Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

131–140 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#131

All of you smart arses out here and there, we know it, we know. We know, VPNs and other stuff in between are not so secure and not private. Stop saying it, don't you have some other piece of knowledge to be proud of? for god's sake. Tor and Signal are better than Public Cloud, Chrome & SMS if you're looking for privacy. Don't you have common sense? - HTTPS is more secure and private than HTTP - Signal is more secure…

I mean, fair enough to a lot of the above, but you’re decrying people saying VPN’s are insecure then showing how wrong they are by talking about six otherwise unrelated security technologies.

The VPN’s people will actually use are a poor trade-off that will leave most people with a false sense of security at best, and probably with significantly less rights over what happens to their data regardless.

Don’t disagree with you on the rest of the above.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#132

All of you smart arses out here and there, we know it, we know. We know, VPNs and other stuff in between are not so secure and not private. Stop saying it, don't you have some other piece of knowledge to be proud of? for god's sake. Tor and Signal are better than Public Cloud, Chrome & SMS if you're looking for privacy. Don't you have common sense? - HTTPS is more secure and private than HTTP - Signal is more secure…

Sit down dude. You think you are standing up for rights, but are making a case for weaker security by trusting, i.e. that MS and Apple won't backdoor you in an instant if they must. You are literally, actually, a shill, especially with this pompous presentation. None of your list is better than nothing, if the authoritarians want your data. Except, maybe, Tor, and only if people contribute to running exit nodes. If i…

> If it isn't end-to-end, and only you know and control your keys, you are already doomed. In other words, you cannot trust any service with your keys. That includes https and signal.

https://en.wikipedia.org/wiki/Security-in-depth

Re: Stop the Earn IT Bill Before It Breaks Encryption

#133

I was going to call my Representative, and express my disapproval to my Senators for being on the sponsors list, when I actually read the act. I really don't see what the EFF is talking about. It seems like a very straightforward bill that makes things much better by explicitly removing any liability from companies for either having end to end encryption or for not creating backdoors. Here's my breakdown of the text…

Thank you for the summary.

I guess the gotcha is in "preventing, identifying, disrupting, and reporting X", which seems impossible to do when communication is encrypted end to end.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#134

Earlier quoted context omitted.

> Once the net adopted the platform model, we were screwed. So stop being another brick in the wall: stop using the platforms just because it is convenient. For example: * https://old.reddit.com/r/selfhosted/

There is some irony in this being a reddit link.

A better link: https://prism-break.org.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#135
post #25

What i don't get, yes you can force Facebook to implement Backdoors, but how would you do that with a opensource project like Matrix or even the full opensource Android?

Many options: - block access ala GFW, ensuring that most people will have difficulty accessing it or using it - block access to any data you cannot decrypt or from an endpoint you cannot backdoor - go after creators and ensure some kind of backdoor is inherent to the project - shut down projects by exerting pressure on developers - run some kind of propaganda campaign on the evils of using unsanctioned software (supp…

>- block access ala GFW, ensuring that most people will have difficulty accessing it or using it

depending on sofistication of that solution you could imagine some forms of tunnelling to be efficient against that (IP-over-X). Then of course due to the complexity this workaround will be used by a tiny fraction of users.

>- block access to any data you cannot decrypt or from an endpoint you cannot backdoor

steganography would be a solution to this, you can decrypt the cat pictures I'm exchanging with friends but you may not be able to notice that those images have hidden content (which may also be encrypted)

>- do nothing, knowing that most users will avoid using anything that isn't one of the major web platforms

this seems to be a guaranteed-to-succeed solution. Probably much better than

>- run some kind of propaganda campaign on the evils of using unsanctioned software (supporting terrorism etc.)

since there is always a risk that this may backfire and encourage resistance in some groups

Re: Stop the Earn IT Bill Before It Breaks Encryption

#136
post #98

The question is what is really secure? Running Telegram, over multiple VPN's? Accessing Gmail over multiple VPN's so Google doesnt get to know where you are 'really' logging on from? Making your own VPN network over a combination of AWS, G-Cloud, Azure, DO and Aliyun to 'hide' your actual location? Peoples thoughts?

I2P: https://geti2p.net.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#137
post #96
post #73

Earlier quoted context omitted.

I think tokamak meant they will be banned by law , which sadly I can see happening - it effectively happened already with napster and bittorrent in some jurisdictions.

I doubt a US ban will have much effect on a french open source project.

The US govt will just convince their Nine Eyes friends to adopt the same legislation and that's the end of that, as well.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#138
post #34

Earlier quoted context omitted.

Sadly Australia did the opposite - they can force us to backdoor applications and punish us for refusing. Australia is not the place to look for security applications.

Ah, the old penal colony mindset where the citizens are secretly prisoners.

Except it’s not a secret any more.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#140

All of you smart arses out here and there, we know it, we know. We know, VPNs and other stuff in between are not so secure and not private. Stop saying it, don't you have some other piece of knowledge to be proud of? for god's sake. Tor and Signal are better than Public Cloud, Chrome & SMS if you're looking for privacy. Don't you have common sense? - HTTPS is more secure and private than HTTP - Signal is more secure…

This tirade and "go improve it" recommendation may make sense in a vacuum, without governments undermining encryption and criminalizing parts of the activities to provide secure, private comms "because terrorism/pornography/covid/whatever".

In the real world, many states freely admit that they will fight against secure, private messaging between citizens (say, because law enforcement needs a backdoor to solve crimes). And while governments can, and do, make laws to that effect, improvement will be legislated away beyond a certain point. This also produces a chilling effect on engineering: why work on a technology that will likely be outlawed if successful?

In most cases when the government is making laws to criminalize X trying to overpower it with better engineering just does not work. My 2c.

Post reply on HN