Live data from Hacker News

European Court of Human Rights bans weakening of secure end-to-end encryption

eureporter.co

31–40 of 273 posts

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#31

For a better understanding: The Court held (in the circumstances of this case) that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. The law in question specifically obligated messengers such as Telegram to hand over communications alongside the "information necessary to decrypt electronic messages if they were encrypted". To come to that conclusion, it re…

> The Court held that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy.

*when no adequate safeguards against abuse are in place

Unfortunately it is not as straightforward as that it's incompatible altogether. Per this ruling, it's only incompatible when there are no good safeguards (they use the word "adequate" in one place and "suitable" in another, neither is very specific about what it means)

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#32

Reminder that the European Court of Human Rights, although very powerful and influential, does not have the authority to force anyone to abide by their rulings. Also, here's a better article: https://fortune.com/2024/02/13/end-to-end-encryption-russia-...

Slightly misleading: The Court's judgments are legally binding upon the State members of the Council of Europe. However, it is true that there is no armed enforcement mechanism – something that most domestic courts lack too – and instead decisions are enforced and monitored by the Council of Ministers (the equivalent of the UN General Assembly). However, most of its decisions are complied with most of the time by most nations (safe for Russia and Turkey), frequently because domestic courts will abide by the Court's rulings to overturn laws through its own decisions.

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#33
post #18

Earlier quoted context omitted.

Its a judgement that will provide precedence. A Pirate Party member of the European Parliament comments because its a core issue to the party. Why would there be anything about the Pirate Party in the ruling?

I thought precedents only matter in the US "common law" framework, but most of the EU is following the "civil law" framework where precedents do not matter. Does this precedent really matter?

Precedence is still a thing. Just less mechanically than in the US.

This might be interesting: https://opensiuc.lib.siu.edu/cgi/viewcontent.cgi?article=101...

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#34
post #28
post #25

Earlier quoted context omitted.

Why would you include "We Pirates will now fight even harder for our digital privacy of correspondence!" (and then continuing to link their website as a source of truth on the matter) in a non-promotional piece? This is an advertisement, not a news article One which I agree with, to be clear. I'm not opposed to the pirate party's views on digital matters. This party's goals/narrative just has no place in a piece abou…

I'm not arguing that with you. You misunderstood what was going on here, edited your comments many times, and now you want to discuss the article linked instead of the actual news (the judgement). Calm down.

I edited in more info as I found it, trying to be helpful for what's currently the top comment. Sorry if that's not okay

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#35

Reminder that the European Court of Human Rights, although very powerful and influential, does not have the authority to force anyone to abide by their rulings. Also, here's a better article: https://fortune.com/2024/02/13/end-to-end-encryption-russia-...

Not so. The UK, for instance, appears to treat these rulings as binding. This is why the UK conservatives want to scrap the Human Rights Act and replace it with a supposedly identical Bill of Rights, the key difference being a presumption that the UK's supreme court would cease to defer to the convention court.

A couple of examples relating to this that come to mind:

* Deporting refugees to Rwanda was stopped by an injunction from the ECHR * Depriving prisoners of votes was ruled illegal in 2005 or so

There are a few others but these two come to mind.

My understanding is that although the treaties (plural?) of the CoE and ECHR don't assume judgements are binding, a number of countries made them binding in their legal systems via domestic legal instruments.

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#36

Is there an exception for emergency purposes?

I think that depends on what you mean: a general state of emergency or a specific situation where the police deem there to be an emergency (e.g. classic hidden bomb scenario)

Regarding (2), the Court found that a statutory obligation to decrypt E2E-encrypted data upon (judicial) request to be disproportionate, but it could still be imagined that – if more narrowly construed – a law could be considered to be proportionate. But the Court does seem quite unwilling to entertain the idea of backdoors for E2E encryption.

Regarding (1), the European Convention on Human Rights (ECHR) allows so-called derogations from certain rights in "time of war or other public emergency threatening the life of the nation" (Art 15 ECHR), insofar as they are necessary and the state of emergency has been properly declared. The right to privacy is such a right, so a State that faces an insurgency may declare a state of emergency and, as part of its emergency measures, could probably demand the decryption of E2E communications if it's necessary to fight the insurgency (e.g. it's a guerilla group using an E2E messenger) - but hard to judge in the abstract.

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#37
post #12
post #3

Earlier quoted context omitted.

When there is an emergency to break into a house, the police needs to get a mandate from a judge.

That's not true at least in Spain. There's "In flagrante delicto" which means if the police suspects something going on they can kick your door down. It was used many times during the pandemic: when they suspected you were having too many people over at home, they acted. Unconstitutionally, mind you. The EU is not the utopia many think it is.

People think the EU is a utopia? I just think it is the best of a bad bunch

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#38
post #25
post #18

Earlier quoted context omitted.

Its a judgement that will provide precedence. A Pirate Party member of the European Parliament comments because its a core issue to the party. Why would there be anything about the Pirate Party in the ruling?

Why would you include "We Pirates will now fight even harder for our digital privacy of correspondence!" (and then continuing to link their website as a source of truth on the matter) in a non-promotional piece? This is an advertisement, not a news article One which I agree with, to be clear. I'm not opposed to the pirate party's views on digital matters. This party's goals/narrative just has no place in a piece abou…

There’s a disclaimer at the bottom of the article that says they publish articles from a variety of sources, and that the viewpoints expressed aren’t necessarily their own, etc. Considering that it does seem to have an angle, the byline says it’s from their own unnamed correspondent, it’s not called an opinion piece, and there’s no link to the original, I’m guessing their slightly unpredictable correspondent’s surname is GPT.

Re: European Court of Human Rights bans weakening of secure end-to-end encryption

#40
post #31

For a better understanding: The Court held (in the circumstances of this case) that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. The law in question specifically obligated messengers such as Telegram to hand over communications alongside the "information necessary to decrypt electronic messages if they were encrypted". To come to that conclusion, it re…

> The Court held that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. *when no adequate safeguards against abuse are in place Unfortunately it is not as straightforward as that it's incompatible altogether. Per this ruling, it's only incompatible when there are no good safeguards (they use the word "adequate" in one place and "suitable" in another, neithe…

Yes, that is very true. The Court generally does not oppose surveillance measures in general, as long as adequate safeguards are in place. However, I read the relevant paragraphs (paras 76-79) to be quite a strong rejection of any statutory obligation that would effectively require the installation of a backdoor undermining E2EE. The criticism of a lack of adequate safeguards and the risk of abuse is more focused on other aspects of the law.

That also becomes clear in the key paragraph 80: "The Court concludes from the foregoing that the contested legislation providing for the retention of all Internet communications of all users, the security services’ direct access to the data stored _without adequate safeguards against abuse_ and the _requirement to decrypt encrypted communications_, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society"

The Court does not qualify the requirement to decrypt E2EE communications with the same safeguards requirements. That of course does not exclude the possibility of the Court finding that a more narrowly-construed law is not in violation. But the Court clearly signals its skepticism towards any "requirement that providers of such services weaken the encryption mechanism for all users" (para 79).

Post reply on HN