Live data from Hacker News

UK pulls back from clash with Big Tech over private messaging

ft.com

31–40 of 320 posts

Re: UK pulls back from clash with Big Tech over private messaging

#31
post #26

[flagged]

> How could such a gulf emerge between good intent and practice? Road to hell paved with good intentions - always has been. To be honest, I don't think it could have gone any differently. It's an eminently hard thing to achieve: we want everyone to be free on the internet, but we also want "bad guys" not to be, and you can't really disjoint the two sets of people.

I agree on the intractability of the problem. But could it have gone differently?

I'd like to think so.

How could it have gone differently?

Sincerity and honesty from the get-go. Using science and mathematics?

It is the deceit and self-deceit, the avoidance of difficult questions that has marred this bill from the start.

Ambitious social aims need backing up with outstanding technical competence, in computing, law, social sciences....

That didn't happen. Ignoring the advice of experts has been business as usual for our government, at least since Covid.

Re: UK pulls back from clash with Big Tech over private messaging

#32

[flagged]

It's very easy to protect kids online - simply don't allow them online. Banning children from the internet violates fewer people's rights(the number of children) than violating everyone's right to privacy(the total population: adults + children). The podcast makes a unsubstantiated and unexamined assumption: kids must be online. A cursory glance reveals that they in fact do not.

> The podcast makes a unsubstantiated and unexamined assumption: kids > must be online.

You haven't listened to a single word of it have you?

https://soundcloud.com/chrismorrisbits/peter-ohanraha-hanrah...

It says precisely the opposite.

Re: UK pulls back from clash with Big Tech over private messaging

#33
post #11

Earlier quoted context omitted.

"Strong enough post-quantum schemes" already exist, and every single mainstream communications platform will update to become quantum-proof overnight if/when quantum computers approach that level of capability. Quantum computers cracking encryption is really not a concern on anyone's mind, at least no more than, say, modern processors cracking SHA-1 etc.

TIL! Which ones? I've only seen ones that were proclaimed to be secure, only to be broken in some simple/clever ways not much later.

There were a lot of pqcrypto candidates, and several of them were indeed thoroughly broken, prey to the fearsome cryptanalyst's laptop left running over a weekend

NIST standardized Kyber and Dilithium, and for now at least, they seem to be holding up. I'd still want to do hybrid (ECC+PQ) asymmetric crypto for the time being, but we're (slowly) starting to gain a modicum of confidence in the new standards, enough for deployment

Re: UK pulls back from clash with Big Tech over private messaging

#35

Earlier quoted context omitted.

> why not just distribute your message over that channel in the first place Latency? You can hand deliver a password ahead of time, but not messages.

One-time pad isn't a password. It is a flash drive or hard drive full of random bits.

The difference between those is just one of scale and storage.

You still have to reliably move a chunk of out-of-band information in a way such that it gets to (and only gets to) the person you want to have it.

Re: UK pulls back from clash with Big Tech over private messaging

#36
post #14

Earlier quoted context omitted.

Quantum computing doesn’t matter. Nothing in the universe can break a one time pad.

Is quantum computing relevant to symmetric encryption like OTP? GP was talking about asymmetric encryption. My limited understanding is that quantum computing is a threat to asymmetric encryption. There's also the question of, if you can distribute a key which is at least the same size as your message over a secure channel - why not just distribute your message over that channel in the first place?

One-time pads are obviously not a serious widespread cryptography proposal.

But the question of, "Why not just send the message instead of the pad" is pretty straightforward: when you have the opportunity to safely deliver the pad, you don't know what the message will be. When you do know what the message will be, you don't have the opportunity to safely deliver the pad.

Re: UK pulls back from clash with Big Tech over private messaging

#37
post #5

It's a little unclear, but my reading of this is that the power to do it will still be in the law, requiring at most secondary legislation to put into effect (perhaps not even that) if they think they ever have enough leverage over messaging providers, or are willing to spend the political capital. Not a great place to be in really, but better than it actually being deployed.

Yeah that was my reading as well. The legislation isn't being changed. The statement even says "We know you can develop [the methods to access], and we still have the authority to order it."

The only relevant part of from op is the govt acknowledging that 2+2 = 4. But it fails to acknowledge that if they want to get 5, they can still order the equation to be 3+2.

Re: UK pulls back from clash with Big Tech over private messaging

#38

So it seems from the news that it was industry that forced this, but do we know how effective our campaigning and emails to MPs were? Or just some un-noteworthy political cog wheel action? How could we find out? Do the reasons get leaked unofficially usually?

Maybe don't over-rate the influence of the industry.

The Conservative party's own members tore it to shreds.

From: https://cybershow.uk/media/episodes/OSB1_r2_2023-08-27.mp3 *

"The source of the bill itself, the UK Conservative Party, has a significant number of its own critics calling it "fundamentally misdesigned" David Davis said its well-intentioned attempts may constitute "the biggest accidental curtailment of free speech in modern history."

(* sadly my other sincere comment has been buried by people who apparently can't read past the first line)

Post reply on HN