Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

321–330 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#322

I see this as follows: 1. Terrorism and trafficking of children will win the moral high ground. 2. App stores will be forced locale by locale to conform to these policies. 3. Most people will not notice or care. 4. This will be used by N-Eyes and totalitarian governments to quash dissent. 5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely. 6.…

It all comes down to distribution.

We need actual software like https://Matrix.org or https://qbix.com/platform to be good enough that people will install it. Like the Web Browser did killed AOL and MSN. Otherwise we will live with Facebook Google etc. and this is moot. But that is just the beginning.

Secondly, we need open source hardware. We are nowhere close to competing with Apple and Android. But as we have seen over the last 20 years - there is a war on general purpose computing and the closed systems have started to win. Just today I read that Android doesn’t let you take a screenshot of your own phone.

Third of all - the open distribution mechanisms you rely on today to not block you (eg web browsers) can be closed or ship updates with backdoors tomorrow to most users. Apple and Google together control most of the market. It isn’t hard to pressure them to do this.

Apple blocked blockchain dapps being distributed on iOS, unless they are made by an Apple developer whose app they can revoke. Amazon can yank your movies and books out of your hands.

Anything you think is secure (eg secure enclave) may not be. Trusted Computing Environments are made by two companies essentially.

In fact, I am surprised that more “stuxnet” attacks arent done in nuclear reactors across various countries. As self driving cars get hooked up to the net or delivery drones become ubiquitous we may see massive vulnerabilities that can be exploited all at once. Not just by state actors but anyone. Really scary stuff.

Sadly the same entities locking down the computing devices also start requiring uplinks to their servers and can push any updates. Regular people are at the mercy of corporations and the state.

Unless open source companies step up and build a decentralized hardware distribution infrastructure, with multiple actors (like VOIP relaced centralized telephone switchboard operators) all these arguments are moot. There is a handful of tech companies whose arms need to be twisted and that’s all.

PART II:

To be honest ... I no longer think that end-to-end encryption is the right solution to human rights problems. If citizens are reduced to sneaking around and denying their activities to survive, their governmental system is way past due for fixing. This is like the “good slave owners” delaying the abolition of slavery. You’re solving the wrong problem.

I believe that crypto is needed to secure decentralized byzantine fault tolerant systems like Ethereum etc. to be TRUSTED, not to hide information. Signatures, not encryption, if you will. If anything, it is the government who doesn’t want encryption to be broken (eg of copyrighted DVD content etc.) and there is an inherent contradiction since anyone who consumes unencrypted content can reshare it.

What we really need is to decentralize the personal data in many places, and use zero-knowledge proofs for attestation, but that is different than encrypting and hiding information.

Re: EU Draft Council Declaration Against Encryption [pdf]

#323
post #293

Earlier quoted context omitted.

Thanks—we've changed the URL from https://fm4.orf.at/stories/3008930/ . Submissions to HN need to be in English—we have great respect for other languages, including German, but HN is an English language site. Happily in this case, following the site guideline that calls for original sources solves this problem as well. (I've taken the title from the new URL, btw, which uses the rather strong preposition "against"—I s…

The German article is more on point and it goes into more details about the background and also the probable solution with "Exceptional Access" architecture. The official EU draft documents always use a very careful language to not create too much suspicion. Only one or two sentences actually tell the truth: "Possible solutions may need the support of service providers in a transparent and lawful manner, as well as i…

I'm certainly open to changing the URL from what is probably an obscurantist press release to a more accurate and neutral source. But it would need to be in English. Sorry—I realize that's frustrating to anyone who reads both languages, but most HN readers can't.

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

Re: EU Draft Council Declaration Against Encryption [pdf]

#324
post #236

This is madness. Oh, of course, it's much easier to put a wrench into some gears to show that you are actually working at "solving the terrorism problem" than shaving the yaks, but that machine is actually important for other things. We live in a dangerous world. We cannot control everything. I don't mind a slight risk of terrorist attack on myself or my family (caveat lector: I am young), if that means greater freed…

>We live in a dangerous world. No we don't, but that's what the Politicians try to implement in our brains.

You are wrong. We live in such a dangerous world that the biggest reason for cause of death in many developed countries is suicide, obesity, diseases, etc.

Re: EU Draft Council Declaration Against Encryption [pdf]

#325

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

Matrix is awesome. Also, doesn’t the French government use Matrix? Are they trying to outlaw their own policies?

No it simply means two leagues, just like before. Politicians have tools that are not accessible to the citizen. Nothing new in a way :)

Re: EU Draft Council Declaration Against Encryption [pdf]

#326
So, basically they want a backdoor but want strong encryption as well. In this case you can't have your cake and eat it.

And really how are they going to make this happen? I'm sure Whatsapp, Telegram etc will cave in. But there will always remain open-source solutions. Encryption is not a secret.

Re: EU Draft Council Declaration Against Encryption [pdf]

#327
post #287

Earlier quoted context omitted.

What about proposing encryption as an EU human right? Has that been attempted?

Maybe generalize that further, a right to privacy.

We already have a right for privacy in the EU. That's why the EU court has declared mass logging of meta data by ISPs and mobileproviders illegal.

Re: EU Draft Council Declaration Against Encryption [pdf]

#328

Earlier quoted context omitted.

That is not encrypted then.

Should we say that no building is really locked, since the fire department is alway able to force entry?

Scale and viability. Your fire department can't break force entry without notifying others in the area or do it to every building in the city.

Now digitally, that's not true. You can keep collecting data without anyone knowing at an unprecedented scale.

Re: EU Draft Council Declaration Against Encryption [pdf]

#329

Earlier quoted context omitted.

I don't think he's talking about the guy who mugs him. More like about the guy who mows down a crowd with an automatic weapon, the guy who drives a truck through the center of a Christmas market or the guy who blows up a metro station. That kind of people.

The guy who does that stuff is going to keep using encryption. Or maybe he won’t bother and he’ll keep using SMS or some other channel that intelligence agencies are too busy to monitor. Mass communications surveillance against operations like this is a fool’s errand.

>The guy who does that stuff is going to keep using encryption.

Then we can charge him regardless of the contents of his messages.

Re: EU Draft Council Declaration Against Encryption [pdf]

#330

Earlier quoted context omitted.

It isn't "safe from courts" because courts can allow them to bug your house and hack your phone using the unlock code their bug recorded you entering. They can't do that to the entire public at once because it's not economical, but that's the point .

Not sure I follow. The struggle politicians are in isn't to eavesdrop on everyone. The fact that this is possible is an unwelcome side effect. The struggle is to not lose the same ability (targeted eavesdropping after court orders) when people switch to e2e from phone calls. If cell phones had e2e encryptoions so the normal court-order landline eavesdropping disappeared from law enforcements' toolboxes - there is zer…

“The struggle politicians are in isn't to eavesdrop on everyone.”

Counterpoint: yes it is.

Post reply on HN