Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

301–310 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#301
post #190
post #160

Earlier quoted context omitted.

That seems like such a gross oversimplification I don’t even know where to start. There will always be those in society who want to do harm for one reason or another, utopia does not exist. These people are what we call criminals.

Most criminals are criminals because of the circumstances. Circumstances can be improved but they'd rather spend 5.5 billion (the one after the million) € on Eurofighters than make away with poverty. We could go back and forth and it would change nothing at all because no one from the EC will see it and as an EU citizen I can't change the resolution, because the EP can't do anything about it. And just because there a…

Your view of reality is that of a severely coddled person. In reality, you cannot have rich without poor, unless you suggest literal communism. Even in Scandinavian utopias, people rape, steal and murder.

Please wake up from the fairy tale that all bad things have a just cause that can be fixed. No. Some people would rather steal your stuff than go to the trouble of getting their own legitimately.

Re: EU Draft Council Declaration Against Encryption [pdf]

#302
post #30

I'm sick and tired of seeing tech-illiterate decision makers on both international levels attempt to thwart our right to privacy. Does anyone know what we or I can do (in this case specifically) to help fight this idiocy?

Yeah: run for office, win, and then effect policy change. But almost no one's willing to actually do that. They just want easy outs like "contacting your MP" or "donating to an org that says they'll try to fix it".

The most successful British politician in the last 100 years never got elected - he was defeated 7 times, once by a dolphin.

On a more recent example a footballer has managed to affect meaningful change and government u turns time and time again.

Charisma and making the population care about your cause is how you do it.

Re: EU Draft Council Declaration Against Encryption [pdf]

#303
The current HN link points to a page written in what looks like the German language to me. I do not understand German. The German language could be and has historically been used to spread hatred resulting in the deaths of millions of people. It is clearly risky to allow people to run around using languages I don't understand. Especially scary languages like German. And that includes Dutch.

Please ban all speech that is not understandable by me. If you are that concerned about privacy, you can use Pig Latin.

Re: EU Draft Council Declaration Against Encryption [pdf]

#304
post #239
post #131

My serious question is this: how do we stop terrorism and criminals when they have access to military grade encryption technology? It seems like there is a lot of ideological push for freedom, but as criminal activity moves to the virtual world, have we not created a problem for ourselves?

> My serious question is this: how do we stop terrorism and criminals when they have access to military grade encryption technology? You don't and technology has nothing to with it either. Terrorism is as old as government itself and doesn't need the internet in order to function. Radicalisation takes place in many places and law enforcement as well as national intelligence agencies have put their focus away from goo…

I think you missed the part where law enforcement has problems putting criminals behind bars because there is too little evidence. This happens all the time.

Re: EU Draft Council Declaration Against Encryption [pdf]

#305

Earlier quoted context omitted.

It pretty much is, section 12 of the Universal Declaration of Human Rights states: > No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks. I mean wearing my programmer goggles it doesn't state privacy AND correspondence but OR, but sti…

It continues " There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law" [to ensure everyone's safety]. E2e encryption that is "safe from courts" isn't protected.

that's the short story.

The long story is that encrypted files alone are no use to anyone, so the courts have no more right to it than anyone else. The decrypted text is a different matter. It's supposed to be protected. So you are saying, eventually, if I may interpret it that way, that speech which is protected from the authorities including the courts is not in fact protected from the courts.

Oh, ok, that's not even illogic, just paradox.

Problematicly, if you consider the abstract danger of a key cypher pair a threat, the same goes for the legislatator court partnership. The courts aren't a threat as long as there's no legislation that opens them up to it. So, clearly, the legislation is key to the infringement. This means that legislation has to act in accordance with legislation, which is as difficult to understand for regular joe as function pointer semantics in C++. So it appears to say, simply, that legislation has to act...

That's you and me. Actually though, the law is accordingly a huge tower of abstraction. The moment you try to dereference "the law" it blows up into your face, a group of skilled experts has to drop into debugging mode and, eventually, has to decide if they want to have their access limited even in debugging mode. Well, the system was designed for the hypervisor kernel to access all areas, this seems to be a problem of the virtual OS handling the capabilities for userspace incorrectly.

Bug closed: won't fix.

Re: EU Draft Council Declaration Against Encryption [pdf]

#306
post #184

Earlier quoted context omitted.

When they have a court warrant, it's not arbitrary. I think some rights were given to the people to combat government tyranny (right to bear arms for example), but combating government tyranny is just not feasible anymore, due to a set of factors, like our inability to organize behind a common cause. Anyway, the choice here is reserving our ability to overthrow an unjust system, or giving the government the rights to…

>giving the government the rights to catch those who might want to unjustly overthrow it. So how decides when an attempt is just? Did the British think the American revolutionaries were just in declaring independence?

It is might makes right essentially - if treason doth prospor none dare call it treason. If there is absolutely no hope of any effort to revert it succeeding it is just.

Re: EU Draft Council Declaration Against Encryption [pdf]

#307
post #267

I see this as follows: 1. Terrorism and trafficking of children will win the moral high ground. 2. App stores will be forced locale by locale to conform to these policies. 3. Most people will not notice or care. 4. This will be used by N-Eyes and totalitarian governments to quash dissent. 5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely. 6.…

It's the infinite horse race. Black hats vs white hats. Neither holds the upper hand for long. I hope that if we ever reach a steady state, it will be unbreakable privacy.

Entropy always wins in the end.

Re: EU Draft Council Declaration Against Encryption [pdf]

#308

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

Thanks for Matrix. This proposal seems to address general abuse, spam, propaganda, filter bubbles, and so on. While these are worthy issues to tackle, the authors of the 7-eyes statement are not really interested in them. What they say they want is for terrorism and child pornography to be detectable or meaningfully reduced. Do you think a relative reputation system will solve that problem?

Yes, we think it will help meaningfully help detect and reduce abuse - mainly because it's shamelessly mimicking the way society works in real life. Many (most?) abusive communities are at least adjacent if not overlapping with publicly visible communities. Simply put, they need a way to advertise and recruit.

So, just as in person you might stay away from a given political party / religious institute / youth club because your social graph has warned you that it might actually be a front for whatever obnoxiousness, the same approach can work online (or, conversely, could also be used to help hunt down abuse in the first place). It's then up to the authorities to investigate what's going on - which is quite possible through infiltration etc without having to go and blanket break encryption for the whole of society.

To be clear: this is still largely sci-fi, and we don't think this is a perfect solution, especially given this is a fundamental problem of the human species which nobody has yet solved. Our proposal doesn't solve lone wolf situations, for instance. So perhaps for that you need the ability to gather evidence from endpoints post hoc.

Unrelated: one particularly dark dystopian outcome we've been wargaming is: what if someone (not us!) used decentralised rep to seed a GPT-3 style bot to locate abusive communities, and then automated the process of infiltrating & investigating them... only to then end up ascending the ranks while preserving its cover and accidentally triggered some atrocity. So, um, let's not do that.)

Re: EU Draft Council Declaration Against Encryption [pdf]

#309

Earlier quoted context omitted.

Yes. So for a static location that's feasible. But the status quo is they can also tap old school mobile voice calls and text messages.

Which they can do, too. Just break into an Android phone (easy enough to do remotely). Bug home, bug the car, bug shoes, now you have phone calls from an iPhone. (You can pick up electrical interference from phone calls on an iPhone, due to the hearing aid induction loop.) For every phone, you can just slip an antenna under the case (or in the phone's body) and pick up the LCD switching interference – faint though it…

I don't see any good middle ground between "authorities can never eavesdrop on inviduals' comms even with a warrant" and "authorities can do mass surveillance". It's a very difficult dilemma. I (as you do) prefer the former if I have to choose. I understand why it's not a very wasy pill to swallow though. Hopefully techniques for targeted eavesdropping (like those you mention) will improve as e2e gets more widespread. The easy of eavesdropping on mobile comms has probably been too comfortable for too long.

Re: EU Draft Council Declaration Against Encryption [pdf]

#310
2 things:

1. creating a backdoor defeats the purpose of having encryption in the first place. it makes the creation of encryption irrelevant and pointless. a chicken and egg scenario. so it's an all or nothing kind of argument.

2. don't quantum computers make all encryption obsolete anyways? and with quantum encryption, whether or not your data gets compromised, it tells you that someone tried to, or got access to, your encrypted data.

it seems like the government already has a backdoor for all encryptions since they already have a quantum computer. so i think that this whole argument is more about setting the precedent of control over a population. gaining consensus and solidifying power. something you do when you're trying to increase your influence [which someone says the gov is always trying to do]. applying the use of force to encryption.

i think the thing for humanity to realize is that absolutes exist only in oblivion

Post reply on HN