Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

431–440 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#431

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

Does the idea you're proposing enable recording reputation scoring on the scope of a single post/message?

Re: EU Draft Council Declaration Against Encryption [pdf]

#432
post #4

We need to establish the use of encryption as a basic human right. I'm so tired of this cropping up every couple years.

It pretty much is, section 12 of the Universal Declaration of Human Rights states: > No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks. I mean wearing my programmer goggles it doesn't state privacy AND correspondence but OR, but sti…

> interference with [...] correspondence

Imagine that some unnamed corrupt government treats your telegram messages as correspondence, but not encryption keys. It then orders Telegram to release said keys (pinky promising not to do anything nefarious with them) because they aren't considered correspondence.

Re: EU Draft Council Declaration Against Encryption [pdf]

#433
post #96

Earlier quoted context omitted.

It's common that people become much more concerned about possible threats to physical safety after having children. That strikes me as reasonable, even if it leads someone to take a different side than I would in a freedom/safety question. With that out of the way, how do you propose stopping criminals from using encrypted chat? You can make it illegal, of course, but making it impossible for someone who doesn't care…

Well, one way: If you do make it illegal: 1. Police finds e.g. a 19 year criminal gang member doing something mildly illegal. 2. Police inspects their phone 3. Police finds illicit encrypted chat app 4. Criminal gang member refuses to cough up password 5. Criminal gang member gets sentenced and cannot hurt the public while they are contained.

[deleted]

Re: EU Draft Council Declaration Against Encryption [pdf]

#434
post #395

Earlier quoted context omitted.

WhatsApp is hardly safe from prying eyes anyway. Sure, there's always-on E2E encryption that is really well designed. However, WhatsApp constantly prompts every user to back up to the cloud, which is much less well secured. Thus, it's pretty trivial for the authorities to get to it there, I'm sure they can get into iCloud and Google Drive if they want to. It only takes one person in the conversation to have this opti…

Which is to say WhatsApp is perfectly secure as long as the hostile actor cannot access the WhatsApp backups. Only nation state actors might be able to do that.

Isn't it more like "literally any LEO or pseudo-LEO in a 'friendly' country" at this point based on what we know at this point?

I think the threat model here is less about a hostile actor subverting the backups than the extreme ease of access to all data on those systems that is given to law enforcement?

Re: EU Draft Council Declaration Against Encryption [pdf]

#435

Earlier quoted context omitted.

Even a closed-source app is never really closed. In the end it's all machine code which is basically source code as well. There's many tools to analyse binaries, like IDA Pro. It's just difficult and often steps are taken to obfuscate what it's doing. Having the higher-level source code just makes it a lot easier. But if WhatsApp did this, it would probably be noticed pretty quickly by experts. But like I said above,…

Would it? This kind of transmission of messages could be hidden alongside legitimate looking traffic like updates...

Also wven if it does not exhilarated user data now, it's one update from doing that tomorrow. Quite possible even via a targeted update on some specific people "not in favor".

If it was open source there is some chance a backdoor would be spotted (eq. by Linux distropackage msintainers), but not when a company is pushing obfuscated binary blobs preatty much directly to users.

Re: EU Draft Council Declaration Against Encryption [pdf]

#436

I see this as follows: 1. Terrorism and trafficking of children will win the moral high ground. 2. App stores will be forced locale by locale to conform to these policies. 3. Most people will not notice or care. 4. This will be used by N-Eyes and totalitarian governments to quash dissent. 5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely. 6.…

We are not at (2) yet. The EU is at least privacy-conscious - its parliament especially so. As an example, see the attention given to privacy here: https://www.politico.eu/wp-content/uploads/2020/09/SKM_C4582... In my view there is a good chance that (2) will not be EU law for the foreseeable future, although this does require some opposition work. I guess one can see it as education of the politicians (the commissio…

And even if it passes parliament there is still a chance that it will squashed by the ECHR.

Re: EU Draft Council Declaration Against Encryption [pdf]

#437

I see this as follows: 1. Terrorism and trafficking of children will win the moral high ground. 2. App stores will be forced locale by locale to conform to these policies. 3. Most people will not notice or care. 4. This will be used by N-Eyes and totalitarian governments to quash dissent. 5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely. 6.…

Terrorists and other criminals already have more than enough tools in their possession to exchange data absolutely without fear of their messages being compromised.

So this is interesting, care to elaborate?

Re: EU Draft Council Declaration Against Encryption [pdf]

#438
post #267

I see this as follows: 1. Terrorism and trafficking of children will win the moral high ground. 2. App stores will be forced locale by locale to conform to these policies. 3. Most people will not notice or care. 4. This will be used by N-Eyes and totalitarian governments to quash dissent. 5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely. 6.…

It's the infinite horse race. Black hats vs white hats. Neither holds the upper hand for long. I hope that if we ever reach a steady state, it will be unbreakable privacy.

"Red Queen's Race" is the term often used for that.

Re: EU Draft Council Declaration Against Encryption [pdf]

#439
post #284

Earlier quoted context omitted.

And indeed it would be. Conversely, if you only used a gun to defend your self it would be a defensive technology. Seems like classifying technology as either offensive or defensive is a fool's errand. Perhaps you should try a different argument.

> And indeed it would be. Only if that logic is sane, which it isn't. There is an difference between doing something directly and indirectly. Anything can do anything given enough indirection. There is no plausible way in which your ordinary use of encryption or body armor could directly harm anybody else. There are some immediately obvious ways that your ordinary use of a howitzer could directly harm somebody else.…

Ransomware uses encryption to harm people.

Re: EU Draft Council Declaration Against Encryption [pdf]

#440
post #437

Earlier quoted context omitted.

Terrorists and other criminals already have more than enough tools in their possession to exchange data absolutely without fear of their messages being compromised.

So this is interesting, care to elaborate?

It is trivial to create an app using encryption to send messages between two users. On Android you can sideload so no need for app store.

You can also solve this with a webpage, this way it can be used on all devices.

The point is that creating a secure channel few users use is pretty trivial unless you outlaw crypto libraries. These laws can only take down apps/websites in mainstream use.

Post reply on HN