Most operating systems already have a "front door" keys in the form of automatic updates certificates. Android, windows, ios, even apt get, all base their security around certificates which, if stolen, can by design lead to running code. All the objections to end to end encryption + government access fail to mention that we already have an implicit trust in corporate certificates in the security of nearly all devices…
ProtonMail, Tutanota urging EU to reconsider encryption rules
61–70 of 85 posts
Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#62Most operating systems already have a "front door" keys in the form of automatic updates certificates. Android, windows, ios, even apt get, all base their security around certificates which, if stolen, can by design lead to running code. All the objections to end to end encryption + government access fail to mention that we already have an implicit trust in corporate certificates in the security of nearly all devices…
> yet that front door was never used by hackers like everyone suggests government backdoors would be used. Would you hear about it if it had? If the US military collaborated with Apple, Google, or Microsoft on a classified project to abuse the autoupdate mechanisms everyone leaves enabled to exec code using their certificates on some military target (leaving aside for the moment that a "military target" is whoever th…
I also think WhatsApp messages backup is literally a backdoor to bypass the end to end encryption.
I think government RCE is far more serious concern than encryption, yet it gets no attention.
We hear about the encryption from all the second class governments that are blocked from the juicy NSA backdoors of auto updates. Ever noticed how the NSA stays quiet in all those encryption debates?
Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#63Because, who checks the government and makes sure that the master key is not abused by those in power? The scariest part is that it all can be done silently, behind our backs, without us ever knowing what's really happening. You will never find out if your message was decrypted and read.
Remember, it all starts with the banner of "fighting organized crime and terrorists", but that is just an excuse to an even bigger treasure trove of information these people want. I'd say giving these people that much power is much more dangerous than anything else.
Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#64It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.
Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#65Earlier quoted context omitted.
What is wrong with the method which vbezhenar suggested? (sibling comment of yours)
Considering how all master keys of most popular measures have been hacked, its natural to assume that government keys will be hacked and leacked too.
Some examples are the code signing keys of most major desktop and mobile operating system vendors, the package signing keys of major Linux distributions, the SSL private keys of most banks and major e-commerce sites, and the certificate signing keys of most SSL certificate issuers.
Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#66It really is amazing to me that anyone thinks it's reasonable policy to ban end-to-end encryption. For the sake of national security, I would want to strengthen the security of digital data, not weaken it.
You claim that somebody thinks it is reasonable policy to ban e2ee. Who is that exactly? Consider this section from the resolution: Striking a right balance The principle of security through encryption and security despite encryption must be upheld in its entirety. The European Union continues to support strong encryption. Encryption is an anchor of confidence in digitalisation and in protection of fundamental rights…
Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#67Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#68I guess that's one of the reasons why there are so many voices against PGP...
Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#69Earlier quoted context omitted.
Proton is "Zero Knowledge" so, they can't divulge anything but, with a weak enough password, high enough computational power or with a big enough wrench[0], you can get anything. [0]: https://xkcd.com/538/
All that zero knowledge stuff goes out the window once someone deploys malicious code to prod.
As long as both parties use a known safe version of e.g. Signal everything is kind-of good.
Messages may pass through NSAs and GRUs headquarters and they are none the wiser even if they have access to Signals servers.
However, if any of them somehow manage to strongarm a release of Signal through the release channels and you or whoever you talk to updates or auto-updates Signal and that new release somehow uploads data from the Signal client, then for most of us we would be none the wiser.
Re: ProtonMail, Tutanota urging EU to reconsider encryption rules
#70Earlier quoted context omitted.
Yes, it is possible. You have to encrypt session key with government public key and include that encrypted data with your session. Government can decrypt that data with their private key. I think that's a pretty reasonable scheme as long as government private key managed by a competent organization (e.g. NSA). HSM makes it impossible to easily extract private key and military guard and other physical security measure…
Yeah, and that part is the pipe dream. You really need to compromise it only once to have access to everything. It’s unreasonable to believe only the government will have access.