5 ms·
There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to
by dabbledash 5y ago
There is no way to scan people’s content while “respecting their privacy.” The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it).
- chrismorgan 5y ago> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). There’s this bizarre notion that using end-to-end encryption can absolve you of responsibility, that the authorities will have to accept an answer of “we literally can’t access it”. That’s just not the case for centralised things: you’re deliberately facilitating some service, government will find you liable for some things in its operation, and if you don’t comply, they’ll fine or shut you down. E2EE doesn’t absolve you from law; law is all about saying you’re not allowed to do things that are physically possible. (Decentralised things, now they can be banned but not truly stopped because there’s no central party to shut down.)
- dabbledash 5y agoThere’s nothing stopping governments from banning E2EE, but in the absence of such bans, no one is under any obligation to build systems that empower them to spy on their users.
- Retric 5y agoI wouldn’t be sure about that, the phone companies already have a legal obligation to allow wiretapping and the government is very happy to put gag orders on this stuff.
- pengaru 5y agoShouldn't the E2EE apple walled-garden app equivalent of wiretapping be pushing an app update to the suspect's phone with a sidechannel added for law enforcement to snoop, with warrant in hand?
- supertrope 5y agoCALEA has a carve out for encryption. I’m sure when E2EE is about to be deployed to the masses the law will be updated to force key escrow.
- heavyset_go 5y agoCourts can order them to collect data on users.
- Zak 5y agoWhen end-to-end encryption is done correctly, the answer is "we literally can't access it" as a matter of mathematics, whether the state accepts it or not. A state that does not accept it might retaliate against the entity giving that answer or forbid future use of end-to-end encryption without backdoors, but the truth of the answer doesn't depend on anyone's acceptance.
- onethought 5y agoIsn't that when the state prohibits your service? So then no body cares about your mathematical proof because it's a crime to use it. This is what has happened in many countries already.
- 3np 5y agoSure, but that's a case of "we're prohibited from providing end-to-end encryption and preserving user privacy so we can scan for prohibited content as mandated by authorities", not "we are keeping children safe while still preserving user privacy" Legal terms such as "murder", "fraud" and "rape" do change as effect of regulatory changes. "Encryption" and "privacy" do not. There's a limit to how much you can bend semantics in your PR before it breaks and you get backlash.
- onethought 5y agoBut if you're a company like apple, it'd be bad business to wait until large government bans your service/device before you respond to it. Much better to read the tea leaves and get a head of it.
- 3np 5y agoAgain, their double-speak and redefining words don't help with the reception. They're deliberately misrepresenting what's happening, appearing surprised when people misunderstand, and bundling together legitimate criticism with misunderstandings. I can draw some parallels to how Google went out with FLoC. Honestly I can't tell where Hanlon's razor should cut here.
- raxxorrax 5y agoThe law may say that government isn't allowed to spy on people. So no, the state cannot just come and demand anything it wants. Problem is that the law is self-contradictory and it is up to the judicative institutions to fix it as soon as possible.
- Retric 5y ago> The goal should be to create a system where you couldn’t do so even of you wanted to (or the state demanded it). You can still do secure backups of your phone without using iCloud, but there isn’t a way for Apple to do end to end encryption of backups transparently like you can with real time communication. The only way end to end encryption of backups works is to require people keep a separate secure key(s) to avoid losing their data, which means a universal implementation has real direct risk for users. As long as Apple has access to these files the FBI can legally require them to do these searches. From a pure PR perspective they should have communicated what was already going on before releasing this system because people assume something significant changed.
- simfree 5y agoMega.io (from the same people as MegaUpload) has e2e file encryption with just usernames and passwords. There is no reason the password can't be the encryption key, with backup keys stored with a trusted third party (eg: your credit union or bank) without notation as to what these backup keys are tied to.
- Retric 5y agoStandard passwords don’t provide enough entropy to provide secure encryption. Trusting third parties with the password in unencrypted form is either systematic in which case the FBI now just needs collect data from 2 different organizations, or on a case by case basis in which case users will mess it up. Apple etc would have no way to verify users actually did something to back up their keys. Apple’s current approach is to let users setup their own backups if they want security which allows for privacy just fine without providing a service with fundamental issues.
- UncleMeat 5y agoIn this case, the state does demand it. Running a major cloud photo storage and sharing platform without checking for this material isn't an option in the US.