23 ms·
Facebook, WhatsApp Will Have to Share Messages With U.K.?
- lone_haxx0r 7y agoIf you're logically consistent, then outlawing encryption implies outlawing computers and mathematics. We are venturing straight into a totalitarian nightmare, and are totally fine with it.
- newman314 7y agoNOBUS is going to work well. Not.
- cheez 7y agoExcellent.
- ga-vu 7y agoTFA says just UK...
- bobthepanda 7y ago> Social media platforms based in the U.S. including Facebook and WhatsApp will be forced to share users’ encrypted messages with British police under a new treaty between the two countries, according to a person familiar with the matter.
- alehul 7y ago> under a new treaty between the two countries > The U.K. and the U.S. have agreed not to investigate each other’s citizens as part of the deal
- deleted 7y ago[deleted]
- Nextgrid 7y agoCurious what this means for other end-to-end encrypted services such as iMessage.
- superkuh 7y agoOr any of the innumberable actually secure messaging solutions that aren't centralized in one easily manipulated company. I suppose they'll just pass the laws(?) making it all illegal but only enforce it when it's politically useful or if someone rocks the boat.
- i_am_proteus 7y agoI'm equally curious what this means for Signal and any other open-source encrypted services. In the US, ITAR could hypothetically be used to make open-sourcing of cryptographic algorithms illegal. This technique is used for robotics software that could be dual-purposed for weapons guidance.
- deleted 7y ago[deleted]
- wbl 7y agoThe EAR does not cover publically availible source code but specifically exempts it.
- smudgymcscmudge 7y agoIs "EAR" the agreement? It sounds like you know about it. Can you share information with us?
- mark_l_watson 7y agoProteus, I am concerned too. Sometimes fiction reflects reality better than we might like, I am thinking of William Gibson’s cyber punk future distopean sci-fi. That said, freedom can also be in our own minds, creating a good life in an ocean of political corruption and increasing control of corporations/elites. It would take more effort, but I think I could also have a good life in Gibson’s sci-fi worlds.
- colejohnson66 7y ago> In the US, ITAR could hypothetically be used to make open-sourcing of cryptographic algorithms illegal. Wikipedia has some good info re: export of cryptography[0]. In addition, two circuits (Ninth[1] and Sixth[2]) have ruled that source code is protected by the First Amendment. [0]: https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... [1]: https://en.wikipedia.org/wiki/Bernstein_v._United_States https://en.wikipedia.org/wiki/Bernstein_v._United_States [2]: https://en.wikipedia.org/wiki/Junger_v._Daley https://en.wikipedia.org/wiki/Junger_v._Daley
- bobthepanda 7y agoThe title is editorialized - it's not just Whatsapp, it's all social media platforms.
- cwyers 7y agoAnd it's misleading -- the article and the article's headline say nothing about adding a backdoor. There's not enough detail in the article to say exactly how this decision will affect WhatsApp. (The headline on Bloomberg, "Facebook, WhatsApp Will Have to Share Messages With U.K. Police" is more restrained.)
- falcolas 7y agoIf messages are encrypted end-to-end, and laws force the ability to intercept those messages, the end-game (the backdoor) is fairly easy to tease out.
- smudgymcscmudge 7y agoOn re-reading the sort article, I realize it only says they will be compelled to share "encrypted messages" and "information to support investigations". It never says anything about decrypting the messages. If that is literally all it is, then it is quite misleading.
- ryeights 7y agoWhat use would ciphertext be to GCHQ? I’m fairly certain that “encrypted messages” describes which messages they will have to provide in plaintext, not the format they will come in.
- Buge 7y agoYour interpretation is likely right. But it's interesting to consider the other. Maybe they can get metadata from the ciphertext, such as size. Or maybe they are just interested in other metadata such as time. Or maybe they have some cryptographic attacks, maybe involving extracting a shared key from the peer's phone, or key injection via sim spoofing.
- nicky0 7y agoIf WhatsApp is end to end encrypted, how can they share the messages?
- Gaelan 7y agoThe government could compel them to change their software.
- blocked_again 7y agoEnd to end encryption does not exist.
- kd3 7y agoPlease elaborate?
- dboreham 7y agoThe ends aren't secure.
- packet_nerd 7y agoNot the parent, but true in a sense. Communication is the act of conveying information from one person's consciousness to another. In the usual encrypted chat scenario, that path is unencrypted at two points (plaintext input, and plaintext output at the far end). It is entirely possible though to have a true end-to-end encrypted channel if both parties are able to do the encryption in their heads without the plain text message ever being visible. A trivial practical example would be a single bit message with a single bit one time pad (agree ahead of time that if I say yes on the phone, it means no and vice versa).
- deleted 7y ago[deleted]
- i_am_proteus 7y agoFacebook controls both endpoints.
- AnssiH 7y agoIs there any more detailed info out there? I would expect such an accord between countries to enable data sharing, not force companies to record more data. So I'm sceptical of the article's claim for now.
- smudgymcscmudge 7y agoAll I've found is this paywalled article. https://www.thetimes.co.uk/edition/news/police-can-access-suspects-facebook-and-whatsapp-messages-in-deal-with-us-q7lrfmchz https://www.thetimes.co.uk/edition/news/police-can-access-su...
- Pete_D 7y ago(disclaimer, speculation) The Times article says this has been in progress for four years, so I suspect that this is the culmination of https://wiki.openrightsgroup.org/wiki/UK-US_Bilateral_Agreement_on_Data_Access https://wiki.openrightsgroup.org/wiki/UK-US_Bilateral_Agreem.... Which was originally planned to be encryption-neutral, but maybe things have changed in the past two years.
- spzb 7y agoGiven that Priti Patel is involved it probably is nothing like what's being described. She's exactly the sort of politician who thinks that mathematics can be redefined by a policy statement on TV.
- Gys 7y ago> Social media platforms based in the U.S. including Facebook and WhatsApp will be forced to share users’ encrypted messages with British police under a new treaty between the two countries, according to a person familiar with the matter. This sounds as if the platforms are already sharing with the US authorities. So this being about them sharing it now with UK authorities.
- nextos 7y agoI wonder what happens with Signal as it's US-based.
- robert_foss 7y agoMaybe @moxie could enlighten us.
- hos234 7y agoNothing. Whoever is interested, has to get hold of the phones to access the messages.
- cheschire 7y agoHistorical messages, yes. However an app maker can be coerced into adding a hidden user that can participate in chats and receive all future messages decrypted. It doesn't require any special crypto hacks for that to work.
- kd3 7y agoLooking forward to what the people at Signal have to say about this.
- JohnJamesRambo 7y agoIs Signal still safe?
- rurban 7y agoSignal was never safe: https://web.archive.org/web/20180914145702/https://sandervenema.ch/2016/11/why-i-wont-recommend-signal-anymore/ https://web.archive.org/web/20180914145702/https://sanderven... https://news.ycombinator.com/item?id=12880520 https://news.ycombinator.com/item?id=12880520 The safe variant LibreSignal was killed by Signal. https://github.com/LibreSignal/LibreSignal/wiki/What-to-do-after-LibreSignal-was-abandoned%3F https://github.com/LibreSignal/LibreSignal/wiki/What-to-do-a...
- move-on-by 7y agoThis comment is absurd. Your linked article even says: > To be clear: the reason for this is not security. To the best of my knowledge, the Signal protocol is cryptographically sound, and your communications should still be secure. The reason has much more to do with the way the project is run, the focus and certain dependencies of the official (Android) Signal app, as well as the future of the Internet, and what future we would like to build and live in. Beyond the author flat out saying that it’s secure- the title of the article is why they will not recommend it. It has nothing to do with it being compromised.
- rurban 7y agoWe are not talking about the protocol and simple one to one chats, we are talking about the app. They are several major weaknesses in Signal which have nothing to do with the protocol.
- rvz 7y agoThis is essentially a worrying prospect if these developments are actually implemented or advance further. The users trust in the social media service is breached if a backdoor where to be placed in their products (It also defeats the purpose of the end-to-end encryption argument). If you reside in the UK and especially in London, things have just become 500% more Orwellian. >Priti Patel, the U.K.’s home secretary, has previously warned that Facebook’s plan to enable users to send end-to-end encrypted messages would benefit criminals... In London alone, it is not possible to pay for public transport with cash. A debit card/oyster is required but for anonymous travel, an oyster can be topped up via cash and reduces transport surveillance, unlike using credit / debit cards. Their reasons for doing this because it "benefits criminals" is echoing the "ban encryption" nonsense. > The U.K. and the U.S. have agreed not to investigate each other’s citizens as part of the deal... This I don't believe. EDIT: Use a oyster card for public anonymous transport, refrain from using a credit / debit card for this.
- hdfbdtbcdg 7y agoCan't you buy new oyster cards with cash?
- joshvm 7y agoYes, and most newsagents will let you top them up with cash.
- cameronbrown 7y agoI believe so. I know there's definitely a way to get transport with cash. It's just a cost saving measure to only take contactless.
- rvz 7y agoYes that's possible and it is anonymous. I've clarified this in the edited post.
- cosmodisk 7y agoI live in London.It has already gone way beyond of what Orwell could have ever imagined. However,despite of all the surveillance, London is the crime capital of the world.This is probably the best place for criminals,as unless you pull a machine gun on a crowd,not much will be investigated.
- cyphar 7y agoIt's interesting this is even necessary -- Australia's legislation to this effect passed last year could've been used just as easily (in combination with the 5-EYES pact). (As an aside, there was meant to be a parliamentary review of the Assistance and Access Act earlier this year -- but I haven't heard anything about it.)
- fossuser 7y agoWithout more details I’m pretty skeptical, currently WhatsApp metadata gets turned over in warrant requests but no message content (metadata includes the times messages were sent and who they were sent from/to). It’d be a big deal to force FB to modify WhatsApp for message content interception and I think it’d be challenged in court.
- cosmodisk 7y agoThere's a funny,rag level newspaper in the UK, called DailyMail. I suggest reading comments under the article about this, gives a good idea of how naive people can be. https://www.dailymail.co.uk/news/article-7514787/Facebook-forced-reveal-encrypted-messages-terror-suspects-paedophiles.html#comments-7514787 https://www.dailymail.co.uk/news/article-7514787/Facebook-fo...
- isostatic 7y agoThe daily mail comments section makes the Mos Eisly cantina look like a respectable day at ascot.
- cosmodisk 7y agoI agree, it's pure cancer and I think right now 40-60% of UK's population has it, in varying stages..
- sofaofthedamned 7y agoThat's the nerdiest, but most British description of them ever. I'm nicking that.
- noir_lord 7y agoNothing funny about the Daily Mail, it's the mouth piece of the reactionary idiots on the right (there are just as many on the left before I get tagged as a liberal) and has been for a century give or take. This is the newspaper that had an editorial starting with "Hurrah the Blackshirts". https://www.globaljustice.org.uk/blog/2017/oct/31/horrible-history-daily-mail https://www.globaljustice.org.uk/blog/2017/oct/31/horrible-h... Other than using it as a way of keeping an eye on what some people in my society will believe (because the Mail told them to) I see zero merit in it's continued existence. It's a cancer with a masthead.
- NeedMoreTea 7y agoThe rest aren't much better. The Express and Telegraph were right facing, honest but partisan newspapers forty or fifty years ago. Now the Express is a racist comic, and since the famously and comically reclusive Barclay brothers bought it, the Telegraph is working on getting down to the Mail's level. The Mail are currently working on buying the i. There really isn't much left on the right that you can rely on. Which is depressing considering most of our press is right leaning.
- theobeers 7y agoAnother reminder that there are no secure platforms; there are protocols with (one hopes) the potential to be secure. The difference becomes more important by the day.
- Erlich_Bachman 7y agoThere are more-or-less secure platforms (which are secure up until the point where you literally try to blow up a whole country up or something). It's just that (oh shocker!) a closed-source platform held by a US corporate entity, with a privacy history of Facebook no less - no that's not a good platform to assume it will be secure. There is plenty of other much more secure options.
- markstos 7y agoWhen the article says "share users’ encrypted messages", it's not clear if it's referring to the messages in their encrypted state, or is referring to messages have been decrypted before sharing.
- deleted 7y ago[deleted]
- Barrin92 7y agofrom whatsapps official homepage, respectively (https://faq.whatsapp.com/en/android/28030015 https://faq.whatsapp.com/en/android/28030015, https://faq.whatsapp.com/en/general/26000050 https://faq.whatsapp.com/en/general/26000050) >WhatsApp has no ability to see the content of messages or listen to calls on WhatsApp. That’s because the encryption and decryption of messages sent on WhatsApp occurs entirely on your device. Before a message ever leaves your device, it's secured with a cryptographic lock, and only the recipient has the keys.[...] >A search warrant issued under the procedures described in the Federal Rules of Criminal Procedure or equivalent state warrant procedures upon a showing of probable cause is required to compel the disclosure of the stored contents of any account, which may include "about" information, profile photos, group information and address book, if available. In the ordinary course of providing our service, WhatsApp does not store messages once they are delivered or transaction logs of such delivered messages, and undelivered messages are deleted from our servers after 30 days. WhatsApp offers end-to-end encryption for our services, which is always activated Very interested to see what their response is and if their promise holds that they do not have technical access to content but merely to account information.
- smudgymcscmudge 7y agoDid you notice the article doesn't say anything about decrypting the messages? It just says they have to turn over encrypted messages.
- squarefoot 7y agoThe question should be why on Earth would they ask access to encrypted messages if they couldn't already decrypt them, or be able to do that soon.
- brenden2 7y agoIf the source code isn't available for audit by 3rd parties (or yourself), and you can't build it from source, then it was never really "secure" anyway. What lawmakers do or don't say is just noise. Platforms that rely on trust (in this case, trusting that FB isn't doing bad things) provide very weak guarantees about privacy/security. They could easily include a keylogger in WhatsApp and bypass the e2e encryption, for example, and us regular folk have no way of knowing.
- EvgeniyZh 7y agoIf the source code is available for audit by 3rd parties, but nobody you trust have actually audited it (depending on your paranoia, this may be only yourself), then it was never really "secure" anyway.
- londons_explore 7y agoThe Whatsapp binary is sufficiently transparent to enable someone determined to write their own client. Thats enough info for an expert to verify their "messages are end to end encrypted and we don't know the key" claim. The fly in the ointment is the client might have additional functionality to leak the e2e encryption key. That is far harder to find, but if it's use were widespread, it would be found by researchers. The whole point is moot though - whatsapp is designed to (by default) upload cleartext chat logs to google/apple servers. Since all chats have 2+ recipients, the conversation is only safe from snooping if nobody in the chat has backup enabled, which is unlikely.
- deleted 7y ago[deleted]
- pmlnr 7y ago1) If someone wants to find something you are "hiding", they will anyway. It's always been like this. Encryption is never a protection against this. 2) Personally I still think e2e encryption is not a secure solution on operating systems that runs godmode 3rd party, eg. google play services: it relies on a key that can be stolen too many ways too easily. Signal included. 3) internet eons (20 years) ago we nearly all used plain text IRC, closed source ICQ, AIM, etc, apart from a few. Recently I started to question the usefulness of "encrypt everything": we do need a way to verify the content from end to end, but is encryption really the way to do so? Are there any other ways, signatures, hashes, etc? 4) All that said, I'm not surprised. Skype used to be p2p, until M$ moved it to server-client, because "battery life". Everything is moving back to the Eternal Mainframe in this cycle.
- the8472 7y agoThe landscape changed. More people use the internet, more spy agencies from multiple countries siphon traffic en bulk, information of higher value is exchanged over the internet, more untrusted parties are involved (e.g. wifi hotspots). I mean go ahead, do everything unencrypted. But I surely won't entrust data to you if you're leaking like a sieve.
- pmlnr 7y ago> I mean go ahead, do everything unencrypted. That is not what I wrote. I wrote "encrypt everything". There is valuable and useful use of encryption, I'm just not certain everything everywhere needs it or benefits from it.
- the8472 7y agoIt's a sensible default since the developers don't know when users will need it and users don't want to bother to choose for every single action they take. And they may not even know in advance that they will need it. An innocent conversation can quickly turn into something confidential or private. That said, I do agree that p2p is preferable since it cuts out a central party that can be strongarmed by government being in control
- eitland 7y agoIsn't there any laws against this? I would think this should at least be against one or another amendment for Americans?
- UncleEntity 7y agoMost of what the federal government does is against one or another amendment (the 10th mostly) but gets slipped by under the commerce clause as that's how the system turned out.
- formatkaka 7y agoOff the topic, how much can we trust the keyboard we are typing on (on mobile). They probably collect everything we type. Wow !! Just realized that.
- stordoff 7y agoAs Gboard used to demonstrate: > Share snippets: Automatically share snippets of what and how you type in Google apps to improve Gboard [enabled by default]
- feanaro 7y agoYou can and should block your keyboard app's access to the network using a firewall. However, this will require root access and I've seen people jump at this point to say you absolutely should not have root access to your own phone, which I find pretty ridiculous and unacceptable.
- pier25 7y agoWhy would anyone wanting to exchange incriminating information use Whatsapp or Facebook? It seems this would only serve to catch the most stupid small-time criminals.
- classified 7y agoIn every comment thread where quitting Facebook is discussed I find commenters saying they can't because Facebook is so indispensable for them. Maybe the same is assumed for criminals?
- deleted 7y ago[deleted]
- sandworm101 7y ago>> while the U.S. won’t be able to use information obtained from British firms in any cases carrying the death penalty. Lol. So I guess it cannot be used for actual terrorism. They can use it up until an act of terrorism occurs. Then, now that murder charges are on the table, they cannot use the same date source to catch the perpetrators? The US isn't going to waive the death penalty on every terror case. That isn't politically possible. We have to just admit that US laws are increasingly incompatible with those of the rest of the world. Treaties are getting harder and harder to reconcile. The US needs to back off its departure from international norms.
- tboughen 7y agoBut it can facilitate parallel construction in cases mandating the death penalty. https://en.m.wikipedia.org/wiki/Parallel_construction https://en.m.wikipedia.org/wiki/Parallel_construction
- verizonuser 7y agoOne can infer that the NSA cannot break strong encryption used in WhatsApp.
- stordoff 7y agoOr they want political cover to avoid revealing their capabilities, or to enable that data to be used more easily in court or for a wider range of offences.
- avip 7y ago@mods pls change title
- burtonator 7y agoHere is what is most frightening. So let's say this law passes BUT someone builds a really good open-source messenger. You can't install it now because you can't side-load apps on devices. You alpha geeks can but the other consumers can't. What we need is a law requiring some type of side loading. It needs to be possible to go to a website, and install an app there directly and have it support all of the native platform features.
- Erlich_Bachman 7y ago> You alpha geeks can but the other consumers can't. Isn't it literally enabled by 1 simple setting in developer options on an Android device?
- beatgammit 7y agoBut it is. I installed F-Droid by visiting a website, so it's definitely possible. Maybe you're talking about Apple specifically? Afaik, there's no way to do that on iOS (though I read a related article about it recently, I think it was here), so if you want that, petition Apple. There's no law preventing it given that Android devices can do it, so it's just an Apple policy, and you can always install apps through XCode if you want to.
- classified 7y ago> So let's say this law passes In that case, would you expect the people who wanted this to actively create a means for its circumvention?
- johnisgood 7y ago> So let's say this law passes BUT someone builds a really good open-source messenger. > What we need is a law requiring some type of side loading. You are asking the bad guys (passing bad laws) to be good (passing good laws). I do not think those expectations are realistic.
- nabla9 7y agoNowhere in the article is backdoor mentioned. Only sharing data that is encrypted. US an UK governments can't just force FB to add backdoor. It would require new legislation. FB must play ball for that to happen. Since WhatsApp has forward secrecy and end-to-end encryption, giving access to encrypted data is not easy to use. There might be some useful metadata that helps though.
- shostack 7y agoThere's also value in storing and archiving encrypted data because at some point in the future technology may enable them to decrypt it. Certain communications could prove quite valuable, even if old.
- Nasrudith 7y agoHaving a large base of encrypted messages to work from is essentially a prerequisite for pattern analysis related attacks and finding weaknesses.
- jcriddle4 7y agoThere is absolutely zero ways for WhatsApp and other to comply unless there is a back door. If the Senate votes on this treaty then it has the exact effect of legislation.
- nabla9 7y agoTreaty would not include backdoor. It would be just access to encrypted messages. Unless the law enforcement has access to the phone used to send the message, encrypted messages are useless.
- m0dest 7y agoAgree. The title of this post is dangerously deceptive and should be changed. The linked source does not claim or substantiate any backdoor. >"will be forced to share users’ encrypted messages with British police" So far, all the article is saying is that ciphertext will have to be shared. Anything about decrypted messages is speculation at this point. (It would be very bad if a backdoor will be forced.)
- angel_j 7y agoPolice can only search what belongs to the company. If it the data is yours, and the keys are yours, then the company can only provide it by theft (if at all).
- tinus_hn 7y agoNot sure what they’re planning to do with these encrypted messages though.
- villgax 7y agoI think everyone needs to focus on protocol more than apps per se.
- Lordarminius 7y agoAt what point did the world adopt the standard that all private communication is government business ?
- rocgf 7y agoAs a lot of other things, it happened step by step, with the main catalyst being 9/11. We somehow accepted that it's an acceptable trade-off to have no privacy in the name of stopping "the terrorists". "You're either with us, or a terrorist" Bush once said. And now we're at a stage where it's acceptable to say things like "if you've got nothing to hide, why are you so worried about this stuff?".
- akerro 7y agoOk, so next years WhatsApp will have backdoor and ads.
- A4ET8a8uTh0 7y agoI am weirdly.. giddy about this development. The more goverments try so hard to publicly force companies to, effectively, mandate backdoors, the more public will be aware of it. Added benefit is that FB will lose some market share. The sucky part is.. my mom loves Whatsapp. She was able to use it wo any issues. There are few alternatives that she was able to use so easily. All that said, I wonder. What is the breaking point for people surveillance-wise? I was so wrong a lot about the tolerance already..
- deleted 7y ago[deleted]
- Smithalicious 7y agoYou are assuming that the public isn't aware of it and would care if they were. I think the public is aware of it, they just don't care.
- A4ET8a8uTh0 7y agoI wish I could say you are wrong. I definitely saw people on both ends, but I can't say with certainty which is more common. People is US had a joke about wiretaps and a variation of the joke returned. People change based on stimuli.
- fsloth 7y agoUnless your mom is planning to involve herself in illegal activities I don't see a problem. Most electronic communication channels are compromised anyway. If you don't want eavesdroppers, don't use electronics.
- jedberg 7y ago> Unless your mom is planning to involve herself in illegal activities I don't see a problem. I assume you'd be happy to post all your credit card receipts and emails for all of us to see then. You're not doing anything illegal, right? That would be the only reason you don't want those things to be visible.
- nairboon 7y agoSo to which messenger should we finally switch to? Telegram, Signal, Threema, Wire or some other newcomer?
- OrgNet 7y agomatrix seems pretty good, but it is still young and buggy (at least with the the client that I use, riot.im)
- feanaro 7y agoFor some contrast, I find Riot (web and desktop) quite nice and usable these days. There are still a few rough edges, but it's good enough as a "daily driver" for me.
- ptman 7y agoWhat's buggy?
- OrgNet 7y agoOne example is that voice calls only ring on one side, sometimes (on the calling side). Another is that when some rooms get updated, you can get unread notices from the old room and your client keeps telling you that you have new messages even if you don't. Another thing that I think should be considered a bug, is that when you enable encryption in a room and you have multiple devices on the same account, you have to approve all your devices separately so that they will be able to decrypt the messages... There are more bugs related to how the encryption process works and I stopped using encryption because of it (some might have been fixed by now...)
- ptman 7y agoThe encryption things are being worked on. Encryption is still in beta. I think riot fixed that problem with the unread notices. Have you reported the bug about calls only ringing on one side?
- 7y ago
- ISL 7y agoCongress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.
- jedberg 7y agoI believe the courts have ruled previously that your speech is not limited just because the government has access to it. Otherwise wiretaps would be illegal already. This is just an extension of wiretap law. In both cases they need to be fought from another angle than freedom of speech, because we've already lost that battle.
- ISL 7y agoIf I wish to send you, jedberg, a message that looks like: C8hWgwo5YeC5ojiOaDe3JVaLev+3zaZDfRVTAjvqNCA= ("Jedberg is thoughtful.", encrypted with AES key jedberg). I must be able to do so. To compel a backdoor is to make some speech illegal.
- jedberg 7y agoThe courts have already ruled that it’s ok to make speech illegal in the name of public safety.
- ISL 7y agoTo me, C8hWgwo5YeC5ojiOaDe3JVaLev+3zaZDfRVTAjvqNCA= is a lot less harmful than shouting "Fire!" in a crowded theater. Banning C8hWgwo5YeC5ojiOaDe3JVaLev+3zaZDfRVTAjvqNCA= is akin to banning shouting in a theater, for any purpose. In particular, the banning of political speech is highly protected. One cannot readily show that C8hWgwo5YeC5ojiOaDe3JVaLev+3zaZDfRVTAjvqNCA= is not political speech (and indeed, here, it is).
- einpoklum 7y agoIn other news: US, UK subjects agree to stop using WhatsApp in favor of Telegram and Signal: https://telegram.org/ https://telegram.org/ https://www.signal.org/ https://www.signal.org/ These are free software, not controlled by a giant corporation (although both are limited liability companies; Telegram in London/Dubai, Signal in San Francisco IIANM); with the developer/company not having unencyrpyed access to your data.
- damnyou 7y agoTelegram group chats are not e2e encrypted, while Signal is notorious for being unreliable at actually delivering messages. Also, if you change your phone number the official Signal recommendation is to manually tell all your friends about the new number. WhatsApp just lets you do it. I use both apps regularly but neither of them is perfect.
- anigbrowl 7y agoYeah timely message delivery is a big problem for Signal. It doesn't happen often but when it does the delay can range from minutes to hours. A few years ago my wife and I failed to meet up as arranged and had a big yelling match until we looked at our phones half way through. The delay of some messages and not others led to almost exactly opposite beliefs about the electronic conversation we thought we had been having.
- smcleod 7y agoOut of interest what is your citation for Signal being nutritious or having messages going missing? Anecdotally speaking, neither I or my friends that have been using Signal for years have every had any messages go missing, so I’m just interested as to why you might be experiencing this.
- damnyou 7y agoEvery single person I know who uses Signal has complained about this. I'm glad Signal is reliable for you but that is not our experience.
- jchw 7y agoDoes anyone have any advice for what platform might be best to migrate to? I'm not overly concerned with group E2E, but it is a nice-to-have. Telegram and Discord seem like two of the most practical options, Keybase and Matrix seem like two of the most ideal from a security standpoint. I wonder what offers the best cross-section of features and user experience.
- e12e 7y agoMatrix or Signal?
- dvdgsng 7y agoFor the interested, matrix project lead answered many questions regarding security and encryption in yesterday's AMA: https://www.reddit.com/r/privacy/comments/da219t/im_project_lead_for_matrixorg_the_open_protocol/ https://www.reddit.com/r/privacy/comments/da219t/im_project_...
- coolspot 7y agoTelegram is not EtE encrypted by default. Only special “private chats” are and they unavailable on desktop.
- jchw 7y agoYeah, I am aware of that. E2E isn't necessarily a hard concern, but E2E with backdoors actually feels worse to me than just not having E2E to begin with (I do wish Telegram were less misleading about this issue, however.)
- dehrmann 7y agoMeanwhile, the US government (mostly Trump) is banning Huawei equipment over spying concerns. Apparently the only concern is that we weren't the ones doing the spying. This really hurts our credibility on a government level outside the Five Eyes.
- GordonS 7y agoThe idea that moves like this will "keep us safe" is utterly preposterous; there are a multitude of other ways in which terrorists (or the boogeyman de jour) could communicate - are the UK and US governments going to insist on backdooring IRC, Slack and face-to-face conversations? Are they going to outlaw encryption libraries? I truely fear for the future that western governments, in particular the 5 eyes members, are hell-bent on creating. They denounce China and Russia for their human rights records in one breath, and seek to strip us of privacy and personal rights in the next - the hypocrisy is simply staggering. What's perhaps even more frightening is that so many people believe that moves like this are to keep us safe, will keep us safe. This can not end well...
- shrimp_emoji 7y ago>moves like this are to keep us safe From the government's perspective, they are to keep "us" safe. It's easier to do that if no one's safe from us. :) Granted, that's a little over-ominous because the government's mission statement is to keep its people safe, and it's also elected by its people. Either of these two facts changing is the way bigger danger; backdooring centralized services is stuff that happens in the meantime either way.
- philipov 7y agoIf you look at the way elections work at a micro scale in the US, you will begin to lose confidence in the assumption that they are elected by the people. Political machines have huge influence in controlling who it's possible to vote for, and swaying low-information voters. That makes sure they have a lockdown on decision-making, even if they allow a few mavericks through the cracks for the sake of plausible deniability. Even if this or that individual politician gets voted out, or even ten of them, it won't stop the machine's influence. They're still the ones who decide who the replacements can be chosen from.
- autokad 7y agoFrom what I can tell, it seems like the US is not forcing a backdoor. is that correct? This sounds like UK is forcing the issue. However, I don't care if it "keeps us safe". It's just wrong in so many ways
- chooseaname 7y ago> Social media platforms based in the U.S. including Facebook and WhatsApp will be forced to share users’ encrypted messages with British police under a new treaty between the two countries, according to a person familiar with the matter. Would Apple's iMessage qualify? (I can't read the whole article because of the paywall).
- jcriddle4 7y agoI suspect Facebook has wanted an excuse to remove the end to end encryption and avoid the negative publicity at the same time. Done.
- usgroup 7y agoI think the implication is just that Whatsapp has to hand over encrypted messages ... I'd imagine if the police are then in control of the target mobile they can decrypt those messages. Tbh, if my understanding is correct, I'm not sure I see any problem there. It's targeted at specific individuals for good reason (presumably following a warrant process) and requires both the messages (from Whatsapp) and they keys (from the individual's device). What's the problem?
- jimnotgym 7y agoSo we are back to using code words, one time pads etc? This will do nothing except intrude on civil rights.
- johnisgood 7y agoYes, this is exactly what I meant when I said that you either do what the Government says, or you go down. This is why I do not believe statements of privacy from Apple (such as we keep your data safe, 100% secure, etc.), for example. If they really have no backdoors or any other ways for the Government to access your data, then the Government would go after Apple. If the Government were to request your data, they would hand it over, right? Is this incorrect? If yes, why?
- chillacy 7y agoApple fought a court battle over this and won. If the government just beat the CEO over with a rubber hose until they built in backdoors, why would they bother publishing a public treaty or trying to amend the laws?
- deleted 7y ago[deleted]
- nindalf 7y agoYes, this is something that literally everyone who reads HN will oppose. Meanwhile do you hear the deafening silence from the average Joe who thinks he has "nothing to hide"? Don't hate the politicians who keep pushing this. They're just trying not to get fired. And the surest way to get fired in a western country right now is to be seen doing nothing about the terrorism problem and then having terrorist acts committed under your watch. So the politician asks the security forces "what can we do to stop terrorism?" Security says "get us access to messages of terrorism suspects". Seems reasonable, let's go ahead with it. Yes, we know that it doesn't stop with terrorism suspects. Then law enforcement wants to read the messages of drug kingpins, then drug suspects, then shoplifters, then jaywalkers, then everyone, just to be on the safe side. But as long as people are told that they need to give up some privacy in exchange for security, they'll take the latter every time.
- spo81rty 7y agoYou are absolutely right. I also already assume the government can access virtually anything I am doing anyways. I think we are all naive to believe otherwise. I also have nothing to hide :-)
- Lutzb 7y agoMy questions to people who say they have nothing to hide: - what are the things you and your significant other are doing in the private of your house? - which co-worker do fantasize about, be specific in what you like to do. - As teenager what legal/illegal drugs did you consume. How often did you pass out, who where the people you consumed these drugs with? - What are your political leanings? - How much do earn, where are your savings invested in. - Which illnesses do you currently have, which exist in your social circle. - what private information was shared with you by other parties. Are you aware of any wrong doings/illegal activity by other people? Be specific esp. friends and family. Be aware that I will share this information with anyone in your social group/work/volunteering work whenever I feel like it. I may also share this data with extremists groups on the other side of the spectrum, if helpful. Lastly I can use this data to fabricate "helpful" information about you if necessary. Thank you.
- perfectstorm 7y agowhy are they exempting Apple's iMessage then?
- guiomie 7y agoWhat are the alternatives to facebook and whatsapp? Is there anything open source and p2p that can be used to replace facebook?
- XCSme 7y agoDepends on what you use Facebook for.
- _emacsomancer_ 7y agoA backdoor that will be exploited by criminal third-parties. Even if you (against all sense and reason) trust the US and UK governments, this is a move that will expose your data to criminals.
- vbezhenar 7y agoNot necessarily. Simplest implementation is to use government public key to encrypt session key and include that encrypted session key into a message. You can implement it with open source code, yet only government who possesses corresponding private key can decrypt the message. I think that it'll be secure enough. If private company can keep their CA key in secret, government can do that too. Hardware Security Module stored in defended military place and guarded by soldiers, available for use only by authenticating of the few key politiancs.
- _emacsomancer_ 7y ago> only government who possesses corresponding private key can decrypt the message Yes, that sounds like a secure system. Surely no private keys would ever leak out of a government through incompetence or corruption.
- corndoge 7y ago"Social media platforms based in the U.S. including Facebook and WhatsApp will be forced to share users’ encrypted messages with British police" Does this mean they're sharing ciphertext or plaintext? Anyone know?
- mayop100 7y agoThe title is inaccurate. This does not require a backdoor. The agreement changes nothing about the use of encryption. https://twitter.com/mmasnick/status/1177979730932297728?s=21 https://twitter.com/mmasnick/status/1177979730932297728?s=21
- jonplackett 7y agoI agree it would be good for police to be able to look into a criminal’s phone, but how will they actually achieve this without wrecking the encryption for everyone?
- lttlrck 7y agoIMHO editorializing this as a ‘back door’ is inflammatory. Users need to learn to not have any expectation of privacy when using social networks. It extends far beyond PII leaks. Perhaps complaints should be directed at the root of corruption/abuse of such systems, at least as much as the capability itself. The capability is inherent to the technology just as tapping a phone line is. Telcos have to provide interception capabilities (CALEA in the US) or they are not allowed to operate. This has been true for decades, most people do not know how that works but they do know it is possible. As these social media communications services become more entangled in our lives perhaps they too could be deemed essential infrastructure and treated as utilities.
- DanBC 7y agoI agree. The proposed law is a bit confusing. The UK already has forced key disclose under RIPA. https://www.legislation.gov.uk/ukpga/2000/23/part/III https://www.legislation.gov.uk/ukpga/2000/23/part/III
- screwunatzi 7y agoIt's the Russians that continuously screw us up the only want control to run their gang activity,sex trafficking child molesting pure EVIL into our country the one's that bring this and terrorism should be put to death they are also racist natzi white supremacist
- andrerm 7y agoThere are really smart and empowered people just waiting for really dumb but empowered people to make the move that opens the path to constant mass surveillance.
- nradov 7y agoIs this literally a treaty that will be submitted to the US Senate for ratification and thus carry the force of law, or is it merely an executive branch agreement on cooperation? Does anyone have a link to the actual treaty text?
- decafbad 7y agoI thought there are backdoors already. This must be a diversion.
- andrerm 7y agoIs this treaty public? Where is it?
- louwrentius 7y agoIn The Netherlands a government VPN solution was left unpatched for many month, exposing critical infrastructure to any third-party hacking nation state. I'm not a right-wing anti-government nutcase. I do believe that the government will not be able to keep such a back door secure.
- lordnacho 7y agoNot my area of expertise but would it not be relatively easy for someone to make their own app using open source and put it in an apk for ordinary phones? I've messed around with the open source cryptography libs before and I don't see why someone could not do that. There's even a fair bit of advice about how not to misuse such libs.
- concordDance 7y ago> serious criminal offenses including terrorism and pedophilia sigh "Pedophilia" is not a crime, child rape is.
- jarjoura 7y agoWhy is this article Facebook focused? Is this click-bait? Telegraph and iMessage also support unbreakable end to end encryption. Also, if we're talking backdoors, why not just force Apple to unlock devices so that police can just read the messages in WhatsApp directly? That's something I could get behind as it means the intelligence community has to at least have the physical device on hand. Do people have actual links to this treaty they're about to sign and what the exact wording is? I remember there being this 5-nation meeting in the summer with Canada and Australia that was specifically looking to lobby Facebook to open WhatsApp. Haven't seen anything new since.
- OrgNet 7y ago> [...] has to at least have the physical device on hand. not really since most of them are connected 24/7
- jarjoura 7y agoOk, I'm starting to think this article is click-bait. There is no need for a backdoor with WhatsApp because messages are stored on the device. If police have the device on hand, they should be able to see the messages (assuming they can unlock it.) https://www.facebook.com/safety/groups/law/guidelines/ https://www.facebook.com/safety/groups/law/guidelines/ > International Legal Process Requirements > We disclose account records solely in accordance with our terms of service and applicable law. A Mutual Legal Assistance Treaty request or letter rogatory may be required to compel the disclosure of the contents of an account. Further information can be found here.
- DanBC 7y agoThat would be overt surveillance, and the security services are claiming they need the backdoor for covert surveillance.
- fortran77 7y agoEncryption are "munitions", right? I wonder if there's an argument in the U.S. that this violates our right to "bear arms". It's also interesting how the Left and Right flip positions when arms are digital.
- samstave 7y agoWtf is HNs lack of knowledge of history? We have known since at least 1997 that all Cisco (and other) equipment has had backdoors in them. Like why the fuck would you even be surprised at this at this point. EVERYTHING YOU DO IS CAPTURED. Downvote away yee who are uninformed
- wcathcart 7y agoWe were surprised to read this story and are not aware of discussions that would force us to change our product. We believe people have a fundamental right to have private conversations. End-to-end encryption protects that right for over a billion people every day. We will always oppose government attempts to build backdoors because they would weaken the security of everyone who uses WhatsApp including governments themselves. In times like these we must stand up both for the security and the privacy of our users everywhere. We will continue do so. Will, Head of WhatsApp
- spuz 7y agoSo are you saying the backdoors will or won't be introduced to WhatsApp?
- wcathcart 7y agoWill not. We are completely opposed to this. Backdoors are a horrible idea and any government who suggests them is proposing weakening the security and privacy of everyone.
- spuz 7y agoThanks.
- benevol 7y agoAs much as would like to believe all promises coming from corporate execs - Facebook has been caught lying more than enough. So thanks for trying, but I have uninstalled WhatsApp and I'm happy with Threema.
- ripdog 7y agoHave you considered Riot (Matrix) or Signal? Both are open source so it's possible to verify claims made on their website, which is a lot less possible with proprietary software like Threema.
- phkamp 7y agoSounds familiar... Ohh, right: https://queue.acm.org/detail.cfm?id=2508864 https://queue.acm.org/detail.cfm?id=2508864
- m0dest 7y agoMods, please fix the post title. The idea of a backdoor is speculation that is not substantiated by the article. "will be forced to share users’ encrypted messages with British police" So far, all the article is saying is that ciphertext will have to be shared.
- cfv 7y ago> "The U.K. and the U.S. have agreed not to investigate each other’s citizens as part of the deal" Sweet Jesus this people are insane
- deleted 7y ago[deleted]
- Fakira 7y agoI have long stopped using American social media for anything. I think everyone else should do the same.
- ac2u 7y agoMods: Is this title accurate? It makes it sounds like an encryption back door, but from reading it sounds more like social media companies being forced to provide the cyphertext. (with the authorities then being in a position to compel the end users to give access to devices).
- rahuldottech 7y ago> Social media platforms based in the U.S. including Facebook and WhatsApp will be forced to share users’ encrypted messages with British police under a new treaty between the two countries, according to a person familiar with the matter. This might mean "...must share messages that are otherwise encrypted", it's not completely clear from the language used.
- johnisgood 7y agoFeels like the perfect time to read the "Anatomy of the State" by Murray Rothbard. It is only 62 pages long. You can find the book here: https://upload.wikimedia.org/wikipedia/commons/4/45/Anatomy_of_the_State.pdf https://upload.wikimedia.org/wikipedia/commons/4/45/Anatomy_...
- deleted 7y ago[deleted]
- johnflan 7y agoI wonder does this also apply to services like Apple iMessage
- deleted 7y ago[deleted]
- daodedickinson 7y agoIn before a gov't forces someone into pregnancy through the "front door" just cuz
- tehjoker 7y agoJust a reminder that anytime they breach communications like this, it's because they want to be able to spy on their own citizens in order to subvert and control opposition political movements. For example, climate activism, whistle blowers (e.g. Snowden, Reality Winner, the guy that talked about the Ukraine deal if it wasn't an official CIA leak), animal rights, anti-imperialists, etc.
- HashThis 7y agoUS Citizens don't need to worry. All of your private information will be turned over to the NSA / US Gov. If the US wants a US citizens private info, they just request it of the UK's intel services. The UK Intel services get it from Facebook, and they then hand it to the US Gov. For your convenience.
- neonate 7y agohttps://outline.com/9LpW2E https://outline.com/9LpW2E
- jka 7y agoGoing by the original Sunday Times (UK publication) article[0], it looks like this headline relates to _upcoming_ data sharing legislation which UK Home Secretary Priti Patel[1], who took that office this July, is expected to sign in October 2019. It's worth putting scrutiny both on the UK's desire to create these backdoors in social media apps (a path that many would argue could lead to eventual exploitation and abuse of that backdoor by unintended parties), and also WhatsApp's ability to deny the existence of such backdoors, now or in future. [0] https://www.thetimes.co.uk/article/police-can-access-suspects-facebook-and-whatsapp-messages-in-deal-with-us-q7lrfmchz https://www.thetimes.co.uk/article/police-can-access-suspect... [1] https://en.wikipedia.org/wiki/Priti_Patel https://en.wikipedia.org/wiki/Priti_Patel
- whycombagator 7y ago> Social media platforms based in the U.S. including Facebook and WhatsApp will be forced to share users’ encrypted messages with British police If true, I wonder if this includes other US based apps like Signal
- natch 7y agoI am not one to believe what I read on Bloomberg but the story does say "will be forced to share encrypted messages..." If that's all this is, good luck to them doing anything with those.
- zaro 7y agoI see some comments are raising this topic with nothing to hide. But people on both sides, do you think it's OK for you to have nothing to hide, but the government that rules you has something to hide? For me it's not so much whether I hide something or or, but rather that if I'll be living under nothing to hide paradigm then the people controlling that should also live under the same. And actually not only the people but rather the institutions. So if an institution is having access to all citizens data that is being collected then the citizens should also have transparency on each decision made and each cent spent by this institution at any time.
- Havoc 7y agoUK seems to be doing all sorts of crazy shit right now so not all that surprised that people are finding out about this via news