Live data from Hacker News

WhatsApp would not remove end-to-end encryption for UK law, says chief

theguardian.com

21–30 of 173 posts

Re: WhatsApp would not remove end-to-end encryption for UK law, says chief

#21

Earlier quoted context omitted.

France effectively banned encryption in the 90s and had to backtrack, I can't see this being enacted for any length of time before even the most stupid of politicians realise it's a bad idea.

Would you happen to have links to some good reading material on this? People could -eg.- show it to their representatives.

I'm probably not best equipped since I wasn't living in France at the time, but there's a quick summary at the time here:

https://www.theregister.com/1999/01/15/france_to_end_severe_...

Re: WhatsApp would not remove end-to-end encryption for UK law, says chief

#22

Call me sceptic, but does not whatsapp see what you are typing when you are creating messages? They need to log the keydown event somehow, right? And the predictive text spits out what it thinks you want to type. And backups are possible even if you never had one before. This is so very dodgy to me. Maybe its e2e from the moment you submit until it arrives at the desired destination. Which brings me to the next issue…

If it ain't open-source, you can't trust it.

Signal or GTFO.

Re: WhatsApp would not remove end-to-end encryption for UK law, says chief

#24

Call me sceptic, but does not whatsapp see what you are typing when you are creating messages? They need to log the keydown event somehow, right? And the predictive text spits out what it thinks you want to type. And backups are possible even if you never had one before. This is so very dodgy to me. Maybe its e2e from the moment you submit until it arrives at the desired destination. Which brings me to the next issue…

I believe you don't know the meaning of the term "end-to-end encryption". Obviously the application itself (and the phone) can see the text you put into it, because it has to display that text.

"End-to-end encrypted" means "from the moment the text leaves the phone, to the moment the text arrives at the recipient's phone, the text is encrypted such that no intermediate party can read it". You must of course trust or verify that the WhatsApp app isn't leaking your text, that the keyboard you are using isn't leaking your text, that Android or iOS or whatever isn't leaking your text, that you yourself aren't somehow taking unencrypted backups and you aren't using whatever unencrypted-backup features WhatsApp might make available, etc.

Re: WhatsApp would not remove end-to-end encryption for UK law, says chief

#25
post #5

Earlier quoted context omitted.

They say that 98% of users are outside the UK (and those users very likely won't want reduced encryption), so whatsapp would probably just exit the UK.

I know in some non-US countries, WhatsApp is the default way of communicating (like SMS is in the US). Is that true in the UK? That could put significant pressure on the government

It's the default way of communicating for politicians that are making this law. Of course, they probably don't see the value of E2E encryption because their messages are inevitably leaked by a defector in the group chat.

Re: WhatsApp would not remove end-to-end encryption for UK law, says chief

#27
post #3

“If the company refused to do, it could face fines of up to 4% of its parent company Meta’s annual turnover – unless it pulled out of the UK market entirely.” Wow. I wonder if it got to that point if Meta would change course and disable end to end encryption for UK users and people messaging UK users, if that would be sufficient to comply. If this lobbying causes the UK to change course, I wonder what impact that wou…

Which entity? I'm not sure the UK would have the mandate to fine a foreign company who's not operating in the UK. They'd just create a company whatsapp UK, license technology, have no other links to meta and have a revenue of about 0.

Re: WhatsApp would not remove end-to-end encryption for UK law, says chief

#28

What are the government's arguments against end-to-end encryption?

It allows criminals to do bad things, common examples would be CP or terrorism.

Which always makes me wonder, what is the extend of the child pornography problem? How big is the nail compared to the proposed hammer? If I had to guess, I would guess this is hammer affecting 80+ % of the population to go after a group constituting a fraction of a percent of the population.

Re: WhatsApp would not remove end-to-end encryption for UK law, says chief

#29
post #11
post #3

“If the company refused to do, it could face fines of up to 4% of its parent company Meta’s annual turnover – unless it pulled out of the UK market entirely.” Wow. I wonder if it got to that point if Meta would change course and disable end to end encryption for UK users and people messaging UK users, if that would be sufficient to comply. If this lobbying causes the UK to change course, I wonder what impact that wou…

UK politicians themselves use WhatsApp a lot. They will strike the law down a day after WhatsApp stops working in UK. 2 days after there will be massive public outrage since everybody uses WhatsApp in UK. It's an empty threat, just like the internet porn law.

That last bit is exactly right. The UK has proposed all sorts of plainly moronic online restrictions, which never actually get implemented.

They simply don't have the clout to push around enormous American companies. It's a tiny country. If the EU or US were proposing such a law, you should take it seriously, but this is just a joke.

Re: WhatsApp would not remove end-to-end encryption for UK law, says chief

#30

Call me sceptic, but does not whatsapp see what you are typing when you are creating messages? They need to log the keydown event somehow, right? And the predictive text spits out what it thinks you want to type. And backups are possible even if you never had one before. This is so very dodgy to me. Maybe its e2e from the moment you submit until it arrives at the desired destination. Which brings me to the next issue…

I believe you don't know the meaning of the term "end-to-end encryption". Obviously the application itself (and the phone) can see the text you put into it, because it has to display that text. "End-to-end encrypted" means "from the moment the text leaves the phone, to the moment the text arrives at the recipient's phone, the text is encrypted such that no intermediate party can read it". You must of course trust or…

That is all good and clear, but its not open source and the government would not need have a back door, they can just request the received messages, or am I wrong here?
Post reply on HN