Live data from Hacker News

Real people don't need end-to-end encryption says UK Home Secretary

uk.businessinsider.com

41–50 of 92 posts

Re: Real people don't need end-to-end encryption says UK Home Secretary

#41

Earlier quoted context omitted.

Say a smartphone app ran both an https client and server. For users to send each other messages, they connect to each others servers. That's end to end encryption, right? And looks identical to the type of encryption they'd still allow right? What have I missed?

The follow up bill which makes it mandatory to have government spyware on all https servers?

They can't do that because it would require major open source web servers to be forked. There's no way they're going to persuade operators in other countries to run UK government spyware.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#42

Basically she's saying chat apps in the UK shouldn't be allowed end-to-end encryption. So the terrorists will setup a chat system that look like payments. In the mean-time, the UK government will use our chat to identify harmless political dissidents, groom them online and then fail to incite them to violence. Given previous performance, they will meet some of their targets, get a few pregnant and then get sued 20 ye…

Say a smartphone app ran both an https client and server. For users to send each other messages, they connect to each others servers. That's end to end encryption, right? And looks identical to the type of encryption they'd still allow right? What have I missed?

I guess once it gets popular, they just force Apple and Google to remove it from the apps store. So it has to be a web site with all the http server running in javascript/web assembly. I guess you still need a central server to let clients find each other in the first place. They could block that at the DNS level.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#43

I realize the article was about the UK, but this entire encryption/spying issue certainly applies to the US as well. My comments are regarding the US because I don't know enough about the UK's laws and general situation to speak on it. The cat is out of the bag. End to end encryption that is very easy for the average user to use exists. There's no going back. These terrorists that they are so worried about are going…

E2E is only easily accessible to regular users because because you can install Signal straight from the appstore. It can be made much less easy by a sufficiently determined government.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#44

Dear UK secretary: your department lost credibility to talk about "real people" needs when the UK police helped Murdoch's "News of the World" to hack into "real people" phones. But I don't expect you to understand your own responsibilities so let's just wait until Vladimir Putin hacks into any server containing your private information. Then UK politicians will understand.

Nah, she's an "important" politician, so she's not "real people", she's allowed to use encryption. Phone hacking? Well celebs are not real people either, they should be able to apply to use encryption, in her mind.

Not just celebs:

https://en.wikipedia.org/wiki/Murder_of_Milly_Dowler#Voicema...

Re: Real people don't need end-to-end encryption says UK Home Secretary

#45
post #28
post #12

The problem is largely the UK's lack of a constitution. There are no checks or balances in the UK. Parliament can literally do anything they want. The courts can't block Parliament. Parliament can just abolish the courts. The house of lords can't stop the house of commons, the commons can just override the lords. The queen won't veto the commons because she fears parliament will just abolish the monarchy.

I'm really not trying to be pedantic, but that's not true. The UK has no written constitution but it does have a constitution. It's important to make the distinction because it is entirely possible that this proposal is unconstitutional (and I wonder if that's why the Home Secretary is asking for companies to voluntarily adopt it rather than passing legislation). It smells unconstitutional to me because it is an atta…

There's no entrenched right to privacy in the domestic constitution. The Human Rights Act has, though, brought Article 8 of the European Convention on Human Rights into UK law:

> 1. Everyone has the right to respect for his private and family life, his home and his correspondence.

> 2. There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others.

[Note the exceptions, which are (by design) wide enough to drive a bus through]

An Act of Parliament restricting end-to-end encryption for the expressed purposes of preventing crime and preventing terrorist atrocities would fairly clearly be constitutional, I think. Even if it was ruled incompatible with the ECHR, the courts have no power to overturn primary legislation - just to punt it back to Parliament with a declaration of incompatibility.

If a minister tried to do it without Parliament under the royal prerogative or secondary legislation, I think the chance of it being overturned as unlawful are somewhat higher.

I'm a political scientist, not a lawyer, mind.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#46
It'll be interesting in 10-15 years when the US is one of the few countries left that allow unfettered access to encryption, VPNs, secure messaging, etc.

How does the saying go? "The dark night of fascism is always descending in the United States and yet lands only in Europe"

Re: Real people don't need end-to-end encryption says UK Home Secretary

#48

Earlier quoted context omitted.

The follow up bill which makes it mandatory to have government spyware on all https servers?

They can't do that because it would require major open source web servers to be forked. There's no way they're going to persuade operators in other countries to run UK government spyware.

> They can't do that

Well, it works for China, so I don't see why it wouldn't elsewhere.

As a techie, I'd like to believe that there are limits to what can be passed as law, but the history shows that it is not so. Just because something is technically impossible doesn't mean it can't be required by law, with all the consequences for not complying. It's uterly futile to go against the people in power with technology or even science alone. The best you can hope for is for you and me, personally, avoiding problems. For a time.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#49
post #39

Earlier quoted context omitted.

I think the US proves that the "constitution" as any mechanism for safety is absurd. It's ignored or abused when it's convenient.

The problem is that the protections of civil liberties work for for the times and contexts under which they were formulated, but they are not adapted to evolving technology and culture as frequently as efforts to circumvent them. It's reverse hill climbing via million slippery slopes.

> The problem is that the protections of civil liberties work for for the times and contexts under which they were formulated...

The people who wrote the US Constitution and its Bill of Rights survived a time when the most powerful army in the world was marching through their backyards. I have no doubt they had that in mind when they were writing freedoms into law.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#50
post #36

Earlier quoted context omitted.

How could they prevent terrorists to develop their own end-2-end encrypted chat app?

... or connecting with SSL to an overseas server under their control ?

Jailed for use of an illegal encryption scheme. Welcome to the future.
Post reply on HN