Live data from Hacker News

UK Home Secretary says encryption on messaging services is unacceptable

reuters.com

351–360 of 394 posts

Re: UK Home Secretary says encryption on messaging services is unacceptable

#351
post #113

Earlier quoted context omitted.

So, no matter how bad the government, and how ridiculous its laws (let's say they ban music, and dole out harsh punishments to people who dare listen to music), then we as technology providers should enable them to catch such people and punish them for their "crimes"? Saudi Arabia punishes rape victims. We should help with that? China punishes people who try to air grievances about government abuse and corruption. Ag…

I can ask the same. Why should a suspected rapist, assassin, drug dealer, corrupt politician, be free or unjustly imprisoned, because of lack of evidence? Do you think we should help criminals? Nowadays here are other more efective ways, than encrypted WhatsApp (secrecy), to fight bad governments and ridiculous laws. North Korea and Saudi Arabia are obviously very extreme examples. Internet encryption must be the lea…

I like how you leap from "suspected" to "Do you think we should help criminals?"

North Korea and Saudi Arabia and China and the UK would claim that their justice systems are working just fine.

As would my local sheriff jurisdiction where they can't even manage to hire anybody who bothers to do so much as use turn signals. If they can't even manage to do that tiny thing, greatest country on earth or no, I don't trust them with the temptations of the kind of power you're talking about.

>If you think you country justice system is not working properly there are ways to fight that.

LOL! Good luck! Strictly speaking, you are correct that "there are ways to fight that" but the consequences are brutal! It's a pretty big ask for most people. And that possibility will be eroded and, more likely, wholly negated by such systems.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#352

We hear most terrorists ate with forks so all forks are now banned. Also, we were shocked to discover that virtually ALL criminals rely on something called Oxygen to perform their work so this is now a controlled substance that will be heavily regulated. We were then terrified to learn that after banning forks, terrorists were able to successfully eat with spoons or even their hands. /s Seriously, you cannot ban tool…

More to the point, terrorists lock their doors! We need to ban deadbolts!

Seriously though. Next step would be to force people to install locks that have a master key that only intelligence services have and can only use for good reasons.

If you're ok with encryption back doors you should also be ok with govt master keys for all your stuff (house, car, bank account, etc)

Re: UK Home Secretary says encryption on messaging services is unacceptable

#353
post #328
post #263

Earlier quoted context omitted.

Every time a person in a position of power calls for the intentional weakening of cryptographic systems - be it via backdoors, limits on key length or whatever, I long for a gutsy interviewer to ask them - preferably live - whether they advocate that position out of ignorance or malice. There really aren't many other alternatives.

More likely they would say they want to do it because it would be "helping the police and security services to do their job" and be "protecting the people".

For sure, but wouldn't it be nice if the interviewer at least challenged the assumption that such measures do protect people overall? Leaving aside the question of whether there would be any benefit in the case of attacks like the one we saw last week, which is debatable in itself, there's also the question of whether the reduced security would do more harm than good.

The interviewer could explore the impact of online fraud or identity theft or cyber-bullying, and look at how fast these problems have been growing in recent years. Then challenge the advocate of weakened encryption or mass surveillance over why they want to require security vulnerabilities or create huge databases that will make great targets for criminals. If they claim everything would be securely held and strictly for police use or similar, go with Snowden and Wikileaks.

If the advocate brings up their other favourite argument about protecting children, the interviewer could ask whether it's really a good idea to make it easier to intercept private picture messages between teenagers.

They could ask why the government wants measures that would inevitably undermine investigative journalism that holds the government and the police and the security services to account. Then start listing past controversies relating to the behaviour of those groups to demonstrate why that public interest reporting matters.

It's not as if privacy and security advocates only think these things are important because they don't like the government or something. There are real, serious consequences in play several different ways here.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#354

Poorly timed opportunism. Police have said the attacker acted alone, so he wasn't using encrypted comms to talk to anyone.

He sent a message 2 mins before the attack, and they want to know what that message was and who it was sent to, in case he wasn't acting alone. However, can't they already find out who the message was sent to? Whatsapp obviously has to have that information, and it appears they will give it to law enforcement: https://www.forbes.com/sites/thomasbrewster/2017/01/22/whats... I'm not sure that knowing the contents of th…

Shhh! You're letting the "facts" get in the way of a good power grab.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#355
post #348
post #320

Earlier quoted context omitted.

> That means there are still problems for you and me to solve. This was my last sentence. With which I tried to say that we have to still solve the problem and come up with the solution. My comment "that's a perfect solution" was about the answer "software that can effectively monitor communications with proper privacy" to the question about properly reconciling privacy and security, in a situation where the people a…

We live in a world, not a democracy. There are many different countries, with many different systems. Any proposed solution has to deal with that reality, not with the little bubble of one democracy which may arguably in the questionable opinions of some subset of people have a good government. The reality includes police states where the police are truly evil. It also includes police states where the software is wri…

> And yes, the security of a crypto system can be verified. If it's designed to be secure.

Theoretical security and actual security are two very different things. Once is mathematical which can be verified by equations. Other deals with software and imperfect developers. Software can't be verified for perfect security in a deterministic way, no matter how hard you try. Vulnerabilities pop up all the time. Your expectation that theoretical security translates to real world security is something I believe you need to think about again.

>Not if it's designed to be monitored. Even if the experts are perfect angels and absolutely competent, if there is a way to monitor, hackers will find a way to get access to it.

You seem to miss the part where I said a new protocol, not something which is modified, or backdoored. I'm surprised at you being so sure about the failure of a non-existent protocol. Do you have anything to back up your claim that any such protocol wouldn't work? Remember, it doesn't exist yet.

I honestly didn't find most of your post very coherent. There is no avenue for free speech in North Korea and other authoritarian regimes so it is a waste of time talking about working around the existing government for privacy and free speech rights. The only place where the masses can bring about change is in a democracy.

>not with the little bubble of one democracy

Last time I checked, most countries are democratic. Please show me the case where democratic countries vastly differ in how their government is organized.

> The reality includes police states where the police are truly evil.

Again, I talked about a democracy since we really can't do anything to help them with encryption and code. If there are no rights, strong encryption doesn't really matter. Look up rubber-hose cryptanalysis.

> The system has to work for this reality. I'm pretty sure that simply drawing a line and fully protecting the privacy of users' messages, full stop, is a better solution than whatever you and your senators will come up with.

It is of course is a better solution for individual privacy, I thought I talked about this at the end of my last comment. I don't have much control over my senators.

>>>When it comes to properly securing the physical part (the servers), I'm sure something can be figured out there.

>You're dreaming. Remember, the authorities will have full power over that system, and even in countries where the authorities are not evil, the authorities as a rule are inevitably corruptible if not corrupt. This isn't just cynicism, it's reality. Look around.

Full power? I don't believe you have understood what I said.

At this point it feels like you're arguing for the sake of an argument.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#356
post #355
post #348

Earlier quoted context omitted.

We live in a world, not a democracy. There are many different countries, with many different systems. Any proposed solution has to deal with that reality, not with the little bubble of one democracy which may arguably in the questionable opinions of some subset of people have a good government. The reality includes police states where the police are truly evil. It also includes police states where the software is wri…

> And yes, the security of a crypto system can be verified. If it's designed to be secure. Theoretical security and actual security are two very different things. Once is mathematical which can be verified by equations. Other deals with software and imperfect developers. Software can't be verified for perfect security in a deterministic way, no matter how hard you try. Vulnerabilities pop up all the time. Your expect…

Looking forward to learning more about this new perfect future protocol that you think will solve the problems.

/s

Re: UK Home Secretary says encryption on messaging services is unacceptable

#357

Earlier quoted context omitted.

We're a very long way from being a totalitarian state and likely to remain so for quite some time The scary thing is that the difference between the UK and the kind of place we might describe using words like "totalitarian state" is now more about how our laws are used in practice than what the laws actually say. The government and its agents already have very broad powers, our courts have already taken surprisingly…

I agree with this. The last thing we need is more laws and new powers for the surveillance state. For example, Australia's Lindt Cafe siege - the guy was already under "24 hour surveillance" by ASIO (Australian Security Intelligence) - which did nothing to prevent the attack. Despite this, AFAIK there was not much blame placed on ASIO. I'm sure there are many other examples. I'm not saying it's an easy problem to sol…

Man Monis was not under surveillance by ASIO. He was considered a "serial pest" and "not a threat".

Re: UK Home Secretary says encryption on messaging services is unacceptable

#358
Reading all of the comments I am deeply concerned. Everyone who is opposed to this is doing 'their side' a disservice.

Comments are about how stupid, or ill informed the Home Secretary and advisors are, or that they are being blackmailed by the intelligence services. Seriously? These kinds of comments are not going to get the broader public to support your ideals.

I think you misunderstand why she (and law enforcement) believe that they should have access to the messages. If the terrorist called someone they can get a warrant for the metadata and see who he called and whether it is relevant to the investigation. If the terrorist sent an SMS they can get a warrant for it. However, if the terrorist sends a WhatsApp message what can they get? Why should a WhatsApp message be treated different from an SMS?

That is what we as the tech community need to explain, why backdoors, weak encryption, and escrow are not a solution.

I value my privacy. I want my messages to be secure. But if the tech community keep acting like most of the comments on this, we will lose.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#359
post #21

Hmm, this definitely brings up an interesting discussion I don't think HN has had before, especially something in a similar vein since Apple+San Bernardino fiasco. Obviously privacy is something that HN holds very close to its heart. But I'm interested in what do people here have to say about the privacy features are used by terrible people to do terrible things. And I want to share something that I think is one of t…

>> But I'm interested in what do people here have to say about the privacy features are used by terrible people to do terrible things. Giving up such a valuable right to possibly stop attacks which, in the grand scheme of things actually harm very few people, is idiotic. Terrorism is obviously awful but the number of people in the UK actually affected by it is far, far too small to consider forgoing such an important…

> How about tackling the actual problem - terrorists seem to have resorted to using cars and trucks to kill people. Lets put up some metal/concrete bollards alone the edge of pavements that have no 'escape route', such as the one on Westminster Bridge.

Nice post. I agree almost entirely with you, but you can't put a bollard everywhere, and even if you could, bad people would find a way around or between the bollards, or simply another way to hurt people. It would be like playing a futile game of whack-a-mole.

At the end of the day, there are people who are so mean-spirited that they want to hurt innocent people for no reason, and they will find a way to do that no matter what we do. Honestly I think a lot of it is mental health more than anything we can really protect against.

It's not possible to wrap everyone in cotton wool, and in order to have some freedom we risk a small percentage of harm. There is no way around that. Without that freedom, there's also the IMO much larger risk of harm from the authorities themselves.

There's no way around it, living in the world involves some risk. It's unrealistic to not accept that risk and fantasize that all outcomes are preventable.

Like another comment mentioned, there are literally tens of thousands of stabbings in the UK every year. Why are we even talking about removing fundamental freedoms (the right to privacy) in order to probably not prevent a few unfortunate deaths per year? The payoff is so small and the cost is much too great.

Re: UK Home Secretary says encryption on messaging services is unacceptable

#360
post #342

Earlier quoted context omitted.

No properly-informed voter would want this kind of legislation.

"No true Scotsman..." I have a feeling that some top level FBI people are properly informed, but still want this kind of legislation.

Simply because it wouldn't apply to them.
Post reply on HN