20 ms·
Signal threatens to dump US market if EARN IT act passes
- viklove 7y agoEARN IT will affect all encryption software, not just Signal. This bill is just the newest way Congress is trying to enforce required backdoors in all apps/devices. Last time it was under the guise of protecting us from terrorists, this time it's under the guise of protecting the children from pedophiles. I wonder what they'll try next time, when this inevitably fails again.
- kitotik 7y ago> when this inevitably fails again May I ask where your confidence comes from? I’ll actually be more surprised if this doesn’t go through, at least in some form.
- giancarlostoro 7y agoWith so many eyeballs locked up at home, bored, not paying attention to congress. I think this is definitely much more concerning.
- jimbob45 7y agoNot paying attention to Congress...until a big player gets taken down by this bill and makes a loud fuss about it.
- StillBored 7y agoThey just need to word it correctly: "This product is designed with the highest levels of security in order to keep you safe from criminals and other illicit actors on the internet. Because of this, it has been deemed inappropriate for use by citizens of the USA by the EARN IT act. Until this changes, it is only available outside of US jurisdiction. Please contact your congressional representatives for more information"
- Nasrudith 7y agoTo be fair even if they get what they think they it will fail and then they'll pout and try to move the goal posts again like how the DMCA failed to stop piracy or DRM from being cracked. Of course indulging their utter folly leaves us all worse off so we need to stop them. I notably haven't gotten even an email or after sending an email calling out EARN IT as downright nationally suicidal given the how much of the US economy is dependent upon secure cryptography, and the obvious relationship between GDP and power, and that if they gave a damn about the children they would be investing more in social services and investigation instead of trying to seize more power. Not sure if I reached them or got it put in a proverbial circular file or "enemies list/ban from volunteering as disgruntled" by a staffer but the fact they didn't send a "for the children" form letter bullshit is somewhat reassuring that it reached a real human and they at least recognized one case of "too pissed to even try to form letter bullshit" is a small victory and enough negative tickmarks to say "this is a bad plan" is the current win condition. Of course a large victory would be dropping from sponsorship but that would be near impossible even if I was a connected great speaker who called him out in person.
- vardump 7y agoI hope it's not against people who vote "wrong".
- elliekelly 7y agoThe federal government enjoys a freely accessible and wide open back door to our entire financial system under the guise of protecting us from terrorists. What makes you so sure the same trick won't work again? Most Americans don't seem to know enough about how the government uses the backdoor to care.
- mcny 7y agoThat’s a good point. I would like to plug taler here. There is no technical reason why the federal government needs to have access to all our financial information as far as I know. https://en.wikipedia.org/wiki/GNU_Taler https://en.wikipedia.org/wiki/GNU_Taler
- null0pointer 7y agoI feel like as soon as someone uses a "think of the children" argument they immediately invalidate any point they may have had. It's a total cop out argument. I wish more people could see through it.
- mywittyname 7y agoThere are a million better ways to help children.
- lvs 7y agoLike food, health care, and education. Encryption is not the reason human trafficking exists. Poverty is the reason it exists. The separation of wealth is the reason it exists.
- GrinningFool 7y ago> I wonder what they'll try next time, when this inevitably fails again. We're at a major disadvantage, so I'm not sure where that optimism is coming from. We have to stop it every time, and in every variation. On the other hand, they can keep trying over and over again. I'd much rather see EFF and others working with congress to introduce laws that _prevent_ this kind of thing, saving the long sequence of future fights as this resurfaces under names. One of those fights, we're bound to lose.
- colordrops 7y ago"guise" implies misdirection. What is their true intention?
- Fazel94 7y agoIf everybody who cares doesn't take a strong unrelenting stand against it, I will eventually pass. Hitler had minority support when using backroom politics got his way.
- unknown2374 7y agoWhat is wrong with the wording of the title? The first line is "Signal is warning that an anti-encryption bill circulating in Congress could force the private messaging app to pull out of the US market." Being forced out of the market is different than "threatening to dump the market".
- dylan604 7y agoIt might be a bit hyperbolic, but the end result is the same. Rather than compromising the integrity of their app, they'd rather no longer offer it to an entire country's market. Whether it is "dumping" the users or "pulling" out of the market, what's the difference? Lavabit shut their entire operation down once they were forced to compromise their system. While Lavabit didn't have much notice, Signal is signaling their intent to their users. If that signals their users to take action by contacting their congress critters to put pressure, then it seems like a good idea.
- thanksforfish 7y agoThe bill seems like it would result in forcing e2e out of the market. Each product that offers e2e would then need to make a choice. Remove e2e or keep e2e. If they keep e2e then either they proactively dump the US market or they face legal peril. It seems like the same thing to me. They don't want to offer a product that doesn't support e2e.
- dwheeler 7y agoIf you oppose the EARN IT act (I do), and you're a US citizen (I am), then you need to contact your US House and State representatives. It's generally easy, fill in an online form. Obviously there's no guarantee that they'll do what you ask, but that is the minimum thing you should do.
- hiq 7y agoThread of the blog post (source of the article): https://news.ycombinator.com/item?id=22815112 https://news.ycombinator.com/item?id=22815112
- aeurielesn 7y agoAre companies afraid that opposing the Anti-Encryption Bill will automatically label them as in favor of online child exploitation? I'm honestly curious about why there's no widespread opposition to the bill yet.
- Barrin92 7y agoIn general they seem to be afraid of standing up to the administration on virtually everything. Facebook in that regard seems particularly embarassing with Thiel on the board apaprently writing Facebook policy.
- IAmEveryone 7y agoThere are other methods of lobbying than just public, visible disagreement. They probably are registering their disagreement in private talks with people in congress. Facebook publicly coming out against this might not be helpful: most people just don’t care. Those that (potentially) do care are far more likely to be mobilized by the EFF or ACLU, which they tend to trust. Facebook isn’t the most trusted brand name in privacy, as far as I can tell. Their support might actually be detrimental for the cause. An open split of Silicon Valley and Republicans would also “politicize” the issue. Almost instantly, you’d have the 35% of Trump supporters galvanizing around the bill, even if they were previously ignorant or lukewarm on it. See the recent train wreck around Qunines-against-covid for a great example of this effect.
- suizi 7y agoThe Internet Association which represents them wrote a letter opposing it to Congress, although there hasn't been much other noise out of them, except for a minor statement from Facebook.
- lonelappde 7y agoWhich companies? Most companies don't use e2e encryption because they read your data for ads. Apple, maybe? Big companies don't generally make ethical stands, and small companies can't afford to. Apple makes some stands but only to be competitive against Android.
- hjkgfdfgh 7y agoIf Signal were federated, there would be no single entity to shut down. Alas...
- thanksforfish 7y agoGiven the amount of open source code already, it should be possible to clone. Edit: see below, server code is open. Keeping original text below: IIRC the server code is proprietary, but the clients are open. That's a decent starting point. https://github.com/signalapp/Signal-Android https://github.com/signalapp/Signal-Android
- correct_horse 7y agoThe server is also open source https://github.com/signalapp/Signal-Server https://github.com/signalapp/Signal-Server
- bscphil 7y agoAm I mistaken or isn't there some way in which Signal effectively prevents anyone from running their own server? I seem to recall hearing this. (I mean, there's the obvious practical problem that the official server URL is hardcoded into the app, so if you wanted to use your own server you'd have to build your own copies of the app for you and your communicants, but other than that...?)
- tialaramex 7y agoA pile of separate Signal clones = zero interoperability = zero functionality. So that's why there aren't any. You could solve that by Federating, except... Federation would be lovely if you could actually deliver Signal's goals and do federation for free, but what we always see from proponents of Federation is that was their goal and so they're done. Oh you wanted security? Sorry, we federated everything, so you'll need to get every single member of the federation on board with every single change you need, we know you can't get that done but that's fine because our priority was federating stuff, so we are successful, shame about your goals. As an example, somebody earlier in this thread mentions you can "just" know who is communicating with who anyway. Signal got rid of that, because they can, and it's a security improvement, so they put all the work in and did it. Now even Signal's own servers don't know who sent most messages! "Sealed Sender" means Signal has no idea who is sending this message to my friend Steve. Maybe it's me? No idea. It just has to be somebody who Steve allows to send him messages. Could be Steve loves spam and so it's a spammer. Could be Steve loves the AfD and so it's a Nazi. No way to know without reading the message which only Steve's Signal client can do. Now imagine trying to roll that out to a federated system. After years of effort maybe you switch it on, and then you find a bug and have to switch it off again for a few years while you fix that. Hopeless.
- djaque 7y agoIf you haven't already, please take the time to email your federal representatives. The EFF's tool [1] only takes a few clicks to use. [1] https://act.eff.org/action/protect-our-speech-and-security-online-reject-the-graham-blumenthal-bill https://act.eff.org/action/protect-our-speech-and-security-o...
- thaumasiotes 7y ago> The EFF's tool [1] only takes a few clicks to use. Your input is discounted at least in direct proportion to how little you sacrificed in order to provide it. If you really want to make an impression, telephone your representative.
- thanksforfish 7y agoDon't let that discourage you if you've only got time to tap a few buttons. Better to send a weak signal than none. In either case, contact instructions are here: https://www.usa.gov/elected-officials/ https://www.usa.gov/elected-officials/
- pc86 7y agoI take issue with the premise that there is anyone who doesn't have time to send a better signal? It takes all of about 4 minutes to call the Capitol offices of your two representatives in Congress. They'll get your name address and you can make it as quick as "I just wanted to let Rep./Sen. so-and-so know that I am for/against HB/SB 1234." and it's done. You will absolutely spend more time looking up their phone numbers than you will on the phone. You can do this while walking out of the office to the parking lot or metro station.
- hanniabu 7y agoIf you really want to make an impression, create a SuperPAC and donate millions to their campaigns.
- pas 7y ago
- mikece 7y ago1. The police are either lazy or incompetent if they say they cannot trace criminals because of E2E secure chat. 2. You don't need to know the contents of a chat to glean massive amounts of metadata. FB Messenger and WhatsApp going truly E2E encrypted will still put FB (and anyone serving them with warrants) to know in real time who is talking to whom, what their IP addresses are, and possibly real location (if they are using the app on their phone). This can be used to created a Signature profile... many Pakistanis and Yemeni have died from a Hellfire missile strike because they matched a pattern of activity. Google "signature strike" for more info. 3. The terrorists and pedophiles that are the most dangerous are using far more sophisticated means of communication than Wire, Signal, WhatsApp, Wickr, etc. Saying that this is "for the children" or "for our safety" is complete bullshit and anyone saying otherwise needs to prove it.
- blfr 7y agoPerhaps I'm not hip enough but I'm pretty sure there is nothing more sophisticated than Signal.
- mikece 7y agoSession -- it just doesn't have as many features. BTW, one of Signal's weaknesses is that you MUST use a phone number with it. If you're savvy you realize this can be a Twilio number you control making your account immune from SIM hijacking. However, unless you override a bunch of defaults Signal is not immune to other attack vectors like attempting to unfurl a URL sent in a message -- which can expose your true IP address -- or generate a thumbnail of a video -- which can launch a malware attack -- which is the method of attack alleged to have been used by Saudi intelligence to hijack Jeff Bezos' phone (via an E2E encrypted WhatsApp message no less). A more sophisticated messenger system would turn off lots of "convenience" features by default and let me pick a random username and NOT make me enter a phone number or email address. People who care about security don't need a way to reset their randomly generated 128 character passwords.
- rsync 7y ago"BTW, one of Signal's weaknesses is that you MUST use a phone number with it. If you're savvy you realize this can be a Twilio number you control making your account immune from SIM hijacking." Does Signal not ever send messages from, or otherwise use, SMS shortcodes ? I ask because no twilio number can receive an SMS shortcode (because no twilio number is classified as a "mobile" number). Genuinely curious.
- yingw787 7y agoSo...assuming this bill passes and Signal pulls out of the U.S., what can the average person do to continue to access Signal's servers in other countries? Can we VPN into an Apple computer based in the EU, build our own Signal client, and then somehow scp the files back to the U.S.? I think TestFlight would be out of the question, since you probably would need to sign Apple U.S. Terms and Conditions, and because Apple Developer Program is $99 / year. Maybe I should get a Purism phone.
- paxys 7y agoThing is the VPN service would be subject to the same law, and so the connection would likely still be insecure.
- yingw787 7y agoHmm, okay, so I can drive over to Canada, make a developer friend there, build an instance of the Signal iOS app using the licenses there, load it onto my phone via TestFlight or USB stick, then drive back to the U.S. and use it assuming TSA doesn't touch my phone?
- aspenmayer 7y agoAfter you load TestFlight and Signal build onto your phone, make a full encrypted local backup via iTunes.[0] Upload that backup image somewhere. Turn off Find My (iPhone) to disable activation lock. Restore iPhone to factory setttings. Return iPhone to factory sealed box. Optional: mail phone to self at destination or other location of your choosing in destination. Cross border. When at desired use location, unbox phone. Fetch backup you made earlier. Restore backup to iPhone. Use Signal. [0] https://support.apple.com/guide/itunes/back-up-your-ios-device-itns3280/12.9/mac/10.14 https://support.apple.com/guide/itunes/back-up-your-ios-devi...
- yingw787 7y agoThat sounds much more feasible! I copied and pasted your tip into my notes app. Thanks!
- Thriptic 7y agoI think its better to just admit that freedoms / tech will always be misused by criminal actors, and that's just a price we agree to pay for privacy, security, and liberty. I don't think think that's a controversial statement, and we make such trade offs all the time unconsciously. The United States has largely agreed to accept a certain amount of criminal gun violence in the name of personal gun ownership. We agree that a certain amount of money laundering will occur due to shell corporations and foreign ownership of assets. We agree that police have to let a certain amount of crime go unpunished in order to protect against unreasonable search and seizure. The only difference between those things and this is that no one has the balls to stand up and admit that a certain amount of child abuse is an acceptable price given the stakes at hand, even though it is true.
- t-writescode 7y agoTruly, this is a stance we have to have for everything. If we want criminal justice reform, too, for example, we have to agree that some criminals will come out of prison after their shorter sentences and they will get into positions and jobs where they will cause harm. Any lightening of sentences will come with bad people getting through and hurting others. But, this is an acceptable price to pay to allow the other felons redemption in this world.
- mikece 7y agoJust because an Ethernet cable can be used to strangle someone doesn't mean that failing to stand in opposition to network wiring is to accept a certain amount of murder by strangulation. Don't focus on the tool being used for the crime but on the tool committing the crime.
- rapind 7y agoI think this depends on the tool. Certainly we could see the tool being a problem if it was a mini nuke or Anthrax (I don't for the record think encryption rises to this level). I'm very concerned that technology will put something devastating (at scale) in people's pockets and then we're kind of screwed (do we choose big brother and all that entails, or indescribable mass destruction?). I don't have a solution but it keeps me up some nights.
- lambdasquirrel 7y agoThe sheer irony being that Federal workers have started using Signal instead of other apps, because it's encrypted.
- AlexandrB 7y agoIt's not really a "threat". I don't think Signal could legally operate in the US with this act in place. More like saying: "If you effectively ban end-to-end encryption, we can't offer our end-to-end encrypted chat app in your jurisdiction any more."
- FigmentEngine 7y agoit is a threat. signal could still operate, they would just be at risk of being killed by a thousand cuts.
- pacificmint 7y ago> I don't think Signal could legally operate in the US with this act in place. Of course they could operate. They would just have to backdoor their encryption. Which, presumably, is what this legislation wants to achieve. They don't want a world with no chat apps, they want a world with chat apps they can listen to. What Signal is saying in this blog post is that they would rather give up the US market than weaken their encryption. Which is worth saying, because it's probably not true for most other apps. Most corporations would not give up the US market, no matter what compromises they have to make.
- maqp 7y agoSpot on. The thing is, content is still valuable and companies would like to access it on behalf of the government, but they now have to compete with private messaging apps. The big tech companies want the government to force them to make more profits on user data by forcing the backdoor. If this was something the tech companies didn't want, they'd be spending billions to lobby for the human right to privacy.
- AlexandrB 7y ago> Of course they could operate. They would just have to backdoor their encryption. Is it even possible to have end-to-end encryption (in the technical sense of the term) with a backdoor? If your product's marquee feature is security via end-to-end encryption your product is a non-starter in a jurisdiction that bans end-to-end encryption, no?
- DenisM 7y agoInterestingly, The term “interactive computer service” has the meaning given the term in section 230(f)(2) of the Communications Act of 1934 (47 U.S.C. 230(f)(2)): The term "interactive computer service" means any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server, including specifically a service or system that provides access to the Internet and such systems operated or services offered by libraries or educational institutions. It appears that a P2P app would be off the hook, at least for now, because there is no "server" in the picture.
- r3trohack3r 7y ago> any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server Wouldn't that mean every node on a P2P network would be considered a client, server, and interactive computer service? Another way of interpreting this, I think, is that everyone participating in a DHT or scuttlebutt network would be responsible for every other user's behavior on that network.
- DenisM 7y agoI am thinking two phones knowing about each other's IP-6 addresses. No central directory. You might be right though.
- throwaway55554 7y agoThis just kills me: https://arstechnica.com/tech-policy/2020/04/senator-backing-anti-crypto-bill-calls-out-zooms-lack-of-end-to-end-crypto/ https://arstechnica.com/tech-policy/2020/04/senator-backing-...
- RickS 7y agoThere's a coherent worldview where this isn't hypocritical: > Encryption is for hiding our comms from China and Facebook, which keeps you safe. Hiding your comms from America makes it harder for America to keep you safe. Encryption should be weak enough to let the US government have the knowledge it deems necessary, but strong enough to build a moat around that superiority. It's misguided for a bunch of reasons that HN well understands, but it holds water. That's what makes it scary: not that it's absurd, but that unless you're both well educated and skeptical, it sounds downright responsible.
- ummonk 7y agoPeople keep saying that backdoors weaken security in general, but that's simply not true. If you create a cryptographic backdoor that only one third party entity can access (because only they have the private key to do so), this doesn't fundamentally make it any weaker than ordinary end-to-end encryption (where the recipient has the private key to decrypt the messages you send them).
- saagarjha 7y agoIt does, because the third party may share their keys with others.
- throwaway55554 7y ago> It does, because the third party may share their keys with others. It makes the store where the keys are kept a priority target as well.
- nabnob 7y ago
- pgm8705 7y agoPresumably, this would affect Apple and iMessage as well, correct? Hopefully, Apple will publically denounce this act, putting stronger pressure on representatives and increasing public awareness.
- maqp 7y agoApple can already silently eavesdrop on all iMessages, because they control the public keys inserted to your device. There are no fingerprints to verify you're not under MITM attack so they can just start attacking everyone. Read my longer post on this topic here: https://news.ycombinator.com/item?id=21425897 https://news.ycombinator.com/item?id=21425897
- saagarjha 7y agoApple cannot do this "silently".
- maximente 7y agowhat evidence do you have to refute the longer post that the OP linked to where they explain the exact mechanism that this can be done silently?
- saagarjha 7y agoThe fact that adding a new key is no longer silent? iMessage will alert you when a new device is added to the account.
- maqp 7y agoDoes it alert you when your contact's key changes? Does it alert you when your contact buys another iDevice and installs iMessage on it? Thought so. That's where the attack happens, when you receive a new public key for contact's device. Just because your account keeps track of your devices, doesn't mean Apple can't do this attack.
- flattone 7y agoThe state of respect from law and corporations upon consumers is already the single most depressing thing and now earnit. Grew up wanting to live in the future now i just want out. Remember that 15 year joke ‘dont be evil’? I believe i could self immolate a million times over in front of a variety of scenes and meanings, people could call, write and click, teach and learn. There is however an absolute, it seems, that there is no profitable path for relatively infinite powers (politicians and corporations) to allow any meaningful movement towards the more humanitarian, civil/passionate version of a culture. Instead we will visibly or not be corralled into a highly monitored and monetized form of drone happiness. Its cool.. as long as zoom always works, right? In a sort of twisted ‘we will do things to them but it wont happen to us’. Perhaps quarantine brain is boiling over into my comment style.
- dTal 7y ago>Perhaps quarantine brain is boiling over into my comment style. Quite honestly this comment sounds like you're entering a schizophrenic episode. I don't mean to be disrespectful and I am not a psychologist, but there's a characteristic tone and I recognize it. Quarantine is hard for brains. If you're in quarantine and you sense that your brain isn't working quite right, give your loved ones a call. Actually, do that anyway.
- flattone 7y agoI appreciate your sharing this view... but i lack background as to why. This tone and line of thinking is quite regular with the exception of a few friends who prefer surrendering privacy for safety. Tell me more about your views? Basically im trying to get at does this non psychologist have valid insight or is this just a knee jerk disagreement+quarantine comment? And to better clarify my boiling over thing it is really to say that with the added time on our hands we all have so much time to read and think about our lives. Just in case you’re right... hello from loony town. Haha. Sorry not funny.
- dTal 7y ago>Basically im trying to get at does this non psychologist have valid insight or is this just a knee jerk disagreement+quarantine comment? Neither. I am only reacting to your writing style, which reminds me very much of some schizophrenic people I have known. If I had to describe it, I would say it is characterized by disjointedly jumping around a theme, often using sentence fragments instead of complete sentences. It makes sense to you, but it is difficult for others (well, me) to follow. Again I don't mean this as an attack at all, just as an encouragement to reach out. I don't have a lot to say about the actual content of your comment, except to say that it sounds awfully pessimistic and that life can surprise us with history's twists and turns. I'm sure things felt similarly hopeless in the early 20th century with the robber barons, or during the plague that immediately preceded the enlightenment. Chin up!
- harikb 7y agoCan we please have new articles at least state the law correctly as anti-security instead of anti-encryption?
- mirimir 7y agoOK, instead of "dump US market", why don't they (or someone) create a clone that can't be fscked with? Maybe hybridize with Briar, or whatever. Take everything off clearnet, and have everything anonymous. I was thinking that Session/Loki was better protected, but the Loki Foundation is likely just as vulnerable.
- einpoklum 7y agoIn Soviet Russia, government spy on everyone's phone. In Capitalist America, phone spy on everyone for government.
- lonelappde 7y agoWhy can't clients encrypt client side? Chat apps should support input plugins. If a user encrypts locally, there's nothing the network can do about it.
- t-writescode 7y agoThat is how E2E works. But that means the software you’re using must be able to communicate with your client, unless you want to copy-paste every message into a decrypted. That’s a pain for normal communication. Therefore, we have programs like Signal that do that for us.
- mLuby 7y agoI wonder if a keyboard app could do it, since they sit between the user input and the chat app. It would be nice if message transportation were decoupled from composition and consumption. Default bundling is fine for ease of use, but allow first-class replacements.
- maqp 7y agoThese are called in-line encryption systems. They're generally not apps, but separate devices with automated ciphertext transmission. I've been working on something that does this http://github.com/maqp/tfc http://github.com/maqp/tfc and that can be plugged to almost any transport system with relative ease. The current design is using v3 onion services for each endpoint.
- maqp 7y agoSome messaging apps like Pidgin provide API for message input and output via some IPC like dbus.
- president 7y agoHas anyone here actually read the full-text of the bill [1]? I don't see any mention of banning cryptography/encryption in it at all. In fact, the only thing that the bill proposes is the creation of a commission to establish best practices for child exploitation. Seems a bit unfair to call this an ANTI-ENCRYPTION bill. [1] https://www.govtrack.us/congress/bills/116/s3398/text https://www.govtrack.us/congress/bills/116/s3398/text
- mundo 7y agoScroll down to section 6 - it amends CDA 230 to strip protections from companies that don't follow the "best practices" (which might not involve backdoors, but are presumed to based on past statements by the commisioners-to-be, especially AG Barr) established by this commission.
- steindavidb 7y agoSenator Feinstein (D-CA) is a do’s-onshore of the bill. Here’s the form to contact her office and encourage her to not support the bill: https://www.feinstein.senate.gov/public/index.cfm/e-mail-me https://www.feinstein.senate.gov/public/index.cfm/e-mail-me
- tln 7y agodo’s-onshore = co-sponsor? Thanks for the link, I sent an email with it.
- mirimir 7y agoIf EARN IT passes, and if Signal wimps out, something tougher will replace it.
- ENGNR 7y agoThey achieved this in Australia by saying "we don't care how you achieve both security and putting backdoors in, just have a 'capability'". If you don't have the ability to open a backdoor for them you've committed an offence The best counterargument I came up with at the time is the security of our children. Who the hell knows what teenagers are sending to each other these days? Do we even want to know? I don't, and it's weird that Attorney General Barr wants to open this door. Why risk letting the wrong person sneak into a position where they can see all of our children's messages, everyone deserves real security
- garyfirestorm 7y agoGuns kill children!! Politicians - we need to defend ourselves and our rights. Keep the guns. Encryption is dangerous to children Politicians - yup...take it away guys.
- floren 7y agoFeinstein, one of the co-sponsors of this bill, has a pretty good track record of going against anything which could give power to the people rather than the government, including guns. Now, that didn't stop her from being one of the only people in San Francisco with a concealed carry permit (up until 2012)... laws for thee, but not for me.
- vibesngrooves 7y agoWith all the press around EARN IT, this would be a great opportunity for companies with even a mild focus on combating criminal activity on their platforms (Facebook, Mailchimp, etc.) to collaborate with bureaucrats and/or testify in congress. Thorn seems especially poised as mitigating child abuse is the essence of their organization. Whatever their stance, they appear to be an authority in the private sector spearheading technical efforts to combat child abuse. If any Thorn engineers/representatives - or any platform engineers focused on abuse prevention - are reading, I'd love to hear your take on the proposed legislation. It's imperative that we grant resources necessary to challenge such a horrific human issue without sacrificing our privacy and subsequent civil liberties For context... https://www.thorn.org/ https://www.thorn.org/
- LatteLazy 7y agoYou can't maintain democracy or the rule of law with these laws in place. This isn't about privacy, making it about that is missing the point. Privacy is a nice side benefit, something we give up routinely for safety. Democracy isn't.
- rlt 7y ago> Although the goal of the legislation, which has bipartisan support, is to stamp out online child exploitation, it does so by letting the US government regulate how internet companies should combat the problem—even if it means undermining the end-to-end encryption protecting your messages from snoops. As usual, one of the Horsemen of the Infocalypse: https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalypse https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
- GekkePrutser 7y agoThis is why something serverless is needed. Then there is nobody to sue.
- neets 7y agoWell there is tox and other protocols that work through Tor network
- GekkePrutser 7y agoTrue, I will probably switch to something like that. The problem with tor I don't like is that it's no longer the lighthouse of freedom it once was. It's too tainted by all the perverts and heavy criminals that abuse its power. The same happened with Freenet sadly and completely killed it for the mainstream public. This "slimy" feeling is slowly corroding tor as well. I can't help but feel it does need some kind of control, not identification of peers but some kind of banhammer. Also, the anonimity tor/tox provides is not really needed as I'll use it to communicate with people who know who I am anyway. Finally, tor isn't exactly serverless either. Governments could shut it down if they wanted to. But I think they rely on it too. I'm sure they run exit nodes to keep tabs on things and I'd imagine they use it for communication with their own spies. After all, it was invented by the US government itself for such reasons.
- maqp 6y agoTox doesn't torify by default.
- cageface 7y agoThis kind of thing and the pulling of HKMaps are the main reason I'm running Android again. Being able to run apps on my phone that my government won't allow in an official app store is looking more and more likely to be an essential freedom.
- codeisawesome 7y agoAren’t there many proprietary blobs starting at the SIM card level, which are black boxes that could contain malicious code? I can’t trust Android phones “completely” because I’m not sure just how much of it is truly open source - so iPhone is a more convenient alternative of the same thing with at least lip service to privacy and security...
- cageface 6y agoI don't really trust my Android phone but at least I have some escape hatches.
- lisper 7y agoIf anyone here is interested in helping to develop E2E encryption that cannot be shut down by the government here is my effort towards that end: https://github.com/Spark-Innovations/SC4 https://github.com/Spark-Innovations/SC4 The project has been moribund for a while because it's hard to compete with Signal but it wouldn't take a lot of encouragement for me to take it up again. First on the agenda is adding a ratchet. Most of the heavy lifting is already done (https://github.com/rongarret/ratchet-js https://github.com/rongarret/ratchet-js) it just needs to be integrated. I also have an iOS app that was kinda sorta working the last time I tried it.
- sliken 7y agoMakes me wonder if Signal moved elsewhere to avoid the EARN IT act, could they still publish their app to the Android and IOS stores?
- lvs 7y agoIf they had users in the US, they would be operating in US jurisdiction. I think the only answer, if the law turns against us all, is to move to a decentralized system like Matrix. Signal as a centralized system has a single point of failure.
- miki123211 7y agoI just wonder what leaving the US market means. Sure, they can ban American IPs and pull the app from Google Play, but will they still be liable if an american gets an apk and goes through a VPN?
- Etheryte 7y agoHow would a company be liable if it isn't stationed in the US nor does any business there? Asking sincerely, I don't see any way that it could be.
- zajio1am 7y agoWell, it could be liable (if law says so), but it would not be enforceable.
- miki123211 6y agoIt could be liable in the same way copyright violators / darknet drug store owners are liable. If you live in a European country and host your torrent website there, but you host Harry Potter, Star wars and so on, they can extradite you to the U.S.
- spanktheuser 7y agoSo much of this conversation accepts the government’s anti-crime message is made in good faith. Is isn't. What‘s more, you all know that. Everyone agrees the act is unlikely to to stop dedicated pedophiles and terrorists. The Republicans and Democrats know that as well. Crime is a useful pretext to openly push for what they can’t say aloud. They wish to suppress dissent. They know the threat unbreakable encryption poses to their wealth and to their power. It’s freedom. Freedom from detection, identification, coercion to comply. Freedom to do what you think is right. If it’s passed, terrorists will reasonably include domestic terrorist. Which will broaden to include Antifa [1] and Black Lives Matter [2] in the government’s eavesdropping. Then people who attend the same protest that BLM or Antifa appear at will need to be monitored. And so on. This is the whole point. Not pedophiles. Not Al Qaeda or Isis. They pose no threat to the power of the ruling class. You do. [1] https://www.washingtonpost.com/politics/2019/07/20/senators-want-antifa-activists-be-labeled-domestic-terrorists-heres-what-that-means/ https://www.washingtonpost.com/politics/2019/07/20/senators-... [2] https://foreignpolicy.com/2017/10/06/the-fbi-has-identified-a-new-domestic-terrorist-threat-and-its-black-identity-extremists/ https://foreignpolicy.com/2017/10/06/the-fbi-has-identified-...
- pota05258 7y agoThe examples you've chosen are revealing. Are you equally concerned that militant ethnonationalists will be treated the same way? Or is there some specific reason that you'd prefer for militant marxists to continue operating freely in the United States?
- mirimir 7y agoAs wealth/income inequality increases, capability to suppress dissent becomes increasingly important. And yes, "domestic terrorism" will include anything that threatens the wealthy.
- brocklobsta 7y agoSlowly but surely personal privacy is getting chipped away in the name of "Good"... smh
- throw7 7y agoDoes Biden support the EARN IT bill? Does Trump support the EARN IT bill?
- AlexCoventry 7y agoAs much as I love Signal (I use it every day), wouldn't the USG, given its values, just say "good riddance"?
- hedora 7y agoMany senators use it, apparently. Hopefully some will switch to a surveillance platform and get outed for whatever it is senators do between screwing the country over. grabs popcorn
- suizi 7y agoSome do after their security experts twisted their arms to get them to use it over emailing each other things which could be used to blackmail them. I wouldn't expect them to understand the consequences of what they're doing, they likely think it magically just applies to all the people they don't like.
- tanilama 7y agoIt is only a threat if it has leverage. Forcing Signal out of US market is the goal.
- DeathArrow 7y agoWhen government agencies want to do something bad they always bring in child exploitation, terrorism or war against drugs. Government agencies should be able to fight crime without massively spying and monitoring their citizens.
- eru 7y ago> Government agencies should be able to fight crime without massively spying and monitoring their citizens. Nor the rest of the world's citizens.
- suizi 7y agohttps://twitter.com/signalapp/status/1247938861184909312 https://twitter.com/signalapp/status/1247938861184909312 Their tweet on Twitter.
- suizi 7y agoRelated: https://www.protocol.com/earn-it-act-hearing-section-230 https://www.protocol.com/earn-it-act-hearing-section-230
- bagacrap 6y ago"Companies should not deliberately design their systems to preclude any form of access to content" e2e encryption only prevents certain forms of access to the content. You can still find the physical device and (provided it's unlocked) read the messages off it. Encrypting on one end and decrypting on the other could theoretically be performed manually with the message sent via an insecure channel. So is two party encryption what's illegal now?
- classified 6y agoSo the US govt declares war on Math. Again. What else is new? Tech won't stop them, we have to vote those assholes out of office.