Live data from Hacker News

Petition UK government to not ban encryption

petition.parliament.uk

101–110 of 113 posts

Re: Petition UK government to not ban encryption

#101
post #52
post #50

Earlier quoted context omitted.

Indeed there is, it is called plausible deniability [1]. With Truecrypt, you can nest a hidden volume within another volume, so you can decrypt the latter and it will only show innocuous files, while another password (using other parts of the volume) would provide other (incriminating) files. I wonder what is in a judge's mind when the encrypted evidence turns out to be kitten pictures and the defendant claims that h…

That is not what OP is talking about. You cannot get different information out of the same chunk of encrypted data. That would basically make infinite compression. What the methods you mentioned are doing, is hiding information in places which are marked as: random data no information here . But in reality there is information there. You then need to have dummy information somewhere else.

This would be trivial to do with one-time-pads. A bit bulky, but simple. But in a way, you'd still be right. The "dummy information" is (encoded into) the second key.

Re: Petition UK government to not ban encryption

#103
post #25
post #12

It really worries me that the leader of our nation does not appear to have all the information required in order to make a decision on a topic as important as this. I would have thought that a domain expert within government would have be consulted before Cameron goes off half cocked in debates and discussions. With technology a key and growing industry within the UK, shouldn't we expect our leaders to at least attem…

What past experience would have given you the idea that a UK prime minister would let domain expects stop them from coming up with stupid proposals? (I was about to single out Cameron, but while I detest him, and while he seem to have a particular blind spot for technology, the problem is by no means unique to the Tories; e.g. consider when David Nutt was asked to go because his evidence-based advice on drugs didn't…

You mean had to go because it didn't agree with the Medias Agenda

Re: Petition UK government to not ban encryption

#104
post #101
post #52

Earlier quoted context omitted.

That is not what OP is talking about. You cannot get different information out of the same chunk of encrypted data. That would basically make infinite compression. What the methods you mentioned are doing, is hiding information in places which are marked as: random data no information here . But in reality there is information there. You then need to have dummy information somewhere else.

This would be trivial to do with one-time-pads. A bit bulky, but simple. But in a way, you'd still be right. The "dummy information" is (encoded into) the second key.

[deleted]

Re: Petition UK government to not ban encryption

#105
post #21

The government's story has been "we need a way to access people's data so we can catch pedophiles, drug dealers and terrorists" and it seems there is a widely held belief that in order to do this, they would need to either ban encryption or weaken it sufficiently to make it effectively useless. However, as far as I can tell, backdoors into your phone or your desktop PC already exist. All the government has to do is c…

Not exactly. Apple, for example, has already begun encrypting so that they themselves can’t decrypt the data.

And that’s exactly how it should be.

Re: Petition UK government to not ban encryption

#106
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

Reading "between the lines" is not a valid way to interpret laws. What is written is what is valid, not what you think it should mean. As yourself used the term, how is "communication between a bank and a customer" not a form of "communication"?

Oh right, because laws are ironclad codifications of pure, unadulterated Justice, and that's exactly why you can be imprisoned for collecting rainwater on your property: http://cnsnews.com/news/article/oregon-man-sentenced-30-days...

In reality, the correct way to interpret laws is to think about their real purpose. Who benefits? What is the goal here?

The vast majority of laws have one of these two purposes: to enrich the government's cronies, or to cement the government's continued rule.

Re: Petition UK government to not ban encryption

#107
post #70
post #55

Earlier quoted context omitted.

I don't know why you think that. Perhaps I was unclear. The average prospective terrorist / criminal etc isn't going to be able to set up TLS. If they encrypt their communications, the odds are it's going to be going via a third party. Next time you send an email, tell the recipient that from now on you're going to communicate directly by TLS, and they'll need to set up a server before you can talk to them again. I b…

Using PGP securely is as easy as downloading some software, typing in your message, and clicking a button. It's not something that requires any knowledge beyond basic computer usage. You aren't going to be able to stop people from sharing PGP software on the internet. I think you're severely underestimating the intelligence of people in general. If we're talking about ISIS, all it takes is one moderately experienced…

Using PGP is as easy as understanding PKI, which is beyond most people that don't work in tech, and a substantial amount of people that do.

Re: Petition UK government to not ban encryption

#110
post #77
post #66

Earlier quoted context omitted.

TLS is currently simply a matter of point and click on a graphical interface. For hosting provider setup, to domain name registration and TSL certificate generation there are thousands of online tutorials. You don't need to be an expert or a developer to know how to setup TLS on a Wordpress blog.

A Wordpress blog run by a third party does not constitute a secure messaging system, even if you have TLS enabled on it. And it's still a lot less easy than using WhatsApp.

Installing pidging, otr, starting a chat and confirming who you're talking too doesn't exactly require a comp sci degree.

This isn't really about stopping that though, it's about the snooping nanny state plain and simple.

Post reply on HN