[HN Gopher] IT companies warn in open letter: EU wants to ban en...
___________________________________________________________________
IT companies warn in open letter: EU wants to ban encryption
Author : kseistrup
Score : 233 points
Date : 2021-04-15 20:22 UTC (2 hours ago)
(HTM) web link (mailbox.org)
(TXT) w3m dump (mailbox.org)
| jmull wrote:
| > But in the fight against child pornography, domestic
| politicians and legislators have identified [end-to-end
| encryption] as the core problem and would prefer to ban it.
|
| There's no logic to this. These people already access banned
| child pornography. They aren't going to hesitate to use
| encryption to do so, banned or not.
|
| The encryption tech already exists and is widely and freely
| available and a ban doesn't change that. A ban could keep good
| encryption out of popular, high-profile platforms. But these
| people are already seeking out the dirty, dark corners of the
| web, and I'm sure will have less trouble adjusting to this than
| almost anyone else. My random guess is they will be communicating
| and sharing images via encrypted blockchains that are ostensibly
| (or even mainly) for something else, or some such.
| prepend wrote:
| I view it differently in that even if breaking encryption
| allows for the arrest and wiping out of all child pornography,
| the damage to the non-porners is too great to warrant.
|
| Similar to how a jury trial requires unanimous agreement among
| 12. This leads to some true criminals not being convicted, but
| it provides the benefit of many more innocents not being
| wrongfully convicted.
|
| I think the "criminals will break the law anyway" is a dead end
| as it bypasses the moral decision that society needs to make of
| whether privacy is worth some tiny percent of evil doing.
|
| One day we'll have the ability to have mental implants that
| block bad things. Similarly, we'll need to decide whether that
| is worth implementing if it means bad trade offs. The argument
| isn't that criminals will skip the implants, I think the
| important argument is whether putting implants in all the non-
| criminals is worth the effort.
| estaseuropano wrote:
| There's no logic in it as the article misstates the acural
| legislation and intention. Read the linked documents and its
| pretty obvious (I left a longer comment below).
| [deleted]
| eointierney wrote:
| Good luck with that EU, it's dead on arrival.
|
| The day a politician tells a mathematician what to think is the
| day a mathematician instructs a politician on how to think.
|
| Real criminals have good opsec, it's part of the job. Non-
| criminals want provable privacy and security. Deluded and
| ignorant politicians want a PR stunt with good optics.
|
| If I, as a relatively mathematical individual, employ
| mathematical methods of communication there is literally nothing
| any government can do about it. I can even obfuscate. Judge in
| court tells me what for? I tell judge in court what for. Contempt
| of court? Ab-so-fucking-lutely. Qualms? Zero. I've no dependants.
| Fallout of jailing someone for defending their privacy? All the
| way up to revolution. Jailing 80% of a population because they
| know how to use a one-time-pad, or a free, libre, and open source
| solution such as Matrix? Sure. Let me know how that works out.
|
| Telephone/email/registered post your representatives today if an
| EU citizen. Tell them to study
| http://people.math.harvard.edu/~ctm/home/text/others/shannon...
|
| Otherwise ignore this pathetic grandstanding by vacuous
| vainglorious amadans.
| o_p wrote:
| This violates my human right to send random garbage messgages to
| my friends
| lenkite wrote:
| What on earth is it with modern governments wanting to control
| every aspect of citizen lives ? Why can't they just leave stuff
| well alone. I think first world politicians and bureaucrats (and
| second world too now) have far too much copious amounts of free
| time in the Internet era. This is always the problem with Big
| Govt.
| agilob wrote:
| >In the fight against child pornography
|
| Can't we simply ban cameras?
| dekerta wrote:
| As crazy as that would be, it's actually a much better
| solution. Heck, it would even be better if they wanted to ban
| all images on the internet.
|
| But of course, banning encryption isn't actually about
| protecting children
| booleandilemma wrote:
| Ban child making itself, I say!
| ngngngng wrote:
| Bring back the Shaking Quakers
| doomroot wrote:
| This always stops people in their tracks.
| bob1029 wrote:
| Or children if we are being really serious about the whole
| problem.
| ngngngng wrote:
| We can also implant electronic eyes in everyones skulls,
| required by law. That way we can see if they're ever looking
| at illegal content.
|
| (this is the premise of more than one Black Mirror episode)
| smoldesu wrote:
| "Banning encryption" is such a dumb premise. If I lived in some
| future, hellish Europe, I'd simply mail USB drives with GPG keys
| on them to the people I love. Costs $15 if you buy the drives in
| bulk. After that, chat away using PGP encrypted messages. Good
| luck, EU.
| estaseuropano wrote:
| That future is not going to happen. Read the underlying
| documents and this lobby article just misrepresents what is in
| the actual legal/policy documents
| geek_at wrote:
| the problem is not that you won't be able to use encryption
| (software), it's that if the police suspect you of anything and
| you have encrypted data that you're not willing to unlock
| you'll be punished by full extend of the law.
|
| But I think that could lead to better encryption software with
| plausible deniability like Veracrypt has
| akira2501 wrote:
| > it's that if the police suspect you of anything and you
| have encrypted data
|
| So, back to steganography, then?
| mullingitover wrote:
| One time pads are pretty great. Unbreakable with brute
| force attacks, indistinguishable from random numbers so you
| have plausible deniability about whether you're actually
| storing encrypted data.
| candiodari wrote:
| Are they unbreakable by the technique actually used by
| the average EU country though ?
|
| https://en.wikipedia.org/wiki/Key_disclosure_law
|
| Generally it goes like this
|
| 1) you get a notice either from a judge or the police to
| provide unspecified assistance with an investigation (you
| are not told even 5 minutes in advance WHAT assistance,
| and there is a default gag order: if you inform a
| customer or ... that you handed over their info, you go
| to jail)
|
| 2) if you refuse to do something they charge you with a
| crime, not providing encryption keys is such a crime
|
| 3) look like EU "average" sentence is 2 to 5 years
| prison, plus 50k euros
|
| One time pads are obviously encrypted, meaning if you see
| one you know they're a key to something, so if you refuse
| to decrypt what is encrypted with them (or can't, let's
| not pretend these people know or care about what is and
| isn't possible beyond obvious cases like whatsapp), and a
| police officer cares, you may very well have a choice:
| decode or face 2 years prison. JUST for not giving a
| police officer full access, for example, to your phone,
| nothing else.
| mullingitover wrote:
| > One time pads are obviously encrypted
|
| Not obviously - you could have a 1GB blob of encrypted
| data, or a 1GB blob of random numbers, so there is
| plausible deniability.
|
| You're right that they're vulnerable to a rubber hose
| attack, but it's not a slam dunk case in court.
| dane-pgp wrote:
| If your threat model includes the threat of your
| government torturing you for information, then you don't
| need to worry about whether they are able to decrypt your
| data because they could just as easily plant some false
| evidence, or simply "disappear" you.
|
| Specifically on the issue of plausible deniability,
| though, you probably don't want just a 1 GB blob of
| random-looking data, you want a file system with various
| levels of "secret compartments" which open up depending
| on which key you use to open it.
|
| The game theory is that this prevents the attack you
| describe (and after which Assange named this
| countermeasure) because you could never prove to your
| torturers that you have given them the last key, and thus
| you would have no reason to comply.
|
| https://en.wikipedia.org/wiki/Rubberhose_%28file_system%2
| 9
| mullingitover wrote:
| > If your threat model includes the threat of your
| government torturing you for information, then you don't
| need to worry about whether they are able to decrypt your
| data because they could just as easily plant some false
| evidence, or simply "disappear" you.
|
| wrt a 'rubber hose attack' I'm really talking about
| general coercion, not actual torture. A court could jail
| you for contempt you until you produce the information
| it's demanding.
| upofadown wrote:
| Just use an email server outside the EU that will not respond
| to EU warrants. Almost all email transfers are protected by
| TLS these days. So the authorities won't know you are using
| encryption in the first place. If they suspect you of
| something they would have to come to you to get your IMAP
| password to check if your email is encrypted.
|
| PGP is, as before, a technical counterargument to this sort
| of oppression. Perhaps the powers that be need to be again
| reminded of its existence. After all, the proposal is to
| backdoor all encryption software. That is simply impossible.
| nness wrote:
| It seems more than a few countries already treat refusing to
| reveal your password or keys as contempt of the court or a
| breach in its own right:
|
| https://en.wikipedia.org/wiki/Key_disclosure_law
| Jenk wrote:
| It's not that. You can already be charged with obstruction of
| justice in many countries if you refuse to provide keys for
| encrypted drives. This is about prohibiting encrypted
| messaging in the first place. WhatsApp et al will be denied
| market access, app/play store entries for all encrypted chat
| apps will be removed or have versions shipped without
| encryption etc.
|
| The average HNer won't be that affected but the general
| public will. Access to encryption will be greatly reduced and
| most people won't even care or notice.
| beiller wrote:
| Does it mean that https will be turned off for all EU
| websites? Can't wait!
| hawk_ wrote:
| or may be all the private keys need to be shared with the
| regulator...?
| intricatedetail wrote:
| This already is a law in the UK. It is 5 years for not
| disclosing password.
| beckman466 wrote:
| wow that is scary.
| atat7024 wrote:
| "Politics doesn't affect me" is unfortunately not true
| these days.
| oarsinsync wrote:
| Where "these days" is "the last two decades", as far as
| RIPA goes.
| luxuryballs wrote:
| dang so that means 5 years for forgetting your password too
| CameronNemo wrote:
| Cut to LE carrying around encrypted thumb drives to plant
| as evidence.
| colejohnson66 wrote:
| Doesn't even need to be encrypted; It could just be
| random data. Sufficient encryption is indistinguishable
| from random noise.
| fastball wrote:
| Damn thank god for the 1st amendment.
| gerdesj wrote:
| The Regulation of Investigatory Powers Act 2000 -
| https://www.legislation.gov.uk/ukpga/2000/23/contents
|
| It's a bit of a beast.
| Tenoke wrote:
| >But I think that could lead to better encryption software
| with plausible deniability like Veracrypt has
|
| That works for encrypted drives and whatnot but it doesn't
| look especially applicable for any real-time communication.
| SCHiM wrote:
| Except it is. IS used facebook for a lot of their
| communication. Imagine a code like:
|
| "Ten camels drink from the water at $some oasis".
|
| Meaning:
|
| "Attack $city at 10 AM tomorrow"
|
| Or
|
| "Meet at $place at 10 tomorrow".
|
| This has been documented extensively. All was perfectly
| legible by whoever can read conversations on facebook, but
| the meaning is lost.
| Tenoke wrote:
| Okay, yes sure but it does seem limiting.
| mnd999 wrote:
| If they make it illegal they can just kick down your front
| door, arrest you and take your computer and your encryption
| keys.
| StreamBright wrote:
| First off PGP is not a great security tool, second of all the
| EU can just stop the GPG encrypted messages at the service
| provider level.
|
| The ultimate solution against government stupidity like this is
| a full mesh based "internet" that is based on connections
| between homes without using an ISP. It is not going to happen
| for obvious reasons (90% of population is non-technical for
| starting).
| prepend wrote:
| Great is subjective but GPG is pretty good and could be
| argued as great. It was based on "Pretty Good Protection."
|
| EU can't stop GPG encrypted messages at the service provider
| level because the content looks like any other base64 traffic
| or can easily be made like that.
| turnerc wrote:
| > service provider level
|
| I think the parent comment was going to mail such drives, and
| good luck getting the EU to agree on blocking anything on
| their independent providers level.
| Tenoke wrote:
| They've been pretty good at banning things at the provider
| level. Sites in the UK seemingly get banned by everyone as
| soon as the government requests it. Similar in Germany, and
| they go out of their way to analyze most or enough torrent
| data going through I believe all ISPs to detect what you
| pirate. Doing the same for detecting encryption doesn't
| seem farfetched.
| turnerc wrote:
| > Sites in the UK seemingly get banned by everyone as
| soon as the government requests it
|
| I live in the UK this is not correct, these are voluntary
| agreements by ISP's and you can opt out of the default
| filtering.
|
| I think the only time something has been blocked here it
| was due to a Court Order:
| https://www.virginmedia.com/help/list-of-court-orders
| Tenoke wrote:
| I mean that's still a fair amount of sites. I recognize
| and have used plenty of those.
| dharmab wrote:
| A classic: https://xkcd.com/538
|
| Replace the drugs with a warrant and the wrench with the threat
| of criminal punishment and expense of lawyer and court fees.
| st_goliath wrote:
| This kind of response saddens me every time I get it.
|
| Every time governments start scaring people about pedo-
| terrorists behind every corner and start demanding
| censorship/mass surveillance/back doors, the standard response
| from fellow people in tech fields seems to be "this doesn't
| concern me, I will just do $CIRCUMVENTION".
|
| It utterly misses the point. The issue here isn't a technical
| one. If a law is proposed that you can see as morally,
| ethically flawed and outright dangerous to society, the
| response definitely shouldn't be to laugh it off and pretend it
| doesn't concern you.
| yoz-y wrote:
| What are they going to do anyways? Jail everyone? Ban the
| browser? Encryption can be developed on top of any
| communication protocol anyways.
| roywiggins wrote:
| Require backdoors in apps available in the Apple and Google
| App stores. That will steer loads of people away from using
| e2ee encryption.
| [deleted]
| estaseuropano wrote:
| A bit disappointed about the blind commenting here. I have just
| read the Commission Communication (pdf linked at the top of the
| article) and can't find anything on prohibiting encryption. They
| write a few times about how increasing default encryption will
| make law enforcement more difficult but the only action proposed
| on encryption is:
|
| > One of the specific initiatives under the EU Internet Forum in
| 2020 is the creation of a technical expert process to map and
| assess possible solutions which could allow companies to detect
| and report child sexual abuse in end-to-end encrypted electronic
| communications, in full respect of fundamental rights and without
| creating new vulnerabilities criminals could exploit. Technical
| experts from academia, industry, public authorities and civil
| society organisations will examine possible solutions focused on
| the device, the server and the encryption protocol that could
| ensure the privacy and security of electronic communications and
| the protection of children from sexual abuse and sexual
| exploitation.
|
| So they want to see what can be done without breaking encryption,
| I guess this could be e.g. hash checks or things like that.
|
| The rest of the Communication is about prevention, victim support
| and rehabilitation, so really about pedophilia/child abuse, not
| encryption as a main issue.
|
| There is also a 3-layer-deep link[1] to a proposed new regulation
| (=eu-wide law) which puts an obligation on providers to detect
| and report or delete child abuse materials. No mention of
| encryption and its just four articles if you scroll down to the
| end, so look for yourself if that sounds problematic. The intro
| page [2] says it actually just provides a legal base for
| providers to scan data as another regulation that already allowed
| this is running out. I have no specific expertise on the matter
| but assuming that that does not seem problematic?
|
| The issue seems to be that police/ courts/NGOs/... basically have
| no chance to police as thesr networks are inaccessible and
| extremely complex to pursue anything. Seems obvious that the onus
| must be on the providers to do their duty - we all know what a
| cesspit the internet can be. If Telegram doesn't delete CP (or
| say beheading videos, calls for lynching, rape videos, ...) then
| who could possibly do it?
|
| So the legislation here is intended to give providers the legal
| right to check content. What's the alternative? Should the
| internet simply be lawless?
|
| 1. https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=69213
|
| 2. https://ec.europa.eu/digital-single-
| market/en/news/fighting-...
| fossuser wrote:
| After reading the source material, this HN post sounds like
| political spin bullshit that's arguing in bad faith - but it
| would take more time than I have right now to figure out the
| truth.
|
| Edit: Here's the actual regulation in question: https://digital-
| strategy.ec.europa.eu/en/library/interim-reg...
|
| I haven't read it yet - but I'd guess my comment below that I
| made without reading it is probably not understanding what it
| actually proposes.
|
| Edit2: Skimming it - it's not even clear to me it's about
| encryption at all? But about allowing creating laws around
| getting companies to participate in blocking child abuse imagery
| (that many are already doing voluntarily)? Am I missing
| something? I don't see anything about requiring unencrypted
| communications of these companies. It sounds like it's even just
| allowing certain practices that may have already been in place
| prior to some other EU privacy law?
|
| ---
|
| Child abuse imagery is a real problem and though I'm sympathetic
| to the difficulty fighting it, encryption ban is not the right
| tradeoff.
|
| FB has actually implemented something good here, basically
| encrypted communication but users can report imagery (so a user
| can choose to send an encrypted log of a chat to FB for review).
|
| I have a friend at whatsapp and a lot of work goes into shutting
| down groups sharing child abuse imagery and clever ways to detect
| them even though they're encrypted (sometimes you don't even need
| to be that clever really).
|
| See this:
| https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
|
| It's possible to see this as an enormous societal problem that
| deserves attention, _and_ think that an encryption ban is still a
| bad idea for all the reasons technical people think it is. Like
| most things, the policy argument here is nuanced. Just because
| banning encryption is the wrong thing to do does not mean that
| the child abuse imagery concern is false or misplaced.
|
| I think the argument in favor of encryption becomes stronger when
| conceding the severity of the child abuse imagery issue.
| Dismissing it out of hand is simplistic.
| anthk wrote:
| European here. It wont happen.
| oytis wrote:
| Why? Who is going to stop it?
| StavrosK wrote:
| I'm hoping NOYB.eu.
| oytis wrote:
| Are they influential?
| pojntfx wrote:
| I _really_ hope the CCC, D64 and other lobbying groups are
| strong enough to fight back.
| mxscho wrote:
| In times where one of the biggest messaging application providers
| is able to leak hundreds of millions of personal records, I'd
| rather don't want governments to make laws to expand that risk to
| all of my private conversations as well.
| oh-4-fucks-sake wrote:
| Please forgive me if I'm misunderstanding the scope of the
| proposal, but without a modifier "Ban E2E Encryption" would mean:
|
| * Any party who is the exclusive holder of the private key of an
| asymmetric key (and uses it) is basically in violation of the
| proposed law(s)?
|
| * So, literally, someone who uses an SSH-only server (given all
| data-in-transit is also encrypted) is in violation of the laws
| (given they aren't willing to provide the private key when
| asked)?
|
| * No more end-to-end encrypted communication with your attorney
| or physician?
|
| * A student project that implements a one-time-pad is illegal now
| too?
|
| * What about encryption that is e2e for all intents and purposes,
| but is briefly decrypted, then re-encrypted on a zero-log private
| (proxy) server as one of its hops in the round-trip?
|
| * Does this mean quantum encryption is completely banned now?
|
| * By that measure, quantum internet is completely illegal, no?
|
| * What about the fact this means governments will have to go
| through hoops to get a special blessing to use it--meaning
| they'll use it less often in practice (humans)--meaning more of
| _their_ confidential data will be snooped. How about the fact
| that traffic that looks like e2e is probably now gov. traffic--
| making all of that traffic a more identifiable target?
|
| I'm obviously preaching to the choir here...the problems abound--
| would love to hear more y'all hypotheticals that illustrate how
| _garbage_ this is.
| AnssiH wrote:
| There is no real proposal to ban encryption - the title is
| hyperbole.
|
| They are looking for possible solutions to reduce child abuse
| with the industry, not proposing anything.
|
| It could still be they'll arrive at some problematic proposal
| later on, but from my reading of the linked documents straight-
| out breaking/banning E2E encryption is not really on the table.
| [deleted]
| game_the0ry wrote:
| I have some dumb questions - how do you ban encryption? How do
| you ban open source tools that implement encryption? Do you fine
| and jail people who have the code on their devices? How do you
| implement the policy of banning certain types of code? How about
| SSH? Are corporations and banks included in the ban?
|
| I don't think you can. Its like banning bitcoin - you can't
| unless you ban the internet altogether.
|
| Western lawmakers really don't understand tech or the second
| order consequences of their actions. Do they think they get to
| keep encryption for "national security" for themselves while the
| citizens don't? Hello, do you realize the signal protocol is open
| source?
|
| My prediction - EU and US lawmakers die of old age before writing
| even one definitive line of policy that would regulate
| encryption. Or regulation fails completely, like how the EU tried
| to regulate data collection via GDPR but we got annoying pop ups
| instead.
|
| And btw, criminals use tor, not i-message. SMH.
| Threeve303 wrote:
| Taken to an extreme, banning encryption is like criminalizing
| math.
| Quarrelsome wrote:
| > Western lawmakers really don't understand tech or the second
| order consequences of their actions
|
| our political systems blow in terms of getting people that know
| this stuff to legislate on it. Closest we've had to the US
| throne was Yang (?) and I've heard him talk and I don't think
| he's fam.
| kawsper wrote:
| You don't ban the tools, but you hold up dissidents that refuse
| to hand over their keys in prison as contempt of court, that is
| what happens in the UK at the moment:
| https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...
| mrtksn wrote:
| Governments can ban anything through denying infrastructure.
| Think alcohol regulations, you can say that "are they going to
| ban chemistry" but as it turns out they can indeed ban
| chemistry. You can distill alcohol at home but if you want to
| do business through any infrastructure that's possible thanks
| to the existence of the government(legal systems, banking etc)
| you will have to ask for permission despite the fact that the
| government doesn't have any influence over the laws of nature.
| vages wrote:
| I've thought about this since last year, and I can't understand
| how this proposal has been able to survive this long. First of
| all, the EU is very pro-business, which means it should be pro-
| encryption. Second, the structures of its governing bodies does
| not make it very prone to populism. Based on what I know from
| this Kurzgesagt video: https://youtu.be/h4Uu5eyN6VU
|
| Is this all some hidden plot to turn the EU into a totalitarian
| state? I'm (half) joking, but I really can't see the motivation.
| estaseuropano wrote:
| I recommend to read the actual proposal rather than this
| fearmongering.
| Hiopl wrote:
| I don't understand how it's in any way feasible. Do none of
| these people own laptops with sensitive business or political
| information? How do they think they're going to protect any of
| it without strong encryption? Or all the sensitive data on
| their phones or other mobile devices? How do you secure
| anything ever against espionage without strong encryption? Have
| these people not put _any_ thought into this?
| AnssiH wrote:
| AFAICS no one is trying to literally ban encryption, the
| headline seems very exaggerated to me.
|
| Looking at some of the EU documents linked, I don't see any
| real intention to ban E2E encrypted communications - at most
| the documents are saying that child abusers using E2EE is a
| problem, or explaining various technical possibilities to try
| to catch them (with or without breaking E2EE).
|
| I'll be concerned when there is an _actual_ proposal
| mandating backdoors or banning encryption.
| TedDoesntTalk wrote:
| I imagine exceptions will be built into the laws exempting
| certain government agencies and businesses or types of
| business.
| SOMA_BOFH wrote:
| They don't think the rules will apply to them.
| spullara wrote:
| I've never heard anyone, ever describe the EU as pro-business.
| dane-pgp wrote:
| Left-wing eurosceptics try to present the EU as being pro-
| business (and anti-worker), while right-wing eurosceptics
| believe the EU is anti-business with all its regulations
| affecting companies.
|
| It's technically possible that both sides are right in their
| criticism, but the fact that neither side seems to
| acknowledge the other suggests that both aren't seeing the
| full picture.
| prof-dr-ir wrote:
| the main claim of the letter reads:
|
| "the European Union plans to abolish the digital privacy of
| correspondence."
|
| to which I can only say: [citation needed]
|
| In fact, as far as I know there is only a discussion piece
| circulating with _perhaps_ some debatable wording, but there is
| no proposed legislation whatsoever to justify this claim. (Feel
| free to correct me, authors of the letter or others.)
|
| I would think that meaningful contributions to any discussion do
| not begin with outrageous claims.
| 1123456789 wrote:
| Everybody prepare your wireshark to get the CC details for FREE.
| God bless "smart" PPL
| Andrew_nenakhov wrote:
| Every time Russian government introduced new measures to restrict
| freedom of internet users, they have launched a campaign
| explaining that _it is necessary to protect the children!!!_
|
| Don't you want to protect the children, you _monsters_??!!!
| silasdavis wrote:
| There is a longstanding thread of political thought in the UK
| about banning encryption https://www.wired.co.uk/article/uk-
| encryption-whatsapp-amber...
| always_left wrote:
| I know we don't like when people cite child pornography as a
| reason, but child pornography is a real issue. It is spread via
| any and every kind of social media. Kids are groomed into sending
| their photos online. Enforcing encryption will make it harder to
| detect these kinds of distribution.
|
| What is the answer?
| jedberg wrote:
| Better programs for kids to learn what grooming is. Better
| training for teachers and other people who work with kids a lot
| to see the signs of abuse. Better enforcement of child
| pornography laws. More money for investigating child
| pornography and trafficking.
|
| But not banning encryption. Encryption is a tiny piece of the
| child pornography puzzle and will have little effect whether it
| exists or not.
| prepend wrote:
| Smarter kids to prevent grooming and sending pics (btw, in most
| states this turns kids into child porn producers a more serious
| crime than child porn viewer).
|
| To stop the adults abusing kids it's hard like any other crime.
| o_p wrote:
| >in most states this turns kids into child porn producers a
| more serious crime than child porn viewer
|
| This is even worse than the OP
| prepend wrote:
| Sadly when end to end encryption gets blocked the highest
| number of convictions will probably be 12 year olds, since
| they are probably less likely to be able to get around
| controls.
| o_p wrote:
| Dont let your kid videochat on the internet? Maybe?
| COGlory wrote:
| Yeah this is a parenting failure first and foremost. We don't
| know what the magnitude of the problem is once that variable
| is accounted for.
| mothinx wrote:
| As I concealed my first puffs on a join to my parents, I'm
| 100% sure that my kids have access to internet without my
| permission.
| ant6n wrote:
| So how will online banking work with encryption?
| 1123456789 wrote:
| You won't need. Everything will be 123 hackable
| bscanlan wrote:
| > Under the EU Internet Forum, the Commission has launched an
| expert process with industry to map and preliminarily assess, by
| the end of 2020, possible technical solutions to detect and
| report child sexual abuse in end-to-end encrypted electronic
| communications, and to address regulatory and operational
| challenges and opportunities in the fight against these crimes.
|
| It is a spectacular overreaction to equate this to "EU wants to
| ban encryption". This will never happen.
| matheusmoreira wrote:
| Banning encryption, completely neutralizing and circumventing
| the encryption... The effect is the same: the government will
| be able to read the messages.
| vages wrote:
| If you search for the word "encrypt" in this document, you'll
| see that they are against Facebook end-to-end encrypting
| messenger: https://ec.europa.eu/home-
| affairs/sites/default/files/what-w...
|
| I don't think this is an overreaction.
| [deleted]
| hvdijk wrote:
| The bit about Facebook's planned end-to-end encryption ends
| with:
|
| > One of the specific initiatives under the EU Internet Forum
| in 2020 is the creation of a technical expert process to map
| and assess possible solutions which could allow companies to
| detect and report child sexual abuse in end-to-end encrypted
| electronic communications, in full respect of fundamental
| rights and without creating new vulnerabilities criminals
| could exploit. Technical experts from academia, industry,
| public authorities and civil society organisations will
| examine possible solutions focused on the device, the server
| and the encryption protocol that could ensure the privacy and
| security of electronic communications and the protection of
| children from sexual abuse and sexual exploitation.
|
| I read this as "Okay, fine, we can't ban end-to-end
| encryption and we cannot backdoor it. What _can_ we do? " If
| that is what they mean, it seems a reasonable enough question
| to ask.
| matheusmoreira wrote:
| > possible solutions focused on the device, the server and
| the encryption protocol
|
| Looks like they're going to find ways to read our messages
| _before_ they are encrypted and sent. Why would anyone
| continue to use a communications application that 's known
| to do this?
| AnssiH wrote:
| > Why would anyone continue to use a communications
| application that's known to do this?
|
| Network effect. Most people are not using Whatsapp
| because it is E2EE, they are using it because all their
| friends are.
| IanCal wrote:
| Where do they say they are against it? Can you quote
| precisely what you are referring to?
|
| They seem to just explain the problem it causes and calls for
| finding new approaches since current ones are made
| ineffective.
| estaseuropano wrote:
| They are not against it, they say it makes precenting child
| porn dissemination more difficult, which seems like a rather
| obvious truth. They say Industry and government need to work
| together SNF try and see what can be done about it _without
| breaking privacy_.
|
| So total opposite of how you read it.
| AnssiH wrote:
| That is not my read at all:
|
| > Last year, Facebook announced plans to implement end-to-end
| encryption by default in its instant messaging service. In
| the absence of accompanying measures, it is estimated that
| this could reduce the number of total reports of child sexual
| abuse in the EU (and globally) by more than half and as much
| as two-thirds, since the detection tools as currently used do
| not work on end-to-end encrypted communications.
|
| Seems more like stating a fact.
| fossuser wrote:
| That's not even the proposal they're talking about, this is:
| https://digital-strategy.ec.europa.eu/en/library/interim-
| reg...
|
| Also as the other comments said, even in the one you link
| they're discussing the true issues that exist and what to do
| in that context.
| ineptech wrote:
| Do you imagine that this "expert process" will come up with a
| way to preserve message privacy while also flagging which
| messages are illegal? What else could the purpose of it be than
| to recommend requiring providers to MITM their customers'
| messages?
|
| (Although I agree that the title should be changed to "ban
| _end-to-end_ encryption "; certainly the suggestion that the EU
| would try to ban encryption generally is an exaggeration)
| IanCal wrote:
| I can think of a very obvious one, identify and refuse to
| send messages that the client app decides are child porn. No
| intrusion.
|
| Or perhaps add a counter to the account when it's detected.
| Minimal intrusion, single flag defining the message.
|
| You don't need to mitm things to implement _some_
| mitigations.
|
| Before the inevitable - a method that is not 100% reliable in
| stopping something is not useless. Otherwise we may as well
| make it as easy as possible to share child porn because it
| wouldn't make a difference.
| fossuser wrote:
| FB also already proposed one where users can report
| encrypted messages and send an unencrypted log to them from
| their client device.
|
| Since most existing child abuse imagery is reported by
| users that see it somehow - this seems like a reasonably
| pro-privacy way to keep the same amount of reporting.
| jeffbee wrote:
| What the EU actually proposes to do is self-contradictory. It's
| like appointing a panel of physicists to study creation of a
| perpetual motion machine. If there are any actual experts
| appointed, they've vote to disband the panel immediately.
|
| """Under the EU Internet Forum, the Commission has launched an
| expert process with industry to map and preliminarily assess, by
| the end of 2020, possible technical solutions to detect and
| report child sexual abuse in end-to-end encrypted electronic
| communications, and to address regulatory and operational
| challenges and opportunities in the fight against these
| crimes."""
| dmje wrote:
| Can someone explain to me exactly how the EU plans to ban
| encryption? Like, what's the mechanism to stop an EU citizen
| hosting their (whatever) in a country that does support E2E? Or
| how, practically, you stop anyone from using X service which
| provides strong encryption on their computer or servers at home?
|
| I'm naive about such matters but from where I'm standing I can't
| see how this is even vaguely enforceable?
| IanCal wrote:
| > Can someone explain to me exactly how the EU plans to ban
| encryption?
|
| They aren't, that's the simple answer.
| o_p wrote:
| Lets ban children
| tines wrote:
| If this ever happened/happens anywhere, a great pastime would be
| to start sending streams of random data to people across the
| internet. Since random data is indistinguishable (theoretically)
| from encrypted data, I'm sure you'd waste a lot of the
| regulators' time. You'd almost force them to ban anything that
| _looks like_ random data, or give up on enforcing the ban on
| cryptography altogether.
| dane-pgp wrote:
| Surely you'd need the recipient to actually save the random
| data (unless you think that regulators are going to be breaking
| every TLS connection and checking the contents of every
| packet).
|
| I think people already make efforts to avoid being swamped with
| unwanted data, so anti-spam and anti-DDOS systems would
| probably block you and delete your streams without any human
| noticing.
| notwedtm wrote:
| Every time I see this I realize just how little people realize
| what makes the world run around them.
|
| Do they not realize that their worlds would cease to function
| without encryption?
| africanboy wrote:
| Why this old news-not-news reappear every few months?
|
| > _Is Europe about to ban E2E Encryption?_
|
| > _No._
|
| https://www.google.com/amp/s/techcrunch.com/2020/11/09/whats...
| Tylerian wrote:
| C'mon... as if banning cryptographic messagery services would end
| criminals from encrypting their messages and sending the payload
| in plain text like they were doing since internet's inception
| gaius_baltar wrote:
| Remember: every time a government cites child pornography or
| terrorism as the reason ban cryptography or otherwise limit human
| rights, they are just using an excuse.
| CameronNemo wrote:
| It's like banning assault rifles to prevent mobsters from
| getting hold of them.
|
| Except in this case the good being banned is just some well
| known and distributed, cheap to copy, easy to build, easy to
| use software.
| draw_down wrote:
| Whoops! Not allowed to say that.
| Jenk wrote:
| > It's like banning assault rifles to prevent mobsters from
| getting hold of them.
|
| Obvious bait is obvious but whatever, I'm in...
|
| Is it the same, though? Is it really?
|
| On one side we have literal implements of death responsible
| for countless accidental and/or illegal deaths, and the other
| we have some encryption software.
| PartiallyTyped wrote:
| The moment encryption becomes illegal is the moment
| political dissidents, whistleblowers, reporters and every
| person in between are criminals.
|
| We forfeit our freedom to express any idea or thought that
| deviates from the current list of acceptable thought
| patterns.
|
| Suddenly you and all your thoughts or actions are subject
| to tracking by any government, any government official, any
| corporation and any malevolect actor.
|
| The government already has a monopoly on violence, what's
| next?
| Jenk wrote:
| I think you replied to the wrong post. I'm against
| banning encryption.
| CameronNemo wrote:
| Never said same! Just has some resemblances. As well as
| major hilarious contrasts (hence why I chose the subject,
| instead of cats and cat lovers).
|
| I don't think a gun and cryptography should have the same
| treatment.
| robcohen wrote:
| Countless doesn't seem totally accurate. Last I checked the
| FBI census a few years back showed 318 deaths over a year
| due to long guns in the United States. That includes
| shotgun, rifle, and scary "assault" weapons.
|
| Handguns on the other hand kill 100x-200x the same amount
| of people. Seems like if gun control proponents wanted to
| reduce harm, they'd focus on handguns first.
| schoolornot wrote:
| Aggregated stats from 2019: https://ucr.fbi.gov/crime-in-
| the-u.s/2019/crime-in-the-u.s.-...
| Jenk wrote:
| That's _just_ murder. Doesn't include accidental deaths.
| tshaddox wrote:
| I'm not sure why you need to split your focus on handguns
| versus long guns. I bet most gun deaths are caused by
| right-handed people too, but that doesn't mean we should
| focus on gun laws for right-handed people first.
| hn8788 wrote:
| Because that's what politicians do. Tons of talk about
| banning "weapons of war" that are rarely used to kill
| anyone, meanwhile handguns are used for murder/suicide
| much more often, but they rarely make the news because
| they aren't scary looking, and because the majority of
| crimes with them are committed by minorities, so
| Democrats don't want more restrictions on them.
|
| And before anyone says it, no, that last part is not some
| right-wing racist conspiracy. A couple of years ago in
| Maryland, the governor wanted harsher punishments for
| people using handguns to commit crimes because of how bad
| gun violence is in Baltimore, and the state Democrats
| said it was a racist policy because it would mostly
| affect minorities. They didn't want to seem soft on gun
| violence though, so they banned bump stocks, which have
| never been used to commit a crime in Maryland, and which
| the ATF says are trivial to reproduce using belt loops
| and rubber bands.
| Jenk wrote:
| 318 > 0.
|
| So yeah.. ban all guns then.
| HideousKojima wrote:
| 390 deaths from swimming pools every year in the US. 390
| > 0, ban all swimming pools.
| dghlsakjg wrote:
| 300 + confirmed by rifle.
|
| 3,000 + had no weapon type listed.
|
| How confident are you that no rifles snuck into the
| unknown weapon type.
| ian-g wrote:
| I think the point is that the people who're already on the
| wrong side of the law will continue ignoring this new law.
|
| Mobsters won't stop buying guns because they're banned.
| Lots of people won't stop using encryption software just
| because it's banned.
| tshaddox wrote:
| I think the hope isn't that mobsters would choose to stop
| buying guns out of respect for the law, but rather that
| it will literally be more difficult for mobsters to buy
| guns because of actual enforcement of the law.
| CameronNemo wrote:
| >Lots of people won't stop using encryption software just
| because it's banned.
|
| In particular organized crime, which the government is
| claiming to address via this policy.
| debacle wrote:
| Those implements of death have been tools of liberty,
| stability, and safety in the hands of hundreds of millions
| of people across the world in the last several hundred
| years.
|
| The world, under its thin, patchy veneer of peace and
| prosperity, is still a savage place. Ask the IDF, Ukraine,
| South Korea, etc.
| matheusmoreira wrote:
| > On one side we have literal implements of death
| responsible for countless accidental and/or illegal deaths
|
| Cars?
| kajecounterhack wrote:
| We need encryption to do peaceful things like economic
| transactions on the internet and private conversation. We
| don't need assault rifles for anything but murder. So no it's
| not the same.
| chad_homenim_ wrote:
| > We don't need assault rifles
|
| > need
|
| Rosa Parks didn't need to sit at the front of the bus
| either. You don't "need" to prove to anyone why you should
| have anything. It is not up for you to decide.
| marsven_422 wrote:
| We need assault rifles to protect ourselves from the
| government.
| dheera wrote:
| Not to mention you can't ban encryption without banning
| freedom of speech.
|
| If freedom of speech exists, freedom to speak what sounds
| like nonsense to a bystander also exists.
| jcrites wrote:
| What do you mean by "assault rifle"? It's a term used by
| the media but it's often misused.
|
| The "scary black painted rifles" (e.g. AR-15s) that most
| civilians own are not "assault rifles". (Note that the
| acronym in AR-15 is ArmaLite Rifle and does not mean
| assault rifle: see
| https://en.wikipedia.org/wiki/ArmaLite_AR-15 ) Civilian
| AR-15s and generic versions _are not assault rifles_.
|
| The distinction is that _rifles_ like AR-15s fire one
| bullet per trigger pull-they are just a rifle, functionally
| the same as any hunting rifle or handgun, just larger, and
| more accurate at longer ranges.
|
| Actual "assault rifles" are distinguished by having a
| feature called "selective fire" which switches between
| being firing like a rifle, and firing continuously like a
| fully-automatic "machine gun". See
| https://en.wikipedia.org/wiki/Assault_rifle
|
| Actual "machine guns" with fully automatic firing are
| highly regulated in the US and it's not easy for a regular
| person to obtain one. (For example, the Las Vegas shooter
| modified a regular rifle with a "bump stock" to transform a
| regular rifle into something that behaved like a machine
| gun-something that has subsequently been banned.)
|
| Examples of actual assault rifles are the US military's M16
| and the AK-47. You won't see a typical civilian possess
| these, unless they go through a special process of
| obtaining a federal permit from the Bureau of Alcohol,
| Tobacco, and Firearms (ATF). Because you are correct that
| the purpose of such weapons is military warfare; and even
| in the military, fully automatic fire in modern combat is
| used in specific circumstances (typically as suppressive
| fire against a large enemy force; whereas the vast majority
| of shots taken by soldiers would be in single-shot mode).
|
| However there are plenty of justifiable reasons for people
| to possess firearms, whether rifles or handguns, such as
| hunting, sport shooting at a range, or personal protection
| (self-defense, assuming the attacker dies, is not murder).
|
| An additional reason is that firearm ownership is protected
| by the US Constitution in its 2nd Amendment; and one of the
| reasons for its protection by the constitution is to ensure
| that the population can defend itself against tyranny by
| its own government.
|
| (Read about the history of why it was added as an
| amendment; or read the US Supreme Court decision in
| District of Columbia v. Heller, the text of which is very
| readable - once you get past its analysis of the language
| and grammar of the amendment to ascertain its precise
| meaning - and provides a history of the rationale of the
| text and the historical reasons for its protection as a
| right. It analyzes the language used in the Constitution
| and other legal documents, carefully deconstructs the
| grammar in the sentence, and concludes:
|
| > (...) We start therefore with a strong presumption that
| the Second Amendment right is exercised individually and
| belongs to all Americans. (...)
|
| There's a lot of detailed analysis that goes into the
| definition of "arms" as being non-military weapons that
| individuals might use for hunting or self-defense; the
| historical protection of that right; and why it's an
| individual right for all Americans.)
|
| Read the text of the court opinion here:
| https://www.law.cornell.edu/supct/html/07-290.ZO.html
|
| I can respect people's opinion who wish that firearm
| ownership was not permissible-it's an understandable
| perspective, especially for those who have been affected as
| victims by gun violence; however, the respectable path to
| "solve" that problem is for the United States to amend its
| constitution and modify or remove the 2nd Amendment. If
| that's the wish of the people I can respect it. However,
| it's hard for me to respect the "tricks" that states or
| municipalities try to pull, such as banning guns on public
| property (which Seattle tried to do, which was overruled by
| the courts-helped by the Washington State Constitution's
| pre-emption clause, which protects firearm ownership and
| forbids municipalities from limiting that right); or states
| like California that require a permit and make getting it
| burdensome.
| RcouF1uZ4gsC wrote:
| I think the main thing they want to ban is end to end
| encryption. That you really don't need. They are probably
| fine encrypting your connections to various companies since
| they can subpoena records
| CameronNemo wrote:
| Murder? Self defense is not murder. But again my point was
| not that they are similar, just that they are valuable,
| difficult to control, and law enforcement wants a monopoly
| on them.
| lexicality wrote:
| I can understand owning a pistol for self defence, but
| what situation does a civilian need an assault rifle in?
|
| Surely it'd just get in the way massively in any kind of
| home invasion scenario and if you end up firing it the
| bullet will go through 3 houses and hit someone's dog
| calvinmorrison wrote:
| Crypto exists because bad actors exist. The same reason
| Americans own guns.
| cl0ne wrote:
| Some Americans own guns for subsistence hunting as a
| source of food.
| thereare5lights wrote:
| Didn't think of it this way but this is spot on.
|
| If people could trust each other, then we wouldn't need
| crypto in the first place. Just like if we could trust
| others not to attack us, we wouldn't need weapons for
| self defense.
| cpursley wrote:
| And historically the worst bad actors have been
| governments (in terms of body count). Which is why both
| guns and crypto help level the playing field a bit more.
| gre wrote:
| Crypto and guns exist because they are possible.
| doomroot wrote:
| What about owning an assault rifle shooting range? I think
| those owners need assault rifles for things besides murder.
| I get your point but try not to be an absolutist.
| kokx wrote:
| In countries where assault rifles are banned, these
| things generally still are possible. With strict rules,
| for example you're only allowed to have your rifle and
| ammo at a shooting range, and psychological review of
| everyone involved.
|
| Besides all that, it very much is a hobby for people.
| Much less a need than encryption, which is required to
| keep simple things like ordering something online secure.
| Alupis wrote:
| > We don't need assault rifles for anything but murder.
|
| We don't need encryption for anything but hiding illegal
| activities. You have nothing to fear if you're not a
| criminal.
|
| See what I did there? Neither argument is good.
|
| Just like the overwhelming majority of people that own so-
| called Assault Rifles never use them for anything except
| peaceful recreation - the overwhelming majority of people
| that use encryption never use it for anything except
| peaceful online activities.
|
| Why would we ban one and not the other? Both are used by
| criminals to commit acts _which are already illegal_.
| Making them doubly-illegal accomplishes nothing.
| catgary wrote:
| Yeah I still remember that time a mentally ill young man
| got their hands on encryption and senselessly murdered 50
| people.
| mustafa_pasi wrote:
| Encryption is used by criminals and terrorists.
| nulbyte wrote:
| I don't understand this argument. They use food and
| water, too. And roads. We never talk about banning those,
| because the benefit to society is greater than the risk.
| samstave wrote:
| Heh. I guess if you ban encryption, then only criminals
| will have encryption plays here - as then encrypting your
| shit via ransom-ware will be SUPER prevalent
| Kuinox wrote:
| You need encryption to make order online without anybody
| getting your card numbers.
| nemonemo wrote:
| I need encryption to make sure nobody is listening to my
| sensitive conversation like legal/psychological
| counseling. It can be actually more secure than in-person
| conversation.
|
| Recreational ones are not "needs". Your analogy seems
| flawed.
| Threeve303 wrote:
| Imagine needing legal help during the pandemic and not
| being able to privately speak to a lawyer without being
| absolutely sure someone isn't going to listen in and try
| some old fashioned parallel construction.
| skissane wrote:
| Suppose you had a choice between living in country A or
| country B. Country A bans encryption but allows assault
| rifles. Country B bans assault rifles but allows
| encryption. Which would you choose?
|
| I think it is obvious that country B is the better choice
| than country A. A lot of people (including myself) have
| zero interest in the hobby of recreational assault rifle
| ownership. But banning encryption has the potential to
| cause massive harm, both economic, and in terms of
| freedom of speech and freedom of thought. If the
| government wants to control what you say and think,
| taking away your freedom to communicate out of the
| government's hearing is a great first step. By contrast,
| taking away the freedom to own assault rifles has far
| less impact - I don't have that freedom in the country in
| which I live, and I don't even notice it, because I have
| no interest in owning one. But I definitely would notice
| if the government tried to ban encryption.
| saurik wrote:
| This is a weird choice to present the reader, as it can
| only tell you which freedom is more critical, not whether
| they are of similar form (and, FWIW, they are at least so
| clearly related that the United States regulates
| encryption largely as part of arms regulations and
| treaties).
| skissane wrote:
| Encryption seems directly related to freedom of speech,
| freedom of thought, and privacy rights, in a way which
| gun ownership issues are not.
|
| Encryption directly protects your freedom of thought by
| making it possible to communicate your thoughts to others
| without the government being aware of them, hence making
| it difficult for the government to punish you for sharing
| those thoughts if it disapproves of them.
|
| Owning a gun doesn't directly protect your freedom of
| thought. Maybe you could argue that a gun can indirectly
| protect your freedom of thought, since if the government
| tries to restrict your freedom of thought, you can
| respond by violently overthrowing the government using
| your gun. However, in practice, that is very unlikely to
| work - an attempt to use your gun to violently overthrow
| the government is far more likely to result in your own
| death (or spending the rest of your life in prison) than
| in any actual change in the government or its behaviour.
| Even if you had a million fellow citizens with their own
| guns supporting you, you'd still struggle to win against
| the tanks, fighter jets, bombers, drones, missiles, etc,
| of a modern military.
| jcrites wrote:
| It may seem like a minor detail but there's a very
| substantial functional difference between "rifles" and
| "assault rifles": assault rifles can fire as fully-
| automatic "machine guns".
|
| There is no such thing as "recreational assault rifle
| ownership". I posted in detail about this in another
| comment [1], but "assault rifles" are machine guns and
| are highly regulated in the United States. You can't buy
| or own one without a special federal permit from the ATF
| which has a high bar to get.
|
| What everybody is talking about when they say "assault
| rifle" are actually just "rifles", which function the
| same way as other hunting rifles and handguns, merely
| having a different form-factor. AR-15s (ArmaLite Rifles)
| for example are just normal rifles, not assault rifles.
| There are many variants, but plenty of AR-15s will fire
| the same 9mm ammunition that handguns fire. (Caliber has
| nothing to do with the classification; that's just an
| example.)
|
| I'm not even sure that individual people can legally
| possess machine guns in the US. From what I recall you
| essentially need to form a corporation and apply for it
| to become a firearms dealer, and get approved; and then
| the corporation may buy and possess them. There is very
| limited "recreational" use of machine guns: you can go to
| Las Vegas and pay to fire a machine gun that's mounted to
| the ground, and whose firing angle is limited. That's
| about the extent to which any normal person (civilian)
| will ever legally interact with a machine gun or assault
| rifle in the USA.
|
| For those who want to use informed language to have a
| precise discussion, please use the term "rifle" if that's
| what you mean, and avoid using the FUD term "assault
| rifle" (unless that's what you mean), usage of which has
| been polluted by poor journalists and opinion-providers
| that use sloppy language.
|
| [1] https://news.ycombinator.com/item?id=26826847
| arrosenberg wrote:
| I think a large number of Americans would take the
| opposite view.
| reedjosh wrote:
| But note how the encryption ban comes about after the
| firearm ban in the country of discussion.
|
| Firearms rights (at least in the US) were intended as
| protection from tyrannical governments more so than even
| self protection. Though I acknowledge that today the US
| government is too powerful for citizens with firearms to
| prevent any tyranny.
| u801e wrote:
| > Firearms rights (at least in the US) were intended as
| protection from tyrannical governments more so than even
| self protection.
|
| The same argument could also apply to encryption. That
| is, it can offer you protection from a tyrannical
| government in addition to protecting your information
| from criminals.
| reedjosh wrote:
| I do agree with you. I'm just pointing out that both are
| intended as rights of a sovereign individual to protect
| oneself from both other individuals and government.
| dagss wrote:
| Why do you say that? Do you really think that noone can have a
| genuine interest in combating child pornography or terrorism?
|
| My intuition is exactly the opposite: That many have a
| legitimate wish to combat both child porn and terrorism. Many
| people work with that every day and obviously they want to do a
| good job. And one effect of limiting crypto would help that.
| (That doesn't mean in itself crypto should be limited; but I
| don't see how writing one side off as "just an excuse" and
| basically offering a conspiracy theory helps anyone. Better to
| just say "it's unfortunate about child porn and terrorism, but
| it's the price that must be paid / here's another way to combat
| that", if that is what you mean.)
| jedberg wrote:
| If they have a genuine interest in combating child
| pornography or terror, they would be proposing things that
| actually make a difference to those problems.
|
| Encryption is such a small part of those crimes that it would
| make almost no difference to the level of crime whether it
| exists or not.
| dagss wrote:
| According to another poster, there were in fact here other
| proposals and crypto was a small part of it. And that small
| part was, quoting the text:
|
| > One of the specific initiatives under the EU Internet
| Forum in 2020 is the creation of a technical expert process
| to map and assess possible solutions which could allow
| companies to detect and report child sexual abuse in end-
| to-end encrypted electronic communications, in full respect
| of fundamental rights and without creating new
| vulnerabilities criminals could exploit. Technical experts
| from academia, industry, public authorities and civil
| society organisations will examine possible solutions
| focused on the device, the server and the encryption
| protocol that could ensure the privacy and security of
| electronic communications and the protection of children
| from sexual abuse and sexual exploitation.
|
| So -- you may say that you know that this project is
| hopeless and a foregone conclusion. But will every
| politician trust that -- or will they make a panel of
| experts to explore solutions and tell them for sure that
| you can't meaningfully limit encryption in the first place,
| and even if you did you can't do it without violating
| privacy, as is presumed here?
|
| Don't attribute to malice what can be attributed to
| technical ignorance.
| JauntyHatAngle wrote:
| I agree with him because of what has already happened in
| Australia when it comes to metadata collection.
|
| It was touted as anti terrorism and anti child pornography, 2
| years after it came in the agencies that applied for (and
| receieved) access to people's viewing habits were released,
| and it was near every agency.
|
| https://www.google.com/amp/s/amp.theguardian.com/technology/.
| ..
| gher-shyu3i wrote:
| See also: cryptocurrencies.
| notwedtm wrote:
| Such a fitting username.
| estaseuropano wrote:
| Please read the underlying documents and not this
| fearmongering. There is no such plan.
|
| Just click the first link titled 'upcoming plans for
| communication surveillance' and actually read the document (or
| just CTRL-F 'encryption') to see how misleading this lobby
| letter is. It is a communication about child porn/abuse
| outlining measures for prevention, rehabilitation, etc. It
| doesn't say anything about banning encryption, just as one of
| many points it points out that increased encryption is making
| detection of child porn/abuse difficult and that government and
| industry should set up an expert group to discuss what can be
| done _without breaking privacy_.
|
| So total bs article. I used to be a customer at mailbox but am
| right now very happy I moved away already...
| fossuser wrote:
| Yeah - this linked article is total bullshit, at best it's
| misleading political spin arguing in bad faith.
|
| This is the actual proposal: https://digital-
| strategy.ec.europa.eu/en/library/interim-reg...
|
| https://news.ycombinator.com/item?id=26826599
|
| I think when we something that plays right into an existing
| confirmation bias it's important to be extra skeptical of its
| claims to offset that.
| sebyx07 wrote:
| Ban HTTPS, just must be joking. Or ban books or our minds from
| reimplementing it? Descentralization must happen before this
___________________________________________________________________
(page generated 2021-04-15 23:02 UTC)