Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

471–480 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#471

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

I was under the impression that all the mobile communications standards had provisions for lawful intercept, is it such a leap to think that the baseband processor is compromised aswell? Maybe the EU is just salty that they don't have the same kind of access the NSA has.

Yep, it's not about encryption. It's about monopoly for information feed access.

Re: EU Draft Council Declaration Against Encryption [pdf]

#472
post #390
post #334

Earlier quoted context omitted.

> then you have to hope that a jury doesn't see your long pointless messages as strong evidence of using encryption Don't legal people routinely just take few word sentences and rewrite them into long paragraphs of aforementioned hereinafter notwithstanding including but not limited to senseless nonsense?

So long as it looks normal for you, I suspect you’d be fine. If I started writing long paragraphs of aforementioned hereinafter notwithstanding including but not limited to senseless nonsense, I’d be really obvious — at least to a human, not sure if current AI would notice me yet.

Hmm, I think a better strategy might be embedding the ciphertext in the fur of cat pictures. Sending lots of cat pictures seems pretty normal for anyone. Might be possible to create a GAN that outputs a synthesized cat picture with a constraint of some ciphertext that can be decoded later. Or simple modulation might just work, if I can convince JPEG to not wreck it.

Re: EU Draft Council Declaration Against Encryption [pdf]

#473

Earlier quoted context omitted.

Wow that's pretty bad.. Have any decent writeup on it so I can learn more about it?

It's a developing story, I will try to find some got article later. The funny thing is that it all started after one criminal (Marian Kocner) was arrested and his iPhone had the app Threema installed - an E2E encrypted chat. Fortunately for the investigators he had backups enabled and they could access the chat history in plain text. He was in direct contact with government officials including politicians, judges, an…

Wow, this is a truly fascinating story that I hadn't previously heard about in the US. Here is a good article I found that led me down the rabbit hole:

https://www.dw.com/en/slovakia-arrests-ex-police-chiefs-over...

Re: EU Draft Council Declaration Against Encryption [pdf]

#474

Earlier quoted context omitted.

> And indeed it would be. Only if that logic is sane, which it isn't. There is an difference between doing something directly and indirectly. Anything can do anything given enough indirection. There is no plausible way in which your ordinary use of encryption or body armor could directly harm anybody else. There are some immediately obvious ways that your ordinary use of a howitzer could directly harm somebody else.…

Ransomware uses encryption to harm people.

Not really. Ransomware works by creating an encrypted copy of your data and then deleting the original data. The direct harm comes from deleting the original. Where would the harm be if all they did was create an encrypted copy without deleting the original?

And the same attack works if instead of encrypting your data they upload a copy of it to their servers before deleting it. Albeit less efficiently, so we're back to indirect harms.

Re: EU Draft Council Declaration Against Encryption [pdf]

#475

Earlier quoted context omitted.

First step is finding a way to educate the mainstream (including politicians) on the dangers of master keys and backdoors. It is too easy for many politicians and security agencies to think that their master keys and backdoors won't ever fall into the wrong hands, that they're careful, etc. And if you point out the problem, they'll tell you they'll be even more careful. Think about it from a non-techie perspective. I…

WhatsApp is closed source, isn't it? What kind of assurance do we have that these messages still aren't regularly sent to Facebook, unencrypted ?

Ain't it fun when you post http(s) link with WhatsApp, preview fetch originates from server in US to your url. How's that E2E.

Re: EU Draft Council Declaration Against Encryption [pdf]

#476
post #465
post #293

Earlier quoted context omitted.

Thanks—we've changed the URL from https://fm4.orf.at/stories/3008930/ . Submissions to HN need to be in English—we have great respect for other languages, including German, but HN is an English language site. Happily in this case, following the site guideline that calls for original sources solves this problem as well. (I've taken the title from the new URL, btw, which uses the rather strong preposition "against"—I s…

HN needs to come together to reward 'dang's hard work keeping HN to HN quality. I have this theory that with almost any great music groups there's usually one, sometimes two, great mind(s) working in the background, usually introverted, that really define the talent of the wider group (Brian Wilson, Quincy Jones, Phil Spector, etc are the rare few who got that recognition). NYT did a great exploration of how this cur…

> The Aussie girl is in the NYT clip who basically made the song still lives in relative obscurity (you can find her on twitter, probably well paid, but still living without much fanfare), despite this song among others blowing up in the charts.

The sad part is they don't even name her in the summary. She's "a 23-year old songwriter". The famous producers and vocalists get named, but she doesn't.

Re: EU Draft Council Declaration Against Encryption [pdf]

#478
post #465
post #293

Earlier quoted context omitted.

Thanks—we've changed the URL from https://fm4.orf.at/stories/3008930/ . Submissions to HN need to be in English—we have great respect for other languages, including German, but HN is an English language site. Happily in this case, following the site guideline that calls for original sources solves this problem as well. (I've taken the title from the new URL, btw, which uses the rather strong preposition "against"—I s…

HN needs to come together to reward 'dang's hard work keeping HN to HN quality. I have this theory that with almost any great music groups there's usually one, sometimes two, great mind(s) working in the background, usually introverted, that really define the talent of the wider group (Brian Wilson, Quincy Jones, Phil Spector, etc are the rare few who got that recognition). NYT did a great exploration of how this cur…

We can do small tributes on a subdomain. I'll do two small ones;

- dang.matcha.life

- dang.moka.moe

One tea related and one coffee related, of course.

I'll aim to have them live by December 1st.

Re: EU Draft Council Declaration Against Encryption [pdf]

#479

I want to also give some perspective why this is bad even IF we can make sure that only governments will have the keys. We have just uncovered an organized crime at the top levels in Slovakia where even the President of police is part of it and they influenced many court cases and were accessing secret information and databases on citizens, basically a mafia. And we are part of EU. I don't trust our goverment to use…

encryption for the government

no encryption for the people

sounds like the perfect democratic recipe

Re: EU Draft Council Declaration Against Encryption [pdf]

#480

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

What about proposing encryption as an EU human right? Has that been attempted?

So really it wouldn’t be encryption so much as right to have secrets. Because whether I use EDCA or a really strongly in crackable safe, my right to privacy should be a thing?

It sounds like somewhat of a stronger version than the US’s fifth amendment which says that you have a right to privacy unless it has to do with the crime currently being investigated. And come to think of it, encryption is unconstitutional as in because the government can subpoena or obtain a warrant to your information it may not be able to enforce it because of the encryption. So either the government has no right to subpoena or encryption is illegal.

Post reply on HN