Live data from Hacker News

Facebook, WhatsApp Will Have to Share Messages With U.K.?

bloomberg.com

311–320 of 591 posts

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#311

Earlier quoted context omitted.

> Are they going to outlaw encryption libraries? Funny story about that, those used to be considered controlled munitions [0]. [0] http://www.treachery.net/~jdyson/crypto/tattoo.html

TBH, I thought encryption was still subject to ITAR rules and considered "munitions" in the US?

The current situation looks like it still has a whole ton of potential legal tripping points, from Wikipedia:

As of 2009, non-military cryptography exports from the U.S. are controlled by the Department of Commerce's Bureau of Industry and Security. Some restrictions still exist, even for mass market products, particularly with regard to export to "rogue states" and terrorist organizations.

Militarized encryption equipment, TEMPEST-approved electronics, custom cryptographic software, and even cryptographic consulting services still require an export license.

Furthermore, encryption registration with the BIS is required for the export of "mass market encryption commodities, software and components with encryption exceeding 64 bits" (75 FR 36494). In addition, other items require a one-time review by, or notification to, BIS prior to export to most countries. For instance, the BIS must be notified before open-source cryptographic software is made publicly available on the Internet, though no review is required. Export regulations have been relaxed from pre-1996 standards, but are still complex. Other countries, notably those participating in the Wassenaar Arrangement, have similar restrictions.

https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#312

The idea that moves like this will "keep us safe" is utterly preposterous; there are a multitude of other ways in which terrorists (or the boogeyman de jour ) could communicate - are the UK and US governments going to insist on backdooring IRC, Slack and face-to-face conversations? Are they going to outlaw encryption libraries? I truely fear for the future that western governments, in particular the 5 eyes members, a…

>moves like this are to keep us safe From the government's perspective, they are to keep "us" safe. It's easier to do that if no one's safe from us. :) Granted, that's a little over-ominous because the government's mission statement is to keep its people safe, and it's also elected by its people. Either of these two facts changing is the way bigger danger; backdooring centralized services is stuff that happens in the…

If you look at the way elections work at a micro scale in the US, you will begin to lose confidence in the assumption that they are elected by the people. Political machines have huge influence in controlling who it's possible to vote for, and swaying low-information voters. That makes sure they have a lockdown on decision-making, even if they allow a few mavericks through the cracks for the sake of plausible deniability.

Even if this or that individual politician gets voted out, or even ten of them, it won't stop the machine's influence. They're still the ones who decide who the replacements can be chosen from.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#313
post #282

Earlier quoted context omitted.

Thanks for clarifying and stating your opinion about the quality of my comment. However, seems a bit too broad-stroke to use downvoting for both the (lack of) quality of the comment and to express disagreement.

I do not personally have downmod capabilities, but I don't think it is necessarily too broad: If you interpret it as "People shouldn't read this", it seems reasonable.

I think equating "I disagree" with "people shouldn't read this" is problematic for a forum that wants to encourage discourse.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#314

Yes, this is something that literally everyone who reads HN will oppose. Meanwhile do you hear the deafening silence from the average Joe who thinks he has "nothing to hide"? Don't hate the politicians who keep pushing this. They're just trying not to get fired. And the surest way to get fired in a western country right now is to be seen doing nothing about the terrorism problem and then having terrorist acts committ…

It is not the question if you have something to hide or not but once they have unlimited access like this, what is stopping them from manufacturing truth and bend the information to support their biases. Privacy IMO is more important.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#315

At what point did the world adopt the standard that all private communication is government business ?

As a lot of other things, it happened step by step, with the main catalyst being 9/11. We somehow accepted that it's an acceptable trade-off to have no privacy in the name of stopping "the terrorists".

"You're either with us, or a terrorist" Bush once said. And now we're at a stage where it's acceptable to say things like "if you've got nothing to hide, why are you so worried about this stuff?".

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#316

The idea that moves like this will "keep us safe" is utterly preposterous; there are a multitude of other ways in which terrorists (or the boogeyman de jour ) could communicate - are the UK and US governments going to insist on backdooring IRC, Slack and face-to-face conversations? Are they going to outlaw encryption libraries? I truely fear for the future that western governments, in particular the 5 eyes members, a…

Disagree on hypocrisy. US still affords significant freedoms and largely respects human rights. Whether your communications can be decrypted or intercepted on networks that are government regulated anyway is not hypocritical. Residents of the US are still free to use whatever mathematical algorithm they want to encrypt their comms. Transporting OTP's across physical borders is trivial, and not technically illegally i…

Assuming that US citizens are safe, that doesn't apply to citizens of other countries. So even it the US and the UK respect their own citizens' rights (Snowden showed they don't) they won't respect other people's rights. And then surveillance becomes a tool against a countries and policies the US and UK don't agree with regardless if these are a genuine threat or not. So yeah, it is kind of a big problem.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#317
post #198

Does anyone have any advice for what platform might be best to migrate to? I'm not overly concerned with group E2E, but it is a nice-to-have. Telegram and Discord seem like two of the most practical options, Keybase and Matrix seem like two of the most ideal from a security standpoint. I wonder what offers the best cross-section of features and user experience.

Telegram is not EtE encrypted by default. Only special “private chats” are and they unavailable on desktop.

Yeah, I am aware of that. E2E isn't necessarily a hard concern, but E2E with backdoors actually feels worse to me than just not having E2E to begin with (I do wish Telegram were less misleading about this issue, however.)

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#318

Earlier quoted context omitted.

> In the US, ITAR could hypothetically be used to make open-sourcing of cryptographic algorithms illegal. Wikipedia has some good info re: export of cryptography[0]. In addition, two circuits (Ninth[1] and Sixth[2]) have ruled that source code is protected by the First Amendment. [0]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... [1]: https://en.wikipedia.org/wiki/Bernstein_v._United_States [2]: htt…

This case law only applies as long as the algorithm is not classified. As soon as any Original Classification Authority classifies the algorithm, it falls under a new category on the U.S. Munitions List and the government could then restrict its distribution. Obviously, classifying something that has already been open source just makes it more difficult to use and numerous local copies will be retained, but it does m…

Signal doesn't have to be distributed from the US though (well, apk for sideloading at least, app stores are US based..)

OpenBSD in the 90s used to emphasize that they're from Canada and have strong crypto because of that.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#319

The idea that moves like this will "keep us safe" is utterly preposterous; there are a multitude of other ways in which terrorists (or the boogeyman de jour ) could communicate - are the UK and US governments going to insist on backdooring IRC, Slack and face-to-face conversations? Are they going to outlaw encryption libraries? I truely fear for the future that western governments, in particular the 5 eyes members, a…

> Are they going to outlaw encryption libraries? Funny story about that, those used to be considered controlled munitions [0]. [0] http://www.treachery.net/~jdyson/crypto/tattoo.html

When you submit apps to Apple, you _still_ have to declare if your app uses encryption.

https://developer.apple.com/documentation/security/complying...

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#320
post #234

The idea that moves like this will "keep us safe" is utterly preposterous; there are a multitude of other ways in which terrorists (or the boogeyman de jour ) could communicate - are the UK and US governments going to insist on backdooring IRC, Slack and face-to-face conversations? Are they going to outlaw encryption libraries? I truely fear for the future that western governments, in particular the 5 eyes members, a…

Still remember how one German Islamist terror group just used their web-email provider's draft feature. They never 'sent' anything. There are often quite simple ways to circumvent this kind of thing.

Good, but your e-mail provider can still see it. And be forced to eavesdropping.

Back in '90s I used a nym e-mail to receive e-mails anonymously and with no traces.

In a few words - e-mails are encrypted with your PGP key and posted to Usenet groups, where you scan all messages and extract only those signed&encrypted with your key.

https://en.wikipedia.org/wiki/Pseudonymous_remailer

Yep, there are 1000 and 1 method of communicating securely. Governments are just using this as an excuse to wiretap popular messaging services for general surveillance.

Unless they'll get away with making everyone dumber, they shall fail.

Post reply on HN