Live data from Hacker News

UK pulls back from clash with Big Tech over private messaging

ft.com

71–80 of 320 posts

Re: UK pulls back from clash with Big Tech over private messaging

#71
post #59
post #43

Earlier quoted context omitted.

Not technically feasible is akin to abandonment in government circles. To revive this, they would have to find an expert to attest that it is technically feasible to have security with a backdoor that government can access, but at the same time is impossible for malicious entities to access. Ergo, this is technically dead, which is the best form of dead.

> To revive this, they would have to find an expert to attest that it is technically feasible to have security with a backdoor that government can access, but at the same time is impossible for malicious entities to access. > Ergo, this is technically dead, which is the best form of dead. Except it's not. There exist such cryptographic trapdoor constructions that are perfectly secure, if the government backdoor key i…

> The problem is keeping the government backdoor key safe.

Not a problem. Just change the locks every week. [tapping head]

Re: UK pulls back from clash with Big Tech over private messaging

#72

So it seems from the news that it was industry that forced this, but do we know how effective our campaigning and emails to MPs were? Or just some un-noteworthy political cog wheel action? How could we find out? Do the reasons get leaked unofficially usually?

Maybe don't over-rate the influence of the industry. The Conservative party's own members tore it to shreds. From: https://cybershow.uk/media/episodes/OSB1_r2_2023-08-27.mp3 * "The source of the bill itself, the UK Conservative Party, has a significant number of its own critics calling it "fundamentally misdesigned" David Davis said its well-intentioned attempts may constitute "the biggest accidental curtailment of f…

David Davis is somewhat unusual - he actually resigned as MP to protest against an erosion of civil liberties (and stood on a civil liberty platform)

Westminster will be a worse place when he goes, which I assume will be in next year’s election.

Re: UK pulls back from clash with Big Tech over private messaging

#73
post #43
post #39

I'm not sure why people are assuming they've abandoned the idea. They've simply said it's not technically feasible. Which implies that later - through the power of delusions of grandeur - that it will become feasible.

Not technically feasible is akin to abandonment in government circles. To revive this, they would have to find an expert to attest that it is technically feasible to have security with a backdoor that government can access, but at the same time is impossible for malicious entities to access. Ergo, this is technically dead, which is the best form of dead.

> Ergo, this is technically dead, which is the best form of dead.

It's an older reference, sir, but it checks out.

Re: UK pulls back from clash with Big Tech over private messaging

#74
post #14

Earlier quoted context omitted.

Quantum computing doesn’t matter. Nothing in the universe can break a one time pad.

Is quantum computing relevant to symmetric encryption like OTP? GP was talking about asymmetric encryption. My limited understanding is that quantum computing is a threat to asymmetric encryption. There's also the question of, if you can distribute a key which is at least the same size as your message over a secure channel - why not just distribute your message over that channel in the first place?

Because with QKD you can distribute a random key knowing that there were no observers but you cannot distribute a message with the same guarantees. Specifically, any given bit exchanged might be observed, but that is detectable so the bit can be discarded.

I read some years ago about a non quantum technique to achieve the same based on (I think) noise in a coupled electronic system. I wonder if that has been tested further.

Re: UK pulls back from clash with Big Tech over private messaging

#75
post #5

It's a little unclear, but my reading of this is that the power to do it will still be in the law, requiring at most secondary legislation to put into effect (perhaps not even that) if they think they ever have enough leverage over messaging providers, or are willing to spend the political capital. Not a great place to be in really, but better than it actually being deployed.

I’d bet my life we start to see a massive influx of bad press aimed at messaging providers, focusing on how criminals are using their services, over the next few years.

When the general sentiment of the average Dave is ‘encryption === bad’ this BS will rear its head again.

Seems to have been the standard play for governments of this country for decades now.

Re: UK pulls back from clash with Big Tech over private messaging

#76

Earlier quoted context omitted.

Through most of history government always has the power, but the question is whether it has the legitimacy. In this case it has the legitimacy, but lacks the power. This is an unusual turn. We need online safety for kids. The aims of this bill should obtain widespread support from everyone. But instead of carefully researching and implementing difficult ideas, framing it properly and obtaining permission from the peo…

People might be more receptive if the UK government had shown any real intention of going after pedos before this. But the number of scandals and coverups indicate they dont. And this is little more than an excuse to make it easier to spy on their subjects.

[flagged]

Re: UK pulls back from clash with Big Tech over private messaging

#77
post #67
post #59

Earlier quoted context omitted.

> To revive this, they would have to find an expert to attest that it is technically feasible to have security with a backdoor that government can access, but at the same time is impossible for malicious entities to access. > Ergo, this is technically dead, which is the best form of dead. Except it's not. There exist such cryptographic trapdoor constructions that are perfectly secure, if the government backdoor key i…

well, by definition if the key is to be used, and to be used more than once, it cannot be kept safe. The key has to go through multiple hands on its way from the senior government official responsible for its safekeeping to the peon assigned to unlock a specific phone at a specific point in time. It could be copied at any one of those points. No amount of technology or cryptography can solve the master key problem. T…

Doesn't this problem exist throughout the tech industry though?

Microsoft, Google, Apple etc are keeping the keys that allow you to push updates secret, aren't they?

Re: UK pulls back from clash with Big Tech over private messaging

#78

The whole UK government is run via WhatsApp. The threat to withdraw service should have concentrated minds.

This isn't true, is it? If so that's slightly terrifying.

It does seem to be slightly true

Re: UK pulls back from clash with Big Tech over private messaging

#79
post #52

Earlier quoted context omitted.

Through most of history government always has the power, but the question is whether it has the legitimacy. In this case it has the legitimacy, but lacks the power. This is an unusual turn. We need online safety for kids. The aims of this bill should obtain widespread support from everyone. But instead of carefully researching and implementing difficult ideas, framing it properly and obtaining permission from the peo…

Online safety for kids begins at home. The problem is most parents are just too lazy.

Or too busy? In plenty of families both parents have to work hard to make ends meet.

Not helped by the fact that children are growing up in a completely different environment to the one their parents remember. Familiarizing myself with TikTok or whatever the kids are into these days would fill me with dread. And the way platforms work means my experience of them would differ dramatically from a child's anyway.

Re: UK pulls back from clash with Big Tech over private messaging

#80

The real question is why did they want this? Is the UK suffering some giant crime wave or are the powers that be just really intent on making sure people are using Bad Think in their private chats?

This bill (the Online Safety Bill) has a long and politically complicated history. It was originally motivated by the Cameron government's fairly limited desire to mandate that public WiFi had porn filters in place and then seems to have grown over many years to include a huge number of pet projects and power grabs from various career bureaucrats.

I don't think politicians set out to do this but it's been around in some form or other in Whitehall for so long that there's no real responsibility anywhere and it was low priority enough that noone ever thought to properly kill it.

It's very British in that sense.

Post reply on HN