Live data from Hacker News

Petition UK government to not ban encryption

petition.parliament.uk

91–100 of 113 posts

Re: Petition UK government to not ban encryption

#91
post #90
post #84

Earlier quoted context omitted.

GPGTools, for example ( https://gpgtools.org ) I suppose I omitted the step of copying and pasting your recipient's public key, but that's not especially conceptually difficult, either.

That does look quite nifty. There's also keypair generation, which is the step that derails most people I think. Plus the fact that people have to grok the concept of public and private keys, and be able to distribute / not distribute them as appropriate. And revocation certificates. And public keyservers. And trust levels. Etc. I do think an organised, disciplined group might manage to get PGP working as intended, b…

Hmm. I guess my thought is that if it became well-known that using Whatsapp, iMessage, etc. to communicate about illegal activities frequently led to arrest, then knowledge of PGP and the like would spread because it's not too difficult to use. So then government would be able to read everyone's communications through those channels for no appreciable benefit.

Obviously, that's total conjecture, though.

Re: Petition UK government to not ban encryption

#92
post #48
post #32

Earlier quoted context omitted.

Is there any scheme which permits a data to be encrypted such that there are two passwords\keys which can decrypt it - one which unlocks the real data and the other to some dummy\innocuous stuff?

Storing the different information in the same place is impossible. You could use stenography but then anyone with access to the program/source will immediately discover the deceit. You can use what hiq is suggesting, https://news.ycombinator.com/item?id=10097533 , but that is a different method.

I'm sure it was just a typo, but it's 'steganography'.

Re: Petition UK government to not ban encryption

#93
post #86

Earlier quoted context omitted.

Many countries still require warrants.

I think in France the taxman can check your bank account directly so it's a fair bet that the intelligence service have access. I have no reason to think things are different in the UK.

I wouldn't be surprised.

Have you ever read about the various French Intel services after the revolution? Talk about convoluted. They trusted no one or even each other.

Re: Petition UK government to not ban encryption

#95
post #15

For the record Cameron was not suggesting on banning everything that uses encryption. Primary seeking a ban on end-to-end encryption messaging applications (ie, textsecure/signal, whatsapp, snapchat) that does no provide the UK government with a backdoor. Its still a terrifying idea, and shouldn't be allowed to happen. https://en.wikipedia.org/wiki/Encryption_ban_proposal_in_the...

Seeking a mandatory backdoor is equivalent to banning encryption.

This isn't just metaphorical - it is a practical, provable result of it. The various attempts throughout history have been abysmal failures of security.

The other practical result is that the current UK government appears to believe that citizens are their subjects, whose freedom is a privilege and not a right.

Re: Petition UK government to not ban encryption

#96
post #30
post #20

Earlier quoted context omitted.

Apparently our politicians should understand infosec to demand policy, but the people don't have to understand their goverment to demand policy.

How can you have a situation where the HTTPS used to secure communication between two peers is different than the HTTPS used between a bank and one of it's clients ? This just shows serious misinformation on your part.

We do already have different implementations of TLS/HTTPS used for different purposes. They're called cipher suites. There are already weaker cipher suites in widespread use, which are the cause of most of the big security issues with TLS/SSL/HTTPS. (This is pretty good article on the subject: http://blog.cryptographyengineering.com/2015/03/attack-of-we...)

I'd guess all the UK government would do is insist that, by law, all secured P2P messaging goes via a given cipher suite (one with a government backdoor/decryption key and, I guess, no perfect forward secrecy).

It's pretty conclusive how bad an idea it is, when all of the leading security experts in the world have said that this is impossible without weakening the entire security of the system.

Re: Petition UK government to not ban encryption

#98
post #92
post #48

Earlier quoted context omitted.

Storing the different information in the same place is impossible. You could use stenography but then anyone with access to the program/source will immediately discover the deceit. You can use what hiq is suggesting, https://news.ycombinator.com/item?id=10097533 , but that is a different method.

I'm sure it was just a typo, but it's 'steganography'.

Thank you. Yes, I meant steganography.

Re: Petition UK government to not ban encryption

#99
Just One.

The US has the greatest control over apple. From the US is it shared with the five eyes. GCHQ's oldboys network then passes it on to basically any European who asks, while one of the thousands entry-level "analysts" at the many US intel agencies passes it on to the Chinese. Then the next snowden leaks it to the guardian and every other paper still alive, half of which are under surveillance by various police groups. So within a week the only people who cannot read this text are 50% of us who aren't government employees.

One keyring to rule them all.

Post reply on HN