Live data from Hacker News

If David Cameron bans secure encryption he can't intercept

blog.mythic-beasts.com

51–60 of 104 posts

Re: If David Cameron bans secure encryption he can't intercept

#51

As far as I remember (and I may be wrong), the specific quote from David Cameron was about banning encryption that can't be backdoored, so that the government can look at things if they need to. Obviously I'm completely against that, because once there's a backdoor, it's all too easy to collect by default, instead of only when "needed". With this clarification though, lots of this tech would still work. Most things b…

> Most things based on TLS will continue to work, if every computer has to have a government CA certificate installed to allow MITMs. Hopefully HTTP Public Key Pinning will become more prevalent if this looks likely to happen.

HPKP is bypassed for locally-installed CA certificates (if you don't want that, set security.cert_pinning.enforcement_level to 2 on Firefox).

Re: If David Cameron bans secure encryption he can't intercept

#52
post #44
post #24

Except Cameron wants to backdoor end-to-end encryption like iMessage/Whatsapp, rather than mess with something like SSL. With SSL they can just get a warrant (or you know, don't get a warrant) and look at the server, where everything is in plain text. One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the pers…

I would be very surprised if Apple and Facebook (and Google, with GMail, GTalk, Hangouts, etc) didn't use this golden opportunity to swing their weight about and assert who's really in charge of technology around here, by simply wholesale blocking use of all their communication tools in the UK to comply with the law. I have a feeling that if they did this, the uproar would be sufficient to have the law reversed by em…

Doesn't this seem insane? You are advocating punishing some 64 million people because of one idiot.

Re: If David Cameron bans secure encryption he can't intercept

#53
post #50
post #24

Except Cameron wants to backdoor end-to-end encryption like iMessage/Whatsapp, rather than mess with something like SSL. With SSL they can just get a warrant (or you know, don't get a warrant) and look at the server, where everything is in plain text. One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the pers…

> One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the person's phone, which is a clearer analogy to getting a warrant to search someone's house to look for things they have stashed. That doesn't work if the message has been encrypted on transit with an one-time key, which is discarded after the message has…

Your first point: Yep, totally right. I think there's two levels though, the first being that my messages are free from dragnet style surveillance, the second being that my messages are totally secure. Making them get a warrant and get my actual device to decrypt my messages is a damn sight better than having unfettered access to clear text.

Second point: Not sure about that, can't I just serve a warrant on Facebook UK to give me the data? If they say "Sorry, we can't get it because America", I imagine the police will say "What? Give it up or go to prison". Similarly, if Google/Apple allow banned apps in their app store, just bring a suit against their UK tentacles.

Re: If David Cameron bans secure encryption he can't intercept

#54
post #14

As far as I remember (and I may be wrong), the specific quote from David Cameron was about banning encryption that can't be backdoored, so that the government can look at things if they need to. Obviously I'm completely against that, because once there's a backdoor, it's all too easy to collect by default, instead of only when "needed". With this clarification though, lots of this tech would still work. Most things b…

> Most things based on TLS will continue to work, if every computer has to have a government CA certificate installed to allow MITMs. And the following day, there will ba a Chrome+Firefox extension that highlights when the government CA certificate has been used - so that you know EXACTLY when you are MITMd. Isn't it good?

Would probably look more like auto deny with user override if they choose, with a setting to white list the domain. User should have to opt into their connection being MITMd.

Re: If David Cameron bans secure encryption he can't intercept

#55

One-time pad encryption, implemented correctly, cannot be broken or backdoored. There is the matter of key exchange of course, but that is as old as the use of covert communications itself. Anyone who cares enough about their communication remaining secret will find a way of exchanging keys for which any attempt at interception by a government entity is entirely impractical.

I pull 120Gb a month down. That's going to be a fucking big OTP and side channel.

Re: If David Cameron bans secure encryption he can't intercept

#56
What's to stop people from using strong encryption on their own, illegally, end to end? It's not like this is the first time the government has inserted itself in between people's legitimate communications and intercepted them with no recourse. If you assume that that is the default state of being (and except for a few small governments, it is), then you realize that the short periods of time where people could communicate freely and privately using networks outside of private in-person meetings have been lapses in government surveillance more than anything else and minor moments of relief for those who want to communicate privately. Governments will spy. That is a given. They will try to remove privacy. That is a given. Regardless of any laws and especially when it's as simple and undetectable as making some database queries.

I'm not defending any government's actions to remove privacy and spy on its people. Quite the contrary, once one has accepted that as inevitable, it's easier to move on. The need for human privacy is also, IMO, a fact. Some may dispute that, yet there are true, the only other option then becomes to go around the law. An unjust law must be broken. And it will. The worse the government gets, the more it will be broken.

I don't see why people in the UK and elsewhere couldn't get copies of software that still had strong encryption despite the idiotic laws. After all, it's just as easy to click one link as another. Will the UK be monitoring traffic for actual binaries and source code? Will the arrest people that use encryption they can't break? Will they arrest people for sending garbage data that looks like encrypted data but isn't and therefore can't decrypt? As the government gets more totalitarian, I think we will see even regular people training themselves in encryption and its proper uses. It's inevitable as people have more and more to lose. Once life, limb, and property are at stake, people either become competent or become victims, and people are generally a lot more competent than they appear when high stakes are on the line.

Of course, UK companies will be hurt. They won't be able to do a lot of business internationally. UK citizens will have their information stolen in massive data breaches. Bank accounts and identities will be compromised. Many accounts that are not with UK companies will be compromised because of password reuse. Cameron doesn't have to ban ALL strong encryption. Whatever systems he bans it in, will be compromised. That's inevitable. At the same time, the people don't have to put up with it. Stop online banking with banks that don't use strong encryption. Request paper bills. Clog up phone lines. Pay in cash if possible. These are all things a regular person could do in the event that strong encryption is banned that if done by even a small percentage will increase costs quite a bit. It may not get the law reversed, but it might get companies on the side of people if they have to cut paper bills again at a 10-100x cost over electronic ones, for example.

tl;dr: Governments will spy and people will use strong encryption regardless of the law as privacy is a human right and oftentimes necessary to survival. Businesses and convenience will suffer greatly.

Re: If David Cameron bans secure encryption he can't intercept

#57
post #20

Earlier quoted context omitted.

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

Yeah I was going to have that as an example in my comment, but even then that seems unrealistic to me. Why wouldn't the big tech companies simply not do that? The UK needs them more than they need the UK, and if you took away the country's access to Facebook for more than an hour you'd have a riot on your hands.

The big tech companies already support legal intercept for content traversing their networks.

Re: If David Cameron bans secure encryption he can't intercept

#59
post #41
post #32

Earlier quoted context omitted.

What about apps that keep the encryption keys in the user phones and can't decrypt the contents of messages? Do they intend to ban those apps?

That was my second paragraph - and to be clear, they don't want to ban it, they want to backdoor it. My idea was that rather than ban it outright and make it like most other internet traffic (decrypted on a server), they could mandate some kind of cacheing of the _encrypted_ data on the server. Then, once they'd lawfully executed a warrant to grab the suspects phone, they can decrypt at their leisure. Apps using per-…

I'll be very surprised if Apple compromises on this issue. I'll be similarly surprised if Google accepts that kind of compromise. Few things would surprise me about what Facebook is willing to do, but I think this would shock me if fb was willing to go for what you are talking about.

The world is run by technology companies now. Not governments. Governments haven't caught on to this yet, at least officially.

But the bottom line about law is that the law is whatever Google, Apple, Facebook, Microsoft, and Amazon says it is.

That's not the most comforting thought in the world, but that's how it is. And it's sort of okay for now because all of those companies are currently run by idealists. God help us when they are not.

For right now though, there isn't a chance in hell that Cameron's ideas will have any traction. He's just saying things that will win him some support from a certain segment of the population.

Re: If David Cameron bans secure encryption he can't intercept

#60

It's pretty clear that the UK government doesn't have the power to ban encryption. This is just a distraction so that we are happy to accept whatever "less bad" proposals they come up with to increase their surveillance powers. I can't help but feel that peoples dislike of Cameron is a pointless distraction too. This is not Cameron. This is government. We will still be having this same discussion in 50 years, unless…

I think the sane thing to do is assume they are going to ask for legislation to force large companies that do online communication (facebook, whatsapp, twitter, apple, etc) to keep their system potentially and practically back door capable. That is something that would be possible to implement. It is also something with a historical precedent (look into how they responded to the BBM situation after the London riots).

If we don't want that to happen then the smart thing to do would be act as if that is what they are proposing.

If they propose something even worse it isn't like it will have been wasted effort.

Post reply on HN