The U.K. government is close to eroding encryption worldwide
eff.org
eff.org
Any measures without broad international cooperation will push vast number of people towards darker corners of the internet, which will not just end up completely undermining what they are trying to achieve, it will make the problems worse.
Meta alone have the power to make this law a miserable failure. People will want to use WhatsApp, the government themselves use it extensively. If meta refuses there is very little they can do. Facebook can continue to operate without a single person on the ground in UK. It might harm their business in some ways but it's definitely doable. The government might be able to force/convince Apple and Google to take it out their app stores in the UK but such regional restrictions are easily bypassed and WhatsApp is popular enough to make people try it. So that would then normalise the practices such as side loading / jail breaking and avoiding regional restrictions. Cyber criminals would be rubbing their hands at the opportunities this creates and I am sure the peodos and terrorists this is meant to be stopping will jump at the chance to get in on the act.
If I create an E2E messaging app, I don't need to listen to the UK at all. The UK can't tell me what to do any more than China can. China can block my app if they want, but it's on them, not me, to block it. Same goes for the UK. They can set up a firewall too if they want. But I don't need to change my app if I don't set foot in the UK.
Telegram is half banned in Russia.
Of course this doesn't apply to the bad guys: they're already breaking the law, using E2E is a no-brainer for them.
The UK government can't ban math out of existence (even if it looks like they're trying very hard, judging from the quality of their education system) so there will always be encryption.
It's the same with guns: congratulations you've outlawed guns and now only criminals can use them.
So true: gun use and ownership in the UK rises and is mostly criminals. It's still less of a problem per capita than promiscuous gun ownership in the USA by all measures I understand.
This has nothing to do with the "war on encryption by the state" topic
Apple has even threatened to withdraw their own systems from the UK rather than comply with this.
https://9to5mac.com/2023/07/20/apple-imessage-facetime-remov...
It's really hard to be a credible "privacy/security" choice when your morals are plainly for sale...
And iPhones ceasing to be sold in the UK would probably be all it takes for public backlash to neuter the law. I imagine that's not on the table in China.
It's very difficult to square these two sentences together.
On one hand, if they break their privacy and security for the UK government, it's bad for business because they'll continue to sell iDevices and services?
On the other hand, if they break their privacy and security for the CCP, it's good for business because they'll continue to sell iDevices and services?
You're tacitly admitting my assertion - Apple's morals are for sale.
If the US threatened Apple, we can expect they'll sell out there too, no?
Yes.
China is much further from the Western world than the UK. Capitulation there isn’t a step onto the slippery slope. Doing the same thing in the UK would lead very quickly to EU and US demands to do the same.
By exiting such a small market, Apple defends the much larger markets against creeping surveillance.
Remember how fierce the backlash was to their CSAM scanning proposal? They walked that back. Some people might think it was for moral reasons, but I’m pretty sure they realized it would harm their bottom line.
The way things work in China is not the same as the UK. They either play by CCP rules or they don’t play at all. Apple’s calculus here seems to be that not playing in the UK market is worth it, whereas missing out on the Chinese market is not worth it.
Apple made a choice to operate there - and would have still been the world's most valued company regardless.
So, Apple's choice was to sell-out their privacy and security credentials to make more money - counting on their other large markets (ie. the US) not paying close enough attention to see the blatant hypocrisy.
"Security and privacy are great - unless we can make more money selling off your security and privacy to oppressive government regimes!"
Somehow that just doesn't have a catchy marketing ring to it...
So now there's precedent that Apple will violate everything they stand for if a large enough market demands it. What happens when the US government decides to place Apple in the crosshairs for not "helping catch terrorists" or something? Will Apple sell out too? Why not?
We have examples of this from previous attempts to weaken encryption. The FBI’s San Bernardino case being the most memorable one for me.
Apple could simultaneously backdoor their devices while also keep them secure from anyone but the government with a warrant. These things are not mutually exclusive.
The China precedent is troubling - to say the least.
Without China, there is no iPhone, and there is no Apple. Apple, presently, needs to operate in China. They have them by the balls.
Compliance with CCP demands is non-optional.
This may change in the future. Today it is 100% true.
That seems incredibly dubious.
Who forced Apple to manufacturer iPhones in China?
Nobody.
It will take about five years optimistically to build that capability.
It's the effect of the monetary system squeezing the masses hard which forces everyone to buy the cheapest things and it created a kind of technological shrinkflationary race to the bottom.
In my mind, and definitely informed by my attraction to medieval Catholic philosophy, the problem isn’t really debt but rather usury.
I actually think that if it's one's own money, they should be allowed to loan it at any interest rate since they're taking the risk upon themselves. If they can find a willing borrower at such high rates, then good for them. If the borrower agrees to a bad deal, then it's the borrower's own fault.
What I most strongly oppose is the idea of public institutions loaning citizens' money through the issuance of new currency (which dilutes the value of previously issued money). It's especially harmful when the interest rate is low.
For example, if the interest rate is 0%, then it's unjust for a government institution to dilute citizen's currency and shift the risk of borrower default onto currency-holding citizens (savers) without offering any upside to those savers; in that case, the central banks turn regular citizens (savers) into suckers by loaning out their money for free for the benefit of reckless borrowers who borrow it for free.
Manufacturing consumer goods in the west was never unaffordable, just that insane corporates profits weren't possible while keeping manufacturing in the west, as they were in China.
A lot of consumer electronics were made in the west before the mass exodus to China. Nokia phones was made in Finland and Germany, Siemens phones were made in Germany, Ericsson phones were made in Sweden, etc.
It was all possible and they also didn't cost an rm and a leg, but companies saw the allure of ultracheap labor and loose environmental regulations in China to jack up their profits.
Check out the global battery supply chain
That's not dubious, that's obvious.
> Nobody
Ironically correct: the absence of alternatives — nobody else could do it — is what forced them in the first place.
The recent pressure from the US government to "bring it home" is because the US government finally started to realise that was both true and bad (doesn't matter if Huawei was really spying, Washington believed they were); similarly for equivalent EU pressure.
Make no mistake - Apple traded their moral high-ground for a few bucks.
https://www.theregister.com/2023/07/27/prices_of_gallium_and...
Apple made a choice folks... and it was to sell out to an oppressive regime. There is no other way to see this.
Apple made a choice. It's really simple.
They could have not been a large scale electronics manufacturer, but then they don't operate in China by making an entirely different kind of choice to be an entirely different kind of company. I don't think any electronics manufacturer (or meta-manufacturer/designer/whatever/globalization is weird) within an order of magnitude of Apple's scale can practically operate without benefit of China's manufacturing base.
It feels like you have to bend the intuitive notion of "deciding" to operate in China even means for this to make sense and you just want to pin something on Apple here because they're a giant corporation, and all giant corporations are morally gray at best. The global economy has "decided" that China has the manufacturing base for this kind of business.
This doesn't seem productive in the way that appeals to personal responsibility fall flat in dealing with societal issues, like, we shouldn't have public drug treatment programs because people shouldn't do drugs. People do drugs, and there are costs to not having public treatment programs, so if you want to pretend it's just a matter of personal responsibility, you are indeed pretending, because it is also a societal problem not negated by framing it as personal responsibility.
Here, we assign "personal responsibility" to Apple for operating in China, when we have the "societal issue" of large scale electronics manufacturing centralizing there so that they have the industrial base for it. The world, on the whole, has allowed China to link into the world economy in this manner regardless of their humans rights record and other issues.
So, while there's nothing to love about Apple here, I feel like it's really missing the forest for the trees to frame this as an "Apple" issue in any sense whatsoever, but should be framed as a China-human-rights, globalization, and world economy issue, and we don't do ourselves any favors with appeals to "corporate personal responsibility"
When it happens, a company acting purely on someone’s moral code (usually a dictator CEO, though) sounds fine and reassuring. But on the contrary, this is unstable as you never know when that person will be sidelined, forced out, or realign their principles. At this point the company you trust can very well become an enemy. Just look at Twitter or Reddit.
On the long term, you need the company’s financial interests to be aligned with your (various) interests. This is the only thing that remains stable. Well, as long as nobody comes and make it private; then anything goes. It sucks, but that’s capitalism for you.
For the moment, Apple is mostly safe because basic privacy is their brand, and dropping it would be costly. This gives them leverage against some governments, but not so much against others. You can also count yourself lucky not to be born in China, but then there’s nothing Apple can do about that.
Apple makes 10x more selling in the Chinese market than they do in the United Kingdom, even with all of the roadblocks and handicaps China erects. Further Apple realizes that as the UK is a Western, democratic nation it is easy to essentially bargain about policies. Apple's current threats are essentially negotiating. There would be no negotiating with China about stuff like this.
Apple used to be able to access iMessages through iCloud backups. They changed their system worldwide, now they can’t. So presumably GCBD also lost access to iMessages in iCloud backups.
Even if you turn it (e2ee iCloud Backup) on, it's ineffective, as both parties to a conversation must have turned it on for the conversation to be private.
Your beliefs are inaccurate.
I don't see any option to enable e2ee iCloud Backup on iOS 16.6, does this mean your information is outdated and it's all e2ee now?
It’s off by default.
I wonder. Is this an attempt to market? Make it optional, but tout "we do this!', as if it is?
It's not a bad marketing position.
You the have the same level of privacy (if not higher) than with ADP. But with the same drawback, if your recipient does backup to iCloud without ADP then messages can be intercept by apple at rest on your recipient iCloud backup.
Incidentally ADP mainly target users that didn't trusted iCloud backup for the lack of e2e encryption at rest.
The optional iCloud feature called "Advanced Data Protection" is currently an opt-in. It comes with a significant drawback for typical pop and mom users --> If you lost you password and recovery key it's game over you loose everything. So I guess it's sensible to keep this as an opt-in until users are better educated about this drawback.
What will be quite significant is wether or not this feature will be available for chinese users.
It make sense from a technical POV to block ADP feature in poorly democratic countries that might request it like China and maybe tomorrow the UK.
PS : Once a significant % of users activated ADP it could be a good UX improvement to display a warning to mixed ADP status conversation that the conversation is not fully e2e encrypted. However this might be premature right now otherwise early adopters of ADP would be flooded by such warning.
If iCloud is enabled, then by default it gets unencrypted copies of these messages from the device unless “advanced data protection” is also enabled which ensures iMessage is encrypted but means losing your password also loses access to these backups. However, disabling iCloud sidesteps this issue and honestly if you want that kind of privacy then disabling iCloud is probably a good idea.
So if one users uses ADP and the other user disables iCloud then the conversion is protected.
So lots of confusion in this thread, my advice for Apple would be make it very very clear to users that your data is safe. I mean they are threatening to back out of UK, so it’s against their core principles and also probably very technically expensive to undo they end to end encrypted system.
Also possible ADP is off as an option in China.
Of course this wouldn’t work for the UK system unless the UK demanded the iCloud keys same way as China has.
There was a rumor about separate HSMs for device personalization in China, and this would be verifiable by determining whether the Chinese HSMs could verify cryptograms produced by derived keys from a US device, against Apple's personalizaiton endpoints in china. I don't know the protocol off hand, but there is a short list of ways to do it. If Apple uses different root secrets in China from the rest of the world, what further evidence would you need?
Congress knows this would only kneecap one of their largest companies (with no fallback option at present). There is no iPhone without China.
Apple can and does already provide surveillance of this type domestically to FBI/DHS/et al. Approximately all iMessages are readable by Apple and extension by the USG in real-time, with or without a warrant.
There's wiggle room in what you wrote: "Apple doesn't allow China to intercept communications, China just does it on their own" for example is a way to parse that sentence.
Apple can say they don’t allow it, because their local partner company is the one actually doing it. And the local partner would say they don’t allow it, because Chinese law (and the Party) requires them to keep all national security assistance secret.
There's also no evidence to support the claim of this architecture, either.
Famous, sure.
Rich? Perhaps… but I suspect that annoying a superpower will mean that, like Snowden, one would be somewhat restricted in ability to make use of any such wealth or fame.
Don't know what universe or timeline you're from, but on this earth today, the internet definitely has borders.
That's why we have those EU cookie banners and GDPR consent forms, and why some of my favorite piracy websites are blocked by all ISPs in my country, or why I can't watch Top Gear on BBC's website because I'm not from the UK, or why Facebook had to remove some politically spicy content worldwide because the courts where I live forced them to, etc, etc.
Mainstream web companies have to conform to local laws in each country or they'll get fined or blocked. Sure, there's VPNs to circumvent that, but the days of the lawless and borderless internet are a thing of the past.
This argument tends to break down at The Great Firewall of China, however, due to its thoroughness.
In the UK, companies which protest this law are threatening to leave the market. That would mean blocking UK users on their properties, not helping them find ways to break the law.
Or, when you say "no boarders," do you mean that the internet is not zoned for residential use? Sorry if I misunderstood.
Surely china would fall under that statement from OP's perspective.
I disagree with this part. The EU is on that same path. The EU Great Firewall idea has been kicked around for years and it has even shown up in some policy suggestion documents.
I would describe the EU as wavering. Perhaps they'll do it, but it's far from certain.
It would be nice if the UK government used the ridiculous powers they gave themselves to hold Boris Johnson to account though.
But you could make the argument that it was largely due to Britain.
Of course most governments in the UK, like everywhere else (whether right or left wing) are, more or less secretly, authoritarian so they will be favourable to a great firewall when the right time comes.
The EU has been talking about it for some time and I'm sure they'll stick it together with some 600 pages policy nobody will bother reading at some point. https://diginomica.com/eu-policy-doc-recommends-building-eur...
They can't remove all our freedoms at once or people may lift their heads from their smartphones and protest.
We're being slowly boiled alive.
If the UK really cared about unelected government, why don't they get rid of their House of Lords? This would have been much less painful than Brexit. It looks a lot like this unelected government complaint is just an excuse and not something that they actually care about.
The issue is whether the leaders of the commons should be able to appoint people to the upper chamber for life, whether the church should have a seat at the table etc. Or whether the upper chamber should be directly elected. It’s a matter of governance and constitution more than embedded privilege.
So as much as “Guillotine the nobs” would be a popular cry, most of them aren’t nobs in the first place.
French Revolution - 1789.
English Revolution - 1649.
So the English cut off their Monarch's head before the French did. But we then invited the Monarch's back after not liking the republic of the "Lord Protector".
Admittedly the English state, not the later British state, but anyway...
So instead, here's the simple truth.
The UK, in a surge of authoritarianism, cut its own balls off by leaving the EU (and the Civil rights it confers). It did this to appease fringe nutjobs and to make a pile of money for hedgies. Then it howled in pain and blamed the EU, even though the EU was against the chopping of the plums from the get-go.
The conditions for this bollockectomy were created by a barely-elected government, after the fall of which we have had, mainly, unelected government.
This entire manoeuvre was done under a screed of fractal dishonesty, in which scuttling little fibs decorate a structure of brassy falsehoods all stacked higgledy-piggledy on a giant whopper. Unwilling to accept the blame, the responsible parties continue to lie to this day.
In a parallel move completely unrelated to the above, the unelected UK government is ramping up surveillance. The EU has not done this, but the liars blame it anyway.
Serious question as a UK citizen who doesn’t live there anymore. Post-Brexit, leaving is surprisingly difficult despite the refrain of the morons who say “if you don’t like it go somewhere else”, blind or ignorant to the fact they removed that option.
https://www.theguardian.com/uk/2003/feb/15/politics.politica...
https://www.amnesty.org.uk/press-releases/uk-government-plan...
Perhaps you meant another democratic country where the idiot clowns hadn't taken over the circus ...
That's a sad reflection of the tech industry. Too much "we can't make money from them" and too little spitefulness of the sovereignty of foreign governments.
Why would the latter stop them? They have no problem with these.
>Any measures without broad international cooperation
Don't worry, other governments are just as shitty and want the same BS.
Kings respected it... when it was convenient.
And so the democracy they begat also only respects it... when it is convenient.
But freedom of speech when another permits it is no freedom at all, because the right's value increases precisely with its ability to stand up to other, more powerful interests' disagreement with speech.
Can you elaborate?
“It is hard to imagine a more stupid or more dangerous way of making decisions than by putting those decisions in the hands of people who pay no price for being wrong.” Thomas Sowell
I'm glad I was able to experience the true internet while it lasted. Truly a wonder of this world.
... which is why they continue to come for encryption.
Who would you rather be in the public eye, evil or stupid?
some background here.
the opposition in the UK is accusing the government of dragging their feet over this law, and are pushing them to adopt it sooner. they are also criticising the government for watering it down.
various NGOs are also attacking the government for watering it down and not moving as fast as possible.
basically the whole political spectrum is not only for this law, but wants it strengthened even further. there are also calls from the public for the government to go even further.
this is why there is no real backlash against this law. everyone no only wants it, but wants it to go a lot further than what the government has proposed.
They really are not. The current crop of UK politicians of all stripes are thick as they come - intellectual lightweights who can bullshit their way through a media appearance thanks only to an abject lack of shame. No one can look at people like Mark François, Liz Truss or Dianne Abbott (just to take three) and think “ah, there’s someone playing dumb for the camera”!
Unfortunately, the current crop of journalists are largely ineffective if not broadly enabling if this kind of behaviour, and politics is not a field anyone not already independently wealthy can afford to be in (a junior developer in the Bay Area can easily make more than the Prime Minister) so it does not seem likely to self-correct.
If it came to it, Whatsapp could be blocked at the network level. All the gov need to do is impose regulations that forbid ISPs and other infrastructure hosts to carry the traffic.
Now you need to block VPNs, and the cat-and-mouse game gets in full action!
Also, at this point you've basically implemented the roots of a British version of The Great Firewall.
> such regional restrictions are easily bypassed and WhatsApp is popular enough to make people try it. So that would then normalise the practices such as side loading / jail breaking and avoiding regional restrictions.
If people would be doing this (using a VPN, for instance), they would know how to bypass those restrictions.
Breaking encryption is not good for anyone and won't solve absolutely any problems, except the "problem" of right to privacy.
Yeah but it's never worried them much in the past. As a Brit I occasionally come across the effects of them requiring ISPs to block piracy sites. Something comes up saying "this site is blocked" so you click like one or two buttons to switch to a different connection or turn a VPN on (VeePN is good and free). I imagine their encryption ban will be similarly tricky to avoid. I think it's more about looking noble to the electors than actually achieving anything.
No borders (from their POV), puts internet businesses above the law... which it sort of does. The global village happened, but global authority did not. There are no clean resolutions to some of these tensions.
By the way, does a sideloaded WhatsApp on Android still update from the Play store? And what will iPhone owners do?
This is a security/law enforcement issue.
It's currently at 6,327 signatures; it needs 3,673 more for the government to respond and 90,000 more after that for a debate to be considered.
Letters to MPs almost always result in a brush-off too but they do take notice of them at least. Very occasionally you do get a non-template response too.
The one I remember where they didn't do that was when I wrote to them saying that Ordnance Survey's maps should be free, and that did actually improve! They're not totally free not but they are much freer.
And the worst response I've had was the most recent when I wrote about the UK's insane criminalisation of term time holidays, and they wrote back assuring me that they were doing everything they could to deal with COVID??
Even so, still much more effective than petitions.
Let this series of badly-thought-out bills be destroyed in the courts once the courts find that reality bats last.
There’s probably a clause in there that decrees Pi must be four from now on.
How? I thought the UK courts can't override Acts of Parliament, because the courts are subordinate to it (unlike in the US).
This was absolutely an intended outcome for a lot of the figures responsible for the UK’s exit from the EU - European legislation/institutions were more or less the only real absolute check on the authoritarian tendencies of the British state, given the UK’s insane constitutional structures.
The desire to join such beacon of democracy as Russia in jeaving ECHR is heartwarming.
I am not so sure. The recent history of the elites in London, and the rampant corruption and incompetence in the Metropolitan police is, surely, wearing down the English people's trust?
What does it take?
I think the ornate Palace of Westminster gives the political class too much cover, and if they moved into a modernist structure it would be more fitting and reveal their brute disregard for anything virtuous.
Of course it has an authoritarian streak....
As it is the Scottish constitution is generally ignored, and folks more or less assume that the English one applies to the whole UK. If there was an attempt to properly codify the UK constitution, that incompatibility would have to be addressed, and that would open a can of worms.
Else companies will leave or simply ignore the legislation, e.g. Signal, and the law will quietly become impossible to enforce with a series of arbitrary decisions and fines taking place before the digital economy falls off a cliff.
The UK Courts aren't subordinate to Parliament and can tell the UK government to "go back and think again". For example, the move to export immigrants to Rwanda.
https://ukandeu.ac.uk/rwanda-policy-unlawful-unpacking-the-c...
The government are just playing nice and taking heed (or pretending to) of the declaration of incompatibility.
The courts can not force them to change their policy. The courts can not overturn primary legislation, not even the Supreme Court. They are basically just law experts and publish statements on what is lawful and what is not. Their power is derived from how much - or how little - the Government decides to act based on their rulings.
It’s important to remember the courts exist because of Acts of Parliament (some very recently, eg the Supreme Court was created in 2009). Moreover, they are governmental departments!
I’m sure Boris Johnson considered legislating them out of existence during his tenure but decided it was a bridge too far.
That's ... exactly the same as any other country in which the judiciary and executive are separate
All the tech companies should stand together and be ready to block access to their services. Imagine if the UK was left without access to just WhatsApp, let alone iMessage etc. It's not irresponsible or unsafe, there's always SMS for which the govenment has full control over.
Also I don't think any of these companies should fear an competitors. Why? These services are so ingrained a few weeks if not months of protest will not change anything. When the govnement finally succumbs restoration will be easy and the numbers will go back to normal quickly.
You need targeted messages on social media and savvy campaigns to get people irate. Eg “campaigners stopping a pregnant mother getting to hospital”. That’s what gets people foaming at the mouth. Even then that’s usually just limited to angry replies on social media
It’s also illegal to peacefully protest now
This govenment is nutorious for it's u-turns. I would be happy to see another in this case.
FB, Apple and Microsoft need to start this campaign ASAP.
As another commenter said, nobody in the UK is going to protest over this. As a downbeaten kingdom (in my opinion), we have no fight left in most of us. People will sigh and move to another app en masse.
The issue I have with all of this is that we think a law is going to make people who break the law not break the law.
The only people who this affects is people who everyday people chatting to their family.
The ones this is claimed to be fighting don't, by and large, use WhatsApp and the like, so will make no difference to how they operate. The one off they catch who does naively use it, does not justify surveilling the entire UK.
I admire the French for collective physical action.
[1] https://www.theguardian.com/politics/2015/apr/19/spads-speci...
IMHO that's the future.
With all that connectivity you can start being much more creative about who provides your transport versus who provides your IP connectivity. VPNs are already becoming mainstream. Sounds like a positive way forward, right? The internet just routes around damage, heh, and laws that restrict what you can and can’t do can be “routed around” by terminating all your traffic in Dublin or Amsterdam.
The trouble is that as it becomes normal for British subjects to export their traffic overseas then I can’t see HM Government policy avenue going anywhere other than all out war on encryption. Again.
Will this apply to me? Do I need to ensure that no UK users are on my server?
I never anticipated this back when I set up the server. I thought that implementing strong security and privacy measures was a responsibility that I should take seriously.
I wouldn't be willing to run the server if I had to compromise people's privacy. If you don't have privacy, you might as well be on a mega-corp service.
The previous Labour government (1997-2010) introduced the Regulation of Investigatory Powers Act 2000 (https://en.m.wikipedia.org/wiki/Regulation_of_Investigatory_...), which amongst other provisions includes key disclosure rules (https://en.m.wikipedia.org/wiki/Key_disclosure_law#United_Ki...). The burden of proof in key disclosure is inverted (the accused must prove non-possession of the key or inability to decrypt), which was somewhat controversial amongst people who cared at the time (activation, i.e. actual use if RIPA III provisions, began in 2007).
The same Labour Government ran the Interception Modernisation Programme (https://en.m.wikipedia.org/wiki/Interception_Modernisation_P...) (you may recognise this or "mastering the internet" from the Snowden leaks, although IMP was not a secret) and proposed legislation to enact part of it: https://en.m.wikipedia.org/wiki/Communications_Data_Bill_200.... This never made it into law.
I think Labour are on board with this, and the senior civil service (those at the top levels who work with ministers or close to those who do) don't change in the same way US administrations do. It might be the case that this bill runs out of time in the current parliament and is not picked up by the next government (this can happen even if the same political party holds office) but the idea will be back in some form one way or another and I suspect will make it into law.
Mistakes: It could be that the purpose of your life is only to serve as a warning to others.
Australians are pretty darn compliant to bad government because their lives are really quite comfortable either way.
Signal requires a phone number. Use the fork Session that generates anonymous identifiers. https://getsession.org
Apple participated in PRISM and also requires an identifier such as an email address or phone number.
I'm not sure how I feel about any of that.
Can't they just remove any business presence in the country to free themselves from any potential legal troubles?
Basically, you only need to incorporate in UK or establish a foreign branch if you need offices in UK or want to hire someone from UK (even remotely). The only way to opt-out is to block UK users.
Define "need". If there's no legal jurisdiction, where is this "need"? If a company wants to follow the rules, sure, it will so the thing. But otherwise, is there international legal jurisdiction that covers, for example, a company in Seychelles offering e2e encrypted comms that has users in the UK? Isn't it up to the UK to put in place blocking technology or laws that prohibit specific app usage?
I'm kinda thinking about the US TikTok situation.
What if the service is free, like Signal and WhatsApp? (and TikTok)
> Define "need". If there's no legal jurisdiction,
As I have explained your country has an agreement with UK that says they do have the right to make you follow their rules if you want to trade on their market. So they can sue you and your country will say yup that’s fine they can do that. It’s a mutual agreement, so your country can do the same if some UK company decides they don’t want to pay your taxes. There are also mutual agreements about establishing foreign branches & incorporating by foreign persons or companies and UK could demand you must do that as well, if they wanted to.
If there were no diplomatic relations or the country you’re exporting services to was sanctioned then it would be illegal for you to serve or trade with any citizens of that country.
Anyway regardless as before even if you find a country that you think is safe they can still just block your IP range and remove your app, but then you’re clearly not just doing regular business—this was about actual companies operating internationally, so this is a different goalpost. I mean sure, that’s how internet works, but that was already a given.
Also unless you actually live and manage your company from Seychelles or Russia then you should be careful because there are all kinds of laws about creating fictional entities (though mostly concerning avoiding taxes) and you could still be personally liable.
> What if the service is free, like Signal and WhatsApp? (and TikTok)
Certainly WhatsApp isn’t free, you pay with ad impressions and user data. UK can demand you pay tax on that and calculate how much you make for each of their citizens. EU’s doing it already, it’s called EU Digital Tax. Signal has some crypto stuff, they might want to monetize more. Anyway it doesn’t matter, just look at GDPR and how US companies treat it for real-world analog.
Uhhm…. Brexit?
These clowns (and not just this specific bunch, the entire UK political class) did Brexit, do you really think a small thing like the feasibility of this law will stop them?
Once this is done, they'll move the law around to other countries.
> The Australian government has passed a new piece of legislation that, at its core, permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
This is NOT enforceable outside the UK any more than Chinese law enforceable outside China. If you are a messaging service, just close all your business entities in the UK and they have no more jurisdiction over you. People in the UK can still use your messaging services unless the UK decides to implement a firewall like China.
> which will destroy end-to-end encryption
I don't trust any E2E encryption unless at least the clients are open source. How do I know the NSA hasn't inserted a backdoor into WhatsApp?
And then if the clients are open source, the back doors they insert (via git pull requests?) can be removed.
For a political party that likes the cliché "tough on crime", it's kinda surprising how far on the path to accidental anarchy they are.
Unlike the metropolitan police which is utterly useless.
I want my tax money back.
I love it.
"Anarchy" is not a synonym for "chaos". It is the opposite.
Triggered am I!
Labour also likes that cliché too [1].
They're all the same.
[1] https://www.theguardian.com/politics/2021/sep/27/labour-evok...
Maybe that's why math education is being sabotaged.
Could you elaborate on what you see as "doing their job" in this context?
Based on how RIPA and it's successors in the UK have suffered from excessive use I doubt that we will be restricting this power to "sophisticated" criminals if it comes to pass.
It might help them with the dumb criminals.
Australia tried that. This must be resisted wherever it appears.
That's the problem with e2e encryption: it makes the police's job much, much more difficult.
That's the point. People have to realise that there is a real issue which does not have a simple solution.
Of course the trouble in this case is that we either have private, secure communication or we don't. There is no halfway measure available. So both locking the police out of everything and giving them complete access to everything might be simplistic non-solutions to the real issue but they might also be the only options we have on this one so a least-of-evils argument may have to prevail.
Anything that makes their job more easy will only make them more lazy.
Police work should be hard, because they have to navigate the law if they're to prosecute anyone. Lawyers love laziness, it's sloppy and steps all over lines of technicality.
Also, the legal right to violate citizens rights should never be 'made easier' by any legislation. To be on the end of state-enabled rights violations pretty much entirely ruins any trust one may have in 'the system'. And that trust seems to be increasingly valuable and decreasingly present amongst the Western populace.
Cops seem perfectly capable of doing it with the tools they have today.
So what? It should be difficult. They should have to literally send a guy to follow and literally spy on you if they want to learn a single bit of information about you. Not push a button and have your entire life revealed on their screens.
The restrictions and controls, which exist, should be an enforced legal framework. If today the police want to wiretap your phone they need a warrant, that's the control and 'difficulty', but then telcos will route your calls to them at the push of a button.
Again, the issue with e2e encryption is real and complex.
I refuse to grant them any power whatsoever by using subversive technology like encryption. Their only choice is to increase their tyranny by treating all encryption as proof of guilt, undermining the freedom of everyone, including yours. Will you tolerate the increased tyranny or will you oppose it? That is the question.
Making the job more difficult for the police costs nothing but money. To argue that we should relax our liberties to make the polices job easier, is to argue that liberty should be erasable by those willing to pay.
But corrupt politicians? That's not a bug, it's a feature.
Is that fair? The English state is not doing that are they?
Some examples are suitable to back up such a claim.
Then they detain people such as https://thegrayzone.com/2023/05/30/journalist-kit-klarenberg...
Or David Miranda (late husband of Glenn Greenwald).
Surely we believe that UK and USA are the good guys and they don't do evil stuff. That's left for Russia and China who are evil. Not like US and UK who invade and depose governments for commercial and geopolitic interests but "there's always a good excuse for it".
Point definitely made
'We' don't call it 'math', who's 'we'?
You know bad actors won’t care about your bill, I would love to see how the government is going to block an email encrypted with gpg?
Don't forget the pedophiles.
Well if the UK and other countries pass this, I guess it is back to gnupg. No way can that be restricted at this point.
it is not against the will of the people.
the opposition, NGO’s and the general public are accusing the government of moving too slowly and watering down the law. they want the law strengthened and adopted faster.
I expect many UK citizens who were given a clear explanation of what the implications of the law was (without revealing which law it is and using its cutesy name) would say they would be opposed to such a hypothetical law, and would then be surprised if you told them you’d just described the “Online Safety” bill - if they knew what it was.
Literally the way these laws get through is because there are enough uninformed and politically non-engaged people that they can slip them by.
Eventually, they may even decide that they'd like a little privacy and force their government to back down.
Yes, both parties are that bad.
The dumbest thing about this is you create a single attack vector for nation state enemies who we know now all have the facilites to exploit this.
You might as well just turn the lights off and hand Russia, China, Iran, N. Korea the keys.
This is the sort of terrible throwaway law that results from lame-duck governments.
My understanding is this bill will have cross party support and has been in development for many many years.
It might be politically expedient to abandon it at some point, but the mainstream media largely have completely ignored it and the public have little knowledge of it but at all
It's much easier to whip the right-wing into a frenzy when the government is not their natural friend.
Labour's official stance is this and related bills don't go far enough.
If I read this correctly (https://en.wikipedia.org/wiki/List_of_political_parties_in_t...) there are twelve parties in Westminster
can you elaborate?
I know it may be dreaming but as a consumer outside of UK I don’t want to be saddled with the costs via higher fees, inferior service etc. that will be necessitated to pay for the knock-on effects of this weakening of security.
I’d rather do business with companies that stay more secure and not pay this “shoddy security tax” they will impose on the industry.
"As the Online Safety Bill returns to parliament this month, polling shows overwhelming public support for tougher measures to enforce children’s safety online." "81% UK adults want senior tech managers to be appointed and held legally responsible for stopping children being harmed by social media, new polling reveals" https://www.nspcc.org.uk/about-us/news-opinion/2023/Majority...
also https://www.gov.uk/government/news/new-poll-finds-7-in-10-ad...
Although those don't mention encryption and more are asking about protecting kids from harmful content.
Here's some earlier encryption polling:
>More than half (55%) of UK adults believe the ability to detect child abuse images is more important than the right to privacy
>Only 4% say privacy should be prioritised over safety https://www.nspcc.org.uk/about-us/news-opinion/2023/Majority...
While its super illegal for anyone to talk about, literally none of the actions that were going to be taken (Atlassian threatened to move overseas and stop servicing oz, Apple/Facebook/Google all rattled sabers) eventuated. We can only assume that the backdoors have been delivered on time without complaint.
From there the cops get to use their imaginations.
Do they create a backdoor that allows them to get the data just after decryption from the end device?
Do they ask for this to happen in real time for all users and that firehose is directed at some gubment server?
Do they want the ability to unilaterally shut down the service?
Its a grab bag. If the cops are more creative than me, than we are in even worse strife.
Defending yourself legally, no matter whether there's a lot or a little evidence, is an expensive, stressful, drawn out exercise.
Sometimes the accusation is the punishment.
Not really, people have been talking in code for millennia. I wouldnt be surprised if a car company like Mercedes or Volkswagen could use their vehicles like swarm drones, relaying information between them when passing on the road, which could get data out of the UK using the cross channel ferries and eurotunnel.
There's way too much movement of people and stuff inorder to secure anything really. Even the new Apple headset can read the iris of the eye to get subconscious data out of the user when exposed to AV data, and the users wont even know they are giving out this data. Privacy? We dont have any!
Clandestine communications in cyber-denied environments Numbers stations and radio in the 21st century https://www.tandfonline.com/doi/full/10.1080/18335330.2023.2...
Number Stations https://www.youtube.com/@RingwayManchester
They'll consider it enforced if all the major companies comply.
In terms of actually having the criminals using software that complies with the law, absolutely not. Making your own program that doesn't comply isn't much of a challenge.
> The Online Safety Bill, now at the final stage before passage in the House of Lords, gives the British government the ability to force backdoors into messaging services
So it seems like purely P2P communication could still be legally encrypted.
However I believe this is due to my small social circle. Does anyone with better social skills (any at all) have a more positive experience with E2E platforms? Please help me out because I want to believe. I believe it's important for people to speak freely but I'm having trouble reconciling that with how nasty they become.
Anonymity does though.
Telegram is not E2EE.
(Unless you use secret chats, which hardly anyone does.)
The headline is false.
https://www.theguardian.com/technology/2023/jul/20/uk-survei...
(I'm including their various attempts to ban porn from the internet.)
The main one being Great Britain, plus a chunk of Ireland. There are then a number of smaller islands around the English, Welsh, and Scottish parts of Great Britain.
as a UK resident, i can safely say that we aren't going to do a single thing to stop this and we wholeheartedly deserve this and everything else the government does to strip away our rights. we are a nation of spineless cowards, do not feel bad for a single one of us.
same for NGOs. they want the government to go even further.
various members of the public have come forward accusing the government of not doing enough to protect them from the perils of the internet (there were a few tragic cases, as it’s always the case).
basically, everyone wants this, and want it sooner and strengthened.
What a time to be alive.
https://fee.org/articles/australia-s-unprecedented-encryptio...
Poland?
> and the World Wide Web
CERN is a country?
CERN is not a country. Neither is Tim Berners Lee for that matter.
> Is the whole Bletchley park history just some fairytale?
More the common mythology about Turing that gets repeated by people that never checked the details.
Bletchley Park was real and people like Bill Tutte cracked encryption methods more difficult than Enigma.
Tim Berners Lee alone, without being part of a vast group that adopted and used WWW, wasn't sufficient for WWW to take hold.
There were many proto markup attempts, he authored one but it needed soil to grow, s/soil/CERN/.
Z3?
The list really of hate crimes being committed online is endless and these are just the criminals doing this in public:
https://news.sky.com/story/teenager-jailed-for-sending-racis... https://www.bbc.co.uk/news/uk-england-merseyside-4381692 https://www.bbc.co.uk/news/uk-england-tyne-52877886
Everyone occasionally says bad things in private, so banning encryption and policing hate speech laws basically criminalises everyone.
"I'll sometimes use sarcasm as a tool to make you think harder about an opinion expressed."
I find being highly disagreeable often helps makes a point. It's find it can be hard to invoke appropriate emotional outrage with a well reasoned argument.
But, I guess values drift is a thing. My country hasn't been part of theirs for quite a long time, and I guess it has just diverged to that point.
https://www.reuters.com/article/us-mexico-telecoms-cartels-s...
Some cyber crime operations have something similar to AWS. I’ve seen it.
Apple told the US to suck lemons why would it kowtow to the UK.
If this is the case, then you have to ask, why is this bill even needed?
Seems like they'll only be stuck with their own police state friendly system.
More broadly, any backdoor built into any app can and will be exploited by bad actors. Theres no "safe" way to break end to end encryption for just the " good guys".
1. We want to be a developed country.
2. X is a developed country.
3. X does Y.
4. Therefore, we must also do Y.
We have our own GDPR. I've seen judges citing european laws in decisions. Watching other countries pass laws like this one is like getting a glimpse into the future.
The UK has been getting less relevant for years. It's why tech companies are telling it to stick its laws without concern about losing that market. So its position on encryption is becoming less relevant too. But sure it's erosion and that sucks.
Nice thought eh?
Doesn't help that Australian has some sweet FA to help one of its citizens. Weak as piss.
So why is it now so important, when since the early 90s everyone was totally happy to communicate without it?
We don't use telnet anymore, we use SSH, and for good reason. That people that have never heard of ssh have the same demands for their communications shouldn't surprise you.
https://www.saunders.co.uk/news/prosecuted-for-your-password...
to me it looks like the direction of policy in the world when it comes to the internet is pretty clear: the internet needs to be brought to heel. it needs to respect local laws, it can’t be a black box, we can’t rely on foreign/american companies to moderate.
this direction is coming mainly from voters. they feel disenfranchised from the big internet companies, they feel threatened, the internet still feels like a dangerous place. and to be fair, there are so many crimes enabled by the internet, some of them violent.
and so the public and the NGO’s make enough noise so that politicians take stock and start doing something about it.
this law is not the first law in the world to force internet companies to better moderate their content. and it won’t be the last.
but if HN folk want to change people’s view around this issue then they need to step out of this bubble and engage with people’s concerns.
because this direction of travel has been set for a while now. and it won’t change anytime soon.
what’s going to happen with this law? nothing special. it will be adopted, and there will be no consequences. just like all the other countries that did the same.
disclaimer: i’ve been on the internet since there were ~10 websites. that wild west stuff was amazing when growing up. but the cat is now out of the bag.
Comments wailed about the invasion of privacy, thin end of the wedge/normalisation of scanning etc. without any mention of the problem this tries to address.
Personally I still think the risk of encryption to children is outweighed by the risk of permanent, incontestable authoritarian regimes (in which kids aren't safe either). But effectively arguing this requires acknowledgement of the other side's concerns.
As you say, most people prioritise child safety over privacy, so these bills are going to keep happening until the rest of us make our case, acknowledge the problem and help find solutions.
But I disagree there will be no domestic consequences for this law. The UK is the home of the coverup and this places even more power in the hands of a barely accountable old boys club. It should still be opposed, but privacy activists need to better make the case why.
Find another means of resistance, ideally a nonlethal one (they bet everything on terrorism). Bunkering with a shotgun and a six-pack won't cut it anymore.
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.
First, child protection is paramount.
Second, The erosion of big tech companies' power is a benefit as far as I can see.
Third, We still have effective encryption in our hands. TLS is not going to be broken by this.
The argument that offenders will be pushed into darker corners of the internet is probably true, though I expect that will make it easier for law enforcement - take ANOM [1] as an example.
The battle I'd fight would be some kind of accountability in intelligence services.
Can you name one authoritarian regime in which child safety has been a priority? If anything the impunity of those at the top has made child trafficking worse. Your position risks giving a massive amount of power to people who have already demonstrated they can't be trusted with it, let alone with kids. Don't assume privacy activists don't care about children.
> Second, The erosion of big tech companies' power is a benefit as far as I can see.
Big tech can't read E2E communications either. This won't reduce their power.
> Third, We still have effective encryption in our hands. TLS is not going to be broken by this.
Effective against whom? If it's the authorities you don't trust then TLS is already useless.
Seriously, the UK is the home of the coverup. Sir Cyril Smith, Sir Jimmy Saville, Sir Peter Morrison, Sir Peter Hayman, Stuart Hall OBE, Rolf Harris CBE. All of them connected enough to 'put in a call to someone' and in many cases, shown to have received some police or official support. Your system sucks but you trust these people enough to give them more power?
https://en.wikipedia.org/wiki/Westminster_paedophile_dossier
https://www.reuters.com/article/us-britain-abuse-idUSKBN20J1...
https://www.theguardian.com/uk-news/2020/feb/25/police-and-p...