Live data from Hacker News

UK Home Secretary says encryption on messaging services is unacceptable

reuters.com

341–350 of 394 posts

Re: UK Home Secretary says encryption on messaging services is unacceptable

#341
post #168

Earlier quoted context omitted.

One word, my friend: VPN.

> One word, my friend: VPN. A VPN is a way to circumvent surveillance but make no mistake: We must press with all our power for legislation which guarantees privacy, all over the world. This is a battle that in the long run, we can't win with tech. We need to become more privacy-aware. "Those who surrender freedom for security will not have, nor do they deserve, either one."

+1. I agree with this.

With the current trend, how long until VPNs are made illegal? "For the children!"

Re: UK Home Secretary says encryption on messaging services is unacceptable

#342

Earlier quoted context omitted.

I believe they do it because they've been elected to do so. It takes too much to reply: "Tell you what, I'm going to educate you better instead". Because you can educate all you want, you will not have results that helps your re-election 4-5 years down the road.

No properly-informed voter would want this kind of legislation.

"No true Scotsman..."

I have a feeling that some top level FBI people are properly informed, but still want this kind of legislation.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#343
post #222
post #207

Earlier quoted context omitted.

Why do you think the government doesn't know? Why do you think they believe what they say? This is just populist bullshit. It follows on from other populist bullshit.

I think they don't know because I've never seen any of them describe encryption in a way that would suggest they know what they are talking about. I don't doubt that someone in government knows. Probably an entry level staffer. But whenever technology comes up (such as blocking types of content from the internet) the policy is always utterly ham fisted.

I agree that the policies are always ham fisted, but I'm not sure how you could have a policy that achieves the goal of blocking specific "bad sites" without it being ham fisted.

How would you achieve the goal of coming up with a non-ham fisted technical solution to a ham fisted problem?

Re: UK Home Secretary says encryption on messaging services is unacceptable

#344
post #166

Earlier quoted context omitted.

The same way you prevent anything.. they make it illegal for people in the UK to make, or use, such products. Don't think we can "tech" our way out of this.

Exactly, and given we live in a "walled garden" society now, all they need to do is require google or apple to remove from the app stores any app that implements encryption for messaging. It's actually easier than ever to ban encryption for messaging. Would that stop determined people? No, but it's never been about that anyway. Just make the pool small enough and it becomes too difficult to use. (See PGP / email). Al…

> we should have people challenge the notion that two people should never be allowed to share a private message, because that's why Rudd and the government is suggesting.

+1. This is the crux of the matter, although unfortunately I don't think the average person realises it.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#345
post #57
post #34

Earlier quoted context omitted.

How do they want to prevent someone from creating his own end-to-end encryption app? That's not an issue. Writing solid encryption software is very difficult on its own. You will hear "do not roll your own crypto" all the time from security experts. We don't live in a James Bond universe and it's beyond the reach of terrorist organisations.

You don't have to roll your own crypto to create an own end-to-end encryption app. You can use existing crypto. Writing a user interface around it is not so difficult. Beyound the reach of the terrorist organisations? We have already seen pretty sophisticated operations by relatively small crime organizations (like exploiting pseudorandom generators in casino slot machines). There's an established black market for ex…

> like exploiting pseudorandom generators in casino slot machines

Anyone have a link about this story? I'm curious to read about it.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#346
post #255
post #34

Earlier quoted context omitted.

How do they want to prevent someone from creating his own end-to-end encryption app? That's not an issue. Writing solid encryption software is very difficult on its own. You will hear "do not roll your own crypto" all the time from security experts. We don't live in a James Bond universe and it's beyond the reach of terrorist organisations.

You vastly overestimate the difficulty. The reason we're commonly told not to roll our own crypto is because it's easy , and also easy to get wrong and possibly catastrophic if you do. But many perfectly serviceable algorithms are simple and public knowledge. Arguably a scenario where everyone's using their own crypto and half of it's broken is still better than everyone using the "industry standard, pre-backdoored f…

This.

If we outlaw encryption, then only outlaws will have encryption.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#347

The British gov is looking more and more like the Finger from V for Vendetta. The US president more and more like the one from Idiocracy. That we tend to live up to caricatures should be an alarming sign, but I only see worries on sites like HN. Most people still don't see the catastrophy in it.

> I only see worries on sites like HN. Most people still don't see the catastrophy in it.

I'm not in the US. I have actually been very impressed by the outspoken actions of anti-Trump people in the US, with the massive protests and constant (well-deserved) media scrutiny. Also I never knew I could have so much respect for Hawaiian judges.

Why they didn't bother to vote is beyond me, though. Trump is a buffoon, but he was able to successfully motivate other buffoons to actually vote.

I did hear the description of their vote as being force to choose "between a disaster and a catastrophe" though, so that might go some way to explaining it.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#348
post #320
post #283

Earlier quoted context omitted.

>I actually didn't suggest a complete solution. Nobody is saying you did. You yourself said "that is a perfect solution actually" in response to vinceyuan, who had a one-liner comment about "the source code of the monitoring software must be reviewed by independent and trusted software engineers/experts." Maybe we are interpreting this in different ways. How do you envision this "solution" working? It is a bit vaguel…

> That means there are still problems for you and me to solve. This was my last sentence. With which I tried to say that we have to still solve the problem and come up with the solution. My comment "that's a perfect solution" was about the answer "software that can effectively monitor communications with proper privacy" to the question about properly reconciling privacy and security, in a situation where the people a…

We live in a world, not a democracy. There are many different countries, with many different systems.

Any proposed solution has to deal with that reality, not with the little bubble of one democracy which may arguably in the questionable opinions of some subset of people have a good government.

The reality includes police states where the police are truly evil.

It also includes police states where the software is written by truly evil people, to do evil things, with evil experts overseeing it all and approving evil behavior in the software they are checking.

Please tell me how you can be confident that there can be a solution that addresses this reality while protecting the privacy of users. Sometimes all the user wants to do is send a message to their boyfriend, without getting thrown off a building, burned, flogged, or killed, possibly having several generations of your family killed as well (see North Korea).

The system has to work for this reality. I'm pretty sure that simply drawing a line and fully protecting the privacy of users' messages, full stop, is a better solution than whatever you and your senators will come up with.

And yes, the security of a crypto system can be verified. If it's designed to be secure. Not if it's designed to be monitored. Even if the experts are perfect angels and absolutely competent, if there is a way to monitor, hackers will find a way to get access to it.

>When it comes to properly securing the physical part (the servers), I'm sure something can be figured out there.

You're dreaming. Remember, the authorities will have full power over that system, and even in countries where the authorities are not evil, the authorities as a rule are inevitably corruptible if not corrupt. This isn't just cynicism, it's reality. Look around.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#349
post #113

Earlier quoted context omitted.

So, no matter how bad the government, and how ridiculous its laws (let's say they ban music, and dole out harsh punishments to people who dare listen to music), then we as technology providers should enable them to catch such people and punish them for their "crimes"? Saudi Arabia punishes rape victims. We should help with that? China punishes people who try to air grievances about government abuse and corruption. Ag…

I can ask the same. Why should a suspected rapist, assassin, drug dealer, corrupt politician, be free or unjustly imprisoned, because of lack of evidence? Do you think we should help criminals? Nowadays here are other more efective ways, than encrypted WhatsApp (secrecy), to fight bad governments and ridiculous laws. North Korea and Saudi Arabia are obviously very extreme examples. Internet encryption must be the lea…

>Why should a suspected rapist, assassin, drug dealer, corrupt politician, be free or unjustly imprisoned, because of lack of evidence?

"suspected"

That includes you, so... be careful.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#350
post #78

If I may ask a very naive question: Do politicians like her really think encryption is dangerous or is it a devious way to expand mass surveillance? Attacks of the past have shown that terrorists don't have a need to resort to encryption. The people involved in the Berlin attack last year, for instance, were monitored. Authorities knew they would strike but they didn't have sufficient incriminating evidence that woul…

> really think encryption is dangerous or is it a devious way to expand mass surveillance The latter her and the precious home secretary (now PM) have been banging on about how under threat we are from the terrorist hoards for years now - all so they can erode freedoms and increase mass surveillance under the guise of 'keeping Britain safe'. The idea that banning encryption of private conversations will prevent these…

It's an interesting question though, isn't it.

They must know enough to know that this won't actually fix the problem, so I would have to surmise that they are just trying to do something and stay somehow relevant before their term comes to an end.

"Never mind the collateral damage, I'll be retired on a government pension by then."

Post reply on HN