Live data from Hacker News

Petition UK government to not ban encryption

petition.parliament.uk

31–40 of 113 posts

Re: Petition UK government to not ban encryption

#31
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

Reading "between the lines" is not a valid way to interpret laws. What is written is what is valid, not what you think it should mean.

As yourself used the term, how is "communication between a bank and a customer" not a form of "communication"?

Re: Petition UK government to not ban encryption

#32
post #6

Earlier quoted context omitted.

I don't think anyone is dumb enough to actually prevent the electorate logging into facebook. I expect the language to be broad and the enforcement narrow.

> I expect the language to be broad and the enforcement narrow. That's the worst kind of law - you can be locked up at a prosecutors whim. In the UK, it's already illegal not to disclose the key to an encrypted file.

Is there any scheme which permits a data to be encrypted such that there are two passwords\keys which can decrypt it - one which unlocks the real data and the other to some dummy\innocuous stuff?

Re: Petition UK government to not ban encryption

#33
Cameron is not really trying to ban encryption (or even ban end to end encryption apps).

This is misdirection in the run up to new surveillance legislation. The real issue is 'bulk collection'.

The UK government is trying to frame the debate such that the concept of mass surveillance is not challenged.

Re: Petition UK government to not ban encryption

#34
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

I expect that a government may be very interested in the content of communications between a bank and a customer

Re: Petition UK government to not ban encryption

#35
post #33

Cameron is not really trying to ban encryption (or even ban end to end encryption apps). This is misdirection in the run up to new surveillance legislation. The real issue is 'bulk collection'. The UK government is trying to frame the debate such that the concept of mass surveillance is not challenged.

Bulk collection is rendered entirely pointless by end-to-end encryption because the government would just end up with vast amounts of data they can't read. I would say the UK government is trying to ban encryption, and for exactly that reason - they want mass surveillance that is 'useful' (for the government's definition of useful, which is not the same as mine or yours).

Re: Petition UK government to not ban encryption

#36
http://www.revk.uk/2015/07/crypto-wars.html

"If a British citizen with an iPhone purchased in France and roaming in Germany iMessages a Chinese citizen roaming in Sweden using an iPhone purchased in Denmark, which government's keys need to be inserted in the iMessage communications by an American company (Apple) legally based in Luxembourg using servers hosted in Eire?"

Re: Petition UK government to not ban encryption

#39
post #32

Earlier quoted context omitted.

> I expect the language to be broad and the enforcement narrow. That's the worst kind of law - you can be locked up at a prosecutors whim. In the UK, it's already illegal not to disclose the key to an encrypted file.

Is there any scheme which permits a data to be encrypted such that there are two passwords\keys which can decrypt it - one which unlocks the real data and the other to some dummy\innocuous stuff?

[deleted]

Re: Petition UK government to not ban encryption

#40
post #30
post #20

Earlier quoted context omitted.

Apparently our politicians should understand infosec to demand policy, but the people don't have to understand their goverment to demand policy.

How can you have a situation where the HTTPS used to secure communication between two peers is different than the HTTPS used between a bank and one of it's clients ? This just shows serious misinformation on your part.

The number of people that can implement secure communications without relying on third parties is close enough to zero that they basically don't count.

ISIS recruitment would plummet to zero if people had to get TLS working before joining.

Post reply on HN