Signal threatens to dump US market if EARN IT act passes
uk.pcmag.com
uk.pcmag.com
2. You don't need to know the contents of a chat to glean massive amounts of metadata. FB Messenger and WhatsApp going truly E2E encrypted will still put FB (and anyone serving them with warrants) to know in real time who is talking to whom, what their IP addresses are, and possibly real location (if they are using the app on their phone). This can be used to created a Signature profile... many Pakistanis and Yemeni have died from a Hellfire missile strike because they matched a pattern of activity. Google "signature strike" for more info.
3. The terrorists and pedophiles that are the most dangerous are using far more sophisticated means of communication than Wire, Signal, WhatsApp, Wickr, etc. Saying that this is "for the children" or "for our safety" is complete bullshit and anyone saying otherwise needs to prove it.
BTW, one of Signal's weaknesses is that you MUST use a phone number with it. If you're savvy you realize this can be a Twilio number you control making your account immune from SIM hijacking. However, unless you override a bunch of defaults Signal is not immune to other attack vectors like attempting to unfurl a URL sent in a message -- which can expose your true IP address -- or generate a thumbnail of a video -- which can launch a malware attack -- which is the method of attack alleged to have been used by Saudi intelligence to hijack Jeff Bezos' phone (via an E2E encrypted WhatsApp message no less). A more sophisticated messenger system would turn off lots of "convenience" features by default and let me pick a random username and NOT make me enter a phone number or email address. People who care about security don't need a way to reset their randomly generated 128 character passwords.
This isn't a weakness, it is a tradeoff. You use phone numbers (downside) but the server does not have to store any information about who is talking to who (upside). Other tools reverse this choice and don't use phone numbers but do need to maintain the communication metadata.
When the server knows who you are, the app can use your existing contact list to discover contacts. This means unlike e.g. Telegram, Signal server doesn't store your contact list.
I e.g. constantly see people whose phone number I've already deleted appear on my Telegram contact list "X joined Telegram". Telegram knows I had the number at some point. This would never happen with Signal.
Sure, but you can use VPNs. Or Orchid, which is a multi-hop VPN that routes through multiple VPN providers.
Or you can just use VoIP, which can be done via Tor, as long as you can force TCP mode.
Also, if you're going to stay anonymous, you need something that is extremely hard to misconfigure. I use wireguard on my Android and I've set the VPN to activate automatically, and I only allow connection via VPN, but I'd never imagine any of the apps I'm running are properly anonymized.
Also, since you're apparently working for or affiliated with VPN providers[1], you might want to be more transparent about possible vested interests.
I haven't actually used Orchid, because there's no Linux app. But I did buy some of their Etherium currency. And I recall no money trail. As I recall, I converted well-mixed ~anonymous Bitcoin to plain-vanilla Etherium, and then to Orchid's currency.
But whatever, I'm not going to defend Orchid.
Anyway, I use nested VPN chains. It's like a multihop VPN, except that each hop is a different VPN service, and each of them is leased with a different pool of well-mixed Bitcoin. I do all the Bitcoin mixing via Tor, in Whonix instances. That way, I don't need to trust any of them, only that an adversary won't manage to compromise or coerce all of them. It's the same logic as Tor uses, based on Chaum.
If you want to read more, just search "mirimir" on IVPN's and Restore Privacy's sites. There's also https://github.com/mirimir/vpnchains which is pretty over the top. And I've also played with something like that which routes VPNs via Tor.
When you start to chain VPN nodes you gain latency so you might as well use Tor. These days Tor has enough bandwidth to play 720p video with ease and there's less hassle. Also once you hit three modes you won't really benefit from longer chain so mixing VPN with Tor isn't really beneficial unless you're evading censorship of Tor.
You're wrong about nested VPN chains, however. Depending on geographical distribution, each VPN adds 50-100 msec rtt. And bandwidth doesn't drop that much after the first VPN.
I use both nested VPN chains and Tor to mitigate the risk of Tor circuits being compromised. The lesson of CMU's "relay early" exploit for the FBI was sobering. Given that lesson, only fools use Tor without protection.
Add in some routing trough Tor.
That would be harder to beat by a single law agency.
Particularly harder if the countries implied are not friendly towards each other.
Wait how big is the hash of the phone number?
If it's enough bits (e.g., a full sha hash) then it's not that secure to hash at all. 10^10 or even 10^11 is just 10 or 100 billion. I can easily try all phone numbers until I find the one that matches the hash.
It maybe protects against attacks against lots of people, but it really doesn't protect an individual.
You are correct that using a hash does not protect an individual from other users discovering that they can contact them with Signal, which is to be expected because that's the purpose of this feature. If you suspect that Bob, with phone number +15555551234 has Signal installed, you can verify that by... typing Bob's phone number into your contacts list and installing Signal so you can send messages to Bob.
No matter if your phone number is six digits or sixteen, Signal uses 10 bytes (80 bits) of the hash.
What threat model has a IP be worse to leak than a phone number?
This literally happens with Signal. And it makes sense too, the message that Signal gets telling it someone is now on Signal is presumably the same one letting it know it can use encryption rather than SMS to talk to that person.
If Alice tells Bob a secret via Signal, this means Alice cannot be worse off than if she'd used any other means of telling Bob. Can Bob reveal the secret? Yes. Can he claim Alice told him? Yes. Can he prove it? No.
This is a sharp contrast to something like PGP where Bob can prove Alice sent the message.
The way you normally know a message is from Alice on Signal is that the message was sent using keys only you and Alice share†, and you know you didn't write the message. But a third party has no way to verify that last part. That's the entire trick (in layman's terms).
† Signal and similar systems provide a means to do out-of-band verification that the long term identity key for people you know matches. You probably don't use this with most people, but you can and it's made easy if you want to.
The only way you can know if intelligence obtained is reliable is to actually test it. With systems like PGP you get proof. Did Alice send this message as Bob alleges? Yes, the message includes proof so he was telling us the truth.
With Signal all you have is Bob's word as I described.
Signal can't stop the Secret Police from torturing Bob, but they can ensure they don't have any way to know if he told them the truth. If the Secret Police were rational that's enough reason not to bother torturing Bob. But we can't make them rational, for some people just inflicting pain for no reason is their goal.
1. Friends
2. Family members.
3. Members of a business.
If your life or freedom is on the line because of an association with someone then most systems out there are somewhat dangerous due to the weakness of the endpoints. You would want something like an airgapped computer with on or off line dead drops possibly hidden with stenography.
Well, "the best is the enemy of the good". That's the whole point of risk management. As a practical matter, I do the best that I can manage, or at least, be bothered with ongoingly. If I were as paranoid as you're advocating, I'd be cowering in a bunker. Also, for me there's the fact that I have little left to lose.
That, or blasting your message to a huge number of people, only one or a few of whom actually receive it because it's encrypted and then steganographically hidden in spam. Again, use dummy messages and there's no way to predict anything by divining the ebb and flow of spam volumes.
In contrast to your disinterest in convenience features, Session does have a bunch of things that presumably its principles felt were non-negotiable but clearly harm security. The "Open Groups" feature for example is basically "Eh, this is hard, we give up" for larger groups (500+ people). No end-to-end encryption and you're given either a moderator tool that doesn't work ("Ban" pseudonymous people who can for zero cost just create a new pseudonym) or one that's onerous ("Invite" everybody manually).
Does Signal not ever send messages from, or otherwise use, SMS shortcodes ?
I ask because no twilio number can receive an SMS shortcode (because no twilio number is classified as a "mobile" number).
Genuinely curious.
Not only they do not show anything but use misleading terms in order to confuse the reader.
We do not even know if he was hacked. Right now it is just vague accusations.
I do not care about Saudi Arabia, they are a middle-ages, totalitarian and profoundly sick country. What I care about is misinformation.
(1) https://www.documentcloud.org/documents/6668313-FTI-Report-i...
People that really really need to be sure probably use something super simple like PGP after they take the time to learn how.
Sorry pal, that's top secret intel. Just Trust Us™.
We then communicate over a secure messaging platform like Signal, Telegram, etc.
Knowing just that I communicated with one or more people, how you would conduct your investigation to "trace" the participants in this conversation?
The feds would be really put up to unravel this (and are on a daily basis), let alone the police.
1. The police are either lazy or incompetent if they say they cannot trace criminals because of E2E secure chat.
As for the rest of your comments: The feds are watching criminals online because lots of crime is committed online. I do not think weakening encryption will help them in this pursuit.That implies effort and people are lazy. "Hey, Mr Criminal, can you be so nice to use App X when you plan to commit your crime so our automated system can mail us when you are going to break the law and also set up an event in our calendar so we can come and arrest you. Please be nice, we can make each other lives easier if we work together. "
Terrorism is mostly opportunistic radicals communicating via YouTube and Twitter and Fox News, or national / quasinational governments that are brazen and flagrant and don't need to worry about being noticed.
The "most dangerous" part is doing a lot of work there. Just like I think law enforcement needs to admit what they can and cannot do (e.g. they cannot protect a golden key), I think we need to admit some things too. A lot of dangerous criminals are stupid. Maybe not the most dangerous ones, sure. But if law enforcement has a tactic that lets them catch, say, the stupidest 30% of terrorists, that's an extremely valuable tactic that probably saves a lot of lives in practice. It would be wrong to claim that society loses nothing by engineering away that tactic.
I think this sort of thing leads to a lot of frustration on both sides. As a programmer, I find it very frustrating that law enforcement and the media consistently get some of the most basic details wrong about how communication and encryption work, and about the negative side effects of the new laws they're proposing. But I assume that law enforcement folks also feel frustrated about how people like me have no idea how they actually get their jobs done day-to-day, or the negative side effects of the technologies we're building.
Most of which is Facebook posts, which is perhaps the worst platform to use if you wanted to keep your crime secret.
Tiktok?
That has a ton of content that can be considered CP if reviews on reddit/yt are believed. Which given its sordid past as Musical.ly its totally believable.
Signing up to be law enforcement comes with an implicit acceptance of the frustration caused by mechanisms designed to prevent infringing upon the rights of the innocent. It’s part of the job to work hard for a long time and sometimes have to let the criminal go free.
Unfortunately, many prosecutors and cops never learned this, and are all too happy to pursue illegal and invasive methods, or to employ parallel construction to conceal illegal methods.
Sounds nice, but have you really thought that through? I think you might be surprised what people would be willing to give up to live in a crime-free society.
I don't think the "well it wouldn't happen to me" delusion is strong enough for people to actively want that, no.
1. Very often, they're quite willing to give up _other people's_ privacy.
2. Have you considered what many people are willing to give up to live in a mass-surveillance-free society? Probably not, because we're never given these options for serious considerations and for us to choose. It's a false dilemma - the state makes the decision, eats away our privacy and uses things like pedophilia as the excuse because it's scary.
3. Let's start with making some sacrifices to prevent criminal behavior by elected officials (Trump family, Biden family, Bush family, Clinton family - I'm looking at you people), and in high finance (2008 crisis racketeers who never faced any criminal action) and once that's sorted out, then let's talk about what more needs to be done to achieve a "crime-free society".
The nice thing about stupid criminals is that they tend to be indiscriminately stupid. The ones who don't use encrypted messaging are the same ones who proceed to brag about their crimes in front of strangers, and have their phones turned on and with them during the commission of their crimes, and post incriminating pictures on Facebook, and choose equally stupid and unreliable criminal partners.
They are the low-hanging fruit, so you don't need powerful and invasive tools to catch them because they're practically self-incarcerating. When there are 100 other ways to catch them, there's no point in paying a high price just to have 101.
It's the non-stupid criminals that they have trouble catching, but those are the ones this won't catch either. So you're still paying a high price for really nothing in return.
You can compare it to COVID-19 reactions among the people you know. Almost everyone now keeps distance in public, because everyone knows they should and are expected to. But how many people don't connect this with the fact that they should absolutely not meet up with their friends now? Or that they should absolutely not visit their families this Easter? Or that it would be wise to wash groceries and deliveries?
We could say this parroting group is doing cargo-cult OPSEC. They can know they shouldn't brag about their crimes in person or on social media, and yet at the same time they could easily trip using communication tools they don't understand - unless the industry goes out of its way to make such tripping impossible. I think this is the group the law enforcement is talking about. Not the idiot criminals, not the smart criminals - just regular ones, who don't understand the world they live in well, and occasionally make mistakes.
The guy who carries his phone with him during the commission of the crime is the guy at the median.
It also doesn't hurt that the average criminal skews dumber than the average law-abiding citizen to begin with. But even for the somewhat above average criminal who gives you ten ways to catch them instead of a hundred, you still don't need eleven because you only need one.
What do you suppose the percentage of criminals is who are so diligent that having default insecure communications is the only way to catch them and they wouldn't have chosen a secure alternative regardless?
Is this true? I'd be interested to see the research for this. I would believe that the average convict is dumber than the average law-abiding citizen, but how many criminals are lumped in with the law-abiding citizens simply because they don't say "oh yeah, I break the law all the time"?
But if you want to talk about, shall we say, "real" crimes then that's another story. The solve rate for murders is actually pretty high (because they're given significant investigative resources), to the point that the population of convicts is probably not a terribly unrepresentative sample, and the lower intelligence of the convicts is pretty well established.
It also depends how you measure intelligence. The IQ of people who commit politically-motivated bombings is often significantly above average, but they also choose to commit a crime that attracts a hugely disproportionate level of investigative resources and correspondingly has quite a high solve rate despite the perpetrators' supposed intelligence, so maybe there are different kinds of stupid too.
The actual problem is not being able to catch the smart ones who every now and then do something stupid or lazy or expedient (since even the smartest of humans have moments where they are not at their best).
Otherwise, it would just be another police state: a shadow dictatorship.
Either the rule of law is universal or the country is not free.
Freedom of communication means freedom to hide it (I must be able to use a one-time-pad with whomever I choose).
Let's mix time frames. Should police be able to catch the laziest/stupidest 30% of people who sell weed? Of people who marry across racial boundaries? Of people who traffic freed property back north? Should the police be able to catch the 30% laziest gays?
This is a ridiculous argument - now. But in 30 years when the US still has the laws, we have to understand there are social norms now that will be completely different and maybe people in the US won't want police to do their job.
1. Presumption of guilt: Law enforcement doesn't go after "terrorists" or "criminals"; they go after _suspects_ in acts of terror or crime. Part of the norms in non-totalitarian states is that people don't get subjected coercive, violent and otherwise harmful action as though they are guilty of anything - until they are formally proven guilty.
2. The assumption that what the state legally defines as "terrorism" is indeed terrorism, i.e. "the calculated use of violence to create a general climate of fear in a population and thereby to bring about a particular political objective. " There is a definite tendency to broaden the operative definition in many states in the world beyond the dictionary definition.
3. The assumption that the state, and its law enforcement organizations, always have the moral high-ground legitimizing its pursuit of terrorists. This is often not the case, as many states engage in terrorism against populations or groups they are hostile towards, while at the same time facing terrorism from those groups.
4. The assumption that the state, and its law enforcement organizations and personnel, don't misuse their capabilities to spy, harass or harm people who are not suspected of committing "terrorism" or any other crime for that matter.
>I think this sort of thing leads to a lot of frustration on both sides.
The police can be frustrated with the fact that catching the bad guy is hard sometimes. I can live with that.
Speaking of the Soviet Union, you have to remember that it was "law enforcement" that carried out the oppression by the government. Limiting law enforcement seems reasonable to me.
Or far more simple means. It's trivial, really, to write your own app for encrypted communication or signaling. I bet I could build one in a day.
Even without programming skills, you could set up a shared drive containing only a keepass file. Download the file, use your key and password to open it, then read the message. Monitor the last updated timestamp to see if there have been any changes.
Securing your communications is not hard.
But you're otherwise right that people running CP rings are probably using more sophisticated means that can't be stopped by conventional means.
I wouldn't be surprised to learn that pedophilia correlates with lower intelligence, but a more accurate conclusion to arrive at after watcing TCAP is that most people who fall for a fairly obvious sting operation (in some cases, after having watched the show themselves) are borderline mentally handicapped.
Like better apps, or something homebrewed?
You'd be surprised how poor their opsec can be. Regular file transfer services for instance see this traffic, entirely in the clear, not even the slightest attempt at encryption is made.
Signal is actually working on fixing that (https://signal.org/blog/sealed-sender/).
Odd for government to go after chat apps and online encryption when they can't stop child sexual abuse in those places where it happens the most.
You're right. It's usually a teacher, neighbor, pastor, uncle, etc. "Stranger danger" is mostly BS unless you live in a really dangerous neighborhood, and there the risk is more likely to be simple robbery with incidental harm to the child.
Child sex abuse is also under-prosecuted and under-sentenced. Your average child rapist serves less time than people convicted of selling small amounts of drugs. It's really bad if the abuser is wealthy and can really put up a fight. Google Jeffrey Epstein's original indictment and the non-punishment he received.
If they really cared about child abusers they'd prosecute them more aggressively and sentence them more severely.
Did you mean to compare this to racial biased drug sentencing?
No, its totally consistent with the State's MO; using the 'Helen Lovejoy' argument [1] is entirely specious reasoning when even the most superficial analysis on the perpetrators of said crime is done... but its not meant to appeal to reason, rather its meant to create a knee-jerk reaction when someone tries to refute it before being coaxed down the collectivize population's throat.
It's so easy and simple to say 'what, do you want pedophiles to use this tech now?' and end any semblance of coherent logical discourse on the matter: and that's the aim, to end any discussion or counter arguments before its enacted and further erode privacy and civil liberties.
When I really started to delve into the 'why and hows' of cryptocurency I came to the conclusion that after Wikileaks/Assange got cut off from the legacy system in 2010 that we were already in the 2nd Crypto War (Julian is a key target and is shows [2] as he's been treated like a POW) that followed after Zimmerman's PgP project succeeded and ended the 1st.
I'm a Signal user and I'm not entirely sure what that 'dumping the US Market' would entail, will they pull Signal from an app store? Meaning I could just compile it while accessing it from a VPN, or compiling it myself on PC?
1: https://www.youtube.com/watch?v=RybNI0KB1bg
2: https://www.washingtontimes.com/news/2020/apr/9/australian-p...
Yeah, it's decidedly weird turn of phrase since it is (a) open source and (b) they don't try to monetise it.
> will they pull Signal from an app store?
I don't really see what the app store has to do with Signal - it's just a way of distributing it. It's not like you need the app store to avoid compiling it - there are other avenues.
The risk for them is they or their servers come under some pressure from the US Law Enforcement Agencies. Given their programmers and servers are based in the US, that seems like it could be a real risk. Withdrawing from that would involve moving themselves and presumably families out of the US. It sounds like an almost impossible ask.
In 2014, Aslan and Edelmann [1] undertook “a comparison of sex offenders convicted of possessing indecent images of children, committing contact sex offences or both offences” and, while expressing caution about the “contradictory findings” of previous studies, examined a data set of “230 offenders who had been convicted either of possessing indecent images (Internet offenders n = 74) or committing actual direct abuse of children (contact offenders n = 118) or committing both offences (Internet-contact offenders n = 38).” They found:
> There were significant differences between the three groups of offenders in the way the victim was found. Internet-contact offenders (45%) were more likely to target their victims online and use downloaded indecent images to help recruit their victims … Only 15% of Internet offenders initiated online contact, grooming their victims then requesting indecent images without physically coming into contact with the victim. The majority of contact sex offenders (87%) were known to their victims … Internet-contact offenders were more likely to target stranger victims than contact offenders.
[1] https://dx.doi.org/10.1080/14789949.2014.884618
This data reflects the offences that are detected and prosecuted, so you could read it as suggesting that law enforcement (in London) is focusing on internet offending at the expense of contact offending. It’s hard to say. The data also says nothing about whether anti-encryption laws are needed. However, it does indicate that there is a substantial amount of internet-enabled child sexual abuse and that law enforcement bodies should use some of their finite resources to address it.
What is proportionate is certainly debatable. There is often a fundamental difference of values between civil liberties advocates on the one hand, and victims’ advocates and law enforcement on the other, with respect to the seriousness of internet-based non-contact offences, including the possession of child pornography. When these offenders are counted among child sexual abusers, the proportion who are known to their victims is much less than 90%.
This doesn't excuse the government trying to destroy security for everyone else. One of the biggest problems highlighted by the NYTimes is insufficient funding leading to an inability to apprehend culprits, not the widespread use of end-to-end encryption.
Of course, those apps are not all that they use. There are definite advantages to things like encrypted digital radio vs IP communications, and concomitant downsides such as standing out like a sore thumb in the RF spectrum or being more vulnerable to zero-days against niche platforms.
But anyone can use OpenPGP (or any other tool) today, and anyone can tomorrow, even if such a project stops completely. The source is out there, and so is the source for hundreds of other related tools. There will also be people with — subjectively, depending on whom and where you ask — non-nefarious reasons to have their communications end-to-end encrypted who will find ways to provide such software in a decentralised manner without the point of failure that laws like EARN-IT target.
But government programs have other means of collecting data: OS level backdoors, flawed random number generators like DUAL_EC_DRBG, "unintended hardware bugs" in Intel's CPUs.
I guess they mostly rely on these alternative means. These "let's forbid strong encryption" might be just dust in the eyes to make their targets feel secure if they use apps with "strong encryption".
Some countries do (or have) crack down on really outlandish views for a time. One country's views may also differ from another.
As a matter of principle, I don't much like terrorists as they operate under the goal of spreading terror. I have strong doubts cracking down on encryption would stop them, as they operate perfectly fine with fairly mundane tools and the "mass-surveillance" machine loses them in the noise.
I'm very concerned that technology will put something devastating (at scale) in people's pockets and then we're kind of screwed (do we choose big brother and all that entails, or indescribable mass destruction?). I don't have a solution but it keeps me up some nights.
In case you hadn't noticed, the government is currently on its backfoot and disruptive social policy reforms are back on the table. They want to make sure that corporations get everything and the people get nothing.
The encryption fight has been going on for decades, but at root their complaints about terrorists and child trafficking are covers for expanding a lazy version of COINTELPRO. Lazy meaning that they can just sit in an office and see everything. Let's not forget the FBI's role in trying to get MLK to commit suicide. These shadowy agencies are not in any way the good guys.
It's more like saying "sensors can but whatever crap they want in food they sell, but they have to disclose it accurately".
There's no way to guarantee a middle ground.
If you want a good grounding in the legal precedents - both laws and decisions - that have gotten us here, read Habeas Data. Great book laying out all the terrible implications.
Of course, there's a whole 4th Amendment discussion there. And IANAL, so feel free to fact check whatever.
This has seen attempts at being fixed but dies in the Senate each time: https://en.wikipedia.org/wiki/Email_Privacy_Act#Background_a...
Liberty is what wars are fought over.
If we want criminal justice reform, too, for example, we have to agree that some criminals will come out of prison after their shorter sentences and they will get into positions and jobs where they will cause harm.
Any lightening of sentences will come with bad people getting through and hurting others. But, this is an acceptable price to pay to allow the other felons redemption in this world.
Yes! Also, one sure way to know that we have "privacy, security, and liberty" is that criminals are abusing them. And, as an added benefit, efforts to identify and apprehend criminals help identify weaknesses and OPSEC failures.
I'd be very interested in hearing from child abuse investigators how the controls in the bill line up with how tech is used in abusing children. My expectation is that there is very little alignment, because "for the children" is most often the rallying cry of politicians who want something that is not in the best interests of the people they are supposed to represent.
No, you're putting words in their mouth.
You have your head in the sand if you don't think people use perfectly legitimate encryption service to discuss illegal activity. But that is not a reason to ban encryption. The entire US constitution is built on the premise that people have rights.
But it has always been true that some people use their rights to avoid having their criminal activity detected. That doesn't make our rights any less important.
As much as I'm near-absolutist on civil liberties, I think it's also valuable to recognize that the intrinsic good of individual rights are only one part of the story; the other is the balance of power between government and the governed.
I recently heard Sam Harris opine that from a utilitarian perspective, an absolutist right to privacy pales in comparison to allowing harm to come to children, and so the tech community needs to flex a little on the privacy question, and meet law enforcement halfway. Through that reductionist lens, it's hard to find fault in the argument.
The problem isn't limited to privacy, though. Unbreakable digital locks exist, and they aren't going anywhere. [0] And there is power in the ability to keep secrets. You can bet the Feds have little interest in a Panopticon, where they too are obstructed from keeping digital secrets, as "meeting us halfway" for some greater good. Rather, they want to hoard that asymmetric power as their exclusive purview. No matter how well-intentioned, that asymmetry of raw power is something We The People have a vested interest in taking seriously, far beyond some abstract notion of "I want to Google ${CONSENTING_ADULT_SEXUAL_ACTIVITY} without worrying the neighbors will find out".
I'd say it's pretty easy. For utilitarianism to make sense, it has to take the future into account. And what looks like an absolutist right to privacy might be a utilitarian argument of the type that if you grant a monopoly of power (private or public) the right to make use of your private information, then it could well use that private information against you later.
An integral utilitarian might then say "it's worth some harm to children today to ensure there won't be great harm tomorrow". That kind of being able to trade off different scenarios of harm without regard to absolute principle is pretty much what characterizes (act) utilitarianism.
The Chinese made mass surveillance even simpler: they have lots of cameras and face detection.
We don't have much privacy these days.
Secondly when a party consistently pushes for an extreme position if you meet them halfway as a matter of policy you will shortly find yourself within spitting distance. The only productive position is extreme obstinacy.
Nobody is putting words in anybodies mouth.
Obviously this bill is about more than that, but I think that statement pretty much torpedoes their main public argument.
What specific controls are you asking about?
It's possible for both things to be true at the same time.
If Signal exists and is secure, will criminals use it? Sure they will, criminals are people and people want private communications.
But if you ban honest citizens from using Signal, will criminals stop using secure communications? No, they have an unusually strong incentive to use them and will seek out alternatives. The percentage of criminals who switch to insecure communications will be lower than the percentage of honest people who do.
Which increases the amount of crime, because the amount you're helping law enforcement catch criminals is smaller than the amount you're helping criminals exploit victims. This is also compounded by the fact that there are more honest people than criminals.
There is a theory of bureaucracy ("an institution will attempt to preserve the problem to which it is a solution") that says law enforcement agencies will ask for this even when they know full well that it will increase the overall amount of crime, because more crime is good for them since it means more law enforcement.
Regardless, I feel like there's a deeper motive from governments/law enforcement. It would allow them to claim that anyone using secure comms must have something to hide and is thus a criminal. Combine that with mass surveillance and anyone you see sending encrypted traffic can automatically be assumed to be a criminal. I'm not saying this is right, it's certainly not right. But I'm sure that's the argument that will be used by those trying to push it.
The only way to fix this is secure-by-default comms, such that all traffic looks the same and you cannot make any claims of criminality based on that alone.
Suppose you're a criminal organization or a foreign government. You break into AT&T or Amazon or whomever and get access to a bunch of data streams. If they're all E2EE, you have a bunch of inscrutable ciphertext. If they're not, you have everybody's passwords, trade secrets, credit card numbers, information useful for blackmail etc. Lack of strong encryption enables crime -- that's why honest people use strong encryption.
This has been a 2nd Amendment argument for ages: "If we outlaw guns, only outlaws will have guns."
It correctly identifies that the proponents need to justify the cost from substantially all law-abiding citizens following the law against the benefit from only the law-abiding criminals following it.
And say what you will about the benefits of law-abiding citizens carrying firearms, but if you want to seriously dispute the benefits of law-abiding citizens using encryption, try convincing a credit card company to let you accept credit cards on your website without encrypting the traffic.
You listed two things that easily and obviously line up with a Bill of Rights amendment... not sure there is one of those for encryption. Unless I’m just blanking...
I think this is fine here, but I am compelled to point out and remind, given the amount of concurrence in the thread:
In a more rigorous discussion, I think this is a particularly dangerous line of thinking to the Stallman-level advocate and their campaign down the line.
Edit (oops. Chopped off a long version of this paragraph when I edited down the post): Privacy, security, and liberty are maintained by the advocate to be the natural rights that are paid in price for justice.
This isn't to speak of those in agreement here or myself (and not just limited to said advocate), but on the part of anyone that uses such framing, for risk of it massively normalizing, even if I find it an artistically made point.
[1] https://act.eff.org/action/protect-our-speech-and-security-o...
Your input is discounted at least in direct proportion to how little you sacrificed in order to provide it. If you really want to make an impression, telephone your representative.
In either case, contact instructions are here: https://www.usa.gov/elected-officials/
You can do this while walking out of the office to the parking lot or metro station.
Really, you want to have a steady stream of payments flowing from you to them. That way, they're accustomed to it, and you always have the implicit threat of suspending the payments. This basically mirrors the structure of an ordinary ongoing personal relationship.
One-time donations, which would reflect an ordinary commercial relationship, don't work well, since the thing that makes them work outside of politics -- conditioning payment on receipt of the good purchased -- is illegal in politics.
One of my college roommates works for a congresscritter. He says, at least for his guy, written letters still have the most impact, followed by telephone calls. He didn't mention faxes.
E-mail and social media are waaaay down on the list because they take the least effort and can be gamed so easily.
If this were true, corporations would be completely ignored when they provided a measly few million dollars in campaign contributions...
I helped with processing the results of a large government RFC for a large government aid bill (Farm Bill 201?) and the exact opposite was true. There were too many responses to individually read each one so the responses just got bucketed and counted. You could be fine with a one off response but it would be less likely to be bucketed correctly and would still only be counted once per bucket at most.
To cover your bases I would always do the easy one click option and then write the handwritten letter as well.
I've written her enough that I can already write my own reply from her office. Shorter Feinstein: "Thank you for your concerns, but you're wrong."
Because she is a terrible Senator. Please, please, please stop voting for her already.
No need to be so negative. Isn't it nicer to say, "There's a good chance that she won't win reelection*."?
https://projects.fivethirtyeight.com/congress-trump-score/
She used to vote with Trump more than any other Democrat. Now she’s number 2 (and she is much further right wing than many republican senators).
I don’t understand how she keeps winning in places like SF. Even a California republican would probably be further to the left than she is.
FF 74.0.1, 64b, windows 10
May I ask where your confidence comes from?
I’ll actually be more surprised if this doesn’t go through, at least in some form.
"This product is designed with the highest levels of security in order to keep you safe from criminals and other illicit actors on the internet. Because of this, it has been deemed inappropriate for use by citizens of the USA by the EARN IT act. Until this changes, it is only available outside of US jurisdiction. Please contact your congressional representatives for more information"
Of course indulging their utter folly leaves us all worse off so we need to stop them. I notably haven't gotten even an email or after sending an email calling out EARN IT as downright nationally suicidal given the how much of the US economy is dependent upon secure cryptography, and the obvious relationship between GDP and power, and that if they gave a damn about the children they would be investing more in social services and investigation instead of trying to seize more power.
Not sure if I reached them or got it put in a proverbial circular file or "enemies list/ban from volunteering as disgruntled" by a staffer but the fact they didn't send a "for the children" form letter bullshit is somewhat reassuring that it reached a real human and they at least recognized one case of "too pissed to even try to form letter bullshit" is a small victory and enough negative tickmarks to say "this is a bad plan" is the current win condition.
Of course a large victory would be dropping from sponsorship but that would be near impossible even if I was a connected great speaker who called him out in person.
Most Americans don't seem to know enough about how the government uses the backdoor to care.
We have to stop it every time, and in every variation. On the other hand, they can keep trying over and over again.
I'd much rather see EFF and others working with congress to introduce laws that _prevent_ this kind of thing, saving the long sequence of future fights as this resurfaces under names. One of those fights, we're bound to lose.
Of course they could operate. They would just have to backdoor their encryption. Which, presumably, is what this legislation wants to achieve.
They don't want a world with no chat apps, they want a world with chat apps they can listen to.
What Signal is saying in this blog post is that they would rather give up the US market than weaken their encryption. Which is worth saying, because it's probably not true for most other apps. Most corporations would not give up the US market, no matter what compromises they have to make.
Is it even possible to have end-to-end encryption (in the technical sense of the term) with a backdoor? If your product's marquee feature is security via end-to-end encryption your product is a non-starter in a jurisdiction that bans end-to-end encryption, no?
Could they operate, so long as they implemented a mechanism to scan for and report child pornography? Assuming (optimistically) that the government committee that the EARN IT act mandates adopts reasonable standards.
I think this article gives a good background on the problem: https://blog.cryptographyengineering.com/2020/03/06/earn-it-...
I (personally) think that client-side photo hashing and automated comparison against one of the child abuse databases should be sufficient. Alternatively, Signal could probably just disable features for sharing images in the US.
Signal's model is that their servers are never able to understand any user content. You can't effectively scan for prohibited content on the client side for several reasons:
A) someone who wants to send or receive prohibited content could alter the client to skip the checks.
B) shipping the check to the clients makes it possible for distributors to run the checks and alter their content until it passes the checks.
If client side filtering was effective, the ask should be for Google, Microsoft, and Apple to scan and report prohibited content on their operating systems, which together cover the vast majority of user terminals.
I disagree. I think these scanners can only be good, but never perfect, so they're mainly effective against technically unsophisticated abusers. Weakness that are only exploitable by someone with advanced technical skills are not actually a problem.
> A) someone who wants to send or receive prohibited content could alter the client to skip the checks.
That's true in any kind of scanner. Server side checks could be defeated pretty trivially by using any encoding scheme not anticipated by the scanner's authors (e.g. sending an image as text messages encoded with rot13 Base64). No scanner can be robust against even a mildly technically savvy opponent unless the scanner has complete end-to-end control over everything, including the clients.
> B) shipping the check to the clients makes it possible for distributors to run the checks and alter their content until it passes the checks.
My understanding is those databases and algorithms are not secret information, but are publicly available to provide low barriers to implementation, so someone could download one and do what you propose now.
Assuming the checks are not hash-based (literally any mutations to a file make these worthless, and the libraries of hashes of illegal content are gigabytes and growing), the computing power required on the client side is infeasible to ship in a product intended for any modest consumer hardware.
Let's assume this is limited to child pornography only. You first need to store some perceptually-encoded version of _every_ illegal image on the user's device (in such a way that it's impossible to reverse-engineer one of the images back out). Then you need to try to match the image being sent against each of the encoded versions of each of those images. On a server farm, that's _maybe_ practical. On someone's crappy Samsung Galaxy phone from 2013, it would take days or weeks to process a single image.
Let's assume it _was_ some hash based check. People complain that the Facebook Messenger app is over a hundred megabytes. Do you think someone is going to download the Signal client onto their phone with a gig of file hashes so that they can get reported to the police in the event that one of their images has a prohibited hash? No, that's crazy.
And even if it _was_ feasible, Signal is open source [0]. It would take a single person maybe a day of works tops to create a version without those restrictions and throw an APK onto a static website.
I could do that, because nobody knows who I am.
But then, I'm not technical enough. And I couldn't do that as Mirimir, because that persona has existed too long, and has been far too public.
The point, though, is that I'm confident that it's doable.
I believe i could self immolate a million times over in front of a variety of scenes and meanings, people could call, write and click, teach and learn. There is however an absolute, it seems, that there is no profitable path for relatively infinite powers (politicians and corporations) to allow any meaningful movement towards the more humanitarian, civil/passionate version of a culture.
Instead we will visibly or not be corralled into a highly monitored and monetized form of drone happiness. Its cool.. as long as zoom always works, right? In a sort of twisted ‘we will do things to them but it wont happen to us’. Perhaps quarantine brain is boiling over into my comment style.
After five decades of the bloody War on Drugs, I have zero respect for the rule of law.
Or you’re channeling Dostoevsky.
I'm honestly curious about why there's no widespread opposition to the bill yet.
Facebook publicly coming out against this might not be helpful: most people just don’t care. Those that (potentially) do care are far more likely to be mobilized by the EFF or ACLU, which they tend to trust. Facebook isn’t the most trusted brand name in privacy, as far as I can tell. Their support might actually be detrimental for the cause.
An open split of Silicon Valley and Republicans would also “politicize” the issue. Almost instantly, you’d have the 35% of Trump supporters galvanizing around the bill, even if they were previously ignorant or lukewarm on it. See the recent train wreck around Qunines-against-covid for a great example of this effect.
Big companies don't generally make ethical stands, and small companies can't afford to. Apple makes some stands but only to be competitive against Android.
Thanks for the link, I sent an email with it.
They don't want to offer a product that doesn't support e2e.
The best counterargument I came up with at the time is the security of our children. Who the hell knows what teenagers are sending to each other these days? Do we even want to know? I don't, and it's weird that Attorney General Barr wants to open this door. Why risk letting the wrong person sneak into a position where they can see all of our children's messages, everyone deserves real security
Edit: see below, server code is open. Keeping original text below:
IIRC the server code is proprietary, but the clients are open. That's a decent starting point.
(I mean, there's the obvious practical problem that the official server URL is hardcoded into the app, so if you wanted to use your own server you'd have to build your own copies of the app for you and your communicants, but other than that...?)
You could solve that by Federating, except... Federation would be lovely if you could actually deliver Signal's goals and do federation for free, but what we always see from proponents of Federation is that was their goal and so they're done. Oh you wanted security? Sorry, we federated everything, so you'll need to get every single member of the federation on board with every single change you need, we know you can't get that done but that's fine because our priority was federating stuff, so we are successful, shame about your goals.
As an example, somebody earlier in this thread mentions you can "just" know who is communicating with who anyway. Signal got rid of that, because they can, and it's a security improvement, so they put all the work in and did it. Now even Signal's own servers don't know who sent most messages! "Sealed Sender" means Signal has no idea who is sending this message to my friend Steve. Maybe it's me? No idea. It just has to be somebody who Steve allows to send him messages. Could be Steve loves spam and so it's a spammer. Could be Steve loves the AfD and so it's a Nazi. No way to know without reading the message which only Steve's Signal client can do.
Now imagine trying to roll that out to a federated system. After years of effort maybe you switch it on, and then you find a bug and have to switch it off again for a few years while you fix that. Hopeless.
I have a lot of serious criticisms of Matrix, to the point where I don't recommend it to friends (yet?), but this feels like an unfair and unserious criticism. I don't think you can fault their motives.
And as another user points out, if Signal goes down in the United States because of legislation, so much for the supposed convenience of your non-federated central server approach! If that happens I'll take Matrix over nothing, thanks.
Hope you got it!
If Apple users actually controlled the software running on their devices that wouldn't be an issue.
A want for federated services complements a want for control over our computing.
Hope you got it!
Not in the US, where as of March 2020 it maintains a 60.1% share.
...and have an ecosystem of users that cannot communicate with users on Signal. That's what lock-in is and "go right ahead" is just not enough.
> You’d just be opening yourself up to the same problem facing the Signal Foundation
citation needed
Is isn't. What‘s more, you all know that. Everyone agrees the act is unlikely to to stop dedicated pedophiles and terrorists. The Republicans and Democrats know that as well. Crime is a useful pretext to openly push for what they can’t say aloud. They wish to suppress dissent.
They know the threat unbreakable encryption poses to their wealth and to their power. It’s freedom. Freedom from detection, identification, coercion to comply. Freedom to do what you think is right.
If it’s passed, terrorists will reasonably include domestic terrorist. Which will broaden to include Antifa [1] and Black Lives Matter [2] in the government’s eavesdropping. Then people who attend the same protest that BLM or Antifa appear at will need to be monitored. And so on. This is the whole point. Not pedophiles. Not Al Qaeda or Isis. They pose no threat to the power of the ruling class. You do.
[1] https://www.washingtonpost.com/politics/2019/07/20/senators-...
[2] https://foreignpolicy.com/2017/10/06/the-fbi-has-identified-...
The term "interactive computer service" means any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server, including specifically a service or system that provides access to the Internet and such systems operated or services offered by libraries or educational institutions.
It appears that a P2P app would be off the hook, at least for now, because there is no "server" in the picture.
Wouldn't that mean every node on a P2P network would be considered a client, server, and interactive computer service?
Another way of interpreting this, I think, is that everyone participating in a DHT or scuttlebutt network would be responsible for every other user's behavior on that network.
You might be right though.
Maybe I should get a Purism phone.
[0] https://support.apple.com/guide/itunes/back-up-your-ios-devi...
Here’s some links related to these ideas which may be relevant to your interests.
https://support.apple.com/en-us/HT208079 iTunes update that allows installing apps
https://www.idownloadblog.com/2015/12/25/how-to-download-old... Charles proxy how to download specific app versions
https://www.reddit.com/r/jailbreak/comments/auabt7/question_... Context for AppAdmin jailbreak tweak which allows for downgrading apps from device via App Store
http://www.i-funbox.com/en/index.html iFunBox lets you backup and install ipa from device via pc or Mac
http://julioverne.github.io/description.html?id=com.juliover... Jailbreak tweak to auto resign apps and install/backup from device
https://support.apple.com/apple-configurator Apple Configurator allows device management and provisioning by your whitelisted macOS devices
I suspect once you get into "use a secure VPN in an EU country" you've already given up as far as the "average person" is concerned. You might as well recommend something like renting a VPS in a country with strong privacy laws and installing your own VPN on that, which is slightly more difficult but a much better security win if you're going that route.
Encryption is dangerous to children Politicians - yup...take it away guys.
Hopefully, Apple will publically denounce this act, putting stronger pressure on representatives and increasing public awareness.
Just because your account keeps track of your devices, doesn't mean Apple can't do this attack.
The standard method to detect MITM attacks from server side is with public key fingerprints. Sure, that feature could be backdoored too, I've seen that in a real life product. But that's only half of the equation: you need FOSS client with reproducible builds to ensure the feature actually works. After that, the users can verify their E2EE is working the way it should. Fingerprints alone aren't enough.
As I point out in the long post, use Signal that allows this.
Thorn seems especially poised as mitigating child abuse is the essence of their organization. Whatever their stance, they appear to be an authority in the private sector spearheading technical efforts to combat child abuse. If any Thorn engineers/representatives - or any platform engineers focused on abuse prevention - are reading, I'd love to hear your take on the proposed legislation. It's imperative that we grant resources necessary to challenge such a horrific human issue without sacrificing our privacy and subsequent civil liberties
For context... https://www.thorn.org/
https://github.com/Spark-Innovations/SC4
The project has been moribund for a while because it's hard to compete with Signal but it wouldn't take a lot of encouragement for me to take it up again. First on the agenda is adding a ratchet. Most of the heavy lifting is already done (https://github.com/rongarret/ratchet-js) it just needs to be integrated. I also have an iOS app that was kinda sorta working the last time I tried it.
Government agencies should be able to fight crime without massively spying and monitoring their citizens.
Nor the rest of the world's citizens.
As usual, one of the Horsemen of the Infocalypse:
https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
e2e encryption only prevents certain forms of access to the content. You can still find the physical device and (provided it's unlocked) read the messages off it.
Encrypting on one end and decrypting on the other could theoretically be performed manually with the message sent via an insecure channel. So is two party encryption what's illegal now?
Hopefully some will switch to a surveillance platform and get outed for whatever it is senators do between screwing the country over.
grabs popcorn
I wouldn't expect them to understand the consequences of what they're doing, they likely think it magically just applies to all the people they don't like.
I was thinking that Session/Loki was better protected, but the Loki Foundation is likely just as vulnerable.
Forcing Signal out of US market is the goal.
In Capitalist America, phone spy on everyone for government.
Chat apps should support input plugins. If a user encrypts locally, there's nothing the network can do about it.
Therefore, we have programs like Signal that do that for us.
It would be nice if message transportation were decoupled from composition and consumption. Default bundling is fine for ease of use, but allow first-class replacements.
> Encryption is for hiding our comms from China and Facebook, which keeps you safe. Hiding your comms from America makes it harder for America to keep you safe. Encryption should be weak enough to let the US government have the knowledge it deems necessary, but strong enough to build a moat around that superiority.
It's misguided for a bunch of reasons that HN well understands, but it holds water. That's what makes it scary: not that it's absurd, but that unless you're both well educated and skeptical, it sounds downright responsible.
It makes the store where the keys are kept a priority target as well.
So when the system that contains the key is hacked and the key is exfiltrated? Or if an insider steals or leaks the key?
The effin NSA couldn't keep their most well guarded secrets from the Shadow Brokers and from Snowden, there isn't an entity on the planet we should trust with such key.
The problem with tor I don't like is that it's no longer the lighthouse of freedom it once was. It's too tainted by all the perverts and heavy criminals that abuse its power. The same happened with Freenet sadly and completely killed it for the mainstream public. This "slimy" feeling is slowly corroding tor as well. I can't help but feel it does need some kind of control, not identification of peers but some kind of banhammer.
Also, the anonimity tor/tox provides is not really needed as I'll use it to communicate with people who know who I am anyway.
Finally, tor isn't exactly serverless either. Governments could shut it down if they wanted to. But I think they rely on it too. I'm sure they run exit nodes to keep tabs on things and I'd imagine they use it for communication with their own spies. After all, it was invented by the US government itself for such reasons.
Does Trump support the EARN IT bill?