Live data from Hacker News

CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

itsecurityguru.org

71–80 of 86 posts

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#71
post #29

Earlier quoted context omitted.

And after a Tory-led government came to power...

What's that got to do with it? (genuinely interested).

I'm not the GP poster, but I'd suggest that one of the few policy areas the Tories and Lib Dems found that they could readily agree on was civil liberties.

One of the first things the new government did was start the wheels turning on what became the Protection of Freedoms Act 2012. Whether you think that law went far enough or not, I suspect most here would say it took steps in the right direction on numerous issues where the previous New Labour administration had eroded rights and liberties. A few of them were big-headline, fundamental issues, but there were quite a few relatively minor concerns addressed as well, such as the excessive use of surveillance by local authorities that we're talking about here.

Given that coalition government is not the norm in the UK, I suspect politically it was more important that this was something the two parties could agree on as an anchor than anything else, though no doubt many of the incoming Lib Dem MPs and at least some of the Tories were no fans of the previous situation anyway.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#72

Earlier quoted context omitted.

I think most people completely missed the part of Snowden leaks that directly said that GCHQ is not any better than NSA.

GCHQ are both better and worse than the NSA. I would argue that it seems they are if anything even less restrained than the NSA in over broad surveillance. However it is less clear whether GCHQ have actually broken the rules (and certainly not the constitution) which the NSA may have done. My view is that everyone (in the world) should be pissed off at both the NSA and GCHQ and that Americans should be additionally a…

[deleted]

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#73
post #66

Earlier quoted context omitted.

You're right that we may have been naive about trusting our governments. What I don't understand is why anyone trusted businesses (such as CertiVox and Lavabit) to keep their emails secure? If the businesses themselves couldn't decrypt these emails, there's nothing the government could usefully ask them for.

What I don't understand is why anyone trusted businesses (such as CertiVox and Lavabit) to keep their emails secure? Because they didn't consider "because terrorism" to be a security threat that could penetrate privacy and property laws. Lavabit has proven that the Third-Party Doctrine means that once you give data to a business, you're giving it to the government.

Sorry, maybe I wasn't clear.

I have an email I want to be secure.

Why am I giving this data to Lavabit in a form that they can decrypt? (Forget the government for the moment.)

Why aren't these systems engineered to mean that only _I_ have the key to decrypt them?

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#74
post #66

Earlier quoted context omitted.

What I don't understand is why anyone trusted businesses (such as CertiVox and Lavabit) to keep their emails secure? Because they didn't consider "because terrorism" to be a security threat that could penetrate privacy and property laws. Lavabit has proven that the Third-Party Doctrine means that once you give data to a business, you're giving it to the government.

Sorry, maybe I wasn't clear. I have an email I want to be secure. Why am I giving this data to Lavabit in a form that they can decrypt? (Forget the government for the moment.) Why aren't these systems engineered to mean that only _I_ have the key to decrypt them?

I don't know. Why aren't you running your own email server?

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#75

Earlier quoted context omitted.

I think most people completely missed the part of Snowden leaks that directly said that GCHQ is not any better than NSA.

GCHQ are both better and worse than the NSA. I would argue that it seems they are if anything even less restrained than the NSA in over broad surveillance. However it is less clear whether GCHQ have actually broken the rules (and certainly not the constitution) which the NSA may have done. My view is that everyone (in the world) should be pissed off at both the NSA and GCHQ and that Americans should be additionally a…

For those unaware it may be worth pointing out that the UK constitution has a principle of parliamentary sovereignty [1] - basically parliament can pass/amend/remove any law and no current law can bind future parliaments (they can always amend/remove it). Fundamentally if they say it's legal it is, so rules can be changed at any time such that GCHQ isn't technically breaking any rules.

[1] http://www.parliament.uk/about/how/sovereignty/

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#76
post #29

Earlier quoted context omitted.

What's that got to do with it? (genuinely interested).

I'm not the GP poster, but I'd suggest that one of the few policy areas the Tories and Lib Dems found that they could readily agree on was civil liberties. One of the first things the new government did was start the wheels turning on what became the Protection of Freedoms Act 2012. Whether you think that law went far enough or not, I suspect most here would say it took steps in the right direction on numerous issues…

Protection of Freedom Act doesn't work because it's additive. Repealing other acts would be a better solution.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#77
post #76

Earlier quoted context omitted.

I'm not the GP poster, but I'd suggest that one of the few policy areas the Tories and Lib Dems found that they could readily agree on was civil liberties. One of the first things the new government did was start the wheels turning on what became the Protection of Freedoms Act 2012. Whether you think that law went far enough or not, I suspect most here would say it took steps in the right direction on numerous issues…

Protection of Freedom Act doesn't work because it's additive. Repealing other acts would be a better solution.

Many parts of the 2012 act do repeal or limit the effects of earlier legislation.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#78
post #74

Earlier quoted context omitted.

Sorry, maybe I wasn't clear. I have an email I want to be secure. Why am I giving this data to Lavabit in a form that they can decrypt? (Forget the government for the moment.) Why aren't these systems engineered to mean that only _I_ have the key to decrypt them?

I don't know. Why aren't you running your own email server?

Me personally? Because I don't actually need secure email (and so didn't use Lavabit or CertiVox).

My point is that if I did want secure email, I wouldn't trust a company whose email system architecture meant that they could read my email.

A personal email server might be a good solution, but then you have to maintain it. It seems as though it should be possible for a company to build an email system (and offer it as a service to customers) whereby they _couldn't_ read user's email.

This seems like a good thing. (And as a nice side-effect, the government can't then issue them with a warrant to read your email. Although that's not to say they can't read your email in other ways.)

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#79
post #74

Earlier quoted context omitted.

I don't know. Why aren't you running your own email server?

Me personally? Because I don't actually need secure email (and so didn't use Lavabit or CertiVox). My point is that if I did want secure email, I wouldn't trust a company whose email system architecture meant that they could read my email. A personal email server might be a good solution, but then you have to maintain it. It seems as though it should be possible for a company to build an email system (and offer it as…

I'm not aware of any companies providing double-blind encrypted email services, but they may be out there. Certainly they would eventually be accused of providing harbor to terrorists and other unsavories. At best, it sidesteps the problem of the lack of legal privacy protections when using a service provider of any kind.

http://www.legaltechnology.com/latest-news/data-security-in-...

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#80
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

A warrant could imply that they are unable to attack the provider This is the institution which allowed U-boats to sink British ships so not to even hint that the ENIGMA cipher was cracked. I'm sure they're utterly incompetent at keeping secrets, and anyone on the internet can deduce their most critical SIGINT capabilities simply by observing how they deal with civil warrants in minor cases.

This is the institution which allowed U-boats to sink British ships so not to even hint that the ENIGMA cipher was cracked. I'm sure they're utterly incompetent at keeping secrets

Easy call to make 70 years after the fact, I guess.

Post reply on HN