Live data from Hacker News

EU Commission doesn't understand what's written in its own chat control bill

mullvad.net

41–50 of 219 posts

Re: EU Commission doesn't understand what's written in its own chat control bill

#42

This is more common than the opposite. I’m reminded of that recent embarrassing display of US government where the TikTok CEO was peppered with the kinds of questions that betray the fact that the congresscritter doesn’t comprehend the topic. If they wanted real answers they’d say, “I yield my time to this SME I brought in.” But they’re just there to look tough on whatever.

Pretty much that. Your average politician on this side of the pond is not much better than the ones on the other side

And to be even more honest, technical people have a very hard time getting their point across non-technical people and engaging in politics

Re: EU Commission doesn't understand what's written in its own chat control bill

#44
This is so common (not just in the EU) that it makes me feel like it was done by design in a lot of cases. By creating these massive overcomplicated bills, they make sure only a handful of individuals are capable of reading them and the rest of us (including other politicians) will never read them and instead have to rely on faith. It feels to me like they want to give you the illusion that it's all open/public but at the same time they don't want other people to read it. The fact that even the politicians signing on it can't understand it should raise a lot of red flags.

We should treat them the same way that an anti-virus treats "safe" code with payloads that are obfuscated using techniques also used by viruses (a big reason why you get false positives on cracks and keygens btw). We should assume that they are trying to hide something they don't want us to see when they make their bills extremely hard to read even for lawyers.

Re: EU Commission doesn't understand what's written in its own chat control bill

#45
post #22
post #21

Earlier quoted context omitted.

Having a solution is not a prerequisite for providing criticism. It is okay to see a flaw but not yet have an answer.

No but it makes it an empty criticism. It's like the activists who say "abolish the police!" but either have no insight into or are deliberately ignoring why the police exist, and have no ideas regarding who would perform the equivalent function instead.

Here's a real problem. Let's call it X. Someone proposes a solution: "Let's do Y!". It is perfectly valid criticism to say that Y doesn't actually fix X.

I don't care if that counts as "empty criticism" by your definition. If someone proposes a solution, it's perfectly valid criticism to point out that the "solution" doesn't actually solve.

Re: EU Commission doesn't understand what's written in its own chat control bill

#46

This is more common than the opposite. I’m reminded of that recent embarrassing display of US government where the TikTok CEO was peppered with the kinds of questions that betray the fact that the congresscritter doesn’t comprehend the topic. If they wanted real answers they’d say, “I yield my time to this SME I brought in.” But they’re just there to look tough on whatever.

Pretty much that. Your average politician on this side of the pond is not much better than the ones on the other side And to be even more honest, technical people have a very hard time getting their point across non-technical people and engaging in politics

Perfect use case for ChatGPT.

Sure, I'd be as surprised as anyone else if it could straight up write good laws, but it can almost certainly talk in political jargon better than any of us software developers can manage.

Re: EU Commission doesn't understand what's written in its own chat control bill

#47
Someone commented something along the lines of 'but then how are we supposed to tackle organized crime'. As I typed the comment below the comment got flagged and I could no longer reply. Still, I think the bit below may contribute to the discussion. TL;DR; I think that as a society we should more often ask ourselves if something is actually worth fighting if it means sacrificing a lot of our human rights. That may not be a problem on HN, but it is one imho on a political level in many Western countries.

There is not always a solution to a problem.

Let's say you wanted to bring the number of car crashes to zero. Eventually there's nothing 'reasonable' left to be done, and the only remaining option would be to ban cars altogether. Instead, we accept a certain number of crashes because it's deemed more important to be able to drive a car than it is to bring the number of car crash fatalities to zero*.

For example, in a country like Germany there are 0.8 homicides per 100K inhabitants. You could put _everybody_ under surveillance, just to have an easier job of finding the perpetrators. In the process there would be many false positives, wrongful imprisonments, etc.

In order to preserve the rule of law, maybe it's sometimes best to accept that you cannot create the perfect society. At least not a society in which people who are innocent (the very vast majority) can also still enjoy their freedoms.

Besides, I feel like the police has become somewhat lazy in many Western countries for the past 20 years. Before the rise of the internet, it was simply accepted that you couldn't know what two spouses had said to each other and you had to rely on good-old detective work. However, since things like Facebook Messenger, the cops expect to be able to get a warrant for all this data. That era appears to be slowly ending with E2EE, and all of a sudden they're struggling because those detective skills have slowly deteriorated.

* To be clear, I think that in many countries there's still quite a lot of room for improvement to reduce the number of car crash fatalities. Not in the least in the USA.

Re: EU Commission doesn't understand what's written in its own chat control bill

#48
post #44

This is so common (not just in the EU) that it makes me feel like it was done by design in a lot of cases. By creating these massive overcomplicated bills, they make sure only a handful of individuals are capable of reading them and the rest of us (including other politicians) will never read them and instead have to rely on faith. It feels to me like they want to give you the illusion that it's all open/public but a…

Legalese is like that thanks to a long history of people looking for and abusing any and all loopholes.

That led to the natural conclusion of legal words holding standardized definitions that might differ from common understanding, and extreme specification of all details in an effort to preemptively close off any and all loopholes.

Anyone who tries to make legalese simpler finds themselves immediately torn asunder by the aforementioned people looking for and abusing any and all loopholes as lawyers and those who learned the hard way look on shaking their heads.

Re: EU Commission doesn't understand what's written in its own chat control bill

#50
Don't believe vendors' lies about "end-to-end" encryption.

If caught red handed, they will always say it depends on how you define where both "ends" begin.

Do not trust a cloud service that you have not developed and deployed yourself.

You may trust untrusted hardware with your encrypted content, but only if you have given it your content pre-encrypted by yourself, not trusted a third party to encrypt it on your behalf. Obviously, this excludes mobile devices.

Do not trust a tree of certificates if you cannot trust the root certificate because it belongs to an organization that is in a jurisdiction where people may be interested in what you have written and said in your encrypted message.

Don't trust old-school typewriters and the postal system either. Letters are routinely opened and typewriters can be matched. For example, the Stasi (secret police of the former GDR - German "Democratic" Republic) had an archive of type samples of all sold models of typewriters for re-identification of political pamphlets.

You can trust a few things: You can trust your Linux box with your self-compiled kernel (no 3rd party drivers), at least as long as it is not on a network. To build a safe environment, you could start there, taking a defensive approach. Remember, last time the paranoid turned out to be naive when Snowden revealed the real status quo in 2013 (ten years ago, when I couldn't buy a 1 TB USB stick).

Post reply on HN