The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…
There's stuff there about cryptography too, but the logging is about metadata.
For metadata things are the opposite of your logic. It is always accessible. Whatever protocol you create to hide it, will have holes; Math dictates it.
The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…
Do you think that browser makers could come under attack? Will Chrome and Firefox be required to add back doors to their "service".
Pardon my extreme language but Fuck! How on earth do bills like this come to pass without uproar widespread enough to quash it.
Shit like this seriously makes me want to give up on the internet and walk away from it despite it having been my lifeline and the foundation of my income since I was in my teens almost 30 years ago.
"To ensure they do not succeed, we do not comment publicly on the methods or capabilities available to the security and intelligence agencies." Oh but you don't need to, because it's obvious. All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If I don't or can't comply then I will be - by definition - a criminal and potentially a terror sus…
> All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If the VPN connection uses ephemeral keys (IIRC, at least IPSEC, SSH, and TLS 1.3 always use ephemeral keys, while older TLS uses them when possible), by then it's too late: the keys are gone.
You can imagine someone being locked up for this though. If you are required by law to decrypt your data, and you chose technology that does not allow this, then that's on you. To use an analogy, if you choose to ride a bike that doesn't have lights, and then get pulled over for riding without lights, the lack of lights is not a defense because you were required to have them in order to be on the road at night.
"To ensure they do not succeed, we do not comment publicly on the methods or capabilities available to the security and intelligence agencies." Oh but you don't need to, because it's obvious. All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If I don't or can't comply then I will be - by definition - a criminal and potentially a terror sus…
> All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If the VPN connection uses ephemeral keys (IIRC, at least IPSEC, SSH, and TLS 1.3 always use ephemeral keys, while older TLS uses them when possible), by then it's too late: the keys are gone.
Cool. Now all I have to do is prove that to the satisfaction of the investigation while they crawl all over the rest of my life looking for clues as to what it is I'm so keen on hiding. The process is the punishment.
The most scary thing for me is that both political left and political right is nowadays for increasing surveillance - and there is no one in opposition. Except probably for Pirate parties, which are mostly irrelevant.
The Liberal Democrats are against surveillance, and are the third biggest party in the UK.
The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…
There's stuff there about cryptography too, but the logging is about metadata. For metadata things are the opposite of your logic. It is always accessible. Whatever protocol you create to hide it, will have holes; Math dictates it.
Is that true though? I thought the point of protocols like Tor was that it makes gathering the metadata very very expensive.
Unfortunately in the UK you can be prosecuted for not handing over an encryption key the authorities think you have: http://www.theregister.co.uk/2008/10/14/ripa_self_incriminat... It is up to you to prove you don't have it anymore too.
Are perfect forward security protocols then illegal? What if it's physically impossible for you to give them a key that doesn't exist anymore?
Guess we're about to find out. The current government (albeit with a different (arguably more liberal) PM) has already revealed it has a desire to criminalise any crypto it can't decrypt. Because paedos and terrorists. That kind of legislation seems a natural outgrowth of this, once they find a 'think of the children' case to use as leverage. That's why we worry about the 'thin end of the wedge'.
> So although the government is a real threat to citizens privacy That's not privacy which is under threat any more. Say you visit a website of random content in January. Website goes out of business, someone else buys the domain and puts flagged content on it in September. Now... how do you prove you were visiting a different site? Trigger an archive.org call on each and every site I visit? Dig up domain name change…
Concerning historical domain data, there are several vendors (e.g. Domaintools) that provide this kind of information, and domain registrar information usually contains the registration date for the domain, so proving it was a different site is possible. You're absolutely right though that it's highly problematic if we use automated tools to analyze this kind of data, as many people can end up in the wrong category d…
Never before I protected private companies, but looking at the history if Europe, I fear governments more.
> All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If the VPN connection uses ephemeral keys (IIRC, at least IPSEC, SSH, and TLS 1.3 always use ephemeral keys, while older TLS uses them when possible), by then it's too late: the keys are gone.
You can imagine someone being locked up for this though. If you are required by law to decrypt your data, and you chose technology that does not allow this, then that's on you. To use an analogy, if you choose to ride a bike that doesn't have lights, and then get pulled over for riding without lights, the lack of lights is not a defense because you were required to have them in order to be on the road at night.
I can see one of those situations where you get held indefinitely because they obviously cannot charge you but don't want to let you go to a) prove a point and b) hopefully let the law "catch up" to this situation.