Live data from Hacker News

Petition UK government to not ban encryption

petition.parliament.uk

51–60 of 113 posts

Re: Petition UK government to not ban encryption

#52
post #50
post #32

Earlier quoted context omitted.

Is there any scheme which permits a data to be encrypted such that there are two passwords\keys which can decrypt it - one which unlocks the real data and the other to some dummy\innocuous stuff?

Indeed there is, it is called plausible deniability [1]. With Truecrypt, you can nest a hidden volume within another volume, so you can decrypt the latter and it will only show innocuous files, while another password (using other parts of the volume) would provide other (incriminating) files. I wonder what is in a judge's mind when the encrypted evidence turns out to be kitten pictures and the defendant claims that h…

That is not what OP is talking about. You cannot get different information out of the same chunk of encrypted data. That would basically make infinite compression.

What the methods you mentioned are doing, is hiding information in places which are marked as: random data no information here. But in reality there is information there. You then need to have dummy information somewhere else.

Re: Petition UK government to not ban encryption

#53
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

Reading "between the lines" is not a valid way to interpret laws. What is written is what is valid, not what you think it should mean. As yourself used the term, how is "communication between a bank and a customer" not a form of "communication"?

>What is written is what is valid, not what you think it should mean

I am not sure if it would be a good thing or not if this was the case, but leaving that aside laws are, in fact, liberally interpreted all the time, depending on your jurisdiction's legal tradition. This is why you can't hack the law; the interpretation of the law will change to fill in the gaps, provided that's what the justice system wants.

Re: Petition UK government to not ban encryption

#54

They're not going to ban encryption. Seriously. Stop wasting time on misquotes taken out of context blown up by The Guardian. There's more important things to worry about.

As a non UK/third party, i laugh at both, you keep buying that paper, and you have elected cameron… :)

Re: Petition UK government to not ban encryption

#55
post #43
post #40

Earlier quoted context omitted.

The number of people that can implement secure communications without relying on third parties is close enough to zero that they basically don't count. ISIS recruitment would plummet to zero if people had to get TLS working before joining.

I don't think that you understand that the TLS technology used for online banking (which would still be legal) is the very same technology that lets you create a secure communication channel with other users.

I don't know why you think that. Perhaps I was unclear.

The average prospective terrorist / criminal etc isn't going to be able to set up TLS. If they encrypt their communications, the odds are it's going to be going via a third party. Next time you send an email, tell the recipient that from now on you're going to communicate directly by TLS, and they'll need to set up a server before you can talk to them again. I believe that most people will have considerable difficulty doing that.

So, you're reliant on third parties who constitute single points of failure and potential targets of legal action.

Individuals who can securely set up TLS (or PGP or whatever) for their own communications are sufficiently rare that they effectively don't matter.

Re: Petition UK government to not ban encryption

#56
post #45
post #21

The government's story has been "we need a way to access people's data so we can catch pedophiles, drug dealers and terrorists" and it seems there is a widely held belief that in order to do this, they would need to either ban encryption or weaken it sufficiently to make it effectively useless. However, as far as I can tell, backdoors into your phone or your desktop PC already exist. All the government has to do is c…

Or simply start instilling the idea into ignorant people's minds that crypto is bad and just keep repeating that until it becomes a "truth", or gain votes or leverage on the right occasion when needed with "we told you so".

I'm not sure that's a wise strategy. Try telling the users of Ashley Madison that encryption is a bad thing. For each of the government's examples of where encryption enables criminals to do criminal things, the public are going to hear about the cases where lack of encryption enables criminals to do criminal things. There's just as equal a chance in my opinion that raising the issue in the consciousness of the public that they turn against the government and demand stronger encryption rather than less.

The NSA and GCHQ were able to gain significant powers in the last decade primarily by staying under the radar of public awareness. That is why the leaks we heard in 2013 were so significant. Now the cat's out of the bag, it might be the government are left with no choice but to use propaganda to convince the public to give them what they want but there's no guarantee that it will work.

Re: Petition UK government to not ban encryption

#57
post #36

http://www.revk.uk/2015/07/crypto-wars.html "If a British citizen with an iPhone purchased in France and roaming in Germany iMessages a Chinese citizen roaming in Sweden using an iPhone purchased in Denmark, which government's keys need to be inserted in the iMessage communications by an American company (Apple) legally based in Luxembourg using servers hosted in Eire?"

The author of that blog post is the same person who started the petition.

Re: Petition UK government to not ban encryption

#58
post #34
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

I expect that a government may be very interested in the content of communications between a bank and a customer

Banks are so closely regulated that they are not really (in fact not at all) off limit for the government. Unless we are talking about a foreign website of a foreign bank, which would not be required to comply anyway.

Webmails, social medias or dating services are of a much greater interest to a nosy government.

Re: Petition UK government to not ban encryption

#59
post #58
post #34

Earlier quoted context omitted.

I expect that a government may be very interested in the content of communications between a bank and a customer

Banks are so closely regulated that they are not really (in fact not at all) off limit for the government. Unless we are talking about a foreign website of a foreign bank, which would not be required to comply anyway. Webmails, social medias or dating services are of a much greater interest to a nosy government.

Oh, I believe you are mistaken. Governments are quite interested in your financial dealings, even with banks. The more they know, the less you can do without their direct knowledge.

Re: Petition UK government to not ban encryption

#60
post #30
post #20

Earlier quoted context omitted.

Apparently our politicians should understand infosec to demand policy, but the people don't have to understand their goverment to demand policy.

How can you have a situation where the HTTPS used to secure communication between two peers is different than the HTTPS used between a bank and one of it's clients ? This just shows serious misinformation on your part.

Presumably the government asks the bank what you're up to, and the bank tells them. Which is exactly what already happens today.

Do you think the reason you use HTTPS to talk to your bank is to prevent the government from seeing your account balance?

Post reply on HN