Live data from Hacker News

Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

signal.org

71–80 of 357 posts

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#71

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

> Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means?

Makes me think of the most sobering line I ever saw in a museum (Berlin): The biggest atrocities were committed by people with a spreadsheet and a performance goal.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#73
post #53

Earlier quoted context omitted.

Beyond the fact that this isn't true, it's even less credible coming from a new, anonymous account. If privacy is really so dangerous and has no value, you should have no issue making comments like these under a publicly identifiable account.

Every account is new at some point.

I noticed you skipped over every other part of my comment to focus on an irrelevant one. Is that an admission that you don't actually stand by what you say?

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#74
post #27

Earlier quoted context omitted.

>>> That when sharing a picture of your own child with your own mother, you will have to worry about what the electronic bureaucracy will label your picture as. I 100% agree on the need to counter emotional fire with emotional fire. And this is the right way to combat this sort of overreach However, I do think that “the choir” need to rethink what is and is not privacy - a huge amount of the benefits of having our ev…

That's all very well, but we just plain don't have a legal, economic, or technical system which will allow separation of the good uses from the bad uses. Once data is in someone else's possession, there's f-all way to prevent it being used to do whatever the possessor wants. Even if there is a legal agreement, it's easily abrogated, or overridden by insolvency law, or by a company having a "we can update our terms" c…

It’s hard to enforce a law so we should not have the law seems a poor argument.

Let’s say we define personal data about, generated by or inferred from the actions of a natural person as owned by the society as a whole. And misuse is liable to 5% of annual turnover. It’s more or less GDPR. That seems viable - and I am sure an army of class action lawyers will be happy to help out

(Ok I need to work on a better proposal but I think this is more doable than you are allowing for)

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#75
post #48

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

Oh, the people who work on secure boot, attestation, DRM, and other such features know very well, but don't care. This is because the claimed benefits for them, such as less hackers, less malware, less bot traffic, outweigh any possible downsides for the society.

I think it's even worse than that. Our industry has a strong track record of only looking at potential upsides (and pretending they're certain) and not even seeing that there may be serious downsides.

It's a kind of blindness. The kind that is, in my opinion, is one of the major reasons why we ended up building a world that's more than a bit dystopian.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#76

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

What defines a bad tech vs a good tech? Similar arguments can be made for most research including nuclear fusion, AI, vaccines, space, polymers, combustion engines, electric motors, semiconductors...

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#77

Earlier quoted context omitted.

This assumes surveillance prevents crime, or even that crime is worth preventing if surveillance is the cost. In terms of everyday threats to my life, billionaires are a bigger one than criminals.

People are less likely to commit crimes if they know the state has the tools to identify and prosecute them. Surveillance provides that capability, and reducing it makes solving and deterring crime much harder. The cost is manageable as long as it's used for the right reasons and that the data is kept secure. The benefits of deterring violence outweigh those risks. Billionaires may be a bigger threat but criminals ar…

> as long as it's used for the right reasons and that the data is kept secure

Two things that we have yet to be able to even reasonably ensure.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#78

Same people screaming 1984 have five authenticator apps installed on their fingerprinted tracking device and 2fa with their phone number, and have no idea what 'sensors off' does. Palpable irony present when a chat provider whom requires personally identifiable information to use their service complains about privacy...

Two-factor is one thing. They're mandating client-side scanning in every operating system. This was previously rejected for obvious privacy reasons.

There are already phones with an anti-nudity feature as a parental control option, but the key there is that it's optional. The major pivot with age verification is that all devices treat all users as a child until they identify themselves with a third party. This allows a rhetorical paradox that the controls are only for children, when they apply to adults too by default.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#79

Earlier quoted context omitted.

Probably because its leadership seems to have been taken over by more politically and less technically inclined people (for better and/or worse) who don't understand why it matters. The trade is we get (hopefully) people very dedicated to keeping the org developing the stuff alive and well-funded, and gaining mainstream acceptance/attention.

Signal did such things always. They delayed years to clarify licensing to allow iOS forks. And hid server source code for a year to hide MobileCoin integration.

Is Signal compromised?

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#80
post #64
post #38

Earlier quoted context omitted.

My impression is that people who can work on stuff like that are the kind who just take the stuff in the world for granted. "This is how the world is, we need digital restrictions so now we need to implement them." "I don't have a say about whether DRM or remote attestation is standard business practice or not, it is just how it is." This is akin to how two kinds of people respond to law. The first kind think "This i…

> My impression is that people who can work on stuff like that are the kind who just take the stuff in the world for granted. "This is how the world is, we need digital restrictions so now we need to implement them." "I don't have a say about whether DRM or remote attestation is standard business practice or not, it is just how it is." I like to call those people "ventablackpilled". Being blackpilled is all about glo…

You're giving too much thought into the issue or trying to construct something like a conspiracy out of it.

I sometimes work with people who worked on or at least worked with DRM-like stuff (Trustzone etc.). The people who make those systems and the structures that allow it falls squarely on banality of evil. It is not a big evil org or people with their own evil agendas (unlike Palantir, i think they are the true "ventablackpilled" ones). They are thousands of developers who push JIRA tickets like everyone. Many of them live in the developing world and they just pray to keep their jobs. The reason that big tech attracts developers despite their obvious and much bigger (IMO) evils is the same reason that attracts developers who make systems that can be completely closed down.

Many of the developers are not outright evil either. They sometimes voice their opinion. Their opinion doesn't matter in comparison to the business goals.

Sometimes it is understandable to write blocking software. Not all equipment is sold. Many industrial equipment is leased. So the actual owners want guarantees that their devices cannot be modified by renters.

The amount of info you can extract from an Apple phone or Graphene OS is limited due to same restrictions working in your favor too.

Similarly phones can be locked down due to radio restrictions. Nobody wants infinitely exploitable SDNs in peoples hands. It makes such SDNs a juicy target for enemies like Russia to exploit and turn into scalable attack vector as spoofing and jamming devices.

The reason those are attack vectors is also banal. We made our bed as engineers, voters, governments and business leaders one sloppy work at a time. We made shitty chips and shitty software with no care for security or safety. We sold millions of them and nobody wanted to pay to "do it right way". Worse is better. Silicon Valley style scaling up is the goal. Competition is for suckers. All those and every single one of us ate the fruits of shitty hardware and software that are protected by closed down systems. We engineers got the cushy jobs, our business leaders made 10x 100x gains from our work. We either had little voice (because making a big noise is guaranteeing that your cushy job no longer exists) or whatever we had is ignored in the hubris of shipping shit to billions of people.

Post reply on HN