Live data from Hacker News

The coming war on end-to-end encryption

community.qbix.com

31–40 of 58 posts

Re: The coming war on end-to-end encryption

#31
post #9

The thing I don't get is... won't bans on end-to-end encryption ban https? If I go to a website and ask for a web page over https, isn't the request and response between my device and the web server, an end-to-end encrypted message? Because the endpoints are my device and the web server. If I can't send my credit card details to a payment provider over an end-to-end encrypted channel, doesn't all commerce on the web…

No.

To be particular, "bans on e2e" are specifically targeting encryption between individuals on communications platforms.

They won't and can't ban secure comms between a user and a site during a web session. But they want the messaging platforms to be able to reveal the plaintext of conversations to law enforcement.

Of course "they" can't stop coded messages, or me sending encrypted messages via email or media platforms. They're just making it harder for non technical people (some of whom are criminals) to have privacy.

Re: The coming war on end-to-end encryption

#32

Is the world becoming more and more Orwellian? Is this a long term trend? It got pretty much unnoticed on HN, that Europe recently voted to make all crypto payments illegal unless the seller collects the personal data of the buyer. Independent of the amount. So there will be a track record of everything bought via crypto. Is it only a matter of time until cash is going away globally, and states have access to everyth…

If I buy crypto and posess it in my own wallet afterwards I can usw it however. Atleast with monero.

How will you anonymously collect the groceries you anonymously bought?

Re: The coming war on end-to-end encryption

#33
post #25

Earlier quoted context omitted.

For the reason I just told you — they can be compromised much more easily, and are typically run by a party which isn’t fully aligned with your interests and those of the other participants in your conversation.

So what if I run my own server with a private guestbook. Is https not end to end encryption in that scenario? I realize your point, that in most circumstances https is not being used as end to end encryption. But it can be, so wouldn't it also be attacked in this war?

Well, HTTPS with certificate chains without backdoors by a government is already technically illegal in some parts of the world.

But as I said, our definitions need to be useful. If the goal is for individuals to safeguard their conversations from prying eyes, then HTTPS is not the way to do it. Hence the government is likely to start with end to end encryption of the sort I have been emphasizing. With servers, they already have the tools… they can even IMPERSONATE YOU in Australia now and post as you.

Re: The coming war on end-to-end encryption

#34
post #13

Earlier quoted context omitted.

Well, HTTPS is not end-to-end. That latter term is reserved for encryption that encrypts the messages between clients so servers can’t parse them. When you have a centralized system like ICANN DNS, the governments know which IP addresses the domain points to. They can go and serve them National Security Letters or shake them down to install secret backdoors. WhatsApp and Facebook can lie to you that they’re end-to-en…

>When you have a centralized system like ICANN DNS, the governments know which IP addresses the domain points to. They can go and serve them National Security Letters or shake them down to install secret backdoors. HN opinions on CloudFlare aside, CloudFlare Tunnels mean DNS records point at CloudFlare servers, and the IP address of the origin server isn't discoverable via DNS. Sure, it's a court order away from bein…

I’d like to say it was all part of a secret plan to not draw attention to ourselves until we were ready. But it wasn’t.

The sad truth is, we were always low on money and bootstrapping. We spent a lot of time building, and very little time pitching.

We pitched about 10 VCs total in this whole time. I remember being at an event where Reid Hoffman spoke, he said he pitched 99 VCs before he got investment.

But we spent zero on marketing and PR, and 11 million people in 100 countries downloaded our Groups app. But the app is not that interesting, people don’t understand that most of our users are community leaders.

What people don’t get is that in this space, you need ALL THE FEATURES that Big Tech platforms offer before people will switch. It simply took us 10-12 years to get to this point. I picked a hard problem, but a very rewarding one in the end.

Look, MySQL and NGinX took 10 years before VCs funded them. But to be fair, they grew a lot whereas Qbix didn’t. Maybe I and my team simply suck at making things viral. But I believe this year will change that.

Networking is hard. I’m a guy who came from an immigrant family in Brooklyn. I never moved to the West Coast. We applied to HN with Qbix every other year since 2011. Never even got invited to the interview.

Now, I personally know Noam Chomsky, Tulsi Gabbard, Andrew Yang, Tim Berners-Les (see the photo at https://wefunder.com/Qbix), the Rohingya Project guys, Queen Diambi of a tribe in the Congo, the hed of United Nations Capital Development Fund, the head of CoinDesk, and many more randomly assorted people I met over the years. But it took years.

And I still don’t know very good VCs. And many VCs still look at our open source project as ”too big”. They prefer to invest in small feature companies, which we can now spin off from our accelerator.

If you want to introduce me, I’m very happy to take a meeting and demo on Zoom.

And if you want to support it, just go to https://wefunder.com/Qbix and kick in $100 or something. We are gearing up launch the 5th of November this year — and you’ll definitely not forget that :)

Re: The coming war on end-to-end encryption

#35

Is the world becoming more and more Orwellian? Is this a long term trend? It got pretty much unnoticed on HN, that Europe recently voted to make all crypto payments illegal unless the seller collects the personal data of the buyer. Independent of the amount. So there will be a track record of everything bought via crypto. Is it only a matter of time until cash is going away globally, and states have access to everyth…

Everything can already be tracked via crypto, that procedure of attributing a name to it just makes the process easier.

Additionally, everything you do buy is already tracked. Even with cash.

But unlike naysayers, these things already encroaching on our lives gives us even more reason to push for stronger E2E support as a default. Assuming it's done properly, and not "I just need to ask Google for the keys".

Re: The coming war on end-to-end encryption

#37
post #13
post #9

The thing I don't get is... won't bans on end-to-end encryption ban https? If I go to a website and ask for a web page over https, isn't the request and response between my device and the web server, an end-to-end encrypted message? Because the endpoints are my device and the web server. If I can't send my credit card details to a payment provider over an end-to-end encrypted channel, doesn't all commerce on the web…

Well, HTTPS is not end-to-end. That latter term is reserved for encryption that encrypts the messages between clients so servers can’t parse them. When you have a centralized system like ICANN DNS, the governments know which IP addresses the domain points to. They can go and serve them National Security Letters or shake them down to install secret backdoors. WhatsApp and Facebook can lie to you that they’re end-to-en…

> Well, HTTPS is not end-to-end.

Sure it is. It's just that the "ends" in this case are your browser and the web server.

Re: The coming war on end-to-end encryption

#38
post #26

Earlier quoted context omitted.

> The “end” in end-to-end encryption for regular users is never a server. Why not? Are servers not communication endpoints?

With that definition of “end”, “end-to-end encryption” isn’t different from just plain “encryption”. The significance of the phrase is that you don’t leak anything outside the ultimate ends of the communication, including to servers in the middle.

> The significance of the phrase is that you don’t leak anything outside the ultimate ends of the communication, including to servers in the middle.

Correct, but when you're viewing a web page (as opposed to using the web for peer-to-peer communications), that webserver is the ultimate end of the communication.

Re: The coming war on end-to-end encryption

#39

Is the world becoming more and more Orwellian? Is this a long term trend? It got pretty much unnoticed on HN, that Europe recently voted to make all crypto payments illegal unless the seller collects the personal data of the buyer. Independent of the amount. So there will be a track record of everything bought via crypto. Is it only a matter of time until cash is going away globally, and states have access to everyth…

Yes, because computers and world leaders are getting more powerful and everyday citizens are becoming less so.

Re: The coming war on end-to-end encryption

#40
post #22

Earlier quoted context omitted.

The “end” in end-to-end encryption for regular users is never a server. Servers are online 24/7 listening and can be found and raided and/or hacked by various forces. Clients are harder to locate. Especially if all you need to authenticate is a public/private keypair you generated. That is why governments are so frustrated with crypto.

> The “end” in end-to-end encryption for regular users is never a server. Why not? Are servers not communication endpoints?

I've found our problem. It appears the meaning has (apparently?) changed around 2014. Many search results you can find, including from IBM, and EFF, use the "old" (our) definition.

See: https://en.wikipedia.org/wiki/End-to-end_encryption#Etymolog...

> The term "end-to-end encryption" originally only meant that the communication is never decrypted during its transport from the sender to the receiver.

> ...

> Later, around 2014, the meaning of "end-to-end encryption" started to evolve when WhatsApp encrypted a portion of its network. ...

But, I don't have confidence that the policy makers will make this distinction.

Post reply on HN