Live data from Hacker News

If David Cameron bans secure encryption he can't intercept

blog.mythic-beasts.com

61–70 of 104 posts

Re: If David Cameron bans secure encryption he can't intercept

#61
post #44
post #24

Except Cameron wants to backdoor end-to-end encryption like iMessage/Whatsapp, rather than mess with something like SSL. With SSL they can just get a warrant (or you know, don't get a warrant) and look at the server, where everything is in plain text. One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the pers…

I would be very surprised if Apple and Facebook (and Google, with GMail, GTalk, Hangouts, etc) didn't use this golden opportunity to swing their weight about and assert who's really in charge of technology around here, by simply wholesale blocking use of all their communication tools in the UK to comply with the law. I have a feeling that if they did this, the uproar would be sufficient to have the law reversed by em…

You would be very surprised if that didn't happen!? Seems like a long shot prediction to me.

Re: If David Cameron bans secure encryption he can't intercept

#62
post #52
post #44

Earlier quoted context omitted.

I would be very surprised if Apple and Facebook (and Google, with GMail, GTalk, Hangouts, etc) didn't use this golden opportunity to swing their weight about and assert who's really in charge of technology around here, by simply wholesale blocking use of all their communication tools in the UK to comply with the law. I have a feeling that if they did this, the uproar would be sufficient to have the law reversed by em…

Doesn't this seem insane? You are advocating punishing some 64 million people because of one idiot.

The one idiot they technically elected (or at least allow to control the wheel).

Ultimately, it's the people's right and responsibility, not one man.

Re: If David Cameron bans secure encryption he can't intercept

#63
post #20

Earlier quoted context omitted.

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

Yeah I was going to have that as an example in my comment, but even then that seems unrealistic to me. Why wouldn't the big tech companies simply not do that? The UK needs them more than they need the UK, and if you took away the country's access to Facebook for more than an hour you'd have a riot on your hands.

Facebook (et al) already hand over user data to UK and other authorities. There is no need for any MITM certificate and even if there was, these companies would just do it since it makes it easier for them to say to authorities they already have the key to read it without involving Facebook - instant plausible deniability for Facebook to say we don't hand over info to authorities and full access for Governments everywhere.

Re: If David Cameron bans secure encryption he can't intercept

#64
post #53
post #50

Earlier quoted context omitted.

> One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the person's phone, which is a clearer analogy to getting a warrant to search someone's house to look for things they have stashed. That doesn't work if the message has been encrypted on transit with an one-time key, which is discarded after the message has…

Your first point: Yep, totally right. I think there's two levels though, the first being that my messages are free from dragnet style surveillance, the second being that my messages are totally secure. Making them get a warrant and get my actual device to decrypt my messages is a damn sight better than having unfettered access to clear text. Second point: Not sure about that, can't I just serve a warrant on Facebook…

> Similarly, if Google/Apple allow banned apps in their app store, just bring a suit against their UK tentacles.

The app doesn't have to be in their app store: on Android, it's a simple checkbox to be able to install an app from outside the app store. One can also enable developer mode and install it as if it were a self-developed app.

Re: If David Cameron bans secure encryption he can't intercept

#65
post #62
post #52

Earlier quoted context omitted.

Doesn't this seem insane? You are advocating punishing some 64 million people because of one idiot.

The one idiot they technically elected (or at least allow to control the wheel). Ultimately, it's the people's right and responsibility, not one man.

Hahaha! Only 37% of people voted for that guy... So how we are culpable I don't know!!

Re: If David Cameron bans secure encryption he can't intercept

#66
So what are we going to do about it?

We've spent the last year running twitter campaigns, but the people that matter (voters, well tory voters) don't do social media.

This means that you need to write a letter. Yes a real letter, not a fucking email. Write a letter to your MP, then a local Lord.

Then you need to write to your boss, tell them that the cost of business will go through the roof (if you're able to do business. )

Then start looking at jobs abroad. Because no doubt there will be a twitter campaign, meaning that nobody actually bothers to engage in how the democratic process actually works.

Re: If David Cameron bans secure encryption he can't intercept

#68
post #62

Earlier quoted context omitted.

The one idiot they technically elected (or at least allow to control the wheel). Ultimately, it's the people's right and responsibility, not one man.

Hahaha! Only 37% of people voted for that guy... So how we are culpable I don't know!!

Because democracy.

Re: If David Cameron bans secure encryption he can't intercept

#69

It's pretty clear that the UK government doesn't have the power to ban encryption. This is just a distraction so that we are happy to accept whatever "less bad" proposals they come up with to increase their surveillance powers. I can't help but feel that peoples dislike of Cameron is a pointless distraction too. This is not Cameron. This is government. We will still be having this same discussion in 50 years, unless…

So... how close are we to tech that will make encryption universal and surveillance impossible, if so desired?

Re: If David Cameron bans secure encryption he can't intercept

#70
post #22

Earlier quoted context omitted.

Read about the Dulles brothers. They forged very strong connections between overt and covert foreign policy and industry.

I'm actually reading the book Brothers by David Talbot right now. It covers the relationship between John and Bobby Kennedy and includes a pretty good section about how in the 50s the Dulles brothers basically dictated foreign policy. There was a lot of friction when JFK came into office because, especially after the Bay of Pigs, he didn't let them get away with things. The book does veer somewhat into unfounded cons…

> There was a lot of friction when JFK came into office because, especially after the Bay of Pigs, he didn't let them get away with things.

And there is the essence of why we want transparency, oversight, restricted privacy etc. I generally feel that if everything the security services did was publically available (at least on level with civilian police) there would be a lot of friction but they would get immersurably better.

Post reply on HN