Live data from Hacker News

Petition UK government to not ban encryption

petition.parliament.uk

21–30 of 113 posts

Re: Petition UK government to not ban encryption

#21
The government's story has been "we need a way to access people's data so we can catch pedophiles, drug dealers and terrorists" and it seems there is a widely held belief that in order to do this, they would need to either ban encryption or weaken it sufficiently to make it effectively useless. However, as far as I can tell, backdoors into your phone or your desktop PC already exist. All the government has to do is convince Apple, Google, MS or Ubuntu to provide an 'official' update to a target computer, wait for the user to accept (or the OS to accept it automatically) and they have full reign over your device.

Many people say that opening our devices to a special chosen set of good guys is equivalent to opening them to all the bad guys as well. If that's the case, surely we're already vulnerable given most commonly used devices update automatically?

The only purpose I can see for attacking encryption in general is to enable mass surveillance. The government have in fact not been specific about what they are actually asking for, but if they want selective ability to search digital devices, they already have it. If they want further powers, then we need to ask them what they need them for.

Re: Petition UK government to not ban encryption

#22
post #6

Earlier quoted context omitted.

I don't think anyone is dumb enough to actually prevent the electorate logging into facebook. I expect the language to be broad and the enforcement narrow.

> I expect the language to be broad and the enforcement narrow. That's the worst kind of law - you can be locked up at a prosecutors whim. In the UK, it's already illegal not to disclose the key to an encrypted file.

Well, kinda. A RIPA s.49 notice can be defeated with s.53 defenses.

Some people have failed to pass the test of "reasonable doubt" for s.53 (3) / (4) defenses e.g. ( http://www.alphr.com/news/361693/teenager-jailed-for-refusin... ) but in other cases they have succeeded (e.g. Lauri Love had his hdd's taken and the NCA couldn't decrypt them but had to release him on bail; http://www.bbc.co.uk/news/uk-england-suffolk-31544346 and subsequently returned some of the storage (before arresting him again))

There are also people out there working to help the reasonable doubt argument; https://brasshorncommunications.uk/projects/s53/

Re: Petition UK government to not ban encryption

#23
post #6

Earlier quoted context omitted.

I don't think anyone is dumb enough to actually prevent the electorate logging into facebook. I expect the language to be broad and the enforcement narrow.

> I expect the language to be broad and the enforcement narrow. That's the worst kind of law - you can be locked up at a prosecutors whim. In the UK, it's already illegal not to disclose the key to an encrypted file.

It's fun, in Argentina we've had a case were a criminal releasing the key nullified the evidence, because the criminal's lawyer argued that (under Argentinian law):

* He was forced ("tortured" was the word used) to disclose the key by the police.

* You can't accuse yourself or direct relatives, and disclosing an encryption key that resulted in incriminating evidence was argued to be a form of "self incrimination".

* "Best" thing about this was that the evidence led to finding a body, but as it was nullified, legally the status of the deceased person changed from "deceased" to "missing" -- because the evidence they had used to find the body had been nullified, then also the finding of the body had to be null (I'm not kidding, people went nuts over this "technicallity").

* Eventually a more reasonable judge turned the previous statement and accepted that the person was deceased indeed.

Working in forensics (I do digital forensics) is weird some times...

Re: Petition UK government to not ban encryption

#24
Hopefully we can mostly agree that they're not really going to try to ban encryption.

Would anybody like to speculate on what proposals we might see in reality? Are they going to ban me, as an individual, from using GPG? Are they going to ban companies from operating encrypted messaging services in the UK? Are they going to block traffic from non-compliant overseas providers? Are they going to just have a quiet word with the SnapChat people?

Re: Petition UK government to not ban encryption

#25
post #12

It really worries me that the leader of our nation does not appear to have all the information required in order to make a decision on a topic as important as this. I would have thought that a domain expert within government would have be consulted before Cameron goes off half cocked in debates and discussions. With technology a key and growing industry within the UK, shouldn't we expect our leaders to at least attem…

What past experience would have given you the idea that a UK prime minister would let domain expects stop them from coming up with stupid proposals?

(I was about to single out Cameron, but while I detest him, and while he seem to have a particular blind spot for technology, the problem is by no means unique to the Tories; e.g. consider when David Nutt was asked to go because his evidence-based advice on drugs didn't agree with the Labour governments policy)

Re: Petition UK government to not ban encryption

#26
I think we are fighting the wrong battle here. The power equation is already in favor of the government snooping everybody, making it law only puts things in the open. We should fight in that direction, making it so that everything is more transparent. Wanna have my data? Okay, but I want to have yours. I specially want to have all the data about what you do with my data. I want to be able to request all the data you got of me. I want to be able to erase some of it (or at the very least mark it as invalid). I want to be able to add directly to it. I want to know whenever it is used. I want a due process every time it is used for something that affects me. And I want people that make use of data for their own purposes or that don't follow protocol to be prosecuted or at the very least banned from public office.

Re: Petition UK government to not ban encryption

#27
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

The problem with your interpretation is that bank communications are still a means of communication. So the vagueness of the law allows politicians to extend their requirements to any product they wish without exception. This isn't something I believe to be accidental either as terrorism laws are often written to be vague with the intent of common sense regulation - which often gets bypassed when a jobsworth believes they're in the right.

Re: Petition UK government to not ban encryption

#28

They're not going to ban encryption. Seriously. Stop wasting time on misquotes taken out of context blown up by The Guardian. There's more important things to worry about.

The point of this petition, even though it looks at first blush to be taking down a straw man, is to send a shot across the bow.

Either:

a) they ban all end-to-end encryption

or

b) this law is ridiculously easy to circumvent for even non-technical users

An example of b) would be: piggyback messaging on an existing service that has a valid reason for being encrypted

Re: Petition UK government to not ban encryption

#29
To all those saying "it's not about banning encryption - only encrypted messaging then surely either:

a) they ban all end-to-end encryption

or

b) this law is ridiculously easy to circumvent for even non-technical users

An example of b) would be: piggyback messaging on an existing service that has a valid reason for being encrypted

Re: Petition UK government to not ban encryption

#30
post #20
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

Apparently our politicians should understand infosec to demand policy, but the people don't have to understand their goverment to demand policy.

How can you have a situation where the HTTPS used to secure communication between two peers is different than the HTTPS used between a bank and one of it's clients ?

This just shows serious misinformation on your part.

Post reply on HN