Live data from Hacker News

UK pulls back from clash with Big Tech over private messaging

ft.com

201–210 of 320 posts

Re: UK pulls back from clash with Big Tech over private messaging

#201

Earlier quoted context omitted.

It's not completely untrue, there was a whole hoo-hah over getting Boris Johnsons WhatsApp messages. They use it to get around the requirement that official communications be logged and available for later scrutiny, much like a bank has to retain communications in case of an audit.

Also worth a note that Boris Johnson (former prime minister for those far from the UK) himself said he was happy to share all those WhatsApp messages on his phone with the investigation team, and it was a government department that stepped in to refuse access to those messages, repeatedly. They considered the WhatsApp messages too sensitive for an official investigation to read.

Well, if Boris Johnson said it, it must be true. It was his radical honesty that cost him the Prime Ministership, after all.

Re: UK pulls back from clash with Big Tech over private messaging

#202
post #166

Earlier quoted context omitted.

> There exist such cryptographic trapdoor constructions that are perfectly secure, if the government backdoor key is kept safe. A big problem with this statement is the term “the government”. If you give the private key to the UK - the US, India and China will want a copy as well. The UK might want to spy on foreign nationals only in the country and only for CSAM, but that doesn’t mean other nations won’t use it for…

The ostensible reasoning is "think of the children" horseshit, but history proves such a powerful capability will be abused for unrestrained spying. Key escrow for the entire US and world was floated with the Clipper chip (1993-1996). That was strangled in its crib because trusting thousands of people at NSA or GCHQ to just not stalk people is sheer fantasy, just as the Snowden leaks revealed. iMessage stores the e2e…

Why is Signal "irreparably" broken? What makes the phone number issue "irreparable"? As I understand it usernames and phone number privacy are in the pipeline.

I'm a software engineer who does know; I'm aware that Signal is currently tied to phone numbers, and I'd love for it not to be, but I still use it, because it's E2EE and easy for non-technical people to use.

When there's something that's easy to use like Signal that uses decentralized cryptographic identifiers and onion routes all traffic, I'll start trying to get people to use that. I'd be happy to hear any recommendations.

Re: UK pulls back from clash with Big Tech over private messaging

#203
This is framed wrong: It isn't UK against "Big Tech" it's the UK government against privacy and, to some extent, basic logic. That is, the UK government demanded something that's impossible to deliver, and would have ruined the privacy rights of its own citizens had it been able to force companies to deliver the next closest thing which actually got the government its core demands of the police being able to snoop on everyone's messages.

Re: UK pulls back from clash with Big Tech over private messaging

#204
post #5

It's a little unclear, but my reading of this is that the power to do it will still be in the law, requiring at most secondary legislation to put into effect (perhaps not even that) if they think they ever have enough leverage over messaging providers, or are willing to spend the political capital. Not a great place to be in really, but better than it actually being deployed.

I’d bet my life we start to see a massive influx of bad press aimed at messaging providers, focusing on how criminals are using their services, over the next few years. When the general sentiment of the average Dave is ‘encryption === bad’ this BS will rear its head again. Seems to have been the standard play for governments of this country for decades now.

Bitcoin is an example of this already played out.

News cycle perpetuates bitcoin == bad so everyone you know just repeats "scam" and points to criminals.

Meanwhile the largest institutions and richest people are investing heavily due to its revolutionary nature. Just look at all the ETFs coming out (Blackrock, Fidelity, etc).

Once they are fully setup you'll see the news cycle change sentiment. Rinse, repeat, with any technology.

Re: UK pulls back from clash with Big Tech over private messaging

#205

Earlier quoted context omitted.

Also worth a note that Boris Johnson (former prime minister for those far from the UK) himself said he was happy to share all those WhatsApp messages on his phone with the investigation team, and it was a government department that stepped in to refuse access to those messages, repeatedly. They considered the WhatsApp messages too sensitive for an official investigation to read.

Well, if Boris Johnson said it, it must be true. It was his radical honesty that cost him the Prime Ministership, after all.

This does not reflect my experience at all. 3/5 would not vote again.

Re: UK pulls back from clash with Big Tech over private messaging

#206

Earlier quoted context omitted.

Doesn't this problem exist throughout the tech industry though? Microsoft, Google, Apple etc are keeping the keys that allow you to push updates secret, aren't they?

Yeah, but if we're honest all three of those companies are more competent than the UK goverment. Source: sometimes interact with the UK government

So you just make the three companies keep the keys then. People are out here like "a secure backdoor to encryption is impossible" and then don't even blink for the keys for root CAs which is the basis for the world's online security. Or the AWS managed S3 encryption keys.

There's a lot of of hopium in this thread for people who I think want it to be more impossible in practice than it really is.

Re: UK pulls back from clash with Big Tech over private messaging

#207

Earlier quoted context omitted.

I’d bet my life we start to see a massive influx of bad press aimed at messaging providers, focusing on how criminals are using their services, over the next few years. When the general sentiment of the average Dave is ‘encryption === bad’ this BS will rear its head again. Seems to have been the standard play for governments of this country for decades now.

Bitcoin is an example of this already played out. News cycle perpetuates bitcoin == bad so everyone you know just repeats "scam" and points to criminals. Meanwhile the largest institutions and richest people are investing heavily due to its revolutionary nature. Just look at all the ETFs coming out (Blackrock, Fidelity, etc). Once they are fully setup you'll see the news cycle change sentiment. Rinse, repeat, with an…

> Meanwhile the largest institutions and richest people are investing heavily due to its revolutionary nature.

Is that why are they investing? Do investors care if it's revolutionary or that they just get high returns?

E.g. a lot of "coins" have promised high returns that were obviously not sustainable.

Re: UK pulls back from clash with Big Tech over private messaging

#208

The real question is why did they want this? Is the UK suffering some giant crime wave or are the powers that be just really intent on making sure people are using Bad Think in their private chats?

No, they just see that the citizens will have access to greater privacy and security than before (to protect everyone's private information from criminal hackers, foreign states, etc.) and fear losing access to surveillance.

That this will lead to a significant amount of crime is simply assumed, and not from any basis in reality. They also misuse statistics to try and make issues look larger than they are, which does a disservice when these are actually really serious issues. Like with CSAM, they always talk about so many millions of reports, without mentioning that reports are only suspected content, and the vast majority turn out not to actually be illegal (something like 70-80% of reports are discarded by law enforcement in the first pass - but it's understandable that platforms have to be extremely conservative and report anything that even looks a little like it could possibly be CSAM). Then there are massive amounts of duplication and things like that. But it is a serious issue, so it does my head in that they misuse the 'big, impressive reports number' when they know only a fraction lead to investigations, because that just gives critics a basis to show that they're massively exaggerating which could lead people to minimise the issues.

Of course, at the end of the day, you can't surveil your way to safety and these problems are best solved at the source. But that would require things like fighting poverty (oh no, welfare spending!) and deploying large numbers of social workers to help support people in marginalised communities.

Re: UK pulls back from clash with Big Tech over private messaging

#209

You see this time and time again, some initiative to "just introduce some backdoors, what could go wrong", and then it takes some time for people who understand what it actually means to convince them that it is in fact a really bad idea and it would be a giant disaster.

Unfortunately I suspect they will just keep trying it out over and over until the public gets too exhausted to rally against it anymore.

> until the public gets too exhausted

I see this theory pop up around here every few months. Where does it come from? I suspect it's a meme without basis.

Can you please name one time in history where the public gets "exhausted", and as a consequence unwanted legislation is passed?

Re: UK pulls back from clash with Big Tech over private messaging

#210
post #165

Earlier quoted context omitted.

You also need to understand the context that in the UK, and most of the west other than the US, WhatsApp is just the default communication channel for messaging. If you text someone, it's just assumed it's via WhatsApp.

I don't think so. When you text somebody it's assumed it's SMS, but if your friendship circle is on Android then in actual fact it's Google Messages. All the same benefits: end-to-end encryption and data mining.

No. I have lived in the UK for 35 years and I didn't even know Google Messages existed until you mentioned it. WhatsApp is the default and I would only use SMS in the rare case that someone did not use WhatsApp.

There is no automatic integration on Android phones between SMS and another network the way iMessage is automatic.

Post reply on HN