Attorney General will ask Zuckerberg to halt plans for end-to-end encryption
buzzfeednews.com
buzzfeednews.com
Oh, so you’re asking for more end-to-end encryption?
> While the letter acknowledges that Facebook, which owns Facebook Messenger, WhatsApp, and Instagram, captures 99% of child exploitation and terrorism-related content through its own systems, it also notes that "mere numbers cannot capture the significance of the harm to children."
This is such a lazy argument :/
Credit where it's due, good on them building such effective systems to catch this content.
There's a little ambiguity in there, but I wouldn't go so far as to say it's "misleading".
You can get legal datasets for sick pr0n or warzone stuff you would like to keep off-platform that might have the same psychological effect on you.
Facebook has said that they don't do this outside of Australia, where it is required by law, but come on, are we really going to take Zuckerberg's word for it?
This is why I believe that end-to-end encryption is not truly useful unless the source code of the clients is public, or the protocol is open.
Any closed source client can read messages at the ends, or be forced to do so by an evil government.
At the very least, they could open up XMPP compatibility again so that people could write their own open source clients for it. Australia wouldn't be able to do anything about the propagation of such open source software.
I was able to have end-to-end encryption running on top of MSN, AOL, ICQ, QQ, Facebook, Gtalk, Yahoo, and several others about 10 years ago with Pidgin and simple plugins that encrypted/decrypted messages on the fly. It's too bad they all moved selfishly to closed source walled-garden mobile apps -- it's a big step back in privacy.
[1]: https://matrix.org/
Matrix is close, but not what I'm describing. It's far more centralized than I'd like to see.
They want a fishing net so they can catch these people by the thousands.
i.e., of the illegal stuff that goes through their system, some of it is captured, and the majority of that is caught by Facebook's own system.
Note, this article is recent and highly relevant: https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
> And when tech companies cooperate fully, encryption and anonymization can create digital hiding places for perpetrators. Facebook announced in March plans to encrypt Messenger, which last year was responsible for nearly 12 million of the 18.4 million worldwide reports of child sexual abuse material
> Data obtained through a public records request suggests Facebook’s plans to encrypt Messenger in the coming years will lead to vast numbers of images of child abuse going undetected. The data shows that WhatsApp, the company’s encrypted messaging app, submits only a small fraction of the reports Messenger does.
Talk about fear mongering, that article is horrible. It's the same old argument. "Child abuse is bad therefore you can't have any privacy", they position you as being against protecting children when your stance is actually pro security & privacy.
1. Privacy is important and good
2. It has almost certainly contributed to an explosion in the production and sharing of child pornography and abuse
The question is what is the moral way to reconcile the two, not to deny that either exists.
However, without perfect privacy, every world citizen would be subjected to such monitoring, and we'll basically be exactly what 1984 is, with the metaphorical "telescreen" functionality spread across pretty much every device that's connected to a network.
Child abuse has always been happening (several of the older members of my family were abused), it just wasn't broadcasted. Even today I bet 99% of child abuse is never caught on camera. The increase from child porn is probably negligible.
The USA took steps to actually protect property in its founding, something the Supreme Court has interpreted to include privacy as well. From this perspective, the rights of citizens wither away when the government is allowed to take the smallest step towards mass surveillance. For that reason I am very much against it.
My other perspective is from a security standpoint. I believe that if companies are not doing everything in their power to protect themselves and their users from data loss / hacking / theft, they put everyone at risk. Intentionally lessening the security of a product at the request of the US government means giving a potential thief or hacker more attack vectors to exploit.
> The Times’s reporting revealed a problem global in scope — most of the images found last year were traced to other countries — but one firmly rooted in the United States because of the central role Silicon Valley has played in facilitating the imagery’s spread and in reporting it to the authorities.
Clearly the NYT is laying the problem at tech's feet, and we are the best ones able to thwart this. Many times I've scoffed at the government's continual removal of privacy, but this is the first time it's sunk in. Perhaps they have a case.
> 1998 - 3k cases. 2008 - 100k. 2014 - 1M. 2018 - 18.4M.
These figures from a total of 45M images flagged.
Again, is this for real, or this this propaganda?
There are two things I would point out: 1) I would be surprisesd that the ease of communication the internet brought did not benefit to criminals 2) The article describes several problems that won't be fixed by encryption ban (e.g. the lack of means for report clearing houses) and also gives exemples of cases solved despite encryption. I would like to understand why encryption is described as the problem here.
Not to mention:
Congress has regularly allocated about half of the $60 million in yearly funding for state and local law enforcement efforts. Separately, the Department of Homeland Security this year diverted nearly $6 million from its cybercrimes units to immigration enforcement — depleting 40 percent of the units’ discretionary budget until the final month of the fiscal year.
Or in other words, in order to fight the imaginary rapists that Mexico is allegedly sending us, DHS is diverting money originally allocated to investigate actual child rapists.
It's disgraceful that Signal hailed WhatsApp's announcement to use it almost like a second coming of a religious figure.
> "The proponents of this process use fear tactics to win support, what the four cypherpunks dub "The Four Horsemen of the Info-pocalypse: child pornography, terrorism, money laundering, and the War on Some Drugs." In other words, laws passed to go after child pornographers, terrorists, money launderers, and drug dealers end up chipping away at everyone's privacy. The classic example is the PATRIOT Act, passed to prevent terrorism but soon used to expand wiretapping and National Security Letter powers in other contexts."
edit: ok ok sorry I misread
2) terrorism
3) money laundering
3) war on [edit: some] drugs
But rarely did you see or hear about any of those people landing in jail or prison for long periods. If you heard anything it was more or less laughed about, and society forgot about it. The perps maybe would spend a day or two in jail, get bailed out, and have their lawyers negotiate and plead down to a misdemeanor or something like that. Rich guy goes back to party and life.
Crack users? Well - they all ended up in prison for super long stretches and/or died there. Nobody cared or cares. Certainly not the above cocaine users and abiders.
It wouldn't surprise me to learn that the people abusing the cocaine and making deals like that weren't also in on the production and selling of the crack made from a portion of that same cocaine...
I'll take the privacy side in most any discussion of privacy-vs-security, but categorically denying the possibility that some crimes could be aided by encryption seems a step to far.
It's also bad PR strategy: anybody not already on your side will be put off by your apparent lack of reasoning skills.
Instead, acknowledge the possibility and show them why you consider the benefits outweighing the risks.
The societal default used to be that substantially all conversations were inaccessible to the government except through testimony. Encryption does nothing to change the availability of information through testimony.
Previously, remote conspirators could collaborate through the post, and their conversations could only be accessed with a warrant specifically targeting those communicators. End-to-end encryption does little to change the availability of information in a targeted investigation; it just means it's a little more difficult to access the information than entering a phone number into XKeyscore. Investigators can install malware on the device, or microphones and video cameras in the suspect's home to hear or see what is being communicated.
Forbidding end-to-end encryption, in combination with our mass surveillance apparatus, changes the societal default to be that substantially all conversations are trivially and automatically accessible to the government.
I for one am not willing to give up any freedoms in order to prevent the sharing of such vile material. Perhaps the creation, but not the sharing.
I'm sure some of the kids in those videos would have something to say about that.
I don't see those kids getting hurt any further unless they happen to be the sort of people that go out of their way to seek out child abuse material. It's hard to imagine anyone ever accidentally running into images of themselves being abused. You can't possibly be re-victimized if you don't know.
I don't mean to sound heartless, obviously these are horrific acts which hurt people deeply. I simply don't think banning encryption or otherwise eroding our rights to go after distributors and consumers is really going to have much practical effect on how the victims end up feeling.
E: HN doesn't let me reply to selectodude below
>the mere knowledge that pictures of you being abused on the internet is extraordinarily difficult to deal with
I absolutely agree with this. I just know that nobody can ever go tell the victim that now those pictures are forever gone off the internet.
But yes, the mere knowledge that pictures of you being abused on the internet is extraordinarily difficult to deal with. Maybe not the best direction to go in when arguing.
I'm sympathetic to those people's plight but ultimately I place a very high valuation on not only my privacy but everyone's privacy, A much lessor but still very great valuation on preventing such evil happening to the victims, and only a small valuation on preventing the ultimate sharing of those images between perverts except insofar as it serves to lead us to people doing the wrong.
I believe that via a substantial effort we can work to reduce the abuse of children, I think we can via a lot of work take down the groups of people sharing such data by infiltrating such groups and taking down the people participating. I believe that outright stopping all such sharing is probably impossible and I'm unwilling to implement 1984 to try.
Child porn piracy is an essentially victimless crime.
Note: In the above I am considering the generic example of "child porn" to be broadcasting the forcible rape of prepubescents, not 17 year olds sending each other naughty pictures, which is what most content matching the US legal definition is (the UK one is just stupid as it includes drawings).
This runs contrary to the fact that people share things not just for monetary profit, but for other videos/pictures in exchange, and voyeuristic/exhibitionist reasons.
This is contradicted by the evidence we have to the contrary, in particular the model of supply and demand identified in child porn markets.
Anyone remember the FBI and Apple case a few years back? How quickly the FBI hacked the phone after Apple wouldn't cave? Other tools exist to do targeted surveillance and targeted attacks. Only authoritarians want mass surveillance.
To be fair, Apple is working to ensure FBI won't be able to do that next time.
Sure. Before the telegraph was invented. And even before that people used security measures, such as wax seals on letters to prevent tampering or at least have an ability to detect whether or not the message has been tampered with.
You seem to think of messaging systems as if they were spoken conversations in private. They are not. Just because you are chatting with someone from the privacy of your own home, doesn't negate the fact that your words are traveling through a lot of wires and boxes belonging to all sorts of private and public entities.
During WW2, American federal government established Office of Censorship whose sole purpose was to review and censor all communications coming into and out of the country. Now imagine them finding that someone is mailing letters written in an unbreakable code. How long do you think it would take for the FBI to break down that person's door?
I am not saying we should not have end to end encryption. I am saying that government spying on citizens is nothing new, it is not something that was ever limited to totalitarian dictatorships and it should not be surprising to anyone that the government is trying to fight it. The news is not that the government wants to keep an option to read your communications. The news is that first time in history there is a chance people might want to and be able to stop them.
It wasn't done that way. Envelopes were opened, and stamped "Opened by Censor". Material was cut out of letters. Censorship was not concealed at all.[1][2]
[1] https://www.archives.gov/publications/prologue/2001/spring/m...
"Why isn't your desk in front of the telescreen?" - 1984
The day will come when not having an Amazon Echo or Google Speaker will be considered probably cause for a search.
A secure E2EE system must resist even targeted, legally authorised attacks. Are you suggesting that secure, practical E2EE systems do not currently exist? Would a world in which law enforcement must install physical listening devices and exploit unpublished software vulnerabilities to surveil suspects be more private than our current world, where E2EE is available but often disabled by default, and trusted intermediaries like Facebook and Google can be legally compelled to disclose non-E2EE messages?
> Forbidding end-to-end encryption, in combination with our mass surveillance apparatus, changes the societal default to be that substantially all conversations are trivially and automatically accessible
That is not (publicly acknowledged to be) the case today, even though non-E2EE platforms like Facebook are widely used. While Facebook could currently comply with laws authorising mass surveillance, and implementing secure E2EE would prevent them from doing so, the warrants under which they currently hand over non-E2EE messages are at least somewhat targeted. This controversy is not about a proposal to relax the need for warrants, it's about asking Facebook to preserve their ability to comply with them.
They're not. A number of horrible things will happen as a result of pervasive end to end encryption.
However.
You have to run the numbers here. On the one hand, perhaps a bit more crime, some of which horrible. On the other hand, the privacy of everyone.
It's a hard sell. Just picture a politician on live television having to choose between having this cute little child being raped for years before they commit suicide (letting the perpetrators off the hook), or ramp up the surveillance a bit. Picture them choosing rape.
Nevermind the false dichotomy. The horrible fact is, the value of human life is not infinite. A mere inconvenience, suffered by enough people, is worth killing a few. Such situations rarely present themselves. (We rarely condone murder in the name of the betterment of humanity: some tried, didn't go so well.) End to end encryption (and metadata hiding while we're at it), is such a situation. The harm, though hard to perceive, is significant, affects everyone, and can potentially grow into full blown totalitarianism (possibly enforced by incentives rather than violent policing).
Preventing that is totally worth killing a few children… or at least spend resources on properly policing the problem, like going undercover.
Still, go say that on TV. I'm not even sure I'm safe writing it here.
Yep. I'm pretty sure you just torpedoed any hope you may have had at a political career.
sounds like "War" to me.
1. They said that FB captures 99% of those illegal activities by themselves. What makes us think that government will be able to capture that last 1% on their own?
2. Encryption gets removed, potential perpetrators move to another platform that uses encryption and doesn't have the capability to catch those illegal activities that FB already catches using their internal systems. Congrats, now those perps that would have been caught (even if FB implemented the encryption) won't be caught at all.
And with the uncertainty that comes to mind with both of those points, one thing that is definitely guaranteed to come is further erosion of personal privacy.
To stress even more on this point (I have to also FULLY agree with the second), what evidence is there that lack of encryption will even make it easier to capture this 1% more. Pareto is a real thing. I'm not convinced there's an easy answer to capturing the last 1% and that it can be done with minimal resource allocation. That's where I start being suspicious. The back of the envelope math doesn't work out.
I spent less than a minute thinking about this, but there are probably tons of other strategies they can employ. People familiar with the domain, I would actually love to hear your takes on this, as the topic is fairly fascinating.
I think everyone here is familiar with Pareto. Capturing 80% of criminals is easy. Catching the next 10% is harder than catching that first 80%. Catching that last 1% takes significant amounts of resources, way more than the previous 90%. So it just isn't economically viable to stop it all (exponential curve and we don't have infinite resources).
So I'm not sure that saying
> A number of horrible things will happen as a result of pervasive end to end encryption.
But I don't think it is necessarily wrong either. I think encryption enables it, but this sentence implies causation (which is the rhetoric of those that want to remove encryption: causation).
How I read the horsemen comment is that these topics are used as boogie men. Because what sane person wants that stuff to exist? OF COURSE we want 0%. How can you be against stopping child trafficking? (practically) No one is against that! These are also topics we care VERY much about. Because frankly we should do everything we can to stop child exploitation. But we know the goal is unobtainable and to get only a handful more than we currently get (which is almost all of them!) requires huge violations of privacy and significantly more resources to be allocated. The horsemen are being used to get us on board and make us not ask if these methods are meaningfully effective or ask what the costs are. It also says that anytime you hear officials talk about the horsemen that you should perk your ears up and start asking serious questions. How effective is this? Does it actually help? What are the costs? The Patriot Act is a good example. It is not clear that it meaningfully reduced terrorism in any way and yet we gave up a significant amount of privacy (I can quote founding fathers on this too).
So it boils down to "if giving up the privacy does not do an effective job at making any meaningful reduction in actual child trafficking <insert horseman>, why should we give that privacy up? There's clearly benefits to privacy. So is this issue really about child trafficking or is something else at play here and are they just feeding off my emotions?"
Yes they are. And it works because we can't multiply, emotionally. I tend to avoid LessWrong links around here, but this one is appropriate: https://wiki.lesswrong.com/wiki/Shut_up_and_multiply.
My first comment alluded to the torture vs dust speck dilemma. Horsemen vs privacy is nowhere near as extreme (especially at the dust speck end), but it has the same structure. If lay people realised this, the horsemen would not convince anyone.
Actually, please stop there and think about this for a second.
Having zero crime depends extremely strongly on the precise definition of "crime". Much more so than other, non-zero levels of crime.
This is only a good thing if you are absolutely sure that the definition of what constitutes a crime right now is perfect and immutable.
Extreme positions are almost always a bad idea and I think this is one of those cases.
I'm adding to your point by saying that I don't consider "0% crime" as a desirable goal since crime is something defined by people and people are fallible, hence the definition is also fallible.
The problem is not in removing meaning from the word "crime". We all have an imprecise, handwavey meaning of the word in our minds when we use it. We usually mean something like "undesirable behaviour which benefits a single individual while harming others". The problem arises when you try to operationalize this loose notion into laws since this process frequently results in errors. Another way this can go sour is due to overreach by groups currently in power in an effort to stay in power, leading to loss of freedom (which is more applicable in this case).
In other words, some crime is actually people breaking the law because for good reason, like rebelling against an unjust, inefficient or overreaching law.
Therefore, it's better to strive for a low crime rate than a zero crime rate. This is also the conclusion you arrive at through the application of the Pareto principle.
If you consider "not saving while you could" the same as "killing", it's very common. So much in fact that it has its own WikiPedia page:
https://en.wikipedia.org/wiki/Value_of_life
With a cosy link to a letter by the Department of Transportation:
> this guidance identifies $9.6 million as the value of a statistical life to be used for Department of Transportation analyses assessing the benefits of preventing fatalities and using a base year of 2015
https://www.transportation.gov/sites/dot.gov/files/docs/2016...
Our society at large acts just fine with drunk driving deaths; looks like killing people while drunk is less abhorrent to us than trading photos of a teen.
I’m guessing it has to do with sense of purposefulness, malevolence vs. negligence, or identifiability with the commission of the crime?
Sure, idiots do stuff like this all the time. Sure they get caught. But idiots usually get caught by other means, too. And you never catch all the idiots, there's just too many of them.
But the argument doesn't even make sense. It makes the horrible assumption that pedophiles will continue using a service they know to be insecure. That's literally a provably false assumption. The second they realize it's insecure (which will take exactly one raid), they'll switch to something else.
And ALL of the above assumes that there are no criminal programmers and thus they have no ability to just write their own tools if there isn't something sitting on the shelf. We know with 100% certainty this is also a false assumption.
It's not an assumption at all. The fact that people engaged in child pornohraphy have had decrypted communications used against them in court demonstrates this to be true.
Ephemeral conversation is not new and implicit in a right to privacy assuming it extends beyond your actual corpus.
The only way I understand your arguments to be a justification to break encryption is if you believe we should not have freedom to share privately.
It only demonstrates that for some people, it's true. What about cases where they were using secure channels and thus haven't been caught/charged?
Perhaps we should aim for not leaving any piece of space on Earth unsurveilled?
That's literally a provably false assumption.
The second they realize it's insecure (which
will take exactly one raid), they'll switch
to something else.
It is trivial to prove that the second a criminal realizes a given communication mechanism is insecure they do not stop using it if it is convenient.Has every criminal in the world stopped using the phone after the first phone was ever tapped?
And ALL of the above assumes that there
are no criminal programmers and thus they
have no ability to just write their own tools
But we know there are more than 0 non-programmer criminals who will not be writing their own tools.You need better arguments than "if we can't stop all crime with an action it has no value" because it is a silly argument.
Arguments like "we all need to abandon privacy to maybe, potentially stop some crime somewhere" are equally silly.
Everyone should avoid silly arguments.
But imagine if some crazy billionaire set up some sort of autonomous decentralized system that constantly attempted to MITM all the same systems the government likes wiretapping; and then, if it managed to extract any data from that attack, it would find names in that data, and put bounties out on those people on assassination markets (paid from anonymous accounts previously set up by the billionaire.)
Now the choice is between some people dead, and a lot of people dead! Everyone get on board the privacy train!
That is-- pick an insanely fast development cycle where piecemeal/baroque security approaches simply cannot keep up. Eventually you arrive at a place where the whole endeavor become a giant tinder box just waiting to go down in flames. But that forced browser vendors to say, "Ok, let's just assume everything is constantly on fire, cordon everything off into flame retardant boxes, and improve our response time by many orders of magnitude."
If anything ever gets too hot from the thousands of strangers I casually let in the front door I simply move to another building and recycle the burning one.
Meanwhile I treat my Debian install like a prized piece of Shaker furniture. You'd have to be a goddammned 19th century furniture historian with your credentials showing before I let you anywhere near my brittle little museum.
We used to be protected by the ephemeral nature of 99% of life and by the inability for anyone to centrally view or mechanically process the other 1% (letters, diaries, etc). This is just as much argument for strong protection as your argument goes against strong protection.
We see politicians regularly choosing to not enact overwhelmingly popular positions like universal background checks in the face of mass murders of children.
How many politicians have done anything to stop the Catholic church from hiding child rapists? This is a much more direct harm and no one who isn't a child rapist would lose anything if we fixed it.
Politicians are already choosing rape and murder when the stakes are much lower.
It's not just a matter of "many small harms > few large harms" though. Not having privacy can lead to severe harms.
If the bad guys break into a system that allows them to effectively wiretap everybody, now they can snoop around and find blackmail targets. "I know what you did, have sex with me or everyone will know. Or send money. Or give me your employee access badge."
Results: Rape, financing child sex trafficking, facilitating an act of terrorism. Or any of the less visceral but nonetheless widespread and significant consequences like major financial fraud or corporate espionage.
And that's just blackmail. What about the suicides of people who get doxxed? Or the people in violent relationships whose abuser is in law enforcement or in a criminal enterprise that has compromised the surveillance apparatus? Or the mental health epidemic which results when people know their communication is exposed to people they don't trust to see their true selves and then self-censor into performance-art conformists riddled with anxiety and loneliness?
Privacy is about keeping perverts in law enforcement from reading the sexting that should only be between you and your spouse, but it's also about keeping the country and the people safe from terrorists and foreign powers, keeping victims safe from abusers and allowing people to satisfy the human need to be themselves in communications with people they trust.
Privacy isn't a trade off against security, it's a necessary component of having security.
FWIW, I applaud your willingness to make such a statement. (And no, this is not sarcasm!) Self-censorship is a horrible thing, and I feel like I die inside a little bit every time I catch myself doing it. But more and more these days it begins to feel like even hinting at a willingness to engage in "thought-crime" is exceedingly dangerous. I mean, shit, a woman got passed on for a job because she had a picture of herself in a bikini on her Instagram. Imagine if a prospective employer find a comment online which could even remotely be twisted into saying that some child deaths are a sacrifice that may be inevitable in order to protect an abstract principle like Freedom, or "Free Speech". Zoinks!
Do you say you want to apply a dictatorship state of global surveillance because criminals are going to use the internet? What about other tech available to them? Are we going to set up a surveillance mechanism in those as well? Scooters? Cars?
Who's going to compile all that data? How is it protected?
It's about the Governance of Information,
and guess what,
I want to be Governing my Data, not some shady politician that got elected for a 5 or 7-year term in some other country.
Every actor in those systems have access to the data of every person that got their info collected.
And yet we are still here with that pedophilia and terrorism argument that, while they are very true, have still evolved and expanded. Even with the Cloud Act and all of the shady agreements
It's an evolution of our sick society, we had that kind of criminality rampant in 2000, we saw that evolve with the net,
But just like the young gangsters that evolve with stolen scooters,
Criminality will always have its sick way.
But dictatorship and global surveillance?
We didn't accept that in the 2000.
And we should never accept that at any cost,
even if it falsely promises to resolve the problem of pedophilia, terrorism, and criminality on those spaces by applying weird unknown algorithms
Technology will always be used by criminals because these are part of the society we build and evolve. They will change their behavior just like all of us; We cannot give up on our freedom and ethics to help catch the few.
And that's what's the problem. I don't care about police retrieving the data of a criminal once a judge has agreed to that, I care when we give them the entire web information and allow them to dictate the behavior of those networks
This was tried by a Canadian Minister at one point to sell surveillance in this extreme way:
> In February 2012, as Minister, Toews introduced the Protecting Children from Internet Predators Act (also known as Bill C-30).[118][119] The bill, which made no mention of children or "Internet predators" outside of its title,[120] would have granted police agencies expanded powers, mandate that internet service providers (ISPs) provide subscriber information without a warrant and compel providers to reveal information transmitted over their networks with a warrant. When criticised about privacy concerns, Toews responded that people "can either stand with us or with the child pornographers."[121]
* https://en.wikipedia.org/wiki/Vic_Toews#Federal_Minister_of_...
The legislation in question went down in flames as plenty of people sided "with the child pornographers":
* https://en.wikipedia.org/wiki/Protecting_Children_from_Inter...
This argument is so unbelievably stupid, that I don't even know where to begin.
First of all, encryption in WhatsApp is targeted towards consumers. You won't catch terrorists by limiting encryption. If terrorists and other criminals are not using encryption anyway, then they are so stupid that they deserve to be caught.
The only thing a lack of privacy does is throwing us further into dictatorship. Just imagine a madmen, like uhm... say Trump, with the full power of the secret service behind him and limited to privacy for end-users. Well this is just great. All the dirt he can dig up about his opponents. He asks foreign governments to dig up dirt, okay, that means right now the NSA isn't too much inclined to help this guy out, but what if they were?
If you water down privacy you are robbing the people of their only chance to organize protests and rise up to authoritarian governments.
Last but not least, the crimes prevented by not using encryption are absolutely negligible. The numbers are so freaking low that each day more people will die in car accidents in the US alone than would die globally because of pervasive usage of unbreakable encryption.
This analogy of `Uh a person could be prevented from getting raped is more important than preventing a fall into dictatorship` is so contrived that I don't even understand how anyone can eat this shit. Bad things happen all over the place and you are buying this sham argument that is preying on human psychology.
There's also personal defence, but that one has disadvantages too (there might be false positives, were a presumed mugger would get shot). Plus, from what I hear, guns have different effects in different countries.
It's a complicated subject. My opinion right now is not informed enough to be trusted.
Who is more of more danger to you. A cabal of rich drug dealing terroist pedophiles or your own Government? The argument then becomes one of statistics and then of the lesser harm.
I imagine the answer is obvious with the Government being sigificantly more harmful. You're likely comparing a few hundred deaths of tens of thousands.
You'll always find a subset of the population who thinks the death of citizens or harm is justified in some way, because they took some action that broke the law.
But find enough examples where the offernder did no direct harm to anyone else and I suspect you'll give most reasonble people pause for concern.
And if the facts don't match your gut, then maybe you're wrong and privacy isn't all that important.
The thing to point out is that we all make the implicit choice to let people die for convenience every single day: Almost all of us could choose to pay a bit more to charity to save a life, almost no matter how much we're currently giving or what we're currently doing, or could choose to take jobs that would do more to make the world a better place.
We just rarely have to face what choosing differently would have meant, so we get to pretend it doesn't have much to do with us. And granted, most of the time the consequences are many steps removed from our choices.
Wow. I can't agree with that one even a little bit. The real concern is totalitarian abuse. But being inconvenienced allows us to kill? That rings as downright pathological.
In practice, the tradeoffs are never that extreme.
Estimates say there are something like 20-40 million slaves in the world, and that 50,000 people are trafficked per annum in the USA. Something like 20% of slaves are sold for sex. Facebook is believed to be a common platform to facilitate this, though I haven't been able to find numbers.
https://en.wikipedia.org/wiki/Slavery_in_the_21st_century
In contrast, despite the occasional news post of a particularly incompetent company leaking a database of plaintext passwords, Facebook's data storage is pretty safe, and encryption does still afford a lot of protection. The idea that hundreds of thousands of people are going to have their private data extracted from Facebook through individual attacks against the servers is not well corroborated.
Totalitarianism is an important long-tail risk, but I don't think it's reasonable to suggest that these programmes are a path to it. Overall privacy rights quite plausibly are, but that issue exists primarily as a matter of policy and law, not as a matter of technology. If the laws are bad, Facebook illegally preventing protection of trafficking victims will not help those laws change to a more moderate position, and if the laws are reasonable, cooperating to prevent trafficking victims would not be harmful to positive political outcomes.
The scale of abuses would have to be multiple orders of magnitude smaller, or detection mechanisms incredibly ineffective, before this tradeoff made sense to me.
<braces for backlash>
I think this kind of dark-sounding reasoning only holds up when you phrase it not as “a mere inconvenience” but as tyranny, which is what encryption and privacy in general protect against.
I support personal rights to privacy, and believe that we should find ways to enforce laws without violating privacy. Representative governments need the ability to alter their own power structure in order to function, and yet human power structures naturally resist change, including by spying on those who conspire against them: therefore, privacy is essential for representative government. Representative government’s alternative is tyranny, which we know creates incalculably-large-scale suffering.
Human nature is at the root of why privacy is costly and also why it is necessary; however, much evidence suggests that the set of aspects of human nature we express is mutable and dependent on environment.
While I would never argue that we can remove those aspects of our nature, I believe we can alter our environment to reduce how frequently we express the more sinister ones.
In short, I’d rather work on reshaping our environment, including and especially our culture, to make privacy less necessary and costly, than to debate whether it is either. It is both, and it will always be both, but we can make it less of both, or more of both, with our culture. Same for guns.
It's not supposed to invalidate the reality of the matters concerned. It's supposed to suggest that that they're not actually the issues at hand, with CP and Drugs and Terrorism being used as stalking horses because being in a position of being seen to defend the privacy rights of terrorists makes for terrible PR.
There is no benefit to outweigh. For there to be benefits one must convince oneself that we will actively prosecute bad actors via intelligence gathered via holes we will publicly announce we are drilling into previously secure platforms and drug dealers and terrorists will never figure out how to embrace free open source p2p software that doesn't share these disadvantages. There isn't even one smart person among the bad guys or even among the good guys who will create a platform one can connect to with a few clicks amenable to even techno morons. What could possibly go wrong.
This won't increase the number of people affected or reduce the number caught. The only thing encryption can do in this case is make it more difficult for the government or foreign governments to read personal messages.
Not implementing encryption here can only help people violate people's privacy, it cannot help the government do its job.
The letter specifically describes an offender who was sentenced to 18 years' imprisonment, detected when Facebook read his non-E2EE communications with a child victim. Are you suggesting this was an unimportant or unrepresentative case?
Some crimes could be aided by virtually anything. E.g. let's destroy all the roads so criminals won't be able to travel.
It's silly to think that terrorists use Facebook
Very silly
How about 24x7 surveillance for politicians and priests and no surveilance for normal folks.
Specifically Apple-related and North American examples?
And Apple-related? North American? That's not relevant at all.
You boldly claimed that the government is observing me in my home through my devices, and I want you to show your work.
PRISM happens at the ISP level, and doesn't mention directly using iPhones, Macs, HomePods or tv as surveillance endpoints... So, where's your proof showing that they're surveilling US Citizens through those specific devices?
That's an oddly narrow goalpost. Apple shares user encryption keys with the Chinese government, for example, giving the Chinese government access to all iCloud pictures, messages, documents, videos, etc.
https://www.reuters.com/article/us-china-apple-icloud-insigh...
Chinese government nationalized the data centers six months later, gaining access to all the encryption keys and user iCloud data at rest:
https://mashable.com/article/china-government-apple-icloud-d...
Apple does business in China the way they have to do business in China. I don't agree with that, but I'm also quite sure they have not given my iCloud keys to China.
Also, how exactly was what I said "not accurate at all"? I accuarately said Apple was sharing iCloud data and encryption keys with the Chinese government.
Direct quote. Emphasis mine.
Is the full sentence with context, meaning access for all the iCloud data for the encryption keys being shared. Don't mince words because you misunderstood the sentence.
I didn't want to get accused of moving it later. Also, I'm only interested if there's evidence that applies to me. I'm 100% Apple and 100% USA-based, so if there's proof that "the government is listening!" then I want to see it.
https://www.engadget.com/2016/09/23/the-fbi-recommends-you-c...
and, mostly because it's mentioned in the engadget article:
https://twitter.com/topherolson/status/745294977064828929/ph...
If not, you're a bad guy and we can discount any argument you put forth am I right?
Am I right?
High five? Anyone?
Anyone?
Point being that the enemies privacy have been waging an extremely successful propaganda war against our position for longer than most privacy advocates have been alive. A campaign that is at once massive and specially calibrated to go unnoticed. (How many connect the 'Telescreen' to the example in [1] in their minds?) They have the power to ensure that hand picked, specific examples, calibrated to inflame, are used as flag bearers in the zeitgeist. They have a long game of very specific goals, coupled with an army of natural language, behavioral psychology, and media experts all dedicated to that singular purpose. They have decades of experience at manipulating populations at scale, and a track record replete with successes.
Meanwhile, we sit on HN and social media talking to each other about how our side will be proven right in the end. You know, 'cuz "freedoms".
We have to start addressing the legitimate points that government and law enforcement types are making, because not doing so cedes more and more ground in public behavior and public opinion to those enemies of privacy. The great irony here is that we ourselves have helped them manage to cast themselves in the public eye as the "champions of safety", due largely to the poorly chosen nature of our bedfellows. We need to start getting out in front of a lot of the legitimate arguments that law enforcement is making, and we need to push back against professionally subtle narratives in the national media that attempt to attach us to yet more unsavory bedfellows.
----
[1] - https://www.cnn.com/2019/10/02/us/woman-assaulted-boyfriend-...
PRISM was proof that governments pressure tech companies to become sources.
How to build a program to retain power:
1) Make new tech that is very convenient but has potential to become surveillance vector. -> e.g, Phone with voice recordings, fingerprint Face ID, location data, network of friends. Smart TV, smart watch, smart locks, Alexa, etc. 2) Support consumer adoption. 3) Keep public attention on the evils of foreign states and domestic terrorism. 4) Convert devices into active surveillance sources citing home security, public safety and the classic “what do you have to hide?”. 5) Do so as fast as possible without creating a revolt. 6) Have such pervasive surveillance that it becomes increasingly difficult to discuss, assemble and revolt. 7) Continue to introduce more controls, reduce freedoms, increase work week, taxes.
Many smartphones have this, and will respond to "Ok Google" or "Hey Siri". Do you view this differently?
The phone has to cherry pick phrases and capture times. With the right codex, the phone could keep recording for a long time after the right phrase or your IMEI is targeted. Still sub-optimal, but not as easy as Alexa. My bigger concern around phones is GPS data. That's why I've not had a phone in my name in the last twenty years and never owned a smart phone.
Now put the data sets from your phone, Alexa, your credit/debit card together and that paints quite a full picture.
The Ring device is very interesting. It faces the street. I mean, the house on the other side of the street. A network of those can track the movement of anyone that lives near one.
https://www-m.cnn.com/2019/08/29/us/ring-cameras-police/inde...
But that's exactly how many problems are solved.
Perhaps I should clarify that the only way we are going to solve he healthcare issue in the US is by the government spending money on it.
I mean, I agree with you on the argument completely, but I disagree that it’s a lazy argument.
It’s an extremely effective argument, relative to its factual content. The west is culturally conditioned to accept terrorism as justification and child abuse justifiably gets people riled up.
What’s lazy is people who can’t be arsed to look at complex things from multiple angles.
Congress was provided “encrypted text messages [the top US diplomat in Ukraine] exchanged with two other American diplomats in September regarding aid money President Donald Trump ordered to be held back from Ukraine.”
Might the AG also want to monitor these messages?
https://abcnews.go.com/Politics/top-diplomat-ukraine-crazy-w...
Reminds me of this story: "Back during World War II, the RAF lost a lot of planes to German anti-aircraft fire. So they decided to armor them up. But where to put the armor? The obvious answer was to look at planes that returned from missions, count up all the bullet holes in various places, and then put extra armor in the areas that attracted the most fire.Obvious but wrong. As Hungarian-born mathematician Abraham Wald explained at the time, if a plane makes it back safely even though it has, say, a bunch of bullet holes in its wings, it means that bullet holes in the wings aren’t very dangerous. What you really want to do is armor up the areas that, on average, don’t have any bullet holes. Why? Because planes with bullet holes in those places never made it back."
Qoute from https://www.motherjones.com/kevin-drum/2010/09/counterintuit...
They need a permit for a car? Why not just steal it?
I need an identity to do shady stuff on the internet?
Why not steal it?
We cannot reason with malevolent forces, there is always going to be away,
And by that time, we compiled the data of everyone, centralized it all, and let govs that don't understand the implication collect those as if it was mere petrol or gold.
We are putting everyone's life at risk doing so, just wait until it leaks out or it starts getting sold. (ahem, oh wait !)
It is a problem, and tbh it saddens me a f* tons.
Good to see that the "think of the children" argument[0] is still in use today. /s
1984 rings more true with each passing day.
"It was meant to be a warning, not a manual."
Oh, bull crap. By this argument, literally no protection or liberty that allows even one child to be harmed could ever be tolerated. Why stop at vetting baby-sitters or teachers? We ought to require mandatory background checks for every person who ever visits a family or goes into a public space that might contain children. Law enforcement also ought to be able to track every underage child at all times, via mandatory GPS collars.
At the risk of sounding callous, there are occasionally some situations where you really do need to shut up and multiply.
It's an appeal to emotion and a commonly used tactic of politicians to get what they want (and to convince people it's what they want too). Used all the time in gun control debate.
Well, I think the aim is to create (or in this case, maintain) a emotional button that when pressed, create such an extreme picture in the person's mind that they instantly respond with "your freedom? versus this?, yeah screw your freedom, we gotta stop this."
The extreme the pictures shown on media, the more minachean the TV plot, etc, the stronger reaction.
The reptilian brain will respond differently to children from different cultures on the other side of the world. I understand the logic behind your argument but policy isn't driven by logic.
In fact, I wouldn’t be surprised if data could be generated that shows cyber bullying on Facebook results in more child suicides than children murdered in school shootings per year.
> child suicides
https://www.cdc.gov/nchs/data/nvsr/nvsr67/nvsr67_04.pdf
> In 2016, suicides numbered 2,553, while homicides numbered 1,963
> Firearms were the leading method of homicide for persons aged 10–19 years during 1999–2016, accounting for 87% of all homicides in 2016
> Suicide involving suffocation was the leading method among children and adolescents aged 10–19 years in 2016, slightly outnumbering suicide involving firearms (1,103 and 1,102, respectively).
There are some age and gender difference to the method chosen for suicide.
We probably need to include some deaths by unintentional injury, although 85% of those deaths are motor vehicle traffic, drowning, and poisoning.
I'm still getting to grips with the way the US counts deaths by suicide and I still find it a real struggle to find the data and to understand what they've counted and how they've counted it, which is why I only use the CDC data.
I completely agree. Now can we talk about guns just lying around the home?
[argument]: Considering that a large amount of child abuse is perpetrated by the parents of children, perhaps the people who need to be vetted first are...
/of course, that devolves into "vet everyone"...
This NYTimes article https://www.nytimes.com/interactive/2019/09/28/us/child-sex-... is quite good. I don't want to punish FB for doing a good job of detection by turning around clutching my pearls at them. Stamos tweeted that every hosting platform has these challenges and I believe him.
There has to be some nuance from the absolute privacy folks on this one. How do we balance the need to fight child abuse with privacy?
For example, they might be spotting a large fraction via network analysis, or other metadata approaches. Alternatively, they might just hash every image sent over messenger and match those to known CEP. Encryption screws up one avenue, but not the other.
Aren't we putting the cart before the horse? The problem is the exploitation of children, the secondary problem is that this exploitation is sometimes photographed and shared.
I don't believe that a strong solution the latter problem will have any impact on the former.
You measure accuracy of detection via a training set of definitely known examples, and comparing it to the detections reported by your system.
You can say with certainty that their system catches 99% of your training data set, but that doesn't mean it Will generalize to "all permutations of child abuse ever".
That's two totally different things. In the end their use of that statistic illustrates an attempt to lie with statistics more than anything else.
You are now the thorn in the side of every AI salesman trying to pitch you his Neural Net based wonder machine, or politician trying to sell you on giving up rights because they need to be able to violate everyone's privacy because statistics.
If you understand the actual nature of these measurements, it becomes quite a bit more difficult to let the "zomg neato" factor run away with you.
If I wanted to know the accuracy of an important system. I'd do continual audits. Take a (stratified) sample of all things, get ground truth labels for whether they should have been detected, and see what percent were in fact detected. Then I could estimate how much my systems did and didn't catch at any point in time.
No, I'd ask you what your methodology was when you measured. For instance, going to the DMV and getting a list of all registered vehicles, and using that as a representative dataset to reason from is fine. (Depending on your definition of cars in San Francisco, and whether or not that is meant to include cars transiently moving through or not.)
Now if you told me you were using a Neural Network to recognize all Subaru models that drove by a particular camera, I'd start asking you questions, and want to see your training data, output, etc.
>Sure it may be true in my dataset, but that doesn't mean it will generalize to all possible permutations of traffic ever. Well, no shit. But that's not the statement being made.
That generally is the statement being made when people make claims about the accuracy of neural networks. Particularly the marketing people. You can only measure their accuracy within a constrained dataset, and overfitting is a thing.
>If I wanted to know the accuracy of an important system. I'd do continual audits. Take a (stratified) sample of all things, get ground truth labels for whether they should have been detected, and see what percent were in fact detected. Then I could estimate how much my systems did and didn't catch at any point in time.
Which, again means you're operating off things you know a priori to be the case. You don't know the full extent of everything to begin with, which phrasing in this article implies.
I'm not saying audits can't be useful; it'll get you a number, and sometimes that's all you need. You just need to be clear about what the numbers actually mean.
There's lies, damn lies, and statistics after all.
There isn't. This is a logical fallacy. Violating everyone's privacy is not the way to fight child abuse, not even one of the ways that can do anything to prevent it.
I am curious what you think are the ways we can fight child abuse. It seems to me we have some obligation as technologists to see that our works aren't used to harm the most vulnerable.
Now we are seeing multiple instances where scapegoats and boogeymen are being used to systematically strip our rights away. The worst part of the whole thing is that when I attempt to fight for my privacy, I would be seen as supporting child pornography. It is an insidious tactic that is unreasonably effective.
This is the whole problem. There _is_ nuance. Users can still report content, even if it's private. Automated detection systems can still run client-side. Public forums like Facebook itself are still targetable, and we can increase funding and counseling for moderators in those public spaces to reduce turnover.
Barr is the one here saying that, "mere numbers" aren't enough to talk about the problem. How exactly are we supposed to compromise with that? What exactly is a 'nuanced' response to the argument that any system that allows even one child to be abused is unacceptable?
Barr isn't going to be happy unless law enforcement can read every single message. And he's going to trot out the same arguments every single time. And every time we respond, somebody is going to be jumping in to say, "but why can't we just have a little nuance? Why are all of you so dogmatic about this?"
Every position is absolute. Either you have 100% user privacy, or you 100% don't have user privacy. People pretend that the latter option can potentially include "checks and balances" and whatnot, but Snowden showed us how that plays out in reality...
If someone has an idea that can help prevent abuses and protect privacy without enabling abusive governments, I'm all ears. Unfortunately, to date all we've seen are proposals like the Clipper chip which amount to a backdoor to everything. Understandably, experts are somewhat skeptical of replaying the experience.
> I am curious what you think are the ways we can fight child abuse. It seems to me we have some obligation as technologists to see that our works aren't used to harm the most vulnerable.
You are absolutely right. Absolutely, complete, perfectly correct in every way. Yet, might it be possible that cryptography is not the right context for this discussion? Perhaps there are other tools better suited to the question at hand that do not have the same ugly record of pervasive invasions of privacy? I would love to discuss those! Do you have any suggestions as to where we might start?
This seems like a question best posed to the people on the front lines of this effort - what do they think they need? The rest is so much second-guessing.
I would personally even go one further and say that anyone or anything beyond a certain level of power should be radically transparent, and privacy should be reserved for the weak. If you want some privacy, step down from power and influence, and donate your money, because transparency is the only way we can even start to wield democracy properly and prevent the gross abuses of power we see in our society.
What's your point? We can either give governments backdoor access, or we don't. It's disingenuous to suggest that there's some sort of "middle ground" and pretend to care about privacy.
> I am curious what you think are the ways we can fight child abuse. It seems to me we have some obligation as technologists to see that our works aren't used to harm the most vulnerable.
How about traditional targeted investigations requiring a warrant? I don't see any reason for technologists to enable mass surveillance.
One reasonable answer is that FB/Google/etc. should donate or donate more (Google is called out as donating already) to these organizations. I think another reasonable answer is that technologists donate our time, perhaps as 20% projects or as sabbaticals to these orgs and help them modernize.
It does seem Congress (per the NYTimes article I linked above) isn't doling out as much funding as we would like to see.
And, in fairness, children are being harmed here, and at an incredibly alarming rate. Please do read the NYTimes article. The Times is, IMO, a fairly responsible actor in truth telling.
One is our job that we are directly and morally responsible for (like a civil engineer being responsible for having a bridge not collapse at a load of >2 cars), the other is not. Call me callous, call me cold, but that is not explicitly up to us, we can't be under the delusion that we are the one key to everything and anything. It wouldn't make sense to have a "quick-release" button forcibly installed on all bridges that would cause an instant collapse if triggered "because countless children that are victims of human trafficking are taken over bridges everyday."
I'm not saying online systems for catching child abuse can't be implemented. But is it really where our efforts would be most effective?
The question should be: how do you combat child abuse?
For that, we need:
1- Strong reporting systems that connect the people who in contact with children (doctors, teachers, social workers) and centralize and distribute that information. Right now, a social worker doesn't know about the doctor or teacher reports very easily.
2- Then, we need strong systems for handling the situation: i.e. social workers with effective systems for intervention.
3- Then, we need strong systems to take the children that are removed from at risk situations and place them in safe places where they can recover and grow in a healthy environment. This is the foster care system and the national health care system (or lack thereof) that will provide mental health counseling for the affected children.
Given that 1, 2 and 3 of these systems are terribly dysfunctional if not mostly broken, I'm always skeptical when people talk about social media and child protection. The situation gives me a feeling of leaders justifying the erosion of privacy and those who are authoritarian inclined supporting them, rather than people really caring about protecting children.
Maybe I'm missing something, but it clearly states that the main issues saving children are a lack of enforcement availability (i.e. the 3 points mentioned in my comment) and the lack of timely cooperation of existing orders.
Then they talk about how 'some criminals' hide behind encryption.
So... we have a situation where many cases are reported but aren't followed up on. Yet we focus on getting more reporting by undermining the right of non criminals? Doesn't seem very logical to me.
The whole piece even undermines their own arguments. They mention the 'case of the Love Zone'... which was cracked by investigators finding clues the old fashioned way. Not drag net surveillance.
The article also places many issues that aren't tech related as tech problems. It says "Bing was said to regularly submit reports that lacked essential information, making investigations difficult"
Let's compare that line to offline: If I own a pizza parlor where pedo's hang out sometimes, and I find a picture of CP in a restroom and hand it in to the authorities or call them up, would you blame the Pizza Parlor for the lack of fingerprints on the pictures? Would you think it's ok then to make wearing gloves illegal? I mean, if people use gloves, pedos can use gloves and hide their fingerprints. Why not target gloves?
There is a real issue: Child Abuse. There are real solutions that are complex and extremely resource intensive. A report doesn't create a case. Focusing on tech and the lack of having MORE drag net surveillance seems absurd. This is coming from someone who grew up with abuse.
When I go to forums to discuss abuse (it helps me deal with what happened) almost everyone tells of times that the abuse was reported but not well investigated. In fact, I've known people who work in CPS and they almost universally say the system is broken. A child in my city was recently beat to death by his step dad... an CPS had been called on them multiple times.
We could be focusing on fixing that (you know, the things the people on the front line say are wrong). But no. Drag net surveillance is the thing we should focus on apparently (even though in the very article you mention it states we have more current reporting than we have resources to deal with it)
The reality is that the organizations responsible for looking into these reports of abuse only have enough resources to investigate those where the child's life is in immediate danger.
The venn diagrams of "internet chat surveillance" and 'solutions to the problems of child abuse" are mutually exclusive.
Politicians are grossly morally corrupt to use child abuse as an argument against encryption when they're the ones controlling the purse strings for Child Services-type organizations. Feathering their own nests at the cost of actual, real progress on protecting children from abuse.
You can catch a majority of such content just by running a dumb hash over the bits, even though the detection rate suffered a little thanks to dumb smartphone users who will screenshot everything instead of sharing the files, thus creating "new" content.
If you add some simple "content hashing", like https://pypi.org/project/dhash/ or Microsoft PhotoDNA https://www.microsoft.com/en-us/photodna you can catch an astounding number of content shares, something which really looks great in press releases. My guess would be that the vast, vast, vast majority of those 18M reports that letter mentions came from automated engines detecting the "common" content with dumb bit or content hashes. But you really didn't do much except annoy and scare some online pedophiles* who shared the same 10, 20, 40 year old content* and maybe even put a few of them away for good or caused them to kill themselves. And yet, you almost never actually prevented ongoing child rape and other abuses.
The problem however is that you absolutely cannot catch new content that way. Content that isn't widely shared but shared between two people or in rather small groups. These small groups have elaborate vouching and proving systems in place, and are hard to infiltrate, going as far as having to prove yourself by sharing a picture of you victim holding a sign with a time stamp and some passphrase.
facebook aimed their AI at porn so they might catch some of this new content by accident; it's porn after all. Then again, my hopes aren't that high, seeing Microsoft's bing fucked up even removing the known child abuse content from search results even as the company runs the PhotoDNA database I mentioned before. And google's AI is "clever" enough to think black teens are gorillas, but they are supposed to catch child porn?
Also, those dedicated child abuse content producers do read the news and know not to use facebook or twitter. Most of them do, anyway.
There is essentially three types of pedocriminals I have observed: the aforementioned part time online pedos who share the same old child abuse content but do not actually produce it or abuse children in the real world, a group of active pedophiles who do not care about getting caught because they live in places where they do not actually have to fear the police investigating them, and a cautious group who might use common public services to make initial contact and talk a little in code but will immediately exchange tox ids etc or at least link to "how to setup qtox over tor"* guides (I saw a few "groomers" do just that), and never share anything incriminating over a public service. My guess is that they are be behind tor or a VPN even when using those public services.
And there is a small number of dumb fucks too who will get caught easily and who end up in the press, and, of course, a probably quite large group of pedophiles who just abuse children but do not tell anybody about it, especially not on the internet.
The majority of people you'd actually want to neutralize because they engage in ongoing child abuse you will not catch on facebook or twitter or whatever. I sometimes liken it to catching a lot of drug users, but not the dealers let alone the drug producers.
Not that my experience dealing with the police is much better. The average time for them to get back to you is a few months if they are from the West, and usually never in other parts of the world, even if they have dedicated groups and/or tip lines. Maybe sometimes they do investigate without acknowledging the reports you sent, I don't know, but it is my feeling that probably not. I don't want to blame the individual police officers and detectives who have to deal with this shit, it's probably all due to lack of resources and institutional support.
But to shit a bit more on the police: I saw some chats with essentially reverse-grooming, where a "girl" started off telling how "wet" she is and how much she likes dicks and only then that she is only "13". After learning about "her" age the dude then usually quickly leaves, but often only after having posted some personal information already. I later learned that such "girls" are either the police "child grooming" units, or blackmailers. I don't even want to know how many of the grooming cases that actually go to court are a result of this tactic, catching stupid horny wannabe pervs, while the actual groomers go free. Burning resources like this instead of using them to catch the truly evil and nasty people again seems to be a political decision.
Source: personal experience from having to deal with this shit occasionally, and having caused some pedophiles to go to prison.
* There have been a few studies that found that the group of people consuming child abuse media and the group that actually molests and rapes children doesn't have too much overlap, contrary to what one might expect.
A lot of the "common" content is rather old, like digitized VHS tapes and magazine scans, or stuff like "1st st" (the producer of which went to prison like 10 years ago) or the East European nude "modelling" stuff from the early 2000s, or webcams from a time when webcams had half a megapixel. There is some newer stuff, like "Rbn" and "Rgirls", but that's the exception. And if you try to fill in the blanks and google any of this, you're stupid and/or evil; don't.
* I have had a few tell that to my face, taunting me to report them to their local police.
I am singling out tox/qtox because at least at in the recent past it seems to have been the goto tool for security conscious pedophiles, based on my personal observations.
Do you have some links for this? I've anecdotally heard it both ways.
https://olemiss.edu/depts/ncjrl/pdf/I%20C%20A%20C/2013%20-%2... seems to imply the opposite.
This doesn't seem like a valid line of reasoning to me. Just because there are pros and cons to encryption does not mean that the right answer must be a nuanced balance where individuals cannot have completely private communication.
The nature of encrypted messaging is that you don't really have a middle ground. Either there is a way for two entities to privately communicate, or all communications are inspected for content by a central party. I believe that allowing private communications is the option that is more suited to the American tradition of free speech.
I'll try my hand here:
You're talking about this as "preventing child abuse" versus "privacy". The former is pretty concrete, while the latter is pretty abstract. But allowing government to invade everyone's privacy has concrete effects. Let's be clear here: in 2013, 2.2 million people were incarcerated in the US.[1] 1 in 5 is locked up for a nonviolent drug offense[2]--that's 440,000 people. And 540,000 people are incarcerated because they can't afford bail. It's unclear from the graphs on that page how many are locked up for child abuse, but the total incarcerated for rape and sexual assault convictions is 163,000 people in state jails, which by all accounts is where most rape and sexual assault convicts end up. It's unclear how many of those rape and sexual assault cases were convicted due to evidence from surveillance, but I think we can assume that it wasn't all of them. And in case it's not clear, quite a few of those unethically incarcerated will be raped[3]. In short, unethical incarceration is a much larger threat, by the numbers, than child abuse.
We've seen time and time again that violations of privacy are publicized as being used to prevent terrorism and child abuse, but immediately are then used to prosecute nonviolent drug offenders.
What it comes down to for me is that I trust average citizens to do the right thing more than I trust the law. The vanguard of law enforcement is average citizens picking up the phone and calling the police when they see something wrong, and I want to keep it that way. I trust the average person to call the police when they witness a crime like murder, rape, or child abuse, and not call the police when they witness drug possession. I do not trust law enforcement to enforce the law as ethically. Pervasive surveillance takes that power out of the hands of citizens and puts it in the hands of law enforcement who has time and time again shown themselves to be untrustworthy with that power. It's dangerous to be right when the government is wrong.
And that's in the current US. In the past, US law has been even more wrong. For example, US law enforcement was used to suppress, for example, civil rights activists. That time may come again. It has always been beneficial to let illegal behavior slide under the gaze of law enforcement when that illegal behavior wasn't unethical behavior.
[1] https://en.wikipedia.org/wiki/Incarceration_in_the_United_St...
[2] https://www.prisonpolicy.org/reports/pie2019.html
[3] https://en.wikipedia.org/wiki/Prison_rape_in_the_United_Stat...
Well, one place to start is with the realization that 99% of molestation comes from people the child knows. Encryption doesn't affect that pipeline at all, so the gov't shouldn't be worried.
I'd also remind that probably effectively 100% of physical child abuse and violence also comes from people the child knows.
Surveilling strangers can't have anything to do with dealing with any form of child abuse, except the extremely rare case where strangers have been able to find each other and create a subculture with which to provide evidence that exists on Facebook's servers. That's a pretty specific and narrow set of conditions.
I'm not saying Facebook allowing government surveillance on their wires can't produce some hits, but I'd be extremely curious to learn of wider implications and costs that are proportional.
Mostly encryption protects privacy and business information. Corporate espionage is bigger than state espionage or terrorism my many multiples, and directly threatens national security as well as markets.
Encryption is pro-business and pro-privacy for business and individuals. Without encryption or with backdoors you are trusting that bad actors don't get access to it, they will.
Why have a world class security system, yet plenty of keys under rocks in the backyard?
I wish encryption was framed like this:
Going without encryption or including backdoors is another level of trust, like leaving your window open on vacation and putting a note that says, "Only Sally the neighbor can come in through the window, please" (Sally being the gov't). Guess what, Sally won't be the only one coming in. In that situation you may as well open the front door because that is the same as the backdoor or window, just less obscurity but more attractive to underground/opposition forces whether that is state, corporate, personal or more.
Oversight and security has gotten lazy, two decades of surveillance based detective work without warrants over real detective work with warrants has made enforcement and security lazy and unable to operate without all the noise that comes with access to everyone's data. Initially it was about terrorism, but everyone knows it is about business information, personal information and other over steps like the drug wars or fights against sex workers or other wars on people that are low hanging fruit that are picked on constantly. Good detective and intel work needs to come back and less of the surveillance type.
They want to surveil the public.
Writing it yourself for the first time, or just copying some code off the internet, is going to have a vanishingly small chance of being actually secure.
(I'm not saying they're right, but to say that end-to-end encryption is always pro-business is naive.)
Republicans were never pro-market. Or at least not in the last 100 years.
Everybody that works for the state will not be a defender of freedom or liberty. They are servants of the American Empire, and the US is most certaintly an Empire.
The primary function of the state security is preservation of the state, and not security for its people.
If you tried to set up a "super protection" around your house, which (for example) electrocuted people who entered by breaking the door down, and this hurt a police officer you would go to jail.
So to me, the real world seems to line up with having encryption with a "back door" only the government has access to.
Physical access is easier to control as getting access has a cost. Digital access is effectively free.
The problem with this is that physical access has a cost and limiting it behind approvals and procedures - can deter improper access. (Not always - if a cop really wanted into your house - they will get in)
Digital access is effectively free. It doesn’t cost very much to use a backdoor on millions of devices across the globe. There isn’t much that can be done if the backdoor is leaked.
Police officers use a battering ram or force to get into a house. We know how it works. But knowing it doesn’t increase chances of burglaries.
The problem is when the law is against them with things like national security orders, along with the question of how we can ensure that they are regulating access properly. But in theory, these things could be fixed.
If a police battering ram is stolen, you can't really use it to attack millions of houses in a day. There have been known cases of police personnel misusing their roles. Police have broken into houses without warrants. But the scope of damage is limited.
Whereas digital backdoors can be used to jeopardize millions of devices in a very short period of time.
Sure, you could require a warrant. But it doesn't reduce the risk of someone misusing digital backdoors.
All it requires is one breach.
Isn't the entire point of E2E Encryption for user safety, as in safety from the government reading your message?
I'm starting to wonder if this is a smokescreen. Eventually give in to E2E because you know you have got app store signing keys for the apps so you can upload a patched one with backdoors.
> I'm starting to wonder if this is a smokescreen. Eventually give in to E2E because you know you have got app store signing keys for the apps so you can upload a patched one with backdoors.
Is there no way to prevent auto-updating of apps? If the app blocks access barring upgrade it may be suspicious. Though I guess the upgrade would probably be veiled in new features.
Users should have to power to decide when and if to update. If their old version causes them technical problems or exposes them to security issues that is their business. Software can (and often should) offer auto-updates to make things easier for most users but it should respect a user's choice not to update. Especially when updates often introduce anti-features and/or disable existing features.
It also totally changes how government has to force Facebook into giving them something. They can't just request access to some server anymore.
The main way to defeat a state is to make mass survailance difficult enough that it doesn't scale well.
You and whoever you are messaging of course.
That is their stated reason. If given access they will also read your messages to determine if you are a drug dealer, or a drug user, or have committed financial crimes, or if you're organizing disfavored political activity, or...
Ah yes, "think of the children!" This is so tired, I'm (just a bit) surprised they fell into this argument.
Kids being shot in schools: the price of freedom.
Private communications means also criminals can communicate privately: outrage.
I am still pro E2E encryption, especially given the Snowden revelations (the US gov cannot be trusted to be responsible), but it does come at a high cost.
https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
https://en.wikipedia.org/wiki/Blackstone%27s_ratio
"It is better that ten guilty persons escape than that one innocent suffer."
If you start thinking that parents "can be" the criminals then you've decided that parents are automatically guilty and must be proved innocent. This goes against the very moral fiber of the entire western world theory of law, the presumption of innocence.
It's definitely possible to eliminate all crime with total surveillance with a high degree of accuracy.
We probably shouldn't, especially not without being able to quickly update our laws, but it could be done. Imagine if anyone going over the speed limit was instantly charged a fine. We can do that today with complete accuracy, but we choose not to do enforcement that way.
Unless the state itself is criminal. Not only can law stray from morality, authorities of the state can even violate the laws of that state itself. If you can imagine an extreme authoritarian state with a constitution, can't you also imagine that the leaders of that state choosing to ignore that constitution?
But before even getting into the above, you've assumed the possibility of perfect surveillance. Who or what and how could that ever be possible?
The only way I can conceive of perfect law enforcement is to have very few if any laws. Everything else is an excuse for the personal fancies of authoritarians.
And you could set up society so that you'd be useless without carrying your phone, as we're most of the way there already. Not streaming your complete data to the government would become a crime.
All public places could be recorded in a similar way.
If you combined it with satellite tracking of the whole planet, you could even identify people that have chosen to go off the grid for some period of time, so you could solve crimes that happened in the forest if you want.
That's pretty close to perfect surveillance.
I can't think of a crime that couldn't be solved this way, but it's not a society where I'd want to live.
I'm not sure why I'm being so heavily downvoted, the only difference between the dystopian future that I describe and the system we have currently, is that the government isn't collecting and processing data on such a wide scale. If they collect more data, we will have more crimes solved and more privacy forfeited. If you take that to its logical extreme, we have full surveillance, no privacy, and no crime. I'd rather live in a world where we have some crime, but privacy and no surveillance, but I think it's far more likely we'll head in the opposite direction.
How would you handle corrupt senior police officers covering the tracks for themselves, their fellow officers, and friends in high places?
I know you're trying to point out some supposed hypocrisy for not criticizing Obama or Clinton or something, so I'll let you know I think they too enacted unforgivable political violence. Happy?
People exist outside the Republican/Democrat spectrum.
Stop JAQing off and stuff your crypto-fascist views up your ass you Trump slurping gonorrhea nodule.
inb4 "Leftists can't have civil discussions"
Shut the fuck up you stupid fash.
Edit: actually thinking you might be seriously talking about conditions for illegal immigrants detained in the US. Hyperbole, but still not a nice situation.
What are you talking about? I'm seriously asking. This sounds like something people say without having anything real behind it.
https://www.nytimes.com/2019/07/02/opinion/surveillance-stat...
I don't understand why they don't just ask for what they want, why say it's about "user safety" when it's not about that at all.
Just say "As a matter of national security, the government needs to be able to read user messages (and we don't care if that opens up a hole that enables other governments to do it too)"
Have you never heard someone lie through their teeth?
If the demand was phrased around security, it would be less emotionally laden (for most).
I find that quite appalling, to be frank.
Because they don't care about an honest representation of their argument, they just want to have their will imposed. The best way to do that is to lie.
They (government workers at the agency) have no real incentives to fight for privacy other than having to live with eroded privacy, which most people just don't think about as giving something up until it affects them anyways.
I spent a few moments trying to understand what had led to the manufacturer of Tizer, Irn Bru, and various other traditional British soft drinks getting involved in this.
Submitted title was "AG Barr Will Ask Zuckerberg To Halt Plans For End-To-End Encryption".
But I agree that AG should be expanded.
(On another note, it's amazing how easy it is for a comment can sound like a bit of a putdown inadvertently. Even after years of practice trying to skirt around such misinterpretations. Tone of voice and body language must be the greater part of how we avoid this in person.)
By 'stretch' I just mean that there's quite a distance between an attorney general and a soft drink. Usually the things that get conflated are not so incongruous.
https://twitter.com/hashbreaker/status/709314886384427008
> Fun game to play: Take statements from Comey et al. Replace "smartphones" with "brains"/"memories"/"thoughts". Technology will get us there!
Very on brand for the new versions of this request...
https://keybase.io/blog/chat-apps-softer-than-tofu
(I have no affiliation with Keybase, I just appreciate their very thorough and public analysis.)
I used the wayback machine to read the older version of this article, it took specific aim at WhatsApp and Sigal, indicating that (in so many words) it disapproved of the apps providing a notice of Safety Numbers changing instead of the app flipping its wig and making the user take affirmative action to continue communications, otherwise it wasn't true TOFU.
I have about 30+ contacts on Signal, and I almost __never__ get Safety number changes. I certainly don't think making the user click through yet-another-dialog-they-wont-read will be a big security improvement.
I suppose I disagree with the 'not true TOFU' argument.
I am not sure if I'd be willing to make the argument we should ban (as in make illegal) collection of user data, but acting like such data is required to run ads is ridiculous.
How about we techies stop kissing ass to the advertising execs and stand up to them for once??
They want more data, more relevant ads, more more more more more. Their ask is impossible without massive invasions of privacy. Fuck them, I say
Return to scattershot ads, they can understand me as an audience without having to mine every ounce of my life for it. That approach will produce more relevant ads for me anyway
But since this idea has been brought up by a number of ad companies (Google, most notably), I can answer in the more general sense.
I would not support ad targeting done that way. It is a bit less objectionable, but it doesn't really address my objections to the entire practice.
I don't think they will be hurt by the fraction that do leave for this reason.
Assuming someone already has knowledge of Facebook's past activities, then they are likely already gone. If they are still using the service, it's unlikely this will make a difference.
Cheap and convenient is just too much of a draw for some folks. Especially when it involves "staying connected" with friends and family (irrational behavior driven by emotion).
Also, should we read this request as "if you implement E2E encryption we will no longer have visibility over what FB users say"?
If so, and because the connection between us and FB is over https, I assume there are deals in place where various 3-letter-agencies from these 5 countries are given (or they take themselves) the contents of our private messages? I wonder why they would be opposed to something like E2E then /s
Facebook (or other messenger app owners) could train a good classification model to detect child abuse pictures on large servers and provide the model to smartphones locally. Before sending pictures, the app would run the trained model (which is cheap computationally). If if detects pictures of abuse with a certain accuracy, the app would block the transmission of the picture (possibly, explaining why to the user). If the detection of pictures of abuse happens again, the user could be banned from the app for 1 day, and if it happens more often the ban would become longer and longer.
That way facebook can fight child abuse without ever having the pictures.
People sending CP through whatsapp/FBM are not clever. If they were clever, they wouldn't be doing that. The justice department is not primarily interested in catching clever criminals, at least not via this particular mechanism.
This is one of those technologies that are cool in theory but almost impossible to implement in practice on current hardware.
I want to applaud you for thinking outside the box though.
As for Facebook, it is more likely because Facebook is in "progress" of enabling E2E and they have more users than Apple right now. It is easier to hit Facebook now than later unlike in the case of Apple that already implemented it from the start; it would go into court litigation for several years and most likely end up in Supreme Court.
Barr is just assuming FB will cave in.
PS: No, a huge value prop for iMessages is that it's built into iOS and any iPhone user can talk to another iPhone user, not because of E2E. Most users aren't aware of what E2E is.
Because when Apple was preparing it, it wasn’t public about it, and the then-sitting AG wasn't looking to generate news articles with his name that weren't attached to his role in acts fueling an imminent Presidential impeachment, so no similar warning note.
Here is some legislation from 2000: https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po...
> Critics claim that the spectres of terrorism, internet crime and paedophilia were used to push the act through and that there was little substantive debate in the House of Commons.
20 years in life of internet is a lot. Same arguments. Remarkable.
What historical events and periods are you referring to in the past millenia?
so actually fairly analogous!
I think tech companies would have a stronger basis for refusing to monitor and censor user traffic if they hadn't volunteered to monitor and censor some user traffic. Doing anything some of the time makes you vulnerable to pressure to do more of that thing.
Carrying all legal content and refusing any cooperation with the government without a warrant is the only sustainable path.
https://arstechnica.com/information-technology/2013/11/googl...
(Of course, this just prompted Google to serve more legal data requests, but better than letting the Justice Dept sweep everything for who knows what end)
https://hacked.com/italian-hacking-team-hacked/
How do you like those apples?
I can't think of a technical defense against a threat like that that doesn't involve disconnecting all the computers in my house and throwing them away.
This tool is not described in the article you've linked. Do you have an additional link for those of us who want to read more about this?
https://news.ycombinator.com/item?id=9836336
It is true, there is a tool that was developed to basically plant evidence on a compromised machine. So the idea here being that the hired hackers would compromise the machine and then the government client would tell the hackers to put CP, incriminating evidence or other stuff on the machine before the police raided the house/building. The computers would be seized and then it would be used as evidence to prosecute the target.
It is real.
Also if you are interested, dark net diaries did an episode on this group called "hacking team".
Seems easy for FB to comply with this: they are adding encryption specifically to improve user safety.*
The later extract in the article body talks about "public" safety, which is the classic false dichotomy that has been brought up by law agencies for the past 30 years.
Much as it sticks in my craw to say something supportive of either of that meretricious duo Barr and Patel, I have to admit I am glad that they are using an open letter rather than trying for a backroom deal or quiet threats. Perhaps they tried those already and have been rebuffed.
I have seen some friends of mine outraged by social media's inability to do wholesale censorship, spurred by some NYT articles on child abuse from last week. I wonder if that was coordinated?
* OK, they are a corporation doing it to encourage people to use their service, but they are trying to accomplish that by improving user safety.
So the government not having access to private communication is a threat to public safety, and won't somebody think of the children!
Australian here. Does "user safety" include journalists not being raided and/or prosecuted for publishing public interest material? For example, likely evidence of war crimes by some of our soldiers.
As has begun happening here, after laws were introduced forcing our telco's to allow monitoring of anyone.
https://theintercept.com/2019/08/04/whistleblowers-surveilla...
Some more statistics would be useful to quantify the impact on criminal justice of losing either of those options. Otherwise the arguments just feel political or emotional.
End-to-End won’t impact the major source of evidence in, say, sexual assaults where the victim unlocks their phone and submits a copy of their decrypted message threads to the police, though this is a controversial policing method, recently reported on in the UK:
https://www.theguardian.com/society/2019/sep/21/people-repor...
If Americans cared so much about their freedom to protect themselves from their government, rationally it would make far more sense to be up on the fence about encryption than about firearms.
[1] https://law.stackexchange.com/questions/3696/is-the-right-to...
[Edit] I don't want to start a flame war about guns, I'm genuinely curious about what the law would say about encryption under the second amendment.
If you see the insanity of this, you should see the insanity of the Government tapping into private messages.
Well, I don't see the Feds cracking down hard enough on homegrown fascist groups, and I would be happy if Bob Barr's kids or grandkids were locked in a dungeon and made to sit in their own filth Omelas-style if it meant we'd have strong crypto for everyone.
Electronic surveillance is primarily used for reconstruction and back tracking after a significant crime has taken place. After the fact.
Electronic surveillance is paying cheap lip service to a problem instead of paying the expensive price of doing it properly, in meatspace, with boots on the ground.
Ask any woman/minority, domestic abuse victim, etc. They don't want people spying on their messages.
If you want to prevent criminals from communicating safely in the long run, you would have to prohibit open internet access and/or mathematics.
Prohibiting platforms will lead to some delay at best. The collateral damage, taking away privacy from the population at large, is proably the real goal.
So, when is ban on guns, cars and parents coming? Each of them killed countless kids.
I don't think it works that way. Serious criminals that we really want to catch are probably not coordinating their activities using unencrypted channels anyway.
I don’t get it. How could end-to-end encryption reduce user safety?
I eagerly await the publication of these politicians’ private communications.
Classic Spielberg called ’Minority Report’ with underwater ‘precogs’
This will, of course, never happen because breaking up businesses and consumer protection is verboten and anti-american, but I really wish someone with a big voice could stand up and make this point because it makes them look silly.
If there is an infinite supply of encrypted channels, controlling them all becomes literally impossible.
A system that handled things like performing the encryption and decryption of messages over any platform would be interesting, the only pushback you would get from an authoritarian government is them telling providers to "block all pgp/encrypted comms on your platform" and/or the platform actively attempting to block your client's access to the API.
For instance, discovering and negotiating various publically available http or irc or jabber etc. nodes, and coordinating around their unavailability.
What's stopping the government from just forcing Facebook to provide access to the servers directly, or through some sort of portal?
This just means the government can't intercept them without Facebook cooperation... no?
Although I have a tough time believing Facebook would lock themselves out fully... they need all those data points for pushing ads...
The infrastructure should be there. If there's a court order or lawful authorization, info should be accessible without delay.
But
The way to do that would be more systems of review for when it's used, generally making the standards more strict, less ambiguous.
But
The problem is there are side effects to changing the law that can give away methods and also put convictions at risk. There's other ramifications we may not know about until it was put in effect, but they could be negative. I bet that's one reason there isn't as much movement in the area.
There was an article in the news recently that right now in USA the case law considers unopened email to be discarded.
GDPR went into effect in EU. That is another aspect that US doesn't a similar thing for (does it need one? I don't see people bringing it up often, convince me otherwise?)
My point is, backdoors are more of a hypothetical thing. The legal framework around them and making them better is more productive use of your time.
That would involve people coming together and nuancing what the types of privacy are and whether it involves US people, foreign countries, drug dealers, etc.
> end-to-end encryption into its messaging apps will prevent
> law enforcement agencies from finding illegal activity
> conducted through Facebook, including child sexual
> exploitation, terrorism, and election meddling.
Not buying the case for the protection of children from the UK, after repeated failures to protect children despite mountains of evidence [1] [2] [3] [4] [5] [6] [7] [8] [9] [10]. Finding pedophiles is relatively easy in the UK, they are one of the single most hated groups and often cited as the reason to bring back capital punishment.
Terrorists are already using encrypted chat services such as Telegram to evade intelligence agencies. Encryption has no influence over election meddling.
What this is really about is watching the general public. Facebook now blocks content even in private messages. The other day I wanted to share a free-documentary (i.e. fully legal) with a friend and so shared a page with a direct download and magnetic link, which in turn Facebook kindly blocked. Something that is pouted as "safety" is actually just about trying to line the pockets of the film/music industry.
[1] https://en.wikipedia.org/wiki/Rotherham_child_sexual_exploit...
[2] https://en.wikipedia.org/wiki/Derby_child_sex_abuse_ring
[3] https://en.wikipedia.org/wiki/Huddersfield_grooming_gang
[4] https://en.wikipedia.org/wiki/Jimmy_Savile_sexual_abuse_scan...
[5] https://en.wikipedia.org/wiki/Manchester_child_sex_abuse_rin...
[6] https://en.wikipedia.org/wiki/Newcastle_sex_abuse_ring
[7] https://en.wikipedia.org/wiki/North_Wales_child_abuse_scanda...
[8] https://en.wikipedia.org/wiki/Oulu_child_sexual_exploitation...
[9] https://en.wikipedia.org/wiki/Oxford_child_sex_abuse_ring
[10] https://en.wikipedia.org/wiki/Rochdale_child_sex_abuse_ring
"While the letter acknowledges that Facebook, which owns Facebook Messenger, WhatsApp, and Instagram, captures 99% of child exploitation and terrorism-related content through its own systems, it also notes that "mere numbers cannot capture the significance of the harm to children." "
Encrypt it, end to end, the government does not need to be able access all private communications of private citizens. There are other means of investigating potential crimes.
I love the Internet, and my career is in security. But we as a security/privacy/technology community truly need to look hard in the mirror about how we are allowing and perpetuating lifetime harms to children and women.
Terrorism exceptions, like San Bernardino, don't ring with as much impact as the CEP argument.
* https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
bin Salman in Saudi Arabia: https://en.wikipedia.org/wiki/2017–19_Saudi_Arabian_purge
We're just going to completely ignore the last administration spying on their political opponents?
[0] https://www.politifact.com/truth-o-meter/article/2017/mar/21...
But if it was true, seems to be another reason to allow End 2 End.
Unless this was essentially a "but her emails" post.
Law enforcement and security agencies need to be able to access any communication. This does not mean that they should monitor all communications.
They can eavesdrop on any phone call. They do not eavesdrop on all phone calls.
The problem with E2E encryption is that it prevents eavesdropping even with the standard legal safeguards (warrant, etc), while not being required for the privacy of users. It is only effectively a marketing tool to convince people to use services from providers they don't trust, although, of course, since they control the app they can still in principle access the data.
Even with E2E the police can get warrants for the devices which is usually more than enough to access data.
They just want an easier job, it’s not a major roadblock. When police jobs being easy is a good sign that privacy has been completely destroyed.
E2E is not required for privacy. There is also a difference between privacy and the right to privacy, and a guarantee that no-one will ever be able to know what I'm doing.
There is no absolute, including absolute right. It's all about balance: We have a right to privacy but the police may search our homes and eavesdrop on our communications in strict, specific circumstances because that's in the public interest. The idea is simply to have the same online.
If the system uses only P2P encryption then no backdoor is needed, which actually makes the system more secure to external threats. It is then for the provider to allow access to data only to "allowed government agencies" according to the law, which is how mobile phone networks work.
I don't agree with this -- but I think this does strike at the very heart of what the debate is all about.
Why? And while we are at it, why is this such a given that they need it.
COINTELPRO was a thing that actually happened and should be brought up every time privacy rights and government surveillance is discussed
* https://en.wikipedia.org/wiki/Room_641A
* https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...
Nobody really cares about your personal Facebook messages to your friends and family. You're not that important. But still considering what is being offered in payment for this privacy, it's still worth it to you?
I'm not so sure it is, personally.
What do you think the negative consequences are for a government to have a permanent record of every private conversation made over the Internet? Bear in mind that the fraction of all private conversations which occur over the Internet is only increasing.
You must assume that "exceptional access" really means "routine access". While the government claims it only wants access to some encrypted content, decryption leaves no trace. The NSA's collection posture is: "Sniff it All, Know it All, Collect it All, Process it All, Exploit it All, Partner it All." Does it sound to you like the NSA will sit on their hands while some other USG functionary has the Golden Key?
> Nobody really cares about your personal Facebook messages to your friends and family. You're not that important. But still considering what is being offered in payment for this privacy, it's still worth it to you?
Perhaps you're correct now. But imagine that a decade from now, you (or a friend or family member) become an activist or a political candidate. Now your incumbent political opponents have a wealth of sensitive private data to mine to find anything to imprison or discredit you. The argument extends further than your own direct interests: What happens to our political system when policymakers are completely transparent to the NSA and their political co-conspirators?
Considering the very real risks of a totalitarian government ruling with an iron machine learning model, or a silent coup by military intelligence, is it still worth it to you?
This is demonstrably false. Companies are very interested in your private communications and the buying and selling of your personal private data is a multi-billion dollar industry. Governments also have an interest in your data because they can flag you for whatever the current administration finds distasteful. That might mean identifying threats to those in power like activists, or (as we've seen in other places) attempts to hunt down whatever they consider "evil" like homosexuals
The issue isn't privacy vs security. Loss of privacy is also loss of security.