Live data from Hacker News

Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

signal.org

111–120 of 357 posts

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#111
post #59

Earlier quoted context omitted.

I don’t think 1st century Rome had much in the way of digital surveillance. Or even surveillance, for that matter. Plenty of hubris, mind.

The implementation might change, but the pattern of absolute control is old as time.

"Implementation details are left as exercise for the reader.

When in doubt refer to the public API as specified in Revelations 13:15-17"

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#113

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

I remember piping up about all those things. But the excuses were everywhere.

- Oh but you can turn it off so it's no issue (secure boot). Well yeah but more and more stuff just won't run then (eg iOS apps on Mac). It will become the norm to stay inside the fuzzy walled garden just like it already is on phones. And if you stray you will just be blocked from any app that does something useful.

- But companies need to be sure you are who you say you are (attestation). Yes but they will abuse that power if they can profit from it.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#114
post #86

Have they never heard of "the boy who cried wolf"? First of all, age verification is not mass surveillance, it is possible to verify your age without disclosing who you are to the site you're visiting, and without disclosing what site you visited to the government. There are even age verification services (and I do despise them fully, this should be a government provided service!) that use only facial features to det…

> it is possible to verify your age without disclosing who you are to the site you're visiting, and without disclosing what site you visited to the government. I can't believe people are really okay with a system where you have to show your real face to access websites. Cameras on phones went from a novelty to a government mandate so you can be observed. There are various other potential methods to verify one's age,…

> There are various other potential methods to verify one's age, all of which are forbidden by OFCOM. Account age, zero-knowledge proofs, key signing, some kind of OAuth thing, physical tokens that require proof of age to buy, etc. The only permitted ones require your to link your real-life identity.

This is just not true. See 4.17 here, for example [1]

[1] https://www.ofcom.org.uk/siteassets/resources/documents/cons...

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#115
post #38

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

My impression is that people who can work on stuff like that are the kind who just take the stuff in the world for granted. "This is how the world is, we need digital restrictions so now we need to implement them." "I don't have a say about whether DRM or remote attestation is standard business practice or not, it is just how it is." This is akin to how two kinds of people respond to law. The first kind think "This i…

Somebody had to work on it before it was how the world is. When Microsoft proposed a scheme involving remote attestation and DRM in 2003, the New York Times published a critical article. Google SafetyNet a decade later barely got a whimper out of major tech outlets, much less the mainstream press.

https://www.nytimes.com/2003/06/30/business/technology-a-saf...

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#117

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

Why do people vote for large, strong governments that are able to take the power you suggest Tech is enabling them to take?

It's starting to feel like ethno-nationalism is the answer.

See: the PRC. Support for surveillance is allegedly high. Anecdotally, talking to PRC citizens in circumstances where they don't need to worry about said surveillance (e.g., when they're vacationing in Japan and I want to pester someone and practice my mandarin), they generally like it. Makes them feel safe.

The CPC has sold them on a vision of them as members of the state-race "Chinese" (which is not really an ethnicity any more than "American" is) and the surveillance as a thing that keeps them and their "Chinese" lifestyle safe from non-Chinese. Uighurs have to be extra surveilled until they're also Chinese, which, many are now according to the CPC.

So PRC citizens feel safe and cozy among in the country for "their people," not realizing this whole ethnonationalist concept is at best 100 years old, maybe even younger. During the Qing dynasty, there's a whole hell of a lot of people that think of themselves as "Chinese" that definitely weren't by the dynastic government.

I smell similar happening in Russia, the USA, and Israel, with State support. It looks like right wing groups are trying to pull it off in the UK and Germany as well.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#118
This is really disingenuous coming from Signal who pioneered secure compute architecture for a number of useful features [1][2]. On-device checks are no more "surveillance" than Signal's private contact discovery is, and the same slippery slope argument applies there.

It's also technically incoherent: the exact same kind of "surveillance" is already applied by every single phone, because that's how the Photos app (or whatever it's called on Android) searches for cat pictures based on the text "cat". I can't recall any Signal statements about cat recognition technology leading to "reporting people to government authorities".

The "cover-ups" link right in the beginning is a real mask-off moment though. This is not a measured statement informed by the reality of modern Britain. It's an American view informed by the twitter cesspool and divisive rhetoric of the far right. It's a real shame to see Signal falling so low.

[1]: https://signal.org/blog/private-contact-discovery/

[2]: https://signal.org/blog/secure-value-recovery/

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#120
post #119

Earlier quoted context omitted.

and civil service is blindly following orders.

You should watch Yes Minister. They certainly don't.

They do. The tenders don't write themselves. The scale of corruption is unprecedented, yet nothing - as it seems - is being reported or even questioned by civil service.
Post reply on HN