Earlier quoted context omitted.
> The Court held that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. *when no adequate safeguards against abuse are in place Unfortunately it is not as straightforward as that it's incompatible altogether. Per this ruling, it's only incompatible when there are no good safeguards (they use the word "adequate" in one place and "suitable" in another, neithe…
Yes, that is very true. The Court generally does not oppose surveillance measures in general, as long as adequate safeguards are in place. However, I read the relevant paragraphs (paras 76-79) to be quite a strong rejection of any statutory obligation that would effectively require the installation of a backdoor undermining E2EE. The criticism of a lack of adequate safeguards and the risk of abuse is more focused on…
European Court of Human Rights bans weakening of secure end-to-end encryption
61–70 of 273 posts
Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#62Earlier quoted context omitted.
Its a judgement that will provide precedence. A Pirate Party member of the European Parliament comments because its a core issue to the party. Why would there be anything about the Pirate Party in the ruling?
I thought precedents only matter in the US "common law" framework, but most of the EU is following the "civil law" framework where precedents do not matter. Does this precedent really matter?
And precedent has it's place in civil law countries too, mostly around clarifying existing legislation in case of ambiguity, but it isn't an automatic ironclad thing.
Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#63For a better understanding: The Court held (in the circumstances of this case) that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. The law in question specifically obligated messengers such as Telegram to hand over communications alongside the "information necessary to decrypt electronic messages if they were encrypted". To come to that conclusion, it re…
> The Court held that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. *when no adequate safeguards against abuse are in place Unfortunately it is not as straightforward as that it's incompatible altogether. Per this ruling, it's only incompatible when there are no good safeguards (they use the word "adequate" in one place and "suitable" in another, neithe…
> For a detailed description of safeguards that should be set out in law for it to meet the “quality of law” requirements and to ensure that secret surveillance measures are applied only when “necessary in a democratic society”, see Roman Zakharov, §§ 231-34, and Big Brother Watch and Others, §§ 335-39
I am not a lawyer and not motivated enough to go read those decisions, but if anyone is curious that is probably the place to start to figure out what might count as "adequate safeguards".
Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#64Earlier quoted context omitted.
I was assuming it had jurisdiction over the EU? What is the actual real world impact of this?
It's a part of the Council of Europe, which includes all European countries besides Russia and Belarus (who got kicked out last year). It has no real enforcement powers for its judgements, though most countries do adopt most its judgements, and it has pushed human rights in Europe forward a lot. While the EU could potentially just ignore the statement, there's a good chance they won't, especially as the European Parl…
Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#65Earlier quoted context omitted.
The UK DOES NOT WANT TO LEAVE THE ECHR. Select people in the government want to, not the whole of UK.
To tack onto this I don't think most people in the UK understand what the ECHR does and why leaving the EU didn't alter our obligations under the ECHR. The media carries a lot of responsibility for that but not all of it - nearly every person in the UK carries a little box with access to a huge chunk of the sum total of all human knowledge, they just choose to not to use it. If that sounds elitist or arrogant it's be…
Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#66For a better understanding: The Court held (in the circumstances of this case) that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. The law in question specifically obligated messengers such as Telegram to hand over communications alongside the "information necessary to decrypt electronic messages if they were encrypted". To come to that conclusion, it re…
It's worth noting that UK courts can't overturn Acts of Parliament.
The best they can do is issue a declaration of incompatibility, which enables ministers to use secondary legislation to correct any defect rather than having to go through the process of passing another act (if they have the political will to do so...).
Having said that, a lot of how the Online Safety Act tries to get things done is through secondary legislation and statutory codes and guidelines; these all can be quashed by the courts (unless the Act constrains the way the other instruments are made in such a way that it'd be illegal not to make an infringing instrument) so it'll be interesting to see how that plays out.
Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#67Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#68For a better understanding: The Court held (in the circumstances of this case) that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. The law in question specifically obligated messengers such as Telegram to hand over communications alongside the "information necessary to decrypt electronic messages if they were encrypted". To come to that conclusion, it re…
> the UK Online Safety Bill will be overturned by domestic courts (or the European Court) on the basis of this ruling. The UK wants to leave the ECHR[0], so they might be able to get around it — unfortunately. — [0]: https://www.chathamhouse.org/2023/03/uk-must-not-sleepwalk-l...
Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#69Earlier quoted context omitted.
Despite the name, it's not the eu :D
I was assuming it had jurisdiction over the EU? What is the actual real world impact of this?
Re: European Court of Human Rights bans weakening of secure end-to-end encryption
#70Earlier quoted context omitted.
Yes, that is very true. The Court generally does not oppose surveillance measures in general, as long as adequate safeguards are in place. However, I read the relevant paragraphs (paras 76-79) to be quite a strong rejection of any statutory obligation that would effectively require the installation of a backdoor undermining E2EE. The criticism of a lack of adequate safeguards and the risk of abuse is more focused on…
Yes, this was a problem all along with arguments against surveillance (/encryption weakening) based on "it can be abused by bad actors" - it implies that one would be ok with surveillance if it could not be abused by bad actors. While it's tempting to use such arguments (it looks like they had effect in this case at least) it remains necessary to emphasize the true reasons one takes a stand against surveillance e.g.…