Facebook, WhatsApp Will Have to Share Messages With U.K.?
141–150 of 591 posts
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#142Nowhere in the article is backdoor mentioned. Only sharing data that is encrypted. US an UK governments can't just force FB to add backdoor. It would require new legislation. FB must play ball for that to happen. Since WhatsApp has forward secrecy and end-to-end encryption, giving access to encrypted data is not easy to use. There might be some useful metadata that helps though.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#143Earlier quoted context omitted.
I live in London.It has already gone way beyond of what Orwell could have ever imagined. However,despite of all the surveillance, London is the crime capital of the world.This is probably the best place for criminals,as unless you pull a machine gun on a crowd,not much will be investigated.
Isn't most of the crime happening insides the bank offices?
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#144Earlier quoted context omitted.
It's laundering. The idea is presumably to circumvent US rules on domestic spying by having GCGQ do it and transfer it to US agencies. Similarly the UK has had its spying ruled unlawful under ECHR: https://www.theguardian.com/uk-news/2018/sep/13/gchq-data-co... (perhaps this is why Richard Dearlove, "C" of MI6, is so Brexity)
We urgently need new domestic spying laws given that five eyes has effectively broken them.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#145One can infer that the NSA cannot break strong encryption used in WhatsApp.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#146Earlier quoted context omitted.
I'm equally curious what this means for Signal and any other open-source encrypted services. In the US, ITAR could hypothetically be used to make open-sourcing of cryptographic algorithms illegal. This technique is used for robotics software that could be dual-purposed for weapons guidance.
> In the US, ITAR could hypothetically be used to make open-sourcing of cryptographic algorithms illegal. Wikipedia has some good info re: export of cryptography[0]. In addition, two circuits (Ninth[1] and Sixth[2]) have ruled that source code is protected by the First Amendment. [0]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... [1]: https://en.wikipedia.org/wiki/Bernstein_v._United_States [2]: htt…
Obviously, classifying something that has already been open source just makes it more difficult to use and numerous local copies will be retained, but it does make further distribution illegal.
This is the only mechanism I can think of by which the US government could kill Signal in its existing open-source form. It's ugly, but not unthinkable.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#147Earlier quoted context omitted.
Reflections On Trusting Trust: https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...
Yep, it's a super difficult problem. Having the source code available, and being able to validate the builds yourself makes everything a lot easier. It's one of the reasons the Debian project has worked so hard at reproducible builds: https://wiki.debian.org/ReproducibleBuilds/About Bugs can certainly occur (like Heartbleed etc) but the alternative (closed source opaque binary blobs) is much worse.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#148Earlier quoted context omitted.
> If I can compile the code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors Where does that leave the rest of society? Having open source software and hardware is not enough, we also need laws that prohibit mass surveillance and support our efforts to uphold human rights.
Relying on laws leaves a lot of wiggle room for bad actors, slippery slopes, and political opinions changing over time. Laws are based on trust in institutions (do you _really_ trust large governments?). Laws are probabilistic, whereas math & source code is deterministic. You can verify that computer code does what it says it does. Laws depend on enforcement and complicated judicial systems (based on humans) to inter…
This is why moving the goalposts and further normalizing surveillance is extremely dangerous. The rights that you enjoy today are not universal, and can obviously be eradicated in less than a generation.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#149Earlier quoted context omitted.
If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software). Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everyt…
Source code availability isn’t really a solution to the trust problem. Sure, it allows for an audit, but the practical truth is that few people are qualified to perform those audits and few of them have a sufficient incentive to spend their time doing so. So you still just invest trust in the maintainer or — if you’re lucky — the third party auditing firm who was paid to review the code. That you can review the code…
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#150Nowhere in the article is backdoor mentioned. Only sharing data that is encrypted. US an UK governments can't just force FB to add backdoor. It would require new legislation. FB must play ball for that to happen. Since WhatsApp has forward secrecy and end-to-end encryption, giving access to encrypted data is not easy to use. There might be some useful metadata that helps though.
There's also value in storing and archiving encrypted data because at some point in the future technology may enable them to decrypt it. Certain communications could prove quite valuable, even if old.