Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

361–370 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#361

My german isn't that good, but from what I understand and from the translation below, the source seems a bit conspiratorial. I completely agree with the concerns raised elsewhere in this thread, but I'm not sure I see the clear link to recent events in Vienna etc claimed here. Here[0] is an earlier document from 21 october which the article seems to take some screenshots from, so it seems that this has been coming ei…

There is a new revision dated November 6. Changes are highlighted with bold text: https://files.orf.at/vietnam2/files/fm4/202045/783284_fh_st1...

Re: EU Draft Council Declaration Against Encryption [pdf]

#362

Earlier quoted context omitted.

First step is finding a way to educate the mainstream (including politicians) on the dangers of master keys and backdoors. It is too easy for many politicians and security agencies to think that their master keys and backdoors won't ever fall into the wrong hands, that they're careful, etc. And if you point out the problem, they'll tell you they'll be even more careful. Think about it from a non-techie perspective. I…

WhatsApp is closed source, isn't it? What kind of assurance do we have that these messages still aren't regularly sent to Facebook, unencrypted ?

Even a closed-source app is never really closed. In the end it's all machine code which is basically source code as well. There's many tools to analyse binaries, like IDA Pro. It's just difficult and often steps are taken to obfuscate what it's doing.

Having the higher-level source code just makes it a lot easier.

But if WhatsApp did this, it would probably be noticed pretty quickly by experts. But like I said above, Whatsapp's achilles heel isn't really the E2E encryption. It's the cloud backups.

Re: EU Draft Council Declaration Against Encryption [pdf]

#363
post #252

Earlier quoted context omitted.

That is true, but you will be able to vote for a party in power to reverse it. Not possible in case of EU.

In the UK? Voting is a paper tiger for stuff like this. The bill was supported by both Tories and Labour, and I was living in a Tory safe seat. I mean, I could’ve moved to Scotland and supported the SNP bid for independence or Wales and Plaid Cymru (but not NI and Sinn Féin given their policy of not taking their seats), but realistically there was nothing I could do about it other than what I did do about it. https:/…

If you didn't have any luck with the House of Commons, you perhaps should have tried voting for a different member of the House of Lords, or different judges, or a different monarch. Now that the UK has left the EU, you don't have to worry about those institutions being overridden by unelected MEPs.

Re: EU Draft Council Declaration Against Encryption [pdf]

#364
post #343

Earlier quoted context omitted.

What about proposing encryption as an EU human right? Has that been attempted?

I don't think that would help. Most rights are not absolute and can be restricted by other laws. For instance: * Freedom of movement is clearly restricted for people on a jail sentence. * We have secrecy of communication but also lawful interception.

Sure but it could still help.

Re: EU Draft Council Declaration Against Encryption [pdf]

#365
post #284

Earlier quoted context omitted.

By this logic home ownership is an offensive technology because it allows you to safely coordinate an attack.

And indeed it would be. Conversely, if you only used a gun to defend your self it would be a defensive technology. Seems like classifying technology as either offensive or defensive is a fool's errand. Perhaps you should try a different argument.

> And indeed it would be.

Only if that logic is sane, which it isn't.

There is an difference between doing something directly and indirectly. Anything can do anything given enough indirection. There is no plausible way in which your ordinary use of encryption or body armor could directly harm anybody else. There are some immediately obvious ways that your ordinary use of a howitzer could directly harm somebody else.

And the right to defend yourself using indirect offensive measures has no inherent symmetry with the right of government (or lack thereof) to prevent you from defending yourself using direct defensive measures.

Re: EU Draft Council Declaration Against Encryption [pdf]

#366

Earlier quoted context omitted.

I mean, if you put it that way, assumption of innocence is also a scary concept; being the police and having to let someone you know is a murderer or terrorist go because you can't prove what they did is routinely touted as a genuinely terrifying prospect in plenty of TV shows. Privacy is a human right in Europe. I don't think it's a pipe dream to give encryption some good PR, especially when it powers the internet,…

We expect privacy in "unencrypted" phone calls, but seem happy that law enforcement can eavesdrop on 4G when they have to. Not sure how much more privacy people expect. If you explain to people how much privacy they give up just clicking a random facebook questionnaire - they nod and then still do. Privacy and integrity is important but it will never match e.g. "terrorism" or "safety" on the list of important issues…

I'm not happy with that at all.

If anyone calls me on a regular phone call, I'm always aware of this.. It's that nasty feeling of being spied on that's really the main reason I hate this so much. The government shouldn't have any reason to spy on me but spying on everyone is simply becoming the norm because they can.

Re: EU Draft Council Declaration Against Encryption [pdf]

#367
Good lord. As a Scot, when the UK voted to leave the EU, I lamented the fact that the EU has always seemed more liberal, more sensible on privacy and human rights than the UK's home secretaries invariably are. It felt like the EU helped keep our politicians in check, keep them from doing anything too insane.

If the liberal EU is taking a stance like this, what hope is there?!

Re: EU Draft Council Declaration Against Encryption [pdf]

#368

I want to also give some perspective why this is bad even IF we can make sure that only governments will have the keys. We have just uncovered an organized crime at the top levels in Slovakia where even the President of police is part of it and they influenced many court cases and were accessing secret information and databases on citizens, basically a mafia. And we are part of EU. I don't trust our goverment to use…

Wow that's pretty bad.. Have any decent writeup on it so I can learn more about it?

Re: EU Draft Council Declaration Against Encryption [pdf]

#369

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

I was under the impression that all the mobile communications standards had provisions for lawful intercept, is it such a leap to think that the baseband processor is compromised aswell? Maybe the EU is just salty that they don't have the same kind of access the NSA has.

Re: EU Draft Council Declaration Against Encryption [pdf]

#370
post #118
post #91

Earlier quoted context omitted.

The west has terrorists - "we're different"

Terrorism is ostensibly the reason for what China is doing in Xinjiang.

If you have millions of 'terrorists' to lock up, maybe you're really doing something wrong though ;)
Post reply on HN