Live data from Hacker News

Independent review of UK national security law warns of overreach

techradar.com

211–220 of 299 posts

Re: Independent review of UK national security law warns of overreach

#211

Earlier quoted context omitted.

Why worry about E2E encryption, in theory just need a cert issued from a vast array of CAs or intermediates. Which I wouldn't be suprised they possess the ability through some type of secret warrant, heck even private keys.

> Why worry about E2E encryption, in theory just need a cert issued from a vast array of CAs or intermediates. Certificate Transparency thankfully means this is a tool a government could only use once if at all, and then they've burned an entire CA.

Isn't certificate transparency opt-in, so any trusted CA could be a potential attack route.

Re: Independent review of UK national security law warns of overreach

#213
It is becoming more and more important that people learn to encrypt things locally themselves, its not end-to-end if the users are the ones encrypting and decrypting manually and then sending that message over unencrypted methods to comply with this draconian invasion of privacy. It would probably be a matter of time before they try to make using PGP usage illegal as well but they haven't yet.

Re: Independent review of UK national security law warns of overreach

#214

I know this is about UK (where I am a foreigner living for almost a decade). But why are pretty much all governments universally inept? It's not only the UK but US gov has also pushed for this and plenty of other stupendously stupid ideas or decisions - and plenty of other governments (well, all of them) besides. It leads me to believe that our species is incapable of leading itself, that we are incapable of choosing…

What makes you think this is ineptitude? They know exactly what they're doing. The mistake HN commenters make is thinking "But TLS is encryption too! They can't ban Signal without also banning TLS!". They absolutely can if they want to.

Sorry, ineptitude was perhaps the wrong word. But I'm sure people know what I'm getting at.

Re: Independent review of UK national security law warns of overreach

#215

I know this is about UK (where I am a foreigner living for almost a decade). But why are pretty much all governments universally inept? It's not only the UK but US gov has also pushed for this and plenty of other stupendously stupid ideas or decisions - and plenty of other governments (well, all of them) besides. It leads me to believe that our species is incapable of leading itself, that we are incapable of choosing…

Look at how these guys are selected:

Democracy: Through popularity contests

Monarchy: Through birth

Other various dictators: Through force/corruption

How on earth does anyone expect the best, most competent people for the job to be selected by these methods?

Re: Independent review of UK national security law warns of overreach

#216
post #193

Earlier quoted context omitted.

>> The UK arrests 12k people per year for social media posts, using vague laws to undermine free speech. > This doesn't mean anything in isolation. It's pretty good proxy for freedom of speech, one of the features without which democracy is not possible. >> Here's the citation from the EU parliament itself [1], since I doubt you'd believe non-government sources. > Do we know each other? Probably not, but I can smell…

The problem here is that contextually you are falling into the trap of "talking about committing a terrorist act" as being relevant to "having private communications", and in the process you are conflating the two. This means you are falling into the trap that the UK government intentionally creates to suppress privacy — within a reader's head, now the two are related. This also means you haven't had to develop any a…

> American conservatives have framed Nazi speech as a free speech issue

The famous US Supreme Court case[0] that explicitly confirmed that "Nazi speech is free speech" was brought to the court by the ACLU[1], a left-leaning organization that defends things like LGBTQ rights. Your take is completely divorced from factual reality.

American conservatives aren't "framing" it. They are restating what the US Supreme Court has already determined in a case brought to the court by the liberal left. This is a principled defense of free speech that has historically been supported by people across the political spectrum.

[0] https://en.wikipedia.org/wiki/National_Socialist_Party_of_Am...

[1] https://www.aclu.org

Re: Independent review of UK national security law warns of overreach

#217

Earlier quoted context omitted.

> they could sit on their hands and still get paid Could? I know of government employees who literally cannot do their job, yet somehow they've been employed for over twenty years. When I say they can't do their job, I mean they have to ask coworkers how to do something that is and always has been a job requirement, and they have to "ask for help" every time. People are actually enabling massive amounts of waste and…

Indeed. I work with governments all over the United States from federal, to states to counties, and even to larger cities. This is a consistent pattern I see as well. We have senior IT people who don't even know basics about firewall configuration. In one place, I waited 2 weeks for the IT person to figure out how to even get into the firewall configuration. Then they proceeded to completely screw it up in obvious wa…

I wish I could say that was an unusual experience.

It sure is not. I'm not going to list all the examples I know as embarrassing some departments does not end well but I have to share this one. I tried to email someone at the California DMV a couple decades ago. My email bounced and I got a strange routing error. I assumed the problem was on my end. The first thing I did was dig their MX records and what did I get? 2 MX records with RFC1918 address space (10.0/8). I managed to get through to a real person on the phone and that went nowhere. They eventually fixed it some months later but they probably enjoyed the email silence.

Another one involved a 3 letter agency that should know better and could not figure out how to install an intermediate certificate on their website. They expected me to instead install their certificate on all of our servers and got mad & huffy puffy when I refused. I am not naming them but after a couple years they figured it out.

Re: Independent review of UK national security law warns of overreach

#218

> He warns that developers of apps like Signal and WhatsApp could technically fall within the legal definition of "hostile activity" simply because their technology "make[s] it more difficult for UK security and intelligence agencies to monitor communications. Sounds like Let's Encrypt would also fall under that. This has got to stop. If you want to stop criminals, then focus on their illegal activites, not the stree…

> If you want to stop criminals, then focus on their illegal activites,

I don't think their real intention is to stop criminals, it's just the smoke screen similar to ChatControl and other similar legislations prohibiting privacy elsewhere.

Re: Independent review of UK national security law warns of overreach

#219

Earlier quoted context omitted.

> Why worry about E2E encryption, in theory just need a cert issued from a vast array of CAs or intermediates. Certificate Transparency thankfully means this is a tool a government could only use once if at all, and then they've burned an entire CA.

Isn't certificate transparency opt-in, so any trusted CA could be a potential attack route.

Browsers now require it to consider a certificate valid. Firefox, Chrome, and Safari all require a certificate to include proof of being logged in CT logs.

Re: Independent review of UK national security law warns of overreach

#220

This is a terrible headline, despite being the original. The "watchdog" is a KC (senior barrister) officially appointed to review the legislation. He's warning that this could be considered hostile activity under the act, which would be a bad thing . In other words, he's criticising the act for being overly broad, a view that most on HN agree with, and his criticisms of it presumably carry some weight, given his offi…

What an Orwellian name, 'watchdog', for an organization that undermines privacy. They're watching, all right.

edit: I misunderstood the poorly-worded headline. It should have been something like "Creating apps like Signal could be 'hostile activity' according to govt., claims UK watchdog".

Post reply on HN