7 ms·
This is explicitly the point of the article, really: the author’s third type of ‘no’ is “we literally can’t do this” — and that’s the situation in the UK. It’s
by Doches 3y ago
This is explicitly the point of the article, really: the author’s third type of ‘no’ is “we literally can’t do this” — and that’s the situation in the UK. It’s not that Meta, Apple, and Signal are saying “fuck you” to the UK; it’s that they’re saying “there is literally no way for us to comply with this legislation, so our only legal option is to leave your market.”
I agree that there’s a sort of implied, under-the-breath muttering of “…you morons”, but if there were a way for the messaging companies to comply they’d just…comply. Angrily and noisily, perhaps, but even in its current pathetic state the UK is too big a market to ignore.
- peoplefromibiza 3y ago> “there is literally no way for us to comply with this legislation, so our only legal option is to leave your market.” as much as I love my encrypted chats, both those sentences are not true. Devil's advocate would say: 1: Tech companies can obviously share the keys with the government, like they do in a group chat, it would simply mean "GVT has joined the chat" [1] and it could also work the same way wiretaps have always worked, under a very strict legal framework and behind a colossal amount of bureaucracy to authorize their use. 2: tech companies are not leaving those markets, they are simply buying time, they don't want to do the work, because it's work they will not profit from, but there's nothing preventing them on the technical side from doing it. [1] have you ever seen this on an Android device? https://i.imgur.com/XUxiUUr.jpeg https://i.imgur.com/XUxiUUr.jpeg
- rhaway84773 3y agoNot only is it not true, it’s very likely they’re already doing it. For example, WhatsApp sells itself as fully encrypted, etc. but if you’re in a group chat thars not true anymore. That information is available to WhatsApp and they almost certainly make it available to several governments (hopefully in a judicially protected way but we can’t know that). Further, if you backup your WhatsApp chats, that’s game over for any privacy. The UK legislation is stupid because the UK has been run by a bunch of stupid people for at least the past decade. Nothing about this legislation is dumber than Brexit, for example, which was a referendum that was proposed to the public in such a ridiculous manner that the next half decade was spent in divining what the referendum actually meant.
- FabHK 3y ago> For example, WhatsApp sells itself as fully encrypted, etc. but if you’re in a group chat thars not true anymore. That information is available to WhatsApp and they almost certainly make it available to several governments (hopefully in a judicially protected way but we can’t know that). Source? It could well be that the sender e2ee it to each of the recipients, no? (Trivial to add the government or WhatsApp itself to the recipients, then, but that is a different claim.)
- bostik 3y agoOP reads like something I have played devil's advocate for. In an earlier discussion about WA vulnerabilities, one of the reported bugs was that as implemented, Facebook could have added themselves silently to any group chat, thus receiving with plaintext copies of all messages sent in the group from that point onwards. I then extrapolated that if they so chose, they could change their plumbing enough to make all chats group chats - even when they were between two people. To be absolutely clear, there was not - neither back then, nor since - evidence of this being the case. But the technical capability and potential for such subversion was there at the time. I have not followed the domain news enough to know whether this is still the case. What is available to WA and thus to governments, is the traffic pattern part. Who communicates with whom, when, how large the messages approximately are, and so on. The stuff our industry and journalists at large have chosen to call metadata[tm]. I stubbornly call the whole thing for what it is: traffic analysis. Old-school style.
- atoav 3y agoNo. The problem is that as a messenger company you have to comply with different markets at the same time. If the biggest market (the EU) would punish you for breaching privacy and a small market (the UK) wants to punish you for the polar opposite you can either: - develope a seperate app for that small market and break that promise (and have the headache of figuring out just how to treat communications that cross the border of those two markets) - choose the bigger market, retreat from the smaller one and let the small market decide if they really want their special deviating regulation if it now means: "Those politicians took your messenger away" and there is no EU-buerocrat that you can blame for it. Notice how this doesn't even require any particularly strong political stance by the messenger organisation? The latter just makes more sense from the standpoint of an organization that cares about it's use of resources.
- nonethewiser 3y ago> No. The problem is that as a messenger company you have to comply with different markets at the same time. Well then you could technically say they can't keep the keys private then, since some places force them to share. It's definitely a "can but wont" scenario.
- ethbr1 3y ago> (and have the headache of figuring out just how to treat communications that cross the border of those two markets) You could also ban the ability for UK citizens to have chats with EU citizens, which I imagine some of the kookier UK conservatives would love.
- atoav 3y agoYou could do that, but then you cut a whole mode of interaction between e.g. UK parents and their kids who study or live on the continent. Either way this is a measure that (like many conservative talking points) sounds good on paper ("law and order"), but once it becomes reality it won't win you any prices, except negative ones.
- pavel_lishin 3y agoThe response to your devil's advocate argument is: giving you the keys is not actually a solution, because now every foreign government is racing to break, steal or buy those keys, and not only can we not guarantee that it won't happen, but we can't even discover if it happens, or when. We can build a secret entrance, but we cannot guard it!
- EGreg 3y agoWhy can’t they know when someone uses the secret keys? Perhaps the messages would be individually encrypted and the keys would need to be used in order to retrieve the message encryption keys. And to do this, they would need to provide an explicit reason and only get the limited info that the warrants etc. would support and the reasons would be stated in every case.
- pavel_lishin 3y ago> And to do this, they would need to provide an explicit reason and only get the limited info that the warrants etc. would support and the reasons would be stated in every case. The scenario I'm talking about isn't overly-broad warrants, etc. Technology can't prevent that. I'm talking about just the tech implementation. Fine, we have a private keypair for every message, and every message is additionally encrypted with the public key of the government-per-message-keypair. How are these per-message keypairs generated? If from a central server, then that becomes a massive weakpoint in the system for multiple reasons: it could be attacked to prevent new keypairs from being generated, it could be hacked to extract private keys, it could be modified to generate keypairs that an adversary can easily break, it could be modified to also send private keys to adversaries, etc., etc. If they're generated on-client, and the secret key is sent to some central repository, then the client or the device the client is running on could be compromised; the private keypairs could be intercepted en-route; the central repository could _still_ be compromised since it can't be airgapped to receive these keypairs. In the case of a warrant, how is each key actually fetched? I don't mean the legal process, I mean at some point someone has to push a button and decrypt a message. How do we protect that process? Besides the fact that even air-gapped systems can be vulnerable to a sufficiently motivated and well-funded adversary, at some point some human being has to have access to this system, and that human being probably has family members. How vulnerable are they to being beaten with rubber hoses, or receiving their spouse's fingers in the mail? If you're going to build a system that can expose everyone's private communications, it better be incredibly close to fool-proof, or it better not be built at all.
- didntcheck 3y ago> under a very strict legal framework and behind a colossal amount of bureaucracy to authorize their use. In other words we'll provide some comedy material for our "trusted agencies" to amuse themselves with, between writing their latest summary snooping system and sharing stolen nudes round the office
- peoplefromibiza 3y agoFirst of all, the justice system revolves around the rule of the law, homicides are forbidden, doesn't mean that it is hard to kill someone, it's simply prohibited by the law and people tend not to do it. Wiretaps use the same pattern, potentially it is very easy to listen to other people's conversation, but it is unlawful unless authorized, so people usually don't do it. Imagine this scenario: a man only contacts the phone number of some woman when the phone of his wife is out of town, plus the man's phone can be located at the woman's house only at night when the wife is away. What can that mean? Who knows... That kind of data, which is equally revealing and privacy breaking, is completely legal. Why is that? Because tech corporations don't really care about what you say, but about your habits, to exploit them. The justice system OTOH doesn't work in aggregates and patterns, it decides case by case, because every person is responsible of their actions and only theirs. So the two use cases are vastly different and the tension towards complete and unbreakable secrecy is not 100% aligned with the interests of a society at large. Only a very tiny minority benefits from that. Agencies snooping is illegal too, but they are out of the law anyway. "Licence to Kill" is the title of a Bond movie precisely for that reason.
- Tangurena2 3y agoThe tech companies design the system so that there exists no central key that could be used to decrypt every conversation. Each conversation generates their own unique key. If some back door existed, it could never be limited to "law enforcement" any hacker could unlock every conversation. Politicians are incapable of learning this.
- peoplefromibiza 3y ago> The tech companies design the system so that there exists no central key that could be used to decrypt every conversation And in fact nobody claimed that, at least not in this thread. It's still not impossible to provide the keys for a conversation, it's not a technical limitation by any means. Perhaps the good guys at Mullvad can provide that level of privacy, but certainly not WhatsApp, their interest align with those of the users practically never.
- barrysteve 3y agoI don't understand. In the case of a national security incident, the US gov/military would have popular apps cracked open ASAP. We live under a global survelliance network and somehow the gentlemen's agreement on keeping end-to-end encryption in place, is the only thing keeping our chat apps private? One would hope for a concrete privacy that doesn't depend on multi-national corps and nation-states to agree that it should be kept private. Something else has to be going on here, because nobody could commit to keeping dangerous secrets on whatsapp, after assange and snowden.. right?
- rf15 3y ago> We live under a global survelliance network But we don't, right? Neither every word nor every move you make is recorded. Not to mention not globally shared, of all things.
- permo-w 3y agothat's a pretty low bar
- barrysteve 3y agoUhh.. London has a CCTV network that doesn't prevent theft. My parking lots used to be tech-free and all now have poles with cameras and government signs on them. Face camera tech in all retail outlets. Every second or third home is plastered in cameras, some beaming their data back to some US corp. Phone tracks everything you do, to hundreds of app providers, who then sell it on to data aggregators. Refuse covid vax? No access to public services. My IT friends have admitted the whole point since the 80s was the spying. Watergate and Cyberdyne (nixon) started the end of secret keeping. It is no different to Oceangate and Teledyne (sub imploding) starting the end of physical freedom. Snowden, Assange, basic facts about GCHQ and google offshoring domestic data in the UK so they can classify it as 'foreign spying' and legally dissect it all, when they re-import it. Deanonymizing online activity is statisically trivial. All the 9/11 stuff destroying liberty and adding excessive security at airport gates and body scanners that were never needed before. ect. Euthanisia has been legalized. Some of us, do in fact, pay attention. Writing's on the (digital) wall. Every man will be a 'slave' to tech run by harvard-types, by the end of the 2030s. While we're "working from home", the gov and tech companies destroyed the physical infrastructure that allowed freedom and replaced it with tyranny. People are fleeing cities to live in the countryside. I. Wonder. Why. Here I am remembering and telling the truth. As if that mattered. I'm watching this in real time without the means to change my living circumnstances, and it's a big old brain melter. I'm supposedly responsible for my actions as a person, yet the gov and tech companies, really are indicating it doesn't think I should be allowed to exercise free will. ....
- soraminazuki 3y agoThe author's third type of "no" refers to the technical feasibility of compliance. OP, on the other hand, is referring to the refusal of the idea itself. In the case of encryption, the technical side of things is insignificant compared to the Orwellian nightmare these sort of laws intend to create. It would still be a terrible idea even if technical drawbacks were absent, and one doesn't even have to be a nerd to see that.