EU Draft Council Declaration Against Encryption [pdf]
statewatch.org
statewatch.org
I guess we'll be weighing in on the EU proposal as well as the 7-eyes one.
This proposal seems to address general abuse, spam, propaganda, filter bubbles, and so on. While these are worthy issues to tackle, the authors of the 7-eyes statement are not really interested in them.
What they say they want is for terrorism and child pornography to be detectable or meaningfully reduced. Do you think a relative reputation system will solve that problem?
I am in communities that don't use such tools and somehow there is no problem that would require any, but if that is the preference you have the option. I don't see further issues.
1)
a: It's really not that hard to think of ways to solve backdoor problems with a mix of technical and social approaches. For example, having shared keys burned onto silicon, making physical access mandatory, and split between both the law enforcement and the company, so that both parties must knowingly engage.
b: Most software already practically backdoored already, and it's really not that big a deal. Microsoft can push whatever updates they want whenever they want. They already have the keys to the kingdom! Google doesn't store everything E2E encrypted. They also already have the keys to the kingdom! Things have mostly worked out regardless.
2) That a measure will be imperfect is not an argument that it will be ineffectual. In fact it's pretty obviously false; making abuse harder on mainstream platforms will make abuse less mainstream.
3) This is like arguing governments shouldn't be allowed to regulate weapons, because it would be hypocritical, given they own weapons themselves, and it might normalize other countries taking away their citizens' weapons, which might prevent them fighting back. That seems like an obviously bad argument.
4) Yes, your platform that makes oversight impossible is not compatible with regulations requiring oversight. That's not an accident, in either direction.
The idea later in the post seems not really honestly engaging with the topic, that it's not about ‘someone who believes birthday cake is undesirable’, but about networks which are systematically and in actuality doing things like trafficking children for sexual abuse, and that there is a moral imperative for governments to deal with this beyond just letting people choose not to engage.
We live in a dangerous world. We cannot control everything. I don't mind a slight risk of terrorist attack on myself or my family (caveat lector: I am young), if that means greater freedom.
In my book this is the first step towards authoritarianism: ensure that the state survives at all costs. And being able to spy on the whole population to track outlaws and dissidents is part of this. There is an invisible barrier between what's legal and what's not. Crossing it isn't hard, look at extinction rebellion and other civil disobedience protestors. Yet, on the other side, your trusted options are very limited, and encryption is one of those. I'd argue that letting citizens communicate and organize privately is a vital component of democracy, even allowing citizens to seize control of the state if they deem it necessary. More so than U.S.A.'s "Second amendment", encryption is an arm citizens should legally be able to bear.
Now, it is obviously hypocritical to offer such a thing, as politicians certainly wouldn't want their texts to be snooped on, would they? Any bill that requests backdoors should request them from everyone.
And don't get me started on how governments recommend their own to use Matrix and Signal, the very apps they aim to backdoor, because they are secure. You can't both have your cake and eat it, too.
A useful thing to explain encryption backdoors is the TSA master keys: https://news.ycombinator.com/item?id=12177079
Their very existence made locks less secure (possibility of a key leak), and those are worthless against thieves now that master keys have leaked (you can 3D print them).
No we don't, but that's what the Politicians try to implement in our brains.
It is pretty stupid to try to jump a car on your bicycle without a landing ramp. Or play catch with lit M80s. And those weren't our dumbest ideas.
When I was a kid every 8-year-old pushed a lawn mower around once a week. And rode in the back of a pickup truck. Today I don't let my kids ride in the back of pickup trucks, and I'm nervous about the lawn mower. Or rather, I'm nervous about trusting my kid not to be careless with the mower.
But when I see the metal detector at the door of my kid's school I wince. Some dangers and some fears need to be met head on. For some people, those include riding in the back of pickup trucks. For some it is the school's metal detector. If only we could make those choices for ourselves and our children without forcing our fears onto our neighbors.
Edit: clarity
What you are more talking about is the Politicians overstate the chance of dangers and they do it on the most evocative of topics (ex: terrorism, CP, etc).
A high danger we're in is from the potential for our governments to entrench their own powers and encourage potential future totalitarianism for small benefits here and now.
It is by definition. Their ambitions haven't changed the last 30 years.
Actually you can have your cake and eat it. What you can't do is eat your cake and have it :-P
Well, you got the point. In french, we'd say: "You can't both have butter and money for it" -- greedy butter sellers.
1. Terrorism and trafficking of children will win the moral high ground.
2. App stores will be forced locale by locale to conform to these policies.
3. Most people will not notice or care.
4. This will be used by N-Eyes and totalitarian governments to quash dissent.
5. Meanwhile the tech crowd will create alternate app distribution mechanisms allowing those who care to communicate securely.
6. Those secure methods will be used by people with the most to lose. (e.g. the drivers of point 1)
Given this predictable series of events I see the primary question as: How do we prevent (4)? How can we make people secure by default again and make adoption easy in the face of app store capture.
Requisite:
> The term was coined by Timothy C. May in 1988. May referred to "child pornographers, terrorists, drug dealers, etc."[2]. May used the phrase to express disdain for what he perceived as "Think of the children" argumentation by government officials and others seeking to justify limiting civilian use of cryptography tools. Connotations related to such argumentation continue to be attached to the phrase, and it is more commonly used by those who wish to deride various restrictions on Internet activity than by those who support such restrictions.
* https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
• By ensuring there is always an opposing power.
• By maintaining democracy, by which I mean the tenet of electing governments from the citizenry as well as by the citizenry, and specifically rather than any of the oligarchical forms.
• By maintaining the rule of law.
The consequences being, if all encryption is backdoored, then any encryption used by politicians is by definition eavesdroppable by their opponents and enemies. Since all politicians thrive in a web of mendacity and confidences, they have a strong incentive for strong encryption, and will eventually terminate/abandon legislation that weakens it.
Any politician that threatens otherwise is therefore a) grandstanding, and/or b) using the issue to leverage/negotiate something else.
Corollaries:
• Any government seriously implementing such a plan is operating as an oligarchy rather than a democracy, and will have plans to defend themselves from the surveillance imposed on the citizens.
• The first instinct of every would-be oligarch is to undermine the machinery of democracy and compromise the rule of law.
c.f. Utopia (Australia, 2014) Season 4 Episode 4 "Mission Creeps", and probably at least one Jim Hacker moment.
8. Privacy activists will leave group 6 by attrition, further reinforcing justification by authorities for 7.
Privacy only works well when everyone has it.
https://www.politico.eu/wp-content/uploads/2020/09/SKM_C4582...
In my view there is a good chance that (2) will not be EU law for the foreseeable future, although this does require some opposition work. I guess one can see it as education of the politicians (the commissioners in this case).
Educate the Comissioners? The president of the Comission is an ex home secretary ie. a lady with a policing mindset just like Theresa May, only allegedly corrupt. Somehow her phones were wiped clean when required as evidence in a recent investigation. The irony of this legislation is that it could expose her own doings.
https://www.google.com/amp/s/www.politico.eu/article/ursula-...
The Comissioners were told to use Signal after Bezos' phone got trojaned through WhatsApp. Encryption is only good when it's for their own benefit.
As is always the case with these fights, the fundamental fact is that the war is asymmetric. We have to be right all of the time, they have to be right once. We have to break all encryption everywhere forever, they have to find one non-backdoor'd solution.
If you really hold the backdoor proponents' feet to the fire, they'll admit that yes, this is true, but at least with a backdoor you can catch some of the terrorists/child abusers/etc, some of the time (of course, you only get the dumb ones...), and we wouldn't want to let the perfect be the enemy of the good. But of course, saying you want to compromise all privacy in the developed world to catch a few dumb traffickers doesn't get votes.
I hope that if we ever reach a steady state, it will be unbreakable privacy.
We need actual software like https://Matrix.org or https://qbix.com/platform to be good enough that people will install it. Like the Web Browser did killed AOL and MSN. Otherwise we will live with Facebook Google etc. and this is moot. But that is just the beginning.
Secondly, we need open source hardware. We are nowhere close to competing with Apple and Android. But as we have seen over the last 20 years - there is a war on general purpose computing and the closed systems have started to win. Just today I read that Android doesn’t let you take a screenshot of your own phone.
Third of all - the open distribution mechanisms you rely on today to not block you (eg web browsers) can be closed or ship updates with backdoors tomorrow to most users. Apple and Google together control most of the market. It isn’t hard to pressure them to do this.
Apple blocked blockchain dapps being distributed on iOS, unless they are made by an Apple developer whose app they can revoke. Amazon can yank your movies and books out of your hands.
Anything you think is secure (eg secure enclave) may not be. Trusted Computing Environments are made by two companies essentially.
In fact, I am surprised that more “stuxnet” attacks arent done in nuclear reactors across various countries. As self driving cars get hooked up to the net or delivery drones become ubiquitous we may see massive vulnerabilities that can be exploited all at once. Not just by state actors but anyone. Really scary stuff.
Sadly the same entities locking down the computing devices also start requiring uplinks to their servers and can push any updates. Regular people are at the mercy of corporations and the state.
Unless open source companies step up and build a decentralized hardware distribution infrastructure, with multiple actors (like VOIP relaced centralized telephone switchboard operators) all these arguments are moot. There is a handful of tech companies whose arms need to be twisted and that’s all.
PART II:
To be honest ... I no longer think that end-to-end encryption is the right solution to human rights problems. If citizens are reduced to sneaking around and denying their activities to survive, their governmental system is way past due for fixing. This is like the “good slave owners” delaying the abolition of slavery. You’re solving the wrong problem.
I believe that crypto is needed to secure decentralized byzantine fault tolerant systems like Ethereum etc. to be TRUSTED, not to hide information. Signatures, not encryption, if you will. If anything, it is the government who doesn’t want encryption to be broken (eg of copyrighted DVD content etc.) and there is an inherent contradiction since anyone who consumes unencrypted content can reshare it.
What we really need is to decentralize the personal data in many places, and use zero-knowledge proofs for attestation, but that is different than encrypting and hiding information.
Many of the common tools (both hardware & software) that common people use are at the hands of few, who can abuse the users themselves or at the request of the Government.
> To be honest ... I no longer think that end-to-end encryption is the right solution to human rights problems. If citizens are reduced to sneaking around and denying their activities to survive, their governmental system is way past due for fixing. This is like the “good slave owners” delaying the abolition of slavery. You’re solving the wrong problem.
This (clap)(clap)(clap)
Not many seemed to care to click the link in that thread. If one did one would know that it was to a bug report and a fix was even posted in the same link. Screenshots work just fine.
> No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.
I mean wearing my programmer goggles it doesn't state privacy AND correspondence but OR, but still. Not having your personal conversations get intercepted is not too much to ask for, is it?
I mean I get it, if they have a reasonable suspicion they CAN intercept your communications (listening devices, intercepting the phone conversations), but this is not a right they can claim on anyone, and they shouldn't be able to force companies to allow them to listen in. Not arbitrarily anyway (see: Snowden revelations, where it was proven that the NSA just hoovers up anything and retroactively checks if there's anything wrong in there)
In other words, “encryption” needs to be listed there as a right, to remove any room for interpretation. Or explicitly listed as an example of a more general right, like the right to private speech (or whatever you want to call it).
But still what? The logic is perfectly correct; ~(a | b) = (~a & ~b)
The courts may not view the police, with a warrant, wanting to see your texts because they believe you're doing something illegal as a form of 'arbitrary' interference.
This new proposal sounds nutty to me, but I think that our various constitutions provide for the possibility of government access to private stuff given legitimacy, proportionality etc.
E2e encryption that is "safe from courts" isn't protected.
Imagine that some unnamed corrupt government treats your telegram messages as correspondence, but not encryption keys. It then orders Telegram to release said keys (pinky promising not to do anything nefarious with them) because they aren't considered correspondence.
- Everyone has the right to respect for his private and family life, his home and his correspondence.
- There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others.
(I'm not feeling bright enough to comment but this seems extremely relevant)
[0] https://www.equalityhumanrights.com/en/human-rights-act/arti...
Prevention of not just crime, but also disorder? The economic well-being of the country? Protection of health or morals?
I suppose it's better to pay lip service to Right to Privacy, instead of completely ignoring it altogether. But this is not a human right.
That sounds more like declaration of “human rights” by China than by EU
shakes head
It is too easy for many politicians and security agencies to think that their master keys and backdoors won't ever fall into the wrong hands, that they're careful, etc. And if you point out the problem, they'll tell you they'll be even more careful.
Think about it from a non-techie perspective. I don't think most people even understand the concept that a message that goes from sender to recipient in WhatsApp can't be decrypted by Facebook, let alone by anyone else. I don't even know if there is a common analogue-world comparison you can draw, this is an utterly new concept for people who don't understand encryption.
1. Encrypt as normal.
2. Given a language model which can generate a choice of multiple possible next-symbols given what has already been written, use bytes from the cypher text to choose between the available options.
For example, using the predictive text options on my iPhone, and treating 0=left 1=right, the cypher text 011100 and the starting symbol “Hi”, I get:
“Hi I have heard from the other”
(Note: I’m fairly sure the iPhone predictive text system is personalised and therefore time-variable, but the general idea still applies if you are in full control of the system).
3. If the other party knows the model and the initial word, they can use an equivalent process to recover the cypher text and put that into the normal decryption routine.
Found this related question on Crypto Stackexchange: https://crypto.stackexchange.com/questions/32767/how-to-disg...
The question of interest is "how to generate sentences that allow the most dense insertion of data?".
The best two I saw were:
* Used a copy paste (with link) of tweets / jokes / song lyrics with trite comments around them.
* Used an html formatted email with images embedded. The images were fiddled to hold the bulk of the payload and the surrounding sentences were just to describe the image to give it authenticity.
The funniest was a dirty poem generator based on an oracled (to inject the payload) monte carlo sim. It ised historic dirty letters and all sorts of poem formats.
This was at a hackathon in Hampshire (uk) ~2014
I was born and raised in a country occupied by communist invaders, so I know very well how unbelievably horrific it was to live under continuous surveillance.
Despite the many Western fiction works, either movies or novels, which attempted to describe how life was in the Eastern Europe and Soviet Union, I have not seen any that succeeded to really convey how awful that was, because it is very difficult to imagine it when you have not experienced it.
After 1990 there was a short time when things seemed to be improving in the world, about the human rights, but that did not last for long.
After 2000, the Western countries began to resemble more and more every year with the communist countries they were formerly criticizing.
This sad evolution concerns not only the continuous attempts to restrict the basic human rights but also the continuous reduction in competition in the economy, by more and more mergers and acquisitions.
Despite what some say, the socialist economies were not really different from the capitalist economies, but they were identical to the extreme form of a capitalist economy, where, in the absence of regulation, everything is produced by monopolies. Now, with the exception of few domains where there is still vigorous competition, even the American economy is so much dominated by quasi-monopolies, that it resembles more to the old Russian economy than to the American economy of 30 years ago.
Twenty years ago, when I designed some electronics hardware, I could search the Internet for the datasheets and manuals of possible components and I had many possible choices for each of them.
Now, for many key components, I have only one possible source. Moreover, for many important components that I might use, I cannot really determine whether they could be used, because their technical documentation is provided only after signing an NDA and only if you intend to buy really large quantities.
Such changes were very gradual, so for those who did not live enough to span several decades of experience, the way things are done now may seem normal, but they are not and they are definitely worse than before. Now it is far more difficult to innovate.
Regarding surveillance and encryption, most Western people, who have not yet experienced the extreme abuses towards which the current legislation slowly evolves, are very naive and they do not understand how dangerous this really is.
The irony is that now the Western countries are trying to make lawful things that not even the communists had the courage to introduce in their laws.
Even in the communist constitution that was valid when I was a child there were constitutional rights for the secrecy both of the phone conversations and of the mail messages.
Obviously, like the NSA, the secret police did not care about what is lawful and what is not, so they intercepted any mail message or phone conversation they desired, but at least there was no doubt that their activities are illegal. Fortunately, they did not have the technical abilities to intercept all the phone & mail communications, like today. Otherwise I would be still living in a communist country.
Because of my experience, no matter what abusive laws might be introduced in the future by corrupt politicians and no matter which would be the consequences, I would never recognize that any other human being has the right to command me to not encrypt any information that belongs to me. Equivalently with being against the interdiction of encryption, I would also never accept that any human being has the right to demand that I must answer to any question, if I do not want to answer.
Of course, if that question had been in the context of a legal investigation, refusing to answer some question may be considered as evidence supporting the supposition that the questioned person might have done something wrong. Therefore that person might be punished for what he/she is supposed to have been done, if being guilty is considered certain enough.
However, punishing the person just for refusing to answer a question, without any evidence strong enough that the person has committed any other crime, as it is frequent now in the USA, this is something that I consider to be an unacceptable abuse and a breach of the most basic human right.
It is doubtful that it will see something like encryption that allows speech and communication at a distance without government knowledge or control as a basic human right. After all, if some speech is so dangerous that it cannot be posted online, then we should make sure it is not spreading to who knows what kinds of people without government knowledge.
Of course it is, it's called freedom of opinion, simply some opinions are considered crimes by the EU law system.
Removing a post that incites someone to commit suicide or to kill someone can save the poster from being prosecuted.
That's it.
Private communications are excempted though, unless they need to be used in a trial after a judge authorized it.
An example[0] from 2012 in a (then) EU member state is very informative in that regard, as indeed is the name of the special adviser behind the controversial policy.
no encryption for the people
sounds like the perfect democratic recipe
China dealt with the pandemic swiftly and decisively and life is getting back to normal there now. Meanwhile, the West had months of warning and vast majority of the governments chose to do nothing. Instead of stocking up on supplies and preparing the public the officials and the media called Chinese lockdowns authoritarian and played down the severity of the problem until thousands of people started dying. Our governments chose to protect business interests and to sacrifice the public for the sake of the profits.
The pandemic is just a small preview of what we can expect to happen with climate change in the coming decade.
This is sometimes done on purpose:
> The Overton Window is an approach to identifying the ideas that define the spectrum of acceptability of governmental policies. Politicians can only act within the acceptable range. Shifting the Overton Window involves proponents of policies outside the window persuading the public to expand the window. Proponents of current policies, or similar ones within the window, seek to convince people that policies outside it should be deemed unacceptable.
Security services always demand total access to communications. It requires constant democratic pushback.
USA has been doing it as long as the second war started and never stopped.
And they consider strong encryption a weapon.
Are you familiar with the Zimmermann case?
However the Netherlands is a fairly honest country when it comes to statistics, so I wouldn't be surprised that the US still came out on top, but they just didn't report most of their taps for 'national security' reasons.
But something has really changed in the past 20-30 years. Before this there was no way to literally monitor everyone. It was too labour/storage intensive. You really had to be a 'person of interest' for some kind of (usually legitimate) reason.
Whereas now in this digital age (and with everyone carrying a portable listening device in their pocket) this is totally feasible and thanks to Snowden we know it's actually being done too.
No, there's really no comparison.
A justice system, with reasonable information to infer a crime, seeking a warrant, using rules and regulations that have integrity, oversight, sanctioned by a Judge, following specific rules of access with certain, proportional criteria - is nothing like 'China'.
In fact, we are already subject to that, everywhere in Europe, just not your messaging apps.
It is not totalitarian whatsoever - there is just the risk of totalitarianism creeping in. A risk, which quite frankly is overstated. There is almost zero material harm that comes to innocent individuals as a result of these policies in states with lawful civic infrastructure. There can be, but it's rare and again, the 'problem' is more expansive and that an authoritarian takes power and uses the system for unlawful purposes.
China does not have an independent legal system, or much concern for human rights. The CCP uses these things to censor every day speech on a variety of topics - even for the most innocuous things like comparing Xi to 'Winnie the Pooh' let alone for discussing things like Tibet, Hong Kong, or Taiwan privately.
The CPP uses these controls as an 'total and complete information and thought control system' that interjects into every aspect of life. If you talk bad about Xi on your 'chat'- that will literally go on your file. It could affect your credit, promotional opportunities, how the justice system treats you etc..
They have successfully suppressed and controlled dialogue on a variety of issues - this system is frankly the CCP's most powerful means of control, far more so than anything physical like the 'police' or the 'army'.
Western governments want to use it to go after people making bombs, sex traffickers, and tax evaders. There is no chance that the German government is going to send police to your house because you said 'Angela Merkel is a clown and needs to go!' to your buddy on WeChat. There is a chance some future government could to it, for the wrong reasons, and that's cause for come concern, but it's not pragmaticaly the issue.
LMFAO imagine saying that with a straight face in 2020 when US nabs people off the street in unmarked vans, and the judicial branch is staffed by political partisans actively working withe the republican party to steal the election.
You sweet summer child.
So it’s really not a surprise that the idea of banning encryption is on the table.
So encryption as a basic human right sounds like the way to fight this.
I completely agree with the concerns raised elsewhere in this thread, but I'm not sure I see the clear link to recent events in Vienna etc claimed here.
Here[0] is an earlier document from 21 october which the article seems to take some screenshots from, so it seems that this has been coming either way.
I wonder how this effects countries like Switzerland and the UK?
[0] https://www.statewatch.org/media/1434/eu-council-draft-decla...
(I've taken the title from the new URL, btw, which uses the rather strong preposition "against"—I suppose this is a matter of interpretation since the document itself seems to fall over itself insisting on the opposite.)
Exceptional Access document: https://www.politico.eu/wp-content/uploads/2020/09/SKM_C4582...
Rev. 1 of the original document, dated November 6: https://files.orf.at/vietnam2/files/fm4/202045/783284_fh_st1...
I have this theory that with almost any great music groups there's usually one, sometimes two, great mind(s) working in the background, usually introverted, that really define the talent of the wider group (Brian Wilson, Quincy Jones, Phil Spector, etc are the rare few who got that recognition).
NYT did a great exploration of how this currently works in pop music:
https://www.nytimes.com/video/arts/music/100000005858557/wat...
This analogy is already starting to stretch a bit thin but my main point is there are always some smart people working hard in the background who don't always get enough recognition for what they do. The Aussie girl is in the NYT clip who basically made the song still lives in relative obscurity (you can find her on twitter, probably well paid, but still living without much fanfare), despite this song among others blowing up in the charts.
I am going to attempt to think of something on a personal level but it'd be great if we could organize something larger like a community backed gift/reward. At some level simply upvote internet points aren't enough thanks for the work people put into user forums like these to keep them healthy. I obviously don't have the full solution here just a seed of an idea.
Maybe something nice to do in these depressing pandemic times!
Edit: if anyone has any ideas about organizing such a thing please let me know, maybe a discord channel?
EU commission chose signal as official chat app and has been pushing E2E encryption for everybody for a long time.
A law proposal has been presented to enforce mandatory E2E encryption in 2017
https://eur-lex.europa.eu/procedure/EN/2017_3
UK particularly opposed to it.
Also Germany.
This is another proposal, and that's just what it is, a proposal, it has no other value than that.
That could be implemented by having full e2e encryption as today, but requiring clients to hand over the keys when requested by a local governing authority. The client/app would then immediately show to the user "Local Authorities have viewed a copy of this message".
Why isn't this middle ground being discussed?
I understand authorities don't want to alert their targets about an investigation, but let's be honest - if they read the messages and find you've done some crime, authorities will eventually track you down.
The fact that you might be able to see that a government read a message of yours offers little assurance that the government will not start abusing this power. After all, what possible recourse do we have after we start seeing these notifications on our messages? Certainly the government won't start telling us the exact reason they are snooping. The very fact that your conversations had been snooped on by the government might imply there is something shady about you. Where there is smoke, there's also fire, right? And this still has us relying that governments won't start pressuring clients to have special code which bypasses the notification when it is convenient for them.
No. The government must not be allowed to deny the citizen his right to have private conversations.
* https://en.wikipedia.org/wiki/Key_disclosure_law
* https://www.schneier.com/blog/archives/2007/10/uk_police_can...
* https://www.theregister.com/Print/2007/10/03/ripa-decryption...
Why should it? What problem does it solve? Certainly not the problem of terror in Vienna.
Are there some interesting candidates for such a mechanism? At first is sounds like a long shot, but there are cryptographic mechanisms achieving unintuitive results, so it may very well be possible.
that's what they need to do even today after they have found enough evidence that the court sent you what's called "notice of inquiry" and preliminary investigations start (it doesn't mean yo are guilty, it means there's gonna be an official investigation on you and after the investigation has ended they're gonna either drop the charges or go to trial).
but crime prevention usually works best when investigations are kept secret.
Imagine if in Italy we called every mob boss the police was investigating on to tell them they were tapping their phones or checking their bank accounts.
They knew it anyway, but that's where the middle ground is.
Another possibility would be, as I've written somewhere else, that a pair of keys is always created and made available to the local authorities, but they have to be authorized from a judge to use them.
The encrypted data is instead kept on the provider side, so that even if someone steals the keys, they can't access the data because it is in a separate facility, protected in the same way it is today, because it's in the best interest of the provider, that is already collecting that data, to keep it safe.
And if someone steals the data, can't decrypt it.
Metadata are also very important to investigators, I imagine that their need to decrypt the conversations comes from the fact that with the metadata they can narrow down the number of suspects to a few, but without the actual content they can't tell exactly what's going on.
> if they read the messages and find you've done some crime, authorities will eventually track you down
that's not so obvious.
I could show you a lot of cases when this has not happened, for various reasons, most of them formal (tapping lasted a few hours more than authorized, tapping was badly misreported in some other meaningless section of the conversation but it's enough to nullify it in its entirety, tapping included someone else that was not under investigation that should have been removed from the records bu it's still there, etc. etc.)
There's lot of options, we need to discuss this in depth weighing them all.
They also completely fail to address the elephant in the room: bad actors already have access to strong encryption and they don't need the blessings of Apple, Microsoft, Google, Facebook, or any organization to use it. Encryption is an idea, not a product. They cannot prevent terrorists from using strong encryption any more than they can prevent terrorists from using algebra.
Are there any comparable post-WWII Eurpopean abuses that should make citizens think twice about blanket law enforcement back-doors?
"Encryption is a necessary means of protecting fundamental rights and the digital security of governments, industry and society."
But they did reveal themselves by putting the list in order of importance, with "government" first of course.
Which makes sense - the US is gradually going Socialist and the world's other superpower is a Communist dictatorship. The world is about to be pinned between two authoritarian nightmares that presume total power over the individual.
I also think this could spawn lots of Signal-like, self hostable chat-server solutions that will be much harder to spy on. So this could be a shoot in the foot.
The few times I've called, they do have people who pick up the phone and listen to you. It's actually quite cool.
Have your story ready, and remember to be polite. (If only because a lot of MEPs really do deserve our respect.)
e.g. https://www.cnet.com/news/encryption-and-fighting-terror-hav...
This might change, but there is hope that they will continue with this position.
Since you're likely to have multiple MEP representatives from different parliamentary groups (and different national parties), it's worth getting in touch with each of your representatives by party to make your point clear. Some groups and parties will be more sympathetic than others but all will benefit from hearing this - and phone is more compelling than e-mail.
(I'm still trying to find a previous similar vote that might be enlightening on what you can expect.)
The real fight is against general purpose computing. If I control my CPU, then I can easily implement the Diffie-Hellman algorithm and communicate secretly with my friends around the world. Any ban against encryption is ineffective unless it attacks general purpose computing. We live in scary times!
“ok then let’s attack general purpose computing/your control of the cpu”
https://www.eff.org/deeplinks/2020/10/orders-top-eus-timetab...
But maybe that is just because it contains fewer German words.
Edit: the top link has now changed to the actual proposal instead of a German source. The EFF's opinion may still interest people.
How does that follow?
I am as free as anybody else in the EU to use any chat software I want.
This is just a proposal and ha no value in itself until it is approved and ratified by the single parliaments in the EU countries.
EU is not some tirannic state, or some hegemonic super power where when the president loses the elections they refuse to leave.
It's a very complex political institution, that works through official channels.
the proposal is public, there will be a discussion, years of debates, they did not hide it under the carpet, it's in the open so that anyone is aware of what it entails and can react by supporting it or opposing to it.
Nothing to be scared about.
And if the citizen of Europe through their elected members of the EU parliament will approve it, so be it.
It's the democratic process at work.
Either my data is safe from rogue agents and rogue governments or it is not. If encryption is outlawed, only outlaws will use it.
The EU can make as many logical conclusions it wants to, but reality will come back and bite their law enforcement offices that their criminals won't stop using unbreakable encryption.
The difference between theory and practice is greater in practice than it is in theory.
All that being said, obviously countries outside of the EU will continue to allow cryptography. So, unless they create a "great firewall" sensible people (including sensible criminals) will just move elswhere, possibly weakening the EU's presence in the Internet as a whole (which seems like a bad move to me).
[1] https://www.europarl.europa.eu/RegData/etudes/STUD/2020/6487... (Page 37, section 5.1 "European Cloud / European Internet")
Does anyone know what we or I can do (in this case specifically) to help fight this idiocy?
On the other hand, I'd rather not see explicit visuals of von Der Leyen and gang. The sheer horror!
Just drop them a letter or call their office (both works fine).
At this point you can drop encryption anyway, because 1000 eyes will read every message. Just WTF, and everybody said 2020 can't become more worse.
For starters, the document is a declaration "ON" encryption, not "AGAINST" it.
Also the document clarifies the intent to work with the industry to come up with solutions that strike a "balance" and not to blanket ban E2EE protocols.
What the EU decides to do if/when they conclude that there are no viable solutions will be interesting.
IMO the heated comments on this thread that have assumed bad intent is (for now) unwarranted.
Read it, it's in English and it's pretty straightforward
> technical solutions for gaining access to encrypted data must match the principles of legality, necessity and proportionality.
> Since there is no single way of achieving the set goals (read, banning or limiting encryption), governments and industry need to work together to create this balance
See https://twitter.com/iiyonite/status/1325589752431697927
Also relevant https://www.gov.uk/government/publications/international-sta...
Snowden did expose that yes indeed, NSA did share around private pictures of people within themselves and joked around.
The way Uber+Lyft made a giant stink by making everyone acknowledge how Prop22 will affect them before they could hail a ride, tech companies coukd create awareness of anti-encryption in a similar manner right ?
It's a corrupt cabal just like the United States. European citizens like to blind themselves to the atrocities by patting themselves on the back when the EU builds some renewable energy, as if it makes up for the wet work committed by EU members in the Middle East and otherwise. It's almost cult-like.
The criminals that want to stay hidden will continue to do so because you will always find open source projects that provides encryption.
Similarly in most places you already cannot be an ISP or VPN provider without following some reporting requirements. And there's no simple way for criminals to get mainstream quality networking services that don't follow regulations.
I don't agree with the ban, but I do think it would certainly hurt many classes criminals. I'd say it's generally a pretty bad strategy to oppose such policies by denying the supposed effect on criminals. All kinds of freedoms benefit some criminals.
- People following the rules would be hurt by it
- People not following the rules will continue as-is and not care
If that means you’re British: the GCHQ initiated this. Nobody is more under video surveillance than you guys. Enjoy your chat loicense.
If we left at the last minute, it's so that we can go faster. One of the things we are deliberately jettisoning is the protections afforded us by being in the EU.
By working together the President means “we hate encryption but it’s politically distasteful to ban it, so we’re going to make you ban it instead or else we’ll backdate your Irish taxes to be Belgian ones instead.”
If the liberal EU is taking a stance like this, what hope is there?!
The EU, or rather bodies in the EU, have at other times suggested making encryption mandatory. So don't fret.
Most recently when criminals went all-out in Austria with guns the police later admitted they knew the attacker was shopping for ammo. What would change if the police knew they were chit-chatting by tapping into their coms as a man-in-the-middle. Likely they would be saying after the attack they were hating the state over whatever-chat while the attacks would happen nontheless. By banning encryption nothing would change but the potential for abuse is incredible.
What we need is less legislation, that actually has some measurable positive effect. It would also help if EU was way more aggressive against countries that sponsored various terrorist groups, overthrew governments and pushed some middleeastern countries back into the dark ages.
https://www.theguardian.com/world/2018/apr/25/madrid-preside...,
https://www.theguardian.com/world/2012/dec/10/dominique-stra...
Terrorists have easy ways to talk to each other securely, using GPG and email, or even SSH for that matter. They don't need fancy apps, filters, masks, stickers and other UX candy.
General population, on the other hand, wants these things, and uses a small number of apps that government wants to control. Turns out, not just in authoritarian countries, but in a supposedly democratic EU too. It is common people who are most affected by lack of privacy, and the goal is the same that STASI / KGB had: to filter out dissidents who might pose risk to those who are currenlty at the top.
Such powers can be abused easily, and it special services will be granted such powers, they WILL be abused. So a duty of every free person is to fight such proposals and kill them outright.
However, I’m interested in at least understanding the other side. Are there any studies or estimates of the effect this might have? How many crimes would have actually been prevented by this, in the past few years? How many lives saved or child trafficking victims spared?
Of course, criminal behavior might easily change once a law like this is passed, but this would at least help give an upper bound on the benefit and my guess is it would still be very low. The world mostly continues to get safer and safer, there are still some outlier horrific crimes that happen but these might not be affected by banning encryption (such as mass shootings, which are usually a single person not coordinating with anybody).
I would just like to understand what concrete problem this solves from the lawmakers perspective.
1. creating a backdoor defeats the purpose of having encryption in the first place. it makes the creation of encryption irrelevant and pointless. a chicken and egg scenario. so it's an all or nothing kind of argument.
2. don't quantum computers make all encryption obsolete anyways? and with quantum encryption, whether or not your data gets compromised, it tells you that someone tried to, or got access to, your encrypted data.
it seems like the government already has a backdoor for all encryptions since they already have a quantum computer. so i think that this whole argument is more about setting the precedent of control over a population. gaining consensus and solidifying power. something you do when you're trying to increase your influence [which someone says the gov is always trying to do]. applying the use of force to encryption.
i think the thing for humanity to realize is that absolutes exist only in oblivion
To suggest there is a 'fair right' to data behind encryption for goverment use, to my mind, somewhat misses the point of encryption and privacy in general. This is the point I believe we should be arguing.
Your representaiton of the article as a 'declaration against encryption' somewhat undermines this argument, and polarises it into an 'us vs them' debate.
For accuracy, this document is titled:
"Draft Council Declaration on Encryption - Security through encryption and security despite encryption"
Its pretty handwavy, overly general, and seems to call for some sort of 'back door' from the tech companies. Missing the point really, anybody wishing to use strong encryption for criminal purpoes can do so so with very few resources, and quite independently.
And really how are they going to make this happen? I'm sure Whatsapp, Telegram etc will cave in. But there will always remain open-source solutions. Encryption is not a secret.
The terrorist attack is followed by an EU ban on encryption
In the EU Council of Ministers, a resolution was made ready within five days, obliging platform operators such as WhatsApp, Signal and Co to create master keys for monitoring E2E-encrypted chats and messages. Share on Facebook Share on Twitter
From Erich Moechel
The terrorist attack in Vienna is used in the EU Council of Ministers to enforce a ban on secure encryption for services such as WhatsApp, Signal and many others in the rapid-boiling process. This emerges from an internal document dated November 6th from the German Council Presidency to the delegations of the member states in the Council, which ORF.at has received.
This should now be understood under the "further steps against terrorism" that French President Emmanuel Macron wants to discuss with Federal Chancellor Sebastian Kurz (ÖVP) in a video conference at the beginning of the week. The resolution has already been agreed to such an extent that it can be passed in the video conference of the interior and justice ministers at the beginning of December without further discussion. text
<<picture: screenshot of a note from "presidency" to "delegations". Higlighted portion is "Draft Council Resolution on encryption - Security trough encryption and security despite encryption">>
On the right are the council working groups to which this text was sent, the first revised version of which was apparently ready on Friday. As is customary in the Council of Ministers, the document was classified as a "limit". As for this reason it is nowhere available to the public apart from the Council, it is made available here. [PDF]
The final trialogue negotiations on the regulation against terrorism are currently underway in Brussels. The sticking point here are the planned upload filters for relevant videos . Analogies to data retention
Macron's visit, originally planned for the beginning of next week, turned into a video conference “to fight Islamist terrorism” due to the pandemic. In addition, the EU Council President Charles Michel is due to visit Vienna on Monday, who will also hold talks with Chancellor Kurz. In addition, European Minister Karoline Edtstadler (ÖVP) welcomes the French Secretary of State for Europe, Clement Beaune, to the Federal Chancellery. Of course, it is not just about expressing condolences.
In the meantime it is becoming increasingly clear that apparently hair-raising investigative errors in the BVT made the attack possible in the first place and not a lack of digital surveillance powers. However, whether there is any such connection to the act is irrelevant. In Brussels, such an occasion has been abused for 25 years with disdainful regularity to implement surveillance projects that have long been planned. In this way, the data retention, which had been controversial in the EU for five years after the train attacks in Madrid (2004) and London by Islamists (2005), was channeled through the Council of Ministers and Parliament. text
<<picture: screenshot from the note pdf: Protecting the privacy and security of communications through encryption and at the same time upholding the possibility for competent authorities in the area of security and criminal justice to lawfully access relevant data for legitimate, clearly defined purposes infighting serious and/or organized crimes and terrorism, including in the digital world, are extremely important. Any actions taken have to balance these interests carefully.>>
The latest changes (bold and underlined) show which formulations were complained about in the text by individual member states. “Terrorism” and an inconspicuous change in the wording were added last. Instead of the usual “law enforcement” in all documents since 1995, the term “competent authorities” is now consistently used. Who is meant by this is below. Farewell without further discussion
According to the document - any final objections are requested - this resolution of the Council of Ministers is not only almost completely formulated. It has apparently already been voted on in the Council. On November 19, it is to be adopted by the Council Working Group on Cooperation in the National Security Sector (COSI), and on 25th it is planned to be presented to the Council of Permanent Representatives of the EU Member States (COREPER). There, the council resolution already has the status of an I-item, so it can pass without further discussion.
The decision will then be celebrated in a virtual meeting of the Council of Interior and Justice Ministers planned for the beginning of December. What will follow is clear, namely an order from the Council of Ministers to the EU Commission to draw up a draft regulation, which will then go through the usual procedure by Parliament and the Council. In view of the apparent unanimity, however, it would be possible in the Council of Ministers to implement the planned regulation in its core even without the involvement of Parliament. That has already been done in connection with surveillance. For example, the famous decision in the Council's Fisheries Committee of 1995 to monitor the then new GSM networks was carried through as an A-Item (decided matter), of which the EU Parliament only became aware after it came into force in 1996. text
<<picture, highlighted text it "Enable law enforcement access to content in a readable and usable format where an authorization is lawfully issues>>
This passage looks confusingly similar to the EU Council of Ministers decision, but does not come from Europe. Rather, it can be found in a resolution by the interior and justice ministers from the “Five Eyes” states, dated October 11th. In addition to Europol and various European services, the espionage alliance is one of the driving forces behind the current resolution of the Council of Ministers. Driving forces in the background
The presentation of the “moderate suggestions” by the GCHQ for duplicate keys at the end of 2018 was still met with heavy criticism
France has been promoting the action against secure encryption on platforms such as WhatsApp, originally initiated by Great Britain, throughout the year at EU level. The ground for this has been prepared since 2015 in a whole series of campaigns that were run alternately by Europol and FBI or the services of the “Five Eyes” espionage alliance and the responsible ministers. It was only at the beginning of October that the interior ministers of these five countries - Great Britain, USA, Australia, New Zealand and Canada - asked the Internet companies again to equip their IT networks with back doors for law enforcement officers.
They were seconded by their counterparts in Japan and India. Why the secret service alliance has so conspicuously worried about the unfortunate prosecutors for years is actually self-explanatory. They are the remaining “Competent Authorities” that will also be granted access. "Competent Authorities" send their regards
According to further information available from ORF.at, the monitoring method “Exceptional Access” should be selected, which is already indirectly evident from this non-technical resolution text. The one from the British “National Cyber Security Center” (NCSC) was selected from eight possible model proposals, all of which stem from technical scenarios from various secret services. The NCSC is a division of the British military intelligence service GCHQ. Platform operators such as WhatsApp, Signal and Co, who all use E2E encryption, are to be obliged to create and store additional master keys. Sketches from documents
<<picture: graph showing messages transiting on an "ESP server" before reaching the target device>>
Here a duplicate key for third parties is smuggled into the encryption process of two chat participants, it is the "Exceptional Access" method of the GCHQ. Like all other variants contained in this document, this has nothing to do with secure encryption, it is simply different types of "man-in-the-middle" attacks on secure communication. The study was carried out on behalf of the German Council Presidency and published in August by the specialist magazine Politico .
These are the “competent authorities”: GCHQ, DGSE, BND, etc. whose vacuum cleaner methods on the glass fibers bring in less and less processable data due to increasing transport encryption. In order to avert this threatening data poverty, general keys have now been requested and it looks like this will also be approved in the council. Then the BVT, which does not even manage to eliminate a terrorist who is served twice on a silver platter by two other services, will not be able to investigate in future even in chat histories for weeks.
Published on 11/08/2020
[PDF]: https://files.orf.at/vietnam2/files/fm4/202045/783284_fh_st1...
The argument is now to break open what has been until now a private comms channel in order to catch a few crooks, pedos and nutters. Guess we should all be prepared for a stronger presence of people wearing uniforms in our lives.
Please ban all speech that is not understandable by me. If you are that concerned about privacy, you can use Pig Latin.
For example, if backdoor(s) are added to all EU E2E encryption through this... then the NSA and other non-EU groups will be listening in on EU leadership's (eg Angela Merkel) private communications 24/7.
That's not a scenario the EU leadership seems like it would be ok with.
Forcing Apple/Microsoft to build in backdoors in their implementations of encryption packages might be one thing, but software developers surely have local copies of openssl, libsodium, etc, so what will this actually be able to achieve?
Conspiracy theory - wise : how about an idea that the authorities let the terrorist act to happen (as they had been warned in advance about the guy) in order to have pretext to make further push for tightening of the screws ( Belarus has just again shown the power of social media communication channels and that couldn't have been missed by the powers-to-be). I mean it is kind of curious how immediately after the terrorist act where AK-47 was used there is an attack on encryption instead of say on AK-47 sales.
The way I see it is the government/EU, whatever, needs to first force this encryption backdoor into use, then force everyone to only use chat apps with the backdoor, and finally force everybody not to go looking for this backdoor.
They are listed in order of difficulty. And they are totalitarian in their level of force.
Ah, so that's where the Covid recovery funds are going. I was wondering why small business can't access any of it, or why it's not invested in tech (well, I guess you can call this "tech) and energy. Paid for by your taxes.
Why don't we just ban crime, surely that's more effective.
For me it sounds like banning legal weapons in the expectation that all criminals are going to follow the rules.
Austia, for instance, was informed by Turkey and Slovakia about that man's IS affiliation.
https://www.reddit.com/r/syriancivilwar/comments/jqe37d/turk...
Further reading:
https://www.eff.org/deeplinks/2020/10/orders-top-eus-timetab...
https://www.euractiv.com/section/digital/news/the-story-behi...
https://www.euractiv.com/section/digital/news/german-preside...:
English: http://chng.it/8SXDQdKF German: http://chng.it/Gnr682gzr5
should read
> There is no way of achieving the set goals
It's been said many times, but you can't have your own math. Broken encryption is broken for everyone, not just the good guys.
Result: you have a message written in Tibetan. What could be more innocent than that?
Wait. Does this proposal address unintelligible communication?
"Council declaration on eating our cake and having it".
The future is more authoritarian states that don’t espouse neutrality but firmly embrace a value system and enforce it. We are seeing this already. In the US, the political battle is now between left authoritarians and right authoritarians (grudgingly dragging right-liberals/libertarians with them).
This is awful for people with liberal (left or right) sensibilities because it raises the stakes of politics. But there’s nothing we can do about it. Only authority can hold our societies together at this point.
Democracy will probably survive, but liberalism will not, except in its vestigial form. In America (unlike Europe), the government will not come for you for expressing your opinions, but it will indoctrinate your children against you and it will increasingly limit the exercise of freedom of conscience. It will not arrest you for publishing an article, but it will also not stop monopolist private platforms from censoring you, and will in fact encourage that censorship as responsible.
Wouldn't it be feasible to say, have a video streaming site hide messages it its streams and also in its control data? More sophisticated methods are of course possible. Basically "outlawing encryption means only outlaws have encryption."
The only use from any such laws is surveillance of the public at large.
It seems like there is a lot of ideological push for freedom, but as criminal activity moves to the virtual world, have we not created a problem for ourselves?
It's simple. Don't be a douche and no one will slap your face.
There's only hundreds of bad guys (maybe), but there's millions of us. Where do you think the balance should be here? Who should be stronger?
You don't and technology has nothing to with it either.
Terrorism is as old as government itself and doesn't need the internet in order to function.
Radicalisation takes place in many places and law enforcement as well as national intelligence agencies have put their focus away from good old-fashioned police work, infiltration and observation towards telecommunication.
There was no internet in 1972, yet the Munich Olympiad Massacre happened. Just take a look at a random year pre-internet: https://en.wikipedia.org/wiki/List_of_terrorist_incidents_in...
Terrorism is neither a new phenomenon nor boosted by the internet - it's our perception that has been boosted. Today, every single incident is instantly known and international news.
People just seem to have forgotten that terrorism was pretty much part of daily life in past decades, too (the German version seems to be more complete, listing terror attacks without fatalities as well: https://de.wikipedia.org/wiki/Liste_von_Terroranschlägen_im_... )
Exchange of information and coordination doesn't require encrypted internet technology at all.
In Spain, ETA declared a new ceasefire in 2010 presumably because political parties with ties to them were banned and a leading member died (of undisclosed cause).
In Germany, the left-wing terror group RAF disbanded in 1998 after key members had been arrested and the 1991 collapse of the Soviet Union, Germany reunification and the subsequent disintegration of the communist bloc basically robbed them of their ideological base, support structures and legitimisation.
The whole IRA business seemed somewhat sorted with the Good Friday Agreement in 1998, but in the aftermath of Brexit tensions seem to start to raise again.
Basically, politics, old school police work and having a close eye on organisations are much more effective than mass surveillance and technology.
You won't be able to catch every "lone wolf" - be that the right-wing extremist who starts a mass shooting or the Islamic extremist who randomly stabs people.
But you can avoid a lot of it by enforcing a zero-tolerance policy (most of the recent extremist terrorists had a criminal record), deporting criminals, shutting down organisations that support terrorism (including mosques if applicable) and drying out sources of finance.
Mass surveillance, bans, and thought crime (i.e. "hate speech", which is basically a blanket term for "I am offended" these days) are not viable solutions.
The EU politicians have completely isolated themselves from the common folk through their bureaucratical system.
I tried to convince the UK government this was a terrible idea when the Investigatory Powers Act was going through. I failed to make any difference at all to any part of it, but I did learn about Select Committees while trying to find out which MP I had to try to convince given my local MP was a powerless newbie.
1. an individual loses his power against large corporations, most importantly, GOVERNMENTS. Large structures become corrupt over time and occasionally need to be demolished partially or fully because they stop serving their purpose but start serving their self-interest. Only an individual, not groups, as ultimate indivisible units is the last resort for all values that any civilisation is built on: starting from justice, democracy etc. Thus, e-2-e encryption empowers individuals (putting aside criminals that cane be considered as a necessary evil) that doesn't make groups in power happy. So, by shifting the power from individuals to groups, the first loose an ability to use their intrinsic, built by billions of years of evolution, judgements what is good and what is now, to keep the system in check and press a red button when needed to destroy a government (like Nazi) that went out of control or a corporation.
2. Introducing these kind of anti-individualistic laws creates a bad example for already corrupted and authoritarian countries lie Russia, China and others, that would use this as an justifications to toughen already draconian laws to control their citizens. Once they do loose a good example of freedom that is meant to exist in western countries, they would become corrupted even more, causing not only troubles, but potentially military confrontations that would cost way more than those relatively small issues caused by criminals.
Even just this simple example shows that stepping aside from principles for the sake of expedience may create unforeseen consequences that left governments (because all governments in europe are large and trying to become even larger) don't want to realise because of one simple reason: they have already transformed from serving their initial idea and purpose to being self-serving.
I also don't see how they can propose with a straight face that encryption is important in securing human rights while advocating for governmental ability to break encryption.
Imagine having access to the cell phone data of scientists developing the Covid vaccine and getting inside info on their timeline to announcing a working vaccine. They then make calls or pump money into the company and make money.
This is ripe for financial abuse from governments and representatives.
we like stuff to be easy though
for thousands of years people used codes that couldn't be broken
but we got lazy
wah wah
lets break security
There is no "reasonable middle ground" in this issue. Either the encryption works, and it protects the conversation, or it doesn't and it can be broken by both state and private actors, foreign or domestic. It is not like other policies in the phisical world, where a compromise on guns, drugs etc. can be reached that maximize the social welfare. The mathematics of encryption do not allow partial privacy, you either have it, or you don't and when you do, no government can break it.
It follows that any "reasonable balance" in practice alwas means a de facto ban of encryption technology, and replacing it with a state monopoly on encryption. Thus, citizens could pe provided with simulated encryption tools, where messages are securely sent to infrastructure controlled by the government, stored, then resent securely to the intended recipient, with the state or their intermediaries controlling the privacy of the conversations. This conceptual copying need not be done for every encrypted exchange, the key issue being the existence of a backdoor that could be activated at the decision of the state.
This is undesirable for many reasons:
1. It is insecure and dangerous; once a backdoor exists, its activation must be unknowable by the citizens, otherwise it makes no sense as it would tip off the criminals. If activation of the backdoor is unknowable, then there can exist no guarantees it's only used for legitimate purposes. The backdoor would be of a mathematical and technical nature while the institutions called to regulate it would be no better than other institutions humans create: they could be corruptible, incompetent, tyrannical etc. The mathematics of encryption backdoors would serve such institutions well regardless of their dedication to the goal of providing only lawful access, and would serve any 3rd party that could abuse it. Furthermore, lawful intereption points constitute a central point of attack for a powerful adversary, even to the point of weakening national security.
2. It is essentially useless. Smart criminals use off-the-shelf technology because they know it's fit for purpose. If government snooping is implemented in all such products, then they would switch to other forms of communications that can provide them with the secrecy they require to operate. Additionally, encryption is just math, and the fundamental capability of computers that surround us is to perform math and load user-defined programs. Encryption can never be banned, just commercial products that use it. Criminals don't care about such bans and would revert to older implementations or write their own ilegal encryption tools.
3. It disempowers citizens. The ability to have private communication unperturbed by the power of the state is a fundamental freedom in a democratic country. It is a modern manifestation of a timeless pact between the governed and the rulers: government exists to protect the liberty of ruled, not protect itself. People are to be trusted because their freedom is an end in itself, and the technology of encryption is vastly liberty enhancing without being, by itself, a direct threat to anyone.
So I have spent a long time thinking about, and spoken to a lot of prominent people about, encryption and
I have come to a seemingly contrarian type conclusion that perhaps flies in the face of what HN typically says, but I hope that, instead of knee-jerk downvoting it, you think about it and let’s have a discussion based on substance.
There is a difference between using crypto primitives for signatures and zk proofs to secure everyone’s TRUST in a resilient, decentralized system, and using encryption to hide content from others.
To be honest ... I no longer think that end-to-end encryption is the right solution to human rights problems. If citizens are reduced to sneaking around and denying their activities to survive, their governmental system is way past due for fixing. This is like the “good slave owners” delaying the abolition of slavery. You’re solving the wrong problem. I believe that crypto is needed to secure decentralized byzantine fault tolerant systems like Ethereum etc. to be TRUSTED, not to hide information. Signatures, not encryption, if you will. If anything, it is the government who doesn’t want encryption to be broken (eg of copyrighted DVD content etc.) and there is an inherent contradiction since anyone who consumes unencrypted content can reshare it. What we really need is to decentralize the personal data in many places, and use zero-knowledge proofs for attestation, but that is different than encrypting and hiding information.
Should we make bulk collection of data infeasible in huge amounts? Sure. But let’s see if there are any uses of encryption — as opposed to signing and securing data - that are truly indispensable to society and are the right and best solution to solve the problem.
Within organizations, auditing and accountability are very much desired. Banning users and so on. Even though I am a libertarian, there is no simple solution to “just always have a flat system” - hierarchies always form due to efficiencies of scale (eg to gang up on people and defend against that, etc.)
What we should instead focus on, imho, is programming incentives from the beginning to promote checks and balances among the most powerful entities in the system. Look at the US Constitution and how the system has endured. Look at Bitcoin miners, Ethereum miners and so on. That is what we need - to have benign rules for everyone and make sure it’s super hard to maintain a collusion for long to overturn these rules.
Otherwise you can geek out on encryption all you want while the AI-enhanced government will track all of your physical movements and speech with cameras, gait recognition, speech recognition on vibrating potato chip bags through windows, will figure out what you’re all planning through network analysis and precrime, and nail you with parallel construction and social credit score penalties, and if anyone tries to help you they’ll get nailed too. Think it’s far fetched? China and Palantir are already doing it. Social credit systems are actually more benign, jailing and physical coersion and brainwashing are worse. Encryption won’t save the Uyghurs from re-education camps, nor profiling of Black youth in USA, nor will it help foil the next terrorist attack or mass shooting, so it doesn’t help either side of the equation that exacerbates the other in endless escalation and reprisals. And if you really don’t want those things to happen, you need to focus on architecting the governmen’t technology to be more benign in its rules, rather than facilitating sneaking around and delaying the need for the real solutions!!
Don’t listen to me only. Listen to the venerable Randall Munroe: https://xkcd.com/538/
> I no longer think that end-to-end encryption is the right solution to human rights problems
I agree with this sentiment. But I don't understand why you consider it significant. Of course, secrecy is (and always has been) a way to lessen the impact of human rights problems. But where was it suggested that it would solve human rights problems?
> But let’s see if there are any uses of encryption — as opposed to signing and securing data - that are truly indispensable to society and are the right and best solution to solve the problem.
I may be missing the point, but if I want to send a private electronic communication to someone (be it an email containing corporate secrets, a chat message discussing a sensitive topic, or a copy of my bank statements)... What do you propose instead of encrypting the communication channel?
> checks and balances among the most powerful entities in the system [...] make sure it’s super hard to maintain a collusion for long
Isn't a collusion exactly the way to break these rules founded on checks and balances?
> you need to focus on architecting the governmen’t technology to be more benign in its rules
This sounds great in principle. But - while I haven't exactly looked - I'm unaware of any government that's looking to be re-architected, or a concrete proposal for how that would look like. Can you point me to an example of at least the latter?
It's a sad world we live in.
This is (from what I understand) not about a blanket ban on encryption, but the possibility to allow wiretapping on certain E2E comms.
Also relevant is this recent decision by the ECJ https://www.cnbc.com/2020/10/06/ecj-limits-government-spying...
(Naturally this is worrying and I think the main issue with security lies on lack of border control and liberal asylum policies, but that's MHO)
It was 1 guy with a weapon that the Austrian secret service was warned about. The media made it 6 people doing a huge thing, in the end it was just 1 guy with an AK47 apparently. Austrian intelligence was warned by the Slovaks about him and they let him do regardless. Just like the 9/11 stuff, they knew what was coming and they allowed it because it suited their political agenda.
1 guy shooting around doesn't justify chat apps being monitored. This is a political setup.
We need to leave the EU ASAP.
I'd rather not. Can we fix it?
Now I feel the EU in general (some member states a lot worse than others) has backed itself into a corner because of the utterly failed integration efforts, union-wide. I live in a EU nation that has seen a very high rise in violent (and sometimes frankly horrible) crime over the past decade. As a dad of a 1-year old daughter I unfortunately find my self welcoming this proposal. The criminals are doing laps around the police because of these apps. :/
They had all the necessary information to know that guy presented a risk and they didn't act on it. What makes you think that having more information in the form of unencrypted chats would have helped the authorities?
The question on banning encryption always comes back, but so far I haven't seen any cogent argument for why it would really help the police stop crime. And, what would stop criminals from using an illegal chat app that uses encryption? Or from using their own code words? This kind of law will only reduce the rights of the innocent majority while doing very little to stop criminals.
And regardless, we trade freedoms for risk of death all the time. We would have far less crime if no one was allowed to leave their house without an ankle monitor and a body cam, but that would be a violation of people freedoms.
With that out of the way, how do you propose stopping criminals from using encrypted chat? You can make it illegal, of course, but making it impossible for someone who doesn't care about laws to install software that's available on the internet and use it to send and receive data over the internet is... difficult.
And, more importantly, why do you think that your daughter won't want the same freedoms that you had? Or should she be protected from those freedoms?
Don't get me wrong, douchebags exist. Nonetheless, however well intentioned any of this starts off, it opens the road to mass surveillance at a level that was never practical before. And that is just as a big a danger, if not bigger, than any you might see today, and I don't discount extreme religious nuts.
And of course, there's the obvious question: why would you expect a criminal to stop using encryption just because it's illegal?
B. Franklin, 1756
Yet here we are in 2020.
However: the way to get the security you want for your family is not to mess with encryption. Mess with that and everything breaks.
It would genuinely be less bad to require every display to, on command, transmit to the authorities what it is currently showing, to the than to mess with encryption.
Can you provide me one reason why we shouldn't ban sugar including all the candies?