Facebook, WhatsApp Will Have to Share Messages With U.K.?
bloomberg.com
bloomberg.com
We believe people have a fundamental right to have private conversations. End-to-end encryption protects that right for over a billion people every day.
We will always oppose government attempts to build backdoors because they would weaken the security of everyone who uses WhatsApp including governments themselves. In times like these we must stand up both for the security and the privacy of our users everywhere. We will continue do so.
Will, Head of WhatsApp
So will WhatsApp refuse to comply, if this goes forward?
And is that even possible?
I do appreciate that Facebook has the resources to fight. To fight an NSL, even. But IANAL, and have no clue.
Have you considered architectural changes that will allow for the app to be compiled and deployed by an affiliate corp outside of these jurisdictions?
That wouldn’t even be illegal, since they never hit you with a wrench - you just imagined they were about to go xkcd on you
Warrant canaries are nice to have, but viewing them as something which provides proof of absence of government meddling is incorrect.
My understanding is that they can prevent you from removing warrant canaries but they can't force you to continue announcing "I have not received a secret warrant".
In places where there are limits to what the government can do to an with you, its possible to resist.
EX: https://en.m.wikipedia.org/wiki/West_Virginia_State_Board_of...
The US government can’t legally compel you to lie, but may restrict what you can say.
We know that the legal bar for forcing someone to speak or not speak is high (compelling state interest), but national security has usually been held to pass such a bar.
You don't have to take our word on this -- I wouldn't want you to. As others on this thread have pointed out it's possible enough to tear through our binaries that if we did have a backdoor it would be discovered.
No, it's not "possible enough" and I strongly suspect you fully realize that.
A backdoor doesn't need to be in a form of an IF statement or something comparably obvious and silly. It can be a weakly seeded PRNG that would allow a "determined party" to brute-force the key exchange in a reasonable time. That would take man-years to fish out from a binary, and that's without considering that you may (be forced to) distribute an altered binary on demand and to specific targets only.
So in the end all we have - realistically - is in fact just your word. There's no way for you to prove that you are trustworthy by pointing at some random binary. The only option is to distribute reproducible builds from an audited open source.
Active ways to attack the client to make it leak the key are far more worrying - but even an open source project wouldn't protect against that.
Good luck finding even this without a fine comb. And that's us just getting started with code flow obfuscation.
No source = no trust. It's as simple as that.
Signal has the same issue.
Simple example: I'm sure that whatsapp main window is webview. Imagine that application inserts some kind of resource (e.g. CSS) from whatsapp server. So now whatsapp server can serve slightly altered CSS which will leak secret data via custom fonts, etc and you won't be able to find that, unless you're intercepting all traffic and can decrypt it (and apps nowadays love to pin certificates).
This is imaginary attack, I have no idea whether whatsapp does that. But HTML is a powerful and dangerous beast, yet it's used a lot in applications for rich media.
That said, @wcathcart: in community with deep technical expertise like Hacker News, folks do consider how many possible channels and means there are to confidentially leak information from applications.
You're correct that in the general case it's likely that tech-savvy users would scan a popular app like yours and find any 'obviously-placed' backdoors. It's an observational and opportunistic approach, akin to the way a passer-by might spot a poorly locked bicycle on a street.
Unfortunately there's an extra level of complexity here - any app may have unusual behaviors that a sophisticated attacker could trigger for individual users to exploit them - and it's really, really hard for the security-conscious of us -- who might never see or meet those users -- to truly trust that your app is doing what you tell us it is, whether that's end-to-end encryption in all situations, or anything else.
The reason is that without being able to see how the app is written, verify that it's genuinely the same compiled version running on all devices, and audit the behavior it will have under exceptional circumstances -- external observers just don't know.
I'm not expecting you to make the source freely available, incredible though that would be - but attempting to explain the potential disconnect in dialogue you might find with some commentors.
Of course if WhatsApp detected an abnormal or tampered version of the app, they can suspend or disable your account. I'm sure security labs that do reverse engineering of this sort probably do it on test handsets with burner numbers and identities so it wouldn't affect any personal accounts they use.
That's explicitly against your terms of service.
Sometimes this leads to us being blocked. We were blocked in Brazil, for example, but that block was overturned in the courts.
It'd indeed be interesting to know if the FSB had some kind of baseband vulnerability that they'd used willy-nilly to facilitate dragnet surveillance.
I suspect William Binney was right though - blanket surveillance is just expensive and hides your needles in a mountain of hay; you really want high quality in the data you store in order to ease extraction of meaningful information / intelligence.
(that's not to say that aggregate meta data isn't interesting - just that with actual content noise is a problem)
It reads like your product is already compatible with govt ease dropping
Any comment on this?
https://www.theguardian.com/world/2013/sep/11/nsa-americans-...
Hassan https://www.clipart.email/
Platforms that rely on trust (in this case, trusting that FB isn't doing bad things) provide very weak guarantees about privacy/security. They could easily include a keylogger in WhatsApp and bypass the e2e encryption, for example, and us regular folk have no way of knowing.
The fly in the ointment is the client might have additional functionality to leak the e2e encryption key. That is far harder to find, but if it's use were widespread, it would be found by researchers.
The whole point is moot though - whatsapp is designed to (by default) upload cleartext chat logs to google/apple servers. Since all chats have 2+ recipients, the conversation is only safe from snooping if nobody in the chat has backup enabled, which is unlikely.
They could indeed serve you a different binary from the app-store. "Do you think that's Whatsapp you're using?"
I have much more trust in the former than the latter.
I suspect most people want to keep their $500k+/year jobs instead of sticking their necks out. My friends who work at FAANG are largely mentally checked out, and just do it to collect their monies and retire ASAP. You can't pay rent with good feelings.
So just keep making the world shittier. Gotta love individualist capitalism.
Raised the standard of living for billions.
If you define the free market as nothing other than anarchy, then yes the free market is rare indeed.
But I don't that know anyone that speaks in such absolutes.
No one quote in particular; just a recurring theme.
"It is not from the benevolence of the butcher, the brewer, or the baker, that we expect our dinner, but from their regard to their own interest"
- The Wealth of Nations
"The natural effort of every individual to better his own condition...is so powerful, that it is alone, and without any assistance, not only capable of carrying on the society to wealth and prosperity, but of surmounting a hundred impertinent obstructions with which the folly of human laws too often encumbers its operations."
- The Wealth of Nations
"The statesman who should attempt to direct private people in what manner they ought to employ their capitals, would...assume an authority which could safely be trusted, not only to no single person, but to no council or senate whatever"
- The Wealth of Nations
"In spite of their natural selfishness and rapacity [capitalists] are led by an invisible hand...and thus without intending it, without knowing it, advance the interest of society"
- The Theory of Moral Sentiments
> Have you read him?
Yes.
"The man of the most perfect virtue, the man whom we naturally love and revere the most, is he who joins, to the most perfect command of his own original and selfish feelings, the most exquisite sensibility both to the original and sympathetic feelings of others."
Self-interest, yes, but in a system regulated just as much by the church and the aristocracy as by the flow of capital. Pure monetary greed without regard for doing what is right is nothing Smith would ever have advocated.
Careful - you're right that WhatsApp is untrustworthy, but laws that force them to add backdoors could well be applied to open-source code as well. Or make possession of non-backdoored software, open or not, illegal. Or compel OS/hardware manufacturers on which the code runs. The law is a dangerous thing to ignore.
Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everything on the screen and forwards it to some other entity, but in practice it's not so easy because of bandwidth limitations, etc. I suppose it would be much easier to create a physical keyboard that phones home over a mobile network, although it would only give you half the conversation.
*edit: added the word "audited".
You could also decompile the Whatsapp APK and do the same thing (it's Java after all).
Look no further than the OpenSSL Heartbleed vulnerability
https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...
It's one of the reasons the Debian project has worked so hard at reproducible builds: https://wiki.debian.org/ReproducibleBuilds/About
Bugs can certainly occur (like Heartbleed etc) but the alternative (closed source opaque binary blobs) is much worse.
Also, I'm still using one of those original builds on my laptop - upgraded of course...still mad love for my daily driver.
And so they never learned, and so they "can't".
In the same way, I can't use Gentoo or vim or compile either or ski or... :D
Now, to avoid the "Reflections On Trusting Trust" exploit, building the C compiler toolchain from known-good "root" compiler/linker toolchains, and then comparing the output vs. self-compilation is quite a bit harder.
If you have multiple compilers and they all aren't infected in exactly the same way (e.g. one is not infected, or they have different types of infections) then you can detect there's a problem with them.
Where does that leave the rest of society? Having open source software and hardware is not enough, we also need laws that prohibit mass surveillance and support our efforts to uphold human rights.
Laws are probabilistic, whereas math & source code is deterministic. You can verify that computer code does what it says it does. Laws depend on enforcement and complicated judicial systems (based on humans) to interpret and apply the laws, which means they can effectively change over time, and the goalposts are never stationary.
This is why moving the goalposts and further normalizing surveillance is extremely dangerous. The rights that you enjoy today are not universal, and can obviously be eradicated in less than a generation.
[1]: https://www.eff.org/deeplinks/2015/04/remembering-case-estab...
There is no mathematical escape hatch from society. All we have is a messy assortment of technological mitigations that change the cost of surveillance.
These mitigations work best in combination with constitutional rights that limit what the government of the day can do, triggered by the latest outrage in the news.
This is clearly a straw man, no one wants to do this, or is suggesting that we do this. But at some point, even the most hardened OSS advocate has to trust someone (usually the hardware manufacturer). You cannot verify that the device you're on doesn't spy on you, you have to rely on the manufacturer's word that it doesn't. And the manufacturer's suppliers, of course, because the manufacturer is trusting them.
Somewhere along the stack, we all have to draw a line and say "beyond this point, I trust that I am not being spied on". You choose to draw that line at the hardware point. Others choose to draw the line at the software point.
Proper law enforcement (mind the "enforcement" part) can make a neighborhood safe enough so that nobody tries to shoot you and you won't need to wear vests. But in the end of the day, if you are messing with bad people in the bad neighborhood: bulletproof vests are real, laws are not.
And when you are talking about government enforcing the laws that are supposed to forbid uncontrollable government agencies to do what they do: well, government kinda is bad people in the bad neighborhood.
So you still just invest trust in the maintainer or — if you’re lucky — the third party auditing firm who was paid to review the code.
That you can review the code doesn’t mean that anyone does so. At least not in an exhaustive and relevant way.
Closed source or open, the problem is made even worse now that we live in a Package Manager culture where even the simplest applications adopt dozens of dependencies.
I’m not saying that you should trust Facebook and their closed source applications, just that you’re not really all that safer trusting anyone else just because their source code is available.
Correct use of past tense. In the present, e2e encryption is by default.
> Does this new announcement really lessen the security and privacy of the users?
Yes it does, since e2e encryption is enabled by default now. Best I can tell, there’s no way to disable it either.
Hacking into closed source code is much more dangerous (politically) for them and also more difficult.
There's currently a push for reproducible builds which further hardens distros against such attacks.
Not necessarily. Have you ever heard of Ken Thompson's backdoored C compiler?
https://softwareengineering.stackexchange.com/questions/1848...
>Re-write compiler code to contain 2 flaws:
>When compiling its own binary, the compiler must compile these flaws
>When compiling some other preselected code (login function) it must compile some arbitrary backdoor
>Thus, the compiler works normally - when it compiles a login script or similar, it can create a security backdoor, and when it compiles newer versions of itself in the future, it retains the previous flaws - and the flaws will only exist in the compiler binary so are extremely difficult to detect.
It's not necessarily a viable attack method today, but it's the lesson behind it that's important. Anything can be compromised.
As soon as you’re building something written in, say, Javascript, then any semblance of assurance goes out of the window.
JS is an easy target. What about C or C++? You could audit the code but have you also audited your compiler? What if you used Visual Studio?
Code is an easy target. Can you trust the auditors themselves and in the absence of that, your own ability to detect a vulnerability?
The only bulletproof solution is to not use software.
That said, most of us are not as important or recognisable as we believe we are. The layperson won’t have a good reason to isolate their computer and install an airlock between their aluminium-lined office and the rest of their house.
This is just an updated version of the story about the US government scanning your emails for keywords after 9/11. They don’t even need to actually do it, they just need to say they do and most people will monitor their communications.
Many people can compile code from source. Not so many people have the ability to audit code for obscured backdoors. The number of people that are capable to audit and have the time that is necessary to do it is practically nil.
You assume that you actually understand the code well enough to identify the backdoor - e.g. as some sort of function that will bypass authentication when some secret hardwired password is provided (to give a dumb example).
However, to give a real world example of backdoored crypto, it is nothing of the sort. For example, the issue with the potentially backdoored Dual_EC_DRBG pseudorandom number generator has been known since 2004 at least - but the algorithm has been standardized by ISO/NIST and used for years until the potential backdoor issue was widely publicized following the Snowden leaks and the standard was withdrawn.
Good luck finding something like that only by reading code unless you are expert in crypto and mathematics. If you were only auditing code whether or not it matches the published, supposedly correct, standard (or algorithm description), you would never find this. The backdoored code was working completely fine, exactly as intended. But the weak random number generator allowed an adversary with sufficient computing resources to break the encryption.
An improvement in security and privacy isn't limited to "make it impossible, even theoretically, for anything bad to ever happen OR you've accomplished nothing". Most back doors aren't inserted by competent NSA-level actors 20 years in advance. Most are "whenever a message passes through, send a copy to this third party". They are inserted by court order for a specific case due to the government becoming interested late in the game due to a specific case. For example, when terrorists start using some secure email service, the government tries to force the service to allow them to snoop on the relevant conversations. Open sourcing the code would allow you (with the help of the community) to detect these sorts of attempts when the product involves end-to-end encryption.
So while having the source and a community auditing changes to that source doesn't prevent every possible attack against your privacy, it prevents almost every one that is plausibly detectable, which is literally as good as you can do.
That assumes you can get the code. If it's illegal to distribute non-backdoored software, the code might be hard to get, for example Github might be forced to take it down.
This would be quickly detected by anyone looking at the data the WhatsApp app was sending back to the server (this isn't hard to do on a jailbroken device).
Imagine if 10 or 20 different organizations all had access to the source code and could vouch for the checskum of a each build.
While it would be nice if we could trust FB, Apple, etc., it would be much better if we didn't have to, and could simply trust others who have less to lose from alienating government officials.
Back in the day, it was illegal to export "good" encryption. There was nothing stopping it from happening technically, just like there is nothing stopping you from stealing from a convince store, except for the threat of enforcement.
But the threat of enforcement can have a strong chilling effect.
It's still nice to see this spelled out since I've seen many people claim that WhatsApp being closed source is not that problematic. This is definitive confirmation that it cannot be trusted anymore and it's time to start working on the problem (both from a legislative point and by seeking out and moving to technological alternatives).
Audits should start with the actual binary. Only if you can ensure that the binary was build from a specific source code and does not contain any other logic in there (i.e. it was build by a trusted compiler), you can happily skip the decompilation process and analyze that source instead.
Don't hate the politicians who keep pushing this. They're just trying not to get fired. And the surest way to get fired in a western country right now is to be seen doing nothing about the terrorism problem and then having terrorist acts committed under your watch. So the politician asks the security forces "what can we do to stop terrorism?" Security says "get us access to messages of terrorism suspects". Seems reasonable, let's go ahead with it.
Yes, we know that it doesn't stop with terrorism suspects. Then law enforcement wants to read the messages of drug kingpins, then drug suspects, then shoplifters, then jaywalkers, then everyone, just to be on the safe side.
But as long as people are told that they need to give up some privacy in exchange for security, they'll take the latter every time.
I also have nothing to hide :-)
- what are the things you and your significant other are doing in the private of your house?
- which co-worker do fantasize about, be specific in what you like to do.
- As teenager what legal/illegal drugs did you consume. How often did you pass out, who where the people you consumed these drugs with?
- What are your political leanings?
- How much do earn, where are your savings invested in.
- Which illnesses do you currently have, which exist in your social circle.
- what private information was shared with you by other parties. Are you aware of any wrong doings/illegal activity by other people? Be specific esp. friends and family.
Be aware that I will share this information with anyone in your social group/work/volunteering work whenever I feel like it. I may also share this data with extremists groups on the other side of the spectrum, if helpful. Lastly I can use this data to fabricate "helpful" information about you if necessary. Thank you.
Citation needed
Edit: upvoted you. Asking the question, if and when this happened is important for further generations.
That's not your decision to make, as to whether you have something to hide or not. That will be decided by someone else. It's entirely out of your hands and - depending on where and when you are subject to such scrutiny - may be arbitrarily decided, which is in fact a requirement in all authoritarian systems (the law has to be heavily subjective and arbitrarily enforced so it can be directed against anyone at anytime as so required, such that the population is kept in constant fear).
If your conversations aren't encrypted and I have access to them, and people know this, then if I claim that you said a certain something in such a conversation, people are more likely to just believe me.
Also, unencrypted data is data that can be altered by a third party.
Don’t hate the politician for trying to keep their job. In that respect they’re no different from any other person.
Yes, if you can convince politicians that you’re more concerned about the actual damage to your privacy than the hypothetical increase in the probability of a terrorist attack, then go ahead. Do it. Convince them. But my hunch is that most people are far more terrified of dying in a terrorist attack.
This sounds as if the platforms are already sharing with the US authorities. So this being about them sharing it now with UK authorities.
I would, except it requires a mobile phone number.
I agree with that analysis, but it's not clear to me why we don't have similar levels of skepticism about auto-updating desktop apps. Signal in particular uses a third-party software repository, so if it wanted to push a malicious update, it wouldn't even need to sneak it past package maintainers.
Package signing protects you against developers with bad personal security practices, because it makes it harder for a third-party to MITM their apps. But it doesn't do anything I can see to protect you from a developer that turns malicious in the future.
Whether anyone is actually doing that is another question. And there is no technical reason app stores couldn't send a special backdoor-ed build to select list of users under surveillance if government forced them to. (They can target sets of users for staged roll-outs, beta programs, etc.) Which defeats the notion that one person watching can detect it for everybody.
On the other hand, it's possible to do stuff with smart phones at the platform level. Whether through vulnerabilities or some platform capability (updates, etc.), it may be possible to have a backdoor-ed binary that looks to the user like it is the regular binary. That's not a capability that Signal has, but it is a capability that might very well exist.
Regardless of all that, for users who have auto-updates enabled (most users), even if Signal can't silently push a backdoor-ed update, they can unilaterally push one. You could wake up tomorrow with a different version that has a backdoor, so even if you can identify backdoor-ed binaries, you have to turn off updates or verify the binary every time you open the app.
https://wiki.mozilla.org/Security/Binary_Transparency
When you install an app (whether through an app store, or side-loading) the app should state the location online of an append-only log that lists all the releases (with timestamps) for that app. The phone OS could periodically check to see if an upgrade is available, and security researchers could check that the log doesn't contain references to versions which aren't available to the public.
Ideally there should perhaps also be a way for users to anonymously report which version of any app they are using, so that people with particular security concerns could configure their OS to only update an app after, for example, 50% of users have already installed the update.
Telegram is subject to US coercion as much as any US company: both major app stores are US-based, and without app store distribution, a product might as well be dead as far as the masses are concerned.
From the article:
Priti Patel, the U.K.’s home secretary, has previously warned that Facebook’s plan to enable users to send end-to-end encrypted messages would benefit criminals, and called on social media firms to develop “back doors” to give intelligence agencies access to their messaging platforms.
Why comment if you didn't read the article? It's in the first paragraph: "Social media platforms based in the U.S. including Facebook and WhatsApp will be forced to share users’ encrypted messages with British police under a new treaty"
That's the UK's position but it's not clear from the article that some kind of forced backdoor made it into the treaty, just that WhatsApp will be forced to share users’ encrypted messages. But they have already been sharing encrypted messages through other legal means.
More speculation here: https://www.justsecurity.org/24145/u-s-u-k-data-sharing-trea...
"Encrypted" could mean that's how they'll be delivered to the UK.
Or it could be a definition of the set of which messages are in question. The set is defined as the ones that users expected were supposed to be protected by encryption (or that government could not access because of encryption).
In other words, from the phrasing alone, it's not clear whether "encrypted" describes the state of the messages or the scope of the sharing.
Similarly the UK has had its spying ruled unlawful under ECHR: https://www.theguardian.com/uk-news/2018/sep/13/gchq-data-co... (perhaps this is why Richard Dearlove, "C" of MI6, is so Brexity)
(The headline on Bloomberg, "Facebook, WhatsApp Will Have to Share Messages With U.K. Police" is more restrained.)
And worrying that a large number of readers interpretation of the article was influenced by a headline. We really have to do better and be vigilantly aware of how media and power influences public opinion, especially during times such as these.
...that are US-based. You may want to check out Threema for a valid WhatsApp replacement.
>WhatsApp has no ability to see the content of messages or listen to calls on WhatsApp. That’s because the encryption and decryption of messages sent on WhatsApp occurs entirely on your device. Before a message ever leaves your device, it's secured with a cryptographic lock, and only the recipient has the keys.[...]
>A search warrant issued under the procedures described in the Federal Rules of Criminal Procedure or equivalent state warrant procedures upon a showing of probable cause is required to compel the disclosure of the stored contents of any account, which may include "about" information, profile photos, group information and address book, if available. In the ordinary course of providing our service, WhatsApp does not store messages once they are delivered or transaction logs of such delivered messages, and undelivered messages are deleted from our servers after 30 days. WhatsApp offers end-to-end encryption for our services, which is always activated
Very interested to see what their response is and if their promise holds that they do not have technical access to content but merely to account information.
Even if FB / WhatsApp doesn't currently have such a capability, there's no legal guarantee they couldn't be compelled to add it, thereby putting them in conflict with language that didn't include that clause.
Afaik, case law is murky over whether creating new code qualifies as speech (illegal to compel) or facilitating legally-approved wiretapping (legal and required).
More interesting is what happens if someone gets a new phone. In that case (if I understood correctly) they might ask for the sender to resend the messages with a different key. If they really are forced to add a backdoor then that's where I would fit in a MITM attack, as it is limited in scale and detectable when used excessively.
Pretending and using obfuscated language to lead the reader to believe otherwise is disingenuous.
I truely fear for the future that western governments, in particular the 5 eyes members, are hell-bent on creating. They denounce China and Russia for their human rights records in one breath, and seek to strip us of privacy and personal rights in the next - the hypocrisy is simply staggering.
What's perhaps even more frightening is that so many people believe that moves like this are to keep us safe, will keep us safe.
This can not end well...
From the government's perspective, they are to keep "us" safe. It's easier to do that if no one's safe from us. :)
Granted, that's a little over-ominous because the government's mission statement is to keep its people safe, and it's also elected by its people. Either of these two facts changing is the way bigger danger; backdooring centralized services is stuff that happens in the meantime either way.
Even if this or that individual politician gets voted out, or even ten of them, it won't stop the machine's influence. They're still the ones who decide who the replacements can be chosen from.
However, I don't care if it "keeps us safe". It's just wrong in so many ways
I'd love to hear about either a possible alternative government structure in which there are no politicians or a way to attract the smartest people in governments.
https://youtu.be/rgUs5wtXgL4 (the video is a bit dated unfortunately)
If a legislator is not technically up to speed, considerable tax payer money goes towards hiring people in government to do the research and the explaining. Some high level advisers may come from organizations with a private agenda and after a few years of working within the goverment these experts pop right back to their industry jobs and we don't hear of them anymore.
Ultimately its the same need in whatever form of government we want – we need people we can trust.
The intention being that politicians are aware that they must be consistent with their words and actions throughout their term otherwise they will lose their seat.
Some months before the last big bail out legislations, in my state we had a US Senate candidate who was new in our political scene, appeared as a local man with a law degree from our state university, and he spoke about how the working people struggled with unemployment, delinquencies etc, as he knew middle class issues and can change the ways of Washington. PBS featured him and I still remember the interview they aired from his kitchen in a middle class home. I am among the people who voted him in.
A few years after this election I checked his voting records by chance and I realized that he had voted almost always in favor of the bailout system. I wouldn’t have known this by just reading the news or watching cable. In the next election cycle he won handily, this time supported by organizations with cash to blanket our news with favorable lines for him. That’s how life works I guess.
Of course he did not win because the other candidate was much better qualified and rural voters knew him en masse (he’s the one that signs checks for all the citizen stewards of oil fields), but I found it hilarious that people would flame me for not voting for a figurehead (president) but be a-ok to vote in some no name hack to manage our schools because of big money advertising in elections
When you consider the societal fallout and everything that has transpired since, the most insane part to me is that by its very occurrence, 9/11 itself already prevented the next 9/11. The "next 9/11" was to crash the fourth hijacked plane into a high value traget; the plane on which the passengers fought back which was crashed in Pennsylvania WAS the next 9/11. This was a tactic that was apprehended and adapted to before the day was out. It worked three times on one day, once. An update to the mental calculus of common folks was all it really took. If we had successfully prevented it re-shaping our society, it would have never, ever, ever worked again. This newfound understanding of the rules coupled with a straight-forward countermeasure like reinforced cockpit doors would have closed off that vector of attack entirely.
19 malevolent people acting in 2001 have colored nearly two decades of policy for America. I remember two particular circulating ideas from the time: "they're attacking our way of life" and "they hate us because we are free." The latter was much more divisive and so people spent much more time arguing with each other about it. Meanwhile, whether intentionally on the part of the attackers or not, the first was very effectively accomplished.
Maybe if there had been no 9/11, the agencies charged with protecting Americans would have still been seduced by the ease with which modern technology enables broad surveillance. Maybe hoovering up all the data is too good an opportunity to pass up. Regardless, I yearn for, and still miss the end of history. Our hubris has been rewarded with interesting times.
So the core problem is that humans don't make great rulers. Not are we good at selecting rulers.
Individuals are the flaw in the system. And a government without stupidity, means a government without humans.
Thus... http://bit.ly/2nsTLdE
But in that system, how do you allow leniency for the 40 year old single mother of 5 who accidentally switched lanes without using a turn signal?
Individuals also represent humanity in the government. We are not a nation of robots.
In all seriousness this is the aim of all historical anarchist movements. Despite the propagandization of the term "anarchism", that philosophy has a long history of attempts and writers and thinkers, and it has more often than not "failed" when a powerful state entity violently disbanded the efforts or killed prominent leaders. In other cases anarchism has not failed at all but has existed in tribal communities in different ways long before european thinkers wrote on the subject.
In particular anarcho-communism or the more detailed Communalism of Murray Bookchin (The Next Revolution, 2015 https://www.penguinrandomhouse.com/books/239261/the-next-rev...) looks totally plausible to me.
The biggest issue with state-less society is the conflict with the existing state powers this philosophy creates. However the method of governance has found success in present day Mexico with the Zapatistas: https://www.youtube.com/watch?v=Ww46lxIc6-w As well as Rojava in Syria: https://www.youtube.com/watch?v=LcndZ0nZ0mo
https://www.washingtonpost.com/news/worldviews/wp/2012/11/12...
Back in '90s I used a nym e-mail to receive e-mails anonymously and with no traces.
In a few words - e-mails are encrypted with your PGP key and posted to Usenet groups, where you scan all messages and extract only those signed&encrypted with your key.
https://en.wikipedia.org/wiki/Pseudonymous_remailer
Yep, there are 1000 and 1 method of communicating securely. Governments are just using this as an excuse to wiretap popular messaging services for general surveillance.
Unless they'll get away with making everyone dumber, they shall fail.
This is not how it works. As long as enough people are not bothered, they will succeed.
Yes. Absolutely. That's the only logical endgame.
And you can bet those people do understand encryption.
That's pretty far detached from real rocketry.
A similar metaphor for computing would be the allowed use of a LeapFrog system, rather than a computer.
'My cryptography hobby is going pretty well, I just practiced a Caesar cipher on my LeapFrog.'
(neither a LeapFrog or a model rocket being a practical equivalent to their big relative.)
If the goal is to catch malicious people that are trying to hide their communications, then outlawing encryption won't work. But it will give the government a good excuse to spy on people.
I don't think this is the right analogy - instead, I think a better statement would be "you can't outlaw random numbers".
A random number and the ciphertext output of a secure encryption algorithm should be indistinguishable.
I don't think I am being naive to think that even in our wildest dystopian nightmares there is no real path from (current jurisprudence in five-eyes jurisdictions) to (random numbers being illegal).
Residents of the US are still free to use whatever mathematical algorithm they want to encrypt their comms. Transporting OTP's across physical borders is trivial, and not technically illegally if not mistaken. Strong encryption is open source as you've pointed out. There's no law against using those open source libraries, nor any discussion to try to censor/outlaw them, AFAIK.
Policing the airwaves and internet pipes hardly qualifies as some major abuse of human rights, particularly when the best that the Intercept/Snowden crowd can come up with regarding things like "Parallel Reconstruction" is "abuse" of "surveillance power" to catch, e.g., methamphetamine traffickers [1].
[1] https://theintercept.com/2018/01/09/dark-side-fbi-dea-illega...
edit: Downvote due to disagreement? This seems to be the mantra of HN in recent years.
The leaders of today are not the same as those of tomorrow - sweeping powers to invade anyone's privacy and communications could easily be used for nefarious purposes. I don't trust our current leaders with such powers, much less potentially worse ones.
> Residents of the US are still free to use whatever mathematical algorithm they want to encrypt their comms. Transporting OTP's across physical borders is trivial, and not technically illegally if not mistaken. Strong encryption is open source as you've pointed out. There's no law against using those open source libraries, nor any discussion to try to censor/outlaw them, AFAIK.
Do you really think things will stay this way?
It seems to me that TFA is just the next step on a slow, but steady, march towards an authoritarian nightmare - once they've worn us down some more, there will be serious moves against encryption (it's happened before, and politicians have been bringing it up a lot in the past 10 years or so).
Paul Graham:
I think it's ok to use the up and down arrows to express agreement. Obviously the uparrows aren't only for applauding politeness, so it seems reasonable that the downarrows aren't only for booing rudeness.
It only becomes abuse when people resort to karma bombing: downvoting a lot of comments by one user without reading them in order to subtract maximum karma. Fortunately we now have several levels of software to protect against that.
https://news.ycombinator.com/item?id=117171
News Guidelines:
Please don't comment about the voting on comments. It never does any good, and it makes boring reading.
I downvote quite rarely in HN over disagreeing with someone. Usually it is when I don't feel the reply adds any value, and is actually negative for the discourse.
That is, e.g doesn't reach me anything about the opposing position, or is argumentative without any substance, but distracting from comments that are more constructive.
Of course other people use different judgement. At the same time, HN doesn't hide comments to a great extent. Even 'dead' comments are optionally visible (with the 'showdead' setting) and quite a few of us read HN with that on. It's very rare for downvotes to silence people here who aren't actively disruptive.
Couple that with first enabling downvotes when people hit a certain karma threshold, and various other limitations, and HN is free of a lot of the downvote problems of other places.
That to me makes it less of an issue if people downvote to signal disapproval here.
Often initial downvotes will be countered when people feel a comment has been downvotes too much as well.
But I always always downvote complaints about downvotes, such as your edit.
Some of those individuals were guilty of little more than political activism but experienced real harm (e.g. deportation) thanks to surveillance overreach.
If you are US citizen maybe, for the rest of the world. Definitively not.
Without being a lawyer, I'm pretty sure random drone strike on civilians in Pakistan, torture in Guantanamo or intercepting entire world communication is not an example of "respect of humans rights".
This is a good point, I think. The US has an appalling record on human rights (aside from your examples, arming terrorists and overthrowing democratically elected governments spring to mind) - as long as we're talking about the rights of non-Americans.
Which in practice is done by using machine learning [1] on huge data sets gathered with that global surveillance enabled trough Five Eyes.
Because the army of humans that could manually sort trough those zettabytes of data has yet to be cloned. All that ends up in the fancy-sounding "disposition matrix" [2] aka the USGs kill-list. It's just systems upon systems doing their thing and nobody is directly responsible or accountable for anything that ends up happening, like when yet another 30 Afghani farmers get "splatted" by accident [3].
Considering how this has been going on for close to two decades, and the US has a very convenient way going about the casualty statistics [4], I guess these Afghani farmers are just another rounding error in the "war on terror". Figures, because before that they were mostly considered biometric cattle [5] and lab-rats for fantasies about "full-spectrum surveillance" [6].
Note: Under Trump, the USG now even stopped releasing their shined up drone statistics. So it's pretty much impossible to know the full scale about what's still going on to this day.
[0] https://www.nybooks.com/daily/2014/05/10/we-kill-people-base...
[1] https://arstechnica.com/information-technology/2016/02/the-n...
[2] https://en.wikipedia.org/wiki/Disposition_Matrix
[3] https://www.theguardian.com/world/2019/sep/19/us-drone-strik...
[4] https://www.theatlantic.com/politics/archive/2012/05/under-o...
[5] https://www.wired.com/2010/09/afghan-biometric-dragnet-could...
[6] https://we-make-money-not-art.com/big-eye-kabul-surveillance...
I mostly remember the headline, Google does the rest of leading me back to the article.
Funny story about that, those used to be considered controlled munitions [0].
As of 2009, non-military cryptography exports from the U.S. are controlled by the Department of Commerce's Bureau of Industry and Security. Some restrictions still exist, even for mass market products, particularly with regard to export to "rogue states" and terrorist organizations.
Militarized encryption equipment, TEMPEST-approved electronics, custom cryptographic software, and even cryptographic consulting services still require an export license.
Furthermore, encryption registration with the BIS is required for the export of "mass market encryption commodities, software and components with encryption exceeding 64 bits" (75 FR 36494). In addition, other items require a one-time review by, or notification to, BIS prior to export to most countries. For instance, the BIS must be notified before open-source cryptographic software is made publicly available on the Internet, though no review is required. Export regulations have been relaxed from pre-1996 standards, but are still complex. Other countries, notably those participating in the Wassenaar Arrangement, have similar restrictions.
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
https://developer.apple.com/documentation/security/complying...
We dislike it even though we would be forced to do the same thing in their position. We dislike it because we aren’t the ones in power. Again, as it goes in the jungle, life isn’t always fair.
I had this thought yesterday as I read about several prominent politicians in Canada, including the prime minister, actively participating in the climate 'protests' that occurred yesterday. Who were they out there protesting? Themselves? They're the ones with the power to change things. Why were they outside with signs instead of in their offices doing something about it?
Those 20 senators (from Alaska, Missouri, Arkansas) are answerable to the demands of their constituents. Those people are not asking for Climate Change Policies. It has nothing to do with money, but the values and culture of the constituents.
It is incredible how HN and majority of the supposedly 'smart' crowd completely fail to understand the dynamics of how policies and laws are passed or made in this country or anywhere else.
It is also incredibly stupid to paint all politicians with the same brush, because if you are an immoral, evil politician you'd exactly want that situation. "All politicians are the same", "All media is the same" is the foundational strategy of bad actors.
Also, so what if the bad actors want us to believe that all politicians are the same? What if it were true that they're all the same and evil? Would it still be "incredibly stupid" to accurately assess the state of affairs?
The 2019 heat was directly implicated in the deaths of at least 15 people. Five died in France, four in Germany, three in the United Kingdom, two in Spain, and one in Italy. Nine of these were drownings, attributed to people cooling down, and another involved an exhausted farm worker who went unconscious after diving into a pool. The three who died in hot air were aged 72, 80 and 93. Approximately 321 million people were otherwise affected by similar temperatures in the same countries.[1]
[1]https://en.wikipedia.org/wiki/June_2019_European_heat_wave
Edited for clarity
> Netherlands reported 400 excess deaths in the week of the heat wave, a figure comparable to those recorded during the 2006 European heat wave.
Netherlands is considerably smaller than the other nations.. Most put these spikes as a portion* that would have died in the next days weeks, or months lowering statistics later in the year and a portion that would not have.
(Edit) A paper putting the 2003 heat-wave death toll at 70,000: https://www.sciencedirect.com/science/article/pii/S163106910...
*The term from the 2003 paper is harvesting and there were little to no signs of it.
That is not correct whoever wrote it. just do a google search: heatwave 2019 total deaths
CNN reports already 1500 deaths in France only. This is a link to a news site where they estimate a higher count, although I of course cannot verify the correctness of the source: https://www.vox.com/world/2019/6/26/18744518/heat-wave-2019-...
See for example: https://www.theguardian.com/society/2018/nov/30/excess-winte...
Backdooring a communication is only done to safeguard a government's power under the pretense of security.
Further away from democracy, leaders are purely self serving, successful corruption is seen as a sign of intelligence and whistle-blowers, far from being heroes for pointing out maleficence, are threatened with execution.
And indeed, institutions eventually shift to working solely for the benefit of themselves and the people in charge. Mostly because any that don't are undermined until they do.
I don't think it is quite as simple as this (I'll preface this with saying I don't think we should have backdoors and that I wish we had STRONG encryption everywhere). I think the problem is that different departments have different goals. It is very clear that the CIA and NSA's jobs would be easier if there was a magical tool that let them backdoor in and no one else. The police and FBI would have an easier time doing their job if encryption wasn't a thing. That's definitely true! The issue is who is watching the watchmen? That's why we need checks and balances (specifically by people that understand the tech). These departments are so focused on their goals that they lose track of the fact that introducing backdoors actually creates more work for them (and thus actually makes their lives harder). But as humans we're always focused more on the task at hand and less on the over arching tasks (we're notoriously bad at dealing with large scale multifaceted problems). It all really comes down to these departments thinking "if we had this tool it would be possible that we could have stopped this" (which possible is the key word, because we've seen that they can't. There's just too much data. You're just adding more hay to the haystack). The failure really is at the checks and balances stage, that those watching the watchmen don't understand the motivations nor the consequences, and thus let them do as they please. Agencies running the checks and balances are supposed to be suspicious and critical, not friendly. But these agencies aren't getting the funding nor can they attract those that are tech literate, so there's a feedback loop that is only getting stronger. What I'm trying to say is that there's this long chain and things are broken at many stages and that if a single stage was fixed there would be significant improvement. Basically solving at any single stage will help stop the feedback loop.
tldr: The intelligence agencies should be smart enough that they would know that backdoors will backfire on them. But they clearly aren't. There's also a huge failure at the checks and balances stage where these agencies are getting approval which creates a feedback loop and without solving this the problem will continue to grow.
There are ZERO people from the pitchfork community who understands the pressure of working in keeping a community, region or country safe. If there is a terrorist attack, the pitchfork people have to answer to ZERO questions, while CIA/NSA/Police will have to answer 'Why didn't you do something".
It is so easy to sit in their comfortable offices and homes and philosophize about privacy when you have no skin in the game.
> It is so easy to sit in their comfortable offices and homes and philosophize about privacy when you have no skin in the game.
And I definitely agree with this. But that's also why I made a big point into that lack of encryption actually gives these agencies more work (if we look at history). The problem is exactly what you note though, there will always be failure and we ask why they can't stop near impossible things to stop. Post hoc analysis is always easier than in situ.
I think it is. The problem is, denying us access to safe communication is not going to make is more safe, but less.
“One who is elected by the common populace to facilitate business at the cost of logical reasoning, human rights and the natural world.”?
While I’m sure one or two exist, I can’t actually think of a politician in the US, UK or Australia who doesn’t fit into the definition somehow. Again, there would be a few good ones, just not enough.
The implementation of AES in popular CPUs? Yeah, who knows.
Strangely, HN is also very much in favor of the administration’s trade protectionism.
As far as Slack goes... I trust them as much as I trust Discord: I do not.
The "terrorism" rationalization provided for this surveillance has nothing to do with reality. The United States government is not in any way involved in fighting the source of jihadist terrorism, and the state responsible for 9/11, Saudi Arabia. They are allies, and Trump's cabinet is now attempting to arm Saudi Arabia with nuclear weapons. The actual intent of this law is to surveil whistle-blowers and journalists. WhatsApp messages have already been used in the case against IRS whistle-blower John Fry, who exposed the Donald Trump-Michael Cohen hush payments.
https://www.aljazeera.com/news/2019/02/report-trump-rushing-...
https://www.youtube.com/watch?v=JCo-0EAu5Oc
https://www.youtube.com/watch?v=XW-SjxsGHOI
https://theintercept.com/2019/08/04/whistleblowers-surveilla...
Those apps that provide end-to-end encryption are a problem and they are working on solving it.
Claiming that they should not be able to wiretap lawfully (or even otherwise) is a rather naive view of the world and lawful wiretapping does not imply dystopia.
Here's a case where the courts say that police surveillance was not correctly authorised: https://www.bailii.org/uk/cases/UKIPTrib/2018/IPT_17_93_H.ht...
Are they though? There will always be a means to communicate without surveillance. Backdooring encryption is fundamentally incompatible with privacy, and will be abused - at scale.
For any real cases, the security services have a multitude of other ways of getting the information they need regardless - for example, they could gaining physical access to the target's phone and backdoor/bug it, or swap it out with a backdoored/bugged one.
The real problem with backdooring or outlawing encryption is that it lowers the bar to entry for governments - it makes it too easy, and such sweeping powers will be abused.
That's a very bold claim.
Lawful wiretapping exists because it is accepted (and reasonable) that privacy should stop in specific circumstances, e.g. a criminal investigation.
As I wrote before seeing this in black or white is naive. Wiretapping is useful for society. The key is to have proper oversight.
By the way, to lawfully wiretap a phone the authorities only need the phone number: The operator will then duplicate all traffic transparently and on the fly. Bugging a phone really means illegal/covert operations these days...
When a weakness is introduced into that defense, even if it's a secret key held only by trusted governments and only (they promise) to be used in emergencies, that key is a method of attack that anyone, anywhere can use against everyone. The only defense is that the secret key remain secret, and there are an endless number of ways it could be comprimised, ranging from human error, phishing, or plain old brute forcing. A single key for all Whatsapp conversations is a valuable enough prize for criminals all over the world to invest serious money in custom hardware to crack it.
Currently, encryption schemes like Whatsapp's rely on generation of new keys for every message, making the value of attacking any one message limited. Without this defense, Whatsapp will be cracked, sooner or later. And once someone publicly reveals that key, every single message sent before that point becomes compromised. Maybe even publicly exposed. Would you be okay with that? Exposing your private message history to the internet because governments wanted to snoop?
If there is a key which decrypts everything, then there is a risk it can be stolen or guessed and used to decrypt anyone's messages. This risk does not exist in current, properly designed systems.
Any government which wishes to add a backdoor to an E2E encrypted messaging system must understand that they will be HEAVILY undermining the security and privacy rights for all users of the service which has the backdoor.
Whatsapp decided to go for E2E encryption for commercial and marketing purposes following all those privacy scandals.
They did not have to. They could have gone with P2P encryption, i.e. that their databases could have stored messages in cleartext. That way authorities would not have needed to ask for any backdoor. As already mentioned, this is how cellular operators work (that's obviously something governments wanted).
I think we might see legislation brought in in the future in order to force this.
Okay. Let's just get rid of E2E entirely and let Facebook mine not only our metadata but also the content of our messages. Nice plan.
> let Facebook mine not only our metadata...
Don't use Facebook, then.
Yes, but if you make it too easy, oversight fails or is worked around with legalese, and the powers are abused at scale.
> Bugging a phone really means illegal/covert operations these days
My view here is that it should be difficult - the security services should only be able to intercept someone's communications with a legally obtained warrant to do so (the oversight you mentioned); then powers are far more likely to only be used where the is a credible threat.
I hold the opposite view: that the idea that the evolutionary trajectory of the internet seems wont to continue to allow "wiretapping" (and, for that matter, the existence of a capricious state tout court) is the naive view.
The state is looking increasingly obsolete every day, and moves like this are significant leaps forward in solidifying that conclusion.
Politicians, generally, are not hypocrites. That implies the guise of good faith. Do you really think the biggest beneficiaries of terrorism are likely to be honest with you? Humans just like being told what to do and what to fear and whom to be mad at, and politicians make eager use of this role.
Lol. So I guess it cannot be used for actual terrorism. They can use it up until an act of terrorism occurs. Then, now that murder charges are on the table, they cannot use the same date source to catch the perpetrators? The US isn't going to waive the death penalty on every terror case. That isn't politically possible.
We have to just admit that US laws are increasingly incompatible with those of the rest of the world. Treaties are getting harder and harder to reconcile. The US needs to back off its departure from international norms.
US an UK governments can't just force FB to add backdoor. It would require new legislation. FB must play ball for that to happen.
Since WhatsApp has forward secrecy and end-to-end encryption, giving access to encrypted data is not easy to use. There might be some useful metadata that helps though.
It would be just access to encrypted messages. Unless the law enforcement has access to the phone used to send the message, encrypted messages are useless.
>"will be forced to share users’ encrypted messages with British police"
So far, all the article is saying is that ciphertext will have to be shared. Anything about decrypted messages is speculation at this point.
(It would be very bad if a backdoor will be forced.)
The sucky part is.. my mom loves Whatsapp. She was able to use it wo any issues. There are few alternatives that she was able to use so easily.
All that said, I wonder. What is the breaking point for people surveillance-wise? I was so wrong a lot about the tolerance already..
People is US had a joke about wiretaps and a variation of the joke returned.
People change based on stimuli.
I assume you'd be happy to post all your credit card receipts and emails for all of us to see then. You're not doing anything illegal, right? That would be the only reason you don't want those things to be visible.
It's a bad attitude to have because allowing the government to have that power at all is a problem, even for terrorists and murderers and pedophiles. Because we don't know if people are those things until we investigate them, which means the government gets broad powers to investigate people to look for those kinds of crimes, and maybe find other people they want to get for other reasons.
I used to investigate computer crime. Yeah, my job would have been a lot easier if I had unlimited access to anyone's email. But instead I had to investigate and build a case without privileged access. It was harder, but I was glad that the system couldn't be abused.
Why should governments or law enforcement have privileged access?
Who'll protect you when they come knocking on your door to talk about that thing you posted about somewhere online, which used to be quite legal and no problem, but now is super illegal for some oppressive reason or another?
First they came for the socialists, and I did not speak out—
Because I was not a socialist.
Then they came for the trade unionists, and I did not speak out—
Because I was not a trade unionist.
Then they came for the Jews, and I did not speak out—
Because I was not a Jew.
Then they came for me—and there was no one left to speak for me.That should be a much better analogy. Especially in the postmodern hypersensitive world.
I suppose the definition of illegal activity is also fixed and social norms will not change over time?
My point was that there is no uncompromised electronical communications platform. If you wish to communicate using anything having room for a man in the middle attack, it is very hard to proof that the medium is NOT compromised by a nation state or another third party.
You can communicate fairly securely without the messaging being intercepted by black hat non-nationstate third parties. I don't think anyone can guarantee security against nation states.
So if you want to communicate, you either communicate, or you don't, but requiring a 100% tamperproof platform is really hard.
For example, Echelon system probably had/has intercept capability for all phone traffic in europe: https://en.wikipedia.org/wiki/ECHELON
These systems were in place in 1960:s. AFter that modern telecoms substrate was developed in close collaboration with nation state defence parties. As a non-expert, there is no reason to think any platform is secure from nation state eavesdropping.
I've also been surprised how much a properly motivated non-techie can be. I've seen a few grandmothers who live far away purchase and setup a web cam and learn software I find confusing all by themselves.
Snowden was in 2013. I think all that happened is a few people were briefly horrified, but in no time it was back to business as usual.
You can even point to China as an example of how bad things can get when the state can read everything, but people just don't seem to make the connection.
It’d be a big deal to force FB to modify WhatsApp for message content interception and I think it’d be challenged in court.
I would expect such an accord between countries to enable data sharing, not force companies to record more data. So I'm sceptical of the article's claim for now.
Also, if we're talking backdoors, why not just force Apple to unlock devices so that police can just read the messages in WhatsApp directly? That's something I could get behind as it means the intelligence community has to at least have the physical device on hand.
Do people have actual links to this treaty they're about to sign and what the exact wording is? I remember there being this 5-nation meeting in the summer with Canada and Australia that was specifically looking to lobby Facebook to open WhatsApp. Haven't seen anything new since.
not really since most of them are connected 24/7
So let's say this law passes BUT someone builds a really good open-source messenger.
You can't install it now because you can't side-load apps on devices.
You alpha geeks can but the other consumers can't.
What we need is a law requiring some type of side loading.
It needs to be possible to go to a website, and install an app there directly and have it support all of the native platform features.
Isn't it literally enabled by 1 simple setting in developer options on an Android device?
Maybe you're talking about Apple specifically? Afaik, there's no way to do that on iOS (though I read a related article about it recently, I think it was here), so if you want that, petition Apple. There's no law preventing it given that Android devices can do it, so it's just an Apple policy, and you can always install apps through XCode if you want to.
In that case, would you expect the people who wanted this to actively create a means for its circumvention?
> What we need is a law requiring some type of side loading.
You are asking the bad guys (passing bad laws) to be good (passing good laws). I do not think those expectations are realistic.
It's worth putting scrutiny both on the UK's desire to create these backdoors in social media apps (a path that many would argue could lead to eventual exploitation and abuse of that backdoor by unintended parties), and also WhatsApp's ability to deny the existence of such backdoors, now or in future.
[0] https://www.thetimes.co.uk/article/police-can-access-suspect...
I think that it'll be secure enough. If private company can keep their CA key in secret, government can do that too. Hardware Security Module stored in defended military place and guarded by soldiers, available for use only by authenticating of the few key politiancs.
Yes, that sounds like a secure system. Surely no private keys would ever leak out of a government through incompetence or corruption.
"You're either with us, or a terrorist" Bush once said. And now we're at a stage where it's acceptable to say things like "if you've got nothing to hide, why are you so worried about this stuff?".
https://www.facebook.com/safety/groups/law/guidelines/
> International Legal Process Requirements
> We disclose account records solely in accordance with our terms of service and applicable law. A Mutual Legal Assistance Treaty request or letter rogatory may be required to compel the disclosure of the contents of an account. Further information can be found here.
Wow !! Just realized that.
> Share snippets: Automatically share snippets of what and how you type in Google apps to improve Gboard [enabled by default]
I'd imagine if the police are then in control of the target mobile they can decrypt those messages.
Tbh, if my understanding is correct, I'm not sure I see any problem there. It's targeted at specific individuals for good reason (presumably following a warrant process) and requires both the messages (from Whatsapp) and they keys (from the individual's device). What's the problem?
>Priti Patel, the U.K.’s home secretary, has previously warned that Facebook’s plan to enable users to send end-to-end encrypted messages would benefit criminals...
In London alone, it is not possible to pay for public transport with cash. A debit card/oyster is required but for anonymous travel, an oyster can be topped up via cash and reduces transport surveillance, unlike using credit / debit cards. Their reasons for doing this because it "benefits criminals" is echoing the "ban encryption" nonsense.
> The U.K. and the U.S. have agreed not to investigate each other’s citizens as part of the deal...
This I don't believe.
EDIT: Use a oyster card for public anonymous transport, refrain from using a credit / debit card for this.
I live in the UK and I feel like this is the crux of the issue. I am an active member of a sports car forum in the UK and it's terrifying how little police does in case of theft, even when the house was broken into to get the keys. If you get someone to come out and write down a report that is a miracle in itself - in 90% of cases you are just given a case number and told to speak with your insurer, nothing is ever done. I know a guy whose Range Rover was stolen, he reported it, no one came out - then few days later found it parked in a car park nearby, he rang the police to tell them that he found his stolen car, where it is, and asked if they want to come over and maybe catch whoever comes for it(or you know, maybe take fingerprints and such)? Nah, he was told that if he still has the key he can just take it, they don't have any officers to actually come out anyway. I have friends who were robbed, burgled ,and literally nothing is ever done. There is zero police on the roads around where I live, I'm actually surprised people still follow the rules of the road because realistically, the chances of ever running into a police car are somewhere around zero.
It just feels like police in the UK has been gutted to the point that unless you are literally being shot/stabbed, there is not enough resources to actually help or investigate anything. It's a shell of a functional service.
I can't say this in any less of a politically charged way but 10 years of austerity will do that.
Please don't irresponsibly spread this kind of inaccurate information. Crime in London is not unusually high.
You can also buy cash tickets like a travel card
Not strictly true. You can buy an oyster card with cash, you can load it with cash and use that. After a weeks worth of journeys you can return it and get your £5 deposit back and buy another one.
Not exactly perfect but it's essentially the same as having a burner phone.
https://www.independent.co.uk/news/uk/crime/facial-recogniti...
I suppose they'll just pass the laws(?) making it all illegal but only enforce it when it's politically useful or if someone rocks the boat.
In the US, ITAR could hypothetically be used to make open-sourcing of cryptographic algorithms illegal. This technique is used for robotics software that could be dual-purposed for weapons guidance.
That said, freedom can also be in our own minds, creating a good life in an ocean of political corruption and increasing control of corporations/elites. It would take more effort, but I think I could also have a good life in Gibson’s sci-fi worlds.
Wikipedia has some good info re: export of cryptography[0].
In addition, two circuits (Ninth[1] and Sixth[2]) have ruled that source code is protected by the First Amendment.
[0]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
[1]: https://en.wikipedia.org/wiki/Bernstein_v._United_States
Obviously, classifying something that has already been open source just makes it more difficult to use and numerous local copies will be retained, but it does make further distribution illegal.
This is the only mechanism I can think of by which the US government could kill Signal in its existing open-source form. It's ugly, but not unthinkable.
OpenBSD in the 90s used to emphasize that they're from Canada and have strong crypto because of that.
Sweet Jesus this people are insane
(As an aside, there was meant to be a parliamentary review of the Assistance and Access Act earlier this year -- but I haven't heard anything about it.)
Users need to learn to not have any expectation of privacy when using social networks. It extends far beyond PII leaks.
Perhaps complaints should be directed at the root of corruption/abuse of such systems, at least as much as the capability itself. The capability is inherent to the technology just as tapping a phone line is.
Telcos have to provide interception capabilities (CALEA in the US) or they are not allowed to operate. This has been true for decades, most people do not know how that works but they do know it is possible. As these social media communications services become more entangled in our lives perhaps they too could be deemed essential infrastructure and treated as utilities.
sigh
"Pedophilia" is not a crime, child rape is.
But people on both sides, do you think it's OK for you to have nothing to hide, but the government that rules you has something to hide?
For me it's not so much whether I hide something or or, but rather that if I'll be living under nothing to hide paradigm then the people controlling that should also live under the same. And actually not only the people but rather the institutions. So if an institution is having access to all citizens data that is being collected then the citizens should also have transparency on each decision made and each cent spent by this institution at any time.
These are free software, not controlled by a giant corporation (although both are limited liability companies; Telegram in London/Dubai, Signal in San Francisco IIANM); with the developer/company not having unencyrpyed access to your data.
I use both apps regularly but neither of them is perfect.
Anecdotally speaking, neither I or my friends that have been using Signal for years have every had any messages go missing, so I’m just interested as to why you might be experiencing this.
I wonder if it’s something like geography based? By chance are your contacts mostly in the same country - if so which country?
Everyone I speak to on Signal is based in Australia, mostly in Melbourne but a few in Brisbane and Sydney.
This is the newspaper that had an editorial starting with "Hurrah the Blackshirts".
https://www.globaljustice.org.uk/blog/2017/oct/31/horrible-h...
Other than using it as a way of keeping an eye on what some people in my society will believe (because the Mail told them to) I see zero merit in it's continued existence.
It's a cancer with a masthead.
The Express and Telegraph were right facing, honest but partisan newspapers forty or fifty years ago. Now the Express is a racist comic, and since the famously and comically reclusive Barclay brothers bought it, the Telegraph is working on getting down to the Mail's level. The Mail are currently working on buying the i.
There really isn't much left on the right that you can rely on. Which is depressing considering most of our press is right leaning.
It seems this would only serve to catch the most stupid small-time criminals.
You can find the book here: https://upload.wikimedia.org/wikipedia/commons/4/45/Anatomy_...
I've messed around with the open source cryptography libs before and I don't see why someone could not do that.
There's even a fair bit of advice about how not to misuse such libs.
https://twitter.com/mmasnick/status/1177979730932297728?s=21
Another is that when some rooms get updated, you can get unread notices from the old room and your client keeps telling you that you have new messages even if you don't.
Another thing that I think should be considered a bug, is that when you enable encryption in a room and you have multiple devices on the same account, you have to approve all your devices separately so that they will be able to decrypt the messages...
There are more bugs related to how the encryption process works and I stopped using encryption because of it (some might have been fixed by now...)
We're a little different in that we're trying to solve more than just the privacy issues. We're also trying to solve the spam problem for anyone who receives a lot of random inbound email/messages (think open source developers, linkedin spam, anyone who's an influencer).
In both cases they need to be fought from another angle than freedom of speech, because we've already lost that battle.
C8hWgwo5YeC5ojiOaDe3JVaLev+3zaZDfRVTAjvqNCA=
("Jedberg is thoughtful.", encrypted with AES key jedberg).
I must be able to do so. To compel a backdoor is to make some speech illegal.
Banning C8hWgwo5YeC5ojiOaDe3JVaLev+3zaZDfRVTAjvqNCA= is akin to banning shouting in a theater, for any purpose. In particular, the banning of political speech is highly protected. One cannot readily show that C8hWgwo5YeC5ojiOaDe3JVaLev+3zaZDfRVTAjvqNCA= is not political speech (and indeed, here, it is).
(with the authorities then being in a position to compel the end users to give access to devices).
This might mean "...must share messages that are otherwise encrypted", it's not completely clear from the language used.
"will be forced to share users’ encrypted messages with British police"
So far, all the article is saying is that ciphertext will have to be shared.
This will do nothing except intrude on civil rights.
It's also interesting how the Left and Right flip positions when arms are digital.
Does this mean they're sharing ciphertext or plaintext? Anyone know?
If true, I wonder if this includes other US based apps like Signal
If that's all this is, good luck to them doing anything with those.
We are venturing straight into a totalitarian nightmare, and are totally fine with it.
Ohh, right: https://queue.acm.org/detail.cfm?id=2508864
I would think this should at least be against one or another amendment for Americans?
Would Apple's iMessage qualify? (I can't read the whole article because of the paywall).
I'm not a right-wing anti-government nutcase. I do believe that the government will not be able to keep such a back door secure.
The safe variant LibreSignal was killed by Signal. https://github.com/LibreSignal/LibreSignal/wiki/What-to-do-a...
> To be clear: the reason for this is not security. To the best of my knowledge, the Signal protocol is cryptographically sound, and your communications should still be secure. The reason has much more to do with the way the project is run, the focus and certain dependencies of the official (Android) Signal app, as well as the future of the Internet, and what future we would like to build and live in.
Beyond the author flat out saying that it’s secure- the title of the article is why they will not recommend it. It has nothing to do with it being compromised.
> The U.K. and the U.S. have agreed not to investigate each other’s citizens as part of the deal
It is entirely possible though to have a true end-to-end encrypted channel if both parties are able to do the encryption in their heads without the plain text message ever being visible. A trivial practical example would be a single bit message with a single bit one time pad (agree ahead of time that if I say yes on the phone, it means no and vice versa).
Also, the article is unclear about whether the messages have to be decrypted before being shared, so they may just have to share the encrypted message.
This really hurts our credibility on a government level outside the Five Eyes.
2) Personally I still think e2e encryption is not a secure solution on operating systems that runs godmode 3rd party, eg. google play services: it relies on a key that can be stolen too many ways too easily. Signal included.
3) internet eons (20 years) ago we nearly all used plain text IRC, closed source ICQ, AIM, etc, apart from a few. Recently I started to question the usefulness of "encrypt everything": we do need a way to verify the content from end to end, but is encryption really the way to do so? Are there any other ways, signatures, hashes, etc?
4) All that said, I'm not surprised. Skype used to be p2p, until M$ moved it to server-client, because "battery life". Everything is moving back to the Eternal Mainframe in this cycle.
I mean go ahead, do everything unencrypted. But I surely won't entrust data to you if you're leaking like a sieve.
That is not what I wrote. I wrote "encrypt everything". There is valuable and useful use of encryption, I'm just not certain everything everywhere needs it or benefits from it.
That said, I do agree that p2p is preferable since it cuts out a central party that can be strongarmed by government being in control