Live data from Hacker News

Dutch government says no to backdoors, grants $540k to OpenSSL

theregister.co.uk

61–70 of 101 posts

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#61
post #52
post #32

Earlier quoted context omitted.

If there is a reasonable suspicion I don't see the problem with giving law enforcement the legal ability to hack their targets. This is something very different from drag-net surveillance and should not be tainted with the same stigma. It's not like the government actually _needs_ or wants to maintain giant botnets of all the targets they've hacked.

Withholding known security vulnerabilities from the public in order to be later used for hacking is immoral and dangerous. Imagine if the police had prior knowledge of a vulnerability in the computer system of a car, but did not act to protect the public. A few years later a criminal figure out the same vulnerability and causes a major car crash on a motorway and murder several people. I would view the police officer…

> if companies has a legal responsibility to protect their customers and provide safe products

Since 1 January there is also a law in the Netherlands that requires companies to report any data leaks.

https://www.government.nl/latest/news/2015/07/10/obligation-...

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#62

Dutch here. The argumentation is remarkably good. The privacy like you have with letters and phone calls is part of our constitution, and also part of European guidelines. The rules to violate this privacy, only in certain cases, is already part of the law (eg. wiretaps under suspicion). ISPs have to cooperate where possible. That the dutch intelligence services are now hampered by end-to-end encryption making the IS…

How much privacy with phone calls is there, when The Netherlands are known for having the most phone taps in the world? The formal privacy looks pretty strong indeed, government needs a warrant, etc., but at the end of the day they can do whatever they want.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#64

Don't worry, they can still get your stuff; the new Dutch cybercrime law allows the likes of Fox-IT to hack your laptop/ISP and grab your data from there.

Of course they can. But isn’t it better to target specific computers instead of doing dragnet surveillance on all Internet traffic?

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#65

'Although the Dutch position is nuanced and firm, the government also has the luxury of not having real impact on the real world' noted.

They actually put money in development of strong encryption, €0.5M. Here are the details from the government ordering to support OpenSSL: https://zoek.officielebekendmakingen.nl/kst-34300-XIII-10

And contrary to the document on the parliament website [1], that link points to the document in PDF, ODT, HTML and XML.

[1] http://www.tweedekamer.nl/kamerstukken/brieven_regering/deta...

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#67
post #64

Don't worry, they can still get your stuff; the new Dutch cybercrime law allows the likes of Fox-IT to hack your laptop/ISP and grab your data from there.

Of course they can. But isn’t it better to target specific computers instead of doing dragnet surveillance on all Internet traffic?

Sure, but not without a warrant.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#68
post #60

Earlier quoted context omitted.

The money going to OpenSSL might be related to the issue the Dutch government ran into in 2011 with the Diginotar (a certificate authority) hack; the TLS certificates for Dutch government websites were compromised at that time. While this hack was not related to weaknesses in OpenSSL (as far as I know), this did put the spotlight on the vulnerability and dependence on of the certificate chain. Supporting the software…

The amendment to provide €500 million to open sources encryption project (initially only OpenSSL), was done by D66's Kees Verhoeven. He has a history of asking question about the Snowden revelations and other issues around computer security. He is also partly responsible for the amendment on net neutrality, and the infamous 'cookie law' (which is actually more of a 'do not 3rd party track before asking consent' law).…

You probably mean €500 thousand, not million.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#69

Dutch here. The argumentation is remarkably good. The privacy like you have with letters and phone calls is part of our constitution, and also part of European guidelines. The rules to violate this privacy, only in certain cases, is already part of the law (eg. wiretaps under suspicion). ISPs have to cooperate where possible. That the dutch intelligence services are now hampered by end-to-end encryption making the IS…

In the US, there are laws on the books that telecom corps are required to facilitate searches or wiretaps on client communication when presented with a court order. And if you look at the metadata collection deal that Obama passed recently, it says that the NSA can't collect metadata, but telecoms are required to do it instead and produce it when served with a court order. So, it's not at all unprecedented for government to make it a legal problem and put the onus on private industry. This is actually Hillary's most recent stance on encryption. She says if we can't "break" encryption or have backdoors, you have to give us another option. Wouldn't be surprised if Holland and others have a similar idea in mind.

Re: Dutch government says no to backdoors, grants $540k to OpenSSL

#70

Dutch here. The argumentation is remarkably good. The privacy like you have with letters and phone calls is part of our constitution, and also part of European guidelines. The rules to violate this privacy, only in certain cases, is already part of the law (eg. wiretaps under suspicion). ISPs have to cooperate where possible. That the dutch intelligence services are now hampered by end-to-end encryption making the IS…

How much privacy with phone calls is there, when The Netherlands are known for having the most phone taps in the world? The formal privacy looks pretty strong indeed, government needs a warrant, etc., but at the end of the day they can do whatever they want.

From what I hear, police here can also freely access and query all phone metadata, without the need for a warrant.
Post reply on HN