Live data from Hacker News

UK pulls back from clash with Big Tech over private messaging

ft.com

281–290 of 320 posts

Re: UK pulls back from clash with Big Tech over private messaging

#281

Earlier quoted context omitted.

You've sleight-of-handed out "government" for "the UK" and linked two stories which don't really involve the UK government. Furthermore if you read your own links, you will see that the "recent history" of the Rotherham offending is that there is an enormous police investigation costing tens of millions of pounds and a large number of people have been convicted, and the "recent history" of the fallout from Jimmy Savi…

Local police is a part of the government as far as the laws in question are concerned; it's them who will be using or abusing the surveillance powers granted by the law. And the Rotherham scandal took two decades to be addressed, due not least to fierce political interference.

What surveillance powers? Granted by what law?

Re: UK pulls back from clash with Big Tech over private messaging

#282

This article is completely wrong , and almost sabotages the fight against the UK Online Safety Bill, given it claims a victory that simply doesn't exist, and so lures everyone into a false sense of complacency. The UK govt must be ecstatic that they have changed nothing and yet the tech industry seems to believe that they've won something. All the govt said was "we'll only force scanning when it's "technically feasib…

Basically all of the secure messaging platforms have indicated that they will pull out of the UK rather than weaken the security model, if or when they are instructed to. That hasn’t changed either. What this may be politically is a way of the Government saying they won’t actually do it, while pretending that nothing has changed to make it look like it’s not a U-turn and pretending they’re not backing down. Hence the…

> What this may be politically is a way of the Government saying they won’t actually do it

But this is the problem: the Government is NOT saying they won't actually do it. They're saying "we'll do it (when we consider it technically feasible)". The ability to force 3rd party scanning software is STILL going into law, and that's the catastrophic bit!

It's terrifying that this story has been perceived as a victory, and therefore we can take the pressure off. The OSB is STILL on track to go into law giving the government the right to tell Signal or WhatsApp or Element etc that they either need to do compulsory scanning or they are breaking the law.

I am literally receiving emails from Element customers and suppliers which begin:

> Saw that the government backed down from their plans last night and immediately thought of Element – you must be pleased!

...which just leaves me speechless. I'm almost wondering if there's a deliberate misinformation campaign here to prematurely claim victory in order to derail the attempt to protect encryption in the bill.

Re: UK pulls back from clash with Big Tech over private messaging

#284
post #206

Earlier quoted context omitted.

Yeah, but if we're honest all three of those companies are more competent than the UK goverment. Source: sometimes interact with the UK government

So you just make the three companies keep the keys then. People are out here like "a secure backdoor to encryption is impossible" and then don't even blink for the keys for root CAs which is the basis for the world's online security. Or the AWS managed S3 encryption keys. There's a lot of of hopium in this thread for people who I think want it to be more impossible in practice than it really is.

It was never even suggested that the government would have encryption keys. The government do not have access to SSL traffic, but companies are responsible for CSAM uploaded over SSL.

Re: UK pulls back from clash with Big Tech over private messaging

#285

Earlier quoted context omitted.

Doesn't this problem exist throughout the tech industry though? Microsoft, Google, Apple etc are keeping the keys that allow you to push updates secret, aren't they?

If a software signing key is compromised it can be revoked and a few weeks later the risk is only to people who don't keep their OS up to date. Further, exploited compromises are detectable, especially if exploited at scale. If the backdoor crypto key is compromised, sure they can revoke it (assuming they manage to design a competent system), but all the sensitive information up that point is now available to whoever…

The same is true of SSL traffic to a bank though isn't it? If a crime group is intercepted encrypted traffic and saving it, then the keys are stolen, they can decrypt that data.

But opponents of the OSB claim it will make communication with your bank less secure - how?

Re: UK pulls back from clash with Big Tech over private messaging

#286

Earlier quoted context omitted.

Basically all of the secure messaging platforms have indicated that they will pull out of the UK rather than weaken the security model, if or when they are instructed to. That hasn’t changed either. What this may be politically is a way of the Government saying they won’t actually do it, while pretending that nothing has changed to make it look like it’s not a U-turn and pretending they’re not backing down. Hence the…

> What this may be politically is a way of the Government saying they won’t actually do it But this is the problem: the Government is NOT saying they won't actually do it. They're saying "we'll do it (when we consider it technically feasible)". The ability to force 3rd party scanning software is STILL going into law, and that's the catastrophic bit! It's terrifying that this story has been perceived as a victory, and…

and another datapoint at https://www.reuters.com/technology/uk-minister-says-position...

> "We haven't changed the bill at all," she told Times Radio.

> "If there was a situation where the mitigations that the social media providers are taking are not enough, and if after further work with the regulator they still can't demonstrate that they can meet the requirements within the bill, then the conversation about technology around encryption takes place," she said.

Re: UK pulls back from clash with Big Tech over private messaging

#287

This article is completely wrong , and almost sabotages the fight against the UK Online Safety Bill, given it claims a victory that simply doesn't exist, and so lures everyone into a false sense of complacency. The UK govt must be ecstatic that they have changed nothing and yet the tech industry seems to believe that they've won something. All the govt said was "we'll only force scanning when it's "technically feasib…

With the way the law is going the UK could demand that Tech providers provide backdoors into end-to-end encryption. The providers can refuse. The UK can then demand that such apps are not available in the UK. HOWEVER ... the providers can build WASM equivalents that run in the phones browser. These can be available elsewhere in the world, and there is no way to stop UK residents from installing them. If there is no o…

> Legislation that fights well implemented secrecy will always eventually loose, as the government becomes just one more hostile actor, which the tech is already set up to protect against. If the government pushes too hard, all that happens is that encrypted messaging moves out of app stores into the open internet ... and then, not only can they not see the content, they can barely see who is using it.

This is insightful. The mistake the UK government is making lies in it's naked aggression.

It's become sandwiched in hostility toward Big Tech, and the people. And it's a no win situation.

It literally wants to get in the middle, and that seems a sign of great fear of losing power in the digital age.

Fundamentally our government lack the humility to engage in meaningful, evidence-based, debate with all parties, which would be extremely difficult but necessary.

Of course encrypted messaging is already out on the open internet. It's just used for social messaging by a relative minority. The reason governments love (read: awkwardly tolerate) big platforms is they concentrate use, where they hope it can be "kept an eye on".

For me this is "Police and thieves in the street, fighting the nation with their guns and ammunition"

It's a three way fight in which the most important group - the people - are unarmed, indeed entirely excluded.

What we tried to do on https://cybershow.uk is to present some accessible banter that helps the main stakeholders - children and vulnerable people - get a better fix on the issues, and have a voice.

Re: UK pulls back from clash with Big Tech over private messaging

#288

I’d like to see social media companies taking the opportunity to cut off all services to this country. Use them as an example so other nations don’t get any wild ideas.

Given all of the societal ills caused by social media it could backfire.

Re: UK pulls back from clash with Big Tech over private messaging

#289

Earlier quoted context omitted.

The ostensible reasoning is "think of the children" horseshit, but history proves such a powerful capability will be abused for unrestrained spying. Key escrow for the entire US and world was floated with the Clipper chip (1993-1996). That was strangled in its crib because trusting thousands of people at NSA or GCHQ to just not stalk people is sheer fantasy, just as the Snowden leaks revealed. iMessage stores the e2e…

Why is Signal "irreparably" broken? What makes the phone number issue "irreparable"? As I understand it usernames and phone number privacy are in the pipeline. I'm a software engineer who does know; I'm aware that Signal is currently tied to phone numbers, and I'd love for it not to be, but I still use it, because it's E2EE and easy for non-technical people to use. When there's something that's easy to use like Signa…

If you have a mobile phone number, the domestic intelligence agency knows exactly where you are at all times and any LEO (without a warrant) can also find you. In addition, there have been numerous CCC presentations showing how insecure the global (excluding US) and (separately) US carriers are guilty of promiscuous metadata trafficking ($$) and insecure SS7 setups. As a consequence, for low $, you can go to any one of several shady websites and find the last location of almost any phone number (person unique ID) globally. There are additional varying exploitable vulnerabilities depending on the exact combination of {handset x carrier x country} to impersonate them, tap their line, reveal their exact location, and redirect their phone number through a third-party handset or even a PBX. These are more expensive and some capabilities are forbidden for all but a few selective intelligence uses.

Session (Signal fork) doesn't use phone numbers. It's pretty well-designed overall and uses an onion routing approach. It's already a superset of Signal except it doesn't use phone numbers. https://getsession.org

Also look interesting:

* (unproven) https://www.olvid.io/technology

* (unproven) https://simplex.chat

PS: Using regular TOR on home broadband or cloud servers is relatively risky and inefficient. Sybil attacks on it are common. And to network operators and security agencies it gives an easy "flow tag" of your uplink and exit node data traffic as automatically suspicious.

Re: UK pulls back from clash with Big Tech over private messaging

#290
post #165

Earlier quoted context omitted.

I don't think so. When you text somebody it's assumed it's SMS, but if your friendship circle is on Android then in actual fact it's Google Messages. All the same benefits: end-to-end encryption and data mining.

No. I have lived in the UK for 35 years and I didn't even know Google Messages existed until you mentioned it. WhatsApp is the default and I would only use SMS in the rare case that someone did not use WhatsApp. There is no automatic integration on Android phones between SMS and another network the way iMessage is automatic.

> I have lived in the UK for 35 years and I didn't even know Google Messages existed until you mentioned it.

Exactly, even though it is the default messaging app on Android and receives their SMS texts for them, most users don't realise they are using it or that when they "send a text" to another Android user it is actually sending the message over data.

Anyway my understanding is that a text is a SMS text, and a whatsapp is a whatsapp message. I know that Google Messages hides itself by sending SMS texts when the number isn't known to Messages, and I guess Whatsapp does this too. I also live in the UK and occupy a space within multiple different communities which insist on different messaging apps. May be I just don't the option to be so vague.

Post reply on HN