3 ms·
> Your mobile banking app uses E2EE; online chats with HMRC are protected through E2EE; you'd no more have an unsecured web chat with the taxman's helpdesk than
by floatingatoll 5y ago
> Your mobile banking app uses E2EE; online chats with HMRC are protected through E2EE; you'd no more have an unsecured web chat with the taxman's helpdesk than read out your P60 in the middle of a shopping centre.
The Register is only showing an example of #3, but leaves #1 and #2 unaddressed:
1. Your Identity (who everyone is)
2. Your Conversations (with whom, when)
3. Your Content (what was said)
Does the UK government have the ability to identify #1 and #2 for E2EE connections, and they desire #3 (content)?
Is the UK government only able to identify #2, and they desire #1 (identities) and #3 (content)? If so, which is more important to them: Identity, or Content?
I suspect they are much more desperate for Identity and Connections, than they necessarily are for Content, and that their attempt to overreach and backdoor all encryption could be shutdown by offering them #1 and #2 but not #3.
This is obviously unpalatable to consider to "perfect anonymity is the only way" adherents, but it's probably time to consider discussing it, when the alternative is a government backdooring or banning all encryption. It's too bad The Register didn't take that chance, but we could at any time.
- cyphar 5y ago> when the alternative is a government backdooring or banning all encryption. That is not the alternative because the mathematics of encryption is already very widely known. In the scenario where all encryption is outlawed, there will be a black market for encryption tools designed for criminals (this already exists today) and society will not be significantly safer. Or alternatively, open source encryption software development will continue happen outside the UK/USA/AU. Banning encryption will only make inept criminals (those who don't have the resources or aren't smart enough to buy the encryption tools) easier to catch and the general public unsafe. If the police are having trouble catching inept criminals to the point that they want to make the general public unsafe, the issue here isn't the encryption.
- Underphil 5y agoWhat does a ban on encryption even look like? If they see unidentifiable traffic in your ISP logs you're illegally using encryption? What would be allowed and what wouldn't? Is devising a code with the recipient in the real-world and using that in a messaging tool considered E2EE and therefore banned? Do both endpoints have to be in the UK to be covered by this law? I can't get my head round how they think this could be implemented without insane amounts of money and a rule book like war and peace.
- cyphar 5y agoIndeed, that is one of the more practical problems with any kind of approach like this. But the general point is that even if you could hypothetically "ban encryption" it still wouldn't achieve the goals the politicians pushing this crap are claiming to want to achieve. I mean, even if you hypothetically made it impossible for computers to carry out encryption (bake into CPUs some heuristic for what encryption looks like and block it or something), folks could be taught to use ElsieFour[1] which is probably secure enough to make things about as hard as they are today. I'm sure if this hypothetical ban actually happened folks would find ways of making it easy to do ChaCha20 by hand. And as evidence that history repeats, you can always tattoo a Perl program that implements AES on your arm like some hackers in the US did in the 90s. [1]: https://eprint.iacr.org/2017/339 https://eprint.iacr.org/2017/339
- userbinator 5y ago...and then there's also steganography, in which every piece of communication can actually be interpreted in an entirely different way.