Live data from Hacker News

European Union dedicated questionnaire on the Encryption of Data

blog.lukaszolejnik.com

71–80 of 113 posts

Re: European Union dedicated questionnaire on the Encryption of Data

#71
post #60

Earlier quoted context omitted.

I come from Germany. The situation is complicated. The responsible politicians tend to make statements that are contradicting or don't make any sense. There have been multiple statements that at least could be interpreted as supportive of encryption regulation. In one occasion there was a joint statement by the french and german ministers of interior - with the slight problem that the french and german versions of th…

> Recently they created a new institution supposed to help decrypting messages. BSI? They're not new

I guess GP was referring to ZITIS, not BSI.

BSI's job generally is ensuring IT security, not breaking it.

Even the weirder jobs they're tasked with, such as certifying backdoor software for LEAs, it's not about ensuring its operation as a backdoor, but that it only does the designated job (and in particular doesn't bring additional capabilities that are outside their charter)

Re: European Union dedicated questionnaire on the Encryption of Data

#72
"wants to regulate cryptography"??? - I suggest it's already in place. For example, if you wish to create crypto software or hardware (or in some cases even simply importing a crypto library) - for 2 sides to communicate requires sharing either the source, software binaries, or hardware itself - and if 1 of those is outside of the country then obviously export and/or import of the source/sw/hw occurs and therefore crypto controls come into effect.

Re: European Union dedicated questionnaire on the Encryption of Data

#74
post #28

Earlier quoted context omitted.

> " I really do hope that we won't follow USA steps this time." In what way, exactly? Europe is farther down this path than the US is currently.

Is it? NIST has been putting backdoors in recommended encryption standards. USA State Department also classifies strong cryptography as a munition. As far as I know we don't do similar things in Europe (yet?), but I could be wrong.

Europe has dual-use tech export controls - http://www.wassenaar.org/

They're as meaningless as the American versions, only randomly ensnaring companies that sell to a doubleplus ungood entity. They don't do anything to stem the flow of crypto information or open source software to all parts of the globe.

And that NIST thing happened possibly once. It's not a common ongoing occurrence.

Re: European Union dedicated questionnaire on the Encryption of Data

#75
post #40

Earlier quoted context omitted.

Please stop spreading FUD about RIPA, there is no "indefinitely" involved, the maximum sentence is two years, unless it relates to child indecency, in which case the maximum sentence is increased to five years. [1] [1] https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...

I've heard the judge can then ask you again , and you can go back to jail if you refuse, because that's a separate offense or something.

Do you have a written citation for that, something from Out-Law.com (or equivalent), or from a qualified solicitor or barrister, which backs up the "I've heard..." up a little?

Not trying to be a hard ass, but I don't think HN benefits from people spreading "legal facts" (c.f. indefinite imprisonment) with an authoritative written tone but without citing legal precedent, or a detailed analysis of the statute in question.

I'm not a lawyer but I imagine if you were taken in front of the same Magistrate's Court or Crown Court, refused to decrypt the _same_ data a second time, were convicted under RIPA, sentenced, you'd have a damn good argument at appeal and it would very likely be quashed. IANAL.

To put more substance behind this opinion, we can look at the Sentencing Council, which when drawing up sentencing guidance, frequently uses the term "fair and proportionate" [1] which is something of a cornerstone remark about how the judiciary should go about dealing with infractions of the law. Reasonable humans would say going to prison twice for the same thing is neither fair, nor proportionate.

[1] https://www.sentencingcouncil.org.uk/news/item/new-sentencin...

Re: European Union dedicated questionnaire on the Encryption of Data

#76

Earlier quoted context omitted.

Well, they don't matter wrt. the law. Either the prosecution is convinced you gave up all the keys (you win), or they believe you gave them a key that was just a distraction and they throw you in jail unless you give them the other key (you lose).

How do you prove yourself innocent then? You did give them the keys. The point is that you look exactly the same as an innocent person. You are taking the only possible pathway to being proved innocent. It'd be like if I were to say "It doesn't matter what you do. The police are corrupt anyway, and will take you out back and shoot you no matter what. Guilty or innocent, if you get accused of a crime, you are dead." A…

> How do you prove yourself innocent then? You did give them the keys.

Well, prosecution needs to have a legally convincing argument that indicates it is likely you have another encrypted partition you're not giving up keys to.

In fact, the situation is no different from this: say you're a murder suspect and a neighbour saw you carrying several large heavy sacks into your car and you drove away. Say what really happened is that you went and buried some bags of toxic waste in some location, and then went and buried a dead body in another location. When asked by prosecution, you confess to burying toxic waste and tell them where. The rest of the outcome of the trial depends entirely on whether you've successfully convinced them that you just buried the toxic waste.

Re: European Union dedicated questionnaire on the Encryption of Data

#77
post #60

I find the german answers [1] surprisingly reasonable. High Five for the final answer: > 11. Are there other issues that you would like to raise in relation to encryption and the possible approach to these issues? Please share any relevant national experience or considerations arising from your practice that need to be taken into account. > Yes. A regulation to prohibit or to weaken encryption for telecommunication a…

I come from Germany. The situation is complicated. The responsible politicians tend to make statements that are contradicting or don't make any sense. There have been multiple statements that at least could be interpreted as supportive of encryption regulation. In one occasion there was a joint statement by the french and german ministers of interior - with the slight problem that the french and german versions of th…

> (I mean you simply can't decrypt properly designed crypto systems.)

Luckily most deployed crypto isn't properly designed :)

Re: European Union dedicated questionnaire on the Encryption of Data

#78
post #71

Earlier quoted context omitted.

> Recently they created a new institution supposed to help decrypting messages. BSI? They're not new

I guess GP was referring to ZITIS, not BSI. BSI's job generally is ensuring IT security, not breaking it. Even the weirder jobs they're tasked with, such as certifying backdoor software for LEAs, it's not about ensuring its operation as a backdoor, but that it only does the designated job (and in particular doesn't bring additional capabilities that are outside their charter)

Yes, I was referring to ZITIS.

> BSI's job generally is ensuring IT security, not breaking it.

Unfortunately that's also not true. The role of the BSI is very mixed and they have a role as both being offensive and defensive. Which is one of the problems. They're not trustworthy.

Re: European Union dedicated questionnaire on the Encryption of Data

#79
post #71

Earlier quoted context omitted.

> Recently they created a new institution supposed to help decrypting messages. BSI? They're not new

I guess GP was referring to ZITIS, not BSI. BSI's job generally is ensuring IT security, not breaking it. Even the weirder jobs they're tasked with, such as certifying backdoor software for LEAs, it's not about ensuring its operation as a backdoor, but that it only does the designated job (and in particular doesn't bring additional capabilities that are outside their charter)

I sometimes wish BSI had more teeth (e.g. when it comes to stuff like reviewing official backdoor trojans, it's annoying that we need private initiatives and the constitutional court every single time, although that keeps the topic hot), on the other hand it also has a strong whiff of incompetence and bureaucracy that I don't want to see with actual power.

Re: European Union dedicated questionnaire on the Encryption of Data

#80

Earlier quoted context omitted.

This. In the U.S. at least, the 5th amendment gives you the right not to incriminate yourself. A search warrant doesn't change that. Not all authentication methods are equal it appears. Fingerprint, facial recognition, other bio-metrics aren't considered the same as if you need to "speak" your password to someone. In other words, they can make you scan your finger or look into a camera, but they can't force you to te…

Yes, there is a distinction in US law between acquiring physical and "mental" evidence. The former can be forced (e.g. I must provide my safe key) and the latter cannot (e.g. I don't have to reveal my password). The line gets blurry: keyed lock vs combination lock, password vs SSH key.

> (e.g. I must provide my safe key)

Surely you don't need to participate in the activity? They are just allowed to take and use it, I assume?

Post reply on HN