Live data from Hacker News

Stop the Earn IT Bill Before It Breaks Encryption

act.eff.org

121–130 of 361 posts

Re: Stop the Earn IT Bill Before It Breaks Encryption

#121
post #105
post #3

I strongly believe we have lost the war for privacy and security (against state level actors) already. Once the net adopted the platform model, we were screwed. Platforms are as easy to regulate, as for example the telephone companies were back in the days. They were easily forced to comply with wiretapping demands of the government. The moment a central platform controlled (most of) our communication and was able to…

Then we should abandon those big platforms and move to millions of self-hosted personal mini-platforms. That way, you control your data, and you control who you share it with.

> That way, you control your data, and you control who you share it with.

Well, you already control who you share it with, as you're the one initiating connections to sites like Facebook. It just happens people give a lot away to browse sites these days (admittedly exactly what they're giving away remains quite opaque).

Unfortunately even if we did move to one-platform-one-person, the question of data control remains as murky as ever. Suppose you are hosting a party so you send your street address to your friends so they know where to show up. Then they play a fun quiz game that tells them their Harry Potter patronus based on the street address of their friends (that means you). Suddenly some anonymous quiz maker (let's call them Oxford Synthetica) has access to your street address and at least one of your friends' info through no direct fault of your own.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#122
post #34

There is a clear need for an opposite law which will make backdoors illegal. Who could fight for it?

Sadly Australia did the opposite - they can force us to backdoor applications and punish us for refusing. Australia is not the place to look for security applications.

As an Australian, my plan is to route most of my traffic through a self hosted VPN on a server that resides outside the five eyes (and possibly also the extended thirteen eyes).

Yes, there are insecurities and holes in the above, pending the methods of implementation, but it's one level of potentially many.

And whilst it's good to know that there are technical workarounds such as this, the real work, the real progress for society, is to make these technical workarounds unnecessary by, as the EFF says, contacting your representatives and letting them know what they're constituency thinks. Politics, sickeningly, is the only avenue for worthwhile change.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#123

All of you smart arses out here and there, we know it, we know. We know, VPNs and other stuff in between are not so secure and not private. Stop saying it, don't you have some other piece of knowledge to be proud of? for god's sake. Tor and Signal are better than Public Cloud, Chrome & SMS if you're looking for privacy. Don't you have common sense? - HTTPS is more secure and private than HTTP - Signal is more secure…

There are two parts.

1) Yes, you can build better encryption and privacy preserving technology. That is a technology and adoption problem.

2) There is so much you can do once the law says you can’t encrypt certain kinds of things and if you do, the state will be after you. That is a social problem. Our elected leaders aren’t serving us.

Not mutually exclusive. We have to do both. Build better tech, educate others and esp our politicians who can change the fabric of society.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#124

All of you smart arses out here and there, we know it, we know. We know, VPNs and other stuff in between are not so secure and not private. Stop saying it, don't you have some other piece of knowledge to be proud of? for god's sake. Tor and Signal are better than Public Cloud, Chrome & SMS if you're looking for privacy. Don't you have common sense? - HTTPS is more secure and private than HTTP - Signal is more secure…

Sit down dude. You think you are standing up for rights, but are making a case for weaker security by trusting, i.e. that MS and Apple won't backdoor you in an instant if they must. You are literally, actually, a shill, especially with this pompous presentation.

None of your list is better than nothing, if the authoritarians want your data. Except, maybe, Tor, and only if people contribute to running exit nodes.

If it isn't end-to-end, and only you know and control your keys, you are already doomed. In other words, you cannot trust any service with your keys. That includes https and signal.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#125
post #98

The question is what is really secure? Running Telegram, over multiple VPN's? Accessing Gmail over multiple VPN's so Google doesnt get to know where you are 'really' logging on from? Making your own VPN network over a combination of AWS, G-Cloud, Azure, DO and Aliyun to 'hide' your actual location? Peoples thoughts?

Rotate through various VPNs as your initial portal, and throw tor in there as well.

Share your VPN with friends and family to provide some 'noise' (although that may be worth little overall - maybe VPN through friends and family home connections as well).

Re: Stop the Earn IT Bill Before It Breaks Encryption

#126
post #67

Earlier quoted context omitted.

Exactly. I see this defeatism all the time regarding climate change too. It's OK to feel defeated. But why the hell would you spend energy to spread that defeatism?!

If you have been defeated, acknowledging it is crucial. It's hard to make progress while denying the actual nature of the situation. Not saying that's necessarily true in either of these situations, just that it's not a waste of energy to spread depressing truths.

"it's not a waste of energy to spread depressing truths."

It certainly is, if those "truths" are not absolutes. Find a way to redirect your -- and others' -- energies toward something positive and constructive. Spreading doom and gloom, full stop? Always a waste.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#127
I was going to call my Representative, and express my disapproval to my Senators for being on the sponsors list, when I actually read the act. I really don't see what the EFF is talking about.

It seems like a very straightforward bill that makes things much better by explicitly removing any liability from companies for either having end to end encryption or for not creating backdoors.

Here's my breakdown of the text of the bill:

---

Create a commission of 16 people, half appointed by each party. Can only make recommendations that 14 of the 16 approve of.

4 shall have current experience in investigating online child sexual exploitation crimes, of whom, 2 shall have such experience in a law enforcement capacity; and 2 shall have such experience in a prosecutorial capacity;

4 shall be survivors of online child sexual exploitation, or have current experience in providing services for victims of online child sexual exploitation in a non-governmental capacity;

2 shall have current experience in matters related to consumer protection, civil liberties, civil rights, or privacy; and 2 shall have current experience in computer science or software engineering related to matters of cryptography, data security, or artificial intelligence in a non-governmental capacity; and

4 shall be individuals who each currently work for an interactive computer service that is unrelated to each other interactive computer service represented under this subparagraph, representing diverse types of businesses and areas of professional expertise, of whom 2 shall have current experience in addressing online child sexual exploitation and promoting child safety at an interactive computer service with not less than 30,000,000 monthly users in the United States; and 2 shall have current experience in addressing online child sexual exploitation and promoting child safety at an interactive computer service with less than 10,000,000 monthly users in the United States.

---

the Commission shall develop and submit to the Attorney General recommended best practices that providers of interactive computer services may choose to engage in to prevent, reduce, and respond to the online sexual exploitation of children, including the enticement, grooming, sex trafficking, and sexual abuse of children and the proliferation of online child sexual abuse material.

(A) preventing, identifying, disrupting, and reporting online child sexual exploitation;

(B) coordinating with non-profit organizations and other providers of interactive computer services to preserve, remove from view, and report online child sexual exploitation;

(C) retaining child sexual exploitation content and related user identification and location data;

(D) receiving and triaging reports of online child sexual exploitation by users of interactive computer services, including self-reporting;

(E) implementing a standard rating and categorization system to identify the type and severity of child sexual abuse material;

(F) training and supporting content moderators who review child sexual exploitation content for the purposes of preventing and disrupting online child sexual exploitation;

(G) preparing and issuing transparency reports, including disclosures in terms of service, relating to identifying, categorizing, and reporting online child sexual exploitation and efforts to prevent and disrupt online child sexual exploitation;

(H) coordinating with voluntary initiatives offered among and to providers of interactive computer services relating to identifying, categorizing, and reporting online child sexual exploitation;

(I) employing age rating and age gating systems to reduce online child sexual exploitation;

(J) offering parental control products that enable customers to limit the types of websites, social media platforms, and internet content that are accessible to children; and

(K) contractual and operational practices to ensure third parties, contractors, and affiliates comply with the best practices.

----

Amends Sec 230e so that child sexual exploitation law gets its own section, on the list of things that section 230 does not apply to, joining, among other things, all federal criminal law, all IP law, sex trafficking, and privacy laws. The text to be inserted looks similar to the current sex trafficking text?

Explicitly say that the entire list of exceptions to 230 does not create liability, either federal or state IF you are end to end encrypting and cannot decrypt.

Not creating backdoors does not create liability.

----

Go through all federal laws and change "Child Pornography" to "Child Sexual Abuse Material".

---

So overall I don't see the issue. Seems like a good law.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#128
post #84
post #57

Earlier quoted context omitted.

>and then the users of that platform would simply stand out in ISP logs making it actually easier to spot them. Yeah no. Encrypted data would still be flowing all over the place, if our bad actors use VPN's to hide their traffic then it would become impossible for ISP's to see what they're doing or using. In addition, even if you can pinpoint who's using encrypted communications, unless you can prove they're actually…

>if our bad actors use VPN's to hide their traffic then it would become impossible for ISP's to see what they're doing or using you just transfered a problem from ISP level to VPN operator level. While you could argue that using multiple VPNs from different countries could make this somewhat harder, the problem still exists. Especially if you consider metrics other than IP, for example specific packet sizes or timing…

I mean a bad actor can easily use stolen/free wireless with a randomized mac on a machine that’s used for nothing else and not access any “usual” services while doing it.

This is more about ordinary people maintaining privacy in their normal daily activities, in ways that aren’t too inconvenient to use 24/7.

If a bad actor has the knowhow to build a custom platform they sure have the ability to access the internet in a way where they can’t be found by IP.

Governments still like to push anti-privacy laws because they help catch non-technical criminals who don’t put in a serious effort to hide. This is why they hate “built in” privacy protections in consumer software and demand ways around it, because they help protect even technically illiterate criminals.

What I'm trying to say is, the important question is how much do we want to erase privacy for 99% of people who use normal consumer software in order to help police catch the ~1% or whatever the percent of criminals is that also use normal consumer software, and just happen to also be criminals. The 0.01% of people that are criminals and have the resources and knowhow to actively try to avoid detection by building their own systems are not going to be caught in trivial ways (like tracking their IP to their apartment, vpn or no vpn, or tracking them through correlation from using their personal social media account from the same connection they perform illegal activity from) anyway so they don't matter.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#129
Easiest way to build traction around this effort is to write some stories suggesting Trump is trying to take away encryption (even thought spying has bi-partisan support).

The Trump angle will pick up mass media attention and the 'orange man bad' crowd will activate to make sure this doesn't get far.

There may even be debates on encryption and people may actually talk about encryption, privacy and policy.

Re: Stop the Earn IT Bill Before It Breaks Encryption

#130
post #96
post #73

Earlier quoted context omitted.

I think tokamak meant they will be banned by law , which sadly I can see happening - it effectively happened already with napster and bittorrent in some jurisdictions.

I doubt a US ban will have much effect on a french open source project.

You're thinking of PeerTube. Mastodon's lead developer is from Germany.
Post reply on HN