> No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.
I mean wearing my programmer goggles it doesn't state privacy AND correspondence but OR, but still. Not having your personal conversations get intercepted is not too much to ask for, is it?
I mean I get it, if they have a reasonable suspicion they CAN intercept your communications (listening devices, intercepting the phone conversations), but this is not a right they can claim on anyone, and they shouldn't be able to force companies to allow them to listen in. Not arbitrarily anyway (see: Snowden revelations, where it was proven that the NSA just hoovers up anything and retroactively checks if there's anything wrong in there)
In other words, “encryption” needs to be listed there as a right, to remove any room for interpretation. Or explicitly listed as an example of a more general right, like the right to private speech (or whatever you want to call it).
And considering the retrieval would certainly be breaking at least a few laws, the people who are going to pull it off are going to be
- nation states
- APTs
- large criminal organizations
- large corporations (corporate espionage)
So you arguably defeat the entire purpose of having encrypted data streams. Sure, the barrier of going and "stealing the keys" is still there, but given the track record large governments have at not leaking data, it is safe to say there would be little barrier aside from legal ramifications if caught.
It’s the same basic idea as an envelope, as in you need to open it to see what’s inside. However, opening it up inherently breaks the object so if you have it unbroken then it’s obvious that nobody has done so. XRay’s being an obvious risk.
That's true, you have to rely on Sony executives to tweet them out instead. https://m.slashdot.org/story/147470
"really locked" is using a wholy misused modifier. Neither are we talking about royal priviliges, nor the distinction to virtualized fantasy. The necessary capability of encryptian is effectivity. The effectivity of regular locks is indeed a matter of concern in the security industry to begin with, as lock picking sessions at Defcon make clear. But, if the fireman's axe shreds the frontdoor, at least there will be no denying that you have been literally hacked.
Now digitally, that's not true. You can keep collecting data without anyone knowing at an unprecedented scale.
But still what? The logic is perfectly correct; ~(a | b) = (~a & ~b)
The courts may not view the police, with a warrant, wanting to see your texts because they believe you're doing something illegal as a form of 'arbitrary' interference.
This new proposal sounds nutty to me, but I think that our various constitutions provide for the possibility of government access to private stuff given legitimacy, proportionality etc.
E2e encryption that is "safe from courts" isn't protected.
They can't do that to the entire public at once because it's not economical, but that's the point.
If cell phones had e2e encryptoions so the normal court-order landline eavesdropping disappeared from law enforcements' toolboxes - there is zero chance they would ever have been allowed in the hands of the public.
But they haven't. They can physically install a listening device at the location in the warrant and thereby record any conversations you make from there. That gives them the same capability they historically had with landlines.
For every phone, you can just slip an antenna under the case (or in the phone's body) and pick up the LCD switching interference – faint though it may be – and figure out what's on the screen from there. Or, you know, CCTV.
Encryption-for-the-masses merely protects from mass surveillance; anyone protecting themselves from targeted surveillance isn't going to suffer from an encryption ban.
Also, so long as metadata is available from cell towers, you can still use the most useful piece of data: that someone's phone was at a crime scene, even if the communication itself was encrypted. That will always be the case (unfortunately also in authoritarian regimes).
Counterpoint: yes it is.
The long story is that encrypted files alone are no use to anyone, so the courts have no more right to it than anyone else. The decrypted text is a different matter. It's supposed to be protected. So you are saying, eventually, if I may interpret it that way, that speech which is protected from the authorities including the courts is not in fact protected from the courts.
Oh, ok, that's not even illogic, just paradox.
Problematicly, if you consider the abstract danger of a key cypher pair a threat, the same goes for the legislatator court partnership. The courts aren't a threat as long as there's no legislation that opens them up to it. So, clearly, the legislation is key to the infringement. This means that legislation has to act in accordance with legislation, which is as difficult to understand for regular joe as function pointer semantics in C++. So it appears to say, simply, that legislation has to act...
That's you and me. Actually though, the law is accordingly a huge tower of abstraction. The moment you try to dereference "the law" it blows up into your face, a group of skilled experts has to drop into debugging mode and, eventually, has to decide if they want to have their access limited even in debugging mode. Well, the system was designed for the hypervisor kernel to access all areas, this seems to be a problem of the virtual OS handling the capabilities for userspace incorrectly.
Bug closed: won't fix.
> Everyone has the right to respect for his private and family life, his home and his correspondence.
unfortunately it also has exemptions for anything a government could reasonably use as justification to restrict this right:
> There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others.
Imagine that some unnamed corrupt government treats your telegram messages as correspondence, but not encryption keys. It then orders Telegram to release said keys (pinky promising not to do anything nefarious with them) because they aren't considered correspondence.
It so happens that there's no point in taking out a warrant against the man-in-the-middle, because he has no access to begin with.
You'll have to get a warrant against one of the ends.
What these proposals would end up doing is to force people to weaken protocols and start spying as a man-in-the-middle, just so that they can be targeted by a warrant.
This is just a little bit silly, I feel; and doesn't really help anyone. I don't think that authorities realize that that is what they're asking for. Usually when it gets explained to them, sooner or later they relent. And then a few years later someone replaces them, and it happens all over again.
So how decides when an attempt is just? Did the British think the American revolutionaries were just in declaring independence?
- Everyone has the right to respect for his private and family life, his home and his correspondence.
- There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others.
(I'm not feeling bright enough to comment but this seems extremely relevant)
[0] https://www.equalityhumanrights.com/en/human-rights-act/arti...
Prevention of not just crime, but also disorder? The economic well-being of the country? Protection of health or morals?
I suppose it's better to pay lip service to Right to Privacy, instead of completely ignoring it altogether. But this is not a human right.
That sounds more like declaration of “human rights” by China than by EU
shakes head
It is too easy for many politicians and security agencies to think that their master keys and backdoors won't ever fall into the wrong hands, that they're careful, etc. And if you point out the problem, they'll tell you they'll be even more careful.
Think about it from a non-techie perspective. I don't think most people even understand the concept that a message that goes from sender to recipient in WhatsApp can't be decrypted by Facebook, let alone by anyone else. I don't even know if there is a common analogue-world comparison you can draw, this is an utterly new concept for people who don't understand encryption.
Privacy is a human right in Europe. I don't think it's a pipe dream to give encryption some good PR, especially when it powers the internet, keeps your payments safe, protects you from bad guys, etc.
Pushing hard on the concept that Encryption == Privacy is very important. We should not call intentionally-backdoored crypto "Encryption", but something obviously bad such as "Open-Door Fake Encryption", or whatever actually speaks to people.
Don't assume that "we" are happy about that. You might be; others are not.
Unbreakable encryption should be available to everyone, and straightforward for everyone to use, and used by default rather than only for "sensitive" information. Unbreakable encryption should be so widely used that the thought never even occurs to anyone to associate it with wrongdoing. Communication using unbreakable encryption should simply be "communication".
I don't want to suggest everyone is happy with the status quo, but it's at least not one of the top items on everyone's agenda for change.
> Unbreakable encryption should be available to everyone, and straightforward for everyone to use, and used by default rather than only for "sensitive" information. Unbreakable encryption should be so widely used that the thought never even occurs to anyone to associate it with wrongdoing. Communication using unbreakable encryption should simply be "communication".
I agree with you - but I also doubt it will happen. Not because of some government conspiracy but because I don't for a second believe that people would choose "government can't tap a criminal's phone call or text messages even with a court order" as an acceptable drawback for the benefit "my own conversations are always secure". I really don't. I'd be happy to be proven wrong though. So I simply don't think there is any democratic pressure for it.
We need to very clearly and universally make the message clear: there's unbreakable encryption, and there's broken encryption, nothing in between. Anything that purports to be in between is either broken or soon will be.
Make sure the terrorists can't find and research targets.
Make sure child molesters can't get at your kids.
Make sure bank robbers can't get at banks.
Make sure organized crime can't spy on the police and thwart police actions. Etc etc.
If anyone calls me on a regular phone call, I'm always aware of this.. It's that nasty feeling of being spied on that's really the main reason I hate this so much. The government shouldn't have any reason to spy on me but spying on everyone is simply becoming the norm because they can.
"A policeman's job is only easy in a police state." — https://en.wikiquote.org/wiki/Touch_of_Evil
> as a genuinely terrifying prospect in plenty of TV shows.
Probably for a reason:
This is a genuine question because it's a counterintuitive notion to me since I find the lack of E2E encryption scary.
It's obviously even more scary (an existential threat) to authorities that are used to be able to do mass surveillance of messages in transit (Such as the NSA).
knives are scary
Having the higher-level source code just makes it a lot easier.
But if WhatsApp did this, it would probably be noticed pretty quickly by experts. But like I said above, Whatsapp's achilles heel isn't really the E2E encryption. It's the cloud backups.
If it was open source there is some chance a backdoor would be spotted (eq. by Linux distropackage msintainers), but not when a company is pushing obfuscated binary blobs preatty much directly to users.
And of course these stores could have secret functionality for shipping targeted updates.
But if it exists, this means that 1) none of the developers working on the store backend decided to leak info about it and 2) none of the targets have had an expert look at their device to find an unusual update that wasn't seen by anyone else.
Over time, the probability of either of those things happening would be going up…
It's hard enough to explain the easy, obvious stuff like tax brackets. You think people have a native understanding of encryption?
It’s easy. Tell people they’re speaking English to one other person who also speaks English at a dinner table. No one else in the world speaks English. You can look and sound like you’re talking about how excellent the food is, but really you’re saying how terrible it is... and no one on earth will ever know, other than the one person who understands you.
- In your example, the contents can be deduced from the "encrypted" data, without the key. Indeed, there is no key, but rather a complex dictionary transformation.
- A "backdoor" is merely teaching GCHQ to speak English. Sounds perfectly reasonable in your example.
I'd argue the exact problem is that politicians have the particular understanding of encryption that you just gave.
You need to communicate two things:
1) Why backdooring safe encryption irreversibly breaks it for everybody
2) Why that's a bad thing
1. Encrypt as normal.
2. Given a language model which can generate a choice of multiple possible next-symbols given what has already been written, use bytes from the cypher text to choose between the available options.
For example, using the predictive text options on my iPhone, and treating 0=left 1=right, the cypher text 011100 and the starting symbol “Hi”, I get:
“Hi I have heard from the other”
(Note: I’m fairly sure the iPhone predictive text system is personalised and therefore time-variable, but the general idea still applies if you are in full control of the system).
3. If the other party knows the model and the initial word, they can use an equivalent process to recover the cypher text and put that into the normal decryption routine.
If the government is just going to force specific companies to add backdoors, then the process above isn't really necessary, you just need a way to install a client that isn't backdoored. If, however, the government is banning the sending of encrypted messages, then you have to hope that a jury doesn't see your long pointless messages as strong evidence of using encryption.
To improve slightly upon the language model example given above, though, I suggest something like this:
Don't legal people routinely just take few word sentences and rewrite them into long paragraphs of aforementioned hereinafter notwithstanding including but not limited to senseless nonsense?
If I started writing long paragraphs of aforementioned hereinafter notwithstanding including but not limited to senseless nonsense, I’d be really obvious — at least to a human, not sure if current AI would notice me yet.
(Of course the public existence of software that does this could definitely make that excuse less convincing.)
You’d have to be very careful to seem “normal”, as carelessly doing that can change the entropy in a detectable way even for the least significant bits — the least significant bits saved in something like JPEG is not the sensor noise, it’s the smallest stuff that humans pay attention to.
Found this related question on Crypto Stackexchange: https://crypto.stackexchange.com/questions/32767/how-to-disg...
The question of interest is "how to generate sentences that allow the most dense insertion of data?".
The best two I saw were:
* Used a copy paste (with link) of tweets / jokes / song lyrics with trite comments around them.
* Used an html formatted email with images embedded. The images were fiddled to hold the bulk of the payload and the surrounding sentences were just to describe the image to give it authenticity.
The funniest was a dirty poem generator based on an oracled (to inject the payload) monte carlo sim. It ised historic dirty letters and all sorts of poem formats.
This was at a hackathon in Hampshire (uk) ~2014
I was born and raised in a country occupied by communist invaders, so I know very well how unbelievably horrific it was to live under continuous surveillance.
Despite the many Western fiction works, either movies or novels, which attempted to describe how life was in the Eastern Europe and Soviet Union, I have not seen any that succeeded to really convey how awful that was, because it is very difficult to imagine it when you have not experienced it.
After 1990 there was a short time when things seemed to be improving in the world, about the human rights, but that did not last for long.
After 2000, the Western countries began to resemble more and more every year with the communist countries they were formerly criticizing.
This sad evolution concerns not only the continuous attempts to restrict the basic human rights but also the continuous reduction in competition in the economy, by more and more mergers and acquisitions.
Despite what some say, the socialist economies were not really different from the capitalist economies, but they were identical to the extreme form of a capitalist economy, where, in the absence of regulation, everything is produced by monopolies. Now, with the exception of few domains where there is still vigorous competition, even the American economy is so much dominated by quasi-monopolies, that it resembles more to the old Russian economy than to the American economy of 30 years ago.
Twenty years ago, when I designed some electronics hardware, I could search the Internet for the datasheets and manuals of possible components and I had many possible choices for each of them.
Now, for many key components, I have only one possible source. Moreover, for many important components that I might use, I cannot really determine whether they could be used, because their technical documentation is provided only after signing an NDA and only if you intend to buy really large quantities.
Such changes were very gradual, so for those who did not live enough to span several decades of experience, the way things are done now may seem normal, but they are not and they are definitely worse than before. Now it is far more difficult to innovate.
Regarding surveillance and encryption, most Western people, who have not yet experienced the extreme abuses towards which the current legislation slowly evolves, are very naive and they do not understand how dangerous this really is.
The irony is that now the Western countries are trying to make lawful things that not even the communists had the courage to introduce in their laws.
Even in the communist constitution that was valid when I was a child there were constitutional rights for the secrecy both of the phone conversations and of the mail messages.
Obviously, like the NSA, the secret police did not care about what is lawful and what is not, so they intercepted any mail message or phone conversation they desired, but at least there was no doubt that their activities are illegal. Fortunately, they did not have the technical abilities to intercept all the phone & mail communications, like today. Otherwise I would be still living in a communist country.
Because of my experience, no matter what abusive laws might be introduced in the future by corrupt politicians and no matter which would be the consequences, I would never recognize that any other human being has the right to command me to not encrypt any information that belongs to me. Equivalently with being against the interdiction of encryption, I would also never accept that any human being has the right to demand that I must answer to any question, if I do not want to answer.
Of course, if that question had been in the context of a legal investigation, refusing to answer some question may be considered as evidence supporting the supposition that the questioned person might have done something wrong. Therefore that person might be punished for what he/she is supposed to have been done, if being guilty is considered certain enough.
However, punishing the person just for refusing to answer a question, without any evidence strong enough that the person has committed any other crime, as it is frequent now in the USA, this is something that I consider to be an unacceptable abuse and a breach of the most basic human right.
It is doubtful that it will see something like encryption that allows speech and communication at a distance without government knowledge or control as a basic human right. After all, if some speech is so dangerous that it cannot be posted online, then we should make sure it is not spreading to who knows what kinds of people without government knowledge.
Of course it is, it's called freedom of opinion, simply some opinions are considered crimes by the EU law system.
Removing a post that incites someone to commit suicide or to kill someone can save the poster from being prosecuted.
That's it.
Private communications are excempted though, unless they need to be used in a trial after a judge authorized it.
He was 4 years old.
If you read again what I wrote it's already there: free of opinion doesn't mean that all opinions are permitted, because some of them are crimes.
Anyway, if you know Berlin you should also know that there have been a spree of neo-nazi violence lately and the police is not doing much to stop it (I lived in Berlin for a few years)
https://www.dw.com/en/berlin-police-admits-failures-over-far...