Leaked government document shows Spain wants to ban end-to-end encryption
wired.com
wired.com
If the CIA wants Spain to ban encryption, they're not going to be bothered by the resistance of some Spanish MPs, they're going to fix the problem.
We (the citizens) need to ban secret police and secret courts.
Not here. Probably not anywhere outside US and some very few countries.
We need to do something against this. We really do.
¹ https://en.wikipedia.org/wiki/Jeffrey_Epstein
² https://www.researchgate.net/publication/336831983_Understan...
³ https://time.com/2974381/england-land-of-royals-tea-and-horr...
⁴ https://en.wikipedia.org/wiki/Marc_Dutroux
⁵ https://www.spiegel.de/international/germany/past-pedophile-...
Bold claim, without anything to back it up.
Relevant standup bit https://youtu.be/b6NmjK2pgiQ
But I sort of get your #2.
Critical thinking and scepticism are essential, both when you read things from traditionally reputable sources, like WaPo, NYT, state media, politicians, and alternative media, like Youtube opinion people, online forums, or your friends, family and colleagues.
> Critical thinking and scepticism are essential, both when you read things from traditionally reputable sources, like WaPo, NYT, state media, politicians, and alternative media, like Youtube opinion people, online forums, or your friends, family and colleagues.
And I never said otherwise :)
Why do conspiracy theories get a bad rap? it's because there's people who think the moon landing isn't real and the earth is flat. These are what jumps to mind when anyone says "conspiracy theory". Here you are using that association to try to cover for corrupt politicians, which is not exactly a very far out there concept.
Because it's usually speculation without evidence, and because no matter how much evidence contradicts a conspiracy theory people continue to cling to it like a religion.
I'm not sure what "Most relevant child abuse was covered by famous politicians" is supposed to mean, but most child abuse isn't committed by politicians, there is no evidence that most politicians are child abusers, and there have been several insane conspiracy theories about child abusing politicians in recent years so it's pretty natural to be skeptical when it looks like someone's starting down that path.
I expect there's already people who'd say "The crazy conspiracy theories about child abusing political figures were intentionally spread online by child abusing politicians so that anyone on social media talking about politicians abusing children would only be met with eye rolls"
Are you disagreeing with the information in GP's links? As far as I can tell this is all looks pretty legit and the onus is on people like you to prove that all this evidence is somehow fabricated.
That's because politicians keep bringing this up.
At the time the News of the World, a Rupert Murdoch owned tabloid, was stoking the moral panic over pedophiles and creating an atmosphere of fervour over this issue. Maybe other News Corporation owned media worldwide might have started this whole panic around child pornography in the first place, in the early 2000s? With Murdoch seeing the Internet as a large threat to his dominance over the media?
https://en.wikipedia.org/wiki/Operation_Ore
https://www.theguardian.com/technology/2007/apr/26/comment.s...
https://www.duncancampbell.org/content/operation-ore
https://www.whatdotheyknow.com/request/the_home_office_cover...
And rooting out hidden enemies within is typical of what happens during a moral panic. Same with McCarthyism. In reality it's very unlikely that there are pedophile networks within the UK government.
And no more unrecorded votes.
f. Any person to intercept any radio communication which is transmitted:
(1) by any station for the use of the general public, or that relates to ships, aircraft, vehicles, or persons in distress;
(2) by any governmental, law enforcement, civil defense, private land mobile, or public safety communication system, including police and fire, readily accessible to the general public;
(3) by a station operating on an authorized frequency within the bands allocated to the amateur, citizens band, or general mobile radio services; or
(4) by any marine or aeronautical communications system;
———
Which would imply that broadband RF recording using SDRs, even if it excludes the cell phone bands, is not OK!
For example, the MURS band seems to be illegal to intercept.
These signals are being sent into your property, whether you want it or not. I think you have a natural right to receive it. It doesn't matter if the government says it's illegal, or attempts to enforce it. Just as we can hear anything nearby with our ears, nobody tells us we can't overhear conversations in a restaurant, trying to do so would clearly be absurd. My opinion here is from natural law.
Basically, some expectation of privacy especially in a 1-on-1 conversation, even if it's via telecommunications tech rather than in-person.
Some people adopt a more filtered, cautious way of speaking anyway as a defense mechanism. For them it doesn't matter so much. Other people talk informally with less of a filter, and for them it matters quite a bit.
Given that recording is ubiquitous now anyway, and voice deepfakes are about to render even that irrelevant, there probably isn't a good argument against 1-party consent today.
(However, government officials, outside of a foreign policy context, deserve no privacy for anything related to their official duties. The argument that they need to be able to talk informally with their peers, without fear of public judgment, works against the public interest far more than it works for it. That helps build rapport, but no politician these days would fully trust someone they're just building rapport with; that kind of thing may be valuable for diplomatic relations and spies, but not for regular government officials. Privacy and secrecy among ordinary politicians is little more than a recipe for corruption and side-dealing that they know the public would be rightly upset about.)
Now, any conversation with 3 or more parties is considered public. A closed group chat on whatsapp has the same legal protection as shouting it on a megaphone to a crowd, meaning none whatsoever and people have already been convicted for their speech in closed chats or forums.
Are you actually asking hackernews, in a thread about banning encryption, why "if you have nothing to hide you have nothing to fear" is not a good justification for being monitored without your consent?
Compromise is reached in quiet, safe places. Politicians make bombastic statements for their base and donors, and then go behind closed doors to negotiate. You can't negotiate in earnest if every offer for compromise you put forward immediately results in (a) the losers of that compromise creating a ruckus and (b) your opponent using (a) to weaken you.
Public negotiations reward playing to the audience. (You see this in small groups–letting leaders or the people in a friend group who disagree pull aside almost always solves the problem better than litigating it as a group.) If every conversation might be recorded for replaying to a third party, then every conversation will be treated as an open one. That destroys room for compromise.
That may be. But corruption also festers in quiet safe places. It's not clear to me that the the tradeoff is worth it.
Public legislating, private bargaining [1]. This keeps substantive deliberation in the public domain while the horse trading, the job republics delegate to elected representatives, has a limited space within which it can efficiently engage.
It just isn't worth forcing every person to give up the ability to protect themselves by recording their everyday conversations just so that politicians can lie to the public and their donors while screwing over the people behind closed doors.
> Eventually the "losers" of a compromise are going to learn about how their elected officials voted
The point is to let both sides table ideas without having to face the downside. To propose what if scenarios to the other side.
[1] https://preprints.apsanet.org/engage/api-gateway/apsa/assets...
Imagine if politicians acted like normal people, negotiating things in nuance instead of being showmen.
Speaking as someone who often has to tell people "Email that to me or I won't remember it", I can see the utility without it being intrusive.
1. Privacy. The cornerstone of personal conversation has always been an inherent right to privacy. Traditionally, conversations held in confidence were sacrosanct, and any disclosure of their content required mutual agreement. Otherwise, the second party can simply deny it and it will never be known with certainty what has been said.
2. Chilling effect on authenticity. In a climate where any conversation could be recorded without one's consent and later used against them, people would be compelled to adopt calculated diplomacy in all their interactions. This would sterilize authentic conversation, replacing genuine thoughts with measured communication, removing a lot of depth and meaning.
3. Weaponization of speech. Recordings under a one-party consent system could be misused in a myriad of damaging ways, from creating training data for voice (deepfake) AIs to insidious forms of blackmail. This extends beyond traditional notions of blackmail to include public shaming or character assassination. This is the "group chat has leaked" scenario, but potentially decades later. One could be a completely different (and potentially reformed) person, but their past will always haunt them and not let them get ahead in their public life, like hold an office or public trust.
4. Limited utility. In many places that allow first-party consent, these recordings are not recognized as valid evidence in court without consent from all parties involved. This significantly undermines their perceived utility as a defensive tool. Is it worth surrendering our privacy for this?
5. Accountability for human folly. People often vent and ramble, it's part of our emotional expression and a necessary component of our mental health. If every idle venting or thoughtless comment were recorded and held against us, it would make our lives much less peaceful. Sometimes it's good to let some thoughts die in a conversation. Reflect on your own past and the blunders of youth - good that they were not recorded, right? This also applies to intoxicated conversations, conversations while suffering from mental health illness, and similar.
6. Two-party consent already serves many purposes. For most business or evidence needs, two-party consent is enough. One can simply tell the other party that they will start recording the call if the other party does not hang up, and that will be implicit second-party consent in many countries. So one can record conversations, and one can choose to have only recorded conversations with some people. One-party consent has only marginal benefits over two-party, but it has significant downsides.
7. Little effect on harassment or threats. Threats and intimidation could be made in other ways, like face-to-face, or through coded language. "Your political campaign is going great, it sounds like a guaranteed win unless someone fabricates a scandal. You need to play it safe with the people that could."
8. Third-party recording. One-party consent doesn't mean a third party isn't recording. For example, smartphones could record audio of conversations for ad targeting and government purposes if there was one-party consent (one party turned on the call recorder).
9. Other contexts. If the laws for one-party consent are too permissive, this could lead to a lot of surveillance activities becoming permissible. For example, the definition of a conversation could be stretched to include all chatter on an office floor if just one person consents to the recording (perhaps a manager).
Where/when has the been true? Nowhere I know of.
> Chilling effect on authenticity, Accountability for human folly
There are lots of places with 1 party consent already. Not a problem
> Weaponization of speech
People who are going to commit crimes won't hesitate to commit other crimes. Irrelevant.
> Two-party consent already serves many purposes
For business 2 party consent is not enough. It would be enough if people didn't regularly commit crimes... but they do. Wage theft is probably the most common type of theft. Add on shenanigans with worker's comp, and other workplace nastiness and 1 party consent is very much needed.
> Little effect on harassment or threats
If one person can understand covert speech, other people can too. Irrelevant.
> Third-party recording
I'm a little sympathetic to accidental sharing of recordings, but there are plenty of ways to record that don't have this danger (dedicated recording devices and apps where the data doesn't leave the phone come to mind).
> Other contexts
Lots of things are possible. Your example isn't particularly compelling, though: not every instance of speech has an expectation of privacy.
https://www.justia.com/50-state-surveys/recording-phone-call...
(I'm just an interested observer, so I'd love to hear from actual Finns on how they feel about their government's level of openness!)
Look, maybe nuclear secrets, black ops and some kind of weird Blackwater (er excuse me Academi) stuff can be off the books, although that has historically resulted in a lot of misery, especially the CIA: https://www.npr.org/2017/01/23/511185078/america-in-laos-tra... and is probably a major reason behind war in Ukraine since 2014 ... but also in dozens of other countries, too. You'll find out when it's fully declassified 10 years later, but by then they'll just say "mistakes were made".
If we knew about how the covert operations that led to wars that killed MILLIONS of people, we'd hold them to account: https://www.outlookindia.com/website/story/how-jimmy-carter-...
Come to think of it, we'd all be richer, too. Want to get rid of wasteful spending? Start with the Pentagon. Somehow debt-ceiling Republicans aren't eager to do that but it can't account for $35,000,000,000,000 https://www.yahoo.com/video/pentagon-35-trillion-accounting-...
Thankfully we have C-SPAN at least.
This is about duty. Not about profit.
I think you have it flipped.
Have everyone in govt making in excess of 2x poverty line be subject to a tax of 99% for all income exceeding the avg of 5 years of income before joining govt
You can be rich and join govt. You can live ok post-govt. But you sure as hell should not get rich off govt
It's called public service for a reason. Its a service. Not a career.
Either you have a sense of duty and are willing to sacrifice, or else go work on the private sector.
We need statesmen. Not rent-seeking politicians
What has changed since the moment you joined, (nonrich), and now suddenly, you leave and you are hot stuff ?
You can still earn a living in govt, even nice money ( >$100k+ for senior jobs) the point is, that is your cap. Job security and duty come at a price. That price is not trading in insider govt connections.
You can live comfortably. You can have job security. But you cannot get rich off it. That is your "sacrifice" if you want to call it that.
And to be clear, because i realize my comment was not: You can have a really nice bump in earnings while in govt. - For example, if you have an avg salary of 50k, then join govt, at make 100k, that bump is yours to keep just like everyone playing by the same rules. However, once you leave govt, your cap goes back to 50k . So either retire in govt or just go back to what your situation was.
As you may imagine, the complaint is never that public service pays "well" therefore the hypotetical is very unlikely to happen in the first place.
I think the next angle will be that it's needed to prevent hate speech. Any other ideas?
It's time politicians spent time increasing accountability and preventing abuse before they even think about granting more power to law enforcement.
- will it be illegal to transmit a blast of static?
- will it be a crime to transmit words that aren’t good, clear Spanish? If no, what if it’s a crazy complicated language?
- will it be a crime to transmit Spanish with bad grammar? What if I transmit a billion random Spanish words?
The point is that they will look at intention and surrounding context - is there a crime leading to you in some way and could it have been facilitated in part by encrypted messaging? Did you also transit a billion random Spanish words during this time frame? If so, it seems to follow by their current laws and logic that they can assume this was encrypted information and therefore broke the law. And if you refuse to decrypt it for them, that's another broken law.
https://ro.uow.edu.au/cgi/viewcontent.cgi?referer=&httpsredi...
Wildly unrealistic but it exists.
Encryption is the one-to-one mapping of a set of bytes to a set of bytes. Software + key is the mapping function. When doing cryptographic forensics you don't use the user's software, you use your own.
So proving that the user's decryption program is fake is trivial and may not even come up as you wouldn't bother running it.
And you can't choose keys in a way that would alter the byte mapping in a way that you can control, the true key will map to the true data, and anything else will map to random bytes.
In fact, what if encryption one day gets so good we cannot distinguish it from plain English? Kinda like trying to spot LLM generated content.
If encryption is illegal, you are suspected of having to encrypted data and don't provide the keys, the police won't be puzzling about what's random or encrypted bytes: they'll interrogate you, abuse you and throw you into jail.
In fact it would be really nice if Android smartphones, when encryption is enabled, fill up all the unused space with random data. I wonder if they do that already or not?
Even better would be have the operating systems fill up the unused space with random data upon partitioning the disk, by default. SSDs are very fast nowadays so it doesn't really take too much time to do so.
This random data filling could even be implemented by SSD controller firmware. Any SSD firmware developers here, please consider doing this by default, as it would severely impact the ability of the government to violate our rights. If AES crypto hardware is available, just use a random key, and let the hardware generate a stream of encrypted zeros.
Also if you run a Web site, you can generate chunks of random data dynamically each time and serve it up to the users. That way it will end up being stored in peoples' browser caches worldwide. Even a couple of kilobytes at a time would be fine. This can be embedded in HTML files, added as dummy data in video files, music files, JPEG, PNG, etc. Again, this is all perfectly legal to do. Transmission and possession of random data is not illegal.
So anywhere you can, if it's cheap to do, don't pad it with zeros, pad it with random numbers instead! You can even do it with RAM, because it will likely end up in the swap space at some point.
https://lemire.me/blog/2018/06/07/vectorizing-random-number-...
https://old.reddit.com/r/crypto/comments/jj4j47/arx_based_fa...
When nearly every computer or embedded device out there contains large quantities of random data on it's disk, these "key disclosure laws" will be rendered completely useless.
https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...
Not illegal to posses it explicitly, but illegal when accused of it being encrypted information and you can't magically make it not-random
We could write software to do this, and people can install it on their web servers, as a means of protest?
Even if all of this did not incriminate you, you're in trouble for something in the first place, since you're on trial, right? So probably other people you communicated with lead them to you. And in this case, the judge applies common sense, there is this traffic cell of 6 people and on 5 computers we have clear evidence but on 6th nothing, therefore you're still probably 95+% guilty? Judges aren't stupid.
People making comments like yours annoy me since you seem to be calming people down that we could endure total strong encryption ban, while we absolutely could not.
What happens in authoritarian regimes is that the law is used to justify the actions of the ruling body, not the other way around. So if you just so happen to blast random static and act suspicious, you'll be taken, beaten and either admit to a crime or a law will be made or amended to justify it. And then you'll admit to it.
The price of freedom is constant vigilance. You are correct in saying we could not endure a total strong encryption ban.
The parent comment has nothing to do with anything you just spouted.
It's about random transmissions being labeled as "encrypted" when that is not the intention.
Encryption is not limited to the more modern systems. They have existed for a long time.
These are politicians. We cannot trust them to have any knowledge or nuance.
"Oops, sent a funky signal with the wrong configuration, let's try again."
Or
"I messed up the modulation so the message is illegible."
Or
"I just found a funky NASA satellite that is no longer operational. Let me slap it with some messages and see if I get a return."
https://www.science.org/content/article/amateur-astronomer-d...
Or maybe you are an amateur radio astronomer. Built your own radio telescope.
The OP seemed to suggest that when you ban encryption, random people will randomly get in trouble, therefore banning encryption is a bad idea. But judges have common sense and law enforcement has limited resources (prioritization) therefore random people will probably not randomly get in trouble. Therefore strong encryption ban is very realistic and very easy to sell to the population, and not like the OP claimed something that will backfire. This is why his comment is naive. He likes encryption and doesn't want for it to be banned therefore he deludes himself with some alternative reality where doing something he doesn't like backfires and is reversed.
Strong encryption ban will not backfire.
Sometimes they are too old to even comprehend the technology.
Judges are always on the side of law enforcement, and whomever can purchase the more reputable legal firm. Judges have favorites, and biases.
Laws like this will immediately backfire. It won't hurt politicians initially. They get immunity. But it will allow the party in charge to cement their position through illicit use of encryption.
No encryption allowed for the opposing party! But us...
Extremely late edit : I would also point out that "random people" are easier to arrest than actual career criminals. Police here are extremely lazy and usually only go for the low hanging fruit. Some of these cases do get thrown out. But not all of them.
My country does not have free speech. It has some of the most stringent copy right laws in the world. It also has defamation laws that have been used to suppress truthful reports.
Police are allowed to hold you indefinitely with no justification. (Technically they are limited to 30days) They are allowed, and constantly refuse to allow you access to a legal representative.
They are allowed to force you to confess to a crime you never committed.
Politicians get away with corruption, and secure votes through the use of cults.
I know what it looks like when the current dominating party was created by a literal Class A Warcriminal from WW2.
These anti- encryption laws make life even worse. The last thing we have here is a semblance of privacy.
I do not want, or need 1st world countries such as Britain or Spain to give an example for my government to follow.
I am saying no ban on encryption can be logically consistent since you can’t absolutely prove that something is encrypted. Even if it is a file called encrypted_drive.imencrypted.
I’m not a lawyer but this kind of ban should be wide open to legal attack. Especially if the country also has freedom of speech. And if it doesn’t have that, it should.
And if all else fails and this insane law passes, the illiterates who pushed it through will cause a national economic and security disaster. Online crime will skyrocket. The KGB/FSB will have a feeding frenzy. Voters will quickly learn to love encryption again.
I'm open they ban anything related to Latinx. Or at least call it a different language.
There is no evidence that the reason terrorist attacks (the common go to) would be stopped by removing encryption from people, because we know that existing attacks have occurred even when law enforcement is already aware (take the Manchester bombing: multiple friends and family had reported him to the police on multiple occasions).
We do have a huge amount of evidence that any such attack on privacy will immediately be abused. In the UK those laws that were passed to "stop terrorism", etc are used to catch people not picking up dog poop, not paying TV licensing, etc. In the US we had wide spread warrantless surveillance of literally everyone, courtesy of AT&T.
My opinion is that any law that proponents proclaim will only be used to stop X should contain terms along the line of "any use of this legislation for any purpose other than X invalidates this law, any evidence acquired must be destroyed, and any convictions derived from such evidence are no longer valid". I would give good odds that any attempt to add such text would result in push back by the people saying the law is only needed to stop X.
- The government proposes a law to regulate content on the internet, ostensibly targeted at Netflix and similar services.
- Critics point out that the law would apply to small-time content creators too, and could destroy their ability to compete.
- The government pinky-swears that they would never apply the law to individuals.
- A member of the opposition proposes an amendment to explicitly exclude individuals from the law.
- The government rejects the proposal and passes the bill as originally drafted.
Criminals will not use apps that compromise security. They will still use apps that are end-to-end encrypted. These people are breaking the law already, why would they make an exception for one that would compromise their opsec?
1) take risks to accomplish goals that would be beneficial to government, but that government does not want to risk itself, [e.g. if there were no grocery stores, government would have to feed you, but government doesn't have the information to choose locations and stock stores effectively, which competition provides]
2) allow the government to do things that government isn't allowed to do directly [e.g. censor content, cut off undesirables from financial services, pay lower than their current government union contracts or legislation], or to
3) aid the transfer of wealth from government to insiders through either government overpayment for services it could more cheaply provide itself, or by having looser labor/materials sourcing/pollution regulation or monitoring than government does, providing self-dealers a margin built from externalities.
Whether it is A->B or B->A doesn't really matter. It's all a method of operating as a defined entity to the state with minor differences. It would not be hard to define something like Apple with it's corporate campus as a city. That would blur the lines pretty significantly. They could create an actual Apple Police. I'm guessing that would do some heads in.
All power structures are your enemy.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
For the purposes of privacy and human rights, corporations and the state are integrated in almost all large industrialized nations. Businesses are too busy being businesses to fight city hall.
Add in billions of dollars in quarterly revenue, and you have a power structure that will willingly integrate itself with the state to preserve those cash flows.
This is why iMessage is backdoored and isn't really e2ee.
It's not even the "why?". I get the "why?" even though I obviously don't agree.
It's the "how?".
You just make it a felony with a penalty of decades of imprisonment. Then, all the businesses stop doing it and you selectively enforce the law in order to make an example out of people. The idea is never to enforce it fully.
If encryption is a felony, your average business will stop using it, which is pretty much the desired effect. They don't care so much about your personal website or data store using encryption. They'll just make it a fringe technique.
It’s not an analogy, it’s pointing out that encryption is more common than some think.
It’s all punitive because preventative is fantasy.
If you have any presence in Spain then you'd be subject to fines or whatever cross-jurisdictional sanctions they can get away with. Or if you're untouchable legally they could require ISPs to block you and you can play whack-a-mole. The majors players where 95% of communications happens would either have to play ball or withdraw from the country. In practice this probably means that small apps get away without complying until the government has a request for you that you fail to meet.
It's a horrible and terrifying idea, but I think it's reasonable to enforce and get the vast majority of people to have unencrypted communications. (but not the vast majority of dedicated criminals)
You sue and jail any website operator offering access to encrypted peer-to-peer chats.
1. https://english.elpais.com/elpais/2015/02/16/inenglish/14240...
2. https://www.theverge.com/2023/3/10/23633601/uk-online-safety...
Maybe WhatsApp is lying, but it would put them in a predicament for the following situation: a user from outside of Spain chatting with someone inside of Spain. Assuming they comply with Spanish law, they could,
1. Say nothing and show no warning message. Would generate negative press and distrust in the platform.
2. Show a warning message when a user tries to message someone in Spain. Some would commend the transparency, but the press and public may still be upset that they acquiesced to the Spanish governments' demands.
3. Create an entirely different version of the app for Spanish users. This wouldn't generate much negative press outside of Spain, but Spanish users absolutely would be upset that they can't contact people outside Spain with the app.
This is not an edge case scenario: 15% of people in Spain are foreign-born (likely contacting family and friends from their home country) and 2.7 million Spaniards live abroad (likely contacting family and friends inside of Spain.)
Option 3 is likely out of the picture, but of options 1 and 2, while neither would result in the death of WhatsApp, some users may indeed leave the platform due to it. In order to be worse than losing the entire country of Spain, 2.35% of WhatsApp users would have to leave the app. That seems unlikely, but even still WhatsApp might not feel it's worth the risk, and in any case they'd probably prefer to not have to spend development hours building systems to comply with the law. Easier to just cut them off.
It also enables them to stop petty criminals, but we both know they don't really care about that.
Wouldn't simple mappings introduce sufficient plausible deniability in this case?
An example: Every two bits in the encrypted message are mapped to 0=A, 1=T, 2=G, 3=C and suddenly everyone is transmitting DNA sequences for research and evaluation.
Attach the encrypted message to a legitimate sequence and-- boom! --you have a "telomere".
Encode bits as spanish words. Enumerate 2^8 words in the dictionary and just use them.
if the argument is to get discounts on retail products/services, then of course the "think of the children" or "but terrorists" will work on them as well.
putting that much decision making in the hands of the voting public is always a scary idea, and never a sure thing.
I find it remarkable that, even though the UK government is desperate to demonstrate any form of tangible benefit to Brexit, and talks about independence and sovereignty etc, it is moving in exactly the same direction as EU nations on this, ignoring all advice to the contrary.
To be honest I’m kind of feeling left out. My messages are boring. Perhaps if this nonsense goes ahead I’ll start communicating dinner plans with my wife through our own custom key pairs, just to mess with them.
VLOPs are interested in E2E encryption now because it lets them ignore their sexual abuse problem by making it untraceable and therefor unreportable. No normal user needs or benefits from E2E encryption on Facebook.
We don't need a blanket ban of E2E encryption but we do need regulation around who can use it and when. Preventing VLOPs from smoke-screening their platform abuse is a good middle ground.
Many idealistic technocrats on the web already believe E2E encryption is an absolute moral good, so it's hard to even get the conversation started. As evidenced by the extremely simplistic black & white takes in this thread. VLOPs are counting on this when they market E2E features as in their users' best interest.
Basing your laws off the needs of corporate persons instead of human persons is bad policy. Authoritarianism might look good in the short term but $godwin. Will you suggest going after the post office for people mailing illegal items too? It's misplaced. The person who commits the crime commits the crime.
https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
My claim is that these platforms have a proven history of elevating CSAM on the web and are turning to a currently unused technology, E2E encryption of messages and groups, to crystalize the problem instead of tackle it.
This has nothing to do with theoretical beliefs about encryption in general, the value of transport encryption used by Facebook and nearly every other website, or personal liberties. Nobody needed E2E encryption on Facebook in its first couple decades. Nothing is being sacrificed if they don't implement it now. The sacrifice happens when the _do_ implement it. We sacrifice the ability to do anything about the CSAM influencers profiting on the platform.
I'm not even arguing for a blanket ban of E2EE. What I'm arguing for is that we don't allow VLOPs to use it.
> Nobody needed E2E encryption on Facebook in its first couple decades [...]
The reality is that "transport encryption" does absolutely nothing to protect you from a malicious, authoritarian state actor, which is why the state's asking for it in the first place and why there have always been activists pushing for adoption of E2EE on these platforms. I should know, I was and still am one of them, so it's a bit absurd to say "nobody needed it for decades" when the only reason it's being adopted in the first place is because there's clear demand. And because the state has steadily gained the ability for technologically feasible mass surveillance for the first time in history, which is also a new phenomenon.
> We sacrifice the ability to do anything about the CSAM influencers profiting on the platform.
I'll spell it out bluntly: I acknowledge it could have such an effect, and it's a sacrifice I am willing to make, and deem to be a net gain for society as a whole. People have throughout history engaged in despicable behaviour, and will continue to do so in the online world because it's a reflection of who we are as a species, both good and bad.
> I'm not even arguing for a blanket ban of E2EE. What I'm arguing for is that we don't allow VLOPs to use it.
So we lose the ability to *maybe* do *something* on *some platforms* using only the online communications of the perpetrators, whom probably represent single digit percentages in the population. Meanwhile, traditional policing continues to exist, and the ban would, in practice, affect almost everyone else (or else what's the point?). Except, of course, the technologically literate criminals who will as always find ways around it.
I'm assuming you're aware of the far-reaching potential for misuse of your proposal, and presumably that's a sacrifice you're willing to make, so our differences can be easily summarised: you place higher value on punishing a relatively limited number of individuals for crimes deemed particularly damaging and offensive over sacrificing the whole of society's right to private communication, I do the opposite. In fact, if you grant that this issue will likely never fully be resolved (as history suggests is the case), we merely disagree about what the tolerable level for this crime is in exchange for safeguarding societal freedom. Same with all other forms of criminal activity throughout history...
As we've already sacrificed much in the name of this very issue, I hope people living in democratic nations understand what's at stake here, and that there will never be an end to these authoritarian arguments. Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety.
I disagree with how you frame my position. First the argument that criminals will always find a way around it is specifically why I think legislation should target VLOPs. Nobody can just build one of those, including criminals. If you want to firm up my position it's not that E2EE is the last battle against CSAM; rather it's that VLOPs proliferate CSAM in previously impossible ways, with a virality factor unachievable by older means. Criminals are of course free to return to Signal or whatever, but it won't give them the reach that Facebook gives them so it's still progress even if we didn't save every single child on the planet.
Moreover, I disagree (again) with your desire to pull my position into a theoretical debate about free speech absolutism. I just don't think two people on HN are going to get to the bottom of that one. But with a little nuance, which yes is messy, we can stop the proliferation of CSAM on VLOPs without constraining individual liberties. Just go do those liberties on anything except a VLOP.
Ultimately, you’re right, our debate here will have little effect on the outcome, given that members of the Spanish government stated in no uncertain terms they would indeed not restrict it to the large social media platforms. I was pointing to the specifics mentioned in the article instead of pulling it in a theoretical debate like you said.
Alas, whether their stated intentions are the true ones, I trust few legislators to nail some platonic ideal state of authoritarianism, even if they’re benevolent. Too much power stands to be concentrated in too few hands for this ever to go our (society at large) way. When we shift the debate to the problem of the integration, we’ve already lost.
Me, I don’t know where I stand. I think if it eliminated CSAM, terrorism and other such things, it’s a price worth paying.
What I need to be convinced of is the scale of that elimination, because if erosion of privacy is the cost paid, people (as in Joe Public) will want to see returns on that.
What I think it’ll actually do is move offenders away from those platforms and onto ones that are even harder to monitor. I mean, I’d assume that Meta will be able to see who is talking to who even without the content, which puts some pieces of the puzzle together in the presence of other evidence. I’d also assume end to end encryption doesn’t mean much if the app itself has a CVE that leaks information once decrypted, and it certainly doesn’t mean much if authorities have possession of your device (in the UK, not unlocking a device and apps when asked to is itself a punishable crime).
So if all this will do is drive people to platforms that eliminate such things and make the job of law enforcement even harder, it isn’t worth it.
But if there’s more to it than that, it might be. Im guessing it’s feasible that WhatsApp push out an update that sends them your private keys, because I’m assuming the app itself has access to them. If Im right, then in theory the end of E2EE could open up a huge backlog of messages and solve “historic” crimes. If that’s the case, it might be worth it.
Too many variables for me, so Im placing myself firmly in the “I don’t know” camp.
Not the encryption baked into facebook chat, but most certainly the encryption baked into the HTTPS they're accessing facebook through.
Not if you have to use a government-issued root certificate.
Ofc the attempt failed.
Without encryption, you do not have banks, you do not have email, you do not have 90+% of websites, you don't have any business software sales, and now as of Win11 and its Bitlocker-by-default strategy, you don't have consumer desktops.
If Spain wants to get on the fast track to a revolution by literally destroying their economy in the most efficient manner, I say let them. This is a self-solving problem.
There are no secret keys that only the "correct" people can use, there are no impenetrable vaults where hard drives live and only the "correct" people have access to. It is either encrypted, 24/7/365, in all the forms it lives in, or it is not encrypted.
Banning E2E is the first step on banning encryption entirely. There is no other sane way to conceptualize this.
https://www.theregister.com/1999/01/15/france_to_end_severe_...
> Until 1996 anyone wishing to encrypt any document had to first receive an official sanction or risk fines from F6000 to F500,000 ($1000 to $89,300) and a 2-6 month jail term.
This news item from 1999 is about France finally making it legal to use toy ciphers to encrypt documents in France. Let that sink in. Trivial toy ciphers were actually illegal to use in france for 3+ years.
This (I think '97) was when I realized that France is not your typical western democracy style country. Nothing about France is typical.
(And, yes, the it was that Dominique Strauss-Kahn.)
What makes electronic messages be different to other forms of private communication that they need to be provided to the government automatically? And in the case of Spain in particular, there are reports of Pegasus being used to spy on Catalan politicians [1][2].
[1] https://www.amnesty.org/en/latest/news/2022/05/spain-pegasus...
[2] https://www.amnesty.org/en/latest/news/2022/04/spain-pegasus...
"The psyche of a fascist is “authoritarian” in the sense that it attaches itself to figures of strength and disdains those it deems weak. It tends toward conventionalism, rigidity, and stereotypical thinking; it insists on a stark contrast between in-group and out-group, and it jealously patrols the boundaries between them. It is prone to obsession over rumors of immorality and conspiracy, and it represses with self-loathing the sexual licentiousness it projects onto others. In all of these ways, fascism appears as the political manifestation of a pre-political disposition. The authoritarian personality does not always turn explicitly fascist; its politics may remain dormant, only to emerge under certain social-historical conditions."
I mean I would be extremely surprised if agencies such as the GCHQ were unable to crack or completely circumvent end-to-end encrypted messages (and any well-funded signals intelligence agency that claims it's unable to do so, should be required to give an accounting of what it spends it's budget on), so why the sudden desire to ban it?
Wouldn't it be better to give the bad guys a false sense of security to lull them into using seemingly secure end-to-end encrypted messaging apps, and then quietly gather evidence against them?
Even if everybody _inside_ your country plays by the rules... Everyone _outside_ of it does not.
And let's face it, foreign intelligence services will have a feast over this.
I hate the argument 'You have nothing to hide'. It is so untrue for every single person in the world. It is such a weak argument.
You have nothing to hide and we forbid to use any form of encryption.
Alright, lets AI call your grandmother with all the information hackers got on you. Lets see if you really had nothing to hide.
Would allow you to scan the encrypted messages for incriminating or illegal content when there is reason to believe a specific account is doing something illegal (could require court approval, then a further process for full decrypted messages as part of court proceedings)
Their priorities are set on the power plays that happen in government chambers, the government and corporate interests that ask them to change laws for some purpose, and performing actions that will keep them elected (in that order). Banning encryption is something that satisfy the second group, where government organizations would love to make their jobs easier by having a key to encrypted communications. The fact that the entire internet is built on encryption is only a barrier to these governmental powers telling lawmakers to "pull the trigger" on banning encryption, since the compromises will hit corporations the most (since corporations actually do need perfect encryption without the government spying on them).
Who, and why do they want it?
There are elections this year, yes.
But other than that, how does one even notice these proposals, and how can one help to prevent them from passing? Or even, how to help change the people representing the country in these things?
but in general there's the separation of powers (branches of government), the opposition parties, the checks and balances, and the media.
to answer your question directly, the bigger the government the more separate agencies it has, the more people you need to watch them, the more people are needed to simply raise their voices, give their faces as the opposition, and then more people to keep track of what-the-hell are they doing.
that's how you got special interest groups. single issue parties. (and if such a party manages to raise the salience of their issue to the "national level" then this basically forces other parties and actors to reveal their preference regarding that issue.)
https://community.qbix.com/t/the-coming-war-on-end-to-end-en...
> Representatives from Germany—a country that has staunchly opposed the proposal—said the draft law needs to explicitly state that no technologies will be used that disrupt, circumvent, or modify encryption. “This means that the draft text must be revised before Germany can accept it,” the country said.
For the PP all is a flaming hell, for the Socialists all is unicorn glittering wonderful. All are wrong and they know it. The truth is in the middle.
I would just assume that everything said in this week is fake or incorrect. This is simply typical FUD to catch some late votes in minor groups of citizens.