Live data from Hacker News

UK pulls back from clash with Big Tech over private messaging

ft.com

191–200 of 320 posts

Re: UK pulls back from clash with Big Tech over private messaging

#191
post #142

Earlier quoted context omitted.

Some anonymous entity has been putting up posters in my neighborhood decrying Apple for "allowing" CSAM to be stored on iCloud. Very creepy propaganda campaign.

Those posters are almost certainly plastered up by someone who genuinely believes in the cause. They have been manipulated by corrupt media, but it is a tactical error to assume that a political party is directly paying for such poster campaigns.

It's also guerilla marketing 101, and they wouldn't be the first company, interest group or marketing agency that used those tactics to promote their products, interests, etc.

Re: UK pulls back from clash with Big Tech over private messaging

#192
post #84

Earlier quoted context omitted.

I think its increasingly true of several countries, not just the UK. Any State with strong Freedom of Information legislation not surprisingly creates incentives for certain political operatives to want to avoid exposure by use of unofficial channels further out of reach of FoI - private WhatsApp groups etc etc. I don't see this as any different than the instances of private email service mischief that has occurred i…

I think that if you hold a position in the government, all of your communication (including private email, chats, etc) should be subject to public scrutiny. A government official should be defined not as someone who is holding power, but as an elected representative of the people.

Did you even think out this train of thought? Does this cover medical communications, military secrets, private chat between family members, etc?

Re: UK pulls back from clash with Big Tech over private messaging

#193

Earlier quoted context omitted.

This isn't true, is it? If so that's slightly terrifying.

It's not completely untrue, there was a whole hoo-hah over getting Boris Johnsons WhatsApp messages. They use it to get around the requirement that official communications be logged and available for later scrutiny, much like a bank has to retain communications in case of an audit.

Also worth a note that Boris Johnson (former prime minister for those far from the UK) himself said he was happy to share all those WhatsApp messages on his phone with the investigation team, and it was a government department that stepped in to refuse access to those messages, repeatedly. They considered the WhatsApp messages too sensitive for an official investigation to read.

Re: UK pulls back from clash with Big Tech over private messaging

#194
post #39

I'm not sure why people are assuming they've abandoned the idea. They've simply said it's not technically feasible. Which implies that later - through the power of delusions of grandeur - that it will become feasible.

So excuse what may be my profound ignorance, but aren't there 2 unencrypted points in every communication that they could intercept?

Very roughly, I assume every Whatsapp message follows something along the lines of:

1. Unencrypted input

2. Encryption

3. Encrypted transmission

4. Decryption

5. Unencrypted stream to display handler

Technically - what's to stop them from compelling Apple and Google into putting a software keyboard logger inbetween 1 & 2 and another output logger between 4 & 5?

Edit: I'm not saying this backdoor would be secure btw. Of course it wouldn't. But that seems to me a separate issue than "breaking encryption"

Re: UK pulls back from clash with Big Tech over private messaging

#195

Earlier quoted context omitted.

This isn't true, is it? If so that's slightly terrifying.

The political communications are done with WhatsApp. This is illegal of course. There has been no discussion of the obvious national security risk. https://www.theguardian.com/law/2022/mar/22/uk-ministers-acc...

This isn't even limited to the UK. In the US, we have presidents, vice presidents, and presidential candidates all under investigation for mishandling records by running their own e-mail servers. The most charitable explanation being that they don't want to have to deal with separate personal and work devices; the less charitable explanation being "fuck records laws".

Re: UK pulls back from clash with Big Tech over private messaging

#196
post #166
post #59

Earlier quoted context omitted.

> To revive this, they would have to find an expert to attest that it is technically feasible to have security with a backdoor that government can access, but at the same time is impossible for malicious entities to access. > Ergo, this is technically dead, which is the best form of dead. Except it's not. There exist such cryptographic trapdoor constructions that are perfectly secure, if the government backdoor key i…

> There exist such cryptographic trapdoor constructions that are perfectly secure, if the government backdoor key is kept safe. A big problem with this statement is the term “the government”. If you give the private key to the UK - the US, India and China will want a copy as well. The UK might want to spy on foreign nationals only in the country and only for CSAM, but that doesn’t mean other nations won’t use it for…

And don't be naive. The UK absolutely wants it so that it can surveil both it's citizens and everyone else (including within other governments) around the world.

Re: UK pulls back from clash with Big Tech over private messaging

#197

Earlier quoted context omitted.

The political communications are done with WhatsApp. This is illegal of course. There has been no discussion of the obvious national security risk. https://www.theguardian.com/law/2022/mar/22/uk-ministers-acc...

This isn't even limited to the UK. In the US, we have presidents, vice presidents, and presidential candidates all under investigation for mishandling records by running their own e-mail servers. The most charitable explanation being that they don't want to have to deal with separate personal and work devices; the less charitable explanation being "fuck records laws".

I was a federal contractor for NASA and let me tell you about government email: quota of 250MB of storage (2010-2012).

I spent every morning moving emails with attachments to local folders on my Mac (which had no backups) to keep from going over quota. If I went on a 2 week vacation emails would start to bounce to me.

After that fiasco I understood why Colin Powell told Hillary Clinton to just run her own email server (for non-classified communication).

Re: UK pulls back from clash with Big Tech over private messaging

#198

Earlier quoted context omitted.

> "I have nothing to hide anyway". People who make that argument should be forced to have high def webcams installed in their bedrooms and bathrooms.

This would make the most sense if the goal was to actually stop child abuse, given that the majority of it happens in the home.

By the people they know. More likely to be assaulted by family than a stranger.

Re: UK pulls back from clash with Big Tech over private messaging

#199

The whole UK government is run via WhatsApp. The threat to withdraw service should have concentrated minds.

That was certainly true for Boris, I can only imagine if he was in on it a lot of the other senior tories would have been as well.

That's obviously not a good thing at all, and also I would think illegal, but I guess at least it's encrypted. The irony.

Re: UK pulls back from clash with Big Tech over private messaging

#200

Earlier quoted context omitted.

I already have a remit to embrace online safety on my own terms - I can install a local filtering system if I choose to.

Of curse, but it's not terribly easy for the average person to put sophisticated filters into multiple content pipelines on every child's device (imagine having 4 or 5 kids of different ages and needs). So a solution I think we brainstormed on the show was mandating open interoperable APIs that allow easy insertion of (presumably commercial or open source) plugins into the system, within the user's end-to-end digital…

> So a solution I think we brainstormed on the show was mandating open interoperable APIs that allow easy insertion of (presumably commercial or open source) plugins into the system, within the user's end-to-end digital estate, under the control of the user (parent) and completely rejecting the MITM and endpoint compromise via back-doors that the government naively proposed.

What you're proposing would likely enable the creation of some fairly invasive stalkerware. Don't forget that 1) just because a feature says it's for use by a parent on their child's device doesn't mean that it can only be used in that context, nor that 2) not all parents have their children's best interests in mind.

Post reply on HN