Live data from Hacker News

European Parliament approves mass surveillance of private communication

patrick-breyer.de

401–410 of 434 posts

Re: European Parliament approves mass surveillance of private communication

#401
post #216

Earlier quoted context omitted.

Only if the domain uses google's MX as the public facing MX. If it delivers to an intermediate MX for filtering or archiving or ??? and then redelivers to google, it's not visible. Of course, if you don't set the public MX to google, blackberry phones won't use the right SMTP for outgoing mail, and then mail will fail DMARC, because you can't actually configure the SMTP server anyway. Hope they fixed that in BB10, be…

> If it delivers to an intermediate MX for filtering or archiving or ??? and then redelivers to google, it's not visible. That is a) a very odd and theoretical setup b) probably would cause Google's MX to reject most messages for SPF failures

This is not theoretical, if you've got say support@example.com that goes to your support queue, and employee@example.com that goes to your employee, and you want employee email on G Suite, your options are:

a) have your own MX that handles support mail and forwards employee mail to Google MX; G Suite provides a not exactly public domain you can forward to and you can whitelist your forwarder(s) IPs so Google uses the received headers for spam checking and SPF checks. If you don't setup the whitelist properly, a lot of mail will bounce or get flagged, yeah; but Google isn't dumb, they detect mail forwarding IPs with good behavior and will eventually semi-whitelist them without intervention.

b) The opposite way, where google is public MX and then delivers either specific addresses or unhandled wildcards to your MX to manage the support queue. (Or you might also forward it to a third party).

c) some people use third party email archival services (for example, ProofPoint) or virus scanning that shows as the public MX, and then forwards to some other MX for actual delivery

Re: European Parliament approves mass surveillance of private communication

#402
post #53

Are there any primary sources for this? I'm having trouble finding anything talking about any final legislative action involving chat control/ePrivacy etc. that isn't this random pirate party blog.

https://www.politico.eu/article/european-parliament-platform...

https://en.wikipedia.org/wiki/Think_of_the_children

Re: European Parliament approves mass surveillance of private communication

#403

Earlier quoted context omitted.

That’s systems leads to compromises and quod pro quos. That’s not as likely with just one nation state. If Country A wanted strong privacy laws and Country B wanted strong surveillance laws, and both have a veto, then you’ll get paralysis or a compromise. Right now it seems the EU has neither strong encryption as the norm nor a massive surveillance system. Just what one would expect when any nation can veto a law. No…

> Now that the UK is independent, it no longer has the paralysis/compromise/status quo dilemma. ...so they can now pass all the strong surveillance laws they want without being hindered by the EU? My point: "paralysis" can be good if it prevents you from doing something bad. Perhaps forcing a "compromise" actually leads to (better) solutions that account for everyone's concerns? Overall, it is not clear to me that th…

The UK constitutional system has been expanding its “checks and balances” quite a bit.

In the early 2000s the UK Supreme Court was granted a great deal of institutional autonomy. During the Brexit fiasco, it had no problem flexing its muscles.

The House of Lords had likewise been reformed and is much stronger and meritocratic (there’s still work to go on it).

Likewise subsidiary nations and municipalities have an increasingly large amount of independence. If Westminster passed surveillance laws unpopular in Scotland, they likely wouldn’t be implemented in Scotland.

The best example is probably Northern Ireland. There’s much greater support for surveillance powers in NI. But those expanded powers are combined with much greater accountability and oversight of security services.

Some parts of the British Home territory have too little surveillance. Both the City of London and Jersey have a reputation for laundering dirty money - something unthinkable in Northern Ireland.

Nothing about the UKs future is clear.

But I don’t think they need the EU to prevent them from passing overly broad or weak surveillance laws.

Re: European Parliament approves mass surveillance of private communication

#404

Earlier quoted context omitted.

How do we know what those fundamental rights are? By observing what happens to societies that have various formulations of rights. The societies that thrive are closer to the mark than societies that are mired in misery, despair, and death.

You neglected to mention any of these fundamental rights. Can you tell me one of them so I can debate you that it’s not fundamental?

> one

I'll give you three: Life, Liberty, and the Pursuit of Happiness.

Re: European Parliament approves mass surveillance of private communication

#405
post #94

Earlier quoted context omitted.

Doesn't help if you don't control the ends of the end-to-end part. We don't control iOS nor Android on most devices. In general this holds: There's no privacy on the internet.

Security researchers will always break into, reverse engineer, and scrutinize OS firmware and apps. They’re not going to find every backdoor. But I’m sure their work serves as a deterrent to some degree. Vendors aren’t going to deploy backdoors unless some state actor forces them to, and even then chances are they’re caught and called out.

Security researchers will also happily sell their tools to law enforcement and other agencies. Companies like cellebrite specialize on that.

In short, if you are being targeted (and, granted, the chance of that is pretty low), your data and communication is not secure. It's an economical question, not a technological question. (the FBI paid $1.3m in one case to get access to a phone).

Re: European Parliament approves mass surveillance of private communication

#406

Earlier quoted context omitted.

"Fundamental" rights are the ones whose existence is not considered a matter for debate in society.

No such right exists. Can you name one?

In the US in particular:

The right to life (in a negative, the government-shouldn't-take-it-away) is quite universally recognized - in cases where it's violated, defenders of that violation work very hard to craft a strong justification.

The right to free speech (again, in a negative the-government-shouldn't-take-it-away) sense is also a fundamental part of political discourse.

The right to private religious practice is broadly fundamental, though the right to religious practice of various sorts in the public domain (as well as the definition of that public domain) is hotly disputed.

Notably, the right to certain social goods are "fundamental" in parts of Western Europe (e.g. healthcare in the UK), but very much are not in the US. My general impression is that positive (the-government-should-provide-it) rights are much more rarely "fundamental" in the sense of being deep in a polity's consensus.

Re: European Parliament approves mass surveillance of private communication

#407

Earlier quoted context omitted.

You neglected to mention any of these fundamental rights. Can you tell me one of them so I can debate you that it’s not fundamental?

> one I'll give you three: Life, Liberty, and the Pursuit of Happiness.

None of those except life is “part of the innate nature of human beings”.

Death is also part of our innate nature, but you did not mention that one.

Re: European Parliament approves mass surveillance of private communication

#408

Earlier quoted context omitted.

laughs in Mandarin Well, I shouldn’t do that. Suffice to say, it’s simply a fact that China bans VPNs, and pretty much everyone goes along with it. People fear jail. It’s hard (but not impossible) to imagine Europe and the US doing that. NordVPN is practically a household name, at least on YouTube.

President Pooh bans VPNs but pretty much everyone uses them and jumps over the great wall. People just have a 'compliance' phone when authorities ask to rummage through it.

That's why the global digital id is important, you won't be able to access the internet unless you are authenticated.

Re: European Parliament approves mass surveillance of private communication

#409

Earlier quoted context omitted.

The metadata hosted on Facebook's servers is worth more than the actual content.

People keep repeating this trope about metadata being worth more than content. Where does this come from? I can understand that metadata is valuable -- of course it is. You can learn a lot from metadata. But more valuable than the actual content ? Give me a break. Something can be bad without being literally the worst thing ever. Pointless exaggeration like this does nothing for the cause of privacy.

Because processing is easier for metadata but analysis of it can answer many questions.

Direct communication is only interesting for direct surveillance.

Re: European Parliament approves mass surveillance of private communication

#410
post #216

Earlier quoted context omitted.

Only if the domain uses google's MX as the public facing MX. If it delivers to an intermediate MX for filtering or archiving or ??? and then redelivers to google, it's not visible. Of course, if you don't set the public MX to google, blackberry phones won't use the right SMTP for outgoing mail, and then mail will fail DMARC, because you can't actually configure the SMTP server anyway. Hope they fixed that in BB10, be…

> If it delivers to an intermediate MX for filtering or archiving or ??? and then redelivers to google, it's not visible. That is a) a very odd and theoretical setup b) probably would cause Google's MX to reject most messages for SPF failures

> a very odd and theoretical setup

Nope, I use https://mxguarddog.com/ for one of my domains. That acts as a spam filter, but also hides the ultimate MX host.

Post reply on HN