US Anti-Encryption Law Is So 'Braindead' It Will Outlaw File Compression (theregister.co.uk)
An anonymous reader writes: The bill released Thursday by Senators Richard Burr and Dianne Feinstein to force U.S. companies to build backdoors into their encryption systems has been further dissected by experts. In less than 24 hours after the Court Orders Act of 2016 draft was released, 43,000 signatures have been added to a petition calling for the bill to be withdrawn. Bruce Schneier, the writer of the books on modern cryptography, said the bill would make most of what the NSA does illegal, unless no such agency is willing to backdoor its own encrypted communications. "This is the most braindead piece of legislation I've ever seen," Schneier told The Register. "The person who wrote this either has no idea how technology works or just doesn't care." Schneier says cryptographic code will be affected by this legislation, as well as "lossy compression algorithms" that are used to reduce the size of images for sending through email, which won't work in reverse and add back the data removed. Files that can't be decrypted on demand to their original state, and files that can't be decompressed back to their exact originals, all look the same to this draft now. He said even deleted data could be covered in this legislation.
...where nobody seems to know how they continue to get elected.
An interesting comment on The Register pointed out that how the law is written it would ban the use of one way hashes to store passwords.
Please share your views here, too.
http://www.feinstein.senate.go...
https://www.youtube.com/c/BrendaEM
Suppose I use some third-party encryption that is made available anonymously or from another country, so there's no company to compel to reverse it. (Think TrueCrypt, or something from Schneier's Applied Cryptography.) Now suppose I plead the fifth and refuse to decrypt it. What then? We start blocking any site that hosts such a thing? Burn books on cryptography? Ban people from running compilers? Code escrow of all source with the NSA on pain of death?
Sure, there's the obligatory XKCD wrench decryption, but otherwise... I'm not sure how this makes a lick of sense.
If it bans any algorithm "that can't be decrypted on demand to their original state", that pretty cuts out MP3s, and pretty much every streaming audio and video service. Good luck with that...
Won't forcing all US-made encryption software to include backdoors simply force all encryption software developers overseas??? Any company that wants to remain in the US will have to contract it's encryption out to a non-US company. Thanks, DiFI, for sending my job offshore!
I've abandoned my search for truth; now I'm just looking for some useful delusions.
It doesn't matter what this law will say. What matters--and this is of course true of every law--is how it will be enforced. They don't care about MP3s or even cryptography as such. What they care about is being able to decrypt the communications they want to decrypt. It's much easier from their point of view to write an overly broad law even if it appears stupid because it's only the enforcement that counts, and they control the enforcement.
I think those who wrote this brain dead legislation know exactly what they are doing. There is just too damn much freedom on the internets.