Live data from Hacker News

Signal president says company will not comply with U.K. ‘mass surveillance’ law

fortune.com

221–230 of 409 posts

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#221
post #96
post #26

Earlier quoted context omitted.

> but they don’t feel the same way about public benefits or rights associated with other technology that is being replaced When the government creates a law within recorded history — something like a wiretapping law — then the spirit of the law is well-known at time of creation. Usually, that "spirit" is that it's created to explicitly grant a capability to the government to do a thing for the benefit of the public u…

> The people who invented "using gold coins as a common exchange for barter" weren't thinking about anonymity What makes you say that anonymity wasn’t a concern? I have a hard time believing that claim without any substantiation. Anonymity in market participation and transactions has been an important consideration for millennia. Anyone who has watched Jasmine put on peasant clothes and visit the market in Disney’s A…

Because money from the get go was an instrument of the state as the historical record shows pretty convincingly. I suspect anonymity was a concern, just that they would have loved to eliminate it, not encourage it.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#222

Earlier quoted context omitted.

When you say those words people think you are a building-burning store-looting far left hooligan, they call you a commie and shove their head into the ground like an ostrich, as if the last N or so years have not been an endless class war.

The obvious response is to own it and be an actual commie. Join a revolutionary party, organise in a trade union, set up mutual aid, learn self defence, etc.

The problem is that most large left-wing movements tend to be about highly centralized socialism that is at best soft authoritarian (and in practice tends to quickly devolve into something much worse). I understand why - once you take away the cudgel from the people who currently have it, using it yourself to quickly solve problems is just too tempting. But it does mean that many (most?) of those parties are not a viable solution.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#223
post #216
post #201

Earlier quoted context omitted.

lol you should try living here, it tests your sanity

Is there anywhere that’s not true for?

Well as far as political systems go, Switzerland seems the gold standard from what I've read. And if you can deal with the cold then the Nordic nations seem pretty good, particularly Iceland. As for general day to day, I quite like the look of the laidback Mediterranean countries and la dolce vita rather than whatever the fuck the UK is about nowadays.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#224
post #34

> “You cannot create a back door that only the good guys can go through,” Alright, technical argument here. This is false and tech talking heads are spreading this lie for ideological reasons. You don't need to backdoor the protocol, just the specific targeted client. Now, if Signal said this is unfair because competitors won't also backdoor their app then I am with them. What the UK should probably have done is to f…

> You don't need to backdoor the protocol, just the specific targeted client. Distinction without a difference. Either way, the total system is delivering the same plaintext to the same third parties. On edit: and, just to be clear, they want the apps to scan for specific hashes from a master list, and/or apply ML to find "suspicious" material that's NOT in any lists, on EVERY client, not just "targeted" ones. That's…

Ok, so what's your point? Mine was to alleviate the burden on Signal. Fact is, this can be done and done well. Real harm is happening and this popular bandwagon is part of the problem, not solution.

Find a better way for govs to have an advantage against CSAM and other boogeymen. Technical people are supposed to find optimal technical solutions, not pretend to be technocrats or underdogs fighting against governments who are all unjust and out there to get us.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#225
post #88
post #34

> “You cannot create a back door that only the good guys can go through,” Alright, technical argument here. This is false and tech talking heads are spreading this lie for ideological reasons. You don't need to backdoor the protocol, just the specific targeted client. Now, if Signal said this is unfair because competitors won't also backdoor their app then I am with them. What the UK should probably have done is to f…

>You don't need to backdoor the protocol, just the specific targeted client. So how are you backdooring the client that -- where ever you download it from -- can be dumped from the phone and compared against self compiled client with a cryptographic hash? Introducing intentional, ubiquitous vulnerabilities is also a terrible idea, because exploits for those can leak or be stolen (that has already happened, see Shadow…

> Introducing intentional, ubiquitous vulnerabilities is also a terrible idea

No e2ee app has compromised device part of their threat model. People get ratted all the time on their phones bu criminals. This is the same thing except the gov is nice enough to not look ar everything, just scan for content

> Writing a script that comments out the lines of code for such scanning, and that compiles the application from source is trivial. People write E2EE layers on top of existing messaging apps. > One example is OTR plugin for Pidgin/Gaim, another is CryptoCat that at one point had a system that operated on top of Facebook web UI.

Doesn't matter. Those apps can be backdoored too. The whole OS can. And the gov doesn't mind playing whack-a-mole. You can disagree with their policy but I disagree with openly collaborating on lying to policy makers on technical facts.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#226
post #34

> “You cannot create a back door that only the good guys can go through,” Alright, technical argument here. This is false and tech talking heads are spreading this lie for ideological reasons. You don't need to backdoor the protocol, just the specific targeted client. Now, if Signal said this is unfair because competitors won't also backdoor their app then I am with them. What the UK should probably have done is to f…

It is a moral duty to oppose majoritarianism that disproportionately harms minorities, the so-called will of the people be damned.

Ok, if you believe that I have no desire to tell you that you are wrong on your views, all I am saying is let's be technically honest about what is and isn't possible.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#227
post #223
post #216

Earlier quoted context omitted.

Is there anywhere that’s not true for?

Well as far as political systems go, Switzerland seems the gold standard from what I've read. And if you can deal with the cold then the Nordic nations seem pretty good, particularly Iceland. As for general day to day, I quite like the look of the laidback Mediterranean countries and la dolce vita rather than whatever the fuck the UK is about nowadays.

Switzerland is impossibly expensive, and immensely bureaucratic. The Nordic nations are lovely but so cold. Iceland is one of my favorite countries ever. But I could never live there.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#228
post #177

Earlier quoted context omitted.

The Federalist papers are the equivalent of a Medium blog post. And I will treat them as such. Edit: Evidently I've pissed off enough people who drink the red-white-blue kool-aid. -3 at the moment. These newspaper publishings were expressly for the solidification of power at the federal level, and the weakening of the states. And only look closer at what the "federal" powers were about, and it was all about "secur(in…

Maybe a blog post that Tim Berners Lee wrote during the standardization of HTTP.

I agree with your general point that the Federalist Papers aren't quite the same as a random blog post. But to extend that analogy further, if I'm implementing HTTP, should I base my implementation on things only found in a blog post by Tim Berners Lee?

Don't get me wrong, the Federalist Papers are important historical documents and provide unique insight into the minds of the authors. But they're not laws, and treating them as if they have actual legal significance seems wrong.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#229

Governments seem to want to have it both ways. As new technologies are introduced they assume that capabilities and practices available to analogous predecessors must remain available to them (e.g. wire-tapping phones => undermining cryptography) but they don’t feel the same way about public benefits or rights associated with other technology that is being replaced (anonymous cash transactions => ???) It also seems l…

Well yes, they do. Encryption is a real issue for the mandate of a government, and also a real solution for other parts of the mandate of a government. It's not like we (as the broad community) are engaging with empathy. Even if there is maybe no great solution to the whole dilemma, it would help the entire thing, if we stopped camping on one side so entirely.

Empathy is for persons, not for legal entities.

Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law

#230
post #34

> “You cannot create a back door that only the good guys can go through,” Alright, technical argument here. This is false and tech talking heads are spreading this lie for ideological reasons. You don't need to backdoor the protocol, just the specific targeted client. Now, if Signal said this is unfair because competitors won't also backdoor their app then I am with them. What the UK should probably have done is to f…

I didnt read that as a technical argument, but as a sociological one. If there are two apps, one which is easy/legal to obtain, but has a backdoor and another which may be harder/illegal to obtain but has no backdoor, which is the bad guy going to choose? Unless you can somehow force every app to use the backdoor, you cant make the bad guy go through it. Therefore, "You cannot create a back door that only the good gu…

The proposal is to scan every message and report if only there is a match. What bad guy can possibly take advantage of that without coercing Signal? And if Signal can be coerced, they can backdoor it all to begin with. Call it a feature instead if a backdoor if it sounds better lol.

Control of the list which is used to scan your messages has the same security properties as the code of signal itself and a threat actor that can exploit the system must control both that and access the match reporting system (signal servers). An actor that controls these does not need to abuse this system, it would be easier to just push a rat alongside signal.

> "You cannot create a back door that only the good guys can go through"

Perhaps for crypto protocols. Software systems do this all the time in form of software updates, usage monitoring and even unattended remote support accounts. And also, just because it might be possible to find a vuln in a system in the future that does not mean it is vulnerable at the time of design.

Not only are clean backdoors possible, software engineers can design them cleanly and make them sound nice and fluffy when they are the ones accessing the backdoor.

Post reply on HN