Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

501–510 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#501

Earlier quoted context omitted.

So really it wouldn’t be encryption so much as right to have secrets. Because whether I use EDCA or a really strongly in crackable safe, my right to privacy should be a thing? It sounds like somewhat of a stronger version than the US’s fifth amendment which says that you have a right to privacy unless it has to do with the crime currently being investigated. And come to think of it, encryption is unconstitutional as…

Wouldn't you want the word 'encryption' to be in the description, so there is no evil solicitor trying to argue about what 'secrets' meant. Or 'the right to confidentiality whenever, where-ever, and with whomever the person pleases'

But I would also not want the method of storage of secrets to become obsolete. The important thing is that I’m able to keep a secret, not how the secret is stored. For example, say quantum encryption comes to be known as “q-store” and is always said to be different from encryption. Now, what does that do to my rights if I move from traditional encryption to quantum algorithms?

Re: EU Draft Council Declaration Against Encryption [pdf]

#502
post #264

Earlier quoted context omitted.

What about proposing encryption as an EU human right? Has that been attempted?

I'd of thought that Article 8 of human rights would encompass this. https://www.equalityhumanrights.com/en/human-rights-act/arti...

That's right to privacy, not right to encryption specifically. And governments cracking down on encryption will, of course, claim that it is a matter of national security, and is a proportionate action to fight terrorism, child pornography, and other crimes.

Re: EU Draft Council Declaration Against Encryption [pdf]

#503

Earlier quoted context omitted.

> What about proposing encryption as an EU human right? Has that been attempted? Rights conflict. Every new right influences the others. It is easy to shorthand every problem to a human rights declaration. But just like the right to bear arms, that can have unintended consequences.

You did not define a conflict or the unintended consequence here

The unwanted consequence of the US second amendment is that the US has one of the highest gun death rates in the developed world.

Re: EU Draft Council Declaration Against Encryption [pdf]

#504

Earlier quoted context omitted.

What about proposing encryption as an EU human right? Has that been attempted?

So really it wouldn’t be encryption so much as right to have secrets. Because whether I use EDCA or a really strongly in crackable safe, my right to privacy should be a thing? It sounds like somewhat of a stronger version than the US’s fifth amendment which says that you have a right to privacy unless it has to do with the crime currently being investigated. And come to think of it, encryption is unconstitutional as…

> encryption is unconstitutional as in because the government can subpoena or obtain a warrant to your information it may not be able to enforce it because of the encryption

No, you can't subpoena information from someone that doesn't have it. So the government can subpoena the cyphertext, but can't ask for the plaintext if the provider never had access to it.

Re: EU Draft Council Declaration Against Encryption [pdf]

#505
post #465

Earlier quoted context omitted.

HN needs to come together to reward 'dang's hard work keeping HN to HN quality. I have this theory that with almost any great music groups there's usually one, sometimes two, great mind(s) working in the background, usually introverted, that really define the talent of the wider group (Brian Wilson, Quincy Jones, Phil Spector, etc are the rare few who got that recognition). NYT did a great exploration of how this cur…

> The Aussie girl is in the NYT clip who basically made the song still lives in relative obscurity (you can find her on twitter, probably well paid, but still living without much fanfare), despite this song among others blowing up in the charts. The sad part is they don't even name her in the summary. She's "a 23-year old songwriter". The famous producers and vocalists get named, but she doesn't.

Some people might prefer lucrative obscurity?

Re: EU Draft Council Declaration Against Encryption [pdf]

#506

Earlier quoted context omitted.

1a - Because that worked out so well for HDMI? It'll be what, maybe 90 days before those "law enforcement keys" are public? 1b - If it's already backdoored then there is no need for such an act, the problem is already solved. 2 - It's ineffective for it's stated goal because the stated goal is not the real goal. The goal is to enable a continued abuse of power, one which is already ongoing, and one which produces no…

> Because that worked out so well for HDMI? It'll be what, maybe 90 days before those "law enforcement keys" are public? This is a completely different context to having one copy (or a small number) of said low-bandwidth silicon held exclusively by an agency vested in keeping it exclusive, plus another copy held by the company themselves, such that both copies would need to be broken for security to be weakened. > If…

I'm going to start naming a few major government security breaches:

+ TSA keys

+ OPM (all of it)

+ NSA's hacking tools

Were these incredible skilled sidechannel attacks? Movie esque infiltrations?

+ TSA accidentally published the keys

+ OPM was a master password from a contractor who was bribed for about the cost of an ipad

+ NSA hacking tools was.. an email trojan? A CD walked?

Do you really trust these people with anything?

Putting a backdoor into encryption is less secure than a random Microsoft employee backdooring me. At least I know it's Microsoft who will be doing the backdoor...

This isn't politics, this is history. This is not the first time, nor the last time we've seen these moves. We know 5 eyes have had major incidents of internal abuse because we have their own documentation on it - and we have their own documentation that they decided to do nothing about it.

It requires external oversight for any organization to truly follow compliance, otherwise the incentives to cheat the system are overbearing. If they won't take us at our word, why would we take them at theirs?

Re: EU Draft Council Declaration Against Encryption [pdf]

#507
Anyone else getting mixed messages here? Seems like the TL;DR is something like "Encryption is great and helps people be safe and also for our own safety we need the ability to break encryption"

I also don't see how they can propose with a straight face that encryption is important in securing human rights while advocating for governmental ability to break encryption.

Re: EU Draft Council Declaration Against Encryption [pdf]

#508

Earlier quoted context omitted.

> Because that worked out so well for HDMI? It'll be what, maybe 90 days before those "law enforcement keys" are public? This is a completely different context to having one copy (or a small number) of said low-bandwidth silicon held exclusively by an agency vested in keeping it exclusive, plus another copy held by the company themselves, such that both copies would need to be broken for security to be weakened. > If…

I'm going to start naming a few major government security breaches: + TSA keys + OPM (all of it) + NSA's hacking tools Were these incredible skilled sidechannel attacks? Movie esque infiltrations? + TSA accidentally published the keys + OPM was a master password from a contractor who was bribed for about the cost of an ipad + NSA hacking tools was.. an email trojan? A CD walked? Do you really trust these people with…

> Putting a backdoor into encryption is less secure than a random Microsoft employee backdooring me. At least I know it's Microsoft who will be doing the backdoor...

My point isn't about how much you trust Microsoft, but that Microsoft has keys, which are more easily stolen and in many regards more valuable than the scheme I gave.

> TSA keys

Not remotely comparable. These were never designed to be secure in the sense we're talking here.

> OPM (all of it)

> NSA's hacking tools

Hence the scheme I gave, which isn't vulnerable in the same way.

Re: EU Draft Council Declaration Against Encryption [pdf]

#509
post #482

Earlier quoted context omitted.

Kanye might tweets some crazy stuff but his recent crusade against shitty record contracts (tweeting out his entire Warner contract deal for example and calling out real owners to stop robbing kids) and the general nonrecognition of the artists themselves is something I can get behind. https://www.gq.com.au/entertainment/music/heres-the-rundown-... I almost went into the music industry before programming which is why…

Kanye is himself a shitty record label. He signs people promising to produce their record or feature him on his albums and then dumps them.

I was worried mentioning his name would take this thread off-topic and become all about Kayne. I'm neither an expert on GOOD Records's past nor seek to defend him in general. These arguments applies generally to the industry as a whole and are hardly limited to just to Kanye himself.

The way I came across his statements on the matter was that it was a sort of recent revelation he had. And that it's a thing thats out in the wide open, people have been talking about it for a long time, but it's still just the way it is. The labels have a ton of power, regardless of the changes in the industry.

It's reminds me of entrenched businesses exploiting out-of-date regulatory systems. Like trying to apply the old taxi car numbers cap / medallion model to Ubers system just doesn't make sense at all.

The internet changed the music industry even more than taxis. Especially with artists becoming social media 'influencers' in the process (and almost as a pre-requirement) and more of the power is going back into their hands.

So I support anything that gives the artists more control of their masters/content, more say in the room about distribution since it's not all backroom radio shows and record store deals like it used to be.

When you have soundcloud rappers getting famous with zero major label help its just basic logic that the old-school contracts, major parts of which are still apparently being used frequently by the big labels, will need updating.

Certain power dynamics have clearly changed.

I'm not a lawyer and don't have all the answers but it is an opportunity for more decentralized control and wealth going back to the creators and promoters more directly.

Re: EU Draft Council Declaration Against Encryption [pdf]

#510

I see this as follows: 1. Terrorism and trafficking of children will win the moral high ground. 2. App stores will be forced locale by locale to conform to these policies. 3. Most people will not notice or care. 4. This will be used by N-Eyes and totalitarian governments to quash dissent. 5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely. 6.…

Law enforcement clearly thinks it has a need for tools to combat terrorism and child trafficing. EDRi has prepared list of tools that don't need encryption to be broken: https://edri.org/files/encryption/workarounds_edriposition_2...
Post reply on HN