Live data from Hacker News

ProtonMail, Tutanota urging EU to reconsider encryption rules

cyberscoop.com

41–50 of 85 posts

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#41

Earlier quoted context omitted.

It's a trade-off. Of course I want to preserve my privacy. But I get it that law enforcement wants to be able to look into communications. Let's say they find a terrorist (I'm close to Brussels, so not a hypothetical scenario here). Best case you want to see which phones they have, and look into all their communication to get an idea about their contacts etc. It's a very hard problem, and I'm not sure which one I wou…

Oof, a lot of downvotes. Can you please explain why it's not a tradeoff, or what else I said wrong?

Because there is no trade off, communication is end-to-end encrypted or there is a backdoor.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#42

It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.

It's a trade-off. Of course I want to preserve my privacy. But I get it that law enforcement wants to be able to look into communications. Let's say they find a terrorist (I'm close to Brussels, so not a hypothetical scenario here). Best case you want to see which phones they have, and look into all their communication to get an idea about their contacts etc. It's a very hard problem, and I'm not sure which one I wou…

Look at the existing cases of terrorism. All of them used unencrypted forms of communication: shared Gmail account, phone calls, even good old SMS. The issue is not that police can't see what those people are doing, none of the perpretators are unknown; it's that they (and the judiciary branch) don't have enough resources to really tackle them.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#43
post #18

Isn't "encrypted mail" an oxymoron ?

I think they usually talk about the cloud storage not the emails itself.

The mails can very well be E2E encrypted, if we talk about the contents, not the SMTP metadata, headers, etc.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#44
post #6

Earlier quoted context omitted.

Can't we have E2EE+G? (end-to-end encryption, plus government can see everything) Not saying this is a good idea, though.

Welcome to 1998 aka "The Clipper Chip"[0] Also: We know how CSS, BluRay Master Keys, TSA Keys and other various signing keys fared in the wild. [0]: https://en.wikipedia.org/wiki/Clipper_chip

Don't forget the OPM hack! The spooks compiled a self-blackmail database and couldn't even keep that secure. Yikes.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#45
In the end, it doesn't matter.

These are email companies. But end to end encrypted email is a mess and hard to implement when everyone else doesn't follow a standard.

With or without EU's snooping what is more likely to happen is that people will migrate to messaging systems that the EU can't snoop: WhatsApp, Signal, Telegram, etc.

That will happen either because they're more private or because everyone else is there or because they offer a lot more features and less spam.

I bet that when the EU tries to mess with the messaging players the public outcry will be much louder. For email, very few will care.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#46
post #33
post #17

> But the proposals are the digital equivalent of giving law enforcement a key to every citizens’ home To be fair, it’s more like giving law enforcement the key to everyones heavily fortified unobtanium bunker. There’s no way they can possibly get in if the owner doesn’t let them.

I think the intended image there is that they can come and go without announcing themselves, which is what's being proposed. They can still access your E2E encrypted messages under existing laws by bringing a warrant to your door and asking you to hand over your phone, then: A: finding it unlocked. B: hacking it. C: using normal police techniques to convince you to hand over the passphrase. D: using a key disclosure…

But... but... terrorists!

Seriously though, we do need to acknowledge that there are some baddies who wont hand over their passphrases no matter what law enforcement does to compel them.

That said, I'm not sure it's really such a big deal. After all, terrorists will always have access to E2E encryption as long as they have access to general computing tech. Making E2E encryption illegal just hurts law-abiding citizens.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#47
post #21

Earlier quoted context omitted.

As far as I understood, the problem stems from the Crypto AG era. Governments are addicted to be able to listen to communications of everyone and don't want to lose their toys. Also, EU is far more advanced in terms of invisible security so, they don't want to lose the tools which enable them to do it. We need to re-think security and people are lazy about it because, it's hard. Edit: My English gets a hit when I'm l…

What is meant by "invisible security"?

it is usually used in reference to the customer, but in a natsec/cyber context can also mean the citizen[1].

https://www.routledge.com/Handbook-of-Surveillance-Technolog...

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#48
post #21

Earlier quoted context omitted.

As far as I understood, the problem stems from the Crypto AG era. Governments are addicted to be able to listen to communications of everyone and don't want to lose their toys. Also, EU is far more advanced in terms of invisible security so, they don't want to lose the tools which enable them to do it. We need to re-think security and people are lazy about it because, it's hard. Edit: My English gets a hit when I'm l…

What is meant by "invisible security"?

Disclaimer: This is my experience from many short travels to EU countries and having a lot of friends due to job network (my work promotes a lot of friendly work connections from many EU countries. As a whole, we work hard, we play hard).

Europe has a philosophy of "feeling peaceful". Police, intelligence, surveillance, etc. is not done openly, on your face. Instead it flows just beneath the surface.

There are a lot of civilian officers around and police officers are not very visible. Same for borders and higher security places like airports.

If there's something suspicious happening, the concentration is increased invisibly. If something really happens, the area is silently surrounded like a python death hugs its prey, and it's over.

This is possible with intelligence and surveillance, communications sniffing, etc. If you increase encryption, there's a risk of blinding security services. You may need more overt operations are much more manpower to keep tabs on everything.

I'm an encryption proponent. I support it with all my being. Also, I'm aware that being able to see everything can and is being abused.

However, I need to be a realist here: We're addressing the wrong problem here. Is encryption required? Undebatably yes. Do everyone has a right to privacy? Undebatably yes. Do we want to be secure and need security services? Possibly yes.

So, we need to solve the problem of security with the presence of encryption. I.E. Security in a past-encryption era. The no-encryption ship has sailed. Trying to bring it back with the force of law is a last ditch effort. We need another solution to allow security services to their job with the presence of encryption, and without weakening it.

I do not accept someone can just read my office messages or conversations with my family just because somebody may be trying to make a bomb or planning an uprising.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#49
The headline is misleading. These are not rules, there is no legislation. It was a resolution by the national governments. Without the EU commission there will be no European law on this topic. That being said the letter by ProtonMail et al. is still appropriate, the reporting is just inaccurate.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#50

Centralized services are not going to provide 100% reliable end-to-end encryption, they're vulnerable 'single-point-of-failure' that can be pressured/hacked/etc to disclose their users data.

Proton is "Zero Knowledge" so, they can't divulge anything but, with a weak enough password, high enough computational power or with a big enough wrench[0], you can get anything. [0]: https://xkcd.com/538/

All that zero knowledge stuff goes out the window once someone deploys malicious code to prod.
Post reply on HN