Live data from Hacker News

EU Draft Council Declaration Against Encryption [pdf]

statewatch.org

631–640 of 780 posts

Re: EU Draft Council Declaration Against Encryption [pdf]

#631
post #601

A middle ground in the encryption/privacy debate seems to be "the authorities can spy on what I do, but have to notify me first ". That could be implemented by having full e2e encryption as today, but requiring clients to hand over the keys when requested by a local governing authority. The client/app would then immediately show to the user "Local Authorities have viewed a copy of this message". Why isn't this middle…

The obvious downside is that anyone who cares about privacy will write their own client, governments will regulate against unofficial clients, platforms will comply with the regulation and lock everything down, and the end result will be users unable to exercise any control over what's installed on their devices.

I can picture this. It's the year 2050. You hear about how a dangerous man was arrested the other day and is being charged with owning an unlawful communication device.

Re: EU Draft Council Declaration Against Encryption [pdf]

#632
post #614
post #535

Earlier quoted context omitted.

While at the same time these governments fail to properly use the information they have and are able to gather through traditional intelligence work properly to avoid the type of attacks they claim putting up backdoors will prevent. Most recently last weeks attack in Austria could have been avoided if the information the authorities received from a neighboring country of an attempt to purchase weapons by the attacker…

Too late to edit my previous post, but here is the article: "Fejzulai is also believed to have travelled to neighbouring Slovakia in July accompanied by another man, where he attempted to buy ammunition suited to the weapons he used in the attack, but the sale reportedly fell through after he failed to produce a firearms licence. Slovakian authorities are said to have informed their Austrian counterparts at the time.…

In the US, most states allow you to order ammo online or via mail order without any license, and shipped to your home.

Re: EU Draft Council Declaration Against Encryption [pdf]

#633
post #323

Earlier quoted context omitted.

I'm certainly open to changing the URL from what is probably an obscurantist press release to a more accurate and neutral source. But it would need to be in English. Sorry—I realize that's frustrating to anyone who reads both languages, but most HN readers can't. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

Please maybe link the revised article from November 6. You can see the changes made in bold: https://files.orf.at/vietnam2/files/fm4/202045/783284_fh_st1... I can't find it from public sources, the REV 1 is referenced here: https://www.parlament.gv.at/PAKT/EU/XXVII/EU/03/62/EU_36280/... But it's marked as not public.

Update: I got an indirect confirmation that the REV1 version of the document should be authentic and they also noted that radiofm4 (ORF) has a good record of previous disclosures.

Re: EU Draft Council Declaration Against Encryption [pdf]

#634

Earlier quoted context omitted.

> Because that worked out so well for HDMI? It'll be what, maybe 90 days before those "law enforcement keys" are public? This is a completely different context to having one copy (or a small number) of said low-bandwidth silicon held exclusively by an agency vested in keeping it exclusive, plus another copy held by the company themselves, such that both copies would need to be broken for security to be weakened. > If…

So you admit defeat on the politics aspect of it? Because every one of your points was political, save for 1a.

This kind of comment is exactly why I'm avoiding the politics side of things. I don't want to subject myself to this sort of bad faith jabbing, as much as it comes with the topic.

Re: EU Draft Council Declaration Against Encryption [pdf]

#636
post #616
post #608

Earlier quoted context omitted.

I would especially like to see a cryptographic mechanism enforcing such middle ground. That is, a mechanism that would allow law enforcement accessing the private key or plain text, but only with some inescapable side effect which would hinder abusing that power. That may be producing a cryptographic "proof of compromise" for the person being spied on, or the spying being publicized, possibly with some delay, or some…

But then again there is a mechanism already, just not cryptographic, and that is police having to physically seize your device. I guess we don't need to work on this. There's nothing special about an E2E communication device compared to other things you may have in your home.

It is much more difficult to get data off an E2E communication device these days because mobile OSes use cryptography to mitigate the consequences of loss and theft. That is why law enforcement agencies want "the support of service providers," who can do things like deploy a backdoored WhatsApp binary, or bruteforce passcodes without triggering data loss. https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...

Re: EU Draft Council Declaration Against Encryption [pdf]

#637
Recently every crime seems to make legislators think it's time to tighten the grip and introduce more laws to fix societal problems, which remain the same, while I and everyone else is forced to abide by more and more absurd laws.

Most recently when criminals went all-out in Austria with guns the police later admitted they knew the attacker was shopping for ammo. What would change if the police knew they were chit-chatting by tapping into their coms as a man-in-the-middle. Likely they would be saying after the attack they were hating the state over whatever-chat while the attacks would happen nontheless. By banning encryption nothing would change but the potential for abuse is incredible.

What we need is less legislation, that actually has some measurable positive effect. It would also help if EU was way more aggressive against countries that sponsored various terrorist groups, overthrew governments and pushed some middleeastern countries back into the dark ages.

Re: EU Draft Council Declaration Against Encryption [pdf]

#638

Earlier quoted context omitted.

Wouldn't you want the word 'encryption' to be in the description, so there is no evil solicitor trying to argue about what 'secrets' meant. Or 'the right to confidentiality whenever, where-ever, and with whomever the person pleases'

But I would also not want the method of storage of secrets to become obsolete. The important thing is that I’m able to keep a secret, not how the secret is stored. For example, say quantum encryption comes to be known as “q-store” and is always said to be different from encryption. Now, what does that do to my rights if I move from traditional encryption to quantum algorithms?

Well it worked for copyright, we're kinda stuck with it, regardless of how much the we ways we store things have changed.

Re: EU Draft Council Declaration Against Encryption [pdf]

#639

Earlier quoted context omitted.

The world is so safe that instead of dying from war, famine or untreatable infectious disease, those in developed countries are dying from diseases of wealth and comfort.

Obesity does not imply over-use of food with high nutritional value. In other words, obesity comes from worse diets. The working classes are bombarded with corporate foods that contain way too much sugar, etc.

Not sure why you're gone all grey there. This is the prevailing thinking in obesity research at the moment. You're more likely to be obese if you're poor than if you're rich.

Re: EU Draft Council Declaration Against Encryption [pdf]

#640

Earlier quoted context omitted.

What about this tech-agnostic version: citizens have a right to deprive the unrelated citizens from accessing their communications using any means . Note that this includes E2E encryption, whisper, face-to-face private conversation, rubberhose encryption, noise insertion and steganography all in one.

I like this "right to deprive" wording and toyed with it myself. Reminds me of the way DMCA anti-circumvention works. Perhaps we could call this the anti-snooping right.

Anti-snooping would be much more useful than anti-circumvention in fact.
Post reply on HN