We certainly need decentralized systems that cannot be controlled by EU, US, or any government/entity. Privacy is a human right. We probably all know that they will show reasons like "fighting terrorism", "preventing national threats" or "hunting down child pornography" etc, whereas the real motivation is to control people's freedom of speech and communication even though they will 100% deny it. Anyone who is really…
Stop the proposal on mass surveillance of the EU
271–280 of 534 posts
Re: Stop the proposal on mass surveillance of the EU
#272Earlier quoted context omitted.
> It's (technologically) relatively easy to create a private, censorship-resistant distributed system, but if it's illegal people just won't use it. Ask a Gen-Xer about Napster and Bittorrent sometime.
Bittorrent still exists. Plenty Gen-Zers use it too.
Re: Stop the proposal on mass surveillance of the EU
#273Every time this comes up people talk about protecting privacy and anonymity and what not and while luckily for us most of the time the laws die out they still do pass on occasion. The fundamental issue to me is that society still wants to protect against pedophiles or drug dealers or whatever other group more than protect privacy. As an example, how many people here could go on television onto some talk program or ne…
> The fundamental issue to me is that society still wants to protect against pedophiles or drug dealers or whatever other group more than protect privacy. Speaking from a U.S. perspective here. A pedophile with a cameraphone is terrible. But law enforcement without the 4th amendment is worse. A racist with a social media account is terrible. But a president without the 1st amendment is worse. There are people who do…
Re: Stop the proposal on mass surveillance of the EU
#274Earlier quoted context omitted.
Can your country of birth lobby in the EU to stop laws like this?
Honestly, I would believe some of them already do it. You're reading the news from a Swedish company anyway so we use to be pretty vigilant on privacy issues. Sweden is a small player compared to Germany and France, so I am uncertain how much weight our words have.
> When the NDRE law was implemented in 2008, the Director-General (...) wrote that "there is this idea that the NDRE is going to listen to all Swedes' phone calls and read their e-mails and text messages. A disgusting thought. How can so many people believe that a democratically elected parliament would treat its people so badly?"
> However, 13 years later, in May 2021, Sweden was found by the European Court of Human Rights to have violated personal privacy due to the NDRE law. The Swedish government was urged to immediately correct these problems of legal uncertainty. Instead, however, the parliament did the exact opposite: they voted to extend the NDRE law in November 2021.
In fact, it's completely opposite - Swedish government is trying hard to spy on their citizen, and the EU is trying[1] to stop that.
[1] By sending strongly worded letters, and fails to achieve anything. There goes the idea that EU is some kind of a totalitarian dictatorships that forces countries to do what it wants.
Re: Stop the proposal on mass surveillance of the EU
#275Any tips for what an EU citizen can do against this, beyond upvoting this story on HN?
Re: Stop the proposal on mass surveillance of the EU
#276Earlier quoted context omitted.
> We certainly need decentralized systems that cannot be controlled by EU, US, or any government/entity. I agree in principle, but controlled != regulated. It's (technologically) relatively easy to create a private, censorship-resistant distributed system, but if it's illegal people just won't use it. It's a human problem, not a tech problem.
> It's (technologically) relatively easy to create a private, censorship-resistant distributed system, but if it's illegal people just won't use it. Ask a Gen-Xer about Napster and Bittorrent sometime.
Napster lost several lawsuits in the US and filed for bankruptcy
But Napster the brand was sold to Roxio and continued operations
it's still active today
Anyway, in retrospective, Napster times were fun, university networks were clogged by students downloading music all day long and, at least in my country, many people bought a dial up internet connection just to use it.
But it had serious unexpected consequences, it gave birth to new generations of listeners that do not buy music, because they never had to, and the musicians are now paid virtually nothing for the music they create, while majors still make a lot of money, which isn't exactly what we hoped for when we hated on Metallica for suing Napster.
People were not using it because it was illegal, people were using it because it was cool. It was mostly young people.
Chats are a different beast, if they were ever made illegal, a lot of people would stop using them, because they would disappear from app stores and a prominent smartphone manufacturer we all know would probably delete the app remotely from the users' devices and report to the authorities whoever would dear to sideload it.
I feel sometimes a little bit conflicted about those years when I see my musician friends touring over and over because selling records and make a living of it it's not a thing anymore, and now I buy a lot more music than I did in the past (which was already a decent amount), directly from artists when I can.
Re: Stop the proposal on mass surveillance of the EU
#277Earlier quoted context omitted.
a compromised root ca allows an attacker who already has dns or ip control (via bgp, arp spoofing, a captive portal, etc.) to leverage it into a working mitm attack on a tls site, but it can't revoke certs it didn't sign, and the attack is over as soon as the attacker loses dns or ip control by contrast, the ca you chose to sign your cert can revoke it, or refuse to renew it, taking your website permanently offline w…
> a compromised root ca allows an attacker who already has dns or ip control DNS or host/IP control is not a requirement at all: a Trusted CA is already trusted to sign a certificate for any hostname (with exceptions): that's what Trust means, and it also means that we trust them not to issue certificates for domains/hostnames without doing at-least Domain Validation - and we have schemes like Certificate Transparenc…
but, as i said, if you can feed me fake dns results so i connect to the wrong ip, or if you can arrange so that packets to gmail's legitimate ip go to your server instead (for example by having me connect to your wifi), then you can leverage the fake certificate into a successful mitm attack
but your explanation of the part of the basics of tls you understand, incomplete though it is, is irrelevant to the attack i was actually discussing, where someone doesn't like what you're saying (or the communication service you're providing) and gets your cert revoked to shut you up
Re: Stop the proposal on mass surveillance of the EU
#278Earlier quoted context omitted.
Don't call encryption illegal. That's letting them shape the narrative.
Isn't the whole point that they're trying to make mathematics illegal? To my knowledge, encryption is currently legal. To those who say "it's impossible to make encryption illegal": there have been sillier laws. George Orwell once imagined a society where 2+2=5 was a law. While they usually do, laws don't have to make sense.
> https://en.wikipedia.org/wiki/Crypto_Wars
> https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
Re: Stop the proposal on mass surveillance of the EU
#279Earlier quoted context omitted.
Is anyone else astonished by how dramatically Hacker News has shifted its tone on this issue over the last five to ten years?
Eternal September, when big social media sites get big enough you will find larpers and bots including Hacker News.
Re: Stop the proposal on mass surveillance of the EU
#280Funnily enough it is European companies and not American ones that are leading the charge on privacy. ProtonMail / Tutanota etc for example on the email front. I've heard of a company called Snacka! as well that seems to be using some gaming tech in streaming for end-to-end encrypted communication that doesn't suffer performance as much as services like jitsi. If more companies follow privacy principles like this in…
Tutanota was forced to install a backdoor by a German court (see https://www.heise.de/news/Gericht-zwingt-Mailprovider-Tutano... ) I don't think a US court can force a US company to do so.
[1] https://www.theguardian.com/commentisfree/2014/may/20/why-di...