Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

491–500 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#491

I see this as follows: 1. Terrorism and trafficking of children will win the moral high ground. 2. App stores will be forced locale by locale to conform to these policies. 3. Most people will not notice or care. 4. This will be used by N-Eyes and totalitarian governments to quash dissent. 5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely. 6.…

We are not at (2) yet. The EU is at least privacy-conscious - its parliament especially so. As an example, see the attention given to privacy here: https://www.politico.eu/wp-content/uploads/2020/09/SKM_C4582... In my view there is a good chance that (2) will not be EU law for the foreseeable future, although this does require some opposition work. I guess one can see it as education of the politicians (the commissio…

The EU takes a statist approach to privacy. Encryption is always a better protection to privacy than ever changing laws. EP members are either inexperienced when it comes to technology or serve a party or a lobby agenda. The only countries opposing for the sake of opposing are Hungary and Poland and their leaders would love encyption being backdoored as long as their secret services can pry at comms.

Educate the Comissioners? The president of the Comission is an ex home secretary ie. a lady with a policing mindset just like Theresa May, only allegedly corrupt. Somehow her phones were wiped clean when required as evidence in a recent investigation. The irony of this legislation is that it could expose her own doings.

https://www.google.com/amp/s/www.politico.eu/article/ursula-...

The Comissioners were told to use Signal after Bezos' phone got trojaned through WhatsApp. Encryption is only good when it's for their own benefit.

Re: EU Draft Council Declaration Against Encryption [pdf]

#493

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

While I know I'm just attracting downvotes, your points, in order:

1)

a: It's really not that hard to think of ways to solve backdoor problems with a mix of technical and social approaches. For example, having shared keys burned onto silicon, making physical access mandatory, and split between both the law enforcement and the company, so that both parties must knowingly engage.

b: Most software already practically backdoored already, and it's really not that big a deal. Microsoft can push whatever updates they want whenever they want. They already have the keys to the kingdom! Google doesn't store everything E2E encrypted. They also already have the keys to the kingdom! Things have mostly worked out regardless.

2) That a measure will be imperfect is not an argument that it will be ineffectual. In fact it's pretty obviously false; making abuse harder on mainstream platforms will make abuse less mainstream.

3) This is like arguing governments shouldn't be allowed to regulate weapons, because it would be hypocritical, given they own weapons themselves, and it might normalize other countries taking away their citizens' weapons, which might prevent them fighting back. That seems like an obviously bad argument.

4) Yes, your platform that makes oversight impossible is not compatible with regulations requiring oversight. That's not an accident, in either direction.

The idea later in the post seems not really honestly engaging with the topic, that it's not about ‘someone who believes birthday cake is undesirable’, but about networks which are systematically and in actuality doing things like trafficking children for sexual abuse, and that there is a moral imperative for governments to deal with this beyond just letting people choose not to engage.

Re: EU Draft Council Declaration Against Encryption [pdf]

#494
post #482

Earlier quoted context omitted.

> The Aussie girl is in the NYT clip who basically made the song still lives in relative obscurity (you can find her on twitter, probably well paid, but still living without much fanfare), despite this song among others blowing up in the charts. The sad part is they don't even name her in the summary. She's "a 23-year old songwriter". The famous producers and vocalists get named, but she doesn't.

Kanye might tweets some crazy stuff but his recent crusade against shitty record contracts (tweeting out his entire Warner contract deal for example and calling out real owners to stop robbing kids) and the general nonrecognition of the artists themselves is something I can get behind. https://www.gq.com.au/entertainment/music/heres-the-rundown-... I almost went into the music industry before programming which is why…

Kanye is himself a shitty record label. He signs people promising to produce their record or feature him on his albums and then dumps them.

Re: EU Draft Council Declaration Against Encryption [pdf]

#495

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

While I know I'm just attracting downvotes, your points, in order: 1) a: It's really not that hard to think of ways to solve backdoor problems with a mix of technical and social approaches. For example, having shared keys burned onto silicon, making physical access mandatory, and split between both the law enforcement and the company, so that both parties must knowingly engage. b: Most software already practically ba…

1a - Because that worked out so well for HDMI? It'll be what, maybe 90 days before those "law enforcement keys" are public?

1b - If it's already backdoored then there is no need for such an act, the problem is already solved.

2 - It's ineffective for it's stated goal because the stated goal is not the real goal. The goal is to enable a continued abuse of power, one which is already ongoing, and one which produces no actionable results or meaningful outcomes. Five eyes & co is upset that they're losing some of their toys.

3 - Who says governments should be able to regulate weapons? Likewise these days, who is to say they meaningfully can?

4 - Sex trafficking existed prior to encryption. The government failed to stop it then. I strongly suspect that even if the government gets it's way and breaks encryption, sex trafficking will continue exactly at the same rate. Most sex traffickers are not technology ept, nor do they need to be - the track record for capturing them is atrocious. Epstein anyone?

This is a bad faith argument. "Protecting children" and "stopping terrorists" are the siren's song of every government overreach basically since the dawn of time and yet the government remains terrible at solving either problem. I don't think encryption is really the issue preventing those things from getting resolved. I do think encryption is very inconvenient for a very snoop heavy government.

Re: EU Draft Council Declaration Against Encryption [pdf]

#496
When the only real solution is to outlaw encryption, it is disingenuous for government (or the EU president to ask member governments) to “call on industry to work together.”

By working together the President means “we hate encryption but it’s politically distasteful to ban it, so we’re going to make you ban it instead or else we’ll backdate your Irish taxes to be Belgian ones instead.”

Re: EU Draft Council Declaration Against Encryption [pdf]

#497

Earlier quoted context omitted.

While I know I'm just attracting downvotes, your points, in order: 1) a: It's really not that hard to think of ways to solve backdoor problems with a mix of technical and social approaches. For example, having shared keys burned onto silicon, making physical access mandatory, and split between both the law enforcement and the company, so that both parties must knowingly engage. b: Most software already practically ba…

1a - Because that worked out so well for HDMI? It'll be what, maybe 90 days before those "law enforcement keys" are public? 1b - If it's already backdoored then there is no need for such an act, the problem is already solved. 2 - It's ineffective for it's stated goal because the stated goal is not the real goal. The goal is to enable a continued abuse of power, one which is already ongoing, and one which produces no…

> Because that worked out so well for HDMI? It'll be what, maybe 90 days before those "law enforcement keys" are public?

This is a completely different context to having one copy (or a small number) of said low-bandwidth silicon held exclusively by an agency vested in keeping it exclusive, plus another copy held by the company themselves, such that both copies would need to be broken for security to be weakened.

> If it's already backdoored then there is no need for such an act, the problem is already solved.

Seriously? Microsoft having the ability to install a keylogger on any random person's machine is not the solution to finding networks of criminal activity.

> [government bad]

I'll debate the technicals but I'm not going to argue politics here.

Re: EU Draft Council Declaration Against Encryption [pdf]

#498
Sorry if this is an aside, but I mean... practically speaking, wouldn't a ban on encryption basically be useful and impossible to enforce? The US export controls on encryption in the 1990s were largely ineffective, no?

Forcing Apple/Microsoft to build in backdoors in their implementations of encryption packages might be one thing, but software developers surely have local copies of openssl, libsodium, etc, so what will this actually be able to achieve?

Re: EU Draft Council Declaration Against Encryption [pdf]

#499
post #338
post #322

Earlier quoted context omitted.

It all comes down to distribution. We need actual software like https://Matrix.org or https://qbix.com/platform to be good enough that people will install it. Like the Web Browser did killed AOL and MSN. Otherwise we will live with Facebook Google etc. and this is moot. But that is just the beginning. Secondly, we need open source hardware. We are nowhere close to competing with Apple and Android. But as we have seen…

>Just today I read that Android doesn’t let you take a screenshot of your own phone. Not many seemed to care to click the link in that thread. If one did one would know that it was to a bug report and a fix was even posted in the same link. Screenshots work just fine.

Not many seemed to read through the bug report either.

The bug report was for not being able to screenshot in situations when it wasn't actually disabled.

The fundamental problem that the GP is referring to and that demonstrates the loss of control over one's own devices is that it _is_ possible for apps to disable making of screenshots to begin with.

Re: EU Draft Council Declaration Against Encryption [pdf]

#500
post #399

Earlier quoted context omitted.

>Pretty much everybody loses their life somehow. Yeah that's called life. >Today I don't let my kids ride in the back of pickup trucks, and I'm nervous about the lawn mower. That's because you already infected with fear. It's not your Children's fault that you don't trust them with a lawn mower..it's you and probably your society that is the problem. >Some dangers and some fears need to be met head on. Yes like wear…

Perhaps you missed my point. Lawn mowers didn't get more dangerous. The level of danger hasn't gotten worse in that one respect. The level of trust might have changed. The acceptance of risk might have changed. I don't think that keeping my kid away from the lawn mower in order to protect them makes their life overall better or even safer. Lawn mowers are dangerous. But that doesn't mean they should be banned. As you…

How many people are killed by lawnmowers on a yearly basis?
Post reply on HN