Live data from Hacker News

Real people don't need end-to-end encryption says UK Home Secretary

uk.businessinsider.com

81–90 of 92 posts

Re: Real people don't need end-to-end encryption says UK Home Secretary

#81

Earlier quoted context omitted.

The follow up bill which makes it mandatory to have government spyware on all https servers?

They can't do that because it would require major open source web servers to be forked. There's no way they're going to persuade operators in other countries to run UK government spyware.

Yes, UK can just enforce that all SSL certs come from their CA. If they find an invalid SSL cert, they come arrest you, shut you down, or confiscate your equipment (or all 3!)

Re: Real people don't need end-to-end encryption says UK Home Secretary

#82
post #50
post #36

Earlier quoted context omitted.

... or connecting with SSL to an overseas server under their control ?

Jailed for use of an illegal encryption scheme. Welcome to the future.

Not just the future: https://en.wikipedia.org/wiki/Illegal_number

Re: Real people don't need end-to-end encryption says UK Home Secretary

#84
post #64

Earlier quoted context omitted.

"on the advice of her ministers"

Sure, but couldn't a single cabinet member advise the Queen to withhold assent? As long as they made a compelling argument, the Queen could do so. I'm not claiming this is likely or desirable, only possible in the most extreme situation.

It's generally thought she can exercise her reserve powers precisely once, before they (or the monarchy) are removed for good. Personally ordering the armed forces not to take some antidemocratic action demanded by her ministers in a time of crisis is the most likely scenario, I think.

As with much else in the constitution, the 'on the advice of her ministers' is normally (binding) convention rather than statute.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#86
post #10

I don't think her statement actually says "real people don't need end-to-end encryption". I'm not sure what she is saying though. Not banning end-to-end encryption, not asking for back doors, but having "mature conversations" that have something to do with trade-offs between usability and security. What?

These conversations are about being able to decrypt the conversations without using the term backdoor. The government will see them as mature if it is given access.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#88

> Real people often prefer ease of use and a multitude of features to perfect, unbreakable security. So this is not about asking the companies to break encryption or create so called "back doors". Who uses WhatsApp because it is end-to-end encrypted, rather than because it is an incredibly user-friendly and cheap way of staying in touch with friends and family? Companies are constantly making trade-offs between secur…

She's basically saying you could remove E2E encryption from WhatsApp and a significant number of people would still use it willingly. Most wouldn't even notice the difference.

And she's alarmingly right in that regard.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#89

Hilarious! Let's criminalize privacy and ask pointed questions to those who seek it. Staggering double speak from Orwell's own land. Who would have thought. Question: Is a terrorist more a threat to civilization or these closet totalitarians crawling out of the woodwork?

Orwell wrote 1984 as a warning. Not an instruction manual.

Re: Real people don't need end-to-end encryption says UK Home Secretary

#90

Earlier quoted context omitted.

its only a matter of time before the USA outlaws these also. I know the agencies are itching for it. Even though it would be unworkable.

Keep dreaming. Forced to choose between the agencies and big business who do you think the legislators will choose? Sure they can side with the agencies but if business isn't on-board with that checks will get written and there will be new legislators. I hope the agencies force the choice. It gives the legislators a chance to do all the things they should have done after Hoover left.

I really do hope you are right.

I do remember Big Business complained about HTTPS use, coz it blocked them "hoovering"/vacuuming up customer info. (excuse the pun)

Also, the Govt has liaison people with some of the Big Corps. Not to mention big corps give big checks to both sides, as routine, there is no financial hurt on the Pol Parties ever sadly. ATT for instance gets paid millions to give up the data.

Update: I just read Amber Rudd (UK Pol goon) created the "Global Internet Forum to Counter Terrorism with Facebook, Microsoft, Twitter and YouTube (Google/Alphabet, Inc.) and asked them to remove end-to-end encryption from their products "

Post reply on HN