Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

581–590 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#581
post #4

We need to establish the use of encryption as a basic human right. I'm so tired of this cropping up every couple years.

I completely agree with that.

I was born and raised in a country occupied by communist invaders, so I know very well how unbelievably horrific it was to live under continuous surveillance.

Despite the many Western fiction works, either movies or novels, which attempted to describe how life was in the Eastern Europe and Soviet Union, I have not seen any that succeeded to really convey how awful that was, because it is very difficult to imagine it when you have not experienced it.

After 1990 there was a short time when things seemed to be improving in the world, about the human rights, but that did not last for long.

After 2000, the Western countries began to resemble more and more every year with the communist countries they were formerly criticizing.

This sad evolution concerns not only the continuous attempts to restrict the basic human rights but also the continuous reduction in competition in the economy, by more and more mergers and acquisitions.

Despite what some say, the socialist economies were not really different from the capitalist economies, but they were identical to the extreme form of a capitalist economy, where, in the absence of regulation, everything is produced by monopolies. Now, with the exception of few domains where there is still vigorous competition, even the American economy is so much dominated by quasi-monopolies, that it resembles more to the old Russian economy than to the American economy of 30 years ago.

Twenty years ago, when I designed some electronics hardware, I could search the Internet for the datasheets and manuals of possible components and I had many possible choices for each of them.

Now, for many key components, I have only one possible source. Moreover, for many important components that I might use, I cannot really determine whether they could be used, because their technical documentation is provided only after signing an NDA and only if you intend to buy really large quantities.

Such changes were very gradual, so for those who did not live enough to span several decades of experience, the way things are done now may seem normal, but they are not and they are definitely worse than before. Now it is far more difficult to innovate.

Regarding surveillance and encryption, most Western people, who have not yet experienced the extreme abuses towards which the current legislation slowly evolves, are very naive and they do not understand how dangerous this really is.

The irony is that now the Western countries are trying to make lawful things that not even the communists had the courage to introduce in their laws.

Even in the communist constitution that was valid when I was a child there were constitutional rights for the secrecy both of the phone conversations and of the mail messages.

Obviously, like the NSA, the secret police did not care about what is lawful and what is not, so they intercepted any mail message or phone conversation they desired, but at least there was no doubt that their activities are illegal. Fortunately, they did not have the technical abilities to intercept all the phone & mail communications, like today. Otherwise I would be still living in a communist country.

Because of my experience, no matter what abusive laws might be introduced in the future by corrupt politicians and no matter which would be the consequences, I would never recognize that any other human being has the right to command me to not encrypt any information that belongs to me. Equivalently with being against the interdiction of encryption, I would also never accept that any human being has the right to demand that I must answer to any question, if I do not want to answer.

Of course, if that question had been in the context of a legal investigation, refusing to answer some question may be considered as evidence supporting the supposition that the questioned person might have done something wrong. Therefore that person might be punished for what he/she is supposed to have been done, if being guilty is considered certain enough.

However, punishing the person just for refusing to answer a question, without any evidence strong enough that the person has committed any other crime, as it is frequent now in the USA, this is something that I consider to be an unacceptable abuse and a breach of the most basic human right.

Re: EU Draft Council Declaration Against Encryption [pdf]

#582

So apparently no-one read the article itself Read it, it's in English and it's pretty straightforward > technical solutions for gaining access to encrypted data must match the principles of legality, necessity and proportionality. > Since there is no single way of achieving the set goals (read, banning or limiting encryption), governments and industry need to work together to create this balance See https://twitter.c…

Buried very deeply in the comment section, yet the best response.

Re: EU Draft Council Declaration Against Encryption [pdf]

#583
A middle ground in the encryption/privacy debate seems to be "the authorities can spy on what I do, but have to notify me first".

That could be implemented by having full e2e encryption as today, but requiring clients to hand over the keys when requested by a local governing authority. The client/app would then immediately show to the user "Local Authorities have viewed a copy of this message".

Why isn't this middle ground being discussed?

I understand authorities don't want to alert their targets about an investigation, but let's be honest - if they read the messages and find you've done some crime, authorities will eventually track you down.

Re: EU Draft Council Declaration Against Encryption [pdf]

#584
post #563

Earlier quoted context omitted.

> They aren’t directly elected, but the minister is from the government of each country, which is elected (at least as most understand the term) Many ministers are initially elected to posts in their national parliament and then promoted into a government job. But this is not a real requirement, and many aren't. And even those that we elected, we elected for national jobs, not for the EU, and I do think that that mak…

Unless your country has joined the EU since your last election then you know you know you are electing a government head. Technically you tend to vote for a local representative who then elect the head of governemt but that’s not how people see it, just like they think they vote for Trump or Biden, but they actually vote for electors who could vote for anyone. Generally we don’t have a directly elected ministers in E…

> Unless your country has joined the EU since your last election then you know you know you are electing a government head. [...] Generally we don’t have a directly elected ministers in Europe, [...] they are selected by the head of government.

This is all mostly true. But also very indirect, yes? I remember the discussions about the EU constitution project and the treaty of Lisbon, and this system with national government representatives was sold to us as a necessary democratic counterweight to the "dominance" of the most populous states (especially Germany) in Parliament. I acknowledge the need for some kind of balancing between pure population majority one the one hand and the needs of smaller states on the other hand. A proper elected "upper house" similar to the US Senate, with a fixed number (more than two!) of members from each member state, would be vastly superior to the current system.

(Also, when the corrupt Austrian government collapsed last year, it was replaced for half a year with an "expert cabinet", with a chancellor and ministers who were all very capable and all, but not politicians, and never elected for any position. https://en.wikipedia.org/wiki/Bierlein_government They did refrain from big EU-level moves, but nothing would have stopped them.)

Re: EU Draft Council Declaration Against Encryption [pdf]

#585

Earlier quoted context omitted.

While I know I'm just attracting downvotes, your points, in order: 1) a: It's really not that hard to think of ways to solve backdoor problems with a mix of technical and social approaches. For example, having shared keys burned onto silicon, making physical access mandatory, and split between both the law enforcement and the company, so that both parties must knowingly engage. b: Most software already practically ba…

1a - Because that worked out so well for HDMI? It'll be what, maybe 90 days before those "law enforcement keys" are public? 1b - If it's already backdoored then there is no need for such an act, the problem is already solved. 2 - It's ineffective for it's stated goal because the stated goal is not the real goal. The goal is to enable a continued abuse of power, one which is already ongoing, and one which produces no…

>and yet the government remains terrible at solving either problem

You don't kill the cash cow.

Re: EU Draft Council Declaration Against Encryption [pdf]

#586

A middle ground in the encryption/privacy debate seems to be "the authorities can spy on what I do, but have to notify me first ". That could be implemented by having full e2e encryption as today, but requiring clients to hand over the keys when requested by a local governing authority. The client/app would then immediately show to the user "Local Authorities have viewed a copy of this message". Why isn't this middle…

I think this sounds like a fair proposal

Re: EU Draft Council Declaration Against Encryption [pdf]

#587

Earlier quoted context omitted.

Disclaimer: I've made - very minor - contributions to the 2017 proposal to enforce mandatory E2E encryption (as a technical consultant, I have no political role of any kind) How does that follow? I am as free as anybody else in the EU to use any chat software I want. This is just a proposal and ha no value in itself until it is approved and ratified by the single parliaments in the EU countries. EU is not some tirann…

They literally are proposing to kill the freedom to communicate and you say there is nothing to worry about?

That's a bit catastrophic.

First of all, I don't about you, but I am European and have been actively involved in the process of bringing encryption to all of EU citizens, as an obligation to the companies that supply communication software.

I trust the people of EU, on the other hand you seem not to trust other's people capabilities, not even your own parents

> "Apple does know better than the vast majority of its users. It's why I buy, and properly configure, iPhones for my senior citizen parents."

https://news.ycombinator.com/item?id=25032742

I would never talk like that of my mom and dad.

Anyway, back to the point: there is always a tension to find a middle ground between two different opposing interest: one is privacy and secrecy the other is safety.

You probably know technology better than me, you probably know there are technical solutions to the problem that, obviously, involve having some fate that the public servants will exercise the necessary due diligence.

One possible solution that popped out of my mind is to use the same functionalities chat applications use for groups (not because I agree, but because it is possible without compromising too much what we already lacked anyway - secrecy and privacy).

When you have an E2E encrypted group chat every person in the chat receives the encryption keys and messages are encrypted by each sender, signed, sent to the server that than forward it to any participant in the group.

Or you could do it the PGP way, each recipient has its own keys and the message is encrypted for each one of them.

What we need is to add to it separation of church and state.

The state is always participating in these chats, meaning that it always receives a pair of keys, but it has no access to the actual encrypted data, that is stored by the provider and inaccessible by anyone else unless authorized by the justice system.

Nobody, except the key owner, jas the keys to drecrypt them anyway.

It is exactly how it worked before with phone calls, companies kept records of calls and SMS, but they could only be accessed from authorized actors.

Records and keys would expire after a period of time (it was 10 years for phone calls)

objection 1: it means WhatsApp and the other will keep records of my communications -> they are already doing it anyway

objection 2: it would take a lot of space -> they are already doing it anyway

objection 3: that would give the state power over my communications -> it already has it

objection 4: that means anybody could decrypt my messages -> not really, and it would be a crime, you can't prevent crimes by not doing things, in any case it would be easier to steal your phone.

Re: EU Draft Council Declaration Against Encryption [pdf]

#588

A middle ground in the encryption/privacy debate seems to be "the authorities can spy on what I do, but have to notify me first ". That could be implemented by having full e2e encryption as today, but requiring clients to hand over the keys when requested by a local governing authority. The client/app would then immediately show to the user "Local Authorities have viewed a copy of this message". Why isn't this middle…

This is known as a key disclosure law. We have such a law already in the UK.

* https://en.wikipedia.org/wiki/Key_disclosure_law

* https://www.schneier.com/blog/archives/2007/10/uk_police_can...

* https://www.theregister.com/Print/2007/10/03/ripa-decryption...

Re: EU Draft Council Declaration Against Encryption [pdf]

#589

A middle ground in the encryption/privacy debate seems to be "the authorities can spy on what I do, but have to notify me first ". That could be implemented by having full e2e encryption as today, but requiring clients to hand over the keys when requested by a local governing authority. The client/app would then immediately show to the user "Local Authorities have viewed a copy of this message". Why isn't this middle…

I don't know why they are not proposing this instead (well, I do, because they'd prefer more power), but I do not find this proposal acceptable either.

The fact that you might be able to see that a government read a message of yours offers little assurance that the government will not start abusing this power. After all, what possible recourse do we have after we start seeing these notifications on our messages? Certainly the government won't start telling us the exact reason they are snooping. The very fact that your conversations had been snooped on by the government might imply there is something shady about you. Where there is smoke, there's also fire, right? And this still has us relying that governments won't start pressuring clients to have special code which bypasses the notification when it is convenient for them.

No. The government must not be allowed to deny the citizen his right to have private conversations.

Re: EU Draft Council Declaration Against Encryption [pdf]

#590
If you are accused of something you have a right to remain silent. Wouldn't this proposal violate this? If you spy on someone's communication you essentially change the audience to whom the accused may not wish to speak to. I understand that the authorities want to catch the bad people, but where does it end? Should we accept having a civil servant and their handler in our homes? Should we have weekly polygraph testing? What if someone speaks in a code, that is the spoken sentences will have a different meaning than what language would suggest? What if someone speaks their mother tongue, is that going to be classed as circumvention of surveillance? Why this is even an official proposal?
Post reply on HN