Live data from Hacker News

If David Cameron bans secure encryption he can't intercept

blog.mythic-beasts.com

11–20 of 104 posts

Re: If David Cameron bans secure encryption he can't intercept

#11
As far as I remember (and I may be wrong), the specific quote from David Cameron was about banning encryption that can't be backdoored, so that the government can look at things if they need to.

Obviously I'm completely against that, because once there's a backdoor, it's all too easy to collect by default, instead of only when "needed".

With this clarification though, lots of this tech would still work. Most things based on TLS will continue to work, if every computer has to have a government CA certificate installed to allow MITMs. Hopefully HTTP Public Key Pinning will become more prevalent if this looks likely to happen.

Re: If David Cameron bans secure encryption he can't intercept

#13
post #7

Honestly, it sounds kind of relaxing. Good excuse to get some sunshine. On a more serious note, I can't help but think David Cameron is employing the technique of attempting something extreme so that he can do something less extreme (but still really bad) later with less oversight. Of course you can't ban strong encryption. His advisers know that, he knows that, _everyone_ knows that. It will be very interesting to s…

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

Re: If David Cameron bans secure encryption he can't intercept

#14

As far as I remember (and I may be wrong), the specific quote from David Cameron was about banning encryption that can't be backdoored, so that the government can look at things if they need to. Obviously I'm completely against that, because once there's a backdoor, it's all too easy to collect by default, instead of only when "needed". With this clarification though, lots of this tech would still work. Most things b…

> Most things based on TLS will continue to work, if every computer has to have a government CA certificate installed to allow MITMs.

And the following day, there will ba a Chrome+Firefox extension that highlights when the government CA certificate has been used - so that you know EXACTLY when you are MITMd. Isn't it good?

Re: If David Cameron bans secure encryption he can't intercept

#16
post #7

Honestly, it sounds kind of relaxing. Good excuse to get some sunshine. On a more serious note, I can't help but think David Cameron is employing the technique of attempting something extreme so that he can do something less extreme (but still really bad) later with less oversight. Of course you can't ban strong encryption. His advisers know that, he knows that, _everyone_ knows that. It will be very interesting to s…

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

That would be TLS traffic at most (Good luck adding those certificates to curl, MUAs, etc. for example).

That's far from being the only encryption system available - SSH doesn't even have a concept of "root certificate" to MITM with.

Re: If David Cameron bans secure encryption he can't intercept

#17

It's pretty clear that the UK government doesn't have the power to ban encryption. This is just a distraction so that we are happy to accept whatever "less bad" proposals they come up with to increase their surveillance powers. I can't help but feel that peoples dislike of Cameron is a pointless distraction too. This is not Cameron. This is government. We will still be having this same discussion in 50 years, unless…

It's not really the elected government, it's the security services asking for an expanded remit and being granted one by uncritical politicians and an apathetic media.

Who are the security services employed by? I certainly wouldn't call them private industry!

Did you mean to say it's not elected government officials? Just curious, because I definitely consider a country's intelligence apparatus to be completely and wholly part of its "government", and would be surprised to find someone who didn't.

Re: If David Cameron bans secure encryption he can't intercept

#18

It's pretty clear that the UK government doesn't have the power to ban encryption. This is just a distraction so that we are happy to accept whatever "less bad" proposals they come up with to increase their surveillance powers. I can't help but feel that peoples dislike of Cameron is a pointless distraction too. This is not Cameron. This is government. We will still be having this same discussion in 50 years, unless…

It's not really the elected government, it's the security services asking for an expanded remit and being granted one by uncritical politicians and an apathetic media.

[deleted]

Re: If David Cameron bans secure encryption he can't intercept

#19
Suggestions like banning strong encryption is a form of ritual abuse. It is meant to get the public used to the idea of pervasive surveillance. That pervasive surveillance will be carried out through a continuation of what existed before the Snowden revelations, which was a successful Straussian confection of fake freedom, carefully managed.

Re: If David Cameron bans secure encryption he can't intercept

#20
post #7

Honestly, it sounds kind of relaxing. Good excuse to get some sunshine. On a more serious note, I can't help but think David Cameron is employing the technique of attempting something extreme so that he can do something less extreme (but still really bad) later with less oversight. Of course you can't ban strong encryption. His advisers know that, he knows that, _everyone_ knows that. It will be very interesting to s…

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

Yeah I was going to have that as an example in my comment, but even then that seems unrealistic to me. Why wouldn't the big tech companies simply not do that? The UK needs them more than they need the UK, and if you took away the country's access to Facebook for more than an hour you'd have a riot on your hands.
Post reply on HN