Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

451–460 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#451

Earlier quoted context omitted.

Sadly, no one actually has any battleships these days, not even the governments... :-(

We call them "destroyers" nowadays. (The Zumwalt-class destroyer displaces ~15,000 tons, which is too large to be considered a cruiser under the terms of the inter-war naval treaties, and is roughly the displacement of a 1910s-era South Carolina-class battleship).

Thats still less than a half of the displacement of Warspite, third of the Iowas, let alone monsters like the Yamato class. And unlike Zumwalt, all of those had working guns. ;-)

On a more serious note a modern destroyer could sink any of those with long range missiles long before the batlleship could ever get into a range for a proper gun duel.

Not counting modern aircraft with yet more standoof missiles or even the anti/ship ICBMs that are being talked about.

Oh well, battleships were an elegant weapon for a more civilized age...

Re: EU Draft Council Declaration Against Encryption [pdf]

#452
Dear EU leaders,

There is no "reasonable middle ground" in this issue. Either the encryption works, and it protects the conversation, or it doesn't and it can be broken by both state and private actors, foreign or domestic. It is not like other policies in the phisical world, where a compromise on guns, drugs etc. can be reached that maximize the social welfare. The mathematics of encryption do not allow partial privacy, you either have it, or you don't and when you do, no government can break it.

It follows that any "reasonable balance" in practice alwas means a de facto ban of encryption technology, and replacing it with a state monopoly on encryption. Thus, citizens could pe provided with simulated encryption tools, where messages are securely sent to infrastructure controlled by the government, stored, then resent securely to the intended recipient, with the state or their intermediaries controlling the privacy of the conversations. This conceptual copying need not be done for every encrypted exchange, the key issue being the existence of a backdoor that could be activated at the decision of the state.

This is undesirable for many reasons:

1. It is insecure and dangerous; once a backdoor exists, its activation must be unknowable by the citizens, otherwise it makes no sense as it would tip off the criminals. If activation of the backdoor is unknowable, then there can exist no guarantees it's only used for legitimate purposes. The backdoor would be of a mathematical and technical nature while the institutions called to regulate it would be no better than other institutions humans create: they could be corruptible, incompetent, tyrannical etc. The mathematics of encryption backdoors would serve such institutions well regardless of their dedication to the goal of providing only lawful access, and would serve any 3rd party that could abuse it. Furthermore, lawful intereption points constitute a central point of attack for a powerful adversary, even to the point of weakening national security.

2. It is essentially useless. Smart criminals use off-the-shelf technology because they know it's fit for purpose. If government snooping is implemented in all such products, then they would switch to other forms of communications that can provide them with the secrecy they require to operate. Additionally, encryption is just math, and the fundamental capability of computers that surround us is to perform math and load user-defined programs. Encryption can never be banned, just commercial products that use it. Criminals don't care about such bans and would revert to older implementations or write their own ilegal encryption tools.

3. It disempowers citizens. The ability to have private communication unperturbed by the power of the state is a fundamental freedom in a democratic country. It is a modern manifestation of a timeless pact between the governed and the rulers: government exists to protect the liberty of ruled, not protect itself. People are to be trusted because their freedom is an end in itself, and the technology of encryption is vastly liberty enhancing without being, by itself, a direct threat to anyone.

Re: EU Draft Council Declaration Against Encryption [pdf]

#453
post #290
post #236

Earlier quoted context omitted.

>We live in a dangerous world. No we don't, but that's what the Politicians try to implement in our brains.

It's easy for people to lose sight of this with all the bad news we're seeing in 2020, but the present is the safest time in history when zoomed out to a scale of decades. The decline in violence since the 1900s to today is essentially global and scales from bar fights to wars.

Easy to lose sight that whatever safety we have is because we are actively trying to make it safe. We are at a point of development where if it wasn't safe, it would be the polar opposite and be the most unsafe time in history, everything happens on a global scale. What levers we need to maintain safety as technology moves forward is a tough thing to work out. Mucking with encryption doesn't seem like a good way to go though.

Re: EU Draft Council Declaration Against Encryption [pdf]

#454
post #399

Earlier quoted context omitted.

>Pretty much everybody loses their life somehow. Yeah that's called life. >Today I don't let my kids ride in the back of pickup trucks, and I'm nervous about the lawn mower. That's because you already infected with fear. It's not your Children's fault that you don't trust them with a lawn mower..it's you and probably your society that is the problem. >Some dangers and some fears need to be met head on. Yes like wear…

Perhaps you missed my point. Lawn mowers didn't get more dangerous. The level of danger hasn't gotten worse in that one respect. The level of trust might have changed. The acceptance of risk might have changed. I don't think that keeping my kid away from the lawn mower in order to protect them makes their life overall better or even safer. Lawn mowers are dangerous. But that doesn't mean they should be banned. As you…

If you're nervous about your kid being reckless with the mower, you teach them not to be reckless. That's all there is to it.

Re: EU Draft Council Declaration Against Encryption [pdf]

#455

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

What about proposing encryption as an EU human right? Has that been attempted?

> What about proposing encryption as an EU human right? Has that been attempted?

Rights conflict. Every new right influences the others. It is easy to shorthand every problem to a human rights declaration. But just like the right to bear arms, that can have unintended consequences.

Re: EU Draft Council Declaration Against Encryption [pdf]

#456
post #289

Earlier quoted context omitted.

With the UK, I've found (as a foreigner with voting rights previously) that it's best to build your relationship with a seniorish MP, and if that doesn't work, cough up to donate around 8-10k to the parties every year (for much more senior access). You'll pop a few eyeballs in Labour with such a donation, while the Conservatives have their own special interest groups for donors (although these usually end up as mass…

I don’t know if I should be happy to know I personally can afford to buy access to UK politicians, or embarrassed that they are so cheap, but either way that is a very interesting anecdote.

I'd appreciate that at least the system is overt. All of the above information usually is public info. You know exactly which politician got funded by which Russian tycoon, etc.

Re: EU Draft Council Declaration Against Encryption [pdf]

#457
post #437

Earlier quoted context omitted.

So this is interesting, care to elaborate?

It is trivial to create an app using encryption to send messages between two users. On Android you can sideload so no need for app store. You can also solve this with a webpage, this way it can be used on all devices. The point is that creating a secure channel few users use is pretty trivial unless you outlaw crypto libraries. These laws can only take down apps/websites in mainstream use.

Could they inspect traffic at the ISP level and come knocking if they can't decipher what you're transmitting?

Re: EU Draft Council Declaration Against Encryption [pdf]

#458

Earlier quoted context omitted.

> We live in a dangerous world. No, West Europe used to be really safe. Then it changed because of unrestricted immigration policies. East Europe countries are still pretty safe with no terrorism.

Western Europe is still incredibly safe, and in my quick overview safer than eastern Europe: https://en.wikipedia.org/wiki/List_of_countries_by_intention... My home country is Norway, it looks safer than all of Eastern Europe, sometimes by an order of magnitude.

Huh? I'm seeing a 0.5 murders per 100K in Norway which is exceptionally safe no doubt but meanwhile Poland has 0.7 murders per 100K. Bulgaria is 1.3, Czech 0.6...the two most dangerous are Ukraine and Russia.

Belgium's 1.7, France is 1.2, Germany 0.95...

Real mix it seems. But no, it's not safer by an order of magnitude for all of it, mainly just Ukraine and Russia.

Re: EU Draft Council Declaration Against Encryption [pdf]

#459

Earlier quoted context omitted.

You're conflating the language issue with the alleged "obscurantist" issue. In your opinion, since you brought it up, what facts are the original link lying about or hiding?

You misunderstood. They said the current link is possibly obscurantist, not the German one.

Got it, thanks for the clarification. Too late to edit

Re: EU Draft Council Declaration Against Encryption [pdf]

#460

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

While adding backdoors to encryption is a bad idea my gut sys decentralized reputation is just a bad. Most here know the Black Mirror episode "Nosedive". But it's worse than that, people on different sides of the political spectrum will work to "cancel" people of the other side by working to lower their rep via crowdsourcing. 4chan type groups will do the same for "the lulz", I can even imagine the ransomware people trying to find a way to make bots and "pay us or we destroy your rep"
Post reply on HN