Live data from Hacker News

France moves to break encrypted messaging

reclaimthenet.org

61–70 of 149 posts

Re: France moves to break encrypted messaging

#62

Seems to me we're going to have to let the anti-encryption mob have their way until things go wrong—bigtime. No amount of expert advice will convince them until they witness firsthand the negative consequences of weakening encryption. It's only afterwards and as a consequence some highly newsworthy disasters occur such as a child abduction or political sex scandal involving a high profile politician come to light tha…

In most cases I think the revelation of a scandal involving a high-profile politician would be a good thing. (That is, better than it remaining secret.)

Re: France moves to break encrypted messaging

#65
post #35

I still don't understand the note that the companies can't decrypt the messages with e2e encryption. Isn't it as simple as a software update that says: "If user = foo, then send the on device keys elsewhere"? Or if those keys are part of a TPM, then a software update that just asks it to send in the decrypted messages? Can judges not order this now, but can order decryption if the keys are stored centrally?

of course, nothing magically prevents the app from sending keys or decrypted content to a third party.

That's why if you're really serious about e2ee you have to install the app from source.

Re: France moves to break encrypted messaging

#66

Seems to me we're going to have to let the anti-encryption mob have their way until things go wrong—bigtime. No amount of expert advice will convince them until they witness firsthand the negative consequences of weakening encryption. It's only afterwards and as a consequence some highly newsworthy disasters occur such as a child abduction or political sex scandal involving a high profile politician come to light tha…

> until they witness firsthand the negative consequences of weakening encryption.

They won't be affected.

The hitherto invisible but very real wall between social classes is just going to become more visible for "First World" civilians the way it's been in "lesser" countries for decades already.

Actual "criminals" have always been able to get around all the restrictions ever put in place since the dawn of civilization, it's just the common folk that get trodded on and kept in their place.

Re: France moves to break encrypted messaging

#67
post #11

This article incorrectly implies that Telegram is end-to-end encrypted, by putting it in the same line as WhatsApp and Signal. Telegram doesn't even try to be end-to-end-encrypted by default. WhatsApp claims to be end-to-end-encrypted, but it's not open-source, Signal is end-to-end-encrypted.

> WhatsApp claims to be end-to-end-encrypted, but it's not open-source And explicitly does not encrypt metadata. Meanwhile NSA top brass publicly stated, "We kill people based on metadata."

> Meanwhile NSA top brass publicly stated, "We kill people based on metadata.

Can someone post a link to that?

Re: France moves to break encrypted messaging

#68
post #11

Earlier quoted context omitted.

> WhatsApp claims to be end-to-end-encrypted, but it's not open-source And explicitly does not encrypt metadata. Meanwhile NSA top brass publicly stated, "We kill people based on metadata."

> Meanwhile NSA top brass publicly stated, "We kill people based on metadata. Can someone post a link to that?

Maybe just search for it and pick a source you trust. Take the search term "kill people based on metadata" and no noise comes up, just tons of articles about General Hayden's interview and related

Re: France moves to break encrypted messaging

#69

This article incorrectly implies that Telegram is end-to-end encrypted, by putting it in the same line as WhatsApp and Signal. Telegram doesn't even try to be end-to-end-encrypted by default. WhatsApp claims to be end-to-end-encrypted, but it's not open-source, Signal is end-to-end-encrypted.

Open source would not help without the reproducible builds of Signal (I wonder who check them on each release?). And only builds like Molly include no binary blobs of Google [1], which could IMHO at least be used to extract some metadata. Leaving the OS still as a risk, even for Molly or Matrix clients. Even with transparency around linked devices, I would believe that few people would notice silently linked devices. Simplest thing is I guess social engineering which happened in a coordinated attack on Signal messagers of German politicians recently (I guess there should be an official signal app version not supporting linked devices for such people) [2].

[1] https://news.ycombinator.com/item?id=46081855 [2] https://www.politico.eu/article/hackers-attack-phone-of-germ...

Re: France moves to break encrypted messaging

#70

Seems to me we're going to have to let the anti-encryption mob have their way until things go wrong—bigtime. No amount of expert advice will convince them until they witness firsthand the negative consequences of weakening encryption. It's only afterwards and as a consequence some highly newsworthy disasters occur such as a child abduction or political sex scandal involving a high profile politician come to light tha…

[flagged]
Post reply on HN