7 ms·
How do they want to prevent someone from creating his own end-to-end encryption app? It may use other protocols to encode content (images, tweets, fb posts etc.
by orian 10y ago
How do they want to prevent someone from creating his own end-to-end encryption app? It may use other protocols to encode content (images, tweets, fb posts etc.).
For me it seems to be more in a direction of so called "Big Brother" than real counter-terrorism.
- loup-vaillant 10y ago> How do they want to prevent someone from creating his own end-to-end encryption app? It's basically impossible. One can also use steganography to hide messages in lolcat pictures, or music files. The only way to prevent this, I think, is to start a totalitarian surveillance state where using Free or custom software or hardware is punishable by death. Even then, I'm not sure this will be enough.
- thehardsphere 10y agoGiven that even the most totalitarian states eventually fail and don't ever have complete and total control over the entire populace, I think you're correct that it will not be enough. What they really need is to invent time travel, and murder Ada Lovelace.
- M_Grey 10y agoThat should be a canonical test for the implausibility of any policy. "Do we need to invent a time machine for this to work?"
- CJefferson 10y agoThe same way you prevent anything.. they make it illegal for people in the UK to make, or use, such products. Don't think we can "tech" our way out of this.
- fwn 10y agoNot "we" as in "we the general public with no specific interest in staying hidden". But of course criminals, terrorists or secret services do have the right incentive structure to always benefit from circumventing encryption bans.
- nine_k 10y agoWhich shows who the real target is.
- eterm 10y agoExactly, and given we live in a "walled garden" society now, all they need to do is require google or apple to remove from the app stores any app that implements encryption for messaging. It's actually easier than ever to ban encryption for messaging. Would that stop determined people? No, but it's never been about that anyway. Just make the pool small enough and it becomes too difficult to use. (See PGP / email). Also, if you genuinely legislate against encrypted messaging then it's easy to pick up on the relative handful of people who go outside the app stores to get encrypted messaging applications. And it shouldn't come to technical solutions, we should have people challenge the notion that two people should never be allowed to share a private message, because that's why Rudd and the government is suggesting.
- brokenmachine 10y ago> we should have people challenge the notion that two people should never be allowed to share a private message, because that's why Rudd and the government is suggesting. +1. This is the crux of the matter, although unfortunately I don't think the average person realises it.
- stale2002 10y agoTell that to the pirate bay. Just because something is illegal doesn't mean it is enforceable.
- Asdfbla 10y agoWell, the Pirate Bay probably never really caught the interest of totalitarian states that really wanted to suppress its existence. Now, the UK isn't at that point obviously, but if they really wanted to use draconian measures against encryption, it probably would be somewhat effective.
- blfr 10y agoHow do they want to prevent someone from creating his own end-to-end encryption app? That's not an issue. Writing solid encryption software is very difficult on its own. You will hear "do not roll your own crypto" all the time from security experts. We don't live in a James Bond universe and it's beyond the reach of terrorist organisations.
- satysin 10y agoNobody is saying write your own crypto just your own app. Plenty of excellent crypto libraries out there.
- JensRex 10y ago>do not roll your own crypto Sure, but what's to prevent someone from building something on top of OpenSSL or PGP or whatever? Can't be that hard.
- tgummerer 10y agoYou don't really have to roll your own crypto to create such an app. There's always openssl and the signal protocol, which you'd only need to implement without designing anything. Sure that can go wrong as anything can, but it's far from rolling your own crypto and makes things a lot easier.
- Daviey 10y agoI think you've missed the point.. Not talking about writing own crypto.. Talking about not using applications which the western security services have ability to force backdoors. Are you suggesting gpg has been backdoored? A simple wrapper around gpg is not-beyond terrorist organisations.
- orless 10y agoYou don't have to roll your own crypto to create an own end-to-end encryption app. You can use existing crypto. Writing a user interface around it is not so difficult. Beyound the reach of the terrorist organisations? We have already seen pretty sophisticated operations by relatively small crime organizations (like exploiting pseudorandom generators in casino slot machines). There's an established black market for exploits. I think writing an end-to-end encryption app is not much more difficult compared to this. What's more, it will even be perfectly legal in many countries, meaning you could legally hire professionals to do the job. Terrorist organisations won't need to esablish a development office in SV to write the app, they will only need to know how to use Tor and wire money to the app producer. Which isn't such a huge competence to ask for.
- grey-area 10y agoShe's probably being led by the intelligence services on this, and of course they have ulterior motives, their ultimate project is to collect all signals, or as many as they can manage, which apps like whatsapp are thwarting at present. Why can't we collect all the signals all the time? This is incredibly dangerous for our society, no-one should have that much power. That power isn't about terrorism (or even very useful against terrorism), but about subverting governments, judiciary and businesses.
- sklivvz1971 10y agoYes, this: she might as well just be ignorant (not that it is any justification), but her supposedly competent advisors are actually frauds, fakes and spooks, that's what truly scary to me.
- retrogradeorbit 10y agoProbably more blackmailed than led by the intelligence services. This is why the deep state is so intent on surveilling the politicians. And why when they discover the political class engaging in crimes they do not bring them to justice (like the Westminster paedophilia scandal). They like to keep all their dirt on file so they are easily controlled and can be forced to enact the draconian laws the deep state wants.
- grey-area 10y agoI imagine they reserve blackmail for cases where it is deemed necessary; given the views of the PM and HS, I doubt any blackmail is necessary.
- andybak 10y ago> Westminster paedophilia scandal Links to any credible sources?
- collyw 10y agohttps://en.wikipedia.org/wiki/Westminster_paedophile_dossier https://en.wikipedia.org/wiki/Westminster_paedophile_dossier
- sklivvz1971 10y ago> How do they want to prevent someone from creating his own end-to-end encryption app? They can't. The US tried it in the 90's when SSL sites could not use strong encryption outside the US and you'd need a license to "export" PGP... That went well! :-/ https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States#PC_era https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
- OJFord 10y agoYou're forgetting that this has always been possible, and not all adversaries are capable, bother, or aware of what they could do. I expect it's quite likely this one was using WhatsApp because that's what he used; not because he read about its end-to-end encryption.
- sergior 10y agoUltimately this type of "lone wolf" attackers will not communicate at all and what are they going to do next? Install a device on one's head?
- quakeguy 10y agoDon't give them ideas!
- peterwwillis 10y agoThey wouldn't prevent you from making encryption apps. It would be about regulation. You can regulate kinds of encryption (the strength of the algorithms/keyspace etc), and you can regulate who can use it (licensed copies only, or specific businesses only, or types of businesses, non-messaging platforms only, etc). Then there's how you use it. They could mandate all of X businesses could only use encryption that could be inspected by the state, so either weak encryption, or PKI where you send the government your site's private key or use the state's CA or something. They can also mandate backdoors in encryption used in certain ways. And they can mandate that weak encryption be used outside their country's borders. All of these are real parts of US laws on cryptography from WWII to 2000 to prevent "export" of "strong encryption", because of course evildoers around the world might make use of these "munitions". US law still regulates how we can use or distribute cryptography around the world. It is illegal in the US to release open source crypto on the internet without notifying the Bureau of Industry and Security. And 41 other countries (including the UK) have similar laws. The one thing the US has going for it is the 1st Amendment, which makes it illegal for the US to prevent its citizens from making or using crypto within the US.
- mderazon 10y agoIf you ban encryption and monitor all traffic in the world then you can easily flag messages you can't read as suspicious. You can then hunt down people using the encryption.