Live data from Hacker News

Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

signal.org

301–310 of 357 posts

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#301
I also can't stand the privacy violation of CSS. But

> Child safety looks like well-funded education, robust social services, and meaningful guardrails on the very AI technologies and platforms the current government is eagerly courting.

is such a weak, unrealistic, slow and idealistic solution to the real suffering of children. I was hoping this thread might offer up some better alternatives.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#302

This is really disingenuous coming from Signal who pioneered secure compute architecture for a number of useful features [1][2]. On-device checks are no more "surveillance" than Signal's private contact discovery is, and the same slippery slope argument applies there. It's also technically incoherent: the exact same kind of "surveillance" is already applied by every single phone, because that's how the Photos app (or…

> It's also technically incoherent: the exact same kind of "surveillance" is already applied by every single phone, because that's how the Photos app (or whatever it's called on Android) searches for cat pictures based on the text "cat". I can't recall any Signal statements about cat recognition technology leading to "reporting people to government authorities".

Are you suggesting that the automatic scanning of photos on a phone (which has led to wrongful arrests[1]) is not surveillance?

[1]: https://www.eff.org/deeplinks/2022/08/googles-scans-private-...

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#303
From https://www.gov.uk/government/news/new-plans-to-stop-childre...:

> Despite [iphone age verification] children can still take, view, share and save nude images. The government therefore wants Apple and Google to block nudity across the whole device by default, so they can only be deactivated via age assurance.

We tolerate the systematic child rape and run cover for the perps, but teens sending n00dz is a bridge too far. It's time for the UK to nut up and start holding these kids accountable. This works well, too, because it's deactivated on the devices used by adults, so they can continue to view their child porn, I guess.

Is there another reading of this?

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#304

Earlier quoted context omitted.

It's an opt-in feature. https://techcrunch.com/2025/09/08/signal-introduces-free-and... A service that advertises itself as privacy focused refusing to update their privacy policy while adding features like this seems like a pretty big dead canary.

Did we read the same article? You're complaining about an optional back-up service . No data is being "collected," you're giving it to them (in an encrypted form) to store on your behalf. How else would a backup service work? If you don't want to use the cloud version, there's a feature to store backups locally on-device. Signal blog: https://signal.org/blog/introducing-secure-backups/ HN: https://news.ycombinator.co…

> You're complaining about an optional back-up service. No data is being "collected,"

Every app offering cloud-based backup is in fact designed to "collect and store" sensitive data. That at least is opt in. The app also collects your name, photo, phone number and worst of all a list of your contacts and permanently keeps that in the cloud and there is zero way to opt out of that data collection. No matter what excuses you want to make for them there is no getting around the fact that the device does collect and store sensitive data. Just like it can't be denied that they've added several new features none of which is reflected in their privacy policy because they've frozen it in time.

This is an app which is advertised to whistleblowers, activists, and others whose lives/freedom could depend on how well they understand the risks involved yet Signal outright lies to them about those same risks.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#305

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

The people in the industry that I know were/are trying to stop fraudsters, script kiddies, nasty people, and governments from trying to exploit weaknesses and take unauthorised control of devices and services. The problem with that is it generally requires a central point of trust. Sure you can allow multiple points of trust, but for the unskilled user, that means that the little lock symbol becomes unreliable (or wh…

> were/are trying to stop fraudsters, script kiddies, nasty people, and governments from trying to exploit weaknesses and take unauthorised control of devices and services.

While I don't doubt that's a motivation, the problem I have is it's really a question of likelihood. I feel that in terms of security focus it's very common for people to put on blinders and ignore the likelihood of an exploit in favor of "Ooooh look at this thing that COULD be exploited!"

It's fundamentally the problem I have with how CVEs are reported and handled in general.

In terms of secure boot stopping problems. Yes, it does stop someone from rooting a device which is great. However, someone that has access to root a device almost certainly also has the ability to just install a virus in the OS startup scripts. Or to modify a user executable. Or to modify the user's PATH environment variable to inject a malicious app in front of a commonly used one.

That's what I wish security focused people would weigh more heavily when they evaluate these sorts of threats. "What other damage could a malicious individual do if they had the same permissions to pull off this exploit."

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#306
post #290

Earlier quoted context omitted.

There is (seriously) agitation in the UK to ban pointy kitchen knives ... first hit on DDG for example https://theconversation.com/why-stopping-knife-crime-needs-t...

To be fair, pointy knives are unnecessary. At least I haven't found a use for them, though I stab myself with them occasionally when unloading the dishwasher. Some people will tell you that they need a pointy knife for cutting tomatoes but they should try using a serrated knife instead: it's much better.

Getting the eyes out of potatoes, working with tough meat like beef or goat, ... knives are the most popular weapon, but that just because we're not allowed guns. If you take the point from knives then we can attack with the sharp side to the throat fairly effectively. Mandate blunt knives and we'll have to beat people around the head with bricks. Ban bricks and we'll ... and so on.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#307

I sometimes wonder whether the people in the tech industry who worked on things like secure boot, attestation, and DRM saw this as the inevitability open source advocates always saw it as. Did they think, as they worked to transfer final say from users to corporations, by technical means, that politicians couldn't transfer that control to themselves by political means? Did they think they could lock things down to ex…

There were many reasons to deploy these solutions. Much of it from the perennial reason “we can’t have nice things”. Che was a murderous psychopath so I’m not sure what he was to do with freedom other than some college kids though he was edgy in the same way Manson’s followed though he was edgy.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#308

Earlier quoted context omitted.

I, for one, totally believe the government will prevent the government from abusing the government's power. /s

This was so profound. Now that I think of it there is nobody to watch the watcher and we should just dismantle society and let the local warlords sort out the crime rate. /s

Common sense is not profound. What you suggested is a bit too much, but some accountability and reciprocity would be a good start.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#309

Earlier quoted context omitted.

zero knowledge proofs exist, don't they? also it matters "private from whom, and what". You can make what sites you visit private from the government, and your identity a secret from the site, but the inverse isn't true, the government would know the identity, and the site would obviously know someone visited it. The problem with this whole thing is the expectation of privacy online for interactions where their IRL e…

Zero knowledge proofs exist in theory, but none of these age verification laws that are introduced use them, probably on purpose. I'm certain that every government will want to know what sites everyone visits.

but why does it have to be that way. why not have zkp age verification processes anyways, inconvenience aside, what's the harm. If they refuse to let us use them, they need to explain why. I don't disagree with the malicious intent you're talking about but we can have it so that they have no legitimate excuse to require collection of site visit data. all the emotion and fervor aside, why can't we talk about having this as a standardized process that excludes third parties.

Governments are banking on being able to purchase that site visit data anyways, bypassing their own laws that prohibit them to do surveil, we can require them by means of technology to comply with laws and for the last time resolve the "but the children" argument.

Re: Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]

#310
post #295

Earlier quoted context omitted.

> What is it a tool for, A nuclear weapon is a tool. You can use it to blast a city-killing asteroid, one you just noticed, into pieces that'd burn in the atmosphere (and miss the city). You can also use it to mass murder an entire population. > it is a tool for observing while no person is present therefore breaking privacy. The capacity exists, but it's not necessarily used all the time. We should create the legal…

> The capacity exists, but it's not necessarily used all the time. By choosing not to engage with a tool you are deciding that the tool serves you and your goals (perception of good) best by not being used. You can make it illegal to use the tool but as long as the tool exists it does not mean it won't be used. Think of the millions devices part of a botnet or web accessible camera's that are being used illegally by…

This tool is already built. This is why the focus should be on legal frameworks that help us prevent misuse and punish abuses in a way rigorous enough to prevent it.

Not all misuse will be prevented, but we need to build the tools (which aren’t more technology) to prevent the abuse.

Post reply on HN