Live data from Hacker News

German court forces mail provider Tutanota to insert a backdoor

heise.de

61–70 of 103 posts

Re: German court forces mail provider Tutanota to insert a backdoor

#61

Earlier quoted context omitted.

I mean if your code is open source, and you get an order to insert a backdoor of some kind, how can you put the backdoor in the open source code without violating a nondisclosure clause in the government’s order?

Law overrides contract, so if distributing those changes is prohibited, then not distributing those changes to code is not a violation of the open source licence, the relevant clauses of the licence contract can not be legally binding. So you'd just [be required to] keep a non-open fork of that code even if the license (e.g. AGPL) would prohibit that.

I don't think a law requiring you to not distribute the changes overrides the license clauses terminating your license for not distributing them? It's not the license givers problem that you can't comply with the license, don't use it then?

Re: German court forces mail provider Tutanota to insert a backdoor

#62

Encryption is the only thing that forces law enforcement to use warrants, without it it's just a wild wild west of privacy abuse. I do hope we see more services crop up, and new methods for people to encrypt email outside of specific services, maybe better plugins for Thunderbird or something, hell I'd easily pay for such a plugin if someone else can communicate back and forth with me through it and it is encrypted.…

We generally accept that warrants are a reasonable solution when it comes to the state entering private property without permission for law enforcement purposes. This also seems like a reasonable solution for encryption. The state here is not making or trying to make encryption illegal; and it is open about the fact that court authorisation is required to enforce a backdoor.

A backdoor is never a solution. It can, and will, always be abused. Furthermore, warrants are also trivially abused which I have seen done first hand.

Re: German court forces mail provider Tutanota to insert a backdoor

#63
post #37

Earlier quoted context omitted.

You mean so that they do not leak the affected email address?

I mean if your code is open source, and you get an order to insert a backdoor of some kind, how can you put the backdoor in the open source code without violating a nondisclosure clause in the government’s order?

Probably they could make the code open and just leave the specific accounts targeted to be set as an environment variable.

Re: German court forces mail provider Tutanota to insert a backdoor

#64
post #45
post #12

I was planning to migrate to Tutanota, I guess I will not be doing so after all

Realistically speaking, is there jurisdiction where this isn't a threat? Most governments allow for wiretaps (basically what this "backdoor" is) when there's a warrant, so I'm not sure what the alternative is. Not even self-hosting works because they can seize your server/ip/domain name and install a backdoor there.

Unless if your server has full drive encryption

Re: German court forces mail provider Tutanota to insert a backdoor

#65

I suppose the employees at Tutanota can do what the employees at Apple did: they could threaten to quit if they are instructed to work on this.

Would there be some way of wording a contractual agreement with a company such that all of their customers contracts would irrevocably end if such a backdoor were installed. Tutanota should consider ceasing trading in response to this. Surely the court won’t force them to not just stop supplying email services to everyone.

Re: German court forces mail provider Tutanota to insert a backdoor

#66
post #61

Earlier quoted context omitted.

Law overrides contract, so if distributing those changes is prohibited, then not distributing those changes to code is not a violation of the open source licence, the relevant clauses of the licence contract can not be legally binding. So you'd just [be required to] keep a non-open fork of that code even if the license (e.g. AGPL) would prohibit that.

I don't think a law requiring you to not distribute the changes overrides the license clauses terminating your license for not distributing them? It's not the license givers problem that you can't comply with the license, don't use it then?

Of course, not using that license and stopping the use of that code is also a completely valid (though costly) option.

If the licence giver believes that you're violating the contract, they are free to try and enforce that contact in court. A German court would almost certainly rule that the clause is unenforceable at least as it applies to that particular order-related modification (the licence requirements would still be valid for unrelated modifications). There is a nontrivial legal question whether that would imply that the requirement voids the licence as a whole or just the specific clause. Specific terms (e.g. AGPL clause 12) may suggest that it would void the whole licence, but I wouldn't be certain on how German courts would consider it given these specific circumstances; a German lawyer might have a good idea but I do not.

But in any case, contractual obligations are not an excuse for noncompliance with other legal requirements. If it does turn out that executing the order is incompatible with a particular license, then you must execute the order anyway and decide what's the best way to handle the consequences. Breaching a contract is a legally valid option as well, and in some cases that may even be the best option, if the expected liabilities/damages are less than the consequences of complying with it.

Re: German court forces mail provider Tutanota to insert a backdoor

#67
post #52

Earlier quoted context omitted.

I wonder how a company that uses 100% open source software would comply with an order like this. def decrypt_email?(email) do email in surveilance_order_emails() end

They will do what reddit did, keep "sensitive" additions to your system closed, and if you are not distributing it, you are not required to publish it. Just watch out for AGPL.

Just read the list of bad people from a config file?

Re: German court forces mail provider Tutanota to insert a backdoor

#68
post #61

Earlier quoted context omitted.

I don't think a law requiring you to not distribute the changes overrides the license clauses terminating your license for not distributing them? It's not the license givers problem that you can't comply with the license, don't use it then?

Of course, not using that license and stopping the use of that code is also a completely valid (though costly) option. If the licence giver believes that you're violating the contract, they are free to try and enforce that contact in court. A German court would almost certainly rule that the clause is unenforceable at least as it applies to that particular order-related modification (the licence requirements would st…

Tutanotas business is predicated on privacy, and on relying on open source. If the government requires them to disconnect from both, they are destroying the entire business. Imagine if they lost the right to use their foss systems because of this and the cost of starting a closed source replacement. Tutsnkta will already vanish overnight from every single privacy respecting app list. They could get sued for misrepresentation also. Shouldn’t the government at least be liable for compensating them for damages?

This is a death blow

Re: German court forces mail provider Tutanota to insert a backdoor

#69

Earlier quoted context omitted.

> Fun fact: Norway is not a member of the EU. Which I think is a shame. Sweden and Norway together would have a net positive influence on modernizing law across the EU. (I'm saying that as a German)

Sweden already is part of the EU.

I'm just saying that Sweden, Norway and Finland together would make an awesome couple; given how they overcame legislative issues and how they modernized their countries against all odds (with all that happened after 1808).

From a political perspective they're quick to adapt to a changing landscape.

Re: German court forces mail provider Tutanota to insert a backdoor

#70
post #6

I worked in the telecom industry, and knowing how much surveillance related regulations was there, I can't believe true e2e encryption is a thing on the internet. I'm surprised how so many people in tech believe that a messaging application like WhatsApp is allowed to have real e2e encryption. It's impossible for regulators to ignore a platform with substantial traffic.

[deleted]
Post reply on HN