Live data from Hacker News

ProtonMail, Tutanota urging EU to reconsider encryption rules

cyberscoop.com

11–20 of 85 posts

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#11
post #6

It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.

Can't we have E2EE+G? (end-to-end encryption, plus government can see everything) Not saying this is a good idea, though.

Yes, by giving the government access to one or both of the end devices. (Which is probably already a thing somewhere legally, and very likely is the factory state for some Android phones.)

Note that banning E2EE implies banning encrypted p2p communications entirely. E2EE is a concept that applies only to centralized comms providers where all messages go through a server.

Practically speaking, it's impossible to ban every encrypted protocol (TLS, SSH, ...). It's also (probably) impossible to ban IP communications that don't have an "approved server" participating.

However, comms providers / social networks to date at least manage, authenticate, and introduce users at the serverside. Fully distributed projects have problems with spam. So governments would have to ban comms providers from "allowing" their clients to talk to each other directly and not via the backend. That's a hefty technological restriction, which would block a wide range of protocols (webrtc/SIP, torrents, probably a bunch of other Very Important things I'm not thinking of right now).

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#12

It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.

As far as I understood, the problem stems from the Crypto AG era. Governments are addicted to be able to listen to communications of everyone and don't want to lose their toys. Also, EU is far more advanced in terms of invisible security so, they don't want to lose the tools which enable them to do it. We need to re-think security and people are lazy about it because, it's hard. Edit: My English gets a hit when I'm l…

In no way whatsoever is the eu far more advanced at anything at all. U are either a robot for them or some paid product placement. Go away eu

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#13
post #6

It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.

Can't we have E2EE+G? (end-to-end encryption, plus government can see everything) Not saying this is a good idea, though.

If you allow the +G, you allow hackers. It's as simple as that. If you want security, you can't have backdoors.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#14
post #6

It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.

Can't we have E2EE+G? (end-to-end encryption, plus government can see everything) Not saying this is a good idea, though.

Yes, it is possible. You have to encrypt session key with government public key and include that encrypted data with your session. Government can decrypt that data with their private key. I think that's a pretty reasonable scheme as long as government private key managed by a competent organization (e.g. NSA). HSM makes it impossible to easily extract private key and military guard and other physical security measures makes it impossible to steal HSM.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#16

It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.

It's a trade-off.

Of course I want to preserve my privacy.

But I get it that law enforcement wants to be able to look into communications. Let's say they find a terrorist (I'm close to Brussels, so not a hypothetical scenario here). Best case you want to see which phones they have, and look into all their communication to get an idea about their contacts etc.

It's a very hard problem, and I'm not sure which one I would pick.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#17
> But the proposals are the digital equivalent of giving law enforcement a key to every citizens’ home

To be fair, it’s more like giving law enforcement the key to everyones heavily fortified unobtanium bunker. There’s no way they can possibly get in if the owner doesn’t let them.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#19
post #6

Earlier quoted context omitted.

Can't we have E2EE+G? (end-to-end encryption, plus government can see everything) Not saying this is a good idea, though.

Yes, it is possible. You have to encrypt session key with government public key and include that encrypted data with your session. Government can decrypt that data with their private key. I think that's a pretty reasonable scheme as long as government private key managed by a competent organization (e.g. NSA). HSM makes it impossible to easily extract private key and military guard and other physical security measure…

Yeah, and that part is the pipe dream. You really need to compromise it only once to have access to everything.

It’s unreasonable to believe only the government will have access.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#20
post #6

Earlier quoted context omitted.

Can't we have E2EE+G? (end-to-end encryption, plus government can see everything) Not saying this is a good idea, though.

If you allow the +G, you allow hackers. It's as simple as that. If you want security, you can't have backdoors.

What is wrong with the method which vbezhenar suggested? (sibling comment of yours)
Post reply on HN