Besides that, all they will end up with is more information on how to make chocolate cookies and who is sleeping with who, it won't tell them where the next terror attack is going to take place or who will do it.
Besides that, all they will end up with is more information on how to make chocolate cookies and who is sleeping with who, it won't tell them where the next terror attack is going to take place or who will do it.
No, but I'm convinced this isn't the goal. The goal is to monitor the unrest of the people.
I absolutely don't agree it's worth sacrificing our privacy though.
In every revolution we've seen, the elites are unable to comprehend or unwilling to compromise, and in every case, the longer it drags on, the more dispossessed they eventually become. US state population trends starting in the 1840s are currently generating increasing unrest as a function of the structure of the US senate resulting in a rule by minority. As the chamber becomes increasingly unrepresentative, the ability to reform it becomes increasingly less probably due to the structure of constitutional reform.
In a more perfect world, US population geographics would be modulated by representative power. That however, is not the case. State and local governments increasingly sort voters by self-selection bias. Further entrenchment and unwillingness to compromise will be gasoline for the current tinder.
They don't want new powers, they want their old powers back. When I understood that, I enlightened.
The tools we have made are quite dangerous for this and that's one more reason why we as the techies responsible for the creation of such tools should ensure that this can never ever happen. It's also one the reasons why Phil Zimmermann is one of my personal heroes.
I'm not sure I agree but at least that isn't outright ridiculous like the 18'th century would be.
This knowledge was much leaner when compared to today, but there were less population to begin with, so that knowledge was enough.
Crowded countries like China had its social norms evolved accordingly and differently due to this population density.
Increase in the speed of communication and in overall population allowed greater dissemination in shorter time, that's it. Before, more manual methods worked well enough to get a sniff of these activities, but it doesn't work now. So, governments want their cake back.
CIA did mass surveillance on state level with Crypto AG. Russians bugged whole fleet of diplomatic IBM typewriters. Intelligence agencies listened people via central heating pipes, insiders were planted inside suspected groups... The ways were numerous, and still are. The people, society and technology is evolving. So the game.
I don't support the initiative, but that's the state of the play right now.
This might be backwards when looked from there, but this is how it looks from here.
Nope. E2E communications have buried a lot of stuff proverbially underground. The leaks are reduced. Hence, governments lost the ability to monitor as they liked. There's much more and invisible communication going on when compared to the past, and it's much more detailed and direct. Also its volume has increased exponentially.
So monitoring that stuff got way harder, and they want the easy way back.
Notice the part about where the conspiring here took place and how those conversations were discovered and revealed. Sure two people can communicate over E2E but if you want to start a movement (something that actually would matter rather than just complaining to your bestie), you need to open it up to the public which turns out also opens up the door to people spying on you.
I don't agree. They want both. They want more!
Maybe you're too young to remember a time when no one carried a GPS in their pocket, most payments were done in cash and only banks had CCTV cameras. I'd love to see states and companies take back the "powers" they had back then :)
Intelligence is an old craft. Insiders are old as well. However, speed of life and increase in population coupled with new communication methods invalidate these old methods.
To protect their status quo, governments want their so-called vision back, and then some...
The reason why plots get uncovered is usually because someone is stupid, not because of some exceedingly clever bit of code breaking. And let's be thankful for the fact that terrorism wouldn't work if all they were aiming for is mass death of their foes because for all of the fear that terrorists manage to sow they are cumulatively less effective over the course of 40 years than three days worth of COVID deaths,
What will happen tomorrow?
But terrorist suspect 'A' communicating with arms supplier 'B' is far more significant than terrorist suspect 'A' communicating with arms supplier 'B' asking 'B' to bring some potatoes tomorrow.
The value can definitely be in the payload, when both parties believe they are using a secure channel, see 'Encrochat' and a couple of others like it. But most of the time the things you should really worry about are going to look like 'bring me some potatoes'.
Boots on the ground, enough people to follow up on the leads available today would help a lot, and a budget to go with it to make that sustainable. Not more tech toys.
Anyway, I've written enough about this subject by now.
Were there no “intelligence boots on the ground” in the places I have mentioned?
It's the human intelligence gathering where these groups are deficient, but that doesn't scale, so just like the start-up investors the governments believe that they will be able to do this on the cheap by widening the net. But that won't work, it just means they'll catch a ton more krill, and very few extra fish.
The rest of it is likely the "ability to just pull up data on anyone at any time just cause".
The old school, "we know where you live, what you said to your husband, and that you had marmalade jam with your toast this morning" spy insider knowledge gambit is a strong manipulation tactic whenever you need to convince someone to "just comply".
Having inside knowledge of mundane things that are assumed to be private hold a lot more sway than you'd think. It can make threatening ordinary people a lot easier. Do governments do this often? Probably not, but when they want to interrogate someone, I can almost guarantee they like to be able to pull up everything private they can as leverage in an interrogation.
Is this useful for national security? Probably not, but since when do governments actually care about national security when they can roll around on a power trip and feel big and godly?
Source (german):
https://www.bussgeldkatalog.org/news/wespe-toeten-droht-ein-...
And who knows, maybe you would become a political figure or something of that caliber down the road. You just never know. Don't assume you don't need as much privacy as possible.
By you, I'm speaking in general.
pitchforks coming near.
Need to hold on to power,
hide secret contracts and manipulation,
threaten incarceration,
to anyone daring to question,
their legitimation.
Control is their only salvation.
and 99.x% of people aren't engaging in sharing child porn anyway, it's the 0.1% of motivated criminals that will share encrypted files anyway, no matter what the law is. They will find ways around the law, they always do.
This is a thinly veiled excuse to take basic human rights away from people.
That's absolutely not true. Sure, some stretches are just to generate revenue, but that you're not allowed to go 200km/h through a city is not for revenue generation. It's also not given by common sense - the fact that you need to set the limit 20 lower than what's save should be plenty of evidence.
Speeding is tied to one third of traffic fatalities the last 20 years (https://www.nhtsa.gov/risky-driving/speeding), so of course speed limits are put in place in an attempt to increase safety on the road. There are plenty of arguments to be made about the best way to enforce speed limits, or ways to discourage aggressive driving (such as speeding), but there is little doubt that speeding is dangerous.
Countries such as Germany have much lower traffic fatalities than the USA but they can operate vehicles at much higher speeds. Speed isn't the problem... uneducated drivers, poor vehicle maintenance, poor road quality, etc are the problem. But all those things would upset the masses who think they are entitled to operate a vehicle for 50 years after 2 months of training and a 15 minute test, so (in the USA) we get the lowest common denominator and roadways that are engineered to handle vehicles at 80+MPH are stuck with 55MPH speed limits.
Speed isn't the problem, neither are any of the others you mentioned. They all add to the problem of traffic fatalities though.
They did a study in Germany and were able to halve traffic fatalities by adding a speed limit of 130kph on one Autobahn section, measured over 3 years.[1]
Sure you can improve road conditions and driver education, but a multi-pronged approach including speed limits is sensible.
[1] https://www.spiegel.de/auto/aktuell/tempolimit-mit-130-km-h-...
And regarding internet privacy and secure communications, that's exactly what they want: for privacy to be associated (in the mind of the average citizen) with organized crime, terrorism and pedophilia.
In a nutshell, and in case it didn't register with you when it should have: attempts to curb cryptography have been made in the past. The phrase 'you can't outlaw math' is a simple observation: strong cryptography will be available to everybody that wants it regardless of its legal status. So a government that would love to read your mail would do better to realize that they will only be able to read the uninteresting mail and for the rest of it they'll be staring at white noise. Meanwhile the baddies, alerted to the fact that the government is able to read your mail will either resort to other methods of communications or will use channels that they assume to be overt to signal covertly using other methods. There are plenty of examples for this.
So, in conclusion, no matter how much you want to outlaw strong cryptography, those that want it will have it, better plan accordingly or all you will do is waste more time reading data that you will find stupendously boring.
'Oh that, that's just white noise.'
'You are under arrest for illegal encription with the intent to <insert horrible criminal activity here>.'
This is the crux of your argument, but it's false. E2EE has been available for decades but it wasn't used widely, by everyone including criminals, until it was pushed as the default.
It's not as if all of the old volume of mail was steamed open and read or everybody's TV equipped with monitoring equipment. Even libraries did not track who read what (though they did track who borrowed what).
Because the thing is, making encryption software is hard. I doubt there will be convenient and easy to install software out there if you ban this stuff. And the majority of people won't use it if it isn't convenient and easy to install.
We've already seen plenty of examples of that irl.
Unfortunately, our beloved decisionmakers are gerontocratic, completely incompetent and bought out by corporate interests that also don't want encryption (e.g. copyright industry).
I'm sympathetic to that argument, but it seems to be employed very selectively by the tech industry.
We already rely on many backdoors of exactly that kind in form of mandatory auto updates. Not only is this seen as perfectly fine, it's widely regarded as a security best practice.
Why can Apple or Google or Microsoft manage to keep their signature keys secure for decades while any keys managed by a government agency would leak with mathematical certainty?
Also: who is to say that Apple, Google or Microsoft manage to keep their keys secret? Not all thieves would be stupid enough to tell, and nationstates tend to hold such advantages on ice until they have a good enough reason to use them.
At worst the entire industry in that region is broken more often than they are functional. It's also notable that companies existing in this state of brokenness would be competing with companies living in a functional world. One might find that the defective universe continues long enough its inhabitants are extinct.
And as some lower-hanging fruit: The repos of common programming languages and things like Docker Hub.
Python PIP, NodeJS NPM, Ruby Gems, we pull in a lot of stuff from people we don't even know. Every python project installs a gazillion of stuff from its requirements.txt. At least the OS updates come from a party we at least chose to do business with.
And it's not like this is not yet happening already. But I think it'll take a major Wannacry event before we'll stop doing this because it's just so damn handy.
But if you think of it, imagine you're coding and some random 'willywonka2586' on a public slack group says "Hey I wrote a handy library for that, here, go and install it and use it in a project for your customers!". This is kinda what we're doing.
Was it a Microsoft dependency?
It's not "perfectly fine"; but the alternative is millions of computers with known security vulnerabilities exploitable by anyone, which is far far worse than a potential backdoor used by large companies or governments.
At the very least, this would need some quantification of risk: Probability and impact of keys getting leaked vs probability and impact of not installing a backdoor.
Yes, of course.
And in the case of autoupdates:
1. the risk of finding a RCE in any random PC within the next few years is close to 100%
2. an unpatched RCE is strictly worse than a backdoor
3. how many computers won't be patched without forced autoupdates?
In the case of e2ee, I'm afraid it's much harder to quantify, though.
That X makes things worse for people in general just isn't strong evidence that governments will not do X. If you don't want X then you need to explicitly push back.
This is an impossible task. There is no way they will be able to enforce this. It would literally require them to stick their dirty fingers into every piece of software built in the EU.
They can attack large corporations like ISPs and such and force them to do certain things, sure, but there is no way they can "ban" any kind of encryption with any real success, because, as the OC said, it's basically trying to outlaw mathematics. Forcing ISPs to perform deep packet inspection or whatever won't change the axioms of mathematics or fundamentally alter computer science so that they can suddenly break encrypted data coming from their clients.
Of course, the argument is that this is to combat criminals and we all know that it doesn't work that way, but it doesn't matter at the end of the day if the true goal is to just monitor people.
You are not interested in just "people". You are interested in very specific subgroup of those (1-x)% that already operate outside the law.
And another fact is that these bans can even give you access to the people outside of the law. Practical example, Australia's sting operation of pushing their own 'secure' app on the blackmarket to lure criminals in. (https://www.washingtonpost.com/world/2021/06/08/fbi-app-arre...)
Now that math, logic and reason are outlawed, soon I expect ethics and metaphysics to also be outlawed. Of course these fundamental ideas still exist, but if you use them they’ll throw the book at you!
A nonsensical book full of gobbledegook.
It's about control of dissent, about data mining, about preventing unrest. We have seen tiny glimpses of what can happen with France's Yellow Vests... and there is massive potential for unrest: socio-economic differences (wealth disparities), prices of must-have goods (energy, food, housing), corruption in all its forms, political ineptitude and incompetence, discrimination issues, climate protection measures (Yellow Vests) or the lack thereof (Extinction Rebellion), and sadly also measures to fight the coronavirus pandemic (e.g. the current riots in the Netherlands and Belgium, the near-storming of the German parliament).
Don't be fooled that it won't work. It works in China and they have math there too.
The only thing China will succeed in is extending the gerontocracy for a little bit longer. But eventually the cost of strongly encrypted communications will drop to zero and then the information advantage that the government has is over.
Think 'Starlink' + a couple of rounds of tech improvement and the GFOC might as well not exist. The question is will the people care? In China, I'm not so sure. In the West, maybe they will, maybe they won't, but I for one will be happy to utterly ignore this if it ever makes it into law. Right now I don't bother encrypting my mail, but if this happens I might drop off the grid entirely, and I'll make it my mission to spread strong crypto as far and as wide as I can.
But for now it's just a misguided proposal by a clueless bunch of bureaucrats.
In this case, it's simply a matter of crafting the law in such a way that, say, possession or use of strong encryption without government backdoors automatically makes you a terrorist, the same way that possessing lockpicking tools automatically makes you a thief in Illinois. Then, once your communications become a little too random, the authorities can raid your computer and that of everyone you're connected with, arrest you and take you to a black site, and squeeze you for information (including rubber-hose cryptanalysis). And they're bound to find something juicy because most of the people going to the trouble of illegally using unbackdoored crypto are indeed terrorists, pedophiles, and other criminals. Using the "once X is outlawed, only outlaws will use X" effect to good effect.
I'm sure some people have been arrested and prosecuted but that's just symbolic scapegoat tactics and a pebble trying to stop the tide.
The laws you are describing are never going to be put into effect. It's just not going to happen. I don't believe the EU is full of people stupid enough to let it happen.. and even if it did, all the member states don't just automatically adopt and enforce every law immediately without thought. There are plenty of reasonable member states that just wouldn't accept these insane laws, or have populations which wouldn't accept them.
I think that’s wishful thinking, given the previous experience of Clipper chip and 40-bit encryption rules in the USA and the Investigatory Powers Act in the UK.
Even as a British national living in Berlin, when I submit an app to Apple I have to agree to let the US government know about any use of cryptography by the app (by my reading including HTTPS, which is hope is merely legal caution rather than actual obligation).