Live data from Hacker News

Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

blog.torproject.org

31–40 of 55 posts

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#31
post #2

But think of the children!! 'Technology companies currently use encryption positively to keep your bank transactions and online purchases safe and secure. Encryption has many other uses throughout everyday life, but some social media companies such as Meta are proposing to implement or already have implemented E2EE in private messaging spaces. E2EE overrides current controls in place that help to keep children safe a…

> E2EE overrides current controls in place There are no controls in place. This line is becoming quite a pattern in UK (Tory) government rhetoric. They forcefully state wishful thinking as if it were a fact. There are no controls because there is no possibility of controls, as a matter of mathematics. But by exploiting ignorance, the tories managed to beast parliament into an intractable "just imagine if..." clause i…

> There are no controls because there is no possibility of controls, as a matter of mathematics.

This is kind of true because, for example, the one-time pad is information-theoretically secure, and anyone could choose to use a one-time pad with anyone else given prior arrangements. Or anyone could choose to use RSA for confidentiality with anyone else given a mutual desire to communicate confidentially and an authentic but not confidential channel.

However, there's nothing mathematically stopping a government from punishing people who are observed to follow a protocol to create a confidential channel. Although Eben Moglen has argued that the right to speak PGP is the right to speak Navajo, a government could conceivably choose to punish people for speaking a foreign language.

One might wish (I would certainly wish) that people would be extremely upset by this, but I guess it wouldn't contravene mathematics.

In fact, there are some historic cases where populations were subject to official military censorship in wartime, which included overt government review of some of their communications, and possibly a prohibition on the use of "codes", and sometimes restrictions on the use of foreign languages. One might again wish that this would be both much less acceptable and much less feasible now than in the past, but it's not completely impossible.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#32

Earlier quoted context omitted.

Lots of people, including my parents, use email as an asynchronous messaging platform. For those people, Signal is an eminently suitable replacement. As the post points out: email cannot be extended into a secure position. Attempts to do so either fail to interoperate or fail outright.

Email is also an archive of communications with vendors, shops and government departments. Signal doesn't let you migrate chat history to your desktop. Trying to migrate between phones while retaining your Signal history is too hard for most people. Signal is not at all a suitable replacement, and I believe that forward secrecy is an anti-feature for an email-like usecase.

You know you're in trouble when people start talking about forward secrecy being problematic. What you're saying about the "email-like use case" for cryptography is that it's unserious protection, because a lack of forward secrecy practically guarantees full decryption of the entire history of messages, for any ordinary participant in the system.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#33
post #25

Earlier quoted context omitted.

I agree that the verification UI sucks. I have similar stories about otherwise technical people not knowing about it or otherwise not understanding it. At the same time: the relevant comparison here is email. Email isn’t even TOFU between arbitrary identities; it’s trust-on-each-message. Similarly for conceptual identities (like a bank’s catch-all address). (I also agree with your point about this needing to be one o…

Email these days is however tied to DKIM and domains. We have UI problems, but communicating to a companies email servers at their domain name can be reasonably expected to be communicating with that company. It's just the security story on that if you never want the content disclosed isn't great, but conversely, conceptual entity communications are always going to be a bit public by nature. There's a whole other ran…

DKIM is an anti-spam tool, not an end-to-end encryption tool (obviously, it's not end-to-end at all, and if you're relying on it, you might as well forget about message encryption, because you've simply decided to trust your server).

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#34

And for hiding the activities of pedophiles and terrorists. Encryption isn't solely beneficial to human rights, it enables considerable harm to be shielded from scrutiny. There has to be a balance with the extent to which applications of encryption are permitted in society.

you aren’t very bright, are you?

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#35
post #5

One of the largest holes in encrypted communication is still the fact that the vast majority of email is still neither digitally signed, nor encrypted. And even if they are, the usual schemes do not encrypt the subject line. I wish there was something like Let's encrypt but for email. Just make it trivial to sign and encrypt your mail. Also, mail clients should give a huge warning for unencrypted and/or unsigned mail…

This is actually the best example for why encryption isn't a human right. Postal mail isn't encrypted, telephone calls aren't encrypted, and the UN hasn't made a declaration about that. Why is that? It's because encryption is a red herring. The theory that encryption is going to stop government surveillance is ridiculous. Even a perfect technology is not going to override national politics. Any government oppressive…

Postal mail isn't encrypted because it's not viable for ordinary citizens to encrypt physical mail.

However, tampering with mail, or opening someone else's, is a federal crime with harsh penalties attached. The message is clear: "postal secrecy" is highly valued.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#36

And for hiding the activities of pedophiles and terrorists. Encryption isn't solely beneficial to human rights, it enables considerable harm to be shielded from scrutiny. There has to be a balance with the extent to which applications of encryption are permitted in society.

you aren’t very bright, are you?

Based on their username, I assume they play devils advocate

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#37

And for hiding the activities of pedophiles and terrorists. Encryption isn't solely beneficial to human rights, it enables considerable harm to be shielded from scrutiny. There has to be a balance with the extent to which applications of encryption are permitted in society.

Cars, guns, knives, sharp sticks, rocks, language, religion, belief, opinion, cigarettes, sugar, bad parenting, divorce, marriage. Ban 'em all!

Humanity's evils pre-date technology, therefore banning technology will not remove them.

I'd also go on to say that many of the examples I've listed above have more to do with the creation of both terrorists and pedophiles, by a very wide margin, than encryption.

Problems that are hard to solve inevitably have scapegoat solutions thrown at them.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#38

Earlier quoted context omitted.

That’s the point about interoperability. If we’re going to make “email v2” (not a terrible idea!), then the considerations that will go into securing it will ensure that it’s entirely incompatible with the thing we currently call email. In other words: without sufficient clarity, email v2 just confuses people like my parents. Who would be better served by Signal anyways.

Vendors big enough to be known by your parents are sophisticated enough to paper over the differences and make it seamless. (Where possible)

“Where possible” is doing a lot of work!

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#39
post #32

Earlier quoted context omitted.

Email is also an archive of communications with vendors, shops and government departments. Signal doesn't let you migrate chat history to your desktop. Trying to migrate between phones while retaining your Signal history is too hard for most people. Signal is not at all a suitable replacement, and I believe that forward secrecy is an anti-feature for an email-like usecase.

You know you're in trouble when people start talking about forward secrecy being problematic. What you're saying about the "email-like use case" for cryptography is that it's unserious protection, because a lack of forward secrecy practically guarantees full decryption of the entire history of messages, for any ordinary participant in the system.

A major goal of an email-like system is full decryption of the entire history of messages.

Same as it's a feature of my filing cabinet that items don't incinerate themselves whenever I move house.

Re: Global Encryption Day: Encryption's Critical Role in Safeguarding Human Rights

#40
post #32

Earlier quoted context omitted.

You know you're in trouble when people start talking about forward secrecy being problematic. What you're saying about the "email-like use case" for cryptography is that it's unserious protection, because a lack of forward secrecy practically guarantees full decryption of the entire history of messages, for any ordinary participant in the system.

A major goal of an email-like system is full decryption of the entire history of messages. Same as it's a feature of my filing cabinet that items don't incinerate themselves whenever I move house.

Sure. Because people overwhelmingly aren't relying on the security of their email; it's overwhelmingly stuff no adversary would care to read. Then they retrofit the UX requirements they have for those boring mails onto all emails, and suggest that encrypted email should just accept those as constraints, and then we'll declare victory.
Post reply on HN