[HN Gopher] IT companies warn in open letter: EU wants to ban en...
       ___________________________________________________________________
        
       IT companies warn in open letter: EU wants to ban encryption
        
       Author : kseistrup
       Score  : 233 points
       Date   : 2021-04-15 20:22 UTC (2 hours ago)
        
 (HTM) web link (mailbox.org)
 (TXT) w3m dump (mailbox.org)
        
       | jmull wrote:
       | > But in the fight against child pornography, domestic
       | politicians and legislators have identified [end-to-end
       | encryption] as the core problem and would prefer to ban it.
       | 
       | There's no logic to this. These people already access banned
       | child pornography. They aren't going to hesitate to use
       | encryption to do so, banned or not.
       | 
       | The encryption tech already exists and is widely and freely
       | available and a ban doesn't change that. A ban could keep good
       | encryption out of popular, high-profile platforms. But these
       | people are already seeking out the dirty, dark corners of the
       | web, and I'm sure will have less trouble adjusting to this than
       | almost anyone else. My random guess is they will be communicating
       | and sharing images via encrypted blockchains that are ostensibly
       | (or even mainly) for something else, or some such.
        
         | prepend wrote:
         | I view it differently in that even if breaking encryption
         | allows for the arrest and wiping out of all child pornography,
         | the damage to the non-porners is too great to warrant.
         | 
         | Similar to how a jury trial requires unanimous agreement among
         | 12. This leads to some true criminals not being convicted, but
         | it provides the benefit of many more innocents not being
         | wrongfully convicted.
         | 
         | I think the "criminals will break the law anyway" is a dead end
         | as it bypasses the moral decision that society needs to make of
         | whether privacy is worth some tiny percent of evil doing.
         | 
         | One day we'll have the ability to have mental implants that
         | block bad things. Similarly, we'll need to decide whether that
         | is worth implementing if it means bad trade offs. The argument
         | isn't that criminals will skip the implants, I think the
         | important argument is whether putting implants in all the non-
         | criminals is worth the effort.
        
         | estaseuropano wrote:
         | There's no logic in it as the article misstates the acural
         | legislation and intention. Read the linked documents and its
         | pretty obvious (I left a longer comment below).
        
       | [deleted]
        
       | eointierney wrote:
       | Good luck with that EU, it's dead on arrival.
       | 
       | The day a politician tells a mathematician what to think is the
       | day a mathematician instructs a politician on how to think.
       | 
       | Real criminals have good opsec, it's part of the job. Non-
       | criminals want provable privacy and security. Deluded and
       | ignorant politicians want a PR stunt with good optics.
       | 
       | If I, as a relatively mathematical individual, employ
       | mathematical methods of communication there is literally nothing
       | any government can do about it. I can even obfuscate. Judge in
       | court tells me what for? I tell judge in court what for. Contempt
       | of court? Ab-so-fucking-lutely. Qualms? Zero. I've no dependants.
       | Fallout of jailing someone for defending their privacy? All the
       | way up to revolution. Jailing 80% of a population because they
       | know how to use a one-time-pad, or a free, libre, and open source
       | solution such as Matrix? Sure. Let me know how that works out.
       | 
       | Telephone/email/registered post your representatives today if an
       | EU citizen. Tell them to study
       | http://people.math.harvard.edu/~ctm/home/text/others/shannon...
       | 
       | Otherwise ignore this pathetic grandstanding by vacuous
       | vainglorious amadans.
        
       | o_p wrote:
       | This violates my human right to send random garbage messgages to
       | my friends
        
       | lenkite wrote:
       | What on earth is it with modern governments wanting to control
       | every aspect of citizen lives ? Why can't they just leave stuff
       | well alone. I think first world politicians and bureaucrats (and
       | second world too now) have far too much copious amounts of free
       | time in the Internet era. This is always the problem with Big
       | Govt.
        
       | agilob wrote:
       | >In the fight against child pornography
       | 
       | Can't we simply ban cameras?
        
         | dekerta wrote:
         | As crazy as that would be, it's actually a much better
         | solution. Heck, it would even be better if they wanted to ban
         | all images on the internet.
         | 
         | But of course, banning encryption isn't actually about
         | protecting children
        
         | booleandilemma wrote:
         | Ban child making itself, I say!
        
           | ngngngng wrote:
           | Bring back the Shaking Quakers
        
         | doomroot wrote:
         | This always stops people in their tracks.
        
         | bob1029 wrote:
         | Or children if we are being really serious about the whole
         | problem.
        
           | ngngngng wrote:
           | We can also implant electronic eyes in everyones skulls,
           | required by law. That way we can see if they're ever looking
           | at illegal content.
           | 
           | (this is the premise of more than one Black Mirror episode)
        
       | smoldesu wrote:
       | "Banning encryption" is such a dumb premise. If I lived in some
       | future, hellish Europe, I'd simply mail USB drives with GPG keys
       | on them to the people I love. Costs $15 if you buy the drives in
       | bulk. After that, chat away using PGP encrypted messages. Good
       | luck, EU.
        
         | estaseuropano wrote:
         | That future is not going to happen. Read the underlying
         | documents and this lobby article just misrepresents what is in
         | the actual legal/policy documents
        
         | geek_at wrote:
         | the problem is not that you won't be able to use encryption
         | (software), it's that if the police suspect you of anything and
         | you have encrypted data that you're not willing to unlock
         | you'll be punished by full extend of the law.
         | 
         | But I think that could lead to better encryption software with
         | plausible deniability like Veracrypt has
        
           | akira2501 wrote:
           | > it's that if the police suspect you of anything and you
           | have encrypted data
           | 
           | So, back to steganography, then?
        
             | mullingitover wrote:
             | One time pads are pretty great. Unbreakable with brute
             | force attacks, indistinguishable from random numbers so you
             | have plausible deniability about whether you're actually
             | storing encrypted data.
        
               | candiodari wrote:
               | Are they unbreakable by the technique actually used by
               | the average EU country though ?
               | 
               | https://en.wikipedia.org/wiki/Key_disclosure_law
               | 
               | Generally it goes like this
               | 
               | 1) you get a notice either from a judge or the police to
               | provide unspecified assistance with an investigation (you
               | are not told even 5 minutes in advance WHAT assistance,
               | and there is a default gag order: if you inform a
               | customer or ... that you handed over their info, you go
               | to jail)
               | 
               | 2) if you refuse to do something they charge you with a
               | crime, not providing encryption keys is such a crime
               | 
               | 3) look like EU "average" sentence is 2 to 5 years
               | prison, plus 50k euros
               | 
               | One time pads are obviously encrypted, meaning if you see
               | one you know they're a key to something, so if you refuse
               | to decrypt what is encrypted with them (or can't, let's
               | not pretend these people know or care about what is and
               | isn't possible beyond obvious cases like whatsapp), and a
               | police officer cares, you may very well have a choice:
               | decode or face 2 years prison. JUST for not giving a
               | police officer full access, for example, to your phone,
               | nothing else.
        
               | mullingitover wrote:
               | > One time pads are obviously encrypted
               | 
               | Not obviously - you could have a 1GB blob of encrypted
               | data, or a 1GB blob of random numbers, so there is
               | plausible deniability.
               | 
               | You're right that they're vulnerable to a rubber hose
               | attack, but it's not a slam dunk case in court.
        
               | dane-pgp wrote:
               | If your threat model includes the threat of your
               | government torturing you for information, then you don't
               | need to worry about whether they are able to decrypt your
               | data because they could just as easily plant some false
               | evidence, or simply "disappear" you.
               | 
               | Specifically on the issue of plausible deniability,
               | though, you probably don't want just a 1 GB blob of
               | random-looking data, you want a file system with various
               | levels of "secret compartments" which open up depending
               | on which key you use to open it.
               | 
               | The game theory is that this prevents the attack you
               | describe (and after which Assange named this
               | countermeasure) because you could never prove to your
               | torturers that you have given them the last key, and thus
               | you would have no reason to comply.
               | 
               | https://en.wikipedia.org/wiki/Rubberhose_%28file_system%2
               | 9
        
               | mullingitover wrote:
               | > If your threat model includes the threat of your
               | government torturing you for information, then you don't
               | need to worry about whether they are able to decrypt your
               | data because they could just as easily plant some false
               | evidence, or simply "disappear" you.
               | 
               | wrt a 'rubber hose attack' I'm really talking about
               | general coercion, not actual torture. A court could jail
               | you for contempt you until you produce the information
               | it's demanding.
        
           | upofadown wrote:
           | Just use an email server outside the EU that will not respond
           | to EU warrants. Almost all email transfers are protected by
           | TLS these days. So the authorities won't know you are using
           | encryption in the first place. If they suspect you of
           | something they would have to come to you to get your IMAP
           | password to check if your email is encrypted.
           | 
           | PGP is, as before, a technical counterargument to this sort
           | of oppression. Perhaps the powers that be need to be again
           | reminded of its existence. After all, the proposal is to
           | backdoor all encryption software. That is simply impossible.
        
           | nness wrote:
           | It seems more than a few countries already treat refusing to
           | reveal your password or keys as contempt of the court or a
           | breach in its own right:
           | 
           | https://en.wikipedia.org/wiki/Key_disclosure_law
        
           | Jenk wrote:
           | It's not that. You can already be charged with obstruction of
           | justice in many countries if you refuse to provide keys for
           | encrypted drives. This is about prohibiting encrypted
           | messaging in the first place. WhatsApp et al will be denied
           | market access, app/play store entries for all encrypted chat
           | apps will be removed or have versions shipped without
           | encryption etc.
           | 
           | The average HNer won't be that affected but the general
           | public will. Access to encryption will be greatly reduced and
           | most people won't even care or notice.
        
             | beiller wrote:
             | Does it mean that https will be turned off for all EU
             | websites? Can't wait!
        
               | hawk_ wrote:
               | or may be all the private keys need to be shared with the
               | regulator...?
        
           | intricatedetail wrote:
           | This already is a law in the UK. It is 5 years for not
           | disclosing password.
        
             | beckman466 wrote:
             | wow that is scary.
        
               | atat7024 wrote:
               | "Politics doesn't affect me" is unfortunately not true
               | these days.
        
               | oarsinsync wrote:
               | Where "these days" is "the last two decades", as far as
               | RIPA goes.
        
             | luxuryballs wrote:
             | dang so that means 5 years for forgetting your password too
        
               | CameronNemo wrote:
               | Cut to LE carrying around encrypted thumb drives to plant
               | as evidence.
        
               | colejohnson66 wrote:
               | Doesn't even need to be encrypted; It could just be
               | random data. Sufficient encryption is indistinguishable
               | from random noise.
        
             | fastball wrote:
             | Damn thank god for the 1st amendment.
        
             | gerdesj wrote:
             | The Regulation of Investigatory Powers Act 2000 -
             | https://www.legislation.gov.uk/ukpga/2000/23/contents
             | 
             | It's a bit of a beast.
        
           | Tenoke wrote:
           | >But I think that could lead to better encryption software
           | with plausible deniability like Veracrypt has
           | 
           | That works for encrypted drives and whatnot but it doesn't
           | look especially applicable for any real-time communication.
        
             | SCHiM wrote:
             | Except it is. IS used facebook for a lot of their
             | communication. Imagine a code like:
             | 
             | "Ten camels drink from the water at $some oasis".
             | 
             | Meaning:
             | 
             | "Attack $city at 10 AM tomorrow"
             | 
             | Or
             | 
             | "Meet at $place at 10 tomorrow".
             | 
             | This has been documented extensively. All was perfectly
             | legible by whoever can read conversations on facebook, but
             | the meaning is lost.
        
               | Tenoke wrote:
               | Okay, yes sure but it does seem limiting.
        
         | mnd999 wrote:
         | If they make it illegal they can just kick down your front
         | door, arrest you and take your computer and your encryption
         | keys.
        
         | StreamBright wrote:
         | First off PGP is not a great security tool, second of all the
         | EU can just stop the GPG encrypted messages at the service
         | provider level.
         | 
         | The ultimate solution against government stupidity like this is
         | a full mesh based "internet" that is based on connections
         | between homes without using an ISP. It is not going to happen
         | for obvious reasons (90% of population is non-technical for
         | starting).
        
           | prepend wrote:
           | Great is subjective but GPG is pretty good and could be
           | argued as great. It was based on "Pretty Good Protection."
           | 
           | EU can't stop GPG encrypted messages at the service provider
           | level because the content looks like any other base64 traffic
           | or can easily be made like that.
        
           | turnerc wrote:
           | > service provider level
           | 
           | I think the parent comment was going to mail such drives, and
           | good luck getting the EU to agree on blocking anything on
           | their independent providers level.
        
             | Tenoke wrote:
             | They've been pretty good at banning things at the provider
             | level. Sites in the UK seemingly get banned by everyone as
             | soon as the government requests it. Similar in Germany, and
             | they go out of their way to analyze most or enough torrent
             | data going through I believe all ISPs to detect what you
             | pirate. Doing the same for detecting encryption doesn't
             | seem farfetched.
        
               | turnerc wrote:
               | > Sites in the UK seemingly get banned by everyone as
               | soon as the government requests it
               | 
               | I live in the UK this is not correct, these are voluntary
               | agreements by ISP's and you can opt out of the default
               | filtering.
               | 
               | I think the only time something has been blocked here it
               | was due to a Court Order:
               | https://www.virginmedia.com/help/list-of-court-orders
        
               | Tenoke wrote:
               | I mean that's still a fair amount of sites. I recognize
               | and have used plenty of those.
        
         | dharmab wrote:
         | A classic: https://xkcd.com/538
         | 
         | Replace the drugs with a warrant and the wrench with the threat
         | of criminal punishment and expense of lawyer and court fees.
        
         | st_goliath wrote:
         | This kind of response saddens me every time I get it.
         | 
         | Every time governments start scaring people about pedo-
         | terrorists behind every corner and start demanding
         | censorship/mass surveillance/back doors, the standard response
         | from fellow people in tech fields seems to be "this doesn't
         | concern me, I will just do $CIRCUMVENTION".
         | 
         | It utterly misses the point. The issue here isn't a technical
         | one. If a law is proposed that you can see as morally,
         | ethically flawed and outright dangerous to society, the
         | response definitely shouldn't be to laugh it off and pretend it
         | doesn't concern you.
        
           | yoz-y wrote:
           | What are they going to do anyways? Jail everyone? Ban the
           | browser? Encryption can be developed on top of any
           | communication protocol anyways.
        
             | roywiggins wrote:
             | Require backdoors in apps available in the Apple and Google
             | App stores. That will steer loads of people away from using
             | e2ee encryption.
        
         | [deleted]
        
       | estaseuropano wrote:
       | A bit disappointed about the blind commenting here. I have just
       | read the Commission Communication (pdf linked at the top of the
       | article) and can't find anything on prohibiting encryption. They
       | write a few times about how increasing default encryption will
       | make law enforcement more difficult but the only action proposed
       | on encryption is:
       | 
       | > One of the specific initiatives under the EU Internet Forum in
       | 2020 is the creation of a technical expert process to map and
       | assess possible solutions which could allow companies to detect
       | and report child sexual abuse in end-to-end encrypted electronic
       | communications, in full respect of fundamental rights and without
       | creating new vulnerabilities criminals could exploit. Technical
       | experts from academia, industry, public authorities and civil
       | society organisations will examine possible solutions focused on
       | the device, the server and the encryption protocol that could
       | ensure the privacy and security of electronic communications and
       | the protection of children from sexual abuse and sexual
       | exploitation.
       | 
       | So they want to see what can be done without breaking encryption,
       | I guess this could be e.g. hash checks or things like that.
       | 
       | The rest of the Communication is about prevention, victim support
       | and rehabilitation, so really about pedophilia/child abuse, not
       | encryption as a main issue.
       | 
       | There is also a 3-layer-deep link[1] to a proposed new regulation
       | (=eu-wide law) which puts an obligation on providers to detect
       | and report or delete child abuse materials. No mention of
       | encryption and its just four articles if you scroll down to the
       | end, so look for yourself if that sounds problematic. The intro
       | page [2] says it actually just provides a legal base for
       | providers to scan data as another regulation that already allowed
       | this is running out. I have no specific expertise on the matter
       | but assuming that that does not seem problematic?
       | 
       | The issue seems to be that police/ courts/NGOs/... basically have
       | no chance to police as thesr networks are inaccessible and
       | extremely complex to pursue anything. Seems obvious that the onus
       | must be on the providers to do their duty - we all know what a
       | cesspit the internet can be. If Telegram doesn't delete CP (or
       | say beheading videos, calls for lynching, rape videos, ...) then
       | who could possibly do it?
       | 
       | So the legislation here is intended to give providers the legal
       | right to check content. What's the alternative? Should the
       | internet simply be lawless?
       | 
       | 1. https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=69213
       | 
       | 2. https://ec.europa.eu/digital-single-
       | market/en/news/fighting-...
        
       | fossuser wrote:
       | After reading the source material, this HN post sounds like
       | political spin bullshit that's arguing in bad faith - but it
       | would take more time than I have right now to figure out the
       | truth.
       | 
       | Edit: Here's the actual regulation in question: https://digital-
       | strategy.ec.europa.eu/en/library/interim-reg...
       | 
       | I haven't read it yet - but I'd guess my comment below that I
       | made without reading it is probably not understanding what it
       | actually proposes.
       | 
       | Edit2: Skimming it - it's not even clear to me it's about
       | encryption at all? But about allowing creating laws around
       | getting companies to participate in blocking child abuse imagery
       | (that many are already doing voluntarily)? Am I missing
       | something? I don't see anything about requiring unencrypted
       | communications of these companies. It sounds like it's even just
       | allowing certain practices that may have already been in place
       | prior to some other EU privacy law?
       | 
       | ---
       | 
       | Child abuse imagery is a real problem and though I'm sympathetic
       | to the difficulty fighting it, encryption ban is not the right
       | tradeoff.
       | 
       | FB has actually implemented something good here, basically
       | encrypted communication but users can report imagery (so a user
       | can choose to send an encrypted log of a chat to FB for review).
       | 
       | I have a friend at whatsapp and a lot of work goes into shutting
       | down groups sharing child abuse imagery and clever ways to detect
       | them even though they're encrypted (sometimes you don't even need
       | to be that clever really).
       | 
       | See this:
       | https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
       | 
       | It's possible to see this as an enormous societal problem that
       | deserves attention, _and_ think that an encryption ban is still a
       | bad idea for all the reasons technical people think it is. Like
       | most things, the policy argument here is nuanced. Just because
       | banning encryption is the wrong thing to do does not mean that
       | the child abuse imagery concern is false or misplaced.
       | 
       | I think the argument in favor of encryption becomes stronger when
       | conceding the severity of the child abuse imagery issue.
       | Dismissing it out of hand is simplistic.
        
       | anthk wrote:
       | European here. It wont happen.
        
         | oytis wrote:
         | Why? Who is going to stop it?
        
           | StavrosK wrote:
           | I'm hoping NOYB.eu.
        
             | oytis wrote:
             | Are they influential?
        
           | pojntfx wrote:
           | I _really_ hope the CCC, D64 and other lobbying groups are
           | strong enough to fight back.
        
       | mxscho wrote:
       | In times where one of the biggest messaging application providers
       | is able to leak hundreds of millions of personal records, I'd
       | rather don't want governments to make laws to expand that risk to
       | all of my private conversations as well.
        
       | oh-4-fucks-sake wrote:
       | Please forgive me if I'm misunderstanding the scope of the
       | proposal, but without a modifier "Ban E2E Encryption" would mean:
       | 
       | * Any party who is the exclusive holder of the private key of an
       | asymmetric key (and uses it) is basically in violation of the
       | proposed law(s)?
       | 
       | * So, literally, someone who uses an SSH-only server (given all
       | data-in-transit is also encrypted) is in violation of the laws
       | (given they aren't willing to provide the private key when
       | asked)?
       | 
       | * No more end-to-end encrypted communication with your attorney
       | or physician?
       | 
       | * A student project that implements a one-time-pad is illegal now
       | too?
       | 
       | * What about encryption that is e2e for all intents and purposes,
       | but is briefly decrypted, then re-encrypted on a zero-log private
       | (proxy) server as one of its hops in the round-trip?
       | 
       | * Does this mean quantum encryption is completely banned now?
       | 
       | * By that measure, quantum internet is completely illegal, no?
       | 
       | * What about the fact this means governments will have to go
       | through hoops to get a special blessing to use it--meaning
       | they'll use it less often in practice (humans)--meaning more of
       | _their_ confidential data will be snooped. How about the fact
       | that traffic that looks like e2e is probably now gov. traffic--
       | making all of that traffic a more identifiable target?
       | 
       | I'm obviously preaching to the choir here...the problems abound--
       | would love to hear more y'all hypotheticals that illustrate how
       | _garbage_ this is.
        
         | AnssiH wrote:
         | There is no real proposal to ban encryption - the title is
         | hyperbole.
         | 
         | They are looking for possible solutions to reduce child abuse
         | with the industry, not proposing anything.
         | 
         | It could still be they'll arrive at some problematic proposal
         | later on, but from my reading of the linked documents straight-
         | out breaking/banning E2E encryption is not really on the table.
        
         | [deleted]
        
       | game_the0ry wrote:
       | I have some dumb questions - how do you ban encryption? How do
       | you ban open source tools that implement encryption? Do you fine
       | and jail people who have the code on their devices? How do you
       | implement the policy of banning certain types of code? How about
       | SSH? Are corporations and banks included in the ban?
       | 
       | I don't think you can. Its like banning bitcoin - you can't
       | unless you ban the internet altogether.
       | 
       | Western lawmakers really don't understand tech or the second
       | order consequences of their actions. Do they think they get to
       | keep encryption for "national security" for themselves while the
       | citizens don't? Hello, do you realize the signal protocol is open
       | source?
       | 
       | My prediction - EU and US lawmakers die of old age before writing
       | even one definitive line of policy that would regulate
       | encryption. Or regulation fails completely, like how the EU tried
       | to regulate data collection via GDPR but we got annoying pop ups
       | instead.
       | 
       | And btw, criminals use tor, not i-message. SMH.
        
         | Threeve303 wrote:
         | Taken to an extreme, banning encryption is like criminalizing
         | math.
        
         | Quarrelsome wrote:
         | > Western lawmakers really don't understand tech or the second
         | order consequences of their actions
         | 
         | our political systems blow in terms of getting people that know
         | this stuff to legislate on it. Closest we've had to the US
         | throne was Yang (?) and I've heard him talk and I don't think
         | he's fam.
        
         | kawsper wrote:
         | You don't ban the tools, but you hold up dissidents that refuse
         | to hand over their keys in prison as contempt of court, that is
         | what happens in the UK at the moment:
         | https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...
        
         | mrtksn wrote:
         | Governments can ban anything through denying infrastructure.
         | Think alcohol regulations, you can say that "are they going to
         | ban chemistry" but as it turns out they can indeed ban
         | chemistry. You can distill alcohol at home but if you want to
         | do business through any infrastructure that's possible thanks
         | to the existence of the government(legal systems, banking etc)
         | you will have to ask for permission despite the fact that the
         | government doesn't have any influence over the laws of nature.
        
       | vages wrote:
       | I've thought about this since last year, and I can't understand
       | how this proposal has been able to survive this long. First of
       | all, the EU is very pro-business, which means it should be pro-
       | encryption. Second, the structures of its governing bodies does
       | not make it very prone to populism. Based on what I know from
       | this Kurzgesagt video: https://youtu.be/h4Uu5eyN6VU
       | 
       | Is this all some hidden plot to turn the EU into a totalitarian
       | state? I'm (half) joking, but I really can't see the motivation.
        
         | estaseuropano wrote:
         | I recommend to read the actual proposal rather than this
         | fearmongering.
        
         | Hiopl wrote:
         | I don't understand how it's in any way feasible. Do none of
         | these people own laptops with sensitive business or political
         | information? How do they think they're going to protect any of
         | it without strong encryption? Or all the sensitive data on
         | their phones or other mobile devices? How do you secure
         | anything ever against espionage without strong encryption? Have
         | these people not put _any_ thought into this?
        
           | AnssiH wrote:
           | AFAICS no one is trying to literally ban encryption, the
           | headline seems very exaggerated to me.
           | 
           | Looking at some of the EU documents linked, I don't see any
           | real intention to ban E2E encrypted communications - at most
           | the documents are saying that child abusers using E2EE is a
           | problem, or explaining various technical possibilities to try
           | to catch them (with or without breaking E2EE).
           | 
           | I'll be concerned when there is an _actual_ proposal
           | mandating backdoors or banning encryption.
        
           | TedDoesntTalk wrote:
           | I imagine exceptions will be built into the laws exempting
           | certain government agencies and businesses or types of
           | business.
        
           | SOMA_BOFH wrote:
           | They don't think the rules will apply to them.
        
         | spullara wrote:
         | I've never heard anyone, ever describe the EU as pro-business.
        
           | dane-pgp wrote:
           | Left-wing eurosceptics try to present the EU as being pro-
           | business (and anti-worker), while right-wing eurosceptics
           | believe the EU is anti-business with all its regulations
           | affecting companies.
           | 
           | It's technically possible that both sides are right in their
           | criticism, but the fact that neither side seems to
           | acknowledge the other suggests that both aren't seeing the
           | full picture.
        
       | prof-dr-ir wrote:
       | the main claim of the letter reads:
       | 
       | "the European Union plans to abolish the digital privacy of
       | correspondence."
       | 
       | to which I can only say: [citation needed]
       | 
       | In fact, as far as I know there is only a discussion piece
       | circulating with _perhaps_ some debatable wording, but there is
       | no proposed legislation whatsoever to justify this claim. (Feel
       | free to correct me, authors of the letter or others.)
       | 
       | I would think that meaningful contributions to any discussion do
       | not begin with outrageous claims.
        
       | 1123456789 wrote:
       | Everybody prepare your wireshark to get the CC details for FREE.
       | God bless "smart" PPL
        
       | Andrew_nenakhov wrote:
       | Every time Russian government introduced new measures to restrict
       | freedom of internet users, they have launched a campaign
       | explaining that _it is necessary to protect the children!!!_
       | 
       | Don't you want to protect the children, you _monsters_??!!!
        
       | silasdavis wrote:
       | There is a longstanding thread of political thought in the UK
       | about banning encryption https://www.wired.co.uk/article/uk-
       | encryption-whatsapp-amber...
        
       | always_left wrote:
       | I know we don't like when people cite child pornography as a
       | reason, but child pornography is a real issue. It is spread via
       | any and every kind of social media. Kids are groomed into sending
       | their photos online. Enforcing encryption will make it harder to
       | detect these kinds of distribution.
       | 
       | What is the answer?
        
         | jedberg wrote:
         | Better programs for kids to learn what grooming is. Better
         | training for teachers and other people who work with kids a lot
         | to see the signs of abuse. Better enforcement of child
         | pornography laws. More money for investigating child
         | pornography and trafficking.
         | 
         | But not banning encryption. Encryption is a tiny piece of the
         | child pornography puzzle and will have little effect whether it
         | exists or not.
        
         | prepend wrote:
         | Smarter kids to prevent grooming and sending pics (btw, in most
         | states this turns kids into child porn producers a more serious
         | crime than child porn viewer).
         | 
         | To stop the adults abusing kids it's hard like any other crime.
        
           | o_p wrote:
           | >in most states this turns kids into child porn producers a
           | more serious crime than child porn viewer
           | 
           | This is even worse than the OP
        
             | prepend wrote:
             | Sadly when end to end encryption gets blocked the highest
             | number of convictions will probably be 12 year olds, since
             | they are probably less likely to be able to get around
             | controls.
        
         | o_p wrote:
         | Dont let your kid videochat on the internet? Maybe?
        
           | COGlory wrote:
           | Yeah this is a parenting failure first and foremost. We don't
           | know what the magnitude of the problem is once that variable
           | is accounted for.
        
           | mothinx wrote:
           | As I concealed my first puffs on a join to my parents, I'm
           | 100% sure that my kids have access to internet without my
           | permission.
        
       | ant6n wrote:
       | So how will online banking work with encryption?
        
         | 1123456789 wrote:
         | You won't need. Everything will be 123 hackable
        
       | bscanlan wrote:
       | > Under the EU Internet Forum, the Commission has launched an
       | expert process with industry to map and preliminarily assess, by
       | the end of 2020, possible technical solutions to detect and
       | report child sexual abuse in end-to-end encrypted electronic
       | communications, and to address regulatory and operational
       | challenges and opportunities in the fight against these crimes.
       | 
       | It is a spectacular overreaction to equate this to "EU wants to
       | ban encryption". This will never happen.
        
         | matheusmoreira wrote:
         | Banning encryption, completely neutralizing and circumventing
         | the encryption... The effect is the same: the government will
         | be able to read the messages.
        
         | vages wrote:
         | If you search for the word "encrypt" in this document, you'll
         | see that they are against Facebook end-to-end encrypting
         | messenger: https://ec.europa.eu/home-
         | affairs/sites/default/files/what-w...
         | 
         | I don't think this is an overreaction.
        
           | [deleted]
        
           | hvdijk wrote:
           | The bit about Facebook's planned end-to-end encryption ends
           | with:
           | 
           | > One of the specific initiatives under the EU Internet Forum
           | in 2020 is the creation of a technical expert process to map
           | and assess possible solutions which could allow companies to
           | detect and report child sexual abuse in end-to-end encrypted
           | electronic communications, in full respect of fundamental
           | rights and without creating new vulnerabilities criminals
           | could exploit. Technical experts from academia, industry,
           | public authorities and civil society organisations will
           | examine possible solutions focused on the device, the server
           | and the encryption protocol that could ensure the privacy and
           | security of electronic communications and the protection of
           | children from sexual abuse and sexual exploitation.
           | 
           | I read this as "Okay, fine, we can't ban end-to-end
           | encryption and we cannot backdoor it. What _can_ we do? " If
           | that is what they mean, it seems a reasonable enough question
           | to ask.
        
             | matheusmoreira wrote:
             | > possible solutions focused on the device, the server and
             | the encryption protocol
             | 
             | Looks like they're going to find ways to read our messages
             | _before_ they are encrypted and sent. Why would anyone
             | continue to use a communications application that 's known
             | to do this?
        
               | AnssiH wrote:
               | > Why would anyone continue to use a communications
               | application that's known to do this?
               | 
               | Network effect. Most people are not using Whatsapp
               | because it is E2EE, they are using it because all their
               | friends are.
        
           | IanCal wrote:
           | Where do they say they are against it? Can you quote
           | precisely what you are referring to?
           | 
           | They seem to just explain the problem it causes and calls for
           | finding new approaches since current ones are made
           | ineffective.
        
           | estaseuropano wrote:
           | They are not against it, they say it makes precenting child
           | porn dissemination more difficult, which seems like a rather
           | obvious truth. They say Industry and government need to work
           | together SNF try and see what can be done about it _without
           | breaking privacy_.
           | 
           | So total opposite of how you read it.
        
           | AnssiH wrote:
           | That is not my read at all:
           | 
           | > Last year, Facebook announced plans to implement end-to-end
           | encryption by default in its instant messaging service. In
           | the absence of accompanying measures, it is estimated that
           | this could reduce the number of total reports of child sexual
           | abuse in the EU (and globally) by more than half and as much
           | as two-thirds, since the detection tools as currently used do
           | not work on end-to-end encrypted communications.
           | 
           | Seems more like stating a fact.
        
           | fossuser wrote:
           | That's not even the proposal they're talking about, this is:
           | https://digital-strategy.ec.europa.eu/en/library/interim-
           | reg...
           | 
           | Also as the other comments said, even in the one you link
           | they're discussing the true issues that exist and what to do
           | in that context.
        
         | ineptech wrote:
         | Do you imagine that this "expert process" will come up with a
         | way to preserve message privacy while also flagging which
         | messages are illegal? What else could the purpose of it be than
         | to recommend requiring providers to MITM their customers'
         | messages?
         | 
         | (Although I agree that the title should be changed to "ban
         | _end-to-end_ encryption "; certainly the suggestion that the EU
         | would try to ban encryption generally is an exaggeration)
        
           | IanCal wrote:
           | I can think of a very obvious one, identify and refuse to
           | send messages that the client app decides are child porn. No
           | intrusion.
           | 
           | Or perhaps add a counter to the account when it's detected.
           | Minimal intrusion, single flag defining the message.
           | 
           | You don't need to mitm things to implement _some_
           | mitigations.
           | 
           | Before the inevitable - a method that is not 100% reliable in
           | stopping something is not useless. Otherwise we may as well
           | make it as easy as possible to share child porn because it
           | wouldn't make a difference.
        
             | fossuser wrote:
             | FB also already proposed one where users can report
             | encrypted messages and send an unencrypted log to them from
             | their client device.
             | 
             | Since most existing child abuse imagery is reported by
             | users that see it somehow - this seems like a reasonably
             | pro-privacy way to keep the same amount of reporting.
        
       | jeffbee wrote:
       | What the EU actually proposes to do is self-contradictory. It's
       | like appointing a panel of physicists to study creation of a
       | perpetual motion machine. If there are any actual experts
       | appointed, they've vote to disband the panel immediately.
       | 
       | """Under the EU Internet Forum, the Commission has launched an
       | expert process with industry to map and preliminarily assess, by
       | the end of 2020, possible technical solutions to detect and
       | report child sexual abuse in end-to-end encrypted electronic
       | communications, and to address regulatory and operational
       | challenges and opportunities in the fight against these
       | crimes."""
        
       | dmje wrote:
       | Can someone explain to me exactly how the EU plans to ban
       | encryption? Like, what's the mechanism to stop an EU citizen
       | hosting their (whatever) in a country that does support E2E? Or
       | how, practically, you stop anyone from using X service which
       | provides strong encryption on their computer or servers at home?
       | 
       | I'm naive about such matters but from where I'm standing I can't
       | see how this is even vaguely enforceable?
        
         | IanCal wrote:
         | > Can someone explain to me exactly how the EU plans to ban
         | encryption?
         | 
         | They aren't, that's the simple answer.
        
       | o_p wrote:
       | Lets ban children
        
       | tines wrote:
       | If this ever happened/happens anywhere, a great pastime would be
       | to start sending streams of random data to people across the
       | internet. Since random data is indistinguishable (theoretically)
       | from encrypted data, I'm sure you'd waste a lot of the
       | regulators' time. You'd almost force them to ban anything that
       | _looks like_ random data, or give up on enforcing the ban on
       | cryptography altogether.
        
         | dane-pgp wrote:
         | Surely you'd need the recipient to actually save the random
         | data (unless you think that regulators are going to be breaking
         | every TLS connection and checking the contents of every
         | packet).
         | 
         | I think people already make efforts to avoid being swamped with
         | unwanted data, so anti-spam and anti-DDOS systems would
         | probably block you and delete your streams without any human
         | noticing.
        
       | notwedtm wrote:
       | Every time I see this I realize just how little people realize
       | what makes the world run around them.
       | 
       | Do they not realize that their worlds would cease to function
       | without encryption?
        
       | africanboy wrote:
       | Why this old news-not-news reappear every few months?
       | 
       | > _Is Europe about to ban E2E Encryption?_
       | 
       | > _No._
       | 
       | https://www.google.com/amp/s/techcrunch.com/2020/11/09/whats...
        
       | Tylerian wrote:
       | C'mon... as if banning cryptographic messagery services would end
       | criminals from encrypting their messages and sending the payload
       | in plain text like they were doing since internet's inception
        
       | gaius_baltar wrote:
       | Remember: every time a government cites child pornography or
       | terrorism as the reason ban cryptography or otherwise limit human
       | rights, they are just using an excuse.
        
         | CameronNemo wrote:
         | It's like banning assault rifles to prevent mobsters from
         | getting hold of them.
         | 
         | Except in this case the good being banned is just some well
         | known and distributed, cheap to copy, easy to build, easy to
         | use software.
        
           | draw_down wrote:
           | Whoops! Not allowed to say that.
        
           | Jenk wrote:
           | > It's like banning assault rifles to prevent mobsters from
           | getting hold of them.
           | 
           | Obvious bait is obvious but whatever, I'm in...
           | 
           | Is it the same, though? Is it really?
           | 
           | On one side we have literal implements of death responsible
           | for countless accidental and/or illegal deaths, and the other
           | we have some encryption software.
        
             | PartiallyTyped wrote:
             | The moment encryption becomes illegal is the moment
             | political dissidents, whistleblowers, reporters and every
             | person in between are criminals.
             | 
             | We forfeit our freedom to express any idea or thought that
             | deviates from the current list of acceptable thought
             | patterns.
             | 
             | Suddenly you and all your thoughts or actions are subject
             | to tracking by any government, any government official, any
             | corporation and any malevolect actor.
             | 
             | The government already has a monopoly on violence, what's
             | next?
        
               | Jenk wrote:
               | I think you replied to the wrong post. I'm against
               | banning encryption.
        
             | CameronNemo wrote:
             | Never said same! Just has some resemblances. As well as
             | major hilarious contrasts (hence why I chose the subject,
             | instead of cats and cat lovers).
             | 
             | I don't think a gun and cryptography should have the same
             | treatment.
        
             | robcohen wrote:
             | Countless doesn't seem totally accurate. Last I checked the
             | FBI census a few years back showed 318 deaths over a year
             | due to long guns in the United States. That includes
             | shotgun, rifle, and scary "assault" weapons.
             | 
             | Handguns on the other hand kill 100x-200x the same amount
             | of people. Seems like if gun control proponents wanted to
             | reduce harm, they'd focus on handguns first.
        
               | schoolornot wrote:
               | Aggregated stats from 2019: https://ucr.fbi.gov/crime-in-
               | the-u.s/2019/crime-in-the-u.s.-...
        
               | Jenk wrote:
               | That's _just_ murder. Doesn't include accidental deaths.
        
               | tshaddox wrote:
               | I'm not sure why you need to split your focus on handguns
               | versus long guns. I bet most gun deaths are caused by
               | right-handed people too, but that doesn't mean we should
               | focus on gun laws for right-handed people first.
        
               | hn8788 wrote:
               | Because that's what politicians do. Tons of talk about
               | banning "weapons of war" that are rarely used to kill
               | anyone, meanwhile handguns are used for murder/suicide
               | much more often, but they rarely make the news because
               | they aren't scary looking, and because the majority of
               | crimes with them are committed by minorities, so
               | Democrats don't want more restrictions on them.
               | 
               | And before anyone says it, no, that last part is not some
               | right-wing racist conspiracy. A couple of years ago in
               | Maryland, the governor wanted harsher punishments for
               | people using handguns to commit crimes because of how bad
               | gun violence is in Baltimore, and the state Democrats
               | said it was a racist policy because it would mostly
               | affect minorities. They didn't want to seem soft on gun
               | violence though, so they banned bump stocks, which have
               | never been used to commit a crime in Maryland, and which
               | the ATF says are trivial to reproduce using belt loops
               | and rubber bands.
        
               | Jenk wrote:
               | 318 > 0.
               | 
               | So yeah.. ban all guns then.
        
               | HideousKojima wrote:
               | 390 deaths from swimming pools every year in the US. 390
               | > 0, ban all swimming pools.
        
               | dghlsakjg wrote:
               | 300 + confirmed by rifle.
               | 
               | 3,000 + had no weapon type listed.
               | 
               | How confident are you that no rifles snuck into the
               | unknown weapon type.
        
             | ian-g wrote:
             | I think the point is that the people who're already on the
             | wrong side of the law will continue ignoring this new law.
             | 
             | Mobsters won't stop buying guns because they're banned.
             | Lots of people won't stop using encryption software just
             | because it's banned.
        
               | tshaddox wrote:
               | I think the hope isn't that mobsters would choose to stop
               | buying guns out of respect for the law, but rather that
               | it will literally be more difficult for mobsters to buy
               | guns because of actual enforcement of the law.
        
               | CameronNemo wrote:
               | >Lots of people won't stop using encryption software just
               | because it's banned.
               | 
               | In particular organized crime, which the government is
               | claiming to address via this policy.
        
             | debacle wrote:
             | Those implements of death have been tools of liberty,
             | stability, and safety in the hands of hundreds of millions
             | of people across the world in the last several hundred
             | years.
             | 
             | The world, under its thin, patchy veneer of peace and
             | prosperity, is still a savage place. Ask the IDF, Ukraine,
             | South Korea, etc.
        
             | matheusmoreira wrote:
             | > On one side we have literal implements of death
             | responsible for countless accidental and/or illegal deaths
             | 
             | Cars?
        
           | kajecounterhack wrote:
           | We need encryption to do peaceful things like economic
           | transactions on the internet and private conversation. We
           | don't need assault rifles for anything but murder. So no it's
           | not the same.
        
             | chad_homenim_ wrote:
             | > We don't need assault rifles
             | 
             | > need
             | 
             | Rosa Parks didn't need to sit at the front of the bus
             | either. You don't "need" to prove to anyone why you should
             | have anything. It is not up for you to decide.
        
             | marsven_422 wrote:
             | We need assault rifles to protect ourselves from the
             | government.
        
             | dheera wrote:
             | Not to mention you can't ban encryption without banning
             | freedom of speech.
             | 
             | If freedom of speech exists, freedom to speak what sounds
             | like nonsense to a bystander also exists.
        
             | jcrites wrote:
             | What do you mean by "assault rifle"? It's a term used by
             | the media but it's often misused.
             | 
             | The "scary black painted rifles" (e.g. AR-15s) that most
             | civilians own are not "assault rifles". (Note that the
             | acronym in AR-15 is ArmaLite Rifle and does not mean
             | assault rifle: see
             | https://en.wikipedia.org/wiki/ArmaLite_AR-15 ) Civilian
             | AR-15s and generic versions _are not assault rifles_.
             | 
             | The distinction is that _rifles_ like AR-15s fire one
             | bullet per trigger pull-they are just a rifle, functionally
             | the same as any hunting rifle or handgun, just larger, and
             | more accurate at longer ranges.
             | 
             | Actual "assault rifles" are distinguished by having a
             | feature called "selective fire" which switches between
             | being firing like a rifle, and firing continuously like a
             | fully-automatic "machine gun". See
             | https://en.wikipedia.org/wiki/Assault_rifle
             | 
             | Actual "machine guns" with fully automatic firing are
             | highly regulated in the US and it's not easy for a regular
             | person to obtain one. (For example, the Las Vegas shooter
             | modified a regular rifle with a "bump stock" to transform a
             | regular rifle into something that behaved like a machine
             | gun-something that has subsequently been banned.)
             | 
             | Examples of actual assault rifles are the US military's M16
             | and the AK-47. You won't see a typical civilian possess
             | these, unless they go through a special process of
             | obtaining a federal permit from the Bureau of Alcohol,
             | Tobacco, and Firearms (ATF). Because you are correct that
             | the purpose of such weapons is military warfare; and even
             | in the military, fully automatic fire in modern combat is
             | used in specific circumstances (typically as suppressive
             | fire against a large enemy force; whereas the vast majority
             | of shots taken by soldiers would be in single-shot mode).
             | 
             | However there are plenty of justifiable reasons for people
             | to possess firearms, whether rifles or handguns, such as
             | hunting, sport shooting at a range, or personal protection
             | (self-defense, assuming the attacker dies, is not murder).
             | 
             | An additional reason is that firearm ownership is protected
             | by the US Constitution in its 2nd Amendment; and one of the
             | reasons for its protection by the constitution is to ensure
             | that the population can defend itself against tyranny by
             | its own government.
             | 
             | (Read about the history of why it was added as an
             | amendment; or read the US Supreme Court decision in
             | District of Columbia v. Heller, the text of which is very
             | readable - once you get past its analysis of the language
             | and grammar of the amendment to ascertain its precise
             | meaning - and provides a history of the rationale of the
             | text and the historical reasons for its protection as a
             | right. It analyzes the language used in the Constitution
             | and other legal documents, carefully deconstructs the
             | grammar in the sentence, and concludes:
             | 
             | > (...) We start therefore with a strong presumption that
             | the Second Amendment right is exercised individually and
             | belongs to all Americans. (...)
             | 
             | There's a lot of detailed analysis that goes into the
             | definition of "arms" as being non-military weapons that
             | individuals might use for hunting or self-defense; the
             | historical protection of that right; and why it's an
             | individual right for all Americans.)
             | 
             | Read the text of the court opinion here:
             | https://www.law.cornell.edu/supct/html/07-290.ZO.html
             | 
             | I can respect people's opinion who wish that firearm
             | ownership was not permissible-it's an understandable
             | perspective, especially for those who have been affected as
             | victims by gun violence; however, the respectable path to
             | "solve" that problem is for the United States to amend its
             | constitution and modify or remove the 2nd Amendment. If
             | that's the wish of the people I can respect it. However,
             | it's hard for me to respect the "tricks" that states or
             | municipalities try to pull, such as banning guns on public
             | property (which Seattle tried to do, which was overruled by
             | the courts-helped by the Washington State Constitution's
             | pre-emption clause, which protects firearm ownership and
             | forbids municipalities from limiting that right); or states
             | like California that require a permit and make getting it
             | burdensome.
        
             | RcouF1uZ4gsC wrote:
             | I think the main thing they want to ban is end to end
             | encryption. That you really don't need. They are probably
             | fine encrypting your connections to various companies since
             | they can subpoena records
        
             | CameronNemo wrote:
             | Murder? Self defense is not murder. But again my point was
             | not that they are similar, just that they are valuable,
             | difficult to control, and law enforcement wants a monopoly
             | on them.
        
               | lexicality wrote:
               | I can understand owning a pistol for self defence, but
               | what situation does a civilian need an assault rifle in?
               | 
               | Surely it'd just get in the way massively in any kind of
               | home invasion scenario and if you end up firing it the
               | bullet will go through 3 houses and hit someone's dog
        
             | calvinmorrison wrote:
             | Crypto exists because bad actors exist. The same reason
             | Americans own guns.
        
               | cl0ne wrote:
               | Some Americans own guns for subsistence hunting as a
               | source of food.
        
               | thereare5lights wrote:
               | Didn't think of it this way but this is spot on.
               | 
               | If people could trust each other, then we wouldn't need
               | crypto in the first place. Just like if we could trust
               | others not to attack us, we wouldn't need weapons for
               | self defense.
        
               | cpursley wrote:
               | And historically the worst bad actors have been
               | governments (in terms of body count). Which is why both
               | guns and crypto help level the playing field a bit more.
        
               | gre wrote:
               | Crypto and guns exist because they are possible.
        
             | doomroot wrote:
             | What about owning an assault rifle shooting range? I think
             | those owners need assault rifles for things besides murder.
             | I get your point but try not to be an absolutist.
        
               | kokx wrote:
               | In countries where assault rifles are banned, these
               | things generally still are possible. With strict rules,
               | for example you're only allowed to have your rifle and
               | ammo at a shooting range, and psychological review of
               | everyone involved.
               | 
               | Besides all that, it very much is a hobby for people.
               | Much less a need than encryption, which is required to
               | keep simple things like ordering something online secure.
        
             | Alupis wrote:
             | > We don't need assault rifles for anything but murder.
             | 
             | We don't need encryption for anything but hiding illegal
             | activities. You have nothing to fear if you're not a
             | criminal.
             | 
             | See what I did there? Neither argument is good.
             | 
             | Just like the overwhelming majority of people that own so-
             | called Assault Rifles never use them for anything except
             | peaceful recreation - the overwhelming majority of people
             | that use encryption never use it for anything except
             | peaceful online activities.
             | 
             | Why would we ban one and not the other? Both are used by
             | criminals to commit acts _which are already illegal_.
             | Making them doubly-illegal accomplishes nothing.
        
               | catgary wrote:
               | Yeah I still remember that time a mentally ill young man
               | got their hands on encryption and senselessly murdered 50
               | people.
        
               | mustafa_pasi wrote:
               | Encryption is used by criminals and terrorists.
        
               | nulbyte wrote:
               | I don't understand this argument. They use food and
               | water, too. And roads. We never talk about banning those,
               | because the benefit to society is greater than the risk.
        
               | samstave wrote:
               | Heh. I guess if you ban encryption, then only criminals
               | will have encryption plays here - as then encrypting your
               | shit via ransom-ware will be SUPER prevalent
        
               | Kuinox wrote:
               | You need encryption to make order online without anybody
               | getting your card numbers.
        
               | nemonemo wrote:
               | I need encryption to make sure nobody is listening to my
               | sensitive conversation like legal/psychological
               | counseling. It can be actually more secure than in-person
               | conversation.
               | 
               | Recreational ones are not "needs". Your analogy seems
               | flawed.
        
               | Threeve303 wrote:
               | Imagine needing legal help during the pandemic and not
               | being able to privately speak to a lawyer without being
               | absolutely sure someone isn't going to listen in and try
               | some old fashioned parallel construction.
        
               | skissane wrote:
               | Suppose you had a choice between living in country A or
               | country B. Country A bans encryption but allows assault
               | rifles. Country B bans assault rifles but allows
               | encryption. Which would you choose?
               | 
               | I think it is obvious that country B is the better choice
               | than country A. A lot of people (including myself) have
               | zero interest in the hobby of recreational assault rifle
               | ownership. But banning encryption has the potential to
               | cause massive harm, both economic, and in terms of
               | freedom of speech and freedom of thought. If the
               | government wants to control what you say and think,
               | taking away your freedom to communicate out of the
               | government's hearing is a great first step. By contrast,
               | taking away the freedom to own assault rifles has far
               | less impact - I don't have that freedom in the country in
               | which I live, and I don't even notice it, because I have
               | no interest in owning one. But I definitely would notice
               | if the government tried to ban encryption.
        
               | saurik wrote:
               | This is a weird choice to present the reader, as it can
               | only tell you which freedom is more critical, not whether
               | they are of similar form (and, FWIW, they are at least so
               | clearly related that the United States regulates
               | encryption largely as part of arms regulations and
               | treaties).
        
               | skissane wrote:
               | Encryption seems directly related to freedom of speech,
               | freedom of thought, and privacy rights, in a way which
               | gun ownership issues are not.
               | 
               | Encryption directly protects your freedom of thought by
               | making it possible to communicate your thoughts to others
               | without the government being aware of them, hence making
               | it difficult for the government to punish you for sharing
               | those thoughts if it disapproves of them.
               | 
               | Owning a gun doesn't directly protect your freedom of
               | thought. Maybe you could argue that a gun can indirectly
               | protect your freedom of thought, since if the government
               | tries to restrict your freedom of thought, you can
               | respond by violently overthrowing the government using
               | your gun. However, in practice, that is very unlikely to
               | work - an attempt to use your gun to violently overthrow
               | the government is far more likely to result in your own
               | death (or spending the rest of your life in prison) than
               | in any actual change in the government or its behaviour.
               | Even if you had a million fellow citizens with their own
               | guns supporting you, you'd still struggle to win against
               | the tanks, fighter jets, bombers, drones, missiles, etc,
               | of a modern military.
        
               | jcrites wrote:
               | It may seem like a minor detail but there's a very
               | substantial functional difference between "rifles" and
               | "assault rifles": assault rifles can fire as fully-
               | automatic "machine guns".
               | 
               | There is no such thing as "recreational assault rifle
               | ownership". I posted in detail about this in another
               | comment [1], but "assault rifles" are machine guns and
               | are highly regulated in the United States. You can't buy
               | or own one without a special federal permit from the ATF
               | which has a high bar to get.
               | 
               | What everybody is talking about when they say "assault
               | rifle" are actually just "rifles", which function the
               | same way as other hunting rifles and handguns, merely
               | having a different form-factor. AR-15s (ArmaLite Rifles)
               | for example are just normal rifles, not assault rifles.
               | There are many variants, but plenty of AR-15s will fire
               | the same 9mm ammunition that handguns fire. (Caliber has
               | nothing to do with the classification; that's just an
               | example.)
               | 
               | I'm not even sure that individual people can legally
               | possess machine guns in the US. From what I recall you
               | essentially need to form a corporation and apply for it
               | to become a firearms dealer, and get approved; and then
               | the corporation may buy and possess them. There is very
               | limited "recreational" use of machine guns: you can go to
               | Las Vegas and pay to fire a machine gun that's mounted to
               | the ground, and whose firing angle is limited. That's
               | about the extent to which any normal person (civilian)
               | will ever legally interact with a machine gun or assault
               | rifle in the USA.
               | 
               | For those who want to use informed language to have a
               | precise discussion, please use the term "rifle" if that's
               | what you mean, and avoid using the FUD term "assault
               | rifle" (unless that's what you mean), usage of which has
               | been polluted by poor journalists and opinion-providers
               | that use sloppy language.
               | 
               | [1] https://news.ycombinator.com/item?id=26826847
        
               | arrosenberg wrote:
               | I think a large number of Americans would take the
               | opposite view.
        
               | reedjosh wrote:
               | But note how the encryption ban comes about after the
               | firearm ban in the country of discussion.
               | 
               | Firearms rights (at least in the US) were intended as
               | protection from tyrannical governments more so than even
               | self protection. Though I acknowledge that today the US
               | government is too powerful for citizens with firearms to
               | prevent any tyranny.
        
               | u801e wrote:
               | > Firearms rights (at least in the US) were intended as
               | protection from tyrannical governments more so than even
               | self protection.
               | 
               | The same argument could also apply to encryption. That
               | is, it can offer you protection from a tyrannical
               | government in addition to protecting your information
               | from criminals.
        
               | reedjosh wrote:
               | I do agree with you. I'm just pointing out that both are
               | intended as rights of a sovereign individual to protect
               | oneself from both other individuals and government.
        
         | dagss wrote:
         | Why do you say that? Do you really think that noone can have a
         | genuine interest in combating child pornography or terrorism?
         | 
         | My intuition is exactly the opposite: That many have a
         | legitimate wish to combat both child porn and terrorism. Many
         | people work with that every day and obviously they want to do a
         | good job. And one effect of limiting crypto would help that.
         | (That doesn't mean in itself crypto should be limited; but I
         | don't see how writing one side off as "just an excuse" and
         | basically offering a conspiracy theory helps anyone. Better to
         | just say "it's unfortunate about child porn and terrorism, but
         | it's the price that must be paid / here's another way to combat
         | that", if that is what you mean.)
        
           | jedberg wrote:
           | If they have a genuine interest in combating child
           | pornography or terror, they would be proposing things that
           | actually make a difference to those problems.
           | 
           | Encryption is such a small part of those crimes that it would
           | make almost no difference to the level of crime whether it
           | exists or not.
        
             | dagss wrote:
             | According to another poster, there were in fact here other
             | proposals and crypto was a small part of it. And that small
             | part was, quoting the text:
             | 
             | > One of the specific initiatives under the EU Internet
             | Forum in 2020 is the creation of a technical expert process
             | to map and assess possible solutions which could allow
             | companies to detect and report child sexual abuse in end-
             | to-end encrypted electronic communications, in full respect
             | of fundamental rights and without creating new
             | vulnerabilities criminals could exploit. Technical experts
             | from academia, industry, public authorities and civil
             | society organisations will examine possible solutions
             | focused on the device, the server and the encryption
             | protocol that could ensure the privacy and security of
             | electronic communications and the protection of children
             | from sexual abuse and sexual exploitation.
             | 
             | So -- you may say that you know that this project is
             | hopeless and a foregone conclusion. But will every
             | politician trust that -- or will they make a panel of
             | experts to explore solutions and tell them for sure that
             | you can't meaningfully limit encryption in the first place,
             | and even if you did you can't do it without violating
             | privacy, as is presumed here?
             | 
             | Don't attribute to malice what can be attributed to
             | technical ignorance.
        
           | JauntyHatAngle wrote:
           | I agree with him because of what has already happened in
           | Australia when it comes to metadata collection.
           | 
           | It was touted as anti terrorism and anti child pornography, 2
           | years after it came in the agencies that applied for (and
           | receieved) access to people's viewing habits were released,
           | and it was near every agency.
           | 
           | https://www.google.com/amp/s/amp.theguardian.com/technology/.
           | ..
        
         | gher-shyu3i wrote:
         | See also: cryptocurrencies.
        
         | notwedtm wrote:
         | Such a fitting username.
        
         | estaseuropano wrote:
         | Please read the underlying documents and not this
         | fearmongering. There is no such plan.
         | 
         | Just click the first link titled 'upcoming plans for
         | communication surveillance' and actually read the document (or
         | just CTRL-F 'encryption') to see how misleading this lobby
         | letter is. It is a communication about child porn/abuse
         | outlining measures for prevention, rehabilitation, etc. It
         | doesn't say anything about banning encryption, just as one of
         | many points it points out that increased encryption is making
         | detection of child porn/abuse difficult and that government and
         | industry should set up an expert group to discuss what can be
         | done _without breaking privacy_.
         | 
         | So total bs article. I used to be a customer at mailbox but am
         | right now very happy I moved away already...
        
           | fossuser wrote:
           | Yeah - this linked article is total bullshit, at best it's
           | misleading political spin arguing in bad faith.
           | 
           | This is the actual proposal: https://digital-
           | strategy.ec.europa.eu/en/library/interim-reg...
           | 
           | https://news.ycombinator.com/item?id=26826599
           | 
           | I think when we something that plays right into an existing
           | confirmation bias it's important to be extra skeptical of its
           | claims to offset that.
        
       | sebyx07 wrote:
       | Ban HTTPS, just must be joking. Or ban books or our minds from
       | reimplementing it? Descentralization must happen before this
        
       ___________________________________________________________________
       (page generated 2021-04-15 23:02 UTC)