Earlier quoted context omitted.
Why worry about E2E encryption, in theory just need a cert issued from a vast array of CAs or intermediates. Which I wouldn't be suprised they possess the ability through some type of secret warrant, heck even private keys.
> Why worry about E2E encryption, in theory just need a cert issued from a vast array of CAs or intermediates. Certificate Transparency thankfully means this is a tool a government could only use once if at all, and then they've burned an entire CA.
Independent review of UK national security law warns of overreach
211–220 of 299 posts
Re: Independent review of UK national security law warns of overreach
#212Re: Independent review of UK national security law warns of overreach
#213Re: Independent review of UK national security law warns of overreach
#214I know this is about UK (where I am a foreigner living for almost a decade). But why are pretty much all governments universally inept? It's not only the UK but US gov has also pushed for this and plenty of other stupendously stupid ideas or decisions - and plenty of other governments (well, all of them) besides. It leads me to believe that our species is incapable of leading itself, that we are incapable of choosing…
What makes you think this is ineptitude? They know exactly what they're doing. The mistake HN commenters make is thinking "But TLS is encryption too! They can't ban Signal without also banning TLS!". They absolutely can if they want to.
Re: Independent review of UK national security law warns of overreach
#215I know this is about UK (where I am a foreigner living for almost a decade). But why are pretty much all governments universally inept? It's not only the UK but US gov has also pushed for this and plenty of other stupendously stupid ideas or decisions - and plenty of other governments (well, all of them) besides. It leads me to believe that our species is incapable of leading itself, that we are incapable of choosing…
Democracy: Through popularity contests
Monarchy: Through birth
Other various dictators: Through force/corruption
How on earth does anyone expect the best, most competent people for the job to be selected by these methods?
Re: Independent review of UK national security law warns of overreach
#216Earlier quoted context omitted.
>> The UK arrests 12k people per year for social media posts, using vague laws to undermine free speech. > This doesn't mean anything in isolation. It's pretty good proxy for freedom of speech, one of the features without which democracy is not possible. >> Here's the citation from the EU parliament itself [1], since I doubt you'd believe non-government sources. > Do we know each other? Probably not, but I can smell…
The problem here is that contextually you are falling into the trap of "talking about committing a terrorist act" as being relevant to "having private communications", and in the process you are conflating the two. This means you are falling into the trap that the UK government intentionally creates to suppress privacy — within a reader's head, now the two are related. This also means you haven't had to develop any a…
The famous US Supreme Court case[0] that explicitly confirmed that "Nazi speech is free speech" was brought to the court by the ACLU[1], a left-leaning organization that defends things like LGBTQ rights. Your take is completely divorced from factual reality.
American conservatives aren't "framing" it. They are restating what the US Supreme Court has already determined in a case brought to the court by the liberal left. This is a principled defense of free speech that has historically been supported by people across the political spectrum.
[0] https://en.wikipedia.org/wiki/National_Socialist_Party_of_Am...
Re: Independent review of UK national security law warns of overreach
#217Earlier quoted context omitted.
> they could sit on their hands and still get paid Could? I know of government employees who literally cannot do their job, yet somehow they've been employed for over twenty years. When I say they can't do their job, I mean they have to ask coworkers how to do something that is and always has been a job requirement, and they have to "ask for help" every time. People are actually enabling massive amounts of waste and…
Indeed. I work with governments all over the United States from federal, to states to counties, and even to larger cities. This is a consistent pattern I see as well. We have senior IT people who don't even know basics about firewall configuration. In one place, I waited 2 weeks for the IT person to figure out how to even get into the firewall configuration. Then they proceeded to completely screw it up in obvious wa…
It sure is not. I'm not going to list all the examples I know as embarrassing some departments does not end well but I have to share this one. I tried to email someone at the California DMV a couple decades ago. My email bounced and I got a strange routing error. I assumed the problem was on my end. The first thing I did was dig their MX records and what did I get? 2 MX records with RFC1918 address space (10.0/8). I managed to get through to a real person on the phone and that went nowhere. They eventually fixed it some months later but they probably enjoyed the email silence.
Another one involved a 3 letter agency that should know better and could not figure out how to install an intermediate certificate on their website. They expected me to instead install their certificate on all of our servers and got mad & huffy puffy when I refused. I am not naming them but after a couple years they figured it out.
Re: Independent review of UK national security law warns of overreach
#218> He warns that developers of apps like Signal and WhatsApp could technically fall within the legal definition of "hostile activity" simply because their technology "make[s] it more difficult for UK security and intelligence agencies to monitor communications. Sounds like Let's Encrypt would also fall under that. This has got to stop. If you want to stop criminals, then focus on their illegal activites, not the stree…
I don't think their real intention is to stop criminals, it's just the smoke screen similar to ChatControl and other similar legislations prohibiting privacy elsewhere.
Re: Independent review of UK national security law warns of overreach
#219Earlier quoted context omitted.
> Why worry about E2E encryption, in theory just need a cert issued from a vast array of CAs or intermediates. Certificate Transparency thankfully means this is a tool a government could only use once if at all, and then they've burned an entire CA.
Isn't certificate transparency opt-in, so any trusted CA could be a potential attack route.
Re: Independent review of UK national security law warns of overreach
#220This is a terrible headline, despite being the original. The "watchdog" is a KC (senior barrister) officially appointed to review the legislation. He's warning that this could be considered hostile activity under the act, which would be a bad thing . In other words, he's criticising the act for being overly broad, a view that most on HN agree with, and his criticisms of it presumably carry some weight, given his offi…
edit: I misunderstood the poorly-worded headline. It should have been something like "Creating apps like Signal could be 'hostile activity' according to govt., claims UK watchdog".