18 ms·
DOJ plans to strike against encryption while the Techlash iron is hot
- mindslight 7y agoMITM-as-a-business has been nothing but a slow motion train wreck destroying individual liberty. FAANG may bicker with the DOJ/NSA (and Ma Bell) about who is in control of all the surveillance data, but none of them are fighting for we the people. They're all just jockeying over who gets to rule. The sane response to corporate totalitarianism is most certainly not government totalitarianism. Sadly with how the two political salesteams frame a false division merely over different flavors of authoritarianism, this has a good chance of working. As always, the true answer is trustable software running under the control of users ourselves. Unfortunately, we will have to see how bad things get before most people are driven away from all of these centralized attractive nuisances.
- Ididntdothis 7y agoVery true. Nobody cares for the individual citizen. It’s just a power struggle by large players on the backs of the little guy.
- coldcode 7y agoYou first DOJ. These folks want back doors so they can read everyone's traffic, but once you put a back door in an encryption standard, it affects everyone.
- behringer 7y agoMy favorite interview over the last few weeks is from NPR when a guy in law enforcement said that police don't even use that type of encryption (that normal people use) as if he forgot that his police radio, payroll, camera footage, information storage, are all most certainly protected via encryption.
- Klonoar 7y agoI found this exchange amusing as well, for a slightly different reason. The gist of his point was that "who needs this level of encryption, other than maybe the military?". Substitute guns instead of encryption and see how that fits.
- bcrosby95 7y ago> the “techlash” by Congress and the public “in the wake of myriad privacy scandals” and the 2016 election This just makes my head explode. Because tech companies tend to be poor at privacy, let's use that logic to make it so the government can invade your privacy anytime they want?
- IAmEveryone 7y agoIt’s basic enemy-of my-enemy logic. It’s not always correct, but often enough to remain a powerful heuristic. It would be interesting to know if anybody has thought deeper about it, and if there are specific strategies of persuasion that work better in such situations? I’d intuitively think it might be beneficial to acknowledge the cognitive dissonance people might be experiencing when arguing this matter.
- Allower 7y agoNot even just the government, backdoors aren't specific to one actor or another. They are literally trying to make it easier for criminals to commit crimes, that makes my head explode as well..
- orblivion 7y agoThis is a world where (at least it seems to me) the same people are against net neutrality legislation but want the government to regulate Facebook. By the time you get into the nuances of why the tech companies support encryption in some cases, you've lost the PR game.
- chubs 7y agoMaybe the pitch to voters is: "Your privacy is already toast, your information is being used for ads, why not let us use it for counterterrorism?"
- joe_the_user 7y agoYeah, "techlash" is a weird term but it's as good as any I've heard for the phenomena. I have plenty of these amorphous attacks on Facebook in particular here on HN, where you get some amount of too much sharing, some amount of "it's just like drugs, man", some amount of too much privacy and so-forth all cobbled together into some sort of complaint. A lot of smart people seemed to get on board that train without thinking much.
- shuckles 7y agoInteresting to read in context of the fact that public sentiment surveys suggest there is no “techlash” at all.
- zadkey 7y agoI agree. It kind of feels like the media is pushing a "techlash" narrative where there is none.
- zadkey 7y agoOverly large companies wield disproportionately large amounts of influence in our lives and probably should be regulated more. But that disproportionate influence doesn't mean "tech" is the root cause. There shouldn't be a backlash against tech companies specifically, but really companies that are overly large and use and abuse their power and position in ways that benefit shareholders in ways that are severely detrimental the common good. Such as limiting competition, influencing and manipulating legislation, ensuring people have no other options and then raising prices exponentially, selling your data to the highest bidder, etc.
- majos 7y agoCan you provide a pointer to such surveys? In my head the popularity of articles bashing tech companies is out of proportion to people's patronage of those same companies, but numbers would be nice.
- jMyles 7y agoWe tried to respond thoughtfully to each of the strange arguments made by the DoJ regarding the need for encryption backdoors to protect children: https://blog.nucypher.com/todays-kids-need-end-to-end-encryption/ https://blog.nucypher.com/todays-kids-need-end-to-end-encryp... It's difficult at this point to think that the DoJ is arguing in good faith.
- munchbunny 7y ago> It's difficult at this point to think that the DoJ is arguing in good faith. I think people in the tech industry, and especially people working on security or privacy, have known this for over a decade. Unfortunately, the public doesn't pay enough attention to the issue. And why would they? They have enough things to worry about, why pay attention to one of the things that is currently working? It's unfortunate that we're not that good at PR.
- addicted 7y agoIsn’t the tech lash for the complete opposite reasons? The fact that too many people have too much of our data? Why would people (outside of effective propaganda, which would be true even without the tech lash) support something that makes their problems worse?
- alistairSH 7y agoHuge portions of the population (Congress included) are technically illiterate. They don't know any better.
- strbean 7y agoIt's almost like people think their personal data is zero-sum - if we give it to the government then companies won't have it! Just like if you download a car, someone else loses that car. Makes me think of the Israeli voter rolls hack[1]. [1] https://www.cnn.com/2020/02/11/tech/israel-voters-data-exposed-intl/index.html https://www.cnn.com/2020/02/11/tech/israel-voters-data-expos...
- riazrizvi 7y agoExactly. But for the people that want that data, for the people who will pay for it, FUD is a great political tool, and this issue is too subtle for most people to get. I've tried to explain to my family, how the abdication of private behavior logs to some companies is creating economic/political inequality that may forever destroy norms of fairness & competitiveness that we enjoy, but they just don't get it... For example, a friend worked at a proprietary hedge fund of a major US bank that was looking into the private accounts of their customers to drive trading decisions. Other investors can't compete against that, stock market investment is no longer fair. And you've broken a fundamental component of the economy, a fair & transparent investment system.
- summerlight 7y agoIn fact, user data usage and share is a multi-faceted issue. The most obvious stances are (but not limited to): * Pro-privacy claims that big techs share their user data to too many irrelevant entities. * Pro-competition claims that big techs monopolize uses of their user data. * Pro-regulation claims that big techs don't share their user data to accountable government entities. Each of those arguments has some valid points but also conflicts to each other in a some degree.
- caleb-allen 7y agoA small anecdote. A few years ago in an undergrad business class, we were having some discussion and the topic of encryption came up during one of my presentations. A student asked a question related to the ethics of encryption (I don't recall exactly what), and I was clearly confused by the question. To clear up confusion, the professor asked those who thought encryption was "bad" to raise their hand, and at least 60% of the class raised their hands. It was pretty jarring to me, and makes me pessimistic about the outcome of a DOJ campaign to demonize and regulate encryption
- westmeal 7y agoIt sounds like a majority of the students had no idea what encryption was and because the authority figure (the professor) asked them whether or not it was bad they just went with it? I'm having trouble understanding why people would say mathematical functions are bad.
- wyldfire 7y ago> why people would say mathematical functions are bad. People don't think 'encryption' is a mathematical function. They think it's like a radar detector in your car. "Why would you have it unless you intend on speeding?" [goes their thought process] "Oh I use this frequently and things I do every day would be totally broken without it? Really?!" [is the realization we hope dialogue could bring]
- u801e 7y agoThen again, given speeding is so widely accepted, radar detectors are legal to use in 49 out of 50 states. It would be nice if encryption was viewed the same way.
- blattimwind 7y agoIsn't (relatively) strong encryption legal in every one of your 50 states and deployed to more than 10^10 devices globally?
- scarface74 7y agoI’ve posted plenty of times on HN about the danger of the government being overly involved in tech and the last thing you should want if you value your liberty is more government involvement. I’ve also warned that giving government more power to “protect” people from big tech would come back to bite the very people who for some strange reason trust government. Every time I’ve been downvoted to oblivion. Now the chickens are coming home to roost.....
- Goronmon 7y agoSo, you can't trust the government to oversee the tech companies. You can't trust companies to protect privacy. You can't trust voters/users to make good decisions on voting for the government or choosing the "right" companies to support. That doesn't leave a lot of options, unfortunately.
- scarface74 7y agoIt’s called free will. You can logout of Facebook You can not use Google and use an ad ad blocker. You can buy online from some place besides Amazon You can not buy a mobile phone running an operating system written by an ad company. What you can’t easily do is change your government.
- cortesoft 7y agoYou can't solve a collective action problem just with free will, though. You can choose not to use those services and still have your privacy invaded, through other people posting things about you, cameras in public spaces, phone tracking, etc. You can choose to live like a recluse to avoid this (no phones, stay out of public places, don't let friends take your picture, etc), but saying that is a reasonable choice is ridiculous. This is like people who say "well, if you don't like how the credit bureau's operate, just don't use credit! Sure, you can do that... but you won't be able to ever buy a house, get many jobs, fly on an airplane, etc. More and more restaurants and stores are even going 'cashless'. It might technically still be a choice, but it is not a reasonable one you can expect people to make.
- komali2 7y agoConspiracy theory: The NSA hamfistedly contributed to various leaks in the same way the CIA gave guns to terrorists, i.e. by providing various groups with the tools they'd need to break into American companies. Now they can capitalize on it - "see, tech companies can't be trusted with your data. Trust us instead."
- dr-detroit 7y agoBut we can't trust tech companies. I trust my government much much more they answer to me and awsgooglebook doesn't
- afrcnc 7y agoI might be ok with this, but not while incompetents like Trump are at the wheel.
- flyingfences 7y agoIf your system relies on "the right people" being in charge but does not guarantee that those people are in charge then it is a terrible system.
- cpitman 7y agoWhich previous administration would you be ok with passing these laws?
- afrcnc 7y agoRoosevelt
- cpitman 7y agoIf Roosevelt enabled/required these back doors, what would stop all future administrations, including the current one, from doing what they want? IE, why is it any different for a past administration to make these changes compared to the current administration? Expansions of executive power tend to be permanent.
- btilly 7y agoWhy does this say that the DOJ has been pushing for this since 2016? They have been pushing for some variation on this since basically forever. I first became aware of it back under Clinton with the https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Clipper_chip. And the debate has been essentially the same since. Law enforcement wants to be able to break security, and promises that their super secret, super safe system will provide everyone else protection from evildoers while letting law enforcement find the bad guys. Cryptographers have maintained that when you create a back door, it is a question of time until it is found and publicized. And the back door doesn't even have to be found to be abused. Because it will be made available to law enforcement and the courts. Which are surprisingly easy for third parties to subvert. And which are happy to build programs for themselves that break the rules that they are supposed to follow. (Snowden anyone?) Success has gone to both sides. But on the balance, the cryptographers have been right.
- SuperFerret 7y agoCryptographers and liberals.
- giggles_giggles 7y ago> Why does this say that the DOJ has been pushing for this since 2016? Because that's when Trump came into power and nothing bad ever happened under the Obama admin.
- tick_tock_tick 7y agoThere seems to be some kind of intentional ignorance of just how many programs people blame Trump for have been there since Obama or even earlier.
- shadowgovt 7y agoA President (and the priorities of his administration) can make bad programs much worse. Take marijuana enforcement as an inverse example. The federal law around marijuana hasn't changed, and it's as illegal in 2020 to use, grow, and sell as it was in 2004. But the Obama administration made clear to the DEA and FBI that pursuit and enforcement of that law in states that had passed their own laws to legalize it would be a career-limiting move, which gave the states breathing room to experiment (and allowed hard evidence to gather that allowing medicinal and recreational use wouldn't cause societal collapse or, really, almost any negative outcomes). This aspect of the intersection of law and executive enforcement is why the Trump administration is correctly condemned for worsening the situation regarding immigration in the US. Most of the laws the administration uses have been on the books since before 2016. This administration chooses the harshest and cruelest ways to interpret and execute on those laws.
- whytaka 7y agoQuestions to the public should be phrased: “Do you want Chinese style surveillance to be advanced in the United States?”
- dchyrdvh 7y ago+1. This is something tech bros don't seem to get, while politicians get very well: the majority is driven by emotions and has small cognitive ability, but they vote and thus arguments to win their vote must be trivial emotionally charged ideas. A politician says "encryption is a tool of criminals!" and those who start arguing in the rational plane have already lost; instead, the answer should be "lack of encryption enables Chinese style totalitarian communism!" - no need to explain the details, just push their "scary communism" button and let the public contemplate on the "crime vs communism" topic.
- A4ET8a8uTh0 7y agoAgreed. I wish I did not have to agree, but framing has proven to be very important.
- brian-armstrong 7y agoPeople do want that, though they might not admit to it. I think this would backfire. In general Western democracy is inconvenient for most people today.
- Ididntdothis 7y agoAre there any concrete proposals on the table that can be looked at? This feels to me like one of the typical debates where people are shooting at each other but nobody understands what they really are talking about.
- wyldfire 7y agoI think you're mistaken. Virtually any proposal that the government might offer will be a key escrow. We already know it's bad and why it's bad, because it's been debated for decades. I don't think there are any more novel solutions that should revitalize the argument. The problem isn't that there aren't enough oversight mechanisms or checks to prevent abuse. The problem is that the design has unfixable security defects.
- Ididntdothis 7y agoYou say “might offer”. Have they offered anything?
- SpicyLemonZest 7y ago"Offer" is perhaps an overly positive term. The DOJ has issued a number of speeches, letters, etc. insisting that tech companies must build a backdoor to let the government decrypt messages as required.
- Ididntdothis 7y agoI know but I have never heard any details especially how they want to keep the backdoor secret. Cracking the backdoor would be such a high value target that a lot of people would spend insane amounts of money and energy on it.
- JoshTriplett 7y agoDo not under any circumstances let the discussion move from "whether" to "how". Reject the premise of the question. Such a system cannot be built; the requirements are broken. Treat it as though someone asked you to build a system that solves the halting problem, or factors products of large primes in linear time: the correct direct response is patient explanation of impossibility, and the correct indirect response is good PR from real security experts who understand how to do good PR.
- deleted 7y ago[deleted]
- makerofspoons 7y agoSo terrorists will use one-time pads and other strong encryption and everyone else will have their information exposed on a massive scale when the backdoors inevitably are exploited.
- blattimwind 7y agoOTPs are impractical to use for average people, while their use is entirely tractable (and widespread) for covert operations.
- bob1029 7y agoEverything technological is impractical to use for average people until people like us go out and build a practical solution. OTP is not a very complicated scheme. All you need is a good source of entropy, a place to store a big fat array of it all, some XOR operations, and a safe way to hand the codebook to your trusted parties (e.g. phone-to-phone transfer options).
- cesarb 7y agoYou don't even need XOR, just modular addition (XOR is basically addition modulo 2). The Wikipedia article has an example doing it by hand with letters (using addition modulo 26).
- mindslight 7y agoOne time pads are not secure by modern cryptographic standards. Elaboration: https://news.ycombinator.com/item?id=6008695 https://news.ycombinator.com/item?id=6008695
- urda 7y agoHuh? First off citing yourself isn't an elaboration. Second if you are arguing that one-time-pads don't work / won't work in modern times that goes against our entire understanding of certain bits of cryptography. You'll need to yield some real sources first.
- newfeatureok 7y agoI was talking to a layperson about encryption and privacy and they were very much against both interestingly. They compared encryption to wearing a mask in public and said if people don't want to be noticed (w.r.t privacy and encryption) they shouldn't be "participating" (it was unclear what they meant by this). Just goes to show you how the average person thinks about these things. I have to admit I wouldn't like it if people wore masks in public in a way where I couldn't recall their face, but I don't think that's necessarily the same as encryption, but I guess I see the comparison.
- 74ls00 7y agoEncryption isn’t like using a mask - we can still see who is communicating with who, we just can’t see what they’re saying. Banning encryption is like banning envelopes.
- jedberg 7y agoAh, but the government already has a backdoor to envelopes, because they can get a warrant to open the envelopes. This analogy only strengthens their position.
- lostcolony 7y agoNot really. Because strong encryption is like having everything in envelopes only you can open, and weak encryption is like everything passing without an envelope, because you don't know who has compromised the keys (and just like it traveling without an envelope, you have no idea who is seeing and meddling with it). There is no "only the government can remove the envelope, if they get permission". If we had the capability for that, we wouldn't be having the argument; the problem is people think this exists and it's technical company intransigence that is preventing it from being used.
- knodi123 7y ago> There is no "only the government can remove the envelope, if they get permission". Okay, but now the case you're trying to explain is "there are deep technological challenges and a wealth of historical precedent make me skeptical that we can correctly design or implement a solution that allows only the government or the intended recipient to decrypt the message, instead of only the intended recipient". To people who think "technology is magic". And on the other side of the PR battle, the government is saying "Nah, we got this. And if you try and stop us, we're powerless against pedophiles and terrorists." Adding enough nuance to make your position technically accurate, also makes it abstract enough to be politically useless.
- dropoutcoder 7y agoI find it interesting that the hn world is largely unified in beliefs about the trade-offs of exceptional access that aren’t necessarily true. Perhaps this is a cultural top-down tribal mentality borne of an adversarial arrangement between the billionaire oligarchs behind the startup scene and the government which serves to offer counterbalance against unchecked power. I personally find it reprehensible that large trillion dollar tech corps wash their hands of responsibility for the safety of citizens by offering strong encryption to the masses. I’m personally okay with secret police, but such things work better in secret. The calculus has indeed changed. Checks and balances within such secret societies do need to exist. I’m hopeful that tech geniuses will help to solve the problems regarding technical and social trade offs and risks behind exceptional access, instead of conforming to the often strict libertarian mentality of the sv community.
- isthisserious 7y ago> I’m personally okay with secret police What? Why are you ok with secret police? Where has this idea ever worked? > I find it interesting that the hn world is largely unified in beliefs about the trade-offs of exceptional access that aren’t necessarily true. Which trade-offs are you suggesting aren't true? The base claim is that back door access makes security weaker. Do you disagree?
- dropoutcoder 7y agoYes, it’s serious (in response to your handle). I don’t think it’s necessary to create a throwaway to respond and is also against hn policy. I’ve been downvoted to oblivion simply for stating my view; also not necessary. Secret police worked when criminals were put away with parallel reconstruction, for instance. (This being borne of limitations with the anachronistic constitutional notions of civil liberties in the rapidly evolving digital age). I’m all for reducing abuses of surveillance systems, but frankly it’s tech oligarchs who own us, not as much the nsa. “You can’t stop math.” Not true, strictly anyway. You can ban tech oligarchs from using unbreakable E2EE which slows it down and reduces the proliferation of digital entropy. Backdoors are an antiquated way of implementing exceptional access. The proper way is to provide third party access that is truly exceptional (living up to the name), and not based on flaws that a malicious actor or rogue nation can break. Instead of E2EE, how about building E2E2EE. Doesn’t need to be measurably weaker. Sorry on my phone, response isn’t nuanced.
- jliptzin 7y agoI guess it comes down to who are you more afraid of? Terrorists and pedophiles or law enforcement with unlimited power and resources to spy on you and imprison you. Of course it's a false choice anyway, if encryption is legislated away the bad guys will very easily continue to encrypt their communications anyway, after all you can communicate with someone by shooting a wall in a game of halo if you want to.
- shmerl 7y agoSo there is a "techlash" against privacy abuse now, and DOJ thinks it's a good idea to push even further privacy breach by fighting encryption? How stupid is that? Hopefully they'll get even a stronger push back.
- Accujack 7y agoI think the term "techlash" in the blog is an attempt to shape opinion on the source of the problem. Really, the issue is "corplash", or backlash against large corporations abusing privacy... and even then, it's really not the corporations' fault, it's the fault of the US government for not making what they're doing illegal.
- pirate_dev 7y agoThis is genuinely threatening to too many interests in the US, will not pass. Much smoke, but no heat, just like the last few times its been proposed. They will not get a master key to everything lol, nobody trusts DOJ like this. The people in power have dirt to hide too, just like you and me.
- portmanteur 7y agoIs this news or is this a blog post? I understand it's very informed, and I don't necessarily mind opinionated journalism, but this seems to be speculating as to the motives of the FBI. To me, this seems like only one very passionate side of an important debate. A big question I have is, "how likely is this legislation to actually become law?" UK and Australia passed similar laws, sure, but they also banned guns and that's not gonna happen here.
- sjy 7y agoIt’s a blog post, as stated in the URL and at the top of the page.
- dropoutcoder 7y agoIf you were forced to design an exceptional access system that minimized abuses and risks of compromise, how would you do it?
- JoshTriplett 7y agoLeave whatever jurisdiction was attempting to force me to build something unethical, and after being safely out of that jurisdiction, disclose absolutely everything I can about the attempted coercion.
- dropoutcoder 7y agoIn that case you would not be forced, at least in a more extreme application of the word. Regarding ethics, my opinion is that it’s unethical to offer strong E2EE to the masses at scale, without considering the needs of LE.
- unionpivo 7y agoAs someone from ex comunist/socialist state, I am completely fine with LE not having too much power. I think them being able to break all encryption in use is way too much power. Its not if, it's when it will be abused, and how many people die for it. And LE's can do a lot more damage than all terrorist combined.
- dropoutcoder 7y agoThanks for that. The goal is to design a system that prevents abuses. A technological solution to the ape problem would be helpful.
- JoshTriplett 7y agoCurrent systems prevent most abuses, and many people are working on improving it to prevent more abuses. As an excellent example, Certificate Transparency has almost completely mitigated the potential abuse of compromising a certificate authority and using it to MITM traffic. Similarly, "binary transparency" or "software transparency" will hopefully eliminate the abuse of delivering a "special binary" to just one person that others have not received. Part of the threat model is the belief that any system with a backdoor has any hope of "preventing abuses". The backdoor is the abuse, leaving aside all the misuses of it that will happen.
- Allower 7y agoDOJ making everyone less safe - this the definition of treason in my book.
- mullingitover 7y agoEncryption keeps the government out of things it shouldn't be snooping on, and also keeps other governments out of those things. If key escrow is mandated, it would be cracked to high heavens by parties unfriendly to the US within a year or two,tops, mark my words. Then what?
- misiti3780 7y agoSeriously question, how are they going to stop me from downloading signal from source, building it locally, and installing it on my and everyone i knows cell phones?
- sjy 7y agoWhy would they try to stop you, when they could just order Apple or Google to push out a backdoored update to the OS?
- misiti3780 7y agoi guess i didnt think about it that way -- good point.
- clnhlzmn 7y agoWould Apple or Google be able to get a backdoor to Signal? Edit: nevermind, I think I understand what you're suggesting.
- choward 7y agoThe obvious example that comes to mind is a simple keylogger.
- lukifer 7y agoI wouldn't overthink it; the same way they "stop you" from dodging taxes, using illegal drugs, etc: the threat of violence if you're caught. https://xkcd.com/538/ https://xkcd.com/538/ The real question in my mind is whether they'd manage to overturn, or carve out an exception to, the "code == speech" ruling. [1] Would we actually see academics arrested for teaching someone how to craft an unbreakable encrypted message, let alone posting their code to GitHub? It would probably take a panic event far beyond 9/11 for the public to acquiesce to such a thing. In practice, I suspect law enforcement just wants numbers, to nail more pelts to the wall, and would be entirely okay with choking off encryption at the source for average consumers: by outlawing the creation of mass-market encryption apps without backdoors. It's also not infeasible that they might try some sort of mandatory key disclosure, again enforced by threat of violence: "I, Alice, sent an encrypted letter to Bob on Feb 26th 2020, using key 0x123..., which I am hereby committing to the government database as required by law. I'd prefer you didn't use that key without a warrant, pretty please with sugar on top." [0] https://www.eff.org/deeplinks/2015/04/remembering-case-established-code-speech https://www.eff.org/deeplinks/2015/04/remembering-case-estab...
- cdransf 7y agoAs soon as law enforcement is granted any exceptional access they’ll go on to claim they need more access and less oversight. As soon as they’re granted such access it will become an irreversible status quo.
- plmu 7y agoReal criminals won't use such platforms anymore, but use custom end-to-end encryption. They'll find people to make them something, if need be by using steganography. This will only hit innocent people or low-level criminals, the real bad actors will find ways around it.
- pmoriarty 7y agoPeople eager to give others power over them don't really appreciate what it's like to live under a totalitarian state. The older I get the less hope I see of people learning anything from history. Perhaps we really are doomed to repeat it.
- hurricanetc 7y agoThis will just push people to open source applications and peer to peer networking. Basically, devolve back to the early days of the internet with regard to person to person communications. How is the DoJ going to force Signal or even Telegram to add a back door?
- JoshTriplett 7y ago> How is the DoJ going to force Signal or even Telegram to add a back door? Hypothetically: they could easily force the Apple and Google stores to stop carrying it, or even to prevent its installation using the same mechanisms used to scan for malware. Do not underestimate the means by which use of real encryption could be made inconvenient.
- three_seagrass 7y agoThey'll force device manufacturers to give access to keys locally locally. China did it with Apple's iCloud backups by just nationalizing the servers.
- deleted 7y ago[deleted]
- Andrew_nenakhov 7y agoI really would not be surprised if will surface that Telegram has a backdoor for Russian special services. After Anton Rosenberg's posts [1] and Durov's (very unconvincing) responses, it is clear that Durov lies a lot how Telegram operates, and it is quite likely that all their 'blocking' in Russia is just a show to boost credibility. It also should be noted, that while Telegram markets itself as the most safe and protected messenger, it's regular chats are, in fact, non-encrypted at all and are way less secure than WhatsApps. It's actually baffling, he bashes WhatsApp with such audacity [2], telling in one sentence, that 'if your phone dies, you can't access your messages on another device', and then continues preaching how cool it is to use encryption. BUT IF ONE USES END-TO-END ENCRYPTION, ONE CAN'T ACCESS MESSAGES ON ANOTHER DEVICE, BY DEFINITION!!!!! It never ceases to amaze me that people bought into this. A comfortable to use app and a really good promise of security turns out to be better than real proper security. ¯\_(ツ)_/¯ [1]: https://medium.com/@anton.rozenberg/friendship-betrayal-claims-3f395bcc95fa https://medium.com/@anton.rozenberg/friendship-betrayal-clai... [2]: https://youtu.be/kVZN9QbtFgs?t=106 https://youtu.be/kVZN9QbtFgs?t=106
- paulie_a 7y agoTheir attempts will make no difference. I will use encryption and they can't do Jack shit about it
- Accujack 7y agoI think the term "techlash" is an attempt to shape opinion on the existence, source, nature and of the problem being discussed. Really, the issue is "corplash", or backlash against large corporations abusing privacy... and even then, it's really not the corporations' fault, it's the fault of the US government for not making what they're doing illegal. Corporations are actually obligated to make money for their shareholders. A corporation does not have the free will to choose a moral course over those obligations, especially in the US. Corporate officers have to seek out and take advantage of every opportunity to make money available to them or otherwise they may well lose their jobs or even be sued. Since it's not illegal to make money off of invading privacy, corporations are obligated to try provided doing so won't negatively impact their profits. Calling it "techlash" implies that somehow tech is at fault, or even large tech corporations, but in truth the US Government is at fault for not updating privacy laws for the computer age. The term directs anger away from the real culprits.
- upofadown 7y agoOK, so how have things been going for the UK and Australia? Has anything concrete actually happened as result of the legislation that has helped law enforcement get access to encrypted communications? In other words; does legislation actually make a difference in practice? Or is it just some sort of pointless political signalling?
- larrrydavid 7y agoIf legislation was passed, couldn't Apple essentially move it's HQ to a different country where there are now laws against encryption?
- djzeratul 7y agoFantastic, the party that is all about personal freedoms is waging a war against personal freedom. We have come full circle.
- mondoshawan 7y agoSorry, did I miss something? WTF is the "techlash"?
- hnick 7y agoI'm guessing this is cryptographically impossible but are there any schemes that allow 2 different keys to decrypt to two different messages for deniability? Perhaps a key containing a seed number to adjust the algorithm?
- _cairn 7y agoThis is a neat idea but I also have no idea if theoretically feasible or not.
- scott_laroque 7y agoPrivacy is extremely important, especially as also our democratic governments cannot be trusted always, at least this is the impression I get when reading the interview with the UN Special Rapporteur on Torture concerning the Assange case: https://www.republik.ch/2020/01/31/nils-melzer-about-wikileaks-founder-julian-assange https://www.republik.ch/2020/01/31/nils-melzer-about-wikilea...
- LaineHerron 7y agoShouldn't the US government be pushing good encryption? I wonder what sort of world we would be living in if the NSA had spent 1/2 as much time over the last 10 years trying to protect Americans from hacking as they do trying to spy on Americans.
- choward 7y agoExactly. I can't believe I'm supposed to pay for taxes for this. The government is supposed to be for the people, not control the people. I don't remember ever having voted on or agreeing to be spied on for no reason.