Key senators have voted for the anti-encryption EARN IT act
eff.org
eff.org
I, as a European could not be happier about this, from a economic standpoint.
Hope you guys over there are not drifting to a surveillance dystopian.
This is a long term international effort where irrelevant Western countries in the peripheries (that’s the EU) have nibbled away at encryption protections to make it easier for the US to do the same. It’s part of a two decades long effort by Western elites to correct their mistakes from the nineties - namely loosening the noose on information and privacy.
Australia, France, UK all have draconian laws that would cause outrage (or are outright unconstitutional) in the US. The only data protection the EU has is because fussy Eurocrats are annoyed that the US (and not them) get to syphon all of European’s data.
The US is really flawed, but I wouldn't move back to the EU for double my family’s income.
at least in those countries you don't have to resign for what you do in your bedroom, consensually, behind closed doors...
> The only data protection the EU has is because fussy Eurocrats are annoyed that the US (and not them) get to syphon all of European’s data.
[Citation needed]
this comes up every single time, but it's false nonetheless.
The term "eurocrats" in Europe is used in a negative way only by people who don't understand how EU works, usually from far right.
Nowadays the term Eurocrat has come to encompass staff from all EU Institutions and not only staff from the European Commission.
Although the term Eurocrat might convey negative connotations for some, specialists of European Union and its institutions Didier Georgagakakis and Jay Rowell use the concept of Eurocracy as a way to describe and analyse EU actors and professionals interactions [1]
No, you go to jail instead for offending someone. But you still have a job to pay off your court debts with (the US, thankfully, doesn’t have looser pays courts).
As to the rest of your comment, I love it. Any criticism of the EU or Brussels is far right extremism and must be ignored. Its working out great for Trudeau smearing protestors and ignoring them.
It's pretty hard to believe it.
Can you point me to some example ?
Is it what happened to you?
Are you sure it was just an offense?
In which country did it happen?
> Any criticism of the EU or Brussels is far right extremism and must be ignored
I was addressing the wording.
Far right movements in Europe use the same slogans, they are pretty easy to spot, because they are the same in any European language.
https://it.m.wikipedia.org/wiki/Apologia_del_fascismo
Austria apologia of national socialism
https://en.m.wikipedia.org/wiki/Verbotsgesetz_1947
Germany’s the same
Finland two years for tweeting a picture of the bible:
https://www.bbc.com/news/world-europe-60111140
Baltics passed similar laws for communist symbols (so no Che shirts in Vilnus!)
These are all laws against offending someone’s sensibilities. And I could go on, I haven’t even mentioned the UK!
Now, apologia of fascists and commies is unwise. But in the US it is constitutionally protected.
That's a bit of a oversimplification. What she was prosecuted (not convicted) on was definitely not a just a simple picture of the bible. Besides, that's only one of the charges. Other charges come from the times she implied homosexuality to be a genetic degeneration and later on called homosexuality a disorder.
Also, two years of jail is the maximum for that type of crime. IF she is found guilty, she will almost definitely get some relatively small fine.
It's understandable the christian folks want to paint this whole case as just "two years for tweeting a picture of a bible". But it's much more nuanced than that. Additionally the trial is still ongoing and it's very much unclear what the outcome will be. And this case is still handled in district court, I highly doubt it stays on that level. There's a lot of analysis and comments of the trials in the newspapers, but they are all in Finnish. I found this one in English that explains the case a bit better than "two years for tweeting a picture of the bible". https://yle.fi/news/3-12284380
Or maybe you did -- do you, at long last, have some sense of decency left?
Which of the 27(8) countries did you live in, as they are rather different?
And my problem isn't with Europeans, that is Englishmen, Ukrainians, Russians, or normal people in the EU. My problem is with Europes’ (note the plural, this isn't merely about the EU) institutions, the way they think, the mentality of what a person can do.
At no point in the past two years was I prohibited under the yoke of arrest of going outside. My kids never stopped going to school except for the first two months. My kids don’t have to do security theater or wear masks. No law can, or does, limit my speech. If I had the misfortune of living in a bad neighborhood the law protects my right to defend myself against an intruder.
On the whole, pick any EU country and they all failed on those accounts. Maybe Czechia or Hungary are cool on some of the above.
> I speak three European languages at native level
Way not to answer the question.
Also, BTW, you're probably wrong: Very high proficiency, maybe, but almost nobody speaks more than one language (or at the most, two) at a native level. But, sorry, I digress... To get back to the point:
Way not to answer the question.
Anyway, I didn't answer the question because what’s the point? I wouldn't live in Germany, or in Latvia, or in Spain, or in Greece for the reasons stated: restrictions on speech, blasphemy laws, anti-apologia of tyranny laws (commie or facist), laws effectively criminalizing self-defence. I also enjoy the self reliance of Americans; yes its exaggerated, but its more than Europeans anyway.
Ive flirted with Switzerland, but that’s not the EU per my original comment (I wouldn't live in CH either. Love ’em though)
Czechia and Hungary sliding sliding into authoritarianism? Please. That just not serious.
The person who just moved to a new place is very unlikely to speak ill of their new hosts or join an activist group to fight against what is a local issue. It's generally a bad idea to poop where you eat but it's unthinkable when you consider yourself still a guest in that country. The whole thing takes generations usually.
I lived in four different countries across three continents seven different times by age 15. Throughout, middle class. Leaving Europe for Canada as a teen was extremely difficult. I still love Europe the place and Europe the people.
Finally, I moved to the US from Canada - hardly polar opposites - and was reared on a diet of anti-Americanism that took ten years to shed.
I didn't dream of coming to the US, the best grad program that I got accepted to was in the US. I didn’t want to stay, I got married. I came to love the US kicking and screaming.
https://www.patrick-breyer.de/en/members-of-the-european-par...
Please, let me play you the world's smallest violin.
This trope, constantly celebrating that $CURRENT_YEAR will finally be the year of EU tech dominance over US giants, has been on repeat ever since Snowden revealed that the NSA is in bed with every major US tech company and is actively spying on EU users. And that was all the way back in 2013.
Sure, the Facebook empire is crumbling now, but since 2013, we still have no EU competitors for Google, Microsoft, Apple, AWS, etc. despite this knowledge that US tech companies have no regard for privacy and that the US government is using them to spy on us.
What if we don't want FAANGs in Europe? What if it's harder for FAANGs to develop in Europe because they can't be as aggressive and careless as american corps are?
Personally I don't want Europe to allow huge monopolistic corps to take over our economy.
Why would we want Google, the search engine that provides ads and spies on you instead of providing good results?
Why would we want Facebook/Meta, the ridicolously troubled corporation hated by pretty much everyone at this point?
Why would we want Amazon, famous for exploiting it's workforce, using old wild west methods against unions, exploiting its own sellers by copying their products and selling them for less?
Why would we want Microsoft and Apple and their cartel like attitudes, when we could have a different paradigm of software/hardware that goes to benefit everyone, instead of existing only as a competitive advantage to take over the market?
All of this companies will do anything in their power (lecit or not) to increase their market share and avoid paying taxes.
You can keep your silicon valleys and your oligocratic economy, thank you.
Then why are those US tech companies so successful in the EU with no viable local competitors, if nobody wants them?
US tech has too much money they burn it on shit. So any potential competitor is bought, you see some UK AI company pops up then Google buys it and 1 year later you read how Google made huge progress in AI. IMO EU needs to first fix the illegal US companies tax tricks, also fix the Apple software tax or apply a similar tax on closed platforms, "the closed platform tax" , this would mean less money for US SV devs to waste on shit ty stuff and more money for EU devs to try do something better.
(UK here; not quite Europe any more; not my fault or choice)
Because the USA is a large protectionist market that doesn't like EU companies doing business there?
Because USA outspends EU to become dominant?
Because even with the EU wide laws, it's still more expensive to follow every local law compared to USA vs USA states?
Could you explain this one a little more?
As Europeans we should have known better: all nations rise and fall.
If you wish to negate the facts and call me names in return, then its your issue.
The US tech industry is lightyears ahead of European counterparts because of factors other than meeting market demands for privacy.
I don't think this is going to fundamentally change anything.
me neither.
my in-laws (90+) in Japan are excited about a new DoCoMo phone and always talks about the latest features. He is not an engineer. He is also not a rare case in that country (or that continent).
My own mother back in EU and most of my family are deeply ambivalent at best, or absolutely opposing new Tech / data-driven ideas.
Europe is like the polar opposite of Asia in that sense. The US is some kind of weird middle-ground. When I returned from Asia to EU after 10 years over there I had a reverse-culture shock that lasted at least 5 years. Everything looked backward and stagnant to me. As I get older I realize I'm also becoming very critical. But age can't explain the ambivalence otherwise Japan would be the most Technology hostile society in the world.
I mean, how long until a sizeable chunk (+30%) of western tech businesses, or even other major Asian economies, start choosing Aliyun over any of the five big US cloud providers?
I think safe to say not in the next 5 years. But who knows...
that's not a local problem but a global one. Many EU countries are well on their way into dystopia. The dystopia is an unavoidable side-effect[1] of having technology and categorizing everything in systems (and systems of systems). This argument gets attacked by "BUT everything can be used for good or bad". But Technology is not neutral.
We just pretend it's neutral because we wouldn't know who to hold accountable when dealing with cause/effect in complex systems of systems (emergence). Consider the following[2]:
> In a society such as ours, it is almost impossible for a person to be responsible. A simple example: a dam has been built somewhere, and it bursts. Who is responsible for that? Geologists worked out. They examined the terrain. Engineers drew up the construction plans. Workmen constructed it. And the politicians decided that the dam had to be in that spot. Who is responsible? No one. There is never anyone responsible. Anywhere. In the whole of our technological society the work is so fragmented and broken up into small pieces that no one is responsible. But no one is free either. Everyone has his own, specific task. And that's all he has to do.
> Just consider, for example, that atrocious excuse… It was one of the most horrible things I have ever heard. The director of the Bergen-Belsen concentration camp was asked at the Nuremburg trials, “But didn’t you find it horrible? All those corpses?” He replied, “What could I do? I couldn’t process all those corpses. The capacity of the ovens was too small. It caused me many problems. I had no time to think about these people. I was too busy with the technical problem of my ovens.” That is the classic example of an irresponsible person. He carries out his technical task and isn’t interested in anything else.
[1] The Technological Society, by Jacques Ellul https://archive.org/details/JacquesEllulTheTechnologicalSoci...
[2] The Betrayal by Technology, by Jacques Ellul (1993 film), 06:51: https://youtu.be/BOCtu-rXfPk?t=411
https://en.wikipedia.org/wiki/Carnivore_%28software%29?wprov...
FWIW, I sent the email below (largely cribbed from the EFF).
Dear :
I am a constituent. I urge you to oppose the EARN IT act, S.3538. It does not strike a reasonable balance between fighting crimes and the rights of users to privacy and encryption.
The bill empowers every state or territory to create sweeping new Internet regulations, by stripping away the legal protections for websites and apps in Section 230 of the Communications Decency Act of 1996. The states will be allowed to pass whatever law they want to hold private companies liable, as long as they somehow relate their new rules to online child abuse.
The bill’s sponsors have stated that EARN IT will pressure Internet companies to do widespread scanning of user messages and photos. This scanning is incompatible with strong encryption. Consequently, the act allows states to pass laws that will punish companies when they deploy end-to-end encryption, or offer other encrypted services. This includes messaging services like WhatsApp, Signal, and iMessage, as well as web hosts like Amazon Web Services.
The sponsors have falsely claimed that the act would protect children. But abusive images are already highly illegal under federal law. Any Internet platforms that knows about child sexual abuse material being distributed or received are required to take action on it, and can be severely prosecuted if they do not.
EARN IT would lead to penalties for people and companies that use encryption. The harm done by this will fall on vulnerable people. Once we allow encryption to be compromised in order to scan for one thing, authoritarian regimes will demand the same capabilities to track information shared by activists and journalists. Another example is that people subject to domestic abuse, including children, won’t have secure channels of communication to report and reach out for trusted help.
Once again, I urge you to oppose the EARN IT act.
Thank you,
I will vote you out if you support this bill. End of story.
I wish this threat would work on Senators who don't represent purple states. Come hell or high water, my home state will re-elect the same Democrats until the day they die or retire.
Edit: Yes, we can try to vote for a different Democrat in the primary but that rarely ever succeeds, especially against a tenured incumbent. I wish there was a runoff system so the vote isn't split amongst ~6 competitors and the incumbent.
Ah, so child abuse is kind of the new interstate commerce, only for states in stead of the feds?
I really wish politicians would embrace a "we will make policies for things we can understand" motto.
I don't think they'd make many policies if that were the case
That would be progress.
https://www.congress.gov/bill/117th-congress/senate-bill/353...
I just watched some of the Senate hearing on Log4J and she seemed reasonably together on security, open source etc. I was feeling optimistic that she could become the Senatorial analogue to Judge Alsup[1]! But if she's on board with EARN IT, scratch that idea.
[1] https://www.theverge.com/2017/10/19/16503076/oracle-vs-googl...
The personal ideas and knowledge of any given politician are just a starting point for the political choices they make.
Until laws are implemented that forbid this and/or security improves to do so, it doesn't matter how good the encryption is if it's running on a fundamentally insecure device.
I'd love to use signal, but it'd be a very silent place, and have to have WhatsApp anyway. So, instead of trying to entice others, I just try to win a one small battle at a time, reducing my cross-section step by step, where I can.
Being open source is nice, but not required for privacy.
https://www.cnbc.com/2021/09/02/whatsapp-has-been-fined-267-...
I don't know why you feel this way - IME software devs are the least likely to care about privacy.
Maybe they've been so acclimatized to being online all the time, or maybe it's because they feel that they aren't at risk.
In any event, the first people to throw away their privacy has always been software developers. Just look at how many of them use Chrome, for example. Or how many of their personal projects are tied to some proprietary tooling that, as a first action, grabs their data.
Most people would trade their mother for some shiny - that's why we have laws to protect from predatory behaviour. And software devs are just people, in the end.
But yes, I think that understanding helps, and Judge Alsup, whose programming background informed a sane ruling on copyright and APIs in Oracle vs. Google, is exhibit A.
Here you go!
> Senate HSGAC Hearing on the Log4Shell Vulnerability
If this were polarized, it would mean that no senator could risk offending their base by opposing it. They wouldn't budge in the face of popular outrage.
Since it's bipartisan, it means neither party's base badly wants it to pass (which we would already suspect from our own personal experiences).
I wish that too but to be fair: what would any of us be able to make a policy for if we had to really understand the subject first? I'm afraid we'd have to elect about 1 million politicians and let any subset of them make policies about what they are experts about. This is probably what's already going on except nearly everyone in that million is not elected and is part of organizations lobbying for something.
If that were the case we’d have a lot less cockamamie gun laws.
The NIST SP 800 series publications were paid for by our tax money and outline how encryption should be used for ALL. Not to mention sets standards for all of the intricacies that come with development, implementation and validation of strong algorithms for use in commerce, medical, federal, military and even GAH personal use.
“[Use of end to end encryption] shall not serve as an independent basis for liability of a provider […]” but the fact that you did so can now be used against you in court.
The spirit of this bill is to make WhatsApp liable from the moment they become aware of specific instances of child pornography being shared on their platform, and only then after they’ve been shown to be doing nothing to take it down. If they don’t do anything after they’ve verified those specific instances then they are liable.
What’s being implied by all the senators and the journalism around this is something like “everyone knows that in general these E2E platforms carry child porn, so in general they need to turn off E2E.”
The text of the bill doesn’t seem to be talking in generalities. It’s talking about specific criminal cases involving specific instances of abuse? Or maybe it anticipates some sort of action where the government is the plaintiff?
It’s all very confusing.
> Leahy’s encryption amendment isn’t all it’s cracked up to be. There’s still skepticism among tech policy wonks and cryptographers alike over Leahy’s encryption amendment. It essentially gives providers a defense against liability, which is less strong than the a priori immunity from liability in the first place that Section 230 currently provides.
> CDT predicts that it will invite prolonged litigation over whether potential liability is “because of” the provider’s use of encryption (if so, the case is barred) or because of some other reason (if so, no bar).[3] CDT told CyberScoop that the “consistent threat of litigation … will be a strong disincentive against providing [end-to-end encryption] and continuing to have to defend that decision in court.” With potentially wide variation in state CSAM laws, “the worry,” as Techdirt says, “is that we won't know whether or not offering end-to-end encryption would be seen as violating state laws until long and costly cases go through their lengthy process.” The Internet Society’s Joe Hall agreed, telling CyberScoop that the amendment is “a fig leaf of protection for strong encryption” that leaves providers “to fight it out in court, which is far from cementing protection and clarity for encryption, the bedrock of our lives on the internet and in the real world.” I couldn’t have said it better.
> It’s not clear how many cases against providers would actually be precluded by Leahy’s amendment. Plaintiffs and state AGs could readily come up with other grounds besides encryption on which to premise liability for an encrypted service (at least as a pretext, even if encryption is really the ultimate reason they’re mad). CDT also points out that the Leahy amendment doesn’t stop the AG-headed commission from recommending anti-encryption best practices (as any commission with Bill Barr at the helm will likely do). That would’ve been a freebie for Leahy to throw in, especially with the commission’s fangs removed anyway.
https://cyberlaw.stanford.edu/blog/2020/07/earn-it-act-threa...
https://www.congress.gov/bill/117th-congress/senate-bill/3538/cosponsors
on S.3538 - EARN IT Act of 2022
I saw in part: Cosponsors: S.3538 — 117th Congress
(2021-2022)
Sponsor: Sen. Graham, Lindsey
[R-SC] | Cosponsor statistics: 19
current - includes 19 original
* = Original cosponsor
Sen. Blackburn, Marsha [R-TN]*
Sen. Blumenthal, Richard [D-CT]*
Sen. Casey, Robert P., Jr. [D-PA]*
Sen. Collins, Susan M. [R-ME]*
Sen. Cornyn, John [R-TX]*
Sen. Cortez Masto, Catherine [D-NV]*
Sen. Durbin, Richard J. [D-IL]*
Sen. Ernst, Joni [R-IA]*
Sen. Feinstein, Dianne [D-CA]*
Sen. Grassley, Chuck [R-IA]*
Sen. Hassan, Margaret Wood [D-NH]*
Sen. Hawley, Josh [R-MO]*
Sen. Hirono, Mazie K. [D-HI]*
Sen. Hyde-Smith, Cindy [R-MS]*
Sen. Kennedy, John [R-LA]*
Sen. Murkowski, Lisa [R-AK]*
Sen. Portman, Rob [R-OH]*
Sen. Warner, Mark R. [D-VA]*
Sen. Whitehouse, Sheldon [D-RI]*We might as well ban sending pictures and audio because least-significant-bit steganography is a thing.
https://www.wyden.senate.gov/news/press-releases/wyden-gilli...
But what about HTTPS certificates, would The Act have any effect on them? Would there be any legal issues with (for example) running your own Matrix server?
And what about hosting providers (instead of platforms). Would Amazon be compelled to decrypt HTTPS traffic en-mass that's routed to their machines?
I wonder why?
NSLs: https://www.eff.org/issues/national-security-letters/faq
Dragnet/Geofence warrants: https://www.nbcnews.com/news/us-news/google-tracked-his-bike... and https://www.logically.ai/articles/geofence-warrants-on-the-r...
Dragnet/Mass-surveillance keyword warrants: https://www.forbes.com/sites/thomasbrewster/2021/10/04/googl...
Dragnet/mass-scanning of online storage: https://www.forbes.com/sites/thomasbrewster/2021/12/20/googl...
PRISM: https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
RAMPART-A: https://en.wikipedia.org/wiki/RAMPART-A
Forced backdoors into "encrypted" email: https://www.theregister.com/2020/12/08/tutanota_backdoor_cou...
And who knows what else is still secret. A good rule of thumb is that if something's in the "cloud" or hosted on someone's computer that you don't directly control, you should assume that LEOs have access to it.
When all the data is centralized, you don't care about the end-point encryption. All you care about is having access to all the databases.
The USG doesn't need to (and doesn't bother to) break HTTPS for domestic LEO, because existing mechanisms are easier and approved by the courts.
No, read my comment again. Every one of the links shows a completely legal way to grab someone's data from any company. The whole point of my initial comment was to point out that legal system is so well primed against any privacy pushback that it's irrelevant what data is encrypted in transit. All the repositories and databases are just one NSL away. And NSLs are so easy to get that you don't even need to convince a judge to approve one.
From EFF: https://www.eff.org/issues/national-security-letters/faq
>By using NSLs, the FBI can directly order companies to turn over information about their customers and then gag the companies from telling anyone that they did so. Because the process is secret, and because even the companies can’t tell if specific NSLs violate the law, the process is ripe for abuse.
>A judge does not have to approve the NSL or an accompanying gag order.
>Over 300,000 NSLs have been issued in the past 10 years alone. The most NSLs issued in a single year was 56,507 in 2004. In 2013, President Obama’s Intelligence Review Group reported; that the government continues to issue an average of nearly 60 NSLs every day. By contrast, in 2000 (the year before the passage of the USA PATRIOT Act that loosened NSL standards), 8,500 NSLs were issued.
1. HTTPS relies heavily on DNS. It’s as secure as DNS is. Nuff said.
2. As has been said, there’s law enforcement can get the logs. Not hard.
3. The way the web currently works strongly encourages users to wear a “name tag.” It’s hard to take that name tag off. HTTPS doesn’t help with that.
HTTPS is very important, but has much narrower scope, and chaotic implementation, than most people realize.
It's a catch-all term for all the law enforcement people. There's now so many organizations that can get your data through warrants, and some even without warrants, so that's a convenient term to use. And especially if you're not a citizen/resident of the US since the Fourth Amendment does not apply to you. But it's not like the 4A has stopped them or slowed them down anyway.
https://en.wikipedia.org/wiki/Law_enforcement_officer#United...
Edit: "Officer."
Peer to peer or end to end encryption removes this trivially easy access, which is why they don't like it.
That would cover any use of encryption. E2EE is a term used where there is a distinction to be made between access by users at the ends of the system and some other part of the system. Originally used to cover the encrypted email case where there is a lot of "middle" in the form of email servers and a small amount of "end".
The term is often used incorrectly these days for marketing purposes. TLS could be used in an E2EE system, but it is normally not.
How is https communication not end to end encrypted? And what’s the difference between subpoenaing a server vs an end user? The server is just another person/organization.
Edit: Re-reading this I guess you mean that having a centra server acting as a middle man would probably not be end to end which I agree with. I thought you meant user <—-> server wasn’t end to end.
Generally, “end to end encryption” refers to client to client encryption, where the sever routes data but can’t read it.
It would be "NoSignal" from this Act on.
When you guys were surprised about Room 641A, Russia already had warrantless surveillance boxes mandatory for every ISP by law.
I've no clue about China, but I'd be very surprised if they're not even worse in this regard.
At a minimum, the congresspeople's aides will tally up the emails received to measure their constituents' reaction to the bill.
If you do have the time, an original email written in your own words might have a greater impact. To determine who your 2 senators and 1 representative are, use these government pages:
- Senators: https://www.senate.gov/senators/senators-contact.htm
- Representative: https://www.house.gov/representatives/find-your-representati...
Prepare a single email and alter it slightly to make it personalized for each of your 3 recipients. Use the form on the senator's or representative's official senate.gov or house.gov website to reach them, and set the category to "Communications" or "Telecommunications". (The form will block your submission if you include a URL, so don't do that.)
It may sway representatives who haven't made up their minds and want to get relected.
It probably won't change the minds of those who are already fully committed to the other position.
Your one letter won't make much difference. Many letters can sway opinion to some extent.
I also prefer to participate in the process occasionally.
How do you know?
Some don't. Looking at you Nancy Pelosi & Dianne Feinstein
Is it though? I'd like to see the science on this.
I wish we had a legislature who would recognize the importance of net neutrality to fostering competition. Instead, bills like this seem focused on ensuring monopolies so they can control how they operate.
Google, Microsoft and Apple all work with the government extensively, and they, either alone or together, hold monopoly and oligopoly positions in many markets.
The current administration is the only thing that's barely holding back Comcast, Verizon etc. from expanding their plans to expand zero-rating across broadband. Eventually there will be another Ajit Pai.
This will eventually pass.
The discussion on the EARN IT act starts around 1:42:00
Any mention of concerns over encryption are with a really incredulous, dismissive tone. I have a hard time understanding whether that's actual ignorance on the part of the Senators, or if it's some kind of theatrics that plays into the broader politics of the situation.
They also decide who works for them so no subordinate will “make them learn” and everyone perpetuates a cycle of ignorance that leads to the establishment of a dogmatic position that people trying to make things seem more complicated are wrong because I have all my own people telling me it’s not that complicated. Unless they care to be informed and ASK for it, it will never happen.
I know Hanlon's razor stands against me, but I just find the dynamics of a highly connected set of professionals in DC too conducive to passive knowledge of these issues to justify a bunch of "key senators" to be fully ignorant on these subjects. I find it way more likely that ignorance is a convenient narrative to push their agenda without accountability from the opposition.
The media playing gotcha has made it fundamentally dangerous for a politician to be publicly wrong on any topic. The reaction is to avoid engaging with complex issues.
For the convenient clicker: https://news.ycombinator.com/item?id=30298373
But I'd prefer the EU, imo.
They even brag about this in their own party-media: https://www.vorwaerts.de/artikel/innenpolitik-spd-gegen-tele...
> They even brag about this in their own party-media: https://www.vorwaerts.de/artikel/innenpolitik-spd-gegen-tele...
Nothing in this article supports that allegation.
And on the topic of encryption the new administration intents to strengthen it: https://news.ycombinator.com/item?id=29433262
They are like the people complaining about distrust in government while regularly extending surveillance of citizens.
It's a knee jerk reaction at this point, but, in all honesty, China and Russia have 3 times the internet users US has (China is also building internet infrastructures in many African countries), that can't be easily discarded.
And for many of them the "american internet" is less free, more invasive and more dangerous than their own.
Is this true? Will use of encryption be evidence of guilt if this thing passes? Incredible.
> MYTH: The EARN IT Act is simply an attempt to ban encryption. > FACT: The EARN IT Act does not target, limit, or create liability for encryption or privacy services. In fact, in order to ensure the EARN IT Act would not be misconstrued as limiting encryption, specific protections were included in the bill to explicitly state that a court should not consider offering encryption or privacy services as an independent basis for legal liability.
"Hillary Clinton, Biden, Kamala and other Deep State actors want to use the EARN IT act to read your messages and check if your kids are vaccinated. Next year, if your children haven't had 5 boosters, CPS can take them and you could face jail time! FACT!"
Anyone have MS paint and a few sockpuppet FB accounts? I'm only 20% kidding here.
Edit: forgot to fit "globalists" in there
Just need to add Bill Gates and George Soros to the list and you've got it covered.
The reason why popular E2EE messengers are such a problem for authoritarian governments/regimes is the fact that it's transparent and enabled by default. This means that millions (or sometimes billions) of people have strong privacy without having to know anything about it.
Once E2EE is removed from these messengers, those authoritarians can focus on the rest.
Edit: one thing that really confuses me about this whole war on crypto thing is why would a democratic nation want to remove privacy from people. Don't they understand that democracy is fundamentally predicated on privacy? I have a feeling that they do.
Apple, Google, Facebook cannot leave.
Telegram has never been in the US.
Well, that's their problem.
I think we will see a lot of companies founded in the next decade ready to take over such services in the EU. China already has its local companies, and the rest of the world will not be far behind.
If this bill passes, imagine a world where:
- all cloud files, activity, messages, regular over internet activity (provided by any legal company registered in US or wanting to operate in the US) etc shall be readable by the government
- this would apply to ALL countries in the world
- all companies will not be allowed to use nor support any application on their platform that has end2and encryption
- US government will heave sort of "master key" to not just US but the whole world
- end2end encryption use will be outlawed/criminal and forbidden (if you try to install any app that uses end2end encryption, this can be recorded and government can choose to bring you to court and serve you with draconian fines, regardless what you did over end2end encrypted communication)
- there will be nothing stopping any individual actor (good and bad) to use end2end encryption!
- it is impossible to enforce to stop use of end2end encryption (as nobody can control what runs on end points PC/Windows/OS/Mac/de-googled-Android/etc)
- No more VPN, Telegram, Signal, TOR/onion, emails, HTTPS? (all messaging like skype/whatsapp/snapchat/zoom/tiktok/etc in todays form), etc all will be forbidden/criminalized in today's form until changed to allow government to read it in clear form. This does not mean that there won't be still versions of TOR, VPN, HTTPs that use end2end encryption (without giving master key to the government) no there will be, it will just be criminalized and unenforceable unless government decides to not sue/press-charges to all using it (of which there will be hundreds of millions) but instead reserves right to sue/charge or worse bomb you
- centralization of such great power, by design per system threat model, makes one point of failure as total failure and history has proven that such design always fails (i.e. to translate: basically malicious actor will try and eventually succeed to hack the government central control place to take over this capability and such power in the hands of a really determined malicious actor is infinite!) == so technically/logically this is hugely stupid, not just dangerous for government malpractice (which is also historically more norm than exception)
- Internet division of the world will be forced by this! as imagine that you are some/any country (in Europe, especially China or Russia, but hey any) that just wants NOT TO be without clothes fully open to US spying, then you're left with only one choice to FULLY ISOLATE YOUR Internet (including everything, your infrastructure, your devices, your versions of operating systems, etc,..) so this would HUGELY IMPACT ALL BUSINESSES as they will suddenly not be able to sell anything outside of US (other than to allied or vasal countries)!!! (this is inevitable outcome in short period of time and in a divided world you can draw the prediction where that leads = to all worst outcomes)
PLEASE ALL UNDERSTAND THIS CORRECTLY and ACT asking your representatives TO VOTE AGAINS EARN IT
Feel free to use my description when writing to your representative, as it is more understandable to uneducated people and conveys grave dangers versus just your vote!
Government agencies have many different ways to FULLY protect the children and not to destroy the world, only if they use competent people!
Of course the wheels of the EU move slowly, and there aren't a lot of strong alternatives at present, so I don't expect this to cause a sudden crash. The decline will be slow but assured. I don't understand how the legal architects of this can be this naive. Or perhaps they just don't care.
[0] https://www.youtube.com/watch?v=HUEvRyemKSg
[1] https://github.com/jwise/28c3-doctorow/blob/master/transcrip...
So will I have to shut down my personal Nextcloud and Matrix server? Also what will happen to SSH? it's also E2EE
In addition chance of "the beast" finding a method to break any new end2end encryption is likely/tbd/time, however individuals/open-source shall be finding another new method over night :-) as I ~40 years ago on 8bit computers I made very similar algorithm to Rijndael AES and I was a kid and that was ~20 years before AES was invented!
You have to protect yourself because the government cannot and will not do it. So focusing on illegal channels is the obvious choice.
(No sideloading is so great, Apple fanboys here say, no big deal, just do your research and buy another device. )
Apple would fight this all the way to the Supreme Court. This is IMHO a clear violation of the 1st amendment.
With such a conservative Supreme Court, I doubt they would look favorably at restricting speech of a company.
Besides, Apple’s App Store is available in many countries around the world; an American iPhone user could get restricted apps from its App Stores in other countries.
I'm not so sure anymore. Apple of yore is dead. They recently announced a plan to scan local files on iPhones against a government created list of hashes. Only after immense backlash did they agree to "delay" the implementation. This had no profit motive for Apple. As a company, the move served to seriously undermine decades worth of security good will. One can only surmise that they did so in preparation for upcoming legislation like this to ensure their compliance, and continued access to said markets. Apple doesn't care about fighting moral wars. They only care about market access and continued profits. If that means removing apps and scanning phones, I think they'll do it without much fuss.
This is incorrect. Only images uploaded to iCloud would be checked if they matched against multiple CSAM databases.
From the beginning, disabling iCloud Photos disabled this feature.
They painstakingly described the algorithms and encryption behind the plan.
I will remind you that Apple could had given in to the FBI’s request to create a back door to the San Bernardino shooter’s iPhone a few years ago and Apple very publicly told them to pound sand.
Ironically Apple is now suing the company the FBI used to crack that iPhone: https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-...
This wrongful imposing of restrictions on users' freedom to run apps must be stricken down hard.
The government would argue that they aren't banning speech here; the banned apps can be restored to the app store by complying with the law.
> Besides, Apple’s App Store is available in many countries around the world; an American iPhone user could get restricted apps from its App Stores in other countries.
Not if every other country passes laws along the same lines.
Because it improves security... I hate that the loudest voices in our industry so often fail to look beyond the horizon. This is a very predictable weak point.
And mobile security is so great. Not that user data is often exfiltrated by a lot of these vetted apps at all...
On the one hand, encryption shouldnt be necessary.
On the other, much like the RIAA crackdown on mp3s over http brought us torrents and magnets, I would expect the US and UK cracking down on encryption to bring us actually secure clients.
It also stinks of them trying to legalise something they are already doing (see Snowden and the recent declassified cia docs)
Crooked forces are behind this trying to misrepresent this as ability to read all messages that will allow them to "save the children" which is just an excuse for the "foot through the door" or capability for the totalitarian rule (remember total power inevitably corrupts totally)! If we let our representatives, which do not understand this, vote for this, then we all will regret and have much much harder time to restore right for privacy. There are other both better and cheaper ways that government agencies can protect the children and destroying encryption (or criminalizing it) will not help them, since the real criminals will then use encryption only for their business and we law abiding citizens will be stripped off the ability to use it to preserve our privacy!!!
Is there a competent analysis of the bill I can read? I think this is the bill: https://www.congress.gov/bill/117th-congress/senate-bill/353... which to my untrained-in-law eyes seems to do nothing more than establish a commission that makes recommendations to service providers.
Like, don't get me wrong, I'm sure there's good reason to oppose this, I'd just like those arguments in a form that isn't a bunch of nerd-oriented rage-porn.
https://www.techdirt.com/articles/20220202/17411648407/senat...
Edit: They got other articles on the same topic, collected here:
https://news.ycombinator.com/item?id=25030085
First, my bona fides: I am a huge proponent of decentralization, empowering people and giving them control over their own data, relationships, and identity. I distrust large states and organizations and hold them to a very high standard of not harming people. I have put my money where my mouth is and reinvested nearly 90% of our company’s profits to build open source alternatives to Big Tech companies, and routiney give away our software on github. We have built probably the most useful and battle-tested open source alternatives for Web2 and Web3, in the world: https://intercoin.org/overview.pdf
Now, having said all that… as someone who designs distributed systems that reach millions of people across 95+ countries, I have had to seriously consider my responsibility in designing the systems. It would not be very difficult to circumvent whatever laws various jurisdictions have. But regardless of the laws, consider what your tech is enabling. (I wish FB and others did this, but the capitalist profit motive keeps them from doing it, they have to extract rents and distract you at dinner with notifications and get you addicted to arguing online, and suck you into virtual reality or they lose money).
OK, so now to the point
If you are relying on end-to-end encryption to protect you against state-level actors or police, you have already lost and have been reduced to sneaking around. The real solution is to work together fix your democracy and make it a more liberal democracy, with more sensible laws that allow greater freedom of actions and make the punishments fit the amount of harm it caused, with punitive multipliers that account for the probability of not getting caught.
End-to-end encryption, if you uncompromisingly apply critical thinking and call a spade a spade (which is what we should be doing as designers of distributed software) is just an abdication of any sort of governance about what to do about any speech. Freedom of speech is certainly a lofty goal, and personally I don’t think the CSAM in and of itself is the problem — rather it is the acts before and after the content. Terrorists plotting an attack for example, or any group organizing to harm people. Even financial collusion.
Forget states and think organizations. Consider that organizations find it desirable to know whether an employee was using their messaging system and giving away company secrets or plotting to harm the company. A dating site may want to know if a predator is luring women into a trap or duping elderly people into giving up their money. Sex trafficking and many other harms can be investigated.
Now what is the proper way to handle encryption? Due to dropping costs and minituarization we will soon have ubiquitous cameras and surveillance everywhere anyway (including college dorms etc. to solve allegations of rape). The recorded info should all be encrypted at the camera, and anything sent over the network must be encrypted. BUT…
There should be a process to decrypt specific minutes from specific cameras, following a process that involves a complete audit of those trying to access the footage. For example: only if a court case is brought and the video is subpoenaed can the keys be produced, by having the judge, lawyers and the tech companies come together, and only for specific times and specific cameras. In other words: the answer is watching the watchers to only access the info for the correct reasons and always ahve audit trail, rather than having no possibility of watchers in the first place and not knowing whether a rape occurred or not.
Based on this example with cameras, we can extrapolate to communication and groups. If there is suspicion of a group, our society should have the means to decrypt its messages, but ONLY via mesns that highlight WHY, and WHICH times. Certainly it should be possible to do after a crime is alleged to have been committed, and false claims of a crime would be punished too. The remaining question is rather about “precrime”, and whether we should “chill” speech of eg determined would-be criminals plotting something, rather than letting them discuss it and catching them before they commit their destructive acts. For that, there is still open discussion.
But for the rest — the EFF is wrong. We can have freedom of speech, and yet ways to have due process to investigate speech that was tighly related to crimes committed before and after it. What we should REALLY be doing is making sure our agencies (which don’t have to be top-down run by the State, they could be fulfilling yearly contracts paid by neighborhoods or cities) are using the Accountability software the software industry should standardize. The agencies serving us should be more transparent. Rather than citizens sneaking around, they should demand their government become more transparent. The tradeoff of secrets vs transparency which should be discussed is that of GOVERNMENT. 99% of the time, government secrecy harms society, why do we allow it?
To summarize about how our society SHOULD ideally function:
1. Have neighborhoods exercise consumer choice in agencies and courts, let those face market competition. The vouchers used by neighborhoods can be a single payer system by states, but neighborhoods choose to renew contracts or not.
2. Agencies should act transparently. In the case of a court case, responsible platforms should allow decryption by agencies following specific procedures and the public should always have access to the entire audit details
3. We still need https, ie encryption in transit. We still need decentralization and resiliency, so content cannot be taken down, and people’s identity and choices aren’t controlled by specific third parties.
4. Content can harm society (and be exacerbated with botnets retweeting stuff). Individuals do not have the right to unfiltered megaphones, responsible publishing platforms should require peer review (like in science, or wikipedia talk pages) before disseminating information.
The profit motive and capitalism prevent #4 and co-opt ideals like “freedom of speech” to allow pushing messages to groups and radicalizing them. It is not an accident people globally are increasingly divided and hateful politically due to the Internet.
> There should be a process to decrypt specific minutes from specific cameras, following a process that involves a complete audit of those trying to access the footage.
I see your point with this, and I don't contest that it's a conceivable technical solution (all caveats aside). But I don't want to live in the world you describe. That is, it's not a societal solution to me.
Decentralized design is the next TBD step which will follow together with defining how societies could better work with new form of decentralized direct democracies to maximize potential in each of us in a golden rule, maturely balanced way. Decentralized money will follow in new design forms too. I have lots of ideas and number of solutions to propose, but all that takes time and preferable evolution.
However, now we need to stop this evil!
Pretty sure I agree with most of your points. Especially wrt EFF.org; after all these years, I still can't figure out what they want. It'd take me a (long) while to determine if I agree with your conclusions, because this is hard hard topic.
--
I was also weened as an anarcho-libertarian. I've never forgiven the Clinton Admin for the Clipper chip. And it's been all down hill ever since.
But hot damn. There are seriously bad people in the world. How can I ignore real world evil and actual human suffering, just to maximize my own (perceived) well being?
I have friends who work on public safety policy like human trafficking. It's absolutely horrific. And I can barely acknowledge child pornography as a thing -- I mean what the actual fuck -- much less register how bad things are.
After decades of pondering this stuff, I still have no clue, no ideas on how to balance the needs of the few with the needs of the many.
However, any position which simply ignores the negative consequences of encryption technologies is not serious, and not worth further consideration.
FWIW, I've done work on both election integrity and electronic medical records. Individual privacy is precious to me, and a hill I was willing to die on.
https://www.wyden.senate.gov/news/press-releases/wyden-gilli...
EARN IT actually undermines child safety:
https://www.techdirt.com/articles/20220202/17411648407/senat...
Crooked forces are behind this trying to misrepresent this as ability to read all messages that will allow them to "save the children" which is just an excuse for the "foot through the door" or capability for the totalitarian rule (remember total power inevitably corrupts totally)! If we let our representatives, which do not understand this, vote for this, then we all will regret and have much much harder time to restore right for privacy. There are other both better and cheaper ways that government agencies can protect the children and destroying encryption (or criminalizeing it) will not help them, since the real criminals will then use encryption only for their business and we law abiding citizens will be stripped off the ability to use it to preserve our privacy!!!
I don't think people typically contact their representatives, but I figured its a good time to start. The EFF made it really easy to lookup and send a canned message to my senators. I plan to try to call the office tomorrow. I assume I'll get stopped at their secretaries, but even that might be enough to just leave an extra bump of persuasion.
Truly amazing how Chuck Schumer gets a pass in the media for being so utterly worthless.
“Since 1857, the government has been unified 47 times, 22 under Democratic control and 25 under Republican control”
Not entertaining arguments about so and so party isn’t of this or that wing.
But either way, they didn't say "Democrat" they said "left".
Government can not stop criminals to use end-to-end encryption. With this bill only regular internet users loose privacy! This is not how it is represented to Senators and instead they are offered a lie while they do not understand, so we need to act. Crooked forces are behind this!
I am Computer Security expert and urge all from point of understanding this both technically and as a value to all of US citizens!
The last thing she did that she likes to take credit for was back in the 70’s.
California changed the way its elections are run to allow to democrats to run against each other in the general election, essentially just to eliminate her.
Somehow, she keeps getting reelected.
How long until the comparisons to East Germany start? America is apparently gearing up for "If you have nothing to hide you have nothing to fear", with many seemingly agreeing with this sentiment.
Perhaps more importantly, how have major journalistic networks not written about this bill in the worst possible light? When your sources want to use encryption, which is reasonable given some stories, this exact excerpt seems likely to bite someone in the ass.
While we're on the subject, I thought I'd heard that American polititians were using Signal? What happens when using encryption becomes ammunition for a lawsuit against them? Do they simply assume they have very, very good lawyers, and it'll all shake out because they don't believe they did (are going to do) anything wrong?
It should go like this: whoever is in favour of this legislation should have no problem showing their private messages in public. Interesting how nobody presents this angle in congress.
I was originally going to ponder if it was because today's generation of journalists aren't privacy preserving, freedom of speech maximalists. While there are some that seek to limit freedoms as long as their "side" is on top, I don't think that's it.
The last five years of political discourse has worn us down. We're tired of the back and forth, constant everyday existential crises of democracy. If every day the world is falling apart, then something like this just looks like business as usual.
We're tired. Frankly we wasted energy on stupid things and lost sight of the war. And now they get to ram this horrible, freedom rotting legislation through.
The collective shout from the new generations is a resounding Yes.
Sadly it's as historically uninformed as it is privileged to believe that words do harm.
Also, Godwin's law was repealed years ago, so you may as well compare to the third reich.
I think the internet has spoiled everything. Life used to be affordable now prices are going crazy everywhere. I blame the internet. If we didn't have it then we would have less wars, less drama, and more vary in living standards so everybody can get a piece of the pie. Now there's no pie left but the crumbs and crusts which are not very tasty.
Are we drawn in bitter impasse, or is there some intervening move to which we can avail ourselves?
The best I can muster (other than amassing a Bezos fortune and simply buying every shyster for sale) is to buy every elected shyster for sale (i.e. some rough approximation of five nine's worth of elected officials). My local newspaper reported on a school bus driver who was shot in the head, for which there is a go-fund-me effort. Every such mutual aid stop-gap is an indictment of our benighted society.
Maybe Hobbes[1] had it right, but then again, waiting for a messiah is tantamount to resigning.
[1] I love most the story about him in which he entered the club in which The Elements was turned to the final page. He chortled something on the order of "bullshit" or "humbug" and turned to the prior page: and so on and so forth to the first page where he could find no quarrel. The story is surely bullshit itself, but smells none-the-less so sweet.
Instead of emphasizing that crypto should be protected by freedom of speech, they should acknowledge crypto is a dangerous munition. Therefore it’s protected by the Second Amendment.
The second amendment says the right to bear “arms” will not be abridged. Not firearms.
Shouldn’t that protect crypto?
1. There is a significantly larger body of jurisprudence dedicated to protecting freedom of expression, versus whatever you think the Second Amendment guarantees you.
2. The right to bear arms does not entitle you to specific weapons. That's why you're not allowed to own a nuclear warhead, and why strong encryption was historically on the ITAR munitions list. Arguing that cryptography is a dangerous weapon (it isn't!) is a terrible idea.
Unfortunately, with encryption (and code as speech) - has not been tested at the supreme court as much as most think. It's still an open question to an extent.
The Apple policy on your device ratting you out is abominable and anyone telling you otherwise is trying to sell you a brand.
What you deem illegal might not be the same thing Apple is told to treat as illegal. In this country or elsewhere.
You phone should not be the secret police.
The apple policy was likely about coming up with a way to enable encrypted photos on iCloud while still having some privacy preserving form of CSAM detection. Since it was only enabled when iCloud photos was enabled it was better for privacy on net than the status quo (unencrypted iCloud photos that are accessible to apple and scanned anyway).
Now we may end up with a worse outcome as a result.
The Bluetooth exposure notification design early in the pandemic was similarly privacy preserving and the average HN response was similarly stupid.
There are just some topics this forum is not a reliable source of accurate information about and this is unfortunately one of them.
This isn’t because I don’t think access to real encryption is incredibly important (I do) - I just think it’s important to get the details right. Otherwise we’ll just get dismissed on these issues for ignoring the specifics and crying wolf on everything.
This is an unsupported hypothetical about a future change Apple may have made. The only announcement they made was the client-side scanning which is at best equivalent to the status quo.
There should never be any process acting against the user's interests on a device that they own. Ever. Full stop. The only reasonable option is to do full encryption on the device without any system that allows inspection or identification of the material being encrypted. It didn't matter that vouchers enabled the decryption of the material after a threshold was hit. There would have been logic running on everyone's device acting as a snitch. At some point that functionality would be expanded and abused.
Your optimistic point of view does not align with the reality of how this kind of technical capability becomes misused over time. The ones that create these things are not the ones that control them 20 years later.
you don't own anyone else's cloud and you never will, and especially not with government intervention. while i support privacy, i also think it's like freedom of speech, in theory it sounds great but in reality you end up with nazis walking around if you don't have the ability to deter them.
data on my computer == private without a warrant and due cause. data on someone's server == as private as could be, but i don't own it so i can't demand that it be secure from all aspects, especially uploading CSAM.