Every time governments start scaring people about pedo-terrorists behind every corner and start demanding censorship/mass surveillance/back doors, the standard response from fellow people in tech fields seems to be "this doesn't concern me, I will just do $CIRCUMVENTION".
It utterly misses the point. The issue here isn't a technical one. If a law is proposed that you can see as morally, ethically flawed and outright dangerous to society, the response definitely shouldn't be to laugh it off and pretend it doesn't concern you.
Especially when we are the experts who are best equipped to argue against it.
But I think that could lead to better encryption software with plausible deniability like Veracrypt has
The average HNer won't be that affected but the general public will. Access to encryption will be greatly reduced and most people won't even care or notice.
So, back to steganography, then?
https://en.wikipedia.org/wiki/Key_disclosure_law
Generally it goes like this
1) you get a notice either from a judge or the police to provide unspecified assistance with an investigation (you are not told even 5 minutes in advance WHAT assistance, and there is a default gag order: if you inform a customer or ... that you handed over their info, you go to jail)
2) if you refuse to do something they charge you with a crime, not providing encryption keys is such a crime
3) look like EU "average" sentence is 2 to 5 years prison, plus 50k euros
One time pads are obviously encrypted, meaning if you see one you know they're a key to something, so if you refuse to decrypt what is encrypted with them (or can't, let's not pretend these people know or care about what is and isn't possible beyond obvious cases like whatsapp), and a police officer cares, you may very well have a choice: decode or face 2 years prison. JUST for not giving a police officer full access, for example, to your phone, nothing else.
Not obviously - you could have a 1GB blob of encrypted data, or a 1GB blob of random numbers, so there is plausible deniability.
You're right that they're vulnerable to a rubber hose attack, but it's not a slam dunk case in court.
Specifically on the issue of plausible deniability, though, you probably don't want just a 1 GB blob of random-looking data, you want a file system with various levels of "secret compartments" which open up depending on which key you use to open it.
The game theory is that this prevents the attack you describe (and after which Assange named this countermeasure) because you could never prove to your torturers that you have given them the last key, and thus you would have no reason to comply.
wrt a 'rubber hose attack' I'm really talking about general coercion, not actual torture. A court could jail you for contempt you until you produce the information it's demanding.
That works for encrypted drives and whatnot but it doesn't look especially applicable for any real-time communication.
"Ten camels drink from the water at $some oasis".
Meaning:
"Attack $city at 10 AM tomorrow"
Or
"Meet at $place at 10 tomorrow".
This has been documented extensively. All was perfectly legible by whoever can read conversations on facebook, but the meaning is lost.
PGP is, as before, a technical counterargument to this sort of oppression. Perhaps the powers that be need to be again reminded of its existence. After all, the proposal is to backdoor all encryption software. That is simply impossible.
It's a bit of a beast.
https://spectrum.ieee.org/tech-talk/computing/networks/pigeo...
Replace the drugs with a warrant and the wrench with the threat of criminal punishment and expense of lawyer and court fees.
The ultimate solution against government stupidity like this is a full mesh based “internet” that is based on connections between homes without using an ISP. It is not going to happen for obvious reasons (90% of population is non-technical for starting).
Completely agree. Communications infrastructure has always been centralized. Service providers are easy targets for governments. We'll never be free from their tyranny until we have completely decentralized networks.
I think the parent comment was going to mail such drives, and good luck getting the EU to agree on blocking anything on their independent providers level.
I live in the UK this is not correct, these are voluntary agreements by ISP's and you can opt out of the default filtering.
I think the only time something has been blocked here it was due to a Court Order: https://www.virginmedia.com/help/list-of-court-orders
EU can’t stop GPG encrypted messages at the service provider level because the content looks like any other base64 traffic or can easily be made like that.
Edit: I'm not suggesting PGP itself is bad because of this. There are many other reasons why you should consider other methods of sending messages securely that aren't email or PGP.
The content type is done now for convenience, but there’s nothing stopping me from using GPG to generate a message and send it with the content type of a text file or zip or whatnot.
Of course there are other methods, but GPG is free, stable and works as expected.