Live data from Hacker News

European Union dedicated questionnaire on the Encryption of Data

blog.lukaszolejnik.com

61–70 of 113 posts

Re: European Union dedicated questionnaire on the Encryption of Data

#61
post #26
post #15

Earlier quoted context omitted.

Well I'm sure some people lost the respect for the guy after he jumped on the "vote for Hillary" bandwagon. But yeah, things like the Snowden interview, Net Neutrality and some other episodes are simply brilliant.

And he was right there is no 3rd option in the US election system.

Exactly, time to move on now that fake choice #2 won the election.

Almost comical how easily and predictably we stay on track in terms of bread and circuses politics/media - almost comical - if it weren't all real and there wouldn't be far reaching and dire consequences.

Let's not get played but stick together FFS.

Re: European Union dedicated questionnaire on the Encryption of Data

#62
post #5

Surprisingly interesting content for the clickbaity headline: Some excerpts from a questionnaire about how law enforcement deals with encryption answered by various EU governments, with esp. Poland calling for backdoors or weakened encryption. The full answers are here: https://www.asktheeu.org/en/request/input_provided_by_ms_on_...

Poland...calling for weakened encryption and backdoors. Students are going to be so confused when they see that 4 chapters after WWII in their history books.

Re: European Union dedicated questionnaire on the Encryption of Data

#63

Earlier quoted context omitted.

What about plausible deniability keys? 1 password hides the real stuff, and the second one that you give to the police just gives them access to your porn collection (which someone very well might want to hide!).

Well, they don't matter wrt. the law. Either the prosecution is convinced you gave up all the keys (you win), or they believe you gave them a key that was just a distraction and they throw you in jail unless you give them the other key (you lose).

Which is terrifying, as the whole point of plausibly deniable passwords is that attitude will end up with innocent people in jail for data that doesn't exist have.

Re: European Union dedicated questionnaire on the Encryption of Data

#64
post #60

I find the german answers [1] surprisingly reasonable. High Five for the final answer: > 11. Are there other issues that you would like to raise in relation to encryption and the possible approach to these issues? Please share any relevant national experience or considerations arising from your practice that need to be taken into account. > Yes. A regulation to prohibit or to weaken encryption for telecommunication a…

I come from Germany. The situation is complicated. The responsible politicians tend to make statements that are contradicting or don't make any sense. There have been multiple statements that at least could be interpreted as supportive of encryption regulation. In one occasion there was a joint statement by the french and german ministers of interior - with the slight problem that the french and german versions of th…

On the other hand, it has a larger constituency in government who oppose undermining encryption than most other western nations and a good negative example in the recent past (the Stasi). Just look at the recent legislation passed in the UK, and the statements of Theresa May on encryption or the recent lawsuits by the FBI against Apple. It may be our best hope in stopping legislation mandating backdoors to encryption, which would damage everyone.

Re: European Union dedicated questionnaire on the Encryption of Data

#65
post #38
post #4

Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…

Almost nobody is entirely innocent under the law when sufficient scrutiny is applied, so giving LEO access to your computer invites a fishing expedition. IMO.

Yep. I had that happen. Someone tipped the police that me and some friends were hacking computers and stealing credit cards. We were raided, gave access to the police to our computers, they found nothing related to cc fraud (of course) but then prosecuted us for some pirated games they found.

Re: European Union dedicated questionnaire on the Encryption of Data

#66
post #38
post #4

Smart criminals will use strong encryption anyway and won't give the passwords to law enforcement both for data at rest and sent over the Internet. I'm encrypting my disk now, but I'll give the password to police if they have a search warrant. I'm encrypting so if somebody steals my computer they won't read my data. I think that almost everybody is like me. Weakening that encryption doesn't help me and doesn't help i…

Almost nobody is entirely innocent under the law when sufficient scrutiny is applied, so giving LEO access to your computer invites a fishing expedition. IMO.

No almost about it.

"Give me six terabytes of data from the most honest of men and I will find something in them which will hang him. Probably before I make it past the boot sector." - Cardinal Richelieu

Re: European Union dedicated questionnaire on the Encryption of Data

#67
post #40

Earlier quoted context omitted.

On the other hand, not giving your password right away may be interpreted as an indication that you have something to hide (which you inevitably do), and they may tag you for even further scrutiny. Also, UK: don't give your password, go to prison. Indefinitely.

Please stop spreading FUD about RIPA, there is no "indefinitely" involved, the maximum sentence is two years, unless it relates to child indecency, in which case the maximum sentence is increased to five years. [1] [1] https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...

I've heard the judge can then ask you again, and you can go back to jail if you refuse, because that's a separate offense or something.

Re: European Union dedicated questionnaire on the Encryption of Data

#68

Earlier quoted context omitted.

What about plausible deniability keys? 1 password hides the real stuff, and the second one that you give to the police just gives them access to your porn collection (which someone very well might want to hide!).

Well, they don't matter wrt. the law. Either the prosecution is convinced you gave up all the keys (you win), or they believe you gave them a key that was just a distraction and they throw you in jail unless you give them the other key (you lose).

How do you prove yourself innocent then? You did give them the keys.

The point is that you look exactly the same as an innocent person.

You are taking the only possible pathway to being proved innocent.

It'd be like if I were to say "It doesn't matter what you do. The police are corrupt anyway, and will take you out back and shoot you no matter what. Guilty or innocent, if you get accused of a crime, you are dead."

And if they are going to lock you up no matter what, then you may as well use multiple plausible deniability keys. As you said, it doesn't matter what you do, the outcome stays the same.

Re: European Union dedicated questionnaire on the Encryption of Data

#69
post #60

I find the german answers [1] surprisingly reasonable. High Five for the final answer: > 11. Are there other issues that you would like to raise in relation to encryption and the possible approach to these issues? Please share any relevant national experience or considerations arising from your practice that need to be taken into account. > Yes. A regulation to prohibit or to weaken encryption for telecommunication a…

I come from Germany. The situation is complicated. The responsible politicians tend to make statements that are contradicting or don't make any sense. There have been multiple statements that at least could be interpreted as supportive of encryption regulation. In one occasion there was a joint statement by the french and german ministers of interior - with the slight problem that the french and german versions of th…

> Germany isn't the privacy paradise that some people in the international debates sometimes like to see in it.

In comparison with pretty much everyone else, it is.

Re: European Union dedicated questionnaire on the Encryption of Data

#70
post #60

I find the german answers [1] surprisingly reasonable. High Five for the final answer: > 11. Are there other issues that you would like to raise in relation to encryption and the possible approach to these issues? Please share any relevant national experience or considerations arising from your practice that need to be taken into account. > Yes. A regulation to prohibit or to weaken encryption for telecommunication a…

I come from Germany. The situation is complicated. The responsible politicians tend to make statements that are contradicting or don't make any sense. There have been multiple statements that at least could be interpreted as supportive of encryption regulation. In one occasion there was a joint statement by the french and german ministers of interior - with the slight problem that the french and german versions of th…

> Recently they created a new institution supposed to help decrypting messages.

BSI? They're not new

Post reply on HN