Live data from Hacker News

Facebook, WhatsApp Will Have to Share Messages With U.K.?

bloomberg.com

121–130 of 591 posts

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#121

Earlier quoted context omitted.

If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software). Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everyt…

Reflections On Trusting Trust: https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...

Yep, it's a super difficult problem. Having the source code available, and being able to validate the builds yourself makes everything a lot easier.

It's one of the reasons the Debian project has worked so hard at reproducible builds: https://wiki.debian.org/ReproducibleBuilds/About

Bugs can certainly occur (like Heartbleed etc) but the alternative (closed source opaque binary blobs) is much worse.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#123
post #24

The title is editorialized - it's not just Whatsapp, it's all social media platforms.

And it's misleading -- the article and the article's headline say nothing about adding a backdoor. There's not enough detail in the article to say exactly how this decision will affect WhatsApp. (The headline on Bloomberg, "Facebook, WhatsApp Will Have to Share Messages With U.K. Police" is more restrained.)

> And it's misleading

And worrying that a large number of readers interpretation of the article was influenced by a headline. We really have to do better and be vigilantly aware of how media and power influences public opinion, especially during times such as these.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#124
post #92

Earlier quoted context omitted.

> If the source code isn't available for audit by 3rd parties (or yourself), and you can't build it from source, then it was never really "secure" anyway. What lawmakers do or don't say is just noise. Careful - you're right that WhatsApp is untrustworthy, but laws that force them to add backdoors could well be applied to open-source code as well. Or make possession of non-backdoored software, open or not, illegal. Or…

If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software). Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everyt…

Source code availability isn’t really a solution to the trust problem. Sure, it allows for an audit, but the practical truth is that few people are qualified to perform those audits and few of them have a sufficient incentive to spend their time doing so.

So you still just invest trust in the maintainer or — if you’re lucky — the third party auditing firm who was paid to review the code.

That you can review the code doesn’t mean that anyone does so. At least not in an exhaustive and relevant way.

Closed source or open, the problem is made even worse now that we live in a Package Manager culture where even the simplest applications adopt dozens of dependencies.

I’m not saying that you should trust Facebook and their closed source applications, just that you’re not really all that safer trusting anyone else just because their source code is available.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#125

Isn't there any laws against this? I would think this should at least be against one or another amendment for Americans?

Most of what the federal government does is against one or another amendment (the 10th mostly) but gets slipped by under the commerce clause as that's how the system turned out.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#126

There's a funny,rag level newspaper in the UK, called DailyMail. I suggest reading comments under the article about this, gives a good idea of how naive people can be. https://www.dailymail.co.uk/news/article-7514787/Facebook-fo...

The daily mail comments section makes the Mos Eisly cantina look like a respectable day at ascot.

That's the nerdiest, but most British description of them ever. I'm nicking that.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#127

Earlier quoted context omitted.

If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software). Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everyt…

> If I can compile the code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors Where does that leave the rest of society? Having open source software and hardware is not enough, we also need laws that prohibit mass surveillance and support our efforts to uphold human rights.

Relying on laws leaves a lot of wiggle room for bad actors, slippery slopes, and political opinions changing over time. Laws are based on trust in institutions (do you _really_ trust large governments?).

Laws are probabilistic, whereas math & source code is deterministic. You can verify that computer code does what it says it does. Laws depend on enforcement and complicated judicial systems (based on humans) to interpret and apply the laws, which means they can effectively change over time, and the goalposts are never stationary.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#128
post #92

Earlier quoted context omitted.

> If the source code isn't available for audit by 3rd parties (or yourself), and you can't build it from source, then it was never really "secure" anyway. What lawmakers do or don't say is just noise. Careful - you're right that WhatsApp is untrustworthy, but laws that force them to add backdoors could well be applied to open-source code as well. Or make possession of non-backdoored software, open or not, illegal. Or…

If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software). Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everyt…

Yes of course. The old argument that Linux is free of backdoors because it is open source. It's such a ridiculous claim. Software systems on that scale are so complex, there is NO way whatsoever to make sure there isn't a backdoor in there. I would go as far as saying that OpenSource software by definition is more vulnerable to backdoors than closed source software, exactly because the source code is available and anyone with some credibility can make patches. It is the dreamland scape of the NSA.

Hacking into closed source code is much more dangerous (politically) for them and also more difficult.

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#129
post #92

Earlier quoted context omitted.

> If the source code isn't available for audit by 3rd parties (or yourself), and you can't build it from source, then it was never really "secure" anyway. What lawmakers do or don't say is just noise. Careful - you're right that WhatsApp is untrustworthy, but laws that force them to add backdoors could well be applied to open-source code as well. Or make possession of non-backdoored software, open or not, illegal. Or…

If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software). Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everyt…

[deleted]

Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?

#130
post #88
post #17

> Social media platforms based in the U.S. including Facebook and WhatsApp will be forced to share users’ encrypted messages with British police under a new treaty between the two countries, according to a person familiar with the matter. This sounds as if the platforms are already sharing with the US authorities. So this being about them sharing it now with UK authorities.

It's laundering. The idea is presumably to circumvent US rules on domestic spying by having GCGQ do it and transfer it to US agencies. Similarly the UK has had its spying ruled unlawful under ECHR: https://www.theguardian.com/uk-news/2018/sep/13/gchq-data-co... (perhaps this is why Richard Dearlove, "C" of MI6, is so Brexity)

This guy read Snowden.
Post reply on HN