Petition UK government to not ban encryption
petition.parliament.uk
petition.parliament.uk
"If a British citizen with an iPhone purchased in France and roaming in Germany iMessages a Chinese citizen roaming in Sweden using an iPhone purchased in Denmark, which government's keys need to be inserted in the iMessage communications by an American company (Apple) legally based in Luxembourg using servers hosted in Eire?"
David Cameron says there should be no "means of communication" which "we cannot read"
It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition with "we do not intend to ban encryption" and close it.
This just shows serious misinformation on your part.
ISIS recruitment would plummet to zero if people had to get TLS working before joining.
The average prospective terrorist / criminal etc isn't going to be able to set up TLS. If they encrypt their communications, the odds are it's going to be going via a third party. Next time you send an email, tell the recipient that from now on you're going to communicate directly by TLS, and they'll need to set up a server before you can talk to them again. I believe that most people will have considerable difficulty doing that.
So, you're reliant on third parties who constitute single points of failure and potential targets of legal action.
Individuals who can securely set up TLS (or PGP or whatever) for their own communications are sufficiently rare that they effectively don't matter.
For hosting provider setup, to domain name registration and TSL certificate generation there are thousands of online tutorials.
You don't need to be an expert or a developer to know how to setup TLS on a Wordpress blog.
This isn't really about stopping that though, it's about the snooping nanny state plain and simple.
I think you're severely underestimating the intelligence of people in general. If we're talking about ISIS, all it takes is one moderately experienced computer user to show everyone else how to use PGP.
And yet we find a bunch of supposedly encrypted stuff where the user did something wrong, leaving the stuff effectively unencrypted.
See also people uploading keys to github etc.
I suppose I omitted the step of copying and pasting your recipient's public key, but that's not especially conceptually difficult, either.
There's also keypair generation, which is the step that derails most people I think. Plus the fact that people have to grok the concept of public and private keys, and be able to distribute / not distribute them as appropriate. And revocation certificates. And public keyservers. And trust levels. Etc.
I do think an organised, disciplined group might manage to get PGP working as intended, but I doubt there are many such groups.
My point is, I doubt individuals implementing encryption have much to fear from whatever proposals may emerge from this. Maybe they will later. But it seems to me it's much more likely to target companies that offer/facilitate encrypted messaging.
Edit: Thanks to whoever just put my karma over 2000. Does anything exciting happen when you get to 2000 points?
Obviously, that's total conjecture, though.
Do you think the reason you use HTTPS to talk to your bank is to prevent the government from seeing your account balance?
I'd guess all the UK government would do is insist that, by law, all secured P2P messaging goes via a given cipher suite (one with a government backdoor/decryption key and, I guess, no perfect forward secrecy).
It's pretty conclusive how bad an idea it is, when all of the leading security experts in the world have said that this is impossible without weakening the entire security of the system.
I think it's reasonable to assume that the terms would be more explicitly defined in an actual law.
As yourself used the term, how is "communication between a bank and a customer" not a form of "communication"?
I am not sure if it would be a good thing or not if this was the case, but leaving that aside laws are, in fact, liberally interpreted all the time, depending on your jurisdiction's legal tradition. This is why you can't hack the law; the interpretation of the law will change to fill in the gaps, provided that's what the justice system wants.
In any case, there is no law yet, so no language to examine.
In reality, the correct way to interpret laws is to think about their real purpose. Who benefits? What is the goal here?
The vast majority of laws have one of these two purposes: to enrich the government's cronies, or to cement the government's continued rule.
Webmails, social medias or dating services are of a much greater interest to a nosy government.
Have you ever read about the various French Intel services after the revolution? Talk about convoluted. They trusted no one or even each other.
Many people say that opening our devices to a special chosen set of good guys is equivalent to opening them to all the bad guys as well. If that's the case, surely we're already vulnerable given most commonly used devices update automatically?
The only purpose I can see for attacking encryption in general is to enable mass surveillance. The government have in fact not been specific about what they are actually asking for, but if they want selective ability to search digital devices, they already have it. If they want further powers, then we need to ask them what they need them for.
The NSA and GCHQ were able to gain significant powers in the last decade primarily by staying under the radar of public awareness. That is why the leaks we heard in 2013 were so significant. Now the cat's out of the bag, it might be the government are left with no choice but to use propaganda to convince the public to give them what they want but there's no guarantee that it will work.
And that’s exactly how it should be.
Its still a terrifying idea, and shouldn't be allowed to happen.
https://en.wikipedia.org/wiki/Encryption_ban_proposal_in_the...
This isn't just metaphorical - it is a practical, provable result of it. The various attempts throughout history have been abysmal failures of security.
The other practical result is that the current UK government appears to believe that citizens are their subjects, whose freedom is a privilege and not a right.
Governments are passing increasingly Orwellian laws, obviously against our wishes. They clearly don't want us to have any privacy whatsoever, and are basically just making that a legal reality too. Hello police state.
In response, people ask governments to stop stripping away their privacy.
How would you expect governments to respond, besides with some PR-bullshit to placate us or give us a false sense of security. "We would never read the contents of your messages, only the metadata! Honest!".. and people buy that as if they didn't know governments lie to us all the fucking time.
Imagine a King telling his subjects he'll raise taxes until the economy implodes. The subjects ask him nicely to please not raise taxes quite that much.
What does the King do? -Whatever the fuck he damn well pleases, as long as people aren't willing to risk their lives in de-throning him. Of course, after a revolution, a new King is throned, because THIS time it'll be different!
This is so fucking insane.. When will people wake up?
Okay to be honest I haven't really read into the material. but is their actual plan to "ban" encryption? Or do they want to license it to certain parties? Or have a weakened "export" encryption scheme like the US government tried? What's the plan?
I expect the language to be broad and the enforcement narrow.
That's the worst kind of law - you can be locked up at a prosecutors whim.
In the UK, it's already illegal not to disclose the key to an encrypted file.
Some people have failed to pass the test of "reasonable doubt" for s.53 (3) / (4) defenses e.g. ( http://www.alphr.com/news/361693/teenager-jailed-for-refusin... ) but in other cases they have succeeded (e.g. Lauri Love had his hdd's taken and the NCA couldn't decrypt them but had to release him on bail; http://www.bbc.co.uk/news/uk-england-suffolk-31544346 and subsequently returned some of the storage (before arresting him again))
There are also people out there working to help the reasonable doubt argument; https://brasshorncommunications.uk/projects/s53/
This is not ideal, but will probably fail, hopefully with some precedent set.
[http://theconversation.com/hactivists-arent-terrorists-but-u...]
* He was forced ("tortured" was the word used) to disclose the key by the police.
* You can't accuse yourself or direct relatives, and disclosing an encryption key that resulted in incriminating evidence was argued to be a form of "self incrimination".
* "Best" thing about this was that the evidence led to finding a body, but as it was nullified, legally the status of the deceased person changed from "deceased" to "missing" -- because the evidence they had used to find the body had been nullified, then also the finding of the body had to be null (I'm not kidding, people went nuts over this "technicallity").
* Eventually a more reasonable judge turned the previous statement and accepted that the person was deceased indeed.
Working in forensics (I do digital forensics) is weird some times...
That's why the Brazilian police has a hard drive that is known to have tons of incriminating evidence against a number of bankers but they can't do anything about it because, well, TrueCrypt.
It sounds ridiculous that the discovery of a body would be nullified because the evidence leading to it was nullified but this is important because it forces the prosecution to comply with the law. It helps avoid the violation of a fundamental right.
I don't necessarily find that Roman Law is superior to Common Law but all of the silliness about people being forced to type passwords could be avoided with this very reasonable provision. Common Law allows you to incriminate yourself by forcing you to prove your innocence by assuming guilt unless you can prove your innocence via decryption - let's hope we can all remember all of passwords!
You can use what hiq is suggesting, https://news.ycombinator.com/item?id=10097533, but that is a different method.
I wonder what is in a judge's mind when the encrypted evidence turns out to be kitten pictures and the defendant claims that he does not have any other password to provide.
[1]: https://en.wikipedia.org/wiki/Plausible_deniability#Use_in_c...
edit: clarification
What the methods you mentioned are doing, is hiding information in places which are marked as: random data no information here. But in reality there is information there. You then need to have dummy information somewhere else.
The point is that the government want to ban encryption that they can't can't view. That essentially means you'll only be able to run an encrypted service if you're happy to hand over the unencrypted data to the government. It might also mean that end-to-end encrypted services are blocked by ISPs. But the average internet user will still see the little padlock in their browser, so they'll believe it's all still fine, and will carry on as normal.
What the government really seems to fail to understand[1] is the principle that if they can view the decrypted information then so can the bad guys.
[1] Or, I suspect, they do understand but they arrogantly believe they're better at security.
I think your goals are completely orthogonal to the people who made and signed this petition, so your suggestion is unlikely to sway anyone.
Don't get me wrong, I'm not in favour of this, but the distinction is clear and false misinformation isn't going to help prevent this.
I think this is important and have emailed two friends (a doctor and a lawyer) to ask them to sign it. I described it as:
'It may be similar to how you feel when you watch a B movie lawyer or doctor "making a professional decision". The only difference being I'm watching the people who are running this country.'
a) they ban all end-to-end encryption
or
b) this law is ridiculously easy to circumvent for even non-technical users
An example of b) would be: piggyback messaging on an existing service that has a valid reason for being encrypted
With technology a key and growing industry within the UK, shouldn't we expect our leaders to at least attempt to understand the issues around governance?
(I was about to single out Cameron, but while I detest him, and while he seem to have a particular blind spot for technology, the problem is by no means unique to the Tories; e.g. consider when David Nutt was asked to go because his evidence-based advice on drugs didn't agree with the Labour governments policy)
Unfortunately, selective enforcement of this ban will quickly turn it into a tool of tyranny, same as any other.
(Yeah I have a site that doesn't display that stupid cookie notice, but it doesn't matter because I haven't pissed off anybody powerful yet.)
a) they ban all end-to-end encryption
or
b) this law is ridiculously easy to circumvent for even non-technical users
An example of b) would be: piggyback messaging on an existing service that has a valid reason for being encrypted
The US has the greatest control over apple. From the US is it shared with the five eyes. GCHQ's oldboys network then passes it on to basically any European who asks, while one of the thousands entry-level "analysts" at the many US intel agencies passes it on to the Chinese. Then the next snowden leaks it to the guardian and every other paper still alive, half of which are under surveillance by various police groups. So within a week the only people who cannot read this text are 50% of us who aren't government employees.
One keyring to rule them all.
Would anybody like to speculate on what proposals we might see in reality? Are they going to ban me, as an individual, from using GPG? Are they going to ban companies from operating encrypted messaging services in the UK? Are they going to block traffic from non-compliant overseas providers? Are they going to just have a quiet word with the SnapChat people?
EDIT: In fact, I wouldn't even need to go there
"We don't want to ban encryption." - Ed Vaizey, Minister of State at the Department of Culture, Media & Sport, on 16 July 2015 - http://www.scmagazineuk.com/uk-minister-cyber-security-a-pri...
Serious policy isn't influenced by petitions. If you don't have a majority of legislators/MPs in your pocket, you're wasting both time and bandwidth.
The clue is the "I am a British citizen or UK resident" checkbox. ;)
This is misdirection in the run up to new surveillance legislation. The real issue is 'bulk collection'.
The UK government is trying to frame the debate such that the concept of mass surveillance is not challenged.
Yes, increased usage of it will harm "bulk collection" but not too much. Your whatsapp might be end-to-end encrypted, but companies such as facebook and google aren't going to change too much because it would harm their business models.