Live data from Hacker News

European Parliament approves mass surveillance of private communication

patrick-breyer.de

171–180 of 434 posts

Re: European Parliament approves mass surveillance of private communication

#171
post #70

Can this be true? I'm having a hard time understanding how they can stand for internet privacy and legal mass surveillance simultaneously.

A decade ago I watched a documentary about MEP explaining how it happens that crappy law is made in EU. MEPs are too busy to read and understand what they are voting for or against. Law they are discussing often has 100s of pages, a few of such per day. One of the "ACTA" branded regulation was 800+ pages and the document changed daily. MEP have armies of secretaries and interns who as supposed to filter the important…

I've seen a similar documentary a while ago, where it became apparent that some MEP's are so busy that lobbyist groups completely wrote their proposal documents and deposited them at their office to have them 'go with the flow' without any scrutiny whatsoever. Though officially all is legal, it strongly reeked of corruption, especially with some MEP's doing that very frequently.

Re: European Parliament approves mass surveillance of private communication

#172
> Previously secure end-to-end encrypted messenger services such as Whatsapp or Signal would be forced to install a backdoor.

This is surely a fantastic extrapolation of this author. The chance of this happening is zero, which is also the chance of this being explicitly stated in the legal text.

It would be a disaster of course. And extremely controversial. Which is why it doesn’t just get passed under the radar, even as a temporary measure.

Isn’t there a copy of the actual legal text anywhere? Or a sober analysis of that text that isn’t made by a member of the pirate party?

Edit: Here https://www.europarl.europa.eu/RegData/docs_autres_instituti...

It doesn’t mention encryption, back doors, or forcing any entity to do anything. It does mention allowing companies to temporarily continue current monitoring for child abuse under certain conditions. What exactly is the outrage about?

Re: European Parliament approves mass surveillance of private communication

#173
Whatever this law or proposal is, it sounds bad and I don't like it. The only one good thing would be if the ones who draft, pass and implement it are not exempt and equally subject to the invasive tentacles of the buerocrats.

I can kinda understand how and why crime happens, but I never understood the motives or way of thought of the people who want this kind of stuff implemented.uch less the ones who vote for it.

Re: European Parliament approves mass surveillance of private communication

#174
post #158
post #27

Earlier quoted context omitted.

The backups aren't. Same with iMessage. end-to-end has become a marketing buzzword, any large scale deployment gets backdoored (via either key or plaintext escrow) at the endpoints, to FISA/PRISM providers who have to turn it over to the state without a warrant. China has the same setup with providers in their country. WhatsApp and iMessage simply aren't private when the providers get ~100% of the plaintext transitin…

For the purposes of an eu law requiring facebook to scan messages, facebook can’t scan icloud backups.

Any law that the EU can apply to Facebook to scan messages readable by Facebook that transit Facebook's service, the EU can apply to Apple to scan messages readable by Apple that transit Apple's service.

Re: European Parliament approves mass surveillance of private communication

#175
post #146

Just to clarify a point for discussion: this is already the law in the USA, and always has been [0]. European privacy law formerly prohibited private entities from reading personal communications, and handing them over warrantlessly to governments (as I understand it (?)); but this was never a thing in the US. [0] https://en.wikipedia.org/wiki/Third-party_doctrine

From that source: In 1986, the United States Congress updated the Omnibus Crime Control and Safe Streets Act of 1968 by enacting the Electronic Communications Privacy Act which included an updated "Wiretap Act" and also extended Fourth Amendment-like protections to electronic communications in Title II of the Electronic Communications Privacy Act, known as the Stored Communications Act . In Carpenter v. United States…

Think you're glossing over the distinction between compelling material (by warrant, subpoena, &c.) -- what the Fourth Amendment covers -- and private entities voluntarily giving the government material that third parties have entrusted them. Nothing regulates the latter: that's the third-party doctrine.

Re: European Parliament approves mass surveillance of private communication

#176
post #79

Maybe the Brexiteers were right all along.

Well it may not be for the British, they're not going to get less mass surveillance due to Brexit. However for some countries that could choose to leave the EU due to totalitarian laws like this, it may be a benefit, if they choose to pursue a privacy-focused path.

Which are the most privacy-focused nations in the EU that might leave over a law like this?

Re: European Parliament approves mass surveillance of private communication

#177

Earlier quoted context omitted.

The problem with email is that it’s federated; any email is as secure as the least secure mail server it’s being sent from or two. Even if you use something super duper secure in a polity that respects privacy, it does you no good if you send an email to Gmail who immediately hands it over to one or more government bodies.

There is an obvious solution, do not send emails to gmail addresses.

... or to domains that use gmail.

Possible to find out using dig but not as simple as avoiding gmail addresses.

Re: European Parliament approves mass surveillance of private communication

#178

Full name list ECR: Bourgeois, Jurzyca, Kanko, Melbārde, Terheş, Van Overtveldt, Zīle NI: Beghin, Buschmann, Castaldo, Comín i Oliveres, Ferrara, Furore, Gemma, Giarrusso, Gyöngyösi, Pignedoli, Ponsatí Obiols, Puigdemont i Casamajó, Regimenti, Rondinelli, Rookmaker, Sinčić, Sonneborn, Vuolo PPE: Adamowicz, Ademov, Adinolfi Isabella, Alexandrov Yordanov, Amaro, Arias Echeverría, Arimont, Arłukowicz, Asimakopoulou, Băs…

Are you sure these are the right names? These are the people who voted against it or abstained, right?

Document: https://www.europarl.europa.eu/doceo/document/PV-9-2021-07-0... (page 5)

Re: European Parliament approves mass surveillance of private communication

#179
post #146

Earlier quoted context omitted.

From that source: In 1986, the United States Congress updated the Omnibus Crime Control and Safe Streets Act of 1968 by enacting the Electronic Communications Privacy Act which included an updated "Wiretap Act" and also extended Fourth Amendment-like protections to electronic communications in Title II of the Electronic Communications Privacy Act, known as the Stored Communications Act . In Carpenter v. United States…

Think you're glossing over the distinction between compelling material (by warrant, subpoena, &c.) -- what the Fourth Amendment covers -- and private entities voluntarily giving the government material that third parties have entrusted them. Nothing regulates the latter: that's the third-party doctrine.

This is true.. not much to be done with the major providers are all in bed with the Feds. I mean, the telcos literally allow the Feds to port mirror all their traffic. End to end encryption on your own encrypted storage perhaps.

Re: European Parliament approves mass surveillance of private communication

#180
post #91
post #30

Earlier quoted context omitted.

> For Chat tg/signal seem like they would but I am less sure what the best option is for email. Something that doesn't store the chats in a decryptable form on their servers is probably preferrable. So Telegram out and Signal, Threema or WhatsApp in.

Friendly reminder that WhatsApp is far out: it uploads all data unencrypted to at least one cloud if on of the participants have backups enabled. So Signal, Matrix or possible Threema (I don't know it) is in. Personally though, I use Telegram and I drive an ordinary car, not an armored one.

No matter which chat service you use, any recipient could potentially upload the unencrypted data to a cloud backup service. If you don't trust the intended recipients with the data then you shouldn't share it with them in the first place.
Post reply on HN