the future. For example, you want to do something unpopular and a noisy council member opposes your plan. You reach to the "official and confidential" box, find there a personal file on that politician, conveniently created by the AI-scanner, share your discoveries with him and suddenly he changes his mind.
> Imho, sponsors of this bill want to collect dossiers and use them to blackmail opponents in the future.
I wonder how it is that the NSA hasn't already enabled that. One of my early concerns with government spying is that we'd up with some kind of NeoMcCarthyism on crack where someone in power would be able to discredit any inconvenient person or even identify and eliminate the career of a potential opponent before they grew to become a real threat. It's astonishing to me that with the wealth of data being collected already it hasn't happened. We've certainly had some very petty and morally bankrupt people in high positions who I'm sure would not have hesitated to abuse that information.
The risk is certainly real, and laws like EARN IT would only make it easier. Even today it seems like it'd be trivial for someone in power to plant a forbidden sequence of zeros and ones on somebodies mobile device at anytime and ruin them.
> I wonder how it is that the NSA hasn't already enabled that
On paper, at least, the NSA technically isn't allowed to act on US soil or against US persons. The FBI would be the most likely vector for such a political police action, imho.
> I wonder how it is that the NSA hasn't already enabled that.
It seems pretty weird to assume it's not already done and in use by select people or groups in the NSA already. They literally have the ability, they're smart enough to pick their targets carefully, and there's plenty of evidence of their oversight being useless.
You're right that it's possible. We haven't seen full on witch hunts, with people hauled before congress and cameras to have their dirtiest laundry aired while the world watches. We haven't seen presidents able to wield that power unrestrained either (despite the NSA being under the DoD and ostensibly answerable to the commander-in-chief). Still, it's possible that there's a much more quiet sort of manipulation going on behind the scenes from folks within the NSA itself.
Obama campaigned on the promise to end domestic surveillance, and while politicians lie all the time to get elected, listening to him speak back then I believed him. He was a strong orator and was saying what I wanted to hear which admittedly makes my judgement there a bit suspect, but he also had a long history of speaking out against things like the patriot act, the illegal wiretapping of Americans, and national security letters.
Once he got into office however, instead of reining in the NSA he greatly expanded the NSA's ability to spy on the American public and he started defending them in speeches. I've often wondered if he was shown something highly classified that convinced him that violating every American's rights was genuinely needed, or if he was just threatened into compliance by showing him what information they'd collected on him and his family.
In relinquishing our right to violence, we demand both influence over its use and transparent practices. Injustice arises when this exchange fails to be equitable, particularly when the government monopolizes violence without being held accountable to its citizens or offering anything of value in return.
Of course, numerous ethical concerns surround the monopolization of violence, but for I want to focus on on the negotiation of rights for societal benefits.
Similarly, we often surrender our privacy with the promise of protection from criminal threats. However, this bargain becomes unjust and imbalanced when we look at it critically. The map is not the territory as the saying goes, and what are sold as effective measures against crime (on "the map") don't seem like they would be in reality ("the territory"). We risk relinquishing our privacy for nothing of value in return.
_should_ is the main problem I have with this argument. A Monopoly on violence is _never_ fine because there is never a time where we can trust a person or an organization to be completely transparent.
Bruce Schneier put it quite succinctly in his article The Eternal Value of Privacy (from 2006):
Some clever answers: “If I'm not doing anything wrong, then you have no cause to watch me.” “Because the government gets to define what's wrong, and they keep changing the definition.” “Because you might do something wrong with my information.” My problem with quips like these – as right as they are – is that they accept the premise that privacy is about hiding a wrong. It's not. Privacy is an inherent human right, and a requirement for maintaining the human condition with dignity and respect.
Anyone who uses that argument, ask them to hand you their phone, unlocked, and a list of passwords for all of their accounts. If you have nothing to hide, why would you have a problem with me poking around in the most intimate aspects of your life?
This doesn't really convince them. To them, a friend might be someone they want to hide things from, but they won’t care about some unknown government entity having access.
This comes from not knowing what organizations are likely to do with it.
Would they be okay with the data being used to overcharge them whenever they're in a hurry because the organization knows when they don't have time to comparison shop?
How about maximizing their tax burden by using the data to calculate the highest tax rates each area would tolerate before moving or changing their vote?
Suppose the government falls under the control of the party they don't like. Should they have access to the data that allows them to most effectively target their propaganda?
And it doesn't even have to be an organization. How often do you hear of cops or civil employees poking around in records they have no business to poke around in?
But I find the sort of people who believe in "nothing to hide" tend to believe in the efficacy of bureaucratic systems set up to prevent that sort of thing. A belief (ironically) bolstered by the privacy those organizations secure for themselves, so that those kinds of individual abuses are rarely discovered. Who watches the watchers?
Whereas it's easy to understand that if you don't have a high opinion of the opposing party's most recent President, you might very well not want their administration knowing everything about everyone.
The two arguments aren't mutually exclusive. The shock value of 'let me see your phone then' can lead into the greater discussion that AnthonyMouse is presenting. The emotional hook can often be just as useful as the logical argument, especially when dealing with someone who didn't really reason themselves into a given position in the first place.
Unfortunately, it's an issue that's hard for many to understand until it directly affects them. Sometimes you need to find something relatively innocuous but still embarrassing and 'give them a thwap' with it, but even then the chances of them understanding are still low.
I think this is a straw man. I don't think any politician would ever suggest such a thing at face value unless couched in some other argument. For example, after 9/11 a politician would have said, "I respect your need for privacy, but we live in extraordinary times, and we need to temporarily lift the restrictions on our agencies to effectively combat an imminent threat."
The real argument being made isn't that we should give all our secrets to the government, but that we should trust that the government will comply with our 4th Amendment protections and avoid gathering this data without a valid warrant issued by an impartial judge. If you're reading this, I'm guessing that like me, you don't believe a word of that. But that's the argument that's being made, and that's what needs to be debunked loudly and publicly.
> If this is really their argument they've already lost.
This would only be true if government were in fact answerable to people. It isn't, and hasn't been for a long time, if it ever was. Legislators decide what they want to vote for, and then decide how to brush off people who tell them anything they don't want to hear.
Lost in which arena? Do you trust politicians to not expand the scope of governance? If they are called out, they can simply rebrand their efforts under a new bill until 3 letter agencies get all the goodies they desire. How much patience does a low information public have? Is it as much as the political and security state classes?
Nothing to hide is a premise based on most people being terrified of confrontation. It's an intentional staging to force confrontation or capitulation.
When people say they have nothing to hide, in most cases what they're actually saying is that they're afraid of the confrontation implicit in the opposite response (I'm going to forcefully argue for a right to privacy). They're telling you that they're a coward.
The more I think about this, the more it rings true. Implicit in the phrase "I have nothing to hide" is an assumption that everything is open to inspection by default, and concealment is deviance. In most situations, nobody assumes anything close to that. When they do, they're taking a supine position, like an animal submissively exposing its belly.
Well, clothes are mostly down to weather and laws on public decency, and nudists are the counterpoint that prove some demographics would prefer to be naked if the law allowed it, same with tribes like Koma.
Locks are more for security than privacy, and it's important not to conflate the two. People can have nothing to hide, but also not want to be robbed.
And as for email, that's again a matter of security because then someone could impersonate you for one, and I can't name a service that allows you to omit having a password for your email account.
In an information environment, security and privacy are the same thing. The terms may have different connotations culturally, but good security-in-depth is the same set of practices that enable digital privacy, because the objective is the same: prevent leakage of facts.
You can have E2EE to the service provider, but they can be free to rummage through your data if they choose to or are coerced to by a legal demand from an authority. But it eliminates the average schmoe from going through that data.
Is that adequate security? Is that adequate privacy? This is what bills like EARN IT and its ilk are positing with backdoors et al. It depends on your threat model.
If a warrant opens a door or account one way or another, it can be argued that privacy-wise, locks and passwords are poor solutions. Are you protecting business data or trying to survive in an oppressive regime?
Different solutions for different problems, how appropriate they are varies with demographics too.
E2EE refers to fully encrypted communication between end-users of a service, hence end-to-end. If one of the ends is the service provider, the term doesn't apply.
This is the point. It's a buzzword and the reality of a lot of popular services is that the service provider can likely already provide access to your data if requested to by a government.
Ergo, if this is a consideration within your threat model, it's an inappropriate solution. However, I am highlighting that EARN IT is no more a threat than existing service providers abiding by a court order, ergo the existing solutions likely aren't fit-for-purpose for some folks, depending on threat model.
I'd argue that they're overlapping sets of concerns, not necessarily identical to or subsets of each other.
Off the cuff:
* Being an anonymous person walking through a city. This is a privacy concern and only becomes a security concern if I'm a public persona or some kind of person of interest.
* Moving to a new school/city/job and not having your social reputation follow you. This allows a lot of people a chance to redefine who they are and how they interact with people around them. This can't happen if everybody always knows somebody's pervious public persona.
* Breaking a law and being fined/punished/imprisoned for it. Without privacy, such a person has a much poorer chance of having a decent life even after they've done their time or paid their dues.
These all strike me as privacy concerns, but not necessarily concerns to security. I think they're all important enough to consider privacy as a good thing in it's own right and that such scenarios signal that it's possible to advocate privacy in the absence of (or opposition to) security concerns.
Not GP, but security refers to the protection of the system, while privacy refers to the protection of information.
So you need to protect the system to protect the information on it, but there are also sometimes trade offs between security and privacy when you offload some system protection by giving away some information to another party. For example SmartScreen with Microsoft, and Safe Browsing with Google Chrome.
elesiuta had some great commentary I agree with, but to add my own response:
> IMO these are all 'security' related, just personal security (which is what I define privacy as).
I think this level of reduction becomes problematic in scenarios where security>privacy advocates talk about security in the collective sense.
Playing devil's advocate to highlight where I believe this reduction of security->personal security->privacy breaks down: A man borrowed many books from a library on the topic of explosive chemistry. That man later was involved in terrorist acts.
This is a situation where one could argue that less privacy for people in relation to their library borrowing habits may have resulted in greater security.
This is an example of an event that has happened, and while I hate the cliche of terrorism in debates about privacy and feel this particular point can be argued, it's exactly these kinds of scenarios that security>privacy advocates use to push for fewer privacy protections across large groups of people.
I agree its a good counter-point. I would argue that we shouldn't give our decision making power to decide what is and isn't best for us over to any 3rd party because they will never have the same interest in making informed decisions as the beholder. There is nothing on the line for someone to make decisions on another's behalf.
The Sokovia Accords Debate [1] from the Captain America Civil War (2016) film says it best, imho.
Another problem that I feel has barely even been touched on in recent time is what even are facts. People see things on the Internet and take it for gospel.
You know information people ALWAYS blindly believe 100%? "Leaked" data. Imagine how much power one could have with manipulated, leaked, data.
You don't even need to say anything that isn't true. Just being selective about which true secrets you reveal can be a very powerful tool to control the narrative.
> as for email [passwords], that's again a matter of security
I guess if we're nitpicking I'll point out that this is still privacy (how one keeps their password) for the sake of security. Information is kept private and passwords are information.
Perhaps drawing a distinction between outbound and inbound email protocols would be good too. I understand the argument being made, but the sensible assumption is that your email, even with a password, isn't a sensible choice for sensitive communications.
> your email, even with a password, isn't a sensible choice for sensitive communications
This seems like it's shifting the goalposts. Someone says something about "nothing to hide but they have locks on their doors" and you say "security isn't the same as privacy". It's accurate but it's moot. I keep the location of my hide-a-key private so I can continue to keep my house secure with the lock on the front door. I keep my email password private so I can secure the account against unauthorized access.
Some people do use their email for what they would consider sensitive communications, and it's less than helpful to suggest they need better opsec practices in response to someone else saying that they should be able to expect their email to be private. It's saying "just hide it better, lol" when that's literally exactly what many people are trying to do when speaking against this sort of legislation.
> Well, clothes are mostly down to weather and laws on public decency
Where I live, there are no laws against public nudity (as long as the nudity isn't "salacious" in nature). And yet, very nearly 100% of the people are clothed at all times.
And yet in other areas of the world, people wear no clothes.
People also smoke cigarettes, eat junk food, and do things that are unnatural and otherwise detrimental due to what they're bombarded with.
I wear clothes, I'm not a nudist. I have zero shame about my body though, it's a body—we've all got one.
The point as per my other comments: different solutions for different problems, the appropriateness of each varies with demographics. E.g., if you're surviving in an oppressive regime as a dissenter, email is something to be avoided. If you're running a business, it's likely fine, provided that it's compliant for your industry, e.g., HIPAA.
Email passwords are not for preventing impersonation. For one, POP3 passwords are separate from SMTP. Second, nothing in SMTP prevents impersonation… large mail handlers like GMail don’t allow it anymore, but you can put whatever you want in the “From” field. Things like SPF, DMARC and DKIM are there to prevent impersonation at the domain level for mail servers that want to protect their users.
When accessing email via a protocol with an email client, sure, but I primarily had the Gmail web app in mind when I wrote the comment. I also touched on protocols in another comment.
With what I had in mind, if you logged into my Gmail account, which provides both sending and receiving, you could impersonate me to my own mother, but I would have nothing to hide as I don't receive any sensitive information via email (privacy). However, accounts elsewhere could be recovered via my email, and thus be used to impersonate me elsewhere (security).
I routinely pose that question to my kids. And yet, they still poop with the door open. And without the ventilation fan. I keep hoping that eventually I will get through to them. Maybe I'll just put a spring-loaded hinge on the bathroom doors and a motion-activated ventilation fan.
I've got a 2.5yo that furiously yells at me to get out when he poops, but he have no remorse trying to physically drag me out of the loo when I am doing my business. Or force me read some book for him.
I guess he is a metaphor for the surveillance state. Or the other way around. Dunno.
Ha! I remember when my son was about that age he came wandering in while I was using the toilet standing up. Just a little awkward to have your kid walk around the side and stare at your crotch while you pee. I get that it was fascinating for a little boy, but still. And then of course the next time he needed to go, he tried. Predictable results ;-).
He might have been a little younger, I don't remember precisely, I don't believe he was talking much at the age when this happened.
For sure, they act totally different in a public toilet. Very carefully locked door in that case. Hell, the first time my son used a public toilet on his own, I had to talk him through how to actually unlock the door when he finished. I tried to tell him not to latch it since I was standing right on the other side of the door, but no, -CLICK- went the lock anyway.
Unsure if sarcasm but doesn't the exact same reasoning apply to these? If there's things you don't want thieves to steal then obviously you _do_ have something to hide. Or maybe a better word is protect but both apply equally well
Completely agree. Also a reminder that there are things to be scared of, today. People getting abortions in states where it's illegal need their communications to be safe and secure. The current forced medical detransition of adults in Montana means people are going to need to rely on underground distribution networks for their medication, starting in a few weeks. Their communications need to be secure from government spying as well. The police are not your friend. It is no longer necessary to talk about theoretical futures or nebulous harms to privacy, the unjust laws are already here (& should be ignored, fought, frustrated, or routed around, as necessary). We do not need a cop on our phones.
I think all of these injustices are be created to further gaps between classes of people to lay the groundwork for a future paradigm shift towards totalitarianism. Is the same thing we do in other countries to spread the so called democracy under the guise of a dictatorship.
>A reminder that "you have nothing to hide" argument is a fallacy because people abuse their power
Also because we have a lot to hide that we should be able to. Our intimate pictures with our partners, our chats with friends (and gossip), our business plans, our in-progress work and ideas, yet to be filled patents, password and account credentials, and lots more.
Also, "you have nothing to hide" is so wrong, that people fail to understand that privacy isn't about hiding your private life, but having the power to sharing those details with consent and when you're comfortable sharing them. Just because you don't have nothing to hide, doesn't mean anyone can walk in your private life and peek into all corners.
And as you mentioned, power will be abused. Unchecked power will be abused unchecked. This is ethically, morally and humanely wrong.
There's so much wrong with this bill and the thought behind it. It should never see the day of light.
“Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say.”
- Snowden
Personally I favor a confrontational retort: "No, you never get to decide that. The inquisitor does." Revolutions are a messy example which demonstrate what happens when the mandatory becomes forbidden without ex-post-facto restrictions. There is a reason many people get the hell out of dodge even after the fighting stops.
Kind of (if you mean the Shut Up and Dance one), in classic black mirror fashion the episode is littered with twists that make it difficult for people to really grasp the point and instead can argue against it. In the episode the main character gets infected with malware (the tool he wanted is actually a sting operation), but because of what he's being blackmailed about a lot of people feel that's justified.
What a ridiculous argument. That's like saying the police shouldnt have weapons to defend themselves with because there's a history of police killing innocent people.
No, the real answer here is to address the actual corruption to expose and remove it.
Not to mention, if you have nothing to hide, how can someone abuse their power to use it against you?
These bills are put in place because they save lives, especially vulnerable children.
even if they didn't currently abuse their power or abused it only an "acceptable" degree, we're never more than one election away or even just one hiring decision away from someone who would do much worse.
The right protection is for the power to not exist.
The other issue is just because something doesn't need to be hidden today doesn't mean a change in the political/social winds could happen that requires you to hide it tomorrow.
No. Sorry. This is invalid. It would be pretty bad if we declare some shit illegal and retroactively apply the "law". You will be charged for shit that everyone did and is perfectly fine. For example: How would you like to go to jail for not being a Christian? This will be weaponized.
That’s the second time I see bank account number framed as something private. Why? It doesn’t authorise anyone to do anything. It’s not like a debit/credit card number.
A better example are people that do have something to hide - whistleblowers, union organizers, political activists, journalists, upstart politicians... How does the nature of their work change, if the current government in power knows all their secrets, and abuses or selectively leaks/prosecutes them? And does that change society for the better, or for the worse?
Some first hits as reminders of places where their powers are abused
[1]: "NSA staff used spy tools on spouses, ex-lovers: watchdog" https://www.reuters.com/article/us-usa-surveillance-watchdog...
[2]: https://reason.com/2022/07/26/police-can-access-your-ring-ca...
[3]: https://reason.com/2021/04/26/warrantless-border-searches-dr...