Live data from Hacker News

ChatControl: EU wants to scan all private messages, even in encrypted apps

metalhearf.fr

601–610 of 656 posts

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#601
post #583
post #582

Earlier quoted context omitted.

Respectfully, you completely miss the point. You personally, you will still be able to use proper encryption. It's mainstream platforms who won't be. Those platforms will be mandated to scan their own communications. There is absolutely no reason to do this weird encoding stuff. Nobody says that it is illegal to encrypt stuff properly.

Well in that case I will use my silly chained encoding and their fuzzy scans of files on the mainstream platforms will have to figure out what to do with it. For what it's worth I myself do not use these platforms. I just want to get people thinking about mitigating options. I use my own self hosted forums, chat servers, sftp servers, chan servers, voice chat servers and so on. Even then it can be useful to obfuscate…

> I just want to get people thinking about mitigating options.

You should refrain from making dangerous suggestions, I think. Some people may actually need proper encryption.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#602
post #581
post #580

Earlier quoted context omitted.

> In fact it is exactly zero encryption both technically and legally. I am not a lawyer (are you?), but technically you're wrong. "In cryptography, encryption (more specifically, encoding) is the process of transforming information in a way that, ideally, only authorized parties can decode." A caesar cipher is encryption. I don't see why chaining encodings wouldn't be. Technically and legally.

That's for lawyers and judges to work out. I will not concern myself with it. Here is a legal definition: [1] Making text or code unreadable to secure it for transmission or transport. Both the sender, the encryptor, and the receiver, the decryptor, have the means to translate text or code from source language to unreadable, undecipherable gibberish and back. The devices used have a key that is unique to the sender a…

I get your point, we disagree.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#603
post #601
post #583

Earlier quoted context omitted.

Well in that case I will use my silly chained encoding and their fuzzy scans of files on the mainstream platforms will have to figure out what to do with it. For what it's worth I myself do not use these platforms. I just want to get people thinking about mitigating options. I use my own self hosted forums, chat servers, sftp servers, chan servers, voice chat servers and so on. Even then it can be useful to obfuscate…

> I just want to get people thinking about mitigating options. You should refrain from making dangerous suggestions, I think. Some people may actually need proper encryption.

My suggestion has always been to use PGP or OTR for individual messages or individual files. dm-crypt plain with a random cipher/hash/mode combo for filesystems using a 240 to 480 character passphrase which can also be layered and chained.

This is just an alternative if people believe they are not permitted to encrypt something. The threat vector in this topic is fuzzy scanning local and remote. ChatControl uses fuzzy scanning. Encoding can do just as good a job of mitigating fuzzy scans as any level of encryption. Even manual intervention should take a lot of effort just as much as brute forcing a simple encryption password. If we are being honest encrypted files are most often protected by a weak password and the cipher/hash are already disclosed and the key space is usually small. LUKS for example discloses cipher, hash, mode making brute force just a factor of compute power. If an app is chain-encoding and the chain is shared out of band I suspect it will take orders of magnitude more compute time to cycle through every possible combination of encoding and compression.

For fun has anyone decoded my simple message in the thread?

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#604
post #563

Earlier quoted context omitted.

> Not to mention that most people consuming CSAM are not technically savvy. It is known that such material goes through mainstream messengers. The reason is because it works. They're not stupid - they can use signal. The reality is that the privacy options not only exist, they're really good - often better and easier to use than the mainstream stuff. They will just pivot to other tools.

> How do you contact children on mainstream messengers if you can't use mainstream messengers?

The scanning just doesn't include contacting children - it includes CSAM. Talking to kids isn't CSAM. You're talking about something else altogether, and something which is purely hypothetical.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#605

Dear citizens of the EU: If this gets pushed through, you will gradually lose control of your government much like how the people of the UK already lost control of theirs. What are you going to do when the government's interests inevitably drift out of alignment with yours? Start a political movement? You will have the police knocking on your door for criticizing the establishment. Start a revolution? You have no wea…

[dead]

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#606
post #525

Meanwhile, in one part of the EU (Croatia): urgent tax law change is being considered to allow the tax authorities to demand access (passwords, keys, etc) to any electronic/digital device or service used by a person involved with (owning, operating, or just working in) a business, "to combat tax fraud". No warrants necessary.

Can you please give a source on this? t. balkanian

https://www.index.hr/mobile/vijesti/clanak/porezna-ce-uskoro...

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#607
post #556

Earlier quoted context omitted.

All falsely flagged communication is. And there will be lots and lots of it, even if it is just a tiny fraction of the total number of messages sent, since the number of messages sent between people is so big. This is the classic problem with statistical methods looking for rare things in large populations which also is why we don't screen everyone for all illnesses all the time - the false positives would do too muc…

If you care about the tiny fraction of the total number being stored by the government, frankly you should care a lot more about all the data being stored by TooBigTech. Feels a bit hypocritical to accept one and not the other. Really, I think that the problem with ChatControl is that it is a weapon for surveillance. Not because of the false positive, but because whoever controls it can decide what gets reported. Dep…

> If you care about the tiny fraction of the total number being stored by the government, frankly you should care a lot more about all the data being stored by TooBigTech.

And what makes you think we don't?

It's much, much easier to stop new incursions into our privacy than to claw back privacy we've already lost. And it's much, much easier to stop the government from violating our privacy than to stop megacorporations accountable to no one for anything other than profit from doing so.

I think seeing hypocrisy here is being extremely uncharitable.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#608
post #449

Earlier quoted context omitted.

> 2) Citizens here may be significantly less armed, but the same is true of government officials, and even law enforcement is significantly less armed. It kind of evens out, unless military gets involved, but at that point all bets are off - no different than in the US. I don't think that's a correct comparison. If shit ever did hit the proverbial fan, you can bet that any US military walking around an American city…

> If shit ever did hit the proverbial fan, you can bet that any US military walking around an American city would be constantly worried about getting a lead injection from any Tom, Dick or Harry who's got a firearm. And then in many scenarios, that Tom, Dick, or Harry gets returned the favor, except with a tank round or worse. If the military remained organized, or at least large factions of it did, it would consider…

> And then in many scenarios, that Tom, Dick, or Harry gets returned the favor, except with a tank round or worse. If the military remained organized, or at least large factions of it did, it would considerably outclass the general population in both intelligence and firepower / strike capabilities.

Tanks are obsolete weapons - esp in urban areas. They would be taken out by cheap drones. And you are forgetting that for every active US soldier there are ~3x retired and opinionated soldiers. Many of them know tactics to take down armor. And how to train civilians.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#609

I regularly see similar articles with similar comments here, but there's one thing I still don't understand: From the European Convention on Human Rights[1]: ARTICLE 8 Right to respect for private and family life 1. Everyone has the right to respect for his private and family life, his home and his correspondence. 2. There shall be no interference by a public authority with the exercise of this right except such as i…

Item (2) is so broad that you could fit anything trough it.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#610
post #304
post #273

Earlier quoted context omitted.

> A few decades ago, all communications were unencrypted and people were fine. A few decades ago, a user base using whatever was available was about 99% lower than now. As well as governments were so illiterate that they could not read with the tech they had even those unencrypted messages.

Snowden was more than a decade ago. The NSA was recording everything .

A few decades ago implies 1990s or early 2000s. In 1990 he was 7 years old. In early 2000 - 17 years old.
Post reply on HN