10 ms·
I gotta admit, perhaps a bit naive of me, that the concept of "tech charlatans" didn't click for me until now. It's true, they are out there, and I see it now.
by hakunin 3y ago
I gotta admit, perhaps a bit naive of me, that the concept of "tech charlatans" didn't click for me until now. It's true, they are out there, and I see it now. I mean, I know there are phone scammers, but they probably been there before tech. I know there are hackers writing viruses and exploits, but those are oftentimes talented people doing bad things. However, this comment, and a couple recent experiences really drove "tech charlatans" home.
One experience was a trip to a crypto conference. Many booths were making unsubstantiated, impossible claims. If you tried to ask how, they couldn't answer. Like, someone would say they made transactions instantaneous, and when I asked how they solved the problems of unpredictable networks, they'd have no answer. It got pretty frustrating. I had to dig through a few claims like these only to be convinced that they're selling snake oil.
Another (less recent) experience was looking through a spreadsheet of government approved innovation/research grants. I couldn't believe what I was reading. Many of the entries seemed to make absolutely no sense, purposefully using buzzwords to sound smart, but having no meaning when unpacked. Buzzword salads. These are funded projects. And to get more money on round 2, all the "innovators" had to do is show any activity, which is very easy to fake.
So yes, tech charlatans. I'm a bit on the old school side of tech, and this gives me cognitive dissonance. I'm used to thinking of software devs/engineers as honest/creative/driven, but I guess this was always inevitable. Our field is very exploitable, because many people put their livelihood in tech, while knowing very little about it.
- nvm0n2 3y agoWell, nobody likes being called a charlatan and you have to be careful with that accusation. Case in point: this article. I hate it because the argument he makes is correct and useful until the end, when he tries to claim that giving certain government agencies access to encrypted messengers is impossible without giving it to all of them "because maths". This is a good example of tech charlatanism and it's the sort of thing that will hurt our industry a lot in the long run. It's why lawmakers often end up not listening to us. There is nothing that stops tech firms doing exactly what they're being asked to do. Every claim otherwise is obfuscation because tech firms don't want to do it, mostly because of their internal internationalist politics where they don't want to be forced to pick sides and tell some governments "sorry, we're Anglos who choose to give the US/UK governments special access that you don't get because we're better than you". It's an example of the first kind of no, not the third kind. End-to-end encryption is a vipers nest of false claims like this. There's lots of ways to implement such policies, like this: for each message that's being encrypted, you encrypt it under a per-message key which is then itself encrypted under the recipient's key, and also a police (public) key. The servers forward the messages to the police so they can decrypt them. If the decryption fails too often (hacked client) then that user is denied access to the network. Yes yes I know that WhatsApp/Signal and friends use a more complex protocol, that description is a simplified textbook example, but the argument doesn't change. Cryptography is a very flexible set of tools. They can easily be used to achieve complex security goals, like empowering some parties whilst disempowering others. The resistance to doing this is legitimate and I even agree with it, but it's also political and not technological. When politicians push back and insist that their police should have access to WhatsApp, and get told it's impossible, well they are not all stupid and correctly conclude they're being bullshitted. Indeed some of the MPs in the UK have computer science degrees. Fact is, buzzword salads can be used to baffle people and get them to agree with you even if you're wrong. Technologists are especially tempted to abuse them when they want to say "no" to make a Type 1 No seem like a Type 3 No. Researchers do the same thing all the time, your complaints about grant funding are as old as the hills. Honest specialists speak clearly even when they might benefit from speaking unclearly.
- mythhabit 3y agoIf a company have the means to decrypt a particular users data, they have the ability to decrypt all users data. But the argument is not about that, it's about privacy, and how we have seen exceptions to privacy have always led to a slippery slope where they use it for more purposes than originally intended. Btw, end-to-end encryption by its very definition, means that only the sender and receiver kan decrypt it. Your scheme is basically saying that the police should also be a receiver of all messages...
- TeMPOraL 3y ago> Btw, end-to-end encryption by its very definition, means that only the sender and receiver kan decrypt it. Your scheme is basically saying that the police should also be a receiver of all messages... And serverless literally means "without servers", and yet... Point being, scope is a free variable. "E2EE" that's managed by a central server is already stretching it, yet people accept it. They'll mostly accept excluding law enforcement out of the scope of eavesdropers "E2EE" protects you from too.
- mythhabit 3y agoCentrally managed E2EE is not end to end if the server can decrypt anything. The definition means that the keys to decrypt only exists at either end.
- nvm0n2 3y agoThis is cryptography 101. Asymmetric crypto lets you encrypt a message using a public key without having the private key to decrypt it. Remember that the encryption is being done client side by apps these networks control. E2E is therefore sort of fake to begin with because WhatsApp is not only the servers but also the client. You can't mix and match, so you have to encrypt messages using software provided to you by the "adversary". E2E encryption is therefore more of a tool to control bad insiders and negotiate with governments than encryption as conventionally understood. Also remember that tech firms run the public key directory. Almost nobody verifies public keys, and even if they did, they're doing so with apps controlled by the tech firms so you can't know the verification is done properly anyway. And the keys can change at any moment, with your own way to know it's happened being UI controlled by the tech firms. Still, even if clients and servers were separate, nothing stops clients from encrypting messages using a well known government public key and attaching that along with the e2e encrypted version.