Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

231–240 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#231

Earlier quoted context omitted.

Like TSA luggage keys.... there's no way those would leak online, and no way anybody would be able to download them from https://www.thingiverse.com/thing:1687424 and 3d-print them... no way something like that'd happen!

Luckily, you can't 3D print an encryption key that would be useful in any way. Although, now I wish the guy from Lavabits had handed in his SSL cert as 3D printed letters and numbers like a puzzle.

> Luckily, you can't 3D print an encryption key that would be useful in any way.

That's true, you have to rely on Sony executives to tweet them out instead. https://m.slashdot.org/story/147470

Re: EU Draft Council Declaration Against Encryption [pdf]

#232
post #172

Earlier quoted context omitted.

I suspect you're underestimating the ability of criminals to obtain communication tools with sufficient plausible deniability to prevent detection by the local police after the first few prosecutions for that.

I suspect you overestimate the bespoke firmware-altering abilities of the average local criminal gang.

All they really need to hide from the local cops is an app that appears to be something else. A quick google search for "disguised encrypted chat app" found one called CoverMe that can disguise itself as a photo album. There are probably more sophisticated options available now, and there will be an explosion of them if the EU bans encrypted chat apps.

With a marginally more sophisticated user, they can get far more hidden. The Android anti-theft app Cerberus, before the company behind it imploded spectacularly, could be installed as a system app on any rooted device, then hide itself until a user-specified code was entered on the phone dialer. If there isn't already an encrypted chat app with that feature, there surely will be after an EU ban. The barrier to entry is not high.

I'll grant it would likely result in a small number of gang members spending a greater percentage of their lives in jail, but that's not a lot of benefit for an extremely high cost.

Re: EU Draft Council Declaration Against Encryption [pdf]

#233

Earlier quoted context omitted.

Brexit was founded on the misunderstanding that it was "faceless unelected bureaucrats" that run the EU. I'd argue Britons wielded more power than most others in the EU, and that the EU parliament is quite a lot more democratic than the British one. The british are now stuck with the UK parliament without adult supervision.

Can you explain how average Brit had more power?

Because they still had exactly the same power in their own government, and a sizable chunk of power in the European one. Now they'll follow a huge part of European regulations to be able to trade, but have no seat at the table.

Re: EU Draft Council Declaration Against Encryption [pdf]

#234

Earlier quoted context omitted.

E2E encryption is scary. I'm also in the "you can't ban math, why try" camp. But I can't see authorities/politicians give up the idea of getting access to decrypted communications after court orders, in a 100 years, even if everyone completely understood the topic. It's just not happening.

guns are scary knives are scary

Indeed yes. Also, sharks.

Re: EU Draft Council Declaration Against Encryption [pdf]

#235
post #121

Earlier quoted context omitted.

This is silly. Governments have all sorts of things like machine guns, tanks, and battleships that (rightfully) aren't allowed for the general public.

> Governments have all sorts of things like machine guns, tanks, and battleships that (rightfully) aren't allowed for the general public. You have listed three things which are all really the same thing. There is no objection to private ownership of motor vehicles or ships. You object to the weaponry. But we can put aside the whole right to bear arms debate in this case because there is an obvious way to distinguish…

Secure communication is not a purely defensive technology. It allows you to safely coordinate an attack.

Re: EU Draft Council Declaration Against Encryption [pdf]

#236

This is madness. Oh, of course, it's much easier to put a wrench into some gears to show that you are actually working at "solving the terrorism problem" than shaving the yaks, but that machine is actually important for other things. We live in a dangerous world. We cannot control everything. I don't mind a slight risk of terrorist attack on myself or my family (caveat lector: I am young), if that means greater freed…

>We live in a dangerous world.

No we don't, but that's what the Politicians try to implement in our brains.

Re: EU Draft Council Declaration Against Encryption [pdf]

#237

So before discussing this I suggest people read the article because the title is misleading This is (from what I understand) not about a blanket ban on encryption, but the possibility to allow wiretapping on certain E2E comms. Also relevant is this recent decision by the ECJ https://www.cnbc.com/2020/10/06/ecj-limits-government-spying... (Naturally this is worrying and I think the main issue with security lies on lac…

If you can have wiretapping you don't have E2E encryption. So I think this would be a ban on E2E encryption, not on encryption in general of course but I think that should be self evident.

You could permit only weak encryption, this would allow E2E, but still be wiretapped (although with difficultly).

This also gets rid of the need for master keys or key escrow.

(Don't shoot the messenger, this is a technical theoretical idea, not a policy suggestion.)

Re: EU Draft Council Declaration Against Encryption [pdf]

#238
I see this as follows:

1. Terrorism and trafficking of children will win the moral high ground.

2. App stores will be forced locale by locale to conform to these policies.

3. Most people will not notice or care.

4. This will be used by N-Eyes and totalitarian governments to quash dissent.

5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely.

6. Those secure methods will be used by people with the most to lose. (e.g. the drivers of point 1)

Given this predictable series of events I see the primary question as: How do we prevent (4)? How can we make people secure by default again and make adoption easy in the face of app store capture.

Re: EU Draft Council Declaration Against Encryption [pdf]

#239
post #131

My serious question is this: how do we stop terrorism and criminals when they have access to military grade encryption technology? It seems like there is a lot of ideological push for freedom, but as criminal activity moves to the virtual world, have we not created a problem for ourselves?

> My serious question is this: how do we stop terrorism and criminals when they have access to military grade encryption technology?

You don't and technology has nothing to with it either.

Terrorism is as old as government itself and doesn't need the internet in order to function.

Radicalisation takes place in many places and law enforcement as well as national intelligence agencies have put their focus away from good old-fashioned police work, infiltration and observation towards telecommunication.

There was no internet in 1972, yet the Munich Olympiad Massacre happened. Just take a look at a random year pre-internet: https://en.wikipedia.org/wiki/List_of_terrorist_incidents_in...

Terrorism is neither a new phenomenon nor boosted by the internet - it's our perception that has been boosted. Today, every single incident is instantly known and international news.

People just seem to have forgotten that terrorism was pretty much part of daily life in past decades, too (the German version seems to be more complete, listing terror attacks without fatalities as well: https://de.wikipedia.org/wiki/Liste_von_Terroranschlägen_im_... )

Exchange of information and coordination doesn't require encrypted internet technology at all.

In Spain, ETA declared a new ceasefire in 2010 presumably because political parties with ties to them were banned and a leading member died (of undisclosed cause).

In Germany, the left-wing terror group RAF disbanded in 1998 after key members had been arrested and the 1991 collapse of the Soviet Union, Germany reunification and the subsequent disintegration of the communist bloc basically robbed them of their ideological base, support structures and legitimisation.

The whole IRA business seemed somewhat sorted with the Good Friday Agreement in 1998, but in the aftermath of Brexit tensions seem to start to raise again.

Basically, politics, old school police work and having a close eye on organisations are much more effective than mass surveillance and technology.

You won't be able to catch every "lone wolf" - be that the right-wing extremist who starts a mass shooting or the Islamic extremist who randomly stabs people.

But you can avoid a lot of it by enforcing a zero-tolerance policy (most of the recent extremist terrorists had a criminal record), deporting criminals, shutting down organisations that support terrorism (including mosques if applicable) and drying out sources of finance.

Mass surveillance, bans, and thought crime (i.e. "hate speech", which is basically a blanket term for "I am offended" these days) are not viable solutions.

Post reply on HN