Live data from Hacker News

How the Australian government plans to access encrypted messages

theage.com.au

31–40 of 107 posts

Re: How the Australian government plans to access encrypted messages

#31
post #30

Earlier quoted context omitted.

Well they can if fb include a copy of the session key, encrypted with the public key of the escrow authority, appended to the ciphertext. The crypto is done by the fb app, so it is within their ability. Big companies are easier to coerce than e.g. the pgp developers. There is no way for you to wrap your own encryption layer around the one used by WhatsApp/etc. You can post pgp messages on those systems but that is so…

The developers of Signal and similar privacy-oriented apps will probably rather shut down than compromise the security of the app. As long as at least one secure app remains, the policy is pointless. And even then there's other ways to communicate securely. There's no viable way to enforce this.

OWS probably wouldn't comply, but have you noticed how hard it is to install something Apple/Google don't want on their platform? Side loading is feasible but improbable on Android, totally impractical on iOS. In place of well engineered solutions from principled developers there would be apps from collaborators. I'm thinking WhatsApp/Facebook will fold pretty soon. 99% of users won't care, and we'll be back to where we were with PGP: most messages are in the clear, the only encrypted ones are huge red flags for further tracking.

Re: How the Australian government plans to access encrypted messages

#32
post #28

> "I personally want to live in a world where reasonable people and companies would say, 'You know what? Under the rule of law, and with the right oversight and a warrant, communications can be listened to when it's needed to protect us.'" Yes well, I don't. But hey – why not facilitate foreign actors spying on our companies so that we may or may not catch any terrorists?

I would if it meant:

1. The rule of law has not been compromised (snowdon has shown it has already)

2. warrants are issued by a proper judiciary (not the likes of FISA)

3. Oversight that protected citizens privacy rights (let's all laugh at this one since it requires Snowdon to show us that oversight just doesn't exist)

So, agree with you :)

Re: How the Australian government plans to access encrypted messages

#33

Once again politicians making decisions about stuff they fundamentally misunderstand.

Actually, the most depressing part of this, is that they do understand. Turnbull is a noted user of Signal, Wickr, and other secure messaging services, and has pushed for other cabinet and parliament members to use them also.

They know what they're doing, and sooner or later they'll go for a "more equal than others" approach to encryption.

Re: How the Australian government plans to access encrypted messages

#34
Our governments appear to be pursuing mutually contradictory aims. On one hand there are increasingly frequent and powerful cyber attacks which can only be resisted through superior cyber-security and encryption. Then on the other hand we get this rubbish.

Is it even possible to solve both these problems at once in a way which preserves the freedom of the net and doesn't involve some crippling PRC style regulation?

Re: How the Australian government plans to access encrypted messages

#35
post #28

> "I personally want to live in a world where reasonable people and companies would say, 'You know what? Under the rule of law, and with the right oversight and a warrant, communications can be listened to when it's needed to protect us.'" Yes well, I don't. But hey – why not facilitate foreign actors spying on our companies so that we may or may not catch any terrorists?

>Under the rule of law

This is a meme that is coming from the top. Expect to see this phrase a lot more in articles and from talking heads on the topic. They aren't even very subtle about it.

https://www.google.com/search?q=Encryption+%22rule+of+law%22...

Re: How the Australian government plans to access encrypted messages

#36
post #20

The story title mentions Australia but this is relevant to all the 5eye nations, as they're obviously pre-briefing the media on what the agenda will be and this is the first time that we're getting detail on what they'll be proposing (the UK proposals were vague) What they seem to be talking around is implementing an app-level CALEA-like capability. What I think how they think it would work: companies would be made t…

Following this logic, it's a question of time until GPG gets outlawed.

Re: How the Australian government plans to access encrypted messages

#37
freedom-loving internet users will soon know how gun owners feel. every single bogus argument for gun control or "assault weapons" bans can, and will be, used against internet speech freedom and information privacy, now that the western political establishment has taken it upon themselves to strip you of your free speech rights after seeing how trivial it was stripping you of your guns, and how much enthusiasm their populaces had for it. you can count on that. it was almost like a practice round for the real task of shutting everyone the hell up and monitoring what they say in "private".

i wouldn't be surprised if they start calling it assault encryption. the US government at one point had classified encryption as munitions, i suspect^W observe more governments will^W are, or start enforcing usage as such.

the thing you'll be most surprised at (or not) is at how self-defeating your fellow citizens will be, and how enthusiastic they will be about having their freedoms systematically dismantled by government. they will embrace it, nay, they will DEMAND it at any cost. indeed, many of them will only be upset if it DOESN'T happen.

perhaps this will be a wake-up call, but i doubt it, seeing the way things are going. i'm willing to bet most people will actually be pro-speech-control. once they have taken your ability to express and defend yourself securely, what exactly is left?

and just wait until you see the kinds of laws people with no fundamental understanding of the topic are capable of coming up with. it won't be pretty, but i assure you it will be infuriating and hilarious.

Re: How the Australian government plans to access encrypted messages

#38

freedom-loving internet users will soon know how gun owners feel. every single bogus argument for gun control or "assault weapons" bans can, and will be, used against internet speech freedom and information privacy, now that the western political establishment has taken it upon themselves to strip you of your free speech rights after seeing how trivial it was stripping you of your guns, and how much enthusiasm their…

So if I go crazy armed with military grade encryption, how many school kids can I kill before the cops get me?

Sorry, your argument is bullshit.

Re: How the Australian government plans to access encrypted messages

#39
"I think we've got to take a common position [among the five eyes] on the extent of the legally imposed obligations on the device-makers and the social media companies to co-operate," Senator Brandis said.

He's got to realise that any such agreement will inevitably end up being the lowest common denominator of what each of the nations think they can reasonably get away with legislating, which in this case probably means that US (with the strongest device-maker and social-network lobby) will drive what is possible.

Re: How the Australian government plans to access encrypted messages

#40
For those who are unfamiliar with the Attorney General George Brandis, this is one of the people instrumental in implementing two year mandatory data retention.

This is a famous interview he gave which is shows how little he understands about the concept of metadata, and is mandatory viewing for all who are not familiar with him:

https://www.youtube.com/watch?v=Hw1ryLGs2ws

His utter inability to understand the issues that he is legislating is distrubing.

"What people are viewing on the internet is not going to get caught ... What people are viewing on the internet while they surf is not going to get caught. What will get caught is the web address".

The legislation ended up retaining the IP address that you visit, but not the host or URL. I suspect this is the distinction he was trying to make, but nevertheless, it is still disturbing.

Post reply on HN