Live data from Hacker News

If David Cameron bans secure encryption he can't intercept

blog.mythic-beasts.com

31–40 of 104 posts

Re: If David Cameron bans secure encryption he can't intercept

#31
post #7

Honestly, it sounds kind of relaxing. Good excuse to get some sunshine. On a more serious note, I can't help but think David Cameron is employing the technique of attempting something extreme so that he can do something less extreme (but still really bad) later with less oversight. Of course you can't ban strong encryption. His advisers know that, he knows that, _everyone_ knows that. It will be very interesting to s…

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

What's to stop companies from additionally encrypting their channels end to end while passing through the backbone? They can decrypt the backbone all they want.

Re: If David Cameron bans secure encryption he can't intercept

#32
post #24

Except Cameron wants to backdoor end-to-end encryption like iMessage/Whatsapp, rather than mess with something like SSL. With SSL they can just get a warrant (or you know, don't get a warrant) and look at the server, where everything is in plain text. One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the pers…

What about apps that keep the encryption keys in the user phones and can't decrypt the contents of messages? Do they intend to ban those apps?

Re: If David Cameron bans secure encryption he can't intercept

#33

There won't be a ban, it will be licensed. Big companies like banks etc will get their licence right away, so your secure banking will be fine. Routers will still have wifi encryption because they'll have a licence. The licence will be implemented as a fee for a digital certificate that properly authenticates. So, you're a small startup with an idea for a secure messaging app. want a licence. no problem, its £10M. ha…

A license won't be enough. You'll have to provide a backdoor as well.

Re: If David Cameron bans secure encryption he can't intercept

#34
post #17

Earlier quoted context omitted.

It's not really the elected government, it's the security services asking for an expanded remit and being granted one by uncritical politicians and an apathetic media.

Who are the security services employed by? I certainly wouldn't call them private industry! Did you mean to say it's not elected government officials? Just curious, because I definitely consider a country's intelligence apparatus to be completely and wholly part of its "government", and would be surprised to find someone who didn't.

In France, government only refers to the ministers. Prime minister is chief of the government, meaning only the other ministers. But the president is the "chef d'état", (chief of state), and I guess what you call government, we call it "the state". So, for a French citizen at least, a country's intelligence is not part of the government but part of "the state".

Re: If David Cameron bans secure encryption he can't intercept

#35
post #15

The most unrealistic part is > Youtube fails to load with a secure connection error. YouTube still refuses to use anything more recent than RC4 encryption, so, if Cameron would ban all secure encryption, YouTube would probably still work.

"Your connection to www.youtube.com is encrypted with modern cryptography.

The connection uses TLS 1.2.

The connection is encrypted and authenticated using AES_128_GCM and uses ECDHE_ECDSA as the key exchange mechanism."

Re: If David Cameron bans secure encryption he can't intercept

#36
post #25
post #20

Earlier quoted context omitted.

Yeah I was going to have that as an example in my comment, but even then that seems unrealistic to me. Why wouldn't the big tech companies simply not do that? The UK needs them more than they need the UK, and if you took away the country's access to Facebook for more than an hour you'd have a riot on your hands.

I'd assume they'd go along with government policy, like they have done in e.g. China. And the government proposed taking down twitter and BBM during the London riots a few years ago.

I'm afraid you might be a tad ambitious regarding the weight the UK market carries with global corporate interests, as compared to the Chinese

Re: If David Cameron bans secure encryption he can't intercept

#37
post #22
post #17

Earlier quoted context omitted.

Who are the security services employed by? I certainly wouldn't call them private industry! Did you mean to say it's not elected government officials? Just curious, because I definitely consider a country's intelligence apparatus to be completely and wholly part of its "government", and would be surprised to find someone who didn't.

Read about the Dulles brothers. They forged very strong connections between overt and covert foreign policy and industry.

I'm actually reading the book Brothers by David Talbot right now. It covers the relationship between John and Bobby Kennedy and includes a pretty good section about how in the 50s the Dulles brothers basically dictated foreign policy. There was a lot of friction when JFK came into office because, especially after the Bay of Pigs, he didn't let them get away with things.

The book does veer somewhat into unfounded conspiracy territory, but I think it's an interesting read so far and the author doesn't come across as crazy so much as skeptical.

Re: If David Cameron bans secure encryption he can't intercept

#38
post #25

Earlier quoted context omitted.

I'd assume they'd go along with government policy, like they have done in e.g. China. And the government proposed taking down twitter and BBM during the London riots a few years ago.

I'm afraid you might be a tad ambitious regarding the weight the UK market carries with global corporate interests, as compared to the Chinese

I'm not so sure. It only takes one browser vendor with a significant interest in the UK (Google would be a good candidate, given that advertisers are very sensitive to legislation) to make the whole exercise useless.

Re: If David Cameron bans secure encryption he can't intercept

#39

It's pretty clear that the UK government doesn't have the power to ban encryption. This is just a distraction so that we are happy to accept whatever "less bad" proposals they come up with to increase their surveillance powers. I can't help but feel that peoples dislike of Cameron is a pointless distraction too. This is not Cameron. This is government. We will still be having this same discussion in 50 years, unless…

It's not really the elected government, it's the security services asking for an expanded remit and being granted one by uncritical politicians and an apathetic media.

The politicians decide what to fund. The police and border forces want more funding but are forced to make endless cuts. I guess spying is something they can ask for that is relatively cheap compared to traditional police work.

Re: If David Cameron bans secure encryption he can't intercept

#40
post #31

Earlier quoted context omitted.

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

What's to stop companies from additionally encrypting their channels end to end while passing through the backbone? They can decrypt the backbone all they want.

If it's a website, that would be like using custom encryption on HTTP.
Post reply on HN