Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

591–600 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#591

Earlier quoted context omitted.

> Switzerland and several other Eurpean countries have very high rates of gun ownership, but low rates of gun violence. They also have vastly stricter gun regulation laws, and while ownership rates are high in some, the US is an extreme outlier and no other country comes even close. Because nobody in any European country thinks they have a "right" to own a gun, most of them could if they wanted to, but they simply do…

The fact so many people feel they need a gun for safety is the first and biggest issue IMO. This is fueled by movies and culture - have the gun in your possession and you’ll automatically win the fight - that was easy! I’ve read countless comments from Americans that they have a gun to shoot intruders. Statistics telling you there’s a bigger chance someone else will get hurt be damned. These ideas are have to be fuel…

> Statistics telling you there’s a bigger chance someone else will get hurt be damned

Nobody believes the statistics are relevant to them. Statistics are about all those dumb other people; but I'm always the smart, responsible exception.

Re: EU Draft Council Declaration Against Encryption [pdf]

#592
Anti-encryption is a red herring.

The real fight is against general purpose computing. If I control my CPU, then I can easily implement the Diffie-Hellman algorithm and communicate secretly with my friends around the world. Any ban against encryption is ineffective unless it attacks general purpose computing. We live in scary times!

Re: EU Draft Council Declaration Against Encryption [pdf]

#593

Earlier quoted context omitted.

Personally I believe it’s about individualism vs the collective. Here in Sweden we’ve seen a horrible development regarding gun violence - easy to chalk up to “immigration” and “soft laws” but in my mind it’s a lot deeper - interesting enough this is at the same time we have a record amount of dollar millionaires in the country. We used to work as a collective but our economic policies are turning more and more neoli…

Isn't the majority of crime in Sweden committed by migrants ? https://link.springer.com/article/10.1007/s12115-019-00436-8

It appears this study shows that the majority of suspects for crimes are immigrants, which is an important distinction. I have no knowledge about the situation in Sweden, but in Germany there are known statistical problems like immigrants both having a higher chance of becoming suspects ("Tatverdachteffekt") and crimes where an immigrant is suspected are more likely to be reported ("Anzeigeeffekt").

Stastistics about suspects are most commonly used in studies like these because the police, due to the seperation of powers, usually has no or at least less statistics of the actual results of charges.

Re: EU Draft Council Declaration Against Encryption [pdf]

#594

A middle ground in the encryption/privacy debate seems to be "the authorities can spy on what I do, but have to notify me first ". That could be implemented by having full e2e encryption as today, but requiring clients to hand over the keys when requested by a local governing authority. The client/app would then immediately show to the user "Local Authorities have viewed a copy of this message". Why isn't this middle…

I don't know why they are not proposing this instead (well, I do, because they'd prefer more power), but I do not find this proposal acceptable either. The fact that you might be able to see that a government read a message of yours offers little assurance that the government will not start abusing this power. After all, what possible recourse do we have after we start seeing these notifications on our messages? Cert…

The key to all this is probable cause. Which is exactly what the mass data harvesting operations are seeking to circumvent.

Re: EU Draft Council Declaration Against Encryption [pdf]

#595

A middle ground in the encryption/privacy debate seems to be "the authorities can spy on what I do, but have to notify me first ". That could be implemented by having full e2e encryption as today, but requiring clients to hand over the keys when requested by a local governing authority. The client/app would then immediately show to the user "Local Authorities have viewed a copy of this message". Why isn't this middle…

Even in the case of an investigation, there's the option for the authorities to request a time lag.

There's lot of options, we need to discuss this in depth weighing them all.

Re: EU Draft Council Declaration Against Encryption [pdf]

#596

I want to also give some perspective why this is bad even IF we can make sure that only governments will have the keys. We have just uncovered an organized crime at the top levels in Slovakia where even the President of police is part of it and they influenced many court cases and were accessing secret information and databases on citizens, basically a mafia. And we are part of EU. I don't trust our goverment to use…

Government is just another group of people. We currently have few statesmen in politics, only people afraid to loose control and this is a symptom that has haunted us for over 30 years. Any cooperation with the EU on these issue should be denied. Many people are way ahead of constitutions and democratic legitimacy.

Re: EU Draft Council Declaration Against Encryption [pdf]

#597
post #570

Earlier quoted context omitted.

What about this tech-agnostic version: citizens have a right to deprive the unrelated citizens from accessing their communications using any means . Note that this includes E2E encryption, whisper, face-to-face private conversation, rubberhose encryption, noise insertion and steganography all in one.

Some idiot will cut off someones ears and then say to the police that, "it was to deprive him of accessing our communications by using any means. It says so in the law, Sir!"

It would still be criminal on the grounds of breaking the bodily integrity, which is an infringement of someone else's life and health, which is normally considered more protected than privacy.

Re: EU Draft Council Declaration Against Encryption [pdf]

#598

https://matrix.org/blog/2020/10/19/combating-abuse-in-matrix... is our attempt at Matrix to spell out what a catastrophic idea it is to backdoor end-to-end encryption (and to provide an alternative proposal in the form of using decentralised reputation to mitigate abuse. We're kicking decentralised reputation work off in earnest tomorrow, so watch this space to see how it goes). I guess we'll be weighing in on the EU…

While adding backdoors to encryption is a bad idea my gut sys decentralized reputation is just a bad. Most here know the Black Mirror episode "Nosedive". But it's worse than that, people on different sides of the political spectrum will work to "cancel" people of the other side by working to lower their rep via crowdsourcing. 4chan type groups will do the same for "the lulz", I can even imagine the ransomware people…

My suspicion is that this system is a cop-out, like when Google blames their screw-ups on "the algorithm".

There probably has been a recent surge of right-wing users and, the Matrix administrators, which probably lean left-wing, have seen that surge as a problem and have created the reputation system as a way to get rid of those users or, at least, to give them the hypothetical yellow badge. And if someone says "censorship", they will blame it on the "downvotes" those users got.

Re: EU Draft Council Declaration Against Encryption [pdf]

#600

Earlier quoted context omitted.

I'm going to start naming a few major government security breaches: + TSA keys + OPM (all of it) + NSA's hacking tools Were these incredible skilled sidechannel attacks? Movie esque infiltrations? + TSA accidentally published the keys + OPM was a master password from a contractor who was bribed for about the cost of an ipad + NSA hacking tools was.. an email trojan? A CD walked? Do you really trust these people with…

> Putting a backdoor into encryption is less secure than a random Microsoft employee backdooring me. At least I know it's Microsoft who will be doing the backdoor... My point isn't about how much you trust Microsoft, but that Microsoft has keys , which are more easily stolen and in many regards more valuable than the scheme I gave. > TSA keys Not remotely comparable. These were never designed to be secure in the sens…

Basically all your arguments have been proved false in a short amount of time. Agencies could not name a single case where mass surveillance helped. And don't kid yourself, if you have a master key to encryption, it is mass surveillance you try to implement and it will be used as such.

We had security agencies that had the info but didn't act in case of Vienna. Encryption wasn't the issue here, this is an incontinent case of saving face at best, a deliberate attack against civil rights at worst.

> These were never designed to be secure in the sense we're talking here

Encryption today is a protection against access for a limited amount of time. It is an intrinsic rule about every encryption algorithm. It is fundamental property and widely known.

Post reply on HN