Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

331–340 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#331
post #287

Earlier quoted context omitted.

Maybe generalize that further, a right to privacy.

Perhaps, but see Article 8 which is cited in your sibling comment. It already contains a right to privacy. But the term privacy is not very rigid. It can be taken and interpreted in various ways. It's certainly a good thing to mention it, but encryption needs to be mentioned explicitly, spelled out even. There cannot be any room for interpretation: citizens have a right to encrypt their communication, end-to-end with…

That still leaves too much room for interpretation (namely, quibbling over the definitions of "encrypt" or "end-to-end").

People have a right to encrypt their communication, end-to-end with their intended participants, such that no one other than their intended participants can decrypt any aspect of their communication.

Re: EU Draft Council Declaration Against Encryption [pdf]

#332

Earlier quoted context omitted.

Switzerland is not part of the european union but has to follow some rules to have access to their market. If Whatsapp breaks E2E it will possibly affect multiple countries.

If WhatsApp breaks E2E in Europe every other country will jump on the bandwagon.

WhatsApp is hardly safe from prying eyes anyway.

Sure, there's always-on E2E encryption that is really well designed. However, WhatsApp constantly prompts every user to back up to the cloud, which is much less well secured.

Thus, it's pretty trivial for the authorities to get to it there, I'm sure they can get into iCloud and Google Drive if they want to. It only takes one person in the conversation to have this option switched on. I think this is why WhatsApp doesn't get so much flak from the authorities for having good E2E encryption.

Re: EU Draft Council Declaration Against Encryption [pdf]

#333
post #53

Earlier quoted context omitted.

A friend of mine here in Berlin is from Hong Kong. Thanks to the Pro-Democracy protests in Hong Kong, the general nature of which my friend confirmed, I know about how to use traffic cones to defend against tear gas. I’ve personally witnessed “we don’t like how Corona is being handled” marches here in Berlin. The difference is massive.

That’s a great point, thankfully Europe is more humane than China in dealing with riots. The concern for how Corona is handled in Europe, is that the temporary measures for dealing with Corona become permanent. In Denmark these temporary measures are supposed to expire in March 2021, but it’s anyone’s guess if that arrangement is honored by the government.

Oh yeah, the yellow vests that lost their fingers and eyes find the police very humane indeed! /s

Re: EU Draft Council Declaration Against Encryption [pdf]

#334
post #151

Earlier quoted context omitted.

Yes. 1. Encrypt as normal. 2. Given a language model which can generate a choice of multiple possible next-symbols given what has already been written, use bytes from the cypher text to choose between the available options. For example, using the predictive text options on my iPhone, and treating 0=left 1=right, the cypher text 011100 and the starting symbol “Hi”, I get: “Hi I have heard from the other” (Note: I’m fa…

This is the correct answer, although it's worth thinking about what the threat model is. If the government is just going to force specific companies to add backdoors, then the process above isn't really necessary, you just need a way to install a client that isn't backdoored. If, however, the government is banning the sending of encrypted messages, then you have to hope that a jury doesn't see your long pointless mes…

> then you have to hope that a jury doesn't see your long pointless messages as strong evidence of using encryption

Don't legal people routinely just take few word sentences and rewrite them into long paragraphs of aforementioned hereinafter notwithstanding including but not limited to senseless nonsense?

Re: EU Draft Council Declaration Against Encryption [pdf]

#335
post #265
post #237

Earlier quoted context omitted.

You could permit only weak encryption, this would allow E2E, but still be wiretapped (although with difficultly). This also gets rid of the need for master keys or key escrow. (Don't shoot the messenger, this is a technical theoretical idea, not a policy suggestion.)

So only use encryption that can be decrypted by anybody who really wants to? That sounds useful.

If you make it cost $30,000 worth of computer time to decrypt, the vast majority of people would have privacy, yet the government could afford to tap important targets (and it would also block government fishing expeditions - they would be too expensive).

Re: EU Draft Council Declaration Against Encryption [pdf]

#337
post #284

Earlier quoted context omitted.

By this logic home ownership is an offensive technology because it allows you to safely coordinate an attack.

And indeed it would be. Conversely, if you only used a gun to defend your self it would be a defensive technology. Seems like classifying technology as either offensive or defensive is a fool's errand. Perhaps you should try a different argument.

One could maybe play silly rhetorical games like "It wasn't the gun that killed him, it was the bullet", but to say "It wasn't the gun that killed him, it was the house that the killer lived in while she thought about committing the crime" is beyond ridiculous.

I feel quite comfortable classifying encrypted messaging apps in the same category as houses and chain mail, even if the US government has historically disagreed.

Re: EU Draft Council Declaration Against Encryption [pdf]

#338
post #322

I see this as follows: 1. Terrorism and trafficking of children will win the moral high ground. 2. App stores will be forced locale by locale to conform to these policies. 3. Most people will not notice or care. 4. This will be used by N-Eyes and totalitarian governments to quash dissent. 5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely. 6.…

It all comes down to distribution. We need actual software like https://Matrix.org or https://qbix.com/platform to be good enough that people will install it. Like the Web Browser did killed AOL and MSN. Otherwise we will live with Facebook Google etc. and this is moot. But that is just the beginning. Secondly, we need open source hardware. We are nowhere close to competing with Apple and Android. But as we have seen…

>Just today I read that Android doesn’t let you take a screenshot of your own phone.

Not many seemed to care to click the link in that thread. If one did one would know that it was to a bug report and a fix was even posted in the same link. Screenshots work just fine.

Re: EU Draft Council Declaration Against Encryption [pdf]

#339

This makes me sad and somewhat angry. How does mass spying help in cases like the Vienna attack? If the authorities had done their work as I would expect as citizen and tax payer (the government already admitted massive failures, basically they clearly failed to act on existing intelligence) this would not have happened. I also think this could spawn lots of Signal-like, self hostable chat-server solutions that will…

We already have those, see Matrix statement in this thread for instance.

Re: EU Draft Council Declaration Against Encryption [pdf]

#340
post #323

Earlier quoted context omitted.

The German article is more on point and it goes into more details about the background and also the probable solution with "Exceptional Access" architecture. The official EU draft documents always use a very careful language to not create too much suspicion. Only one or two sentences actually tell the truth: "Possible solutions may need the support of service providers in a transparent and lawful manner, as well as i…

I'm certainly open to changing the URL from what is probably an obscurantist press release to a more accurate and neutral source. But it would need to be in English. Sorry—I realize that's frustrating to anyone who reads both languages, but most HN readers can't. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

You're conflating the language issue with the alleged "obscurantist" issue. In your opinion, since you brought it up, what facts are the original link lying about or hiding?
Post reply on HN