Live data from Hacker News

If David Cameron bans secure encryption he can't intercept

blog.mythic-beasts.com

71–80 of 104 posts

Re: If David Cameron bans secure encryption he can't intercept

#71
post #69

It's pretty clear that the UK government doesn't have the power to ban encryption. This is just a distraction so that we are happy to accept whatever "less bad" proposals they come up with to increase their surveillance powers. I can't help but feel that peoples dislike of Cameron is a pointless distraction too. This is not Cameron. This is government. We will still be having this same discussion in 50 years, unless…

So... how close are we to tech that will make encryption universal and surveillance impossible, if so desired?

You are running on it right now, so pretty damn close. :)

Re: If David Cameron bans secure encryption he can't intercept

#72
post #44
post #24

Except Cameron wants to backdoor end-to-end encryption like iMessage/Whatsapp, rather than mess with something like SSL. With SSL they can just get a warrant (or you know, don't get a warrant) and look at the server, where everything is in plain text. One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the pers…

I would be very surprised if Apple and Facebook (and Google, with GMail, GTalk, Hangouts, etc) didn't use this golden opportunity to swing their weight about and assert who's really in charge of technology around here, by simply wholesale blocking use of all their communication tools in the UK to comply with the law. I have a feeling that if they did this, the uproar would be sufficient to have the law reversed by em…

They're businesses though; not rights organizations. Those billions of pounds would also be on them.

Google at least has allowed backdooring before with PRISM, and probably will again in the future.

Re: If David Cameron bans secure encryption he can't intercept

#73
post #52
post #44

Earlier quoted context omitted.

I would be very surprised if Apple and Facebook (and Google, with GMail, GTalk, Hangouts, etc) didn't use this golden opportunity to swing their weight about and assert who's really in charge of technology around here, by simply wholesale blocking use of all their communication tools in the UK to comply with the law. I have a feeling that if they did this, the uproar would be sufficient to have the law reversed by em…

Doesn't this seem insane? You are advocating punishing some 64 million people because of one idiot.

The point is to get those 64 million people to tell the one idiot to stop being an idiot.

Re: If David Cameron bans secure encryption he can't intercept

#74
post #44
post #24

Except Cameron wants to backdoor end-to-end encryption like iMessage/Whatsapp, rather than mess with something like SSL. With SSL they can just get a warrant (or you know, don't get a warrant) and look at the server, where everything is in plain text. One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the pers…

I would be very surprised if Apple and Facebook (and Google, with GMail, GTalk, Hangouts, etc) didn't use this golden opportunity to swing their weight about and assert who's really in charge of technology around here, by simply wholesale blocking use of all their communication tools in the UK to comply with the law. I have a feeling that if they did this, the uproar would be sufficient to have the law reversed by em…

Quite seriously, if there was any collusion between companies which had operations on UK soil, I'd imagine this could be seen as cartel-like behavior and grounds for legal action within the UK.

Of course, if only the UK was part of the Trans-Pacific Partnership... then Google and Github might be able to take the UK government to private court to protest the law in the first place, and sue for lost profits... wait... what...

Re: If David Cameron bans secure encryption he can't intercept

#75
post #7

Honestly, it sounds kind of relaxing. Good excuse to get some sunshine. On a more serious note, I can't help but think David Cameron is employing the technique of attempting something extreme so that he can do something less extreme (but still really bad) later with less oversight. Of course you can't ban strong encryption. His advisers know that, he knows that, _everyone_ knows that. It will be very interesting to s…

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

Possibly in a form of disappearing SIM card.

Re: If David Cameron bans secure encryption he can't intercept

#76
post #62

Earlier quoted context omitted.

The one idiot they technically elected (or at least allow to control the wheel). Ultimately, it's the people's right and responsibility, not one man.

Hahaha! Only 37% of people voted for that guy... So how we are culpable I don't know!!

37% of the people who turned up. 24% of adults.

Re: If David Cameron bans secure encryption he can't intercept

#77
post #22
post #17

Earlier quoted context omitted.

Who are the security services employed by? I certainly wouldn't call them private industry! Did you mean to say it's not elected government officials? Just curious, because I definitely consider a country's intelligence apparatus to be completely and wholly part of its "government", and would be surprised to find someone who didn't.

Read about the Dulles brothers. They forged very strong connections between overt and covert foreign policy and industry.

they sacrificed >100k guatemalans on the false pretence that they had to 'stop a communist state in their hemisphere' - we later found out it was all made up rubbish (this was after the people were dead) and the actual reason was because their mates were in united fruit company.

Re: If David Cameron bans secure encryption he can't intercept

#78
post #7

Honestly, it sounds kind of relaxing. Good excuse to get some sunshine. On a more serious note, I can't help but think David Cameron is employing the technique of attempting something extreme so that he can do something less extreme (but still really bad) later with less oversight. Of course you can't ban strong encryption. His advisers know that, he knows that, _everyone_ knows that. It will be very interesting to s…

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

Do you honestly think that could happen? How? Who would co-operate? Which OS or browser vendor would knowingly distribute such a certificate? Not even Microsoft or Apple would co-operate, let alone Mozilla or the Linux distros...

And it's not as if they can do it secretly. If they suddenly started to MITM all TLS traffic in the country by replacing the certs with certs signed by the national root, it would get noticed within minutes, if not seconds. And God only knows how much stuff it would break. And on top of that, they don't even have the capability...

There is 0% chance they would attempt such a thing. And 100% chance that such a thing would fail immediately and fail badly. I don't know why people think there is even a slight risk of them trying such a thing. There isn't.

Re: If David Cameron bans secure encryption he can't intercept

#79

Earlier quoted context omitted.

Given current trends, I'm guessing national root certificate as a license to MITM all traffic.

Do you honestly think that could happen? How? Who would co-operate? Which OS or browser vendor would knowingly distribute such a certificate? Not even Microsoft or Apple would co-operate, let alone Mozilla or the Linux distros... And it's not as if they can do it secretly. If they suddenly started to MITM all TLS traffic in the country by replacing the certs with certs signed by the national root, it would get notice…

>Who would co-operate?

Who can resist a sufficiently determined state that still enjoys popular support? All he has to do is engineer the support for "security" over the long term.

Don't misunderestimate your fellow voters.

Re: If David Cameron bans secure encryption he can't intercept

#80

Earlier quoted context omitted.

Do you honestly think that could happen? How? Who would co-operate? Which OS or browser vendor would knowingly distribute such a certificate? Not even Microsoft or Apple would co-operate, let alone Mozilla or the Linux distros... And it's not as if they can do it secretly. If they suddenly started to MITM all TLS traffic in the country by replacing the certs with certs signed by the national root, it would get notice…

>Who would co-operate? Who can resist a sufficiently determined state that still enjoys popular support? All he has to do is engineer the support for "security" over the long term. Don't misunderestimate your fellow voters.

When resistance is so damn easy, and capitulation so self-destructive, who would co-operate? You could not force a Linux distro or Mozilla to distribute that cert. It could not be done.

[edit] https works based on trust. We trust the browsers and OS vendors to at least try to prevent the CAs from abusing their power. As soon as it becomes obvious that the OS and browser vendors are now letting state actors compromise all traffic, then https is dead in the water and something else will come along. Nobody is going to risk that happening. It would cost too many rich people too much money.

Post reply on HN