Computer literacy 101: to err is human, to really foul up requires a computer.
They don't understand that by requiring the capability for going after domestic criminals, they've given a huge gift to their international adversaries' intelligence agencies. (And given this is about a computer vulnerability, "international adversaries" includes terrorists, and possibly disgruntled teenagers, not just governments).
https://techcrunch.com/2023/09/21/meredith-whittaker-reaffir...
If politicians don't understand after such campaigning, it's a choice in willful ignorance, not bad computer literacy.
If I'd known about the idea of "inferential gap" at the time, my own effort might not have been completely ignored… though probably still wouldn't have changed the end result as I still don't know how to show lawmakers that their model of how computers and software functions has led to a law that exposed them, personally, to hostile actors.
How even do you explain to people with zero computer lessons that adding a new access mechanism increases the attack surface and makes hacking easier?
The politicians seem to see computers as magic boxes, presumably in much the same way and for much the same reason that I see Westminster debates and PMQs as 650 people who never grew out of tipsy university debating society life.
(And regardless of if it is fair for me to see them that way, that makes it hard to find the right combination of words to change their minds).
You literally tell them that. That's it. As prominent tech leaders have been doing. They either choose to believe experts, or disbelieve them. Or they could get a CS major. They chose option #2. They ostensibly disbelieve experts because what they're hearing does not mesh with what they want.
But let's be honest with ourselves; it's not that they disbelieve them, or don't understand. It's that they don't care. You are giving these people way too much of a benefit of the doubt. They have the tools at their disposal to remove any ignorance.
As it's not working, QED not "that's it".
> You are giving these people way too much of a benefit of the doubt.
They're hurting their own interests in the process. If they were just hurting my interests, I'd agree with you. But this stuff increases the risk to themselves, directly. I may have even told them about https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0204 given the timing.
Neither is underestimating your enemy or making excuses for their behavior.
Indeed. I do neither, which is why I left the UK.
It would be underestimating them indeed to have remained there — I foresaw, even then, that a story equivalent to this very headline would eventually emerge.
And it would also be over-estimating myself to think that I could change them after the Act when I could not change them before the Bill.
> they'll need control later on when they start doing seriously tyrannical things.
You mean like when they start jailing people for social media posts? Or when they are going to ban kitchen knives? Or when they're going to hide a massive gang rape scandal because it makes them look bad? Or when they would convict 900+ people on false charges of fraud because they couldn't admit their computer system was broken? Come on, we all know this is not possible.
Many politicians are individuals without any talent who desire power and control, politics is the only avenue open to people like that.
I used to think it was illiteracy, but when you hear politicians talk about this you realise more often than not they're not completely naive and can speak to the concerns people have, but fundamentally their calculation here is that privacy doesn't really matter that much and when your argument for not breaking encryption based around the right to privacy you're not going to convince them to care.
You see a similar thing in the UK (and Europe generally) with freedom of speech. Politicians here understand why freedom of speech is important and why people some oppose blasphemy laws, but that doesn't mean you can just burn a bible in the UK without being arrested for a hate crime because fundamentally our politicians (and most people in the UK) believe freedom from offence is more important than freedom of speech.
When values are misaligned (safety > privacy) you can't win arguments by simply appealing to the importance of privacy or freedom of speech. UK values are very authoritarian these days.
I oppose that because end to end encryption is still possible by anyone with something to hide, it is trivial to implement. I think governments should just take the L in the interest of freedom.
Traditional warrants couldn't retroactively capture historical realtime communications because that stuff wasn't traditionally recorded to begin with.
> It isn’t necessarily about mass surveillance and the implementation could prevent mass surveillance but allow warrants.
The implementation that allows this is the one where executing a warrant has a high inherent cost, e.g. because they have to physically plant a bug on the device. If you can tap any device from the server then you can tap every device from the server (and so can anyone who can compromise the server).
Which is why the clients have to be doing the encryption themselves in a documented way that establishes the server can't be doing that.
governments should just take the L in the interest of freedom
This was written into the US constitution. Unfortunately, most either don't know or care that it's all but ignored in practice.