Live data from Hacker News

New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

signal.org

21–30 of 45 posts

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#21
post #8
post #6

I'm wondering if this proposal is enforced, and you opt out, how would it be known whether you're sending someone a URL? How would a URL even be distinguished from other text when you have opted out? I suppose you could detect some patterns, and it definitely wouldn't be clickable. But is the text google.com considered a URL for example? I guess it isn't? (yeah I know, it's a stupid law anyway, but just wondering)

If you 'opt out', service providers can prevent you from sending anything under these new rules. You might not even be able to reach out to support to complain without consenting to your messages being scanned.

So what is the difference of opt-in and opt-out here?

In both cases, they identify and scan something.

Not sure, if there is out at all.

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#22

I just want to express how much I appreciate Meredith Whittaker. She helped organize the Google walkouts, She's been working on AI safety since at least 2016, She advised Lina Khan at the FTC, and new she's out here advocating for preserving E2EE. A lot of people online give her flak for her opinions, but she's been consistently very loud and occasionally influential. She's done some cool uncontroversial tech work to…

RMS - https://en.m.wikipedia.org/wiki/Richard_Stallman

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#23
post #20

Earlier quoted context omitted.

Federation doesn't help at all if your host is untrustworthy. This is a question of having strong data privacy rules baked into law and also a good compliance regime. In fact, federation can make things a lot worse since federation makes it a lot harder to reason about who is transmitting and storing your data.

Nothing helps if your host is untrustworthy. But need I go into the little rant about how signal controlling the clients and the network means you have to take it on trust? However the point of federation is that you can find someone you trust. - and you get to control data residency, all those weird hard to comply with laws become super easy if your uncle hosts a family chat server that federates with others; or you…

Hosting a family chat server is a fair amount of work, I wouldn't call it super-easy. I would prefer that the hosting for my server has at least half a dozen people for whom it's their full-time job. I don't think one person can really keep such a thing secure and reliable to the standards that I would prefer.

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#24
post #20

Earlier quoted context omitted.

Nothing helps if your host is untrustworthy. But need I go into the little rant about how signal controlling the clients and the network means you have to take it on trust? However the point of federation is that you can find someone you trust. - and you get to control data residency, all those weird hard to comply with laws become super easy if your uncle hosts a family chat server that federates with others; or you…

Hosting a family chat server is a fair amount of work, I wouldn't call it super-easy. I would prefer that the hosting for my server has at least half a dozen people for whom it's their full-time job. I don't think one person can really keep such a thing secure and reliable to the standards that I would prefer.

but it would then be your choice.

and, c’mon, people do harder things in the interest of family.

Maintaining a home is a shitload of work, but we dont live in a prison so that we can avoid the effort of cleaning and cooking.

The skills to run a federated matrix instance, for example, can be had in less time than it takes to learn how to BBQ without starting a fire or poisoning someone. Yet we choose to do that, we even consider transferal of those skills to be a bonding experience.

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#25

I just want to express how much I appreciate Meredith Whittaker. She helped organize the Google walkouts, She's been working on AI safety since at least 2016, She advised Lina Khan at the FTC, and new she's out here advocating for preserving E2EE. A lot of people online give her flak for her opinions, but she's been consistently very loud and occasionally influential. She's done some cool uncontroversial tech work to…

RMS - https://en.m.wikipedia.org/wiki/Richard_Stallman

How is this relevant?

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#27

Earlier quoted context omitted.

RMS - https://en.m.wikipedia.org/wiki/Richard_Stallman

How is this relevant?

The earlier post mentioned 'rms' without explaining what that meant. The post you replied to added context by providing a Wikipedia link.

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#28
post #9
post #2

After losing my phone and not having a way to recover a lot of data, I've come to the realization that I don't want end to end encryption. I just want a responsible entity to store all my data in a secure way, and they'd only make money from what I'd pay them. If I lose everything, I still want access to my data, even if a proof of identity costs me. Of course incentive systems make that very hard in today's corporat…

This is not just idealistic - it's bordering on naive. Tech companies have proven, repeatedly, over decades, that they are not responsible with our data.

And are users more responsible with their data? I'm not saying to trust companies, I'm merely saying that it's a harder challenge to put the burden on users doing everything correctly than on the products being built with more ethics in mind.

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#29
post #2

After losing my phone and not having a way to recover a lot of data, I've come to the realization that I don't want end to end encryption. I just want a responsible entity to store all my data in a secure way, and they'd only make money from what I'd pay them. If I lose everything, I still want access to my data, even if a proof of identity costs me. Of course incentive systems make that very hard in today's corporat…

I too wish that encryption wasn't necessary, and people could just be nice to each other (or, in grown-up speak, incentives between literally every person and group were always perfectly aligned).

Until somebody figures out a non-dystopian way to achieve that, I'll stick with end-to-end encryption, though.

If you want to opt out of that, I can't stop you – I bet you'll be able to find an entity that will take both your money and your encryption keys. I just don't want that to become the default, or even only, way of doing things.

Re: New branding, same scanning: Upload moderation undermines end-to-end encryption [pdf]

#30
post #24

Earlier quoted context omitted.

Hosting a family chat server is a fair amount of work, I wouldn't call it super-easy. I would prefer that the hosting for my server has at least half a dozen people for whom it's their full-time job. I don't think one person can really keep such a thing secure and reliable to the standards that I would prefer.

but it would then be your choice. and, c’mon, people do harder things in the interest of family. Maintaining a home is a shitload of work, but we dont live in a prison so that we can avoid the effort of cleaning and cooking. The skills to run a federated matrix instance, for example, can be had in less time than it takes to learn how to BBQ without starting a fire or poisoning someone. Yet we choose to do that, we ev…

There are a lot of different layers here. Sure, it's not hard at all to set up a federated matrix instance. Doing it so it's as secure as keeping something in a locked house though, that's actually a pretty tricky skill. I'll grant that it's not necessarily harder than safe cooking, but it's a lot easier to find someone who can teach you safe cooking.

Now, another layer is that while I have a healthy distrust of corporations like Apple or Facebook, I actually think that it's virtually impossible to match the level of security they provide. And it's not a prison, it's a nice, clean cafeteria, with pretty good food which is practically free. The food could be better but I would much rather spend my time making home cooked meals than securing a server.

Post reply on HN