Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

81–90 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#81
post #25

What i don't get, yes you can force Facebook to implement Backdoors, but how would you do that with a opensource project like Matrix or even the full opensource Android?

You enforce it on the main providers. For Android, force Google to supply the backdoor (In Google Play Services), for Matrix force the hosted Element.io instance to provide it. Even if the project is open source and development is distributed, there is often a major entity behind it driving it on which the requirements can be enforced.

>For Android, force Google to supply the backdoor (In Google Play Services),

Again i was talking about the opensource android, not the googlified closed version.

>for Matrix force the hosted Element.io instance to provide it

How? If they are not US Citizens?

Re: Stop the Earn IT Bill Before It Breaks Encryption

#82
post #66

> The EARN IT Act cynically uses crimes against children as an excuse to hand control of online privacy and speech over to state legislatures I like the idea of federal legislature ceding power to state legislatures. Additionally, it looks like encryption is offered more protections in this bill, Considering federal laws preempt state, especially with regard to telecommunications, I do not see what the risks are with…

I don't think I've been paying enough attention but how does this work? The FBI, Police, and some congress members afaik have been talking about the going dark problem for years and now suddenly they pass a bill that explicitly protects companies from liability if they implement end to end encryption etc? Huh?! And why is EFF so wrong about this if that is correct? Maybe it has something to do with "Notwithstanding p…

Notwithstanding means in spite of paragraph 6. So 7(see above) preempts 6(see below).

“(6) NO EFFECT ON CHILD SEXUAL EXPLOITATION LAW.—Nothing in this section (other than subsection (c)(2)(A)) shall be construed to impair or limit—

“(A) any claim in a civil action brought against a provider of an interactive computer service under section 2255 of title 18, United States Code, if the conduct underlying the claim constitutes a violation of section 2252 or section 2252A of that title;

“(B) any charge in a criminal prosecution brought against a provider of an interactive computer service under State law regarding the advertisement, promotion, presentation, distribution, or solicitation of child sexual abuse material, as defined in section 2256(8) of title 18, United States Code; or

“(C) any claim in a civil action brought against a provider of an interactive computer service under State law regarding the advertisement, promotion, presentation, distribution, or solicitation of child sexual abuse material, as defined in section 2256(8) of title 18, United States Code.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#83
post #67
post #47

Earlier quoted context omitted.

And I strongly believe apathy will be the death of freedom. This is a needlessly negative outlook. Click the link, support the EFF. Educate your friends and family. Defeatism is not a compelling philosophy.

Exactly. I see this defeatism all the time regarding climate change too. It's OK to feel defeated. But why the hell would you spend energy to spread that defeatism?!

To make it less questionable.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#84
post #57
post #46

Earlier quoted context omitted.

> anyone can make their own communication platform and then the users of that platform would simply stand out in ISP logs making it actually easier to spot them. If this platform was a dedicated tool developed by/for a bad actor, then everyone working with/for that actor would be easily found. Given that, it seems that steganography (combined with encryption) could be a solution with a "battle" between steganographic…

>and then the users of that platform would simply stand out in ISP logs making it actually easier to spot them. Yeah no. Encrypted data would still be flowing all over the place, if our bad actors use VPN's to hide their traffic then it would become impossible for ISP's to see what they're doing or using. In addition, even if you can pinpoint who's using encrypted communications, unless you can prove they're actually…

>if our bad actors use VPN's to hide their traffic then it would become impossible for ISP's to see what they're doing or using

you just transfered a problem from ISP level to VPN operator level. While you could argue that using multiple VPNs from different countries could make this somewhat harder, the problem still exists. Especially if you consider metrics other than IP, for example specific packet sizes or timing patterns (for example, instead of users connecting to given IP, the adversary would look for users sending 640 byte packets every 300 seconds).

While the arguments that encryption of messages makes it impossible to know the contents of messages (and thus using the contents as evidence), however the ability to uncover the members/employees/cooperators of bad actor would make it easier to investigate them and/or use other means of targeted surveilance to obtain evidence. Also this would make it easier to infiltrate bad actor, since one of the uncovered users could be then coerced into cooperation.

(All above assumes that the app/platform is used only by members of "bad actor" and noone outside that organization is using the app. It is completely different if there are other users, perhaps even bad-actor users being a minority.)

With the developers outside jurisdiction, the problem is that while they of course might or might not be required to comply with the law, but they can still be coerced/manipulated/otherwise encouraged into providing a "patch" (backdoor) into the application.

I believe that much better solution would be to simply use any popular platform as a transport layer, with independent end-to-end encryption. Possibly with some steganography as well. The simplest example would be users exchanging memes/cat pictures - this will not stand out in any ISP/VPN traffic analysis. It will also not stand out (that much) in content analysis by any entity that can decrypt/access plain-content. The images being exchanged could then contain embedded (and end-to-end encrypted) content. While this is still far from perfect - you could imagine detection of repetitive images being sent, content/timing patterns or actual analysis of attachments for steganography but all those still require significantly more resources to work on massive scale.

Alternative would be to use custom platform but having as many "external" (in a sense of not working with/for bad actor) users as possible

Re: Stop the Earn IT Bill Before It Breaks Encryption

#85
post #25

What i don't get, yes you can force Facebook to implement Backdoors, but how would you do that with a opensource project like Matrix or even the full opensource Android?

Many options: - block access ala GFW, ensuring that most people will have difficulty accessing it or using it - block access to any data you cannot decrypt or from an endpoint you cannot backdoor - go after creators and ensure some kind of backdoor is inherent to the project - shut down projects by exerting pressure on developers - run some kind of propaganda campaign on the evils of using unsanctioned software (supp…

>go after creators and ensure some kind of backdoor is inherent to the project

>shut down projects by exerting pressure on developers

The developer probably just going to the press with that, no need to damage your own private centric project, sure the NSA can say they never did that so the developers can ignore it OR they openly say it was them, then the project just can change the country.

>run some kind of propaganda campaign on the evils of using unsanctioned software (supporting terrorism etc.)

>do nothing, knowing that most users will avoid using anything that isn't one of the major web platforms

Those are probably the only viable solutions, but on the other hand it's pure marketing for the product, like banning telegram in Russia.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#86
post #66

Earlier quoted context omitted.

I don't think I've been paying enough attention but how does this work? The FBI, Police, and some congress members afaik have been talking about the going dark problem for years and now suddenly they pass a bill that explicitly protects companies from liability if they implement end to end encryption etc? Huh?! And why is EFF so wrong about this if that is correct? Maybe it has something to do with "Notwithstanding p…

Notwithstanding means in spite of paragraph 6. So 7(see above) preempts 6(see below). “(6) NO EFFECT ON CHILD SEXUAL EXPLOITATION LAW.—Nothing in this section (other than subsection (c)(2)(A)) shall be construed to impair or limit— “(A) any claim in a civil action brought against a provider of an interactive computer service under section 2255 of title 18, United States Code, if the conduct underlying the claim const…

So what's the reason for the EFF's warning?

Re: Stop the Earn IT Bill Before It Breaks Encryption

#87

> The EARN IT Act cynically uses crimes against children as an excuse to hand control of online privacy and speech over to state legislatures I like the idea of federal legislature ceding power to state legislatures. Additionally, it looks like encryption is offered more protections in this bill, Considering federal laws preempt state, especially with regard to telecommunications, I do not see what the risks are with…

Handing national interstate matters over to states has proven to always be a terrible idea as it leads to a selective representation as they rule over far more than can vote for them. Doing so for the internet is doubly terrible given that location of all parties isn't reasonably known ahead of time nor usually relevant.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#88
post #25

What i don't get, yes you can force Facebook to implement Backdoors, but how would you do that with a opensource project like Matrix or even the full opensource Android?

It's only important to break thinks like matrix if you want to catch dedicated criminals. If you're just trying to sway elections and blackmail people then Facebook (WhatsApp) , Gmail, etc more than covers what you need. Plus if you really really want to know what's happening there, call the NSA. They'll send a few chaps to join the matrix dev community. Or they'll use other tools to access the machines in question.…

>Plus if you really really want to know what's happening there, call the NSA

Not sure if they give me any information as a Swiss citizen :-)

>They'll send a few chaps to join the matrix dev community

That's probably more on the James Bond side of reality

>Or they'll use other tools to access the machines in question

Yes that's what they probably will do, but that is targeting and not a Backdoor/break encryption by law.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#90
post #3

I strongly believe we have lost the war for privacy and security (against state level actors) already. Once the net adopted the platform model, we were screwed. Platforms are as easy to regulate, as for example the telephone companies were back in the days. They were easily forced to comply with wiretapping demands of the government. The moment a central platform controlled (most of) our communication and was able to…

Yes, we have already a working precedent with the "Ministerium für Staatssicherheit".
Post reply on HN