Live data from Hacker News

ProtonMail, Tutanota urging EU to reconsider encryption rules

cyberscoop.com

81–85 of 85 posts

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#81
post #66

Earlier quoted context omitted.

You're right that they don't want to ban E2E, they want to mandate that they hold the keys to all E2E though.

This is your conclusion but it is not stated anywhere in the resolution.

They mention access to encrypted data severl times:

>Technical solutions for gaining access to encrypted data must comply with...

They do say:

>there should be no single prescribed technical solution to provide access to encrypted data.

But it's perfectly clear the assumption is that they intend law enforcement to have access to all encrypted data, given the various caveats about doing so legally.

They do mention privacy, but all that means is not making user data public. They make no mention of a right to maintain data private from the government or law enforcement.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#82
post #81

Earlier quoted context omitted.

This is your conclusion but it is not stated anywhere in the resolution.

They mention access to encrypted data severl times: >Technical solutions for gaining access to encrypted data must comply with... They do say: >there should be no single prescribed technical solution to provide access to encrypted data. But it's perfectly clear the assumption is that they intend law enforcement to have access to all encrypted data, given the various caveats about doing so legally. They do mention pri…

Okay I understand the concern, but claiming that there is intent to hold keys to all e2ee is jumping to conclusions. Imagine if investigators could ask authorities for permission to retrieve screenshots from your mobile device if you are under investigation. There would be no need for access to keys.

I am not arguing that this is desirable, but I do acknowledge that investigators may need help to navigate modern technology.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#83
post #42

Earlier quoted context omitted.

Look at the existing cases of terrorism. All of them used unencrypted forms of communication: shared Gmail account, phone calls, even good old SMS. The issue is not that police can't see what those people are doing, none of the perpretators are unknown; it's that they (and the judiciary branch) don't have enough resources to really tackle them.

I partly agree with you. But right now, it's pretty easy to use end-to-end encrypted forms of communication, so why still use sms? Knowing the suspects and having limited resources, seems to me a argument for listening into communication, not an argument against it.

I'm not exactly an expert on the issue, but I could imagine that they use sms because that's the only available form of communication on an anonymous $10 dumbphone, and any computer connected to the internet can connect to a webmail.

Listening to more communications is exactly a resource problem: it isn't exactly cheap to build and maintain the infrastructure to gather and analyze more. Moreover in the context of the link, while I'm not a fan of conversations being listened on by default, I certainly don't want resources be spent so that encryption can be reduced

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#84
post #29
post #19

Earlier quoted context omitted.

Yeah, and that part is the pipe dream. You really need to compromise it only once to have access to everything. It’s unreasonable to believe only the government will have access.

You implement it by putting the key inside a box, and letting that box perform the decryption. No other services/ports allowed. (Except you have to have a way to get the public key out, and allow the box to generate a private key which means it needs entropy). You can pot the box in epoxy for additional security.

So now you have an ultra secure box. It’s like the unsinkable Titanic. Someone (somehow) copies the key, and proceeds to decrypt all your citizens’ communications, but you are 100% that hasn’t happened, because it is, after all, impossible.

Just like it was impossible for the Titanic to sink.

Re: ProtonMail, Tutanota urging EU to reconsider encryption rules

#85
post #19

Earlier quoted context omitted.

Yeah, and that part is the pipe dream. You really need to compromise it only once to have access to everything. It’s unreasonable to believe only the government will have access.

Just to add another thing in: Which government?

Obviously one which can force companies to implement whatever they want. Currently it's US, EU, probably China.
Post reply on HN