Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

241–245 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#241

Earlier quoted context omitted.

> Whoever proposed it should be ashamed of themselves Name and shame: Interior Minister Horst Seehofer of the conservative-authoritarian CSU. He and his party friends are who want this. We have the chance to kick them out of office in 2021, it's time for the stranglehold of Conservative internet-printers (Internetausdrucker, a German word for tech illiterates) as Interior Ministers to end once and for all .

> Conservative internet-printers By association Otto Schily wasn't a conservative and yet...

That there are other authoritarians doesn't make the CDU/CSU less authoritarian.

Re: New German law would force ISPs to allow secret service to install trojans

#242
post #220
post #139

Earlier quoted context omitted.

Browsers should phase out and block executable downloads from HTTP sources in 12 months.

They should not. They should maybe give bigger warnings, but lets not break all of the old web just to protect a few more people against themselves.

Any untouched, unpatched, unmaintained executables from 2007 should not be ran today, period.

Re: New German law would force ISPs to allow secret service to install trojans

#243

Earlier quoted context omitted.

Browsers and operating systems include a list of root certificates which includes those of various governments. Pretty much any government can thus issue valid HTTPS certificates for any domain to MITM traffic.

Part of dns actually prevents that. So long as you are using a browser that has implemented its use, dnd entries specifify the public signing key of the destination server, so if the browser receives a packet signed using a different certificate the Browser will prevent you from navigating there. I know for a fact that Chrome and Firefox have implemented this as standard behavior specifically to prevent this kind of…

Which DNS record type are you talking about? CAA?

Re: New German law would force ISPs to allow secret service to install trojans

#244

Earlier quoted context omitted.

Google, Mozilla, et al. should make a commitment to revoke the trust of any CA that is found to partake in behavior like that. Even retroactive revocation of existing certificates shouldn't be off the table if the offense is egregious enough. It's actually pretty scary seeing just how many CAs are in the list of trusted CAs on any given device. While no government is beyond reproach, I do wish there were a way for me…

Browsers blacklisted Kazakhstan government certificate used for MITM which was not even trusted. It is absurd to expect anything less than blacklisting such a CA immediately. Certificate transparency is required for all certificates since April, 2018, so you can't really issue rogue certificate.

> It is absurd to expect anything less than blacklisting such a CA immediately.

Is it, though? Germany has a lot more economic leverage than Kazakhstan. Suppose they pass a law requiring any browser sold or otherwise offered on the German market to have the government certificate in the chain of trust... how many large companies would cave?

Re: New German law would force ISPs to allow secret service to install trojans

#245
post #110

Earlier quoted context omitted.

The scary stuff about the current development is, that we get flooded with arguments about hardcore criminals, but if you look at the actual changes to the laws, such restrictions are not made, instead these extreme measures are allowed for petty reasons and some politicians will still keep pushing for even more totalitarianism. These siloviki want mass surveillance comparable to what Chinas Ministry of State Securit…

> It does not matter if Germany is not ruled by an autocratic regime at the moment I totally get the appeal of that argument, but it completely breaks down once I ask myself how much that autocratic bogeyman regime, once it got into power, would feel bound by privacy protections put in place by their predecessors.

It makes a big difference, actually. Few regimes go full-on totalitarian right away - it's more common to have a gradual erosion, where they operate within the letter of the law for a while, while gradually diminishing the spirit. So the more the letter allows, the more abuse you'll see from the get go.
Post reply on HN