Live data from Hacker News

Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

haddadi.github.io

41–50 of 164 posts

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#41

These researchers are using logic and reason to fight against a bill that seeks to amass power and control. And while I appreciate the level tone... I do wish they'd at least wink at the real reasons this is being put forward. I get why they don't, to maintain respectability and deniability etc. But look at the sheer hypocrisy on display here. I kinda wish they'd take the gloves off and say, hey - Look at Prince Andr…

I think it's inflammatory and unfair to put Prince Andrew in your list, with a sex trafficker and two serial child abusers. He may have had an inappropriate relationship with a girl at a party, hold him to account for whatever there is in that it, but it's nowhere near on the scale as the others and it's the kind of hyperbole that dismisses the magnitude of major crimes.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#42

Bigger question how will safe messaging apps exit the market? Will people need a number for a privacy friendly foreign nation to continue access?

This is what the micro-nations were on about, people trying to dredge sand up off reefs and take over drilling platforms since the early 1980s to establish "data havens". The long term trend is that no nation will ultimately resist backdoors on encrypted platforms, because militarily they cannot resist the pressure (internally or externally).

The micronation thing is silly, as is relying on a shrinking number of countries which claim they won't enforce these laws. We need satellite-based servers. If I were Musk and had that chain up in the sky, I'd open a simple E2EE Whatsapp for anyone who could ping them directly. At this point, anyone who wants private comms is going to need to go to space for them.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#43

Earlier quoted context omitted.

It'll be a matter of installing the app "from unknown source" then?

Which, unfortunately, is a rather risky situation considering for instance all the rogue ChatGPT-branded extensions and apps people downloaded without a second thought to their legitimacy. We have been conditioned to view branding as the certificate of legitimacy, and that simply is not true for the Internet where branding can be copied and pasted in seconds.

The risk can be reduced with open source code, verified by the community. Usually when the "branding" gets too authoritarian, people reach for the FOSS version that seems the most trusted.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#45

These researchers are using logic and reason to fight against a bill that seeks to amass power and control. And while I appreciate the level tone... I do wish they'd at least wink at the real reasons this is being put forward. I get why they don't, to maintain respectability and deniability etc. But look at the sheer hypocrisy on display here. I kinda wish they'd take the gloves off and say, hey - Look at Prince Andr…

I think it's inflammatory and unfair to put Prince Andrew in your list, with a sex trafficker and two serial child abusers. He may have had an inappropriate relationship with a girl at a party, hold him to account for whatever there is in that it, but it's nowhere near on the scale as the others and it's the kind of hyperbole that dismisses the magnitude of major crimes.

The only reason Prince Andrew met Giuffre in the first place was that she had been "procured" by the Epstein/Maxwell ring!

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#46
post #44

As I understand it, most UK public are in favour of this bill almost Pavlovianly. There is a clear disconnect between us, the tech know-how, and the general public.

The UK public are extremely conservative, and extremely misinformed by conservative news sources. That's at the root of a lot of the demand for authoritarianism.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#47
post #19
post #8

Earlier quoted context omitted.

What would happen in the ideal world: - All online messenger providers (Whatsapp, Signal, Telegram) e.g. withdraw from the UK market. Meta and Google gave a taste for this after Canadian link law. - UK needs to come up with a crappy homebrew messenger ecosystem no one uses. Maybe a messenger.gov.uk? - People download applications with privacy and sideload them to their mobile phones, keep going with their business as…

Closing the sideloading hole on Android then becomes the next step. It's already a nonissue on the most popular device. Eventually the sale of devices that don't include cryptographic controls to prevent terrorists from misusing them to evade terrorist surveillance will be outlawed.

Stopping sideloading will never fix this issue, just having one non-cooperative external website would mean the scheme falls apart, you need to start blocking at the network level and aggressively pursuing people who bypass those blocks, making an example out of the first one that hits courts would likely be enough to scare all but the most dedicated out of such pursuits.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#48
post #26

Bigger question how will safe messaging apps exit the market? Will people need a number for a privacy friendly foreign nation to continue access?

The apps would be delisted in the UK app stores and will eventually stop working for existing users when not updated. That's also a security issue in itself.

For something like this you must start blocking at the network level, simply allowing the traffic would make these trivial to bypass via even something as simple as a web browser.

Re: Open Letter from Security Researchers in Relation to the Online Safety Bill [pdf]

#49
post #20

Earlier quoted context omitted.

If it is implemented as per the legislation, the UK would need to be disconnected from the global internet, and most activity economic or otherwise would cease overnight. I should really retract my original position, things in the UK would be very different. Honestly, it kind of needs to happen properly, otherwise people will never learn. Allowing these half baked pieces of legislation to pass and then not implementi…

There's a general "bad" when law are enacted and then not enforced, especially if it's a law that most people would naturally break because it's a silly law. It allows the authorities to persecute chosen individuals while not actually achieving anything that the law as written looks like it should be trying to achieve. And this is a silly law. Everyone will break it, every time they use an encrypted communication, wh…

So years ago there was a corruption scandal in Brazil, where gambling is illegal. A guy named Carlinhos Cachoeira[1] found that fact a great opportunity and built a gambling empire, which involved financing corrupt politicians so that they would vote according to his interests. Among those on the payroll was a senator, Demóstenes Torres. Well, one day an audio of a conversation between Demóstenes and Carlinhos leaks. It went something like that:

  Carlinhos: so I want you do vote in favor of [law X, which toughened restrictions on the kind of gambling Carlinhos promoted]

  Demóstenes (naively): but, professor, that will make things harder for you, won't it? 

  Carlinhos: oh, don't worry, it's not going to be used against me.

[1] Loosely translated as "Charlie Waterfall" by the NYT
Post reply on HN