Live data from Hacker News

U.S. government seeks Facebook help to wiretap Messenger

reuters.com

71–80 of 109 posts

Re: U.S. government seeks Facebook help to wiretap Messenger

#71

Article on HN: "The government shouldn't be trying to do this, we need encryption, decentralized services" Article on Reddit: "Delete Facebook! Fuck Zuckerberg."

One is a consumer’s answer, the other one is a creator’s answer.

Makes sense, as these are the respective target audiences of the two communities.

Re: U.S. government seeks Facebook help to wiretap Messenger

#72

Earlier quoted context omitted.

Is it? You kind of lost me. Isn't the actual issue math?

It's this: https://xkcd.com/538/

set up the device to wipe itself after $x number of incorrect attempts. keep giving the wrong password after every whack from the wrench. then you have plausible deniability. "how can i possibly think straight when you keep hitting me with that wrench?" just need to make $x a value small enough that you can survive the wrench.

Re: U.S. government seeks Facebook help to wiretap Messenger

#73

The other day i posted a rant on p2p here on HN and everyone was like, huh! Use whatsapp. We need to build our own p2p and e2e secure chat client like whatsapp which works on every platform. Sure, it's possible - skype was exactly this before except for the e2e part. Why we techies can't? Let's make a group and dissect the problem in our free time. Who is up for it?

Some people are working on this problem. You might be interested in looking at the Matrix standard [0] or some of the things built using it like Riot [1], a Slack-like web client supporting text, voice and video communication for one-on-one or group contexts.

0: https://matrix.org/docs/guides/faq.html

1: https://about.riot.im/what-is-riot/

Re: U.S. government seeks Facebook help to wiretap Messenger

#74

Earlier quoted context omitted.

It's this: https://xkcd.com/538/

set up the device to wipe itself after $x number of incorrect attempts. keep giving the wrong password after every whack from the wrench. then you have plausible deniability. "how can i possibly think straight when you keep hitting me with that wrench?" just need to make $x a value small enough that you can survive the wrench.

No good, it is already standard for forensic teams to clone and checksum a hardrive before attempting to look through files. The clone is sent to evidence and any password attempts will be made on a copy. The "original" copy will be kept safe and any number of passwords can be used against nth iteration of copying the clone.

Re: U.S. government seeks Facebook help to wiretap Messenger

#75
post #4

I think it has become abundantly clear that a fully peer to peer, encryption required (non-optional), no single central server infrastructure solution is the answer. No points to tap. No point in tapping the data. If they want to capture conversations it's time to go back to the proper old ways of actually spying on high-value targets.

This discussion should never be framed as a choice between legal solutions and technical solutions. They are complementary.

The legal approach is correct and easy for the public to understand. Explained correctly it is also popular. The government used to have to do things like get a warrant and investigate specific crimes. They couldn't listen to everyone's phone conversations all the time and they shouldn't be able to do this on the Internet either. Digital dragnets are illegal and unconstitutional.

The technical approach is also correct. If you're building something that makes it harder for criminals inside the government to commit more crimes, you're doing work that is profound and in the best interests of society. Anyone with passion and technical skill can participate in this work. It's the right thing to do.

Both efforts help each other. Keep the government in line and accountable to the people. Make it harder for people inside the government to do the wrong thing. All approaches deserve support and should leverage each other's work. They should cooperate with law-abiding, constitutionally empowered government authorities as well. There are good guys in the government too.

Re: U.S. government seeks Facebook help to wiretap Messenger

#76
post #74

Earlier quoted context omitted.

set up the device to wipe itself after $x number of incorrect attempts. keep giving the wrong password after every whack from the wrench. then you have plausible deniability. "how can i possibly think straight when you keep hitting me with that wrench?" just need to make $x a value small enough that you can survive the wrench.

No good, it is already standard for forensic teams to clone and checksum a hardrive before attempting to look through files. The clone is sent to evidence and any password attempts will be made on a copy. The "original" copy will be kept safe and any number of passwords can be used against nth iteration of copying the clone.

Isn't this the purpose of the secure enclave on iPhones? Taking the drive away from the secure enclave makes the drive useless and the enclave only allows a few password attempts.

Re: U.S. government seeks Facebook help to wiretap Messenger

#77
post #4

I think it has become abundantly clear that a fully peer to peer, encryption required (non-optional), no single central server infrastructure solution is the answer. No points to tap. No point in tapping the data. If they want to capture conversations it's time to go back to the proper old ways of actually spying on high-value targets.

This discussion should never be framed as a choice between legal solutions and technical solutions. They are complementary. The legal approach is correct and easy for the public to understand. Explained correctly it is also popular. The government used to have to do things like get a warrant and investigate specific crimes. They couldn't listen to everyone's phone conversations all the time and they shouldn't be able…

Technical and legal solutions are not complementary, they're relatively unrelated. Legal rules addressing behavior are about what we "should" do. Technical rules are about what we "can" do. Technology is about implementation and enforcement, law is about what we consider to be the correct result.

But the main place where law and tech come together is enforcement. For law to work at all, it has to be enforced relatively evenly. Technology may make a law's enforcement impossible or easy, but it does not make it more or less "right" in the abstract.

Re: U.S. government seeks Facebook help to wiretap Messenger

#78
post #4

I think it has become abundantly clear that a fully peer to peer, encryption required (non-optional), no single central server infrastructure solution is the answer. No points to tap. No point in tapping the data. If they want to capture conversations it's time to go back to the proper old ways of actually spying on high-value targets.

Isn’t this what Slack is?

You're thinking of Signal.

Re: U.S. government seeks Facebook help to wiretap Messenger

#79
post #4

I think it has become abundantly clear that a fully peer to peer, encryption required (non-optional), no single central server infrastructure solution is the answer. No points to tap. No point in tapping the data. If they want to capture conversations it's time to go back to the proper old ways of actually spying on high-value targets.

P2P routing is hard (nat bypass only really works on 80-90% of networks which is not good enough and Tor is unviable for mass adoption), and decentralized identifiers are generally not liked by users

Other than that, it's doable.

Spam protection and censorship (necessary for mobile app stores) can be distributed as opt-out blacklists. If it gets to be a huge problem then a "enter this password to add me" type thing could work too.

I've been compiling a bunch of ideas as such for fully P2P decentralized/encrypted chat, but I'm stuck at the two issues I mentioned earlier.

Re: U.S. government seeks Facebook help to wiretap Messenger

#80
post #53

Earlier quoted context omitted.

> Possession of encryption software could be treated the same as possession of drugs It's too late for that, every machine, every browser, every user is using encryption software all the time.

"It's too late to criminalize prostitution, every is already having sex" "It's too late to criminalize possession of drugs. Half the country takes pharmaceuticals!"

The War on Drugs is considered a failure and in parts of the world like NSW, Australia made prostituion legal in 1979 in both cases because criminalising things most people use generally doesn't work and all you do is randomly jail people for doing the exact same thing as a large proportion of the population.
Post reply on HN