Earlier quoted context omitted.
I guess I don't get why the arguments against the Constitution of the time would be useful for "understanding the intent of the Constitution and Bill of Rights"?
The Bill of Rights came about largely as a product of anti-federalist agitation. Many prominent federalists felt that a Bill of Rights would be redundant; in federalist 84, Hamilton writes the following: > There remains but one other view of this matter to conclude the point. The truth is, after all the declamations we have heard, that the Constitution is itself, in every rational sense, and to every useful purpose,…
Signal president says company will not comply with U.K. ‘mass surveillance’ law
361–370 of 409 posts
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#362Earlier quoted context omitted.
My point is that she is appropriately characterizing what she's being asked to do. > Real harm is happening ... and these proposals would be very unlikely to materially reduce that harm. They WOULD, however, create a bunch of other harm. Including harm to children. In fact even including sexual harm to children. > boogeymen You said it, I didn't. > Technical people are supposed to find optimal technical solutions, no…
> and these proposals would be very unlikely to materially reduce that harm. They WOULD, however, create a bunch of other harm. Including harm to children. In fact even including sexual harm to children I would want to hear your explanation for that but more importantly, you should convince lawmakers about this instead of claiming the tech is impossible. > You said it, I didn't. Yes I did, hope you got my point then.…
The people who want it need to prove that it will help.
I had started in to list paragraphs and paragraphs of failure modes, unintended consequences, and directly bad effects, but then I realized that that implicitly accepted an inappropriate burden of proof.
I am tired of hearing "Something must be done. This is something. Therefore this must be done".
Tell me, in detail, how any of these proposals will help. Include all of the steps from the initial scanning through the final removal of harm. Do not stop at "Authority(TM) will know about X, so they can fix it". Tell me how they will fix it, and how they will do that without doing harm. Not how they theoretically could. How they actually will. And make it plausible.
After you've given me that, I'll be happy to rip it to shreds for you.
Otherwise, if you can't figure out for yourself how it's harmful to give platforms massive incentives to shut down anybody who raises costs by triggering too many false positives, how it's equally harmful to give them massive incentives to broaden their definition of what's a "true" positive, how it's harmful to have thousands of random people viewing false "hits", how it's damaging to enable Authority(TM) to come down on kids for communicating among themselves, how it's dangerous to create a massive database of blackmail material on potentially vulnerable people, how it's trivial to repurpose a spying infrastructure for different targets, or how it's useless to give more reports to law enforcement that's overwhelmed with the reports it already has, then you'll have to content yourself with reading the vast volume of stuff other people have written up about the OSB and all the related proposals.
> you should convince lawmakers about this
Many of us have been trying. The OSB has not in fact passed yet. The EU and US proposals still less.
> instead of claiming the tech is impossible.
Nobody, not me, not Meredith Whittaker, not anybody, has claimed that client side scanning is impossible, or that you can't turn around and encrypt a copy of a message after you've spied on it. That is a straw man. It is entirely your fantasy.
What they've said is that it's stupid and contrary to the whole point of having the encryption in the first place. It leaks information that's supposed to be private, including false positives, and paints a target on the most sensitive stuff. It creates infrastructure for abuse. Those are the "security properties" being "communicated". And that is 100 percent true.
When she says "back doors", she's talking about system back doors, not necessarily protocol back doors. Although the protocol would have to have some way to report the data.
Anybody with a remotely clear-headed view of the situation understands that sending off plaintext copies of the stuff you then turn around and encrypt is in tension with the purpose of doing the encryption. They also understand that once you have either the scanning or the reporting system in place, there's nothing that controls how it can be used.
And they understand that the proponents of this stuff have no detailed story at all about how the leaked plaintext is supposed to be secured after the leaking is done... especially if it's actually going to be used for the stated purposes. That is a VAST technical and organizational problem that's constantly handwaved.
> What I would have a problem with is if Signal as a corporation chooses to remain in the UK market and refuse to comply with UK law.
That's another fantasy of yours. She's been very clear that if the UK does this, Signal will exit the UK market.
However, that's her and her corporation. It's not binding on the rest of us.
The fact is that "lawmakers" do not have infinite legitimate power. It is sometimes right and maybe even morally required to directly break the law.
Personally, I'm looking forward to the widespread use of P2P tools that will make Signal look like an open book... whether they're legal or not. At this point, laws even in the "free world" are descending into insanity.
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#363Earlier quoted context omitted.
Nah, this has been coming (and inevitable really) since Snowden prompted the tech companies to introduce e2e messaging. Note that similar laws are being proposed in the UK, EU Australia and Canada (not sure of the latter two tbh).
The idea of pervasive spying has been around forever. The want, and why. Apple mainstreamed, normalized the discourse, and demoed the concept of pre-scanning in the face of E2E. Apple provided the answer for the how.
Before that this sort of legislation was just straight asking for a skeleton key or a ban on e2e, many laws still do. Apple trying a thing and failing didn’t fundamentally change anything because these laws aren’t asking for a specific technology, they’re asking to be able to see all your messages no matter the method. That’s literally the politicians level of understanding “want read read messages”.
If Apple had never thought up the CSAM scanner concept they’d still be pushing to just break the encryption. Hell they may even stumble upon the “well just send us a copy or scan it for all these fingerprints before you encrypt it” concept themselves, it’s not really a tough concept.
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#364Earlier quoted context omitted.
> We don't have state sovereignty even on matters as trivial as which recreational drugs to regulate. By the letter of the law, no. But in practice we do. The federal government is thus-far unwilling to defend their turf on this issue; they have de jure sovereignty but not de facto sovereignty. If a government finds itself politically incapable of exercising a sovereign power, then in a very real sense they no longer…
There are plenty of federal drug laws that are actively enforced in states where that stuff is otherwise legal. People mostly think about basic use & possession in this context, but there's so much else. E.g. buying a gun as a medical marijuana user is a risky proposition.
Try openly producing and selling. Multi-million dollar businesses operating in open plain view of the public and any federal agent. States legalize cannabis and the federal government in turn stops enforcing their laws against cannabis in those states, demonstrating that the states have de facto sovereignty to legalize drugs. They didn't just stop prosecution for "basic use" and possession, they no longer enforce their drug laws against growers and dealers either. They've essentially given up, for the time-being at least.
The fact that the same states are not also defying federal gun laws (with some interesting exceptions *cough* alaska *cough*) is another matter entirely. The federal government does seem to be more keen on exercising their sovereign powers when it comes to guns than with drugs.
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#365Earlier quoted context omitted.
> We don't have state sovereignty even on matters as trivial as which recreational drugs to regulate. By the letter of the law, no. But in practice we do. The federal government is thus-far unwilling to defend their turf on this issue; they have de jure sovereignty but not de facto sovereignty. If a government finds itself politically incapable of exercising a sovereign power, then in a very real sense they no longer…
But that's mostly due to a string of executives that are sympathetic or indifferent to that particular issue. A president that reignited the war on drugs or had outside political motive to go after what is mostly blue states and liberal people would likely succeed.
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#366Earlier quoted context omitted.
> but they don’t feel the same way about public benefits or rights associated with other technology that is being replaced When the government creates a law within recorded history — something like a wiretapping law — then the spirit of the law is well-known at time of creation. Usually, that "spirit" is that it's created to explicitly grant a capability to the government to do a thing for the benefit of the public u…
This is why the Federalist Papers are some of the most important documents when understanding the intent of the Constitution and Bill of Rights – and simultaneously the least read! I'm not saying that case law isn't also an important aspect of the 'law' and that the constitution shouldn't be amended – I'm not really a hardcore 'originalist' – I just mean that any time a SCOTUS ruling comes out, it's clear that in the…
Maybe a datapoint supporting the Flynn Effect?
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#367Earlier quoted context omitted.
The alternative is the UK drafting people to fight in ukraine, which also makes 0 sense?
Obviously the concern is an escalation of that war which pulls NATO into the conflict fully. I don't believe that's a likely scenario, but being deliberately obtuse isn't the right way address that somebody expressing that concern.
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#368Earlier quoted context omitted.
> and these proposals would be very unlikely to materially reduce that harm. They WOULD, however, create a bunch of other harm. Including harm to children. In fact even including sexual harm to children I would want to hear your explanation for that but more importantly, you should convince lawmakers about this instead of claiming the tech is impossible. > You said it, I didn't. Yes I did, hope you got my point then.…
> I would want to hear your explanation for that but more importantly, The people who want it need to prove that it will help. I had started in to list paragraphs and paragraphs of failure modes, unintended consequences, and directly bad effects, but then I realized that that implicitly accepted an inappropriate burden of proof. I am tired of hearing "Something must be done. This is something. Therefore this must be…
Rip this to shreds: if at least one victim of a crime can be prevented by catching a witless criminal then it is worth it. Also this: Homomorphic encryption and differential privacy are a thing, if certificate transparency logs can prove no certs are issued maliciously then similar logs can be published publicly to prove that the scanning list (similar to a CRL) does not contain hashes/patterns that haven't gone through appropriate legal/regulatory checks and balances. E2EE can also be used to secure the message between the gov agency and the device. Certificate authorities already have similar exposure that can compromise all your traffic (including the signal app download/install), "shred" this and show me why a similar risk model is inapplicable to gov scan lists.
> Nobody, not me, not Meredith Whittaker, not anybody, has claimed that client side scanning is impossible, or that you can't turn around and encrypt a copy of a message after you've spied on it. That is a straw man. It is entirely your fantasy. > What they've said is that it's stupid and contrary to the whole point of having the encryption in the first place. It leaks information that's supposed to be private, including false positives, and paints a target on the most sensitive stuff. It creates infrastructure for abuse. Those are the "security properties" being "communicated". And that is 100 percent true.
No, the message you have been spreadning is that it is impossible to secure a message and spy in it which you just admitted there. That is false, that is not a strawman on my end, you just admitted it! The infrastructure can be abused? So can signal's source code repo infrastructure. Your lie is that of omission and context framing while fully knowing how non-technical policymakers will interpret what you are saying. It is absolutley possible to implement a scanning infrastructure that has the same security properties as the app's code or app store download/signature security. If you are claiming the gov end can be abused by malicious humans then that is beyond your exertise to police humans breaking laws, so long as transparency logs can be produced to criminally punish violators.
> Anybody with a remotely clear-headed view of the situation understands that sending off plaintext copies of the stuff you then turn around and encrypt is in tension with the purpose of doing the encryption.
That is not what was suggeste and I am sure you are aware that it is possible to scan for messages without sending off a copy of the message off device and also without informing anyone of false positive hits. Or even contents of true positive hits (requiring them to get a proper warrant and target the device for intrusive collection).
> That's another fantasy of yours. She's been very clear that if the UK does this, Signal will exit the UK market.
It's not a fantasy, it is possibility and I am glad signal will exit the UK if this happens. I support this kind of boycotting.
> It is sometimes right and maybe even morally required to directly break the law.
Maybe, but not everytime you don't like a law, that undermimes the rule of law. Only active and imminent harm to humans is a reason for civil disobedience not mere speculation and disagreement. You spoke of burden of proof, the other side has proof of harm to humans you are on the opposite side of civil disobedience here. You are on the side of the oblivious technocrats profiting from harming people.
> Personally, I'm looking forward to the widespread use of P2P tools that will make Signal look like an open book... whether they're legal or not. At this point, laws even in the "free world" are descending into insanity.
Me too, but for opposite reasons: so that you people finally get that technocrats and civil disobedience is not a thing. You cannot solve politics with technical rebellion. You have to actually convince your peers. Here I am as your peer engaging with you while being aware of most of the technical facts and you are not convincing me. Your strategy of using technical expertise to deceive people will backfire too and so will downvoting people like me attempting to engage in civil discourse with you in good faith. I think you will just end up facilitating the building of "GFW" level national firewalls in the west with your techniques. They are not going to stop trying to find a solution to reduce CSAM and other illicit crimes, a privacy preserving solution is possible and fighting it is a lose-lose scenario.
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#369I fail to understand what the uk is trying to achieve with its current ubiquitous surveillance. Crime in london is rampant, theft is nearly decriminalised in some areas, and now they want to monitor what people do on the internet? Other than docile tax payers what other potential goal is there? Services are steadily degrading, cost of living is out of control, quality of life dropping. Do they just want obedience, an…
When people describe the UK situation like these, they are cancelled, downvoted to hell and called right wing extremists. I am positively surprised you were not downvoted or flagged. What is UK trying to achieve? To maintain, as much as possible, a pretty controlling state in power. It is a country with no free speech, no significant human rights of any sort, population is at the mercy of the govern and they want to…
Re: Signal president says company will not comply with U.K. ‘mass surveillance’ law
#370Earlier quoted context omitted.
That's because government is a collection of institutions, the administration of the executive branch inherits them and has only limited ability to restructure them without legislative assistance (speaking about the US here, terms vary depending on the country and governance structure).
Are you saying the unelected bureaucracy is to blame? Because that's popular today too.