Live data from Hacker News

How the Australian government plans to access encrypted messages

theage.com.au

21–30 of 107 posts

Re: How the Australian government plans to access encrypted messages

#21
> In mid-2013, less than 3 per cent of counter-terrorism investigations intercepted communications that were encrypted. Today that figure was more than 40 per cent, Senator Brandis said.

I want to hear more on this, because so far as reporting has gone on terrorist attacks since 2013... The use of encrypted messaging systems seems conspicuously absent.

Re: How the Australian government plans to access encrypted messages

#22
post #21

> In mid-2013, less than 3 per cent of counter-terrorism investigations intercepted communications that were encrypted. Today that figure was more than 40 per cent, Senator Brandis said. I want to hear more on this, because so far as reporting has gone on terrorist attacks since 2013... The use of encrypted messaging systems seems conspicuously absent.

In fact, it is notorious that they didn't use any such system, just regular SMS, speaking sometimes in Arabic or using very weak coded language. In general, these guys are morons.

However, ISIS overseas is different. They or an allied group have offensive cyber capability and an appreciation of opsec. They are known to have taken advantage of weak opposition opsec for disinformation and tactical advantage (hacking opposition command cellular devices via phishing and social engineering to get tactical planning information). I don't know if they use good encrypted comms, but it seems likely.

Would these skills migrate back to be use by local wanna be terrorists? I doubt it.

So the bigger problem is not deliberate use but accidental. If they were all using imessage by default it is going to be much harder. No easy meta data, no mass scanning of SMS. You're left with physical surveillance, phone calls, rough cell location data and HUMINT. If you can't get their Facebook messenger calls or messages you are stumped.

Of course, this is as intended -- no effective mass surveillance. But how do we enable supervised targeted electronic surveillance without it getting out of control?

If fb/google gave into to a CALEA type enforcement regime there are no limits on how much government surveillance would occur, at a level the Stasi would drool over.

Re: How the Australian government plans to access encrypted messages

#23
post #12

Earlier quoted context omitted.

What do you mean? The article basically boils down to Brandis wanting international intelligence agency protocols for warrants to get access to info like this.

> "get access to info like this" end to end encryption means only the end points (users) have the data. the afp can't ask the fbi to ask facebook to ask whatsapp to hand over the content of your messages if whatsapp don't have the content.

Well they can if fb include a copy of the session key, encrypted with the public key of the escrow authority, appended to the ciphertext. The crypto is done by the fb app, so it is within their ability.

Big companies are easier to coerce than e.g. the pgp developers. There is no way for you to wrap your own encryption layer around the one used by WhatsApp/etc. You can post pgp messages on those systems but that is something very few will do.

Re: How the Australian government plans to access encrypted messages

#24
post #18
post #15

I am a strong proponent of E2E encryption and the right for people to be able to communicate privately, however I thing Brandis is saying generally positive things. If Australia thinks someone is a criminal, and there is an agreed process to obtain a warrant (hopefully from a judge), I think that's fine. The NSA mass-surveiling Americans is entirely different, as are other similar tactics to spy on presumably innocen…

He's saying they'll use warrants... issued by Brandis. Which is the same as no warrants from a 'judicial vs government' point of view.

Yep, Brandi's is as slimy as they come.

Re: How the Australian government plans to access encrypted messages

#25
post #14
post #8

Earlier quoted context omitted.

> Given the difficulty of cracking end-to-end encrypted messages during transmission, one option would be to improve warrant-based access to communications at the sender or receiver ends, Senator Brandis said. > "At one point or more of that process, access to the encrypted communication is essential for intelligence and law enforcement," he said. > "If there are encryption keys then those encryption keys have to be…

Just because it's in your operating system rather than your apps doesn't mean it's any less of a backdoor.

Right, is a different back door, but at least it's not broken crypto. Not that I'm for compromised endpoints either.

Re: How the Australian government plans to access encrypted messages

#26
> The rapid proliferation of encrypted messaging by terrorist networks has prompted...

Giving governments the power to perform mass interception and decryption of communication doesn't seem like a sensible way to fight terrorists, even if they say it's only to be used on suspects. Terrorist attacks aren't increasing because the "bad guys" suddenly got their hands on a copy of OpenSSL.

In the case of the most recent attacks, these people were let into the country voluntarily.

Re: How the Australian government plans to access encrypted messages

#28
> "I personally want to live in a world where reasonable people and companies would say, 'You know what? Under the rule of law, and with the right oversight and a warrant, communications can be listened to when it's needed to protect us.'"

Yes well, I don't. But hey – why not facilitate foreign actors spying on our companies so that we may or may not catch any terrorists?

Re: How the Australian government plans to access encrypted messages

#29
post #2

Fantasy land stuff. Moxie is going to backdoor his encryption because some Australians he's never heard of tell him to? The prime minister, Malcolm Turnbull, is a noted user of Signal... One day these stories will be written by and about people who have a clue. One day...

It says specifically that the government will _not_ pursue the backdoor options; seems that they just want to have clearer international protocols around warrants for information. Seems sensible if you ask me.

A rose by any other name

Re: How the Australian government plans to access encrypted messages

#30
post #12

Earlier quoted context omitted.

> "get access to info like this" end to end encryption means only the end points (users) have the data. the afp can't ask the fbi to ask facebook to ask whatsapp to hand over the content of your messages if whatsapp don't have the content.

Well they can if fb include a copy of the session key, encrypted with the public key of the escrow authority, appended to the ciphertext. The crypto is done by the fb app, so it is within their ability. Big companies are easier to coerce than e.g. the pgp developers. There is no way for you to wrap your own encryption layer around the one used by WhatsApp/etc. You can post pgp messages on those systems but that is so…

The developers of Signal and similar privacy-oriented apps will probably rather shut down than compromise the security of the app. As long as at least one secure app remains, the policy is pointless. And even then there's other ways to communicate securely. There's no viable way to enforce this.
Post reply on HN