No points to tap.
No point in tapping the data.
If they want to capture conversations it's time to go back to the proper old ways of actually spying on high-value targets.
No points to tap.
No point in tapping the data.
If they want to capture conversations it's time to go back to the proper old ways of actually spying on high-value targets.
The legal approach is correct and easy for the public to understand. Explained correctly it is also popular. The government used to have to do things like get a warrant and investigate specific crimes. They couldn't listen to everyone's phone conversations all the time and they shouldn't be able to do this on the Internet either. Digital dragnets are illegal and unconstitutional.
The technical approach is also correct. If you're building something that makes it harder for criminals inside the government to commit more crimes, you're doing work that is profound and in the best interests of society. Anyone with passion and technical skill can participate in this work. It's the right thing to do.
Both efforts help each other. Keep the government in line and accountable to the people. Make it harder for people inside the government to do the wrong thing. All approaches deserve support and should leverage each other's work. They should cooperate with law-abiding, constitutionally empowered government authorities as well. There are good guys in the government too.
But the main place where law and tech come together is enforcement. For law to work at all, it has to be enforced relatively evenly. Technology may make a law's enforcement impossible or easy, but it does not make it more or less "right" in the abstract.
And legal is about what recourse we can seek afterwards, when we understand we've messed up the implementation and security had failed.
Relying on legal protections alone is absurd. Relying on technology without any legal recourse for failures maybe somewhat less so, but still not suitable for this "real" world we live in. Not without reconsidering our approaches and attitudes to way too many things.
Not at all. Legal rules are about what we "should" do, what's right and what's wrong. However, legal rules need to be enforced to be effective. If you create a legal rule that's impossible to enforce and everyone flouts it, not only does your rule not get enforced, but it also creates doubt in the entire legal system.
So legal rules ought to consult with what's possible and impossible, but they should not be dictated by them.
An easy target is saying the government is too powerful. That would be a mistake. If Facebook were more powerful than the government, we would no be in any better hands.
The problems with the US government are that it does not work for the people.
It would be painfully short-sighted to say this debacle goes to show the gov and private companies are not too involved with one another. This will be handled with some deal that will deepen the coupling and citizens will not have a say. That’s how most things in our lives get handles. Without regard for us, that is.
Private interests have eroded our state of civility. Citizens voices mean nothing and that is all that’s going on here.
We need our government back. Nothing else is going to solve this, unless of course we can actually address the technical issue that you raised. That would be nice.
A government that was our government would simply not step over this line. It’s possible; not easy, but possible.
Id say it would be better to decentralize governments so that you dont have any great accumulation of power anywhere, and by bringing government closer to communities you automatically bring back power to the people.
A country that's going to mandate backdoors/access to such communications, are going to outlaw communication methods they can't backdoor.
Say Apple makes a federated end-to-end encrypted messenger app, the government will still go to Apple and say "let us read all the messages, otherwise you can't sell your devices". THAT is the problem, and it can't be solved by more technology and shouting "BLOCKCHAIN!"
If a largish group of users could create end-to-end encryption not with a single company but with "readily available materials", then stopping it could be harder.
So it's a combination of state dictate and the practical ability of users to defy that. This isn't saying I'm optimistic, I'm rather pessimistic on any ability of a wide home-grown encrypted-messaging milieu to appear - if few are aiming for this, those few can easily be picked-off. But I don't think we should just give up on any part of this.
It's too late for that, every machine, every browser, every user is using encryption software all the time.
"It's too late to criminalize possession of drugs. Half the country takes pharmaceuticals!"
It's trivial when you can pass arbitrary legislation.
Back in the 90s we had to deal with US gov restrictions on encryption export. Software companies and organisations fell into line. It was a big deal when 128-bit keyed Netscape became available globally in 1997, per State Dept approval, but even then the full-strength server-side SSL was still restricted to 'approved' entities.
And even 56-bit server SSL was only exportable with us.gov key escrow.
I used to use Apache with the 40-bit SSL option. Pathetic strength but no-one was going to risk jail-time by breaking laws.
I did at that time, it was just another law to ignore.
This isn't meatspace, the dynamics are quite different.
Well, then clearly it would quickly become ubiquitous. I mean, if a war on encryption that was just like the war on drugs were to be launched, why my local stream bed might "place burned passwords here" on the tin-can that currently reads "used needles here." (put there by the other homeless people).
You're forgetting that the average user doesn't care enough to sacrifice ease of use for greater political benefit.
At least in the US, if a US citizen is part of a potentially incriminating conversation, the government's going to have a hard time forcing a court to force the citizen to decrypt the conversation.
Lawyers, correct me if I'm wrong, but it seems like a conversation wouldn't be subject to the vagaries of "combination to a safe"-production loopholes.
Or, ofc, get people to adopt insecure protocols. That we know (or have good suspicion) they've tried.
They most certainly do not have cause to demand access to swaths of comms no matter whose comms they're after and most assuredly when that access actually entails enabling access to all of the comms.
I posit there is no authority that should be able to demand this as a matter of the right to human existence. Law, order, society and government should not have ultimate authority on private communications no matter what the tech is capable of. We, as humans in a modern world, can speak and if desired do so in private. This is our right as individuals and if encryption helps us accomplish and enforce that right then so be it.
If they have probable cause then they need to beat feet or beat heads but either way they need to get to work. And by work I do not mean trying to impose a different reality than the one that we currently have - where math is fact, compute is cheap and source is open.
What's it going to be? 100 go free or six lines from everyone?
What are the building blocks for encryption?
1) An cryptographic algorithm
2) Some form of key generation
3) A software implementation of 1) and 2)
4) A binary distribution of 3)
5) A computer that executes 4)
In practice, chances are those 5 are all rigged. They are rigged because you have so far trusted:
- That there are no tricks in the algorithm or its practical implementation
- That there are no tricks in the key generation algorithm or its practical implementation
- Hundreds of contributors to the software implementation of those algorithms
- The guy that compiled the software into binary form and distributed it
- The compiler used to compile the software and all the libraries and dependencies the software has
- Hardware manufacturers
So, common sense tells me that because you have trusted so many people, in practice, it is very unlikely you can have end-to-end encryption or any real ambition to have privacy.
This does not even consider more aspects, like your operating system, your sources of entropy, etc.
Other than that, it's doable.
Spam protection and censorship (necessary for mobile app stores) can be distributed as opt-out blacklists. If it gets to be a huge problem then a "enter this password to add me" type thing could work too.
I've been compiling a bunch of ideas as such for fully P2P decentralized/encrypted chat, but I'm stuck at the two issues I mentioned earlier.
Nobody has a 100% open smartphone stack from the baseband up to the application.
It's just mildly more difficult than a subpoena to Facebook asking for all messages.
So it's definitely covered by a different legal regime, to set aside the technical bits.
I don't know what government is doing snooping on facebook messenger. I would be blindsided if real crime was happening that way.
People moved onto other messengers like WhatsApp for those purposes.
Heck people use snapchat expiring messages to relay info on illicit activities.
It is not farfetched at all people are using FB messenger, signal, anything for that purpose.