Live data from Hacker News

How the Australian government plans to access encrypted messages

theage.com.au

11–20 of 107 posts

Re: How the Australian government plans to access encrypted messages

#11
None of any of this ever makes any sense. There will always be communication styles that are inaccessible to authorities. And if we ever get "spooky action at a distance" style communication that does not rely on an interposing medium (regardless of speed), then all this becomes even more moot.

Re: How the Australian government plans to access encrypted messages

#12

Once again politicians making decisions about stuff they fundamentally misunderstand.

What do you mean? The article basically boils down to Brandis wanting international intelligence agency protocols for warrants to get access to info like this.

> "get access to info like this"

end to end encryption means only the end points (users) have the data.

the afp can't ask the fbi to ask facebook to ask whatsapp to hand over the content of your messages if whatsapp don't have the content.

Re: How the Australian government plans to access encrypted messages

#13
post #2

Fantasy land stuff. Moxie is going to backdoor his encryption because some Australians he's never heard of tell him to? The prime minister, Malcolm Turnbull, is a noted user of Signal... One day these stories will be written by and about people who have a clue. One day...

It says specifically that the government will _not_ pursue the backdoor options; seems that they just want to have clearer international protocols around warrants for information. Seems sensible if you ask me.

How do you think the government will access end-to-end encrypted data without making use of a backdoor? (Or alerting the user.)

Brandis said warrants should be "sufficiently strong to require companies, if need be, to assist in response to a warrant to assist law enforcement or intelligence to decrypt a communication". A company which makes end-to-end encryption will not be able to assist law enforcement in this way unless they make a backdoor.

Conclusion: Brandis either doesn't know what a backdoor is, or he does know but realises that "backdoor" has negative connotations so he is pretending that that's not what it is. Both possibilities are pretty reprehensible in my opinion.

Re: How the Australian government plans to access encrypted messages

#14
post #8

Earlier quoted context omitted.

> Forcing firms not to implement end-to-end encryption is forcing firms to implement flaws in their encryption software. Which is why they're not pursuing it presumably.

> Given the difficulty of cracking end-to-end encrypted messages during transmission, one option would be to improve warrant-based access to communications at the sender or receiver ends, Senator Brandis said. > "At one point or more of that process, access to the encrypted communication is essential for intelligence and law enforcement," he said. > "If there are encryption keys then those encryption keys have to be…

Just because it's in your operating system rather than your apps doesn't mean it's any less of a backdoor.

Re: How the Australian government plans to access encrypted messages

#15
I am a strong proponent of E2E encryption and the right for people to be able to communicate privately, however I thing Brandis is saying generally positive things. If Australia thinks someone is a criminal, and there is an agreed process to obtain a warrant (hopefully from a judge), I think that's fine. The NSA mass-surveiling Americans is entirely different, as are other similar tactics to spy on presumably innocent people. Warrants are good, especially with people actively making calls.

Re: How the Australian government plans to access encrypted messages

#17
Obviously, either encryption works flawlessly for both legal and criminal purposes, or it works for neither.

What the proposal seems to concentrate is endpoints, where plaintext inevitably exists, and legal protocols for accessing it.

OTOH any sane implementation would only generate plaintext for display purposes, and would clear the RAM as soon as display (or input) is done, so finding the plaintext anywhere may be honestly impossible. At least, without tampering with the software on either end.

Re: How the Australian government plans to access encrypted messages

#18
post #15

I am a strong proponent of E2E encryption and the right for people to be able to communicate privately, however I thing Brandis is saying generally positive things. If Australia thinks someone is a criminal, and there is an agreed process to obtain a warrant (hopefully from a judge), I think that's fine. The NSA mass-surveiling Americans is entirely different, as are other similar tactics to spy on presumably innocen…

He's saying they'll use warrants... issued by Brandis. Which is the same as no warrants from a 'judicial vs government' point of view.

Re: How the Australian government plans to access encrypted messages

#19
post #13

Earlier quoted context omitted.

It says specifically that the government will _not_ pursue the backdoor options; seems that they just want to have clearer international protocols around warrants for information. Seems sensible if you ask me.

How do you think the government will access end-to-end encrypted data without making use of a backdoor? (Or alerting the user.) Brandis said warrants should be "sufficiently strong to require companies, if need be, to assist in response to a warrant to assist law enforcement or intelligence to decrypt a communication". A company which makes end-to-end encryption will not be able to assist law enforcement in this way…

I take the second option, this is a man who tried to claim metadata is not data.

And it took them just a few weeks to breach the 'safe guards' in place for the warrantless data retention scheme.

Http://www.smh.com.au/federal-politics/political-news/police-illegally-obtained-journalists-phone-records-under-new-metadata-retention-regime-20170428-gvutjx.html

Re: How the Australian government plans to access encrypted messages

#20
The story title mentions Australia but this is relevant to all the 5eye nations, as they're obviously pre-briefing the media on what the agenda will be and this is the first time that we're getting detail on what they'll be proposing (the UK proposals were vague)

What they seem to be talking around is implementing an app-level CALEA-like capability.

What I think how they think it would work: companies would be made to build lawful targeted intercept capability into their apps, in the same way telephony and other equipment is today. The app developer receives a warrant for an identifier and they're required to split off that traffic and change the keys, or encrypt it twice (the sender/recipient key and an intercept key - one per warrant (this happens with some net and tele warrants now)).

We all know the downsides of this approach, but it isn't technically impossible. What would be impossible is enforcing it, as it is more a regulatory hurdle. It is more possible today because of vertically integrated walled gardens being used for most app distribution - and backed by two of the largest companies in the world who may be susceptible to a compromise (especially as there is the large tax issues hanging over both their heads).

On a scale of how bad things can get - I think warranted targeted surveillance is better than device backdoors which is better than metadata retention which is better than the mass surveillance we have today (leading to cable splitting and DPI, or situations like Lavabit)

I don't see how, even if you're ok with warranted targeted surveillance, how a compromise is made here that doesn't lead to a wack-a-mole game where legitimate users are inconvenienced while the 'bad guys' are pushed onto alternate Android distributions and unofficial apps.

I also don't see how a CALEA-like capability is kept secure and safe - especially with apps (we saw the NSA use CALEA intercept to surveil political targets). Clapper et al always vaguely answer "key escrow" to this question without spelling out how that would work.

With subsequents backdowns in the scope of what these governments are wanting to do (and this latest proposal is again is a minor backdown) we might be reaching the finite conclusive point where comms do go dark and the new reality is that despite all of the tech we have law enforcement mostly relies on human intelligence and they'll have to scale back up for that. 3,500 terror suspects in the UK, 4,000 employees at MI5 - and notably in the recent attacks there were HUMINT warnings.

Post reply on HN