5 ms·
I always say if politicians want to ban encryption being absolute (by making it insecure): you first. Lets see how well it works by implementing encraption in y
by coldcode 6y ago
I always say if politicians want to ban encryption being absolute (by making it insecure): you first. Lets see how well it works by implementing encraption in your systems and email and seeing if your backdoor deals and illegal activity winds up in the public eye for all to see.
- teekert 6y agoIndeed! Meanwhile our government (the Netherlands) tells their employees to use Signal. Good luck telling your forces in the Middle East: "Please use this app that has breakable encryption, but it's not breakable by the bad guys, at least, we are 98% certain they can't break it. Also, we're pretty sure the master key never leaked. Yeah we know how that went for the New York subway but we are better. It's fine, don't whine, even if they break the encryption, they don't understand your Dutch conversations with your loved ones anyway. I mean, what have we got to hide anyway."
- nalekberov 6y agoWhen I first visited the Netherlands in 2017 I observed public transportation was transitioning to plastic card only payments. That was my first impression about the country in privacy context, not being able to use cash is a big attack on privacy.
- teekert 6y agoYeah there is that wish to go away from cash but we also had this: [0, from 2016]. I hope we will have more privacy oriented fintech companies soon, indeed it may swing the wrong way. It depends a bit on the ruling parties (we have many and they have to form a coalition.) [0] https://www.theregister.com/2016/01/04/dutch_government_says_no_to_backdoors/ https://www.theregister.com/2016/01/04/dutch_government_says...
- nalekberov 6y ago> privacy oriented fintech Can you elaborate on that term? We are talking here about digital payments, right? (where usually more than 3 parties involved in this process) How are you gonna make sure the whole transaction is not traceable back to you?
- teekert 6y agoIt will always be traceable and you can see that many fintecht companies that make things easier (like bunq and N26) also catch a lot of attention from bad guys and at the same time seem to freeze quite some accounts based on suspicious activity (I see that on the forums, I think there are a lot of false positives as well). A lot of "Whatsapp fraud money" seems to move through these companies, no wonder because with some you can get several cards activated immediately, funnel money through hopeless people's accounts into bitcoin exchanges or cash and it's gone. Anyway, we can only hope they won't outlaw cryptocurrencies to have a glimmer of hope for anonymous payment in the future.
- nalekberov 6y agoOh, speaking of cryptocurrencies I recently came across with this article. https://www.metzdowd.com/pipermail/cryptography/2020-December/036510.html https://www.metzdowd.com/pipermail/cryptography/2020-Decembe...
- teekert 6y agoWell, Zcoin, Monero and Dash being delisted from exchanges has got to mean that they are at least somewhat effective...?
- HenryBemis 6y ago> privacy oriented fintech this phrase is an oxymoron. Banks need to monitor, track, report activities. Central banks 'siphon' all transactions every day/week/month, so they can cross reference that Henry Bemis made in total $100m transactions today even if he used 50 different banks. A single bank can only track/monitor for AML its own clients. Central Banks can do that. Tax authorities can tap into bank's data. Side note: There is no such thing as privacy when you use a card. The only thing that 'protects' you is that your bank won't sell your data to Facebook. But NatWest banking app DOES talk to FB when you fire it up... so... at least they don't tell FB (yet) everything you do.
- Koenvh 6y agoYou can still get an anonymous card [1], along with paper cards from a machine, and printed e-tickets. So I would not say that travelling anonymously is becoming impossible, but rather that the current method is a lot more convenient for most, and thus the most known one. [1] https://www.ov-chipkaart.nl/purchase-an-ov-chipkaart/anonymous-ov-chipkaart.htm https://www.ov-chipkaart.nl/purchase-an-ov-chipkaart/anonymo...
- nalekberov 6y agoThanks for pointing this out. I didn't know about that. My experience was like that: one day I could buy transport card by cash, the other day the driver informed that I cannot but tickets by cash anymore.
- vaduz 6y agoThe card is anonymous, but loading it with money is not, at least not in practice - most machines I've encountered only accept Maestro/VPay (which is an improvement over PIN, as they are marginally available in other countries, but they are also tied to your identity), so you are left with the service points at major train stations at best. Exceptions were more common in the Strippenkaart era. At least that was the situation by late 2019/early 2020, as I have not been able to travel to Randstad since then for rather obvious reasons.
- dijit 6y agoEncryption used to be classed as a military munitions, and as such was illegal to export. It will probably revert to that status if this kind of law is put into effect, and used for governments/military with impunity but disallowed for civilians. https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
- morpheuskafka 6y agoHere in the US, I think we seriously need to capitalize on the 2A crowd. Encryption is a purely defensive weapon, like a shield. It can't actively damage or harm anyone else, but it is a critical means of protection in the modern world. We need the 2A people to understand that it both protects the privacy and security of our digital homes and lives, as well as serving as a check on the power of abusive governments, which are both of the purposes that traditional weapons under the 2A protect.
- jorvi 6y agoTo be honest, I much prefer the French government's way, where they are transitioning to Matrix and running their own server. That way they aren't beholden to any organization other than themselves. In general I think it would be great if the EU made it a directive* to national governments to prefer open source. Imagine, a world where the entire EU runs on an EU-customized version of Ubuntu/Fedora, office work being done in Libreoffice, messaging done in Matrix. The support contracts would run in the hundreds of millions and be a huge boost to the improvement of said software. Not to mention some internal IT teams would probably be contributing patches for their specific use cases and bugs. * I am aware the EU has relatively little power to enforce such a thing.
- teekert 6y agoI would highly prefer that as well, in fact it would make me very happy! It gives a lot of credence to a project if a government starts to use it. It would be good if they performed transparent security audits as well. Like the Dutch the French have also rejected back-doors [0] in the past but like the Dutch, the French also sometimes say dangerous things [1]. [0] https://www.infosecurity-magazine.com/news/french-government-rejects/ https://www.infosecurity-magazine.com/news/french-government... [1] https://www.theregister.com/2017/02/28/german_french_ministers_breaking_encryption/ https://www.theregister.com/2017/02/28/german_french_ministe...
- 5560675260 6y agoI don't get the New York subway reference. Could you give more details/link to an article?
- csnover 6y agoThey are probably thinking of the MBTA CharlieCard[0][1], which was cracked by MIT students. The MBTA sued them to try to keep them from presenting their research at DEFCON. [0] https://en.wikipedia.org/wiki/CharlieCard#Security_concerns https://en.wikipedia.org/wiki/CharlieCard#Security_concerns [1] https://archive.boston.com/business/articles/2008/03/06/t_card_has_security_flaw_says_researcher/ https://archive.boston.com/business/articles/2008/03/06/t_ca...
- teekert 6y agoI remember reading a story here about (New York's) subway system and a copied master-key that got around. Can't find it here, but If found this: [0] [0] https://www.nj.com/news/2010/04/master_keys_to_nyc_subway_jeop.html https://www.nj.com/news/2010/04/master_keys_to_nyc_subway_je...
- csnover 6y agoThat does actually make more sense, given the OP’s comment about master keys leaking. I remembered the CharlieCard thing because it was a pretty big deal at the time, and I couldn’t find anything relevant about MTA when I searched, so assumed it was a misremembering since this all happened over a decade ago. Thanks for the link! (I wonder what the outcome was of New York’s audit…)
- simonh 6y agoI think the Solarwinds breach pretty much gives us the evidence we need on this score.
- dalbasal 6y agoThe ironic part here is that the resolution pretty much suggests in points 1 & 2 that their comms will continue to be encrypted by mandate. Like everything else, everything is subtext so you could argue that it doesn't mean this (or anything).
- LocalH 6y agoThe only thing I don't like about the word "encraption" is that it's way too easy to misparse as "encryption" lol
- m463 6y agoIt's also worth mentioning: perspective. I can't find the link, but I read an article where a tech CEO was called to Washington to work with the government for something or other. The one thing he noticed that stuck in my mind is In the tech sector it's about: what you CAN do yet to politicians, the focus is on: what you CAN NOT do So maybe part of the solution is to point out the difference.
- pieter_mj 6y ago"encraption" : chuckle