Live data from Hacker News

UK Home Secretary says encryption on messaging services is unacceptable

reuters.com

31–40 of 394 posts

Re: UK Home Secretary says encryption on messaging services is unacceptable

#31

Is it technically feasible to have a back door and still be `end to end` encrypted ?

Yes, but the back door must be placed on either `end`, so an eavesdropper needs to intercept communication before encryption or after decryption.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#32

Is it technically feasible to have a back door and still be `end to end` encrypted ?

The definition of end-to-end encryption is that the decryption keys are only available to the client. Now your question asks the question of where the backdoor should be.

It is feasible. The backdoor should be at a very low level (not say a sandboxed application) from which basically nothing can hide on the device.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#33
post #7

How do they want to prevent someone from creating his own end-to-end encryption app? It may use other protocols to encode content (images, tweets, fb posts etc.). For me it seems to be more in a direction of so called "Big Brother" than real counter-terrorism.

The same way you prevent anything.. they make it illegal for people in the UK to make, or use, such products.

Don't think we can "tech" our way out of this.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#34
post #7

How do they want to prevent someone from creating his own end-to-end encryption app? It may use other protocols to encode content (images, tweets, fb posts etc.). For me it seems to be more in a direction of so called "Big Brother" than real counter-terrorism.

How do they want to prevent someone from creating his own end-to-end encryption app?

That's not an issue. Writing solid encryption software is very difficult on its own. You will hear "do not roll your own crypto" all the time from security experts. We don't live in a James Bond universe and it's beyond the reach of terrorist organisations.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#35
post #7

How do they want to prevent someone from creating his own end-to-end encryption app? It may use other protocols to encode content (images, tweets, fb posts etc.). For me it seems to be more in a direction of so called "Big Brother" than real counter-terrorism.

She's probably being led by the intelligence services on this, and of course they have ulterior motives, their ultimate project is to collect all signals, or as many as they can manage, which apps like whatsapp are thwarting at present.

Why can't we collect all the signals all the time?

This is incredibly dangerous for our society, no-one should have that much power. That power isn't about terrorism (or even very useful against terrorism), but about subverting governments, judiciary and businesses.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#36

How difficult would it be for these so called terrorists to develop their own end to end encrypted app? Perhaps something masquerading as something common like any port under 1000? It is feasible that the elimination of whatsapp/telegram/signal encryption would just lead to a way more complicated encryption system developed internally to these organisations.

Not that difficult, but it'd almost certainly have major security flaws that GHCQ and the NSA could exploit, because homebrew end-to-end encryption tends to. The bigger problem is that merely using an Isis-branded chat application is the equivalent of sending a text message to the security services saying "hello, I'm a potential terrorist, please pay special attention to my every movement". Even the Tor project hasn't actually managed to reliably disguise their protocol as something else, and they have a bunch of smart people working on it with the advantage that countries tend to reveal the fact they've been detected through blocking rather than just quietly monitoring the people using it and rounding them up the moment they try something.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#37
post #15
post #8

"He sent an encrypted message from whatsapp" Yes, and then he went and did something stupid with easily accessible tools and acted alone. You might have an argument if he was part of a coordinated attack against something but lone-wolf terrorism has always been defined as unpreventable by security services such as SIS. Once radicalised it's impossible to prevent individuals doing stupid stuff. The only thing she has…

> You might have an argument if he was part of a coordinated attack No. Even ignoring the erosion of privacy angle, this just doesn't work. Outlaw encryption, and only outlaws will use encryption. Provide government backdoors into the popular commercial messaging apps, and people coordinating terror attacks will just use custom, unknown, private encrypted messaging apps.

I'm going to play devils advocate here, I also dislike the erosion of privacy (enough that I even left the UK).

But you _can_ make the argument that if only outlaws use encryption then they're painting a target on their back, which leads to greater scrutiny by security services.

This is reasonably achieved by the current dragnet surveillance systems in place, along with ISP's logging everything.

I don't agree with it, of course I don't, but that's probably an angle people could take- But the angle Amber Rudd took is even more starved of sense.

It's like she didn't ask the appropriate question: "What could we have done to prevent this attack" and the follow up "If we had direct access to his phone and all of his communication information, what could we have caught" and the answer is _nothing_. He used tools commonly available to him, acted alone, probably told nobody.

Anyway, tell the bad guys you're watching the comms and they'll figure out how to talk, they're motivated and smart.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#38
It's just reverse psychology.

They have the means to break, degrade or bypass the encryption and they emit statements like these so people remain confident that they're not being spied on.

This routinely happens after leaks reveal that certain type of traffic is being targeted. In this particular case, Wikileaks.

In the past after all the PRISM collusion was revealed, all the PRISM partners started their PR campaigns showing their "commitment to privacy", and the soap opera with law enforcement agencies claiming they couldn't decrypt devices. In reality they have many tricks they have used for years now, like setting up a fake cell antenna, impersonate a phone carrier to take over a device.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#40
post #28
post #21

Hmm, this definitely brings up an interesting discussion I don't think HN has had before, especially something in a similar vein since Apple+San Bernardino fiasco. Obviously privacy is something that HN holds very close to its heart. But I'm interested in what do people here have to say about the privacy features are used by terrible people to do terrible things. And I want to share something that I think is one of t…

I strongly believe that tools are ethically neutral. A hammer, a knife or a government can be pretty useful, or pretty violent - depending on how you use it. This alone does not imply that a hammer, a knife or a government should not exist or be banned. edit: words

It's interesting when you extend that discussion to guns, in the UK guns are quite difficult to get hold of, I wonder what the incident at Westminster would have looked like if they were as available as they are in the US.

As always it's a trade off, some people loose the right to arm themselves at home but that means other people may not loose their life to a shooting.

Post reply on HN