UK pulls back from clash with Big Tech over private messaging
ft.com
ft.com
All the govt said was "we'll only force scanning when it's "technically feasible" to do so" - i.e. when someone believes the CSAM scanning quality is high enough beyond some given threshold. It's still scanning though, and still fundamentally undermines encryption; it's just potentialy delaying the implementation a bit... having enabled it in law. The thing we should be fighting is enabling it in law.
Politico just published an article which nailed it: https://www.politico.eu/article/whatsapp-signal-meta-faceboo...
> "On Wednesday, Whittaker and other privacy campaigners falsely claimed that London was pulling back from its bid to access encrypted messages"
Likewise, the Government has spelt out very clearly that they consider absolutely nothing to have changed: https://www.bbc.co.uk/news/technology-66716502
dang: it's almost worth flagging this thread as being based on entirely incorrect data. For whatever reason, the desire to make progress on this issue means that folks have jumped the gun and are prematurely celebrating a win which is not a win, and thus undermining the whole campaign to protect encryption.
As long as the messaging platforms don’t change their commitment then celebrating a small acknowledgement from the Government that the bill is basically unworkable is not a huge issue.
But this is the problem: the Government is NOT saying they won't actually do it. They're saying "we'll do it (when we consider it technically feasible)". The ability to force 3rd party scanning software is STILL going into law, and that's the catastrophic bit!
It's terrifying that this story has been perceived as a victory, and therefore we can take the pressure off. The OSB is STILL on track to go into law giving the government the right to tell Signal or WhatsApp or Element etc that they either need to do compulsory scanning or they are breaking the law.
I am literally receiving emails from Element customers and suppliers which begin:
> Saw that the government backed down from their plans last night and immediately thought of Element – you must be pleased!
...which just leaves me speechless. I'm almost wondering if there's a deliberate misinformation campaign here to prematurely claim victory in order to derail the attempt to protect encryption in the bill.
> "We haven't changed the bill at all," she told Times Radio.
> "If there was a situation where the mitigations that the social media providers are taking are not enough, and if after further work with the regulator they still can't demonstrate that they can meet the requirements within the bill, then the conversation about technology around encryption takes place," she said.
what could possibly go wrong
The providers can refuse.
The UK can then demand that such apps are not available in the UK.
HOWEVER ... the providers can build WASM equivalents that run in the phones browser. These can be available elsewhere in the world, and there is no way to stop UK residents from installing them. If there is no other way to have end-to-end encrypted messaging, some provider WILL offer this ... and they'll make it pretty slick. You can try prosecute each user (not much chance of success).
Legislation that fights well implemented secrecy will always eventually loose, as the government becomes just one more hostile actor, which the tech is already set up to protect against.
If the government pushes too hard, all that happens is that encrypted messaging moves out of app stores into the open internet ... and then, not only can they not see the content, they can barely see who is using it.
This is insightful. The mistake the UK government is making lies in it's naked aggression.
It's become sandwiched in hostility toward Big Tech, and the people. And it's a no win situation.
It literally wants to get in the middle, and that seems a sign of great fear of losing power in the digital age.
Fundamentally our government lack the humility to engage in meaningful, evidence-based, debate with all parties, which would be extremely difficult but necessary.
Of course encrypted messaging is already out on the open internet. It's just used for social messaging by a relative minority. The reason governments love (read: awkwardly tolerate) big platforms is they concentrate use, where they hope it can be "kept an eye on".
For me this is "Police and thieves in the street, fighting the nation with their guns and ammunition"
It's a three way fight in which the most important group - the people - are unarmed, indeed entirely excluded.
What we tried to do on https://cybershow.uk is to present some accessible banter that helps the main stakeholders - children and vulnerable people - get a better fix on the issues, and have a voice.
The only relevant part of from op is the govt acknowledging that 2+2 = 4. But it fails to acknowledge that if they want to get 5, they can still order the equation to be 3+2.
In this case it has the legitimacy, but lacks the power.
This is an unusual turn.
We need online safety for kids. The aims of this bill should obtain widespread support from everyone.
But instead of carefully researching and implementing difficult ideas, framing it properly and obtaining permission from the people - a remit to empower us to embrace online safety on our own terms - it's taken a strictly 20th Century "Mother knows best, think of the children" approach and made this a battle with Big Tech.
It is laughably "Yes, Prime-Minister" in its clumsiness. We have anachronistic throwbacks in charge.
So a solution I think we brainstormed on the show was mandating open interoperable APIs that allow easy insertion of (presumably commercial or open source) plugins into the system, within the user's end-to-end digital estate, under the control of the user (parent) and completely rejecting the MITM and endpoint compromise via back-doors that the government naively proposed.
In many ways that would take a much bigger stick to Big Tech,
It also transitions the definition of "online harms" to those defined by the guardian/parent rather than problematically allowing the State to define harms and control the selectors.
What that says to me is that the government are dishonest about the real aims of the bill.
And further, as a consequence, it crushes my belief that the government even truly care out child safety except as a vehicle to greater tyranny.
Devices only in public areas in the house. Dumbphones for emergencies.
What you're proposing would likely enable the creation of some fairly invasive stalkerware. Don't forget that 1) just because a feature says it's for use by a parent on their child's device doesn't mean that it can only be used in that context, nor that 2) not all parents have their children's best interests in mind.
Not helped by the fact that children are growing up in a completely different environment to the one their parents remember. Familiarizing myself with TikTok or whatever the kids are into these days would fill me with dread. And the way platforms work means my experience of them would differ dramatically from a child's anyway.
You don't need to. Don't give them devices until they're 16, and then implement the built in parental controls that come on every smartphone. When they are 18 and can buy their own, they can do what they want. I'm guessing your actual issue isn't familiarizing yourself with TikTok etc, but is instead facing conflict. I'm not saying it would be easy but pretending the above isn't a workable solution is self-deception.
I know some parents give their children devices for safety reasons. For others, I guess they don't want their children to be socially isolated if all the other 14 year olds are chatting on messenger.
My only point was that it can be hard, and that not everyone who fails at it is lazy. It sounds like we are mostly in agreement.
Many societal problems would be trivial if you could get perfect compliance from the population. You can't, so if you're interested in solving problems you need to be willing to grapple with the world as it is. So far as I can tell online safety has not meaningfully improved since the late 90s - "enforce safety at home" has been the advice for all of that time and it has never worked.
I don't have a solution but "blame the parents" seems to be a very clear non-answer without some plan for how to make creating safety at home more easily actionable.
I started using the Internet in 1998, and the only advice my parents gave me was "Don't reveal anything about yourself online." (Thankfully I heeded their warning and still to this day I'm very guarded about disclosing any form of PII.)
Whilst admittedly a lot has changed in the last 25 years, I'd say only half the parents will actually try to keep their kids safe online.
The other half will sit around watching crappy reality TV shows getting angry at their five-year-old children finding porn on their own personal smartphone* because they don't want to look up how to prevent them from doing that, and instead absolve that responsibility to the gov't...
...who in turn use that as an excuse to censor the Internet.
*not entirely sure why a five-year-old needs a smartphone, but anyway.
Ok, so is our answer then to abandon safety for the remaining 50% of families? Do we think that's fine, or tragic? I'm going with the latter.
I really don’t understand why Big Tech should magically stop every crime on earth: child abuse, racism, harassment, etc…
I think the supreme Zuck is a dick, but pulling out of the UK market was the right move.
When the general sentiment of the average Dave is ‘encryption === bad’ this BS will rear its head again.
Seems to have been the standard play for governments of this country for decades now.
https://www.techdirt.com/2022/01/19/uk-has-voyeuristic-new-p...
https://www.rollingstone.com/culture/culture-news/revealed-u...
All about saving the children. From everybody except Prince Andrew, it seems.
https://www.wired.com/story/apple-csam-scanning-heat-initiat...
Heat initiative is basically non existent on Google. Not much of said about how they're funded or who is apart of it
Their website is protectchildrennotabuse.org
Has a CEO with experience in running charitable orgs
They're explicitly focused on client side scanning and reporting on the iPhone.
Honestly if you're reading this archive the website and I think that's a smoking gun
Archived http://web.archive.org/web/20230000000000*/https://protectch...
All this and they're solely focused on a small corner case of 1 business and somehow their google presence is just not there.
I'll briefly summarize the back and forth heat had with apple, condensing it makes the weirdness really shine through:
Heat Initiative: "Listen up! We DEMAND that the private data of iCloud users be made accessible for CSAM scans. You are to remove it all. The guilty must be punished." Apple: "woah, slow down. We already decided against policing iCloud like that, it'd get way too Orwellian way too fast. We can use on-device Communication Safety systems to make our environment safer while respecting privacy. With features such as detection of potential nudity, we can start cutting off CSAM images and video at the source and work to prevent abuse in the first place." Heat Initiative: "apple, you make stupid money off anything you touch, you employ geniuses, you have responsibility to design a safe, privacy-forward environment that allows for the detection of known child sexual abuse images and video. Also, we really, really demand scanning iCloud." Apple: "did you just ignore what I just said or is there some deeper issue like not knowing words good. this obsession you have with scanning iCloud makes me suspect you have ulterior motives. Heat Initiative: "It's not that I ignored you, I just don't really care about this shit and can't keep up this farce. Either you let the government access iCloud or we'll say you're running 'instagram for kiddy rapists.' we will destroy you." Apple: "yeah, this conversation is over."
Something like that.
Most of the people I talk to are brainwashed anyway and will happily accept it - just give it time. The discussions over privacy always end-up with something like "I have nothing to hide anyway".
People who make that argument should be forced to have high def webcams installed in their bedrooms and bathrooms.
Guaranteed not 1 person will take you up on that.
News cycle perpetuates bitcoin == bad so everyone you know just repeats "scam" and points to criminals.
Meanwhile the largest institutions and richest people are investing heavily due to its revolutionary nature. Just look at all the ETFs coming out (Blackrock, Fidelity, etc).
Once they are fully setup you'll see the news cycle change sentiment. Rinse, repeat, with any technology.
Is that why are they investing? Do investors care if it's revolutionary or that they just get high returns?
E.g. a lot of "coins" have promised high returns that were obviously not sustainable.
Bitcoin is bad.
Even a broken clock is right twice a day....
That would depend on how it's broken.
A broken clock can be right twice a day
Transaction costs are too high to be useful medium of exchange
The waste it generates, as its central operation to have artificial scarcity is definitely bad.
Bitcoin is very bad
I think this is too often not understood or forgotten.
Maybe that's why they want to keep a provision for it in the law, but develop the technology to break (current) public-key encryption schemes themselves?
But then they'll always be chasing, as the world moves to post-quantum encryption and they won't be able to break it anymore. So it'll always remain technically unfeasible.
Its likely that from a political standpoint, it was easier to deem the bill as technically unfeasible now rather than kill it completely.
Imagine their influence if they would have stayed in the EU, and if France would have joined them (which they usually do when it comes to more governmental oversight of the executive branches of the government).
What scares me a little now is that there was a loss of balance, which is important for any democracy to make progress. And if Big Tech's reaction is always "well then we just pull out of your market(s)" then it's gonna be an empty threat after the third time.
I don't know how the reactions to these events will be like, but most likely we'll see an increase of propaganda press statements on "how bad secure messaging" is, trying to push the narrative into a different direction.
Big Tech tends to have negative connotations, nowadays. So, here the FT is trying to say that a democratically elected government is living in fear of private firms.
While it may be true that our government are now living in fear of not just Big Tech but all types of Big whatever, the fight was way beyond just big tech. Sure Big Tech helped but it still is a badly written and badly thought out think-about-the-children type law that was being fought by everyone not just big tech.
I didn't bother to read the article. Headlines are important There are other things to rage about Big Tech, this is not the one.
“everything you read in the newspapers is absolutely true, except for the rare story of which you happen to have firsthand knowledge”
Edit: actually I was thinking of the Gell-Mann Amnesia Effect. They both work though.
Both discussed in this thread:
The Conservative Party, and parties on the far right parties across the world, have left conservatism behind. Something the the left and centre parties are having to take up.
I can assure you that isn't the case. Whoever wrote that headline is a copywriting genius. The headline conveys almost the exact opposite of what really happened, without being factually wrong.
That doesn't happen by accident.
For me the headline conveyed exactly what happened...
“UK has not backed down in tech encryption row, minister says”
https://www.reuters.com/technology/uk-minister-says-position...
Also not quite democratic when the uk electorate last voted for a gov in 2019 but we have had 3 prime ministers since all with vastly different strategies, where the last 2 were chosen by anyone who wants to pay for a membership to the tory party, including fake identities made by journalists who registered from france.
If you had some context, bigtech are actually fighting to keep encryption alive and are the goodies in this story.
Context is important, so is reading. But thanks for your insight in the article you didn't read.
> UK ministers seek to allay WhatsApp and Signal concerns in encryption row
Nothing to see here folks, just a minor dispute between the Gov and two companies ...
[1] https://www.theguardian.com/media/2023/sep/06/whatsapp-signa...
There has been no discussion of the obvious national security risk.
https://www.theguardian.com/law/2022/mar/22/uk-ministers-acc...
I spent every morning moving emails with attachments to local folders on my Mac (which had no backups) to keep from going over quota. If I went on a 2 week vacation emails would start to bounce to me.
After that fiasco I understood why Colin Powell told Hillary Clinton to just run her own email server (for non-classified communication).
Doesn’t really apply when it’s the Exco board though, if they say jump then it’s the CTOs job to make it happen.
All the same benefits: end-to-end encryption and data mining.
There is no automatic integration on Android phones between SMS and another network the way iMessage is automatic.
WhatsApp is the default
Exactly, even though it is the default messaging app on Android and receives their SMS texts for them, most users don't realise they are using it or that when they "send a text" to another Android user it is actually sending the message over data.
Anyway my understanding is that a text is a SMS text, and a whatsapp is a whatsapp message. I know that Google Messages hides itself by sending SMS texts when the number isn't known to Messages, and I guess Whatsapp does this too. I also live in the UK and occupy a space within multiple different communities which insist on different messaging apps. May be I just don't the option to be so vague.
Also, how are you data mining end-to-end encrypted messages? How can you get data out of messages you can't even see the contents of?
No, the data-mining with these apps is in your list of contacts. Whatsapp takes these and builds you into a network. Its not what you say, it is who you are talking to and when. That is valuable.
When you sign up, you up load your contacts to Whatsapp. If you try to prevent it, it will insist and not work until you do. You can try to clear down your contacts and sign up without any. However, it will still take your number and look it up in the contacts of all those who have your number. It now has your name and any details your contacts have chosen to keep about you.
Whether Boris was telling the truth or not was irrelevant to my intended point.
Of course not, I'm just a random person on the Internet ;)
The problem here is that a basic loophole is being abused to defeat the spirit of the law, thus making the operation of the government less transparent. The consequences should ramp up in proportion with the level of the abuse. You're using private WhatsApp to conduct state business? Your WhatsApp chat logs should be subject to FoI. If you want to keep family chat private, then move it to Telegram, and DON'T use Telegram to conduct state business, because otherwise your Telegram chat logs are next up to be scrutinized. I don't think the "spirit" of this idea is going too far?
> military secrets
There already are established procedures and laws for dealing with state secrets, including strategic information such as submarine designs, locations, nuke launch codes, etc. Whatever FoI/transparency laws are in place, they need to respect the need for protecting state secrets - that should be pretty obvious.
I agree with you in principle, but you are fighting human nature in practice - generally no one wants to look bad in public. I think FoI legislation is important, but in practice the results have often been mixed, and the approach probably needs to be nuanced.
Do you have any examples please?
https://joinup.ec.europa.eu/collection/open-source-observato...
It's only natural that when a public servant want to make sure their message actually reaches the recipient, they would rather use a solution that 100% works. That's not malice, it's common sense.
It's confusing because you nailed "Plain-text emails" but completely ignored signed, encrypted emails for some reason.
The question is whether it's possible to actually deploy and maintain the solution in reality to millions of concurrent users in hundreds thousands of disjoint organizations in thousands of municipalities all over the country. It would require a constant supply (due to organizational churn) of highly qualified tech people who'd willing to be working years for low-five-figures salary in a rigid ineffective governmental structure, surrounded only by non-tech-savvy people. These tech people should also be saints so that they don't embezzle half the budgets while trying to set things up. Also the top visionary who'd push for this multi-year project should not be subject to election cycles.
I honestly think that this level of concentration of long-term effort might be impossible in a country with more than 10 million people or so.
That's obviously not a good thing at all, and also I would think illegal, but I guess at least it's encrypted. The irony.
Which implies that later - through the power of delusions of grandeur - that it will become feasible.
To revive this, they would have to find an expert to attest that it is technically feasible to have security with a backdoor that government can access, but at the same time is impossible for malicious entities to access.
Ergo, this is technically dead, which is the best form of dead.
> Ergo, this is technically dead, which is the best form of dead.
Except it's not. There exist such cryptographic trapdoor constructions that are perfectly secure, if the government backdoor key is kept safe.
The problem is keeping the government backdoor key safe. But that's not a literal impossible technical problem. It's much more a social problem.
Don't get me wrong, I really, really wish what you said was true and we could kill this garbage forever by nature of technical argument. But it isn't, so we must keep fighting against it for the real reason: we simply don't want this.
Anyway, I am gladly surprised they seem to back off.
https://www.pcmag.com/news/master-key-for-tsa-approved-locks...
More importantly, the thing that's technically impossible is a scheme to detect that the key has become compromised before it is used maliciously.
Microsoft, Google, Apple etc are keeping the keys that allow you to push updates secret, aren't they?
Source: sometimes interact with the UK government
There's a lot of of hopium in this thread for people who I think want it to be more impossible in practice than it really is.
Governments can provide immunity, which companies can't do. Companies try not to do these kinds of stealing, governments don't care.
If the backdoor crypto key is compromised, sure they can revoke it (assuming they manage to design a competent system), but all the sensitive information up that point is now available to whoever possesses the backdoor key. Unlike the software signing case, exploitation of the compromise is likely undetectable unless the attacker reveals their knowledge somehow.
But opponents of the OSB claim it will make communication with your bank less secure - how?
From yesterday:
> the China-Based threat actor, Storm-0558, used an acquired Microsoft account (MSA) consumer key to forge tokens to access OWA and Outlook.com. Upon identifying that the threat actor had acquired the consumer key, Microsoft performed a comprehensive technical investigation into the acquisition of the Microsoft account consumer signing key, including how it was used to access enterprise email.
— https://news.ycombinator.com/item?id=37408776
I think Microsoft’s handling of keys is almost certainly far, far more secure than anything the British government would care to achieve.
Not a problem. Just change the locks every week. [tapping head]
A big problem with this statement is the term “the government”. If you give the private key to the UK - the US, India and China will want a copy as well.
The UK might want to spy on foreign nationals only in the country and only for CSAM, but that doesn’t mean other nations won’t use it for more traditional espionage.
Key escrow for the entire US and world was floated with the Clipper chip (1993-1996). That was strangled in its crib because trusting thousands of people at NSA or GCHQ to just not stalk people is sheer fantasy, just as the Snowden leaks revealed.
iMessage stores the e2ee key in iCloud by default, which effectively makes all of a user's communications decryptable by governments and Apple at any time.
To offer a centralized service with actual privacy without zero knowledge p2p constructions, then it falls victim to the Lavabit problem. If you want security and plausible anonymity across your own devices, not metadata, then use a fork of Signal such as Session. (Signal is irreparably broken by being tied to phone number, which is a universal tracking device. The only people who use Signal are drug dealers and software engineers who don't know any better.)
I'm a software engineer who does know; I'm aware that Signal is currently tied to phone numbers, and I'd love for it not to be, but I still use it, because it's E2EE and easy for non-technical people to use.
When there's something that's easy to use like Signal that uses decentralized cryptographic identifiers and onion routes all traffic, I'll start trying to get people to use that. I'd be happy to hear any recommendations.
Session (Signal fork) doesn't use phone numbers. It's pretty well-designed overall and uses an onion routing approach. It's already a superset of Signal except it doesn't use phone numbers. https://getsession.org
Also look interesting:
* (unproven) https://www.olvid.io/technology
* (unproven) https://simplex.chat
PS: Using regular TOR on home broadband or cloud servers is relatively risky and inefficient. Sybil attacks on it are common. And to network operators and security agencies it gives an easy "flow tag" of your uplink and exit node data traffic as automatically suspicious.
It's an older reference, sir, but it checks out.
Very roughly, I assume every Whatsapp message follows something along the lines of:
1. Unencrypted input
2. Encryption
3. Encrypted transmission
4. Decryption
5. Unencrypted stream to display handler
Technically - what's to stop them from compelling Apple and Google into putting a software keyboard logger inbetween 1 & 2 and another output logger between 4 & 5?
Edit: I'm not saying this backdoor would be secure btw. Of course it wouldn't. But that seems to me a separate issue than "breaking encryption"
Dear FT, WhatsApp is not a company, the owner of the WhatsApp service is Meta Inc., also the owner of Facebook and Instagram. (It is misleading to citizens that companies can hide behind the names of their acquisitions.)
Or will they decide to believe that the powers will not be used, and keep their service in operation?
It’s really upto a few execs at tech giants betting how much money is at risk.
For UK and Canada, the state isn’t competent at building a clone of social networks with wide adoption.
China can throw insane money, regulation and Human Resources until they get what they want.
And of course the big internet companies won't complain about it because it gives them legislative capture of the web.
^ Again, in practice if not in law: since no service provider could fully identify and restrict all 'adult' material in real-time, they will be effectively unable to serve any interactive content to minors. Only if the penalties for non-compliance were low enough would the largest of companies take that risk.
I see this theory pop up around here every few months. Where does it come from? I suspect it's a meme without basis.
Can you please name one time in history where the public gets "exhausted", and as a consequence unwanted legislation is passed?
It’s not that hard to explain what would happen and any politician will understand doing something like this would be quite bad for their career.
I do agree that they will keep trying, but the chance of it happening seems slim, as there is just no way to implement this.
How could we find out? Do the reasons get leaked unofficially usually?
The Conservative party's own members tore it to shreds.
From: https://cybershow.uk/media/episodes/OSB1_r2_2023-08-27.mp3 *
"The source of the bill itself, the UK Conservative Party, has a significant number of its own critics calling it "fundamentally misdesigned" David Davis said its well-intentioned attempts may constitute "the biggest accidental curtailment of free speech in modern history."
(* sadly my other sincere comment has been buried by people who apparently can't read past the first line)
Westminster will be a worse place when he goes, which I assume will be in next year’s election.
You don’t get many MPs doing that - especially Tory ones.
Campaigning to your MP is and always has been a waste of time.
In addition, the "safer" their seat, the more of a waste of space the MP is because they know their constituents would vote for a pig if the right coloured rosette pinned to it.
Most of the time they don't bother replying, and then if they do reply, you get a two-page party political broadcast, followed by a generic paragraph about "how they understand your concern blah blah blah" but never addressing the point at hand.
IOW, as soon as backdoors are implemented. And we only have to lose this battle once.
sure, it sucks that they can't sit in their office and wiretap anyone, or might seize a phone that they can't crack. all it does mean they have to get off their asses and investigate at point-of-crime, possibly in person.
to society, the great thing about that is that direct investigation is not scalable, which means that collateral damage will be less common among the innocent and bystanders.
Imagine nuclear secrets being accessed by every grandma on the planet, that would be laughable. Or the politicians payments to their who...i mean deluxe escorts.
What do they mean? Image recognition via homomorphic encryption? “Years” feels like an understatement!
As we progress with climate change and climate disaster, it’s clear that eco terrorism is going to be increasing. This has been especially highlighted in UK.
I put it in quotes because honestly it’s just fighting for survival at this point, but the ones in charge have decided to add the word terror to make it scarier.
Personally, I don't think this is a particularly legitimate concern (and by extension, not one which I would assume the government has), since the whole point of revolutions is that they don't need to be planned; they are a groundswell of popular opinion turned violent. Even if encrypted group chats were necessary for ecological campaigning groups, I don't believe they are popular enough among the British public or violent enough to make even a minor dent in the Britain establishment.
though to your point, that form’s more of an economic weapon than it is terror.
I don't think politicians set out to do this but it's been around in some form or other in Whitehall for so long that there's no real responsibility anywhere and it was low priority enough that noone ever thought to properly kill it.
It's very British in that sense.
The basic premise is that online platforms like Facebook and X will have more legal responsibility and requirements to follow particular UK law and guidance on content that their platforms host.
This is very popular with the press and enjoys widespread public support in polling. All major political parties support it.
The encryption and scanning aspects of it are just one part of the bill.
That this will lead to a significant amount of crime is simply assumed, and not from any basis in reality. They also misuse statistics to try and make issues look larger than they are, which does a disservice when these are actually really serious issues. Like with CSAM, they always talk about so many millions of reports, without mentioning that reports are only suspected content, and the vast majority turn out not to actually be illegal (something like 70-80% of reports are discarded by law enforcement in the first pass - but it's understandable that platforms have to be extremely conservative and report anything that even looks a little like it could possibly be CSAM). Then there are massive amounts of duplication and things like that. But it is a serious issue, so it does my head in that they misuse the 'big, impressive reports number' when they know only a fraction lead to investigations, because that just gives critics a basis to show that they're massively exaggerating which could lead people to minimise the issues.
Of course, at the end of the day, you can't surveil your way to safety and these problems are best solved at the source. But that would require things like fighting poverty (oh no, welfare spending!) and deploying large numbers of social workers to help support people in marginalised communities.
Does this affect security?
There should be things the state simply cannot touch not just things which it should not touch.
Just to be clear I’m all for encryption and our right to do so, but I feel that equating this to our defence for math is a couple bridges too far?
Why?
What if society could be destroyed by performing math? Should it still be a fundamental right? What if the entire universe could be destroyed by doing math?
This reminds me of a couple episodes of The Twilight Zone and The Outer Limits. In one ("Need to Know"), there's some secret; when person A tells person B the secret, person B goes insane (and then tries to tell others the secret). Should a verbally-communicated secret be illegal? In the other, a disgruntled college student figures out how to build a small fusion bomb, and uses it for terrorism and threatens to detonate much larger versions of the bomb. At the end, he's killed and takes his secret with him, but the implication is that the principles aren't really that difficult, and sooner or later some other angry person will figure out how to make such bombs and humanity will be doomed.
they've become the biggest laughing stock in multiple other avenues anyways, you need an example for people to learn from
one look at san fransisco and people start funding their police departments again
if you want to “be done with the endless debate” then perhaps use (and contribute to) protocols/infrastructure which aren’t so easily governed.
UK politicians love WhatsApp’s end to end encryption as it allows them to evade public records laws (as well as snooping by UK spooks who have not hesitated to wiretap British Prime Ministers like Harold Wilson). Boris Johnson’s extensive use of WhatsApp specifically was in the news during the Covid inquiry.
It’s perfectly OK for the proles to lose encryption, but not for politicians.
That would be waiting for a quantum computer and quietly hoping that a) nobody develops a strong enough post-quantum scheme and b) there is still civilization after RSA and ECC are broken? Correct me if I'm wrong.
There's also the question of, if you can distribute a key which is at least the same size as your message over a secure channel - why not just distribute your message over that channel in the first place?
Latency? You can hand deliver a password ahead of time, but not messages.
You still have to reliably move a chunk of out-of-band information in a way such that it gets to (and only gets to) the person you want to have it.
Also, it isn't just a "chunk", for one-time pad it has to be the same length as the messages. Which is fine if just short messages but a lot harder if lots of data.
If can exchange lots of data, better off using them as keys for stream cipher.
But the question of, "Why not just send the message instead of the pad" is pretty straightforward: when you have the opportunity to safely deliver the pad, you don't know what the message will be. When you do know what the message will be, you don't have the opportunity to safely deliver the pad.
I read some years ago about a non quantum technique to achieve the same based on (I think) noise in a coupled electronic system. I wonder if that has been tested further.
Eg, rolling a dice is deterministic, and I imagine an algorithm exists that could recover the value of a dice throw from a recording of the sound of it rolling and it's initial position. But once that sound has turned into heat, and that heat has conducted itself about the walls and into the air, I don't think it's possible to recover the sound.
See also:
"Is flipping a coin random?" (Numberphile)
There’s nothing in the laws of physics that prohibits us turning burned paper smoke back into a document and recover the information.
When you burn a document, all the matter might be transferred into the smoke, but you've rendered it into a stream of particles which is small enough to be effected by Brownian motion. Reversing the process (figuring out the initial position of each soot particle) involves knowing the position and momentum of the air molecules impacting the soot particles. In principle, you could take the current position and momentum of those particles and extrapolate backwards - but you can't actually measure that, not even in theory.
It's like people read that OTPs are the only encryption method that has been proven to be completely unbreakable (when used correctly) and stop reading there, and then completely miss all the things OTPs don't solve (ie, guaranteeing authenticity), not to mention their massive glaring limitation: How do you transfer the encryption key?
NIST standardized Kyber and Dilithium, and for now at least, they seem to be holding up. I'd still want to do hybrid (ECC+PQ) asymmetric crypto for the time being, but we're (slowly) starting to gain a modicum of confidence in the new standards, enough for deployment
Throughout history, encryption has always been a government privilege. Only very recently, and then only in the West, practically speaking, is encryption that is safe from the eyes of government available. The liberalization of encryption has been concomitant with a naive "end of history" belief that once everyone was connected as part of a global network, we'd see an inevitable global rise in liberal forces that would make governments unable to control speech. See Bill Clinton's on "nailing Jello to the wall". Clinton whose administration did liberalize encryption quite a bit.
That "end of history" mindset was wrong. We are back in a quasi cold war, with an active proxy war on top of it and a few more smoldering. And so my prediction is that we will see a reversal to the mean of history, and cryptography become again a govt granted privilege with conditions attached. (Yes yes I know public implementations of every algorithm exist, but China showed the blueprint of the machine that nails Jello to the wall anyways.)
no, throughout history has always been the privilege of those with the ability to encrypt, which was often governments, big businesses, or in some cases very clever individuals.
with the ability to encrypt becoming simpler it follows that the cleverness of individuals to achieve it has decreased.
Electronic financial transactions (banking, e-commerce,...) and commercial communications are two main reasons we won't see this. Too much impact on the economic levels and the government already have access to this data, so it will be just cons, no pro.
You won't catch bad actors, they will move to illegal services and protocols. I think the voice of reason just prevailed and they realized that it's a bad idea. The only next step I can see is the requirement for data persistence to be done inside the country.
Government doesn't want it debated or scrutinised. Tech companies want it to go away. The media doesn't understand it and cannot communicate the issues. People are scared or too pre-polarised to take a position. It's been kicked into the long grass by 4 prime-ministers. Even mentioning here that it is complex and worth examining both sides gets one down-voted to hell (judging by my other comment).
Submitters: "Please submit the original source. If a post reports on something found on another site, submit the latter." - https://news.ycombinator.com/newsguidelines.html