Live data from Hacker News

ProtonMail, Tutanota urging EU to reconsider encryption rules

cyberscoop.com

51–60 of 85 posts

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#51
Most operating systems already have a "front door" keys in the form of automatic updates certificates. Android, windows, ios, even apt get, all base their security around certificates which, if stolen, can by design lead to running code.

All the objections to end to end encryption + government access fail to mention that we already have an implicit trust in corporate certificates in the security of nearly all devices, and yet that front door was never used by hackers like everyone suggests government backdoors would be used.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#52
post #37

Earlier quoted context omitted.

You claim that somebody thinks it is reasonable policy to ban e2ee. Who is that exactly? Consider this section from the resolution: Striking a right balance The principle of security through encryption and security despite encryption must be upheld in its entirety. The European Union continues to support strong encryption. Encryption is an anchor of confidence in digitalisation and in protection of fundamental rights…

> Who is that exactly? Whoever wrote: "at the same time upholding the possibility for competent authorities in the area of security and criminal justice to lawfully access relevant data for legitimate, clearly defined purposes in fighting serious and/or organized crimes and terrorism, including in the digital world, and upholding the rule of law, are extremely important". Either said person doesn't understand end-to-…

Yeah you can encrypt your connection to the server where you store your mail. But don't think about encrypting your mail.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#53
post #30

Earlier quoted context omitted.

You could put a check on the government misusing their private key by having the government key distributed among several parties using a secret sharing system such as Shamir's that requires several parties to agree in order to use the government key. Include privacy or civil rights civilian organizations among the shareholders, such as the ACLU, so that there is an outside check. If you choose a sufficient and diver…

Even assuming purely good intentions, the government would want to use the key very often (hundreds or thousands of concurrent investigations) and in many large unrelated organizations (eg police + FBI + NSA + CIA + DOD + ...). It would be impractical to authorize each individual use, let alone authorize it by several parties each time. Instead we'd see 'ongoing' authorizations on the level of an investigation, a per…

The problem with E2E+G is not technical, it is political. It can be done in a way that it would only be practical for the government to use it rarely (E.g., [1]) and only for cases where there is a broad consensus that it is being used Constitutionally (or whatever is equivalent outside the US).

But getting Congress (or whatever is equivalent outside the US) to pass an E2E+G law that allows it to be done in such a way seems unlikely. They will go for a way that allows broad use.

[1] You could make it a per-device key, generated on the device itself. The device makes the Shamir secret sharing shares, encrypts them with the public keys of the shareholders, and periodically includes those includes those in the chat metadata.

To decrypt a chat, the government needs to record it, get the encrypted shares out of the chat metadata, get each shareholder to use that shareholder's private key to decrypt their share and then contribute that share for recovery of the actual chat key for that chat.

If they want to decrypt a chat from another device, they'd have to do that all over again for that device.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#54
post #30

Earlier quoted context omitted.

You could put a check on the government misusing their private key by having the government key distributed among several parties using a secret sharing system such as Shamir's that requires several parties to agree in order to use the government key. Include privacy or civil rights civilian organizations among the shareholders, such as the ACLU, so that there is an outside check. If you choose a sufficient and diver…

Even assuming purely good intentions, the government would want to use the key very often (hundreds or thousands of concurrent investigations) and in many large unrelated organizations (eg police + FBI + NSA + CIA + DOD + ...). It would be impractical to authorize each individual use, let alone authorize it by several parties each time. Instead we'd see 'ongoing' authorizations on the level of an investigation, a per…

[deleted]

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#55
> ...resolution on security through encryption and security despite encryption

People in government, be it in the EU or elsewhere, have a different idea of what privacy means and a citizen having privacy from state powers is antithetical to it. EU mopes believe their own marketing material regarding privacy, which is why the above phrase can be found in a Council publication, along with the always present "competent law enforcement". Nevermind that when it comes our privacy, a competent law enforcement officer is as much a mythical being as is an "ordinary citizen" who has nothing to fear or hide.

The Council is tasked with "setting" the agenda for the EU. The latest one is from last summer and the first item in it reads "protecting citizens and freedoms". That is exactly how I would imagine someone working at the Council to think of the act of stripping their "fellow" citizens of their privacy, while convinced that they're the good guy. There is no privacy without encryption today. As soon as you mandate that someone with special powers has to have the ability to force their way in and read the thoughts I exchange then you'll have killed privacy. It doesn't matter who that person is, it doesn't matter how you justified it and it doesn't matter what the consequences of privacy are.

We don't yet know what the "regulatory framework" (kill me please) will look like but whatever it is I don't think it's far fetched to expect things like running a Tor relay to get you in trouble, running an IRC server over TLS will be lots of fun too, and so on and so on. How long till you're required to have a license to run nc -l 1234? I'm sure it will be a decade or two but eventually that's where we'll be.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#56

Most operating systems already have a "front door" keys in the form of automatic updates certificates. Android, windows, ios, even apt get, all base their security around certificates which, if stolen, can by design lead to running code. All the objections to end to end encryption + government access fail to mention that we already have an implicit trust in corporate certificates in the security of nearly all devices…

> yet that front door was never used by hackers like everyone suggests government backdoors would be used.

Would you hear about it if it had?

If the US military collaborated with Apple, Google, or Microsoft on a classified project to abuse the autoupdate mechanisms everyone leaves enabled to exec code using their certificates on some military target (leaving aside for the moment that a "military target" is whoever the military says it is and includes people like Snowden), why on Earth do you think that any of the involved parties would ever speak of it?

It's reputational poison; everyone would keep that as quiet as humanly possible.

We know Apple is willingly collaborating with the FBI to avoid encrypting people's device backups, and that's for domestic traffic as well. They work with the CCP and run special backdoored servers there to be permitted to offer iCloud/iMessage services in China.

The Apple software update system can target specific computers by MAC address - fact, today, not speculation.

Why do you think it would be known if they offered this sort of assistance?

It would likely even be illegal for them to divulge it, for various reasons, depending on how they were asked. FISA spying orders and FBI wiretaps already are.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#57

In the end, it doesn't matter. These are email companies. But end to end encrypted email is a mess and hard to implement when everyone else doesn't follow a standard. With or without EU's snooping what is more likely to happen is that people will migrate to messaging systems that the EU can't snoop: WhatsApp, Signal, Telegram, etc. That will happen either because they're more private or because everyone else is there…

> With or without EU's snooping what is more likely to happen is that people will migrate to messaging systems that the EU

historic legislation and these plans suggest that there will be 2 forms of encryption: 1) Legal 2) Illegal.

it doesn't matter if some niche technologies exist if people are unable to access them. even if they could they would not feel strongly enough to "break the law".

This push has been noticeable only to specialists in the field (and the push is also unevenly distributed) but been ongoing in all 9-eye countries.

France implemented snooping charter in 2015 by changing their constitution (using Charlie Hebdo[1] as excuse), the UK is on par with the US and needs no introduction, Australia has the AAbill[1] criminalizing employees if they do not act as moles in companies, Germany has its Bundestrojaner etc etc ... Australia is especially interesting as it is a tiny population and used as a test-bed for more salty US propaganda and to see what can be learned (in terms of messaging) before applied to a wider basis (e.g. one that is later always rolled out to the rest of the countries in the pact)

All of them are driven by US interests and pressure (anyone wanting to become a member of the many eyes is well advised to implement SIGINT technologies and laws to facilitate Western espionage on their citizens.

Public outcry won't matter, nobody cares because why would a sane person not working in Tech even think about topics like encryption - when this is all just to "catch the bad guys" and "only bad guys have something to hide anyway".

[1] https://www.reuters.com/article/us-france-surveillance/frenc...

[2] https://en.wikipedia.org/wiki/Mass_surveillance_in_Australia

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#58

It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.

Exactly, and that only means that people behind anti-encryption regulations does not care about national security.

Or they are so painfully incompetent that they don't understand that it is much better if one cannot figure out that some military officer or energy sector/government employee has a lover since such person could be blackmailed by foreign intelligence.

Apparently they don't get that those pesky terrorists can encrypt message by themselves in thousands of ways. Internet is full of information how to do this.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#59

Most operating systems already have a "front door" keys in the form of automatic updates certificates. Android, windows, ios, even apt get, all base their security around certificates which, if stolen, can by design lead to running code. All the objections to end to end encryption + government access fail to mention that we already have an implicit trust in corporate certificates in the security of nearly all devices…

What do you think of these counter examples?

The automatic upgrades channel issue is close to the very heart of, for example, popular browser extensions becoming malicious.

Another attack from the past was the system certificate store compromise by Lenovo on workstations and laptops sold to its own customers, allowing for decryption of any HTTPS traffic from the customer. [1]

Another high profile attack that everyone will know about is the SolarWinds compromise of its software updates. [2]

[1] https://us-cert.cisa.gov/ncas/alerts/TA15-051A

[2] https://www.bleepingcomputer.com/news/security/new-sunspot-m...

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#60

Most operating systems already have a "front door" keys in the form of automatic updates certificates. Android, windows, ios, even apt get, all base their security around certificates which, if stolen, can by design lead to running code. All the objections to end to end encryption + government access fail to mention that we already have an implicit trust in corporate certificates in the security of nearly all devices…

On the contrary, certificate breaches are a constant source of issues.

https://resources.infosecinstitute.com/topic/cybercrime-expl...

There have been cases of breaches at various root CAs, including Adobe products; the Zeus Trojan that had a forged Microsoft certificate; a Dutch government cert breach that impacted Facebook, Twitter, Skype, Google and also intelligence agencies like CIA, Mossad, and MI6; A breach at ANSSI, the French Cyber Security Agency.

Then of course there's the recent SolarWinds debacle that should kill this notion once and for all.

Post reply on HN