4 ms·
> they just can't provide an automated means to do that for you What I'm wondering is whether two separate applications can be set up to communicate automatica
by eterps 2y ago
> they just can't provide an automated means to do that for you
What I'm wondering is whether two separate applications can be set up to communicate automatically, with one handling messaging and the other being responsible for encrypting and decrypting the data.
What would be against the law in that case? The messaging app? The encryption app? Or the interaction you are doing in that moment?
- mfiro 2y ago> The encryption app? That might be the next step. Banning encryption. We live in a strange world right now.
- Freak_NL 2y agoThe EU does not want to ban encryption, because it is the backbone of e-commerce and banking. There are plenty of public references that show the EU's explicit support of strong encryption. What some law-and-order types (globally) want, is the means to scan, peek, or otherwise access private communication, especially if that communication is provided by a service used by millions. You can encrypt all you like, but if you use WhatsApp or Signal, laws like these force those services to create a way to eavesdrop. How is probably not defined in the law. Client-side scanning before encryption, having those services act as men-in-the-middle for each conversation; this is all fine, and can use encryption as usual. As long as certain agencies get to have a peek somewhere between those strongly encrypted tunnels.
- effie 2y agoNeutralizing encryption is real; it is not about forbidding websites and clients using TLS, it's about getting in the middle.
- Freak_NL 2y agoStep one would be determining if anyone actually uses those two apps together. A handful of people? No one cares. Is it now the default way you install Signal (or its two components) and do hundreds of thousands of users do this? Then the next question asked is who is facilitating it and how is that done? Does the backdoored Signal have a plug-in that allows this kind of use? Does Android facilitate that? Those people will likely find themselves in legal trouble. Of course these laws are dumb, but that doesn't mean they can't be (mis)used to get the desired effect.
- temac 2y ago> Does Android facilitate that? Does Android facilitates IPC and services?
- Freak_NL 2y agoThat's not what the law cares about. Being able to encrypt stuff end-to-end, is not what is being targetted — it is not realistically possible. What is being targetted is millions of people getting private, true end-to-end secure communication with no content scanning of any kind through some service. Are you providing that service to millions like Signal is? This law applies. Are you the size of Meta and are you implementing some 'clever' two-component solution to sidestep this law? Expect legal trouble. You can already install a mail client with PGP-support. Will K-9 Mail get in to trouble if a million users in the EU started privately exchanging keys and using GPG with K-9 Mail? Who knows. These laws are not about such practical details. This is about unlocking massive amounts of signal intelligence to do… who knows what, and those large communication platforms are juicy targets. All it needs is a law to coerce them to cooperate. Don't expect reasonable arguments from the proponents of such laws, and don't expect to be able to avoid them for millions of users with clever tricks; you'll still fall foul of the spirit of the law, if not the letter.
- effie 2y ago> A handful of people? No one cares. Actually police and various agencies do, because when most people aren't encrypting, the few that do are suddenly interesting. Some of them will turn out to be organized crime, but some of them are just adults who want to communicate privately.