Live data from Hacker News

French National Assembly approved Internet traffic monitoring system (French)

lemonde.fr

171–180 of 222 posts

Re: French National Assembly approved Internet traffic monitoring system (French)

#171
post #14

La Quadrature du Net has also affirmed that while they were demonstrating in front of the National Assembly, there were two IMSI Catchers. And the law wasn't even passed yet. Great example of what will happen. ( http://www.franceinfo.fr/actu/politique/article/des-appareil... link in french, can provide a translation if needed) Bernard Cazeneuve, our ministre de l'Intérieur (Tasked with internal security, i.e. police…

Why would you recommend TrueCrypt? That's a terrible suggestion.

Besides the knee-jerk reaction, it all depends on what you're defending against. If the NSA went around opening Truecrypt containers for every criminal case, their cover would be blown. So if you're keeping stuff from the local PD or thieves breaking into your house, even a supposedly backdoored app is better than cleartext.

That said, TC has been audited by what I hear is a reputable group of people, who say there's no evidence of severe crypto vulnerabilities.

Re: French National Assembly approved Internet traffic monitoring system (French)

#172
post #70

Earlier quoted context omitted.

Not a silver bullet. With this we'd still have the death penalty; or voted for populists measures like banning minarets.

Ooh, what a delightfully aristocratic objection. We can't give the lesser peoples self-rule, they'd rule themselves wrong!! Have you considered any noblesse oblige -style colonization and rule of third-world nations? Sounds like a good match.

You can be as snarky as you want, but the fact is, I don't want the average dumbass on the street to have that much power over my life, and neither, I suspect, do you.

There has to be something resembling meritocracy in any functioning organization, and that includes a government.

Re: French National Assembly approved Internet traffic monitoring system (French)

#173
post #57

Earlier quoted context omitted.

Encrypting all communications is certainly the way to go. But, I wonder if we can make these systems completely inefficient by flooding them with false positives. Assuming we can figure out the patterns they are looking for in our communications, could this be a possible solution to force them to withdraw they "black boxes"?

Encryption won't solve the problem. 1/ They're after the meta data. Whether you have plaintext or encrypted communication, they still know to whom you talk. Unless you use TOR or VPN yourself out of the country, it's not going to help... 2/ Strict key disclosure laws. You can be thrown to jail, if you cannot decrypt some information when requested by a judge. That's true even in the case where you can prove the key i…

Who knew Tor wasn't going to be useful only for people in countries like China, Iran or Saudi Arabia...but also France, Spain, UK, US, Australia, Canada...you know, the "most freedom-loving democratic countries" in the world.

There's definitely a coordinated effort to pass these laws together now, to make it seem like it's the "sensible" thing to do after the terrorist attacks. FBI chief Backdoor-Comey has also been making rounds in European countries to push for total surveillance laws "or else it might hurt their relationship with the US". This may especially work in weaker countries where a partnership with the US is regarded as a god-send and they'll try not to do anything to hurt that partnership. In other words they'll do anything the US government tells them to do.

Re: French National Assembly approved Internet traffic monitoring system (French)

#174
post #87
post #70

Earlier quoted context omitted.

Not a silver bullet. With this we'd still have the death penalty; or voted for populists measures like banning minarets.

Then you don't really believe in democracy, and I have to disagree.

I did for a while, but I have to admit the charm is wearing off.

Re: French National Assembly approved Internet traffic monitoring system (French)

#176

Earlier quoted context omitted.

A lot of people seem who recommend TC seem to think the same about BitLocker. To be fair, TrueCrypt has been audited and the code is freely available; BitLocker is proprietary, and the code is only available to a select few under NDA.

TCs developers told you to stop using it, BitLocker's didn't. Even the people responsible for the audit recommend that people not use TC

As always, one must consider their own threat model and make an informed decision. I personally would use BitLocker over TrueCrypt, but LUKS over BitLocker.

Re: French National Assembly approved Internet traffic monitoring system (French)

#177
post #59

Earlier quoted context omitted.

You probably meant "Its not by chance that France get this kind of law". Because "Not a hasard" (hazard) means "not dangerous", making your whole post confusing.

He meant it's not a hazard to the politicians careers to introduce such a law as the public don't really know what it means in reality unlike Germany say who have such direct experience, I think.

I think the OP you respond to is right. It is a common mistake for french persons.

Re: French National Assembly approved Internet traffic monitoring system (French)

#178
post #126

Earlier quoted context omitted.

Flooding the system can only work if the group that floods the system is large enough that it isn't simply expedient for the surveillance organisations to decide you're a potential risk and put you under additional surveillance. Encryption is in a similar position, but it is a far easier sell to business and the general public, and so the chances of reaching critical mass of communications is much greater.

The interesting bit is that the general public increasing their adoption of better security practices to make them invisible will benefit the pedophiles and terrorist already in hiding because their choice to hide/encrypt will no longer result in them sticking out from the masses.

Most criminals are caught because their groups are targeted and OPSEC (operational security) is really, really hard. They catch the people who didn't maintain strict discipline and get them to flip on the rest. This is an age-old recipe which is resistant to technological change because, again, OPSEC is really, really hard.

Re: French National Assembly approved Internet traffic monitoring system (French)

#179

Does anyone know what kind of metadata they will be logging? Are they logging every HTTP request that comes out of my computer for instance? (Including my user agent, the specific page I visited etc.)

In general, this kind of details would not be part of the "law" but would be published in a "decree" cooked up by the executive branch when they decide to "apply" the law.

In this case, it's going to be kept secret and covered by some kind of "security clearance". That would make it a criminal offense to divulge these details. The law explicitly limit this to the "meta data" of the communication, and not the content.

And finally, publishing these details would defeat the whole purpose of the enterprise. The NSA does not publish details about the meta-data they collect in the PRISM database, and they charged the Snowden for the little that he revealed about the program.

The French are essentially doing the same thing. The NSA has some limitations about when US citizens meta data can be collected domestically. The French law has no such provision.

Post reply on HN