WhatsApp would not remove end-to-end encryption for UK law, says chief
theguardian.com
theguardian.com
Now everyone wanting to make a communications app (or anything implementing that functionality) is risking an expensive lawsuit on the UK. Meta too, but they have the bucks and influence to weather it.
I was talking about smaller messaging apps that can't just refuse to comply.
Not because FB as platform in particular but because I appreciate someone with weight telling the UK law makers that their insane ideas are insane.
Just the fact that there is a different position suggests that there is a question to be answered and thought about. Get everyone stop and think.
It wasn't long since there was a discussion where some people were arguing that they can't make moral judgements because disobeying the law would put them in a very difficult situation:
With E2EE, they can legally skirt such demands since they can claim they don't have the data so that's a win for them as well.
Wow. I wonder if it got to that point if Meta would change course and disable end to end encryption for UK users and people messaging UK users, if that would be sufficient to comply. If this lobbying causes the UK to change course, I wonder what impact that would have on other countries’ attempts to weaken encryption, if any other such attempts are happening.
I don't know this is a fight the UK government can win. Does anyone else remember that the American government tried to ban encryption (back in the 90's I think it was)? They eventually had to give up because people just downloaded encryption products from the internet and used them anyway.
2) I'm not making any claims about it being desirable or effective, I'm just explaining what 'exiting the UK' means or what they'd be required to do. The crown won't sue a foreign company because a citizen found a way to workaround it not being available here - that would be like criticising the manufactuter of an illegally dangerous electrical item only rated for and sold in 110V markets that someone imported.
I think it's more of a "don't want to know" than anything, in which case it's their own problem IMO.
Recall that in the US there is no explicit right to privacy. You might be able to make a 1A argument that manually encrypting a message is itself a speech act, but the government could theoretically ban the distribution tools like Signal and argue they have the authority under the commerce clause, which stands on a equal Constitutional footing to the 1A.
I don't think this is likely, but I could easily see it being offered as the justification to honor a UK ban.
https://www.theregister.com/1999/01/15/france_to_end_severe_...
Such rules are not unusual for physical objects - why sell your enemies or even potential enemies the rope they will hang you with? But for encryption it doesn't make sense because it's just information, and unlike physical objects, after writing is invented humans can trivially reproduce information, so too bad.
Eventually they whittled the "export license" step to something like a form letter Fax and IIRC Mozilla had a process where you raised a Bugzilla ticket, that caused the appropriate fax to be filled out and sent, so that was part of the release process, making it as painless as possible to comply with the stupid law.
(And now it's gone altogether)
And then came the Clipper Chip...
WhatsApp can pretty clearly know if a user of the app is in the UK based on their account’s phone number country code and GeoIP. So if they wanted to comply by pulling out of the UK completely they’d probably have to make some attempt to disable WhatsApp messages for those users they’re reasonably expected to know with some confidence are located in the UK.
But as others have said, this all just seems like posturing that’s unlikely to become law.
It comes down to jurisdiction. If you don't have it on the default marketplace for the region, and don't have a physical business presence in the region, it can be argued, you've done enough and aren't subject to the jurisdiction and are not doing business there.
That users may bypass and side-load your application is immaterial. If a user in the UK uses a US based VPN, they can also still use the app even if you added IP blocking, and IP blocking in and of itself is less than perfect often subject to false positive/negatives, and best to be avoided.
P.S. I'm always shocked how people suggest "just use Signal" or something, it's really not up to me what to pick what to use at all, but up to the people I'm trying to connect with. It seems like a very difficult concept for the "just use Signal" crowd to grasp.
Switching costs are free.
They will strike the law down a day after WhatsApp stops working in UK.
2 days after there will be massive public outrage since everybody uses WhatsApp in UK.
It's an empty threat, just like the internet porn law.
They simply don't have the clout to push around enormous American companies. It's a tiny country. If the EU or US were proposing such a law, you should take it seriously, but this is just a joke.
It's very transparent but also standard operating procedure for the current UK government.
> If the EU or US were proposing such a law, you should take it seriously
Judging from a few quick searches, there are more Facebook employees in the UK than in Ireland which is their main base of EU operations. They also have a presence in Switzerland (also not EU). FB apparently have some employees in Germany to comply with local hate speech laws, do marketing and HR work, but it doesn't seem like anything they'd miss much if they had to exit especially as they're laying people off anyway.
Now that said, I think Meta can win against the UK govt if they want to duke it out but the idea that the UK is a "tiny country" vs the EU is not reflective of Meta's actual exposure. The EU is not a particularly attractive place for tech firms to hire.
They would drop the UK in a heartbeat.
They also know this happening would topple the government in the UK.
So it will never occur if they threaten it.
Let's not get carried away. There are other apps with equal parity. Most people in SE Asia use Line perfectly well. There's also Signal and Telegram
Regardless of employee count in the UK office, it's only 2% of the market. I have no doubt about the choice I'd make if were faced with the same choice: especially since companies already have plans to decrease headcount.
The US routinely use similar bully techniques against their partners (in Iran for instance, pour EU comptines asked the EU commission for help but ultimately we retracted from Iran as asked by the US). They are powerful enough to do that, we (countries in the EU) are not.
I think had WhatsApp not added E2EE in 2014, Encryption wouldn't be that wide spread today.
https://www.forbes.com/sites/enriquedans/2021/05/07/how-sign...
> Signal’s idea was to get users to abandon WhatsApp and switch to Signal, an instant messaging service run by a non-profit foundation, which has proven its commitment to protecting the privacy of its users and that is seeing significant take up, especially after the latest changes to WhatsApp’s privacy policies.
This whole ordeal was doubly-dishonest, as not only were they running ads against one product line (Instagram) with the specific goal of getting people to switch away from a different one (WhatsApp), but the entire thing was just FUD designed to attack Facebook for going out of their way to build something that actually did honor end-to-end encrypted goals: companies wanted to be able to do Facebook Messenger -like company-to-user chat stuff, and so Facebook wanted to provide a way--specifically for companies--to use a portal to access a "hosted" WhatsApp client.
But like, that would mean that Facebook would, for just these specific chats with business accounts, potentially (if the company was using this service) be able to read those messages, so they had to adjust their privacy policy. In some cases, this didn't even involve removing text, but was just a matter of moving some text... but Signal didn't care much about accuracy: they were stoking the flames every way they could and in the process frankly harmed their own mission because a ton of people ended up going in the exact opposite direction, moving to apps like Telegram.
Here is a comment I had left at the time of this specific particularly-big incident going down, which has then a link to another comment I'd left with more detail on this (as my memory is fading on this stuff) including quotes from both Facebook representatives and their documentation.
https://news.ycombinator.com/item?id=26801760
Signal is a non-profit whose mission should be to get people to move to encrypted technologies whether or not that decision involves Signal and they should be trying to work with Facebook on the narrative surrounding WhatsApp, not throwing them under the bus any chance they have to get some publicity for Signal. Here's the real question: have you ever seen them publicly go after Snapchat, or Telegram? As far as I can tell--not just from memory, but from doing some searches on the topic--the answer seems to be "no": they go after WhatsApp, because that product is the closest to being a direct competitor to Signal.
(That said, I also want to be clear: the actual part where Facebook didn't allow them to run the ads and the feud there is also not good... but not only are the morals there a bit more murky, it makes both sides look shitty to be sitting around in some epic fight over their market, and all the meanwhile the benefactors were the apps other than Signal and WhatsApp, and Signal should be sticking to their mission and teaming up there to help clarify to prevent those kinds of losses.)
There was a time when Google chat, Facebook Messenger and other high profile chat networks could all interconnect through it.
[0] https://xmpp.org/ [1] https://wiki.xmpp.org/web/OTR
Edit: typo
Shouldn't have worn that petard if you didn't want to be hoisted by it.
A petard is a bomb, not a piece of clothing.
> Britta: Shouldn't have worn that petard if you didn't want to be hoisted by it.
> Jeff: ...What do you think the expression "hoisted by your own petard" is referencing?
> Britta: I guess I just assumed that in the old days a petard was a special outfit like a leotard, with a lot of fancy buckles and loops on it, and that rich people would wear them when they were feeling especially smug, but then poor people would tie a rope through one of the loops, and hoist them up a pole and then let them dangle there as punishment for being cocky.
> Jeff: Never look it up. Your explanation is way better.
https://www.reddit.com/r/community/comments/7vs6ec/brittas_m...
You seem to be referring to the more normal use of it
The literal meaning of the phrase is that when your own bomb's explosion blows you backwards that leads to the derivative understanding of having experienced an ironic reversal or poetic justice in whatever situation is being experienced.
In todays world we now have the culturally apropos Petard Clothes for custom hoisting. [3] So, we actually have a double entendre [4] that should tell us all not to get hoisted by our own petards when telling HN posters not to wear their bombs.
[1] https://en.wikipedia.org/wiki/Hoist_with_his_own_petard
[2] http://changingminds.org/explanations/theories/ironic_revers...
If you use Signal, you can do it basically. Same for Matrix.
Its just that these systems try to make it so people don't have to know anything about this to use it securely.
https://www.ft.com/content/fc95a0f7-5e4e-4616-9b17-7b72daee6...
Sorry, is it naive to think that Facebook bought WhatsApp for its userbase and technology?
Well, no. Absolutely not. Until you notice the 20B pricetag. I'm not seeing 20B worth of ads on WhatsApp, are you?
They largely failed though, as for political (and maybe also technical) reasons the merge was cancelled.
Anyone know?
Furthermore, the UK has a long history of such “strict oversight and transparency” hardly existing, when it comes to these matters, with numerous controversies with police and other agencies abusing their access to systems.
It is worth noting, however, that WhatsApp messages can generally be accessed with such a backdoor anyway. The majority of users backup their messages to iCloud or Google Drive, encrypted, with WhatsApp holding the key. Consumer tools already exist that can access these encrypted backups, and fetch the key from WhatsApp with nothing but a text message. A warrant to Google/Apple for the backup is all that is needed, apart from the small % of users who have enabled the new E2EE backups.
Much like on a group where everyone involved in a group chat has access to the messages. With UK law, all 1 on 1 chats would turn into group chats: 2 people + UK law enforcement.
So it's not like everyone and your grandma will have access to your messages. It's you, the people you chat with and law enforcement.
But regardless, I still think this is stupid because not even governments can be trusted with our privacy, much less law enforcement. Not to mention leaks.
Meanwhile 99% of innocent people will be hugely inconvenienced by weakened security, not to mention the amount of suffering caused by data breaches and impersonation, then the loss of jobs and economy for many business wasting resources on downgrading their products for compliance.
Not a great trade IMO.
It is more likely that "only pervs use encryption" is a pretext to appease lazy police or spooks, who just want to hit buttons and get people arrested. I have this suspicion because actually helping children who are exploitable this way is a much more difficult problem than breaking out the banhammer.
The perception of those people also has to change. I would guess most of them will not have made a conscious choice to be attracted to children in the same way that most homosexuals will not have decided to be attracted to the same sex. So they have to deal with a desire that they can never fulfill without doing something really bad and many of them would probably benefit from professional help. But thinking about those people as if they are the personified evil and considering them almost inhuman, is probably not what will encourage them to come forward and seek help.
Also, sometimes the most strident voices of condemnation are seeking to draw attention away from their own criminality. A couple of months ago a guy in Southern California was arrested and charged with not just possession but production of CP and other sexual offenses. He had a private room on his business premises that he used for these crimes. In 2021, he had hosted an anti-child-sex-trafficking rally in the parking lot of the same business location.
Likewise, think of the numerous cases of moral crusaders against fornication/ homosexuality/ whatever that turn out to have been engaged in the same behavior that they regularly denounce. Dishonest people see no problem with being a pastor or community leader and bilking the suckers foolish enough to donate to them.
Anyway, my point was that some of the most strident condemnation is actually performative & deceptive.
Another example literally just popped up in my news feed: https://www.wusa9.com/article/news/local/maryland/library-va...
Also the decision is not a dichotomy between complete surveillance of all communication and doing nothing at all, there are other measures that can be taken additionally or alternatively. So the proper measure is the additional utility of banning end-to-end encryption over all the other things you can reasonably do, not over not doing anything at all.
The problem is that from a security perspective, it sort of is all or nothing.
I think there's two ways to interpret that:
a) At face value, in that its boomer mindset popular among the Tory voting base to want to convert the internet back into the pre-internet world and its possible the blues are just genuinely representing these concerns.
b) these child protection groups in years to come will be revealed to have links to MI5, given MI5 is one of the few agencies that the government does tend to listen to. Its worth remembering that the UK used to predominantly communicate using text messages which are sent over clear so the universal adoption of encryption post Snowden revelations has been a thorn in the side of intelligence agencies for many years now.
And the predictive text spits out what it thinks you want to type.
And backups are possible even if you never had one before.
This is so very dodgy to me.
Maybe its e2e from the moment you submit until it arrives at the desired destination.
Which brings me to the next issue, they need to parse the text to display and when you quote a text, does it just blindly quote a blurb?
I do not believe in conspiracies and such, but there are so many double speech possibilities here...
Signal or GTFO.
"End-to-end encrypted" means "from the moment the text leaves the phone, to the moment the text arrives at the recipient's phone, the text is encrypted such that no intermediate party can read it". You must of course trust or verify that the WhatsApp app isn't leaking your text, that the keyboard you are using isn't leaking your text, that Android or iOS or whatever isn't leaking your text, that you yourself aren't somehow taking unencrypted backups and you aren't using whatever unencrypted-backup features WhatsApp might make available, etc.