The Belgian government has removed ‘backdoor requirement’ from new law
tutanota.com
tutanota.com
I am very pleased to see that the _current_ administration came to their senses and listened to reason. However, this is a fight i am afraid we will always have to fight over and over again unless right to encryption is codified in EU constitution or a similar document.
The efforts to ban encryption won't stop here.
We need actual workable ideas, not empty statements. It is frustrating that this fight doesn't end. If you have real suggestions, I'd like to hear them.
How is this supposed to work? Can't the bad guys just send each other encryped emails anyway? Or hack together some peer-to-peer messenger?
Our near-term future has both unbreakable encryption and omniscient surveillance in the hands of low-budget and non-technical people, and in a fight between the two, surveillance wins.
I don’t know where the world goes from here, but I’m confident the status quo won’t be for much longer.
Electromagnetic Eavesdropping Risks of Flat-Panel Displays
Masking.
Masking has effectively been normalized in the western world thanks to COVID. Masking is a huge win for a free society. Before COVID, it was actually illegal to hide your face in some US States and many countries [1]
Mask + sunglasses, and you should be effectively anonymous in public.
Until you start looking at things such as height + weight + gait.
1) the claim that the wearing of masks would impede law enforcement, including the passing of statues especially against masks on demonstrations
2) the claim that Muslim women wearing full religious head coverings could not be tolerated in public spaces because it was obvious that it would make it impossible to judge the mood or other psychologically important signals normally exchanged in public
None of this seems to have been true. Sure, there probably is some small validity to some aspects of those claims, but they seem to have been hugely exaggerated.
I was waiting for the anti mask crowd to challenge mask wearing in court by citing this law.
No idea if it's been amended or not. But it definitely used to be illegal to cover one's face.
I'll say our efforts are not without hope for now.
You’d likely be disappointed by the 18th century interpretation of the first amendment, for example.
Our modern understanding of rights is not wholesale received from the time that the constitution was written. The concept itself has evolved over time into what you cherish now. 200 years ago, the constitutional protections one received were far more limited than they are now.
"Everyone has the right to respect for his or her private and family life, home and communications."
On the short term a change to the treaties of the Union is not realistic, in my opinion. So I am afraid we might be stuck with having "to fight over and over again", using the above as a foundation. I guess I think of it as educating the politicians.
Fortunately the pro-privacy voices in the EU seem loud enough. For example, in this case the Belgian national privacy authority had already complained about the proposed law. And Germany seems to have adopted the right to encryption in its latest coalition agreement.
This is the crux of the issue: the so-called "pro-privacy" camp wants absolute privacy of communications.
Law enforcement and intelligence services are not against privacy, they are against systems that provide absolute privacy because these systems prevent even lawful interception.
Voice calls on your smartphone are private but may be lawfully intercepted. This is so because mobile networks are in the hands a few licensed and heavily policed operators. On the other hands, we've reached a point where it is simple to develop and publish software apps that allow anyone to communicate in a way that is impossible to intercept as far as we know.
This is not a simple issue. There is a valid concern but at the same time the potential ways to address it (e.g. backdoors, etc) are not very satisfactory.
This doesn't follow. We can require law enforcement to need a valid warrant before they can decrypt this information.
We have that requirement in the US, but if they have the capability, they use it, warrant or not.
Imagine the uproar if a person being shot and killed during a court approved raid turns out to be completely innocent. Now imagine the silence when the same person just has their private chats or nude pics decrypted and seen by investigators.
The right to a private home is the most basic right a creature is compelled to protect.
Name a LE or IS that hasn't repeatedly been caught doing surveillance for personal or political reasons and we'll talk.
In the US at least, they keep telling us that there are many cases that they thwart that they can't tell us about. However, we do see lots of "known wolf" attacks and shit-shows like Epstein.
What about the other way around? What makes you think it's not police hackers who value privacy just like us, and who strive to protect us, who requested this to politicians? That seems more likely.
IE, "we" need to walk away from a win with something more than "status quo defended." Otherwise, the situation is "hold ground until we fail."
Facebook isn't allowed to track non-Facebook users in Belgium. As a response, all Facebook pages are now behind a login wall in Belgium.
Lootboxes (random rewards in videogames) are not allowed in Belgium, games no longer provide "random" drops (EA, Valve, ...)
On the technical front, your examples are good and valid, but they seem like features that are pretty straight forward to feature flag per country. Something like disabling end-to-end encryption looks a lot more intrusive to me (without being a subject matter, feel free to correct me). Whatever WhatsApp built, they built it to enable end-to-end encryption on a global scale, to enable anyone from around the globe to send an encrypted message around the globe. Poking a hole in that seems non-trivial.
> it's probably not a bad guess that they would lose more users globally due to the bad publicity it would generate than they would lose by cutting off Belgium.
But this is what all the tech companies do in China.
I don't think its hard to "defend" complying with the Belgian government that faces a terrorist network and drug cartel problem bigger than any other 1st world country (in relative terms).
> Poking a hole in that seems non-trivial.
They operated without E2E for many years though. I doubt that non-encrypted chat is even revoked. And even if they pulled, there's many alternatives available. It's not like Belgium is worried about Meta's revenue.
With regards to E2E, I wonder how it would work when you want to chat with someone outside Belgium though. If I'm the person outside Belgium, I wouldn't want E2E to be disabled just like that. And if WhatsApp can only be used between Belgians, that's quite a hinderance.
Belgium doesn't care about Meta revenue and rightly so, but if a law would be the reason that Meta pulls the plug on Belgium, that seems like a cause for a possible serious political backlash.
For your second point, to me that's the same kind of feature work GP was talking about: Just add a little UI that says "Hey, you're speaking with someone in a country that doesn't support encryption. Your messages are unencrypted".
Also agreeing with GP, screw Meta! As a Belgian I could care less about one company when it comes to the rights and laws of my country. They can definitely make suggestions like everyone else, but they also need to follow each country's laws like everyone else.
https://blog.invisiblethings.org/2015/10/27/x86_harmful.html
You might believe there's a backdoor but unless you can prove it what do you want people to do?
That's how you hide a backdoor in open source software.
Hardly anyone cares because it is mostly schizo people who fall for these conspiracy theories.
Can you prove it? It would at least raise confidence if
* It was open source.
* It could be disabled.
* NSA hadn't requested from intel for their own undocumented way to disable ME.
"the chance there is a remotely exploitable vulnerability is minimal"
https://www.intel.com/content/www/us/en/support/articles/000...
"Hardly anyone cares because it is mostly schizo people who fall for these conspiracy theories."*
I can't appreciate the slur against people with schizophrenia. In addition to that, it feels like you would say the same about NSA spying before the Snowden revelations.
Although I do wonder, if there was a backdoor in intel processors for the law enforcement to access, would you support it?
I can't prove it. But Intel has gone on record stating there is no backdoor. People who have reverse engineered it have not stated there is a backdoor.
>* It was open source.
You could say the name thing about Windows. People and business have reasons why they want to restrict access to the source come.
>* It could be disabled.
The ME is required for your computer to properly boot. If it was disabled, then your computer wouldn't work.
>* NSA hadn't requested from intel for their own undocumented way to disable ME.
The government can be overly paranoid. Just look at the procedures they have had for disposing harddrives when simply zeroing the drive was enough.
>linked vulnerability
That vulnerability required someone to have physical access to your machine no they could attach a flasher to it. Once an attacker has physical access to your machine most people would consider this game over. That vulnerability was not remotely executable.
>In addition to that, it feels like you would say the same about NSA spying before the Snowden revelations.
I don't know enough about the Snowden revelations to answer this.
>if there was a backdoor in intel processors for the law enforcement to access, would you support it?
If access could be implemented in a secure way and it required a warrant then yes I would support it. It would be a better alternative than someone breaking down your door to physically take your computer leaving you without one for months or never being able to retrieve it.
I would suggest not using slurs and claim that people who think otherwise are schizophrenic then.
"But Intel has gone on record stating there is no backdoor"
It would not be much of a backdoor if they said otherwise.
"People who have reverse engineered it have not stated there is a backdoor."
I am curious about that. Got a link?
"The government can be overly paranoid."
No reason for civilians not to be as paranoid.
"People and business have reasons why they want to restrict access to the source come."
Obviously, one of them is hiding backdoors. Not saying that closed source software has to be backdoored, it just does not raise confidence.
"It would be a better alternative than someone breaking down your door"
Why not let the government have a master-key of every door then? Sounds like a solution in similar spirit.
"If access could be implemented in a secure way and it required a warrant"
Got any technical suggestion regarding its implementation? How would you make sure that a warrant would be required and that the private key would not leak?
I'm not sure what you expect from me. I similarly can't prove that almost every piece of hardware and software isn't backdoored, but it would be silly to think that it all is especially if you have experience designing hardware or software products.
At least the people who do talk to me about being afraid of the ME often are overly paranoid and don't have a good understanding of hardware / software. These people often think ARM's TrustZone is an equivalent to ME.
>It would not be much of a backdoor if they said otherwise.
Intel is kind of in an impossible situation then. They can't prove there is no backdoor because it wouldn't be much of a backdoor if they showed you. You have to trust Intel that they are developing a secure product. It is Intel's best interest to develop a secure product.
>I am curious about that. Got a link?
I can't link to something that doesn't exist, but there have been a few people / teams who have attempted reversing it which you can find by googling.
>No reason for civilians not to be as paranoid.
Sure people can be paranoid, but it can get in the way of them living their life.
>Why not let the government have a master-key of every door then?
This seems like a logistical nightmare, but something similar already exists for emergency purposes such as for fire fighters.
>Got any technical suggestion regarding its implementation?
People who sign warrants have a hardware device which holds their private key. If this device gets lost or stolen the key can be invalidated. The private key wouldn't leak because you can't access the key itself. The hardware device could potentially also have a rate limit like 100 machines per day to limit abuse.
We're on the back foot here, and the general public is not even aware of this.I used to think this was about technological literacy but i don't think that's the case: most people don't know what's going on, they don't necessarily care how it happens, they just need to know the end "result", which they don't.Another issue is "law language" being hard to swallow, and politicians can always wrap this language as a candy and pretend it's to : protect the children, against terrorism, or some other minuscule reason that won't justify the abuse and also logistically can't be enforced in an online medium.
The "new law" is actually an update of an existing law and it would've forced "apps" (e.g. WhatsApp) to provide the same kind of text logs on request like the telcos have been doing for call log/SMS/location.
Governments have always had warrant requirements, until they decided they didn't need them. If you want my data, get a warrant.
The US had it's own top secret database breached.. because they used a discount contractor. I choose to keep my data in higher regard.
Bulk SMS/location is also a horrible failure of justice and it harms innocent people so that a few criminals may be caught. This is backwards.
It is better that a criminal go unpunished than for a single innocent person to be harmed wrongfully by the government.
> It is better that a criminal go unpunished than for a single innocent person to be harmed wrongfully by the government.
That really depends on the number of criminals and the total harm they cause to our society versus the harm caused by the government.We've been having "liberty versus security" debates for centuries and the balance is always changing.
Our very well trained seers (who are always right) tell us that this will reduce murder by 90%.. but 1/20 people we execute will be innocent of the crime.
Do we take the bargain?
Now the question is, what would make one decide to apply whatever answer they give here, but not there? Definitely food for thought!
Reducing 193 murder victims (Belgium 2017) to 19.3 victims. Assuming there's a 1:1 victim/killer ratio, that would mean ~20 executed killers of which 1 is innocent.
So, "accidentally" killing 1 person to save 173 lives.
Your "legal decryption framework" will be abused precisely the same way - it would be laughably naive to expect anything else.