9 ms·
Signal to leave Sweden if backdoor law passes
- richwater 2y agoAnd people say the US is authoritarian. You can't burn books in Denmark without going to jail and now Sweden wants to spy on all your messages.
- JmsPae 2y agoYou know it's a banger proposal when even the Swedish armed forces tells you "Please don't".
- pavlov 2y agoThey haven’t been in a war since 1814, so they’ve had lots of time to develop other competences. I hear they also make amazing sourdough and can discuss the Beatles catalog at depth.
- bryanrasmussen 2y agoas a general rule countries that succeed with a policy of neutrality do so by having their military strong enough that they're mot worth fucking with.
- diggan 2y ago> having their military strong enough That's not how Sweden remained "neutral" though, although I'm not sure I'd agree Sweden been neutral since 1814, wasn't exactly neutral before/during the second world war. https://en.wikipedia.org/wiki/Sweden_during_World_War_II https://en.wikipedia.org/wiki/Sweden_during_World_War_II
- bryanrasmussen 2y agoin your link there are numerous indications that Sweden keeps its military strong enough that it isn't worth fucking with, as in this quote >Georg Homin, a captain on the General Staff, stated: > Without a defensive force we cannot follow any policy of our own, our declarations become merely empty words and we leave the country's fate to chance, or to the decisions of others. With a defense as strong as Swedish conditions allow, we secure for ourselves the basis of a continued independent Swedish policy. obviously strong enough that not worth fucking with is a relative thing, based on a calculation of what do you get for attacking, how much will you have to spend to get that?
- KajMagnus 2y agoSweden is one of only 10 countries on the planet that has developed its own fighter jet (JAS 39 Gripen, plus retired predecessors). (At least ChatGPT lists Sweden as one of 10 countries with indigenous fighter jet programs.) GGGP: > They haven’t been in a war since 1814 Geography plays a role too I'd think. In a way, located in an icy corner of the world (rather than f.ex. in central Europe)
- bad_user 2y agoEuropean armed forces should know best, given that Signal has seen actual use by Ukrainian military personnel, with Russian forces trying their best to target those encrypted communications (right now mostly by getting those smartphones from dead bodies).
- mmooss 2y agoThey also have a social engineering attack using the Linked Devices features, which was on the front page of HN recently.
- mrweasel 2y agoThe fact that proposals like this get this far, without anyone checking with the defence department and actual experts is really weird. It's not just Sweden, this is clearly a problem in many other countries. I'd really like to know why it's so hard for politicians and police forces to understand that backdoors are dangerous.
- mjburgess 2y agoIt will be waring factions within government (which is never unitary in any country) --- here these laws/proposals/etc. probably come from domestic spying agencies and police forces in most countries. I suspect that signals intelligence agencies and offensive forces have probably mostly moved to "encryption is good" stance given the number of foreign attacks upon domestic assets (gov, biz, etc.). However, we shouldn't underestimate the desire for foreign intelligence agencies to bait one's own domestic agencies into "spying for them". So i imagine there's some pressure from, eg., the US sigint agencies to have the EU compromise EU citizens in ways that even those very agencies may today not wish to compromise their own. At a complete guess, I wouldnt be supried if, eg., the NSA (, CIA, et al.) were goading EUROPOL which was demanding domestic anti-encryption laws. As an empirical matter, encryption makes agencies like EUROPOL's jobs extremely difficult -- i imagine also because they probably struggle to get coop from domestic police forces, so cannot easily do "the physical police work necessary" to get device access. In the end, I imagine we'll have china to thank for the end to this nonesense -- since any backdoor will immediately be a means of mass corp/gov espionage.
- genewitch 2y ago> At a complete guess, I wouldnt be supried if, eg., the NSA (, CIA, et al.) were goading EUROPOL which was demanding domestic anti-encryption laws. The exact purpose of Five Eyes? I'm shocked, shocked! there's gambling going in here!
- mjburgess 2y agoIt's not the purpose of five eyes, it's a noted tactic. But at the same time countries realise they are under attack economically and political from hostile cyber warefare... and so there's something self-defeating about this tactic now whereas perhaps 10-20 years ago there wasnt. It's hard to imagine a US-China war (say by proxy in TW) or a EU-Russia war (eg., esp., by proxy in UA) "going well" under conditions of broken domestic encryption. Eg., back when the UK mass surveillance law was passed in 2016, I imagine sigint agencies were more on-board... today I wonder if that law would now be "quietly opposed" on grounds of national defence
- metayrnc 2y ago> The Armed Forces, on the other hand, are negative and write in a letter to the government that the proposal cannot be realized "without introducing vulnerabilities and backdoors that can be exploited by third parties First time I am seeing an organization against this. Kudos to them for standing up.
- diggan 2y agoAccording to the original article (Swedish: https://www.svt.se/nyheter/inrikes/signal-lamnar-sverige-om-regeringens-forslag-pa-datalagring-klubbas https://www.svt.se/nyheter/inrikes/signal-lamnar-sverige-om-...), the reason for the armed forces to be against it is because they recently started advocating for its personnel to start using Signal to reduce eavesdropping, so backdooring Signal would decrease the armed forces security. > Men Försvarsmakten är negativa och nyligen uppmanade försvaret sin personal att börja använda Signal för att minska risken för avlyssning.
- hav 2y agoIn fact, they are negative because they say that this can't be done without opening up the service to vulnerabilities that could be used by others. > I ett brev till regeringen skriver Försvarsmakten att lagförslaget inte kommer kunna förverkligas ”utan att införa sårbarheter och bakdörrar som kan komma att nyttjas av tredje part”. > In a letter to the government, the Swedish Armed Forces writes that the legislative proposal will not be able to be implemented "without introducing vulnerabilities and backdoors that may be utilized by third parties."
- bramhaag 2y agoUnlike a certain big tech giant who pretends to care about privacy until it cuts into their profits.
- ragnese 2y agoAll of them?
- bramhaag 2y agoWell, only some claim to "remain committed to offering our users the highest level of security for their personal data" while turning off E2EE cloud storage for an entire country.
- Schiendelman 2y agoWhat else could they have done?
- greatgib 2y agoThey could have done like Telegram in Russia and said that they will not care about that and work on ways to bypass any firewall that could setup the authority to block it.
- esafak 2y agoAre we talking about Apple? How can they operate in a country they are banned in? They are predominantly a hardware company.
- 0x5FC3 2y agoNot put absolute profit over principles? Or at least don't advertise they do?
- Schiendelman 2y ago
- mathfailure 2y ago[flagged]
- bayindirh 2y ago> Or do they want us to believe 3-letter U.S. agencies don't have access to Signal right now? Is this some publicity stunt? [Citation needed]
- gcnnbdff 2y ago[dead]
- badlibrarian 2y agoI believe the citation falls under "street smarts" as the WikiLeaks press release mentioned Signal explicitly. Whether this was a subtle outing the origin of the tool itself is left as an exercise for the reader. Regardless, the threat vector is accessing the data before encryption anyway. And drawing attention to yourself by running certain apps and services in the first place. There's a lot of mathematicians in maryland and those who studied the history often land on "if they want you, they got you."
- bayindirh 2y agoI'm on the same page with you, mathematicians and the math itself. I'm not a complete stranger to whats and hows of the craft either. I honestly wanted a source to investigate the claim further, not to stab the commenter. OTOH, you have given a couple of leads, which I can follow deeper. Thanks!
- mathfailure 2y agoYou have to think from time to time. If there are even NDAs that forbid mentioning their existence - how would you cite them? And here we're talking about 3-letter agencies in U.S. Of course they have the access and of course you can't ever prove it. One could even argue that Julian Assange didn't leak anything and it's all lies and he can't prove it, lol.
- 2y ago
- throwaway894345 2y agoIt seems like a lot of these proposals are coming out of Europe—assuming I’m not mistaken (and I may well be), why is Europe cracking down so much on privacy?
- diggan 2y agoThere is a huge section of the population who believes it's possible to strip the security of criminals using apps like Signal without it affecting everyone's security. Same in Sweden as the rest of the world. The military of Sweden seems to get it at least, they "write in a letter to the government that the proposal cannot be realized "without introducing vulnerabilities and backdoors that can be exploited by third parties"". The military also recently advocated for more use of Signal, so clearly they've reviewed it and find the current security good enough.
- bramhaag 2y agoOn the surface it's mostly "think of the children" and "terrorists use encryption" type arguments. I'm sure some of the politicians advocating for this have ulterior motives, but I hope we won't get in a position where we find out what those motives are.
- hoseja 2y agoThe reasons mostly are "they are all owned by elites whose names you're not allowed to even know and who would like to keep the serfs docile and ignorant".
- WmWsjA6B29B4nfk 2y agoIn Russia Internet censorship went in ten years from "we need a legal framework to block websites with child porn on a court order, why are you against it, are you a pedophile" to blocking everything that doesn't speak complimentary of the government without leaving any paper trail at all.
- paganel 2y agoBecause we’re cuckolds and a politically dead society. Also very old. After you’re passed the age of 40 you’re more interested from your pension is going to get paid for when the day will come, not in abstract things like “freedom” and what have you.
- vaylian 2y agoThere is a reason why Free Software (as in freedom) was invented: To ensure that those who create the software do not overpower those who use the software. The idea, that companies or politicians can force the user's machine to work against it's owner, is wrong. And it is wrong, because to be a human in the 21st century means in most cases, that your digital devices and your digital interactions are a core part of who you are as a private person. Invading the privacy of one's digital space is a violation that goes as deep as reading someone's diary when we look back and the time when life was more analog.
- throwaway28409 2y ago> The idea, that companies or politicians can force the user's machine to work against it's owner, is wrong. You are hinting at something important here. Let me strengthen your point: to own an object means to subject it fully to your own will. If the object can act in a way that favors someone else's interests over yours, you do not own it. This is true of pretty much any device running proprietary software. A litmus test: can you make your device lie to the manufacturer's servers? Regardless of the legality or morality of doing so. However this article is really about something else: the vulnerability of centralized services in the face of government oppression. Signal only has the ability to log messages because it is a centralized service that controls both the client and the server. The benefits of E2EE is greatly reduced if the client and the server is controlled by the same entity (tomorrow Signal can push out an update that would send a plaintext backup to their servers, and you wouldn't know it until later). Moreover, the non-free distribution mechanisms on mobile phones (stores) limits a company's ability to resist.
- Canada 2y agoYou don't need to run the server to backdoor the client. You just need access to push updates to the client. It doesn't matter who runs the server.
- tuukkah 2y agoAlso only possible because we use Signal as compiled by themselves and not by trusted third parties from a source kept clean of any future client-side backdoors. The client is open source, right? https://github.com/signalapp https://github.com/signalapp (Reproducible builds is a cool technique.)
- BoredPositron 2y agoWhile I don't personally agree with the law, I genuinely hope we witness a major corporation withdraw from a market just so we can finally observe the concrete impact of these types of threats. (Even though their position is understandable in this particular case.)
- Schiendelman 2y agoHave you ever read the book The Corporation? It goes into some detail about why corporations can't do that. Not "won't" - can't.
- frontalier 2y agoi did not read the book but i did read the news when google gave up on serving censored search results in china
- Schiendelman 2y agoWhat would you say the difference is between Google in 2010 in China and Apple in 2025 in the UK?
- disruptiveink 2y agoGoogle ultimately did that for China. The outcome in that case is that the domestic market filled in the gaps, while complying to all relevant authoritarian legislation. I do not believe that the same would happen for every market where these stunts are being pulled off, at least not to the same level of quality. Why are European countries trying to pull one off from the China playbook, while simultaneously being shocked that companies react to authoritarian moves in the exact same way as they have done in the past, is beyond me. Is the hubris so large that they honestly can't conceive their "requirements" as being "literally the same as China?"
- dartos 2y agoWould you want to be reliant on American companies right now?
- wasmitnetzen 2y agoOriginal article (in Swedish, but the interview with Whittaker is in English): https://www.svt.se/nyheter/inrikes/signal-lamnar-sverige-om-regeringens-forslag-pa-datalagring-klubbas https://www.svt.se/nyheter/inrikes/signal-lamnar-sverige-om-...
- throawayonthe 2y agothe english interview is actually in the video banner above the page btw
- qwertox 2y agoApple did the right thing in the UK. This means that neither politicians nor the military will benefit from E2EE, while it's clear that they wished that just the plebes would be affected by this. Maybe all IMs should then drop encryption altogether, bringing us back to the stone age of clear text messaging (email sent unencrypted between MTAs). Because this "please let them use encryption, but let us peek around it" just doesn't feel right.
- Havoc 2y ago> Because this "please let them use encryption, but let us peek around it" just doesn't feel right. Most of gov regulation works like that. You can have guns but only registered ones. Machines guns illegal unless it’s military etc
- sadeshmukh 2y agoBut it is not encryption if it can be broken. It's like guns, but they can remotely disable them with devices planted in each.
- ronbenton 2y agoWhat would even be the point of Signal if there’s a backdoor? This isn’t just principled, it’s necessary for business.
- genewitch 2y agoOnce Signal is backdoored successfully (in this alternate timeline) you go after WhatsApp, RCS, whatever other encryption you can't bypass. Other countries follow suit because Sweden did it (like an infamous single study out of the Netherlands that affected global health policy.) The goal is no privacy. Because terrorism. Or the children. Or espionage. Just pick one and speak against them directly and you'll find many arguments why the government needs access for any of those reasons. People love going to bat for giving up rights. I forget who said it but you cannot have a civilization without secrets.
- regularjack 2y agoHow are these politicians so clueless?
- makach 2y agoIt is incredibly dangerous to add this kind of functionality to anything. I also believe that this request is illegal with current European legislation.
- pr337h4m 2y agoSignal is headquartered in the US and presumably has no employees in Sweden (and perhaps the entire European Union). There is utterly nothing the Swedish government can do to stop Signal except for pressuring app stores and/or ISP-level censorship. Preemptive surrender is extremely disappointing, especially for a non-profit - there isn’t even any revenue that can be ‘fined’ by the EU!
- willvarfar 2y agoThe app stores are run by companies with a presence in the EU.
- walrus01 2y agoWhat's funny is that it's other EU laws from totally different parts of government which are, at the same time, pushing to allow for side loading of apps and alternate app stores on iOS and Android. https://www.google.com/search?q=apple%20eu%20alternative%20app%20store&ie=utf-8&oe=utf-8&client=firefox-b-m https://www.google.com/search?q=apple%20eu%20alternative%20a... The end result of which, if done at large scale, means that an EU government couldn't ban signal, short of forcing all its domestic ISPs to be downstream of a China type great firewall, or simply null route all the IP space where signal's servers are located.
- ben_w 2y agoAll the alternative app stores can easily be subject to the same legal requirements as Apple. Side-loading is harder to enforce any rules over, of course. Blocking domains is well-established at this point, thanks to the copyright industry doing a 21.5-year whack-a-mole-waltz with The Pirate Bay. Of course, this also demonstrates the limited effectiveness of domain blocking.
- walrus01 2y ago> Of course, this also demonstrates the limited effectiveness of domain blocking. Extremely limited effectiveness, when VPN operators like Mullvad are corporations based in Sweden and offer 5 euro a month service to bypass whatever local "mess with internet traffic" activity, whether government-caused or not, that someone's last mile ISP is up to... There's also the game of whack a mole with taking ownership of domains at the registrar/ICANN level through court orders, such as with the various .com or similar things that get jacked and plastered with a "DOMAIN HAS BEEN SEIZED" notice by the US feds.
- mediumsmart 2y agoSwedenherald and their 807 vendor buddies value your privacy.
- nickslaughter02 2y agoFYI the EU wide proposal to scan all your private messages using an AI agent on your devices also originated in Sweden by EU Commissioner Ylva Johansson in 2022. > EU Commissioner Ylva Johansson has also been heavily criticised regarding the process in which the proposal was drafted and promoted. A transnational investigation by European media outlets revealed the close involvement of foreign technology and law enforcement lobbyists in the preparation of the proposal. This was also highlighted by digital rights organisations, which Johansson rejected to meet on three occasions. Commissioner Johansson was also criticised for the use of micro-targeting techniques to promote its controversial draft proposal, which violated the EU's data protection and privacy rules.
- feanaro 2y agoI don't think anything good ever came from Ylva Johansson. Mentions of her name on something should make one automatically treat that thing with suspicion.
- EasyMark 2y agois there some fascist movement in Sweden that I haven't heard about?
- Release0381 2y agoYeah, the Social Democrats, whose member she is
- powerofmAnNnyYy 2y ago[dead]
- microtonal 2y agoWhat is the state of peer to peer messengers with E2EE? Over ten years ago, Bittorrent Inc. (now Rainberry and Resilio) made a serverless chat client (Bleep IIRC). But I don't think there is anything new that is also user-friendly? (Drop-in replacement of WhatsApp, Signal, iMessage, etc.)
- jeroenhd 2y agoPeer to peer communications are difficult to combine with mobile phones (at least if you value battery life). There are various messengers out there, but they're incredibly niche and I doubt they'll ever get any decent user bases. Tox is peer to peer and encrypted, but its UX will probably drive away anyone who wants the ease of use of Signal or WhatsApp. I think Matrix experimented with the concept of running a server on-device, and that's one of the few alternative chat systems with decent UIs available, but AFAIK that never made it beyond the proof of concept stage. Veilid Chat, developed by the Cult of the Dead Cow, promises to be an interesting option, but it's currently in beta and has been for a while.
- undotoday 2y agoJami is supposed to be encrypted, distributed, opensource, and cross platform, though I haven't personally used it: https://jami.net/ https://jami.net/
- timbit42 2y agoSession, SimpleX, Jami, Briar are a few.
- einpoklum 2y agoI wonder if there is some connection between the more-spying direction of policy to Sweden's recent entry into NATO ("after 200 years of non-alignment"): https://www.nato.int/cps/en/natohq/news_223446.htm https://www.nato.int/cps/en/natohq/news_223446.htm
- TravelPiglet 2y agoSweden has been sharing info with its neighbours and the US for a long time. See SIGINT Seniors Europe for example
- deleted 2y ago[deleted]
- nottorp 2y agoInteresting that the Swedish military agrees it's a bad idea.
- focusgroup0 2y ago[flagged]
- krowek 2y agoHow would that be?
- Alifatisk 2y agoThat's a huge challenge isn't it? Unless you do it like in El Salvador.
- gorjusborg 2y ago> If the purpose is to stop the gang violence, why not remove the gangs from the country? Because the stated purpose is only the sales pitch. The full list of uses will never be stated publicly, unless someone like Snowden leaks it at great personal peril.
- slac 2y agoSome background: Lots of stories in the media in Sweden recently about how murders are now ordered via chat apps. Today in fact, there was one about a Snapchat murder. https://www.aftonbladet.se/nyheter/a/8qL3A1/uppgifter-misstankt-for-inblandning-i-skjutning-fick-uppdrag-pa-snapchat https://www.aftonbladet.se/nyheter/a/8qL3A1/uppgifter-missta...
- fallingfrog 2y agoI certainly hope they don’t install any kind of backdoor, because they will give unfettered access to the fbi, and they will likely use that to hunt down marginalized groups (trans women) to eliminate them.
- hagbard_c 2y agoThe solution to this conundrum is to decentralise these services, i.e. run your own XMPP server for your family and friends. Keep your own data where you can 'see' it, on 'the server under the stairs' with some distributed backups to 'devices under different stairs'. This is no pie-in-the-sky statement, I've been running such a server for years and have installed several for others. System requirements and maintenance are minimal - you can run Prosody on a Raspberry Pi 1B if needed. Availability and reliability are high, it basically works as long as network connectivity and storage are available. The user experience largely depends on the client applications where Conversations on Android is probably the gold standard and in many ways comparable to Whatsapp. When using OMEMO the server admin does not have access to cleartext communications so assuming clients are configured correctly there is not much to be gained from raiding the server. If some government entity wants to snoop on communications they'd have to gain access to at least one of the client devices since encryption is handled locally. Instead of backdooring centralised services run by Whatsapp or Signal or Telegram they'd have to get to a multitude of servers-under-stairs and client devices which makes it infeasible to use the 'dragnet approach' which is most likely the intended outcome of these backdoor laws. Some decades ago at I heard Jello Biafra repeat his statement not to criticise the media but to become the media. This has happened, the (current incarnation of) legacy media is running on its last legs and has been overtaken by 'new' media. Here's a corollary to this statement: Don't criticise the service providers, become the service provider Use the internet as it was meant to be, a network of networks. Lots of networks, each running their own services with 'secure' communications between those services. I put secure in quotes because there might be a chance for some TLA or other organisation to break the encryption on one of those communication links. Even if they managed to do so they'd gain access to only a small fraction of the communications going on around the 'net. But advocating for distributed communications only aids and abets criminals, won't you think of the children? When guns are outlawed, only outlaws have guns. Criminals already use these services (and some of them have been broken/backdoored) so this is nothing new to them. But you can't expect grandma to run her own server No, I don't expect her to do so, she can use yours instead. But but but but You're starting to sound like a chicken. Running this stuff is not hard. If you know how to do it, do so and help others to get started. While you're at it you can help them to secure their networks against intrusion by their service providers as well by making sure the ISP connection terminates at a router managed by the device owner, not the ISP. There is no reason to give the ISP access to your LAN since that only creates an incentive for those government entities to force the ISP to give them access to customer networks. The ISP should be used as IAP - internet access provider - and only be allowed to see whatever traffic you allow out of your network, not what goes on inside of it. That, though, is something for another post, another time. I've been running services like this for decades, this works, it is not difficult and does not take that much time. It has only gotten easier over time, hardware has gotten cheaper and smaller, power use has gone down, performance has radically improved. This is not a pipe dream, it has been first my, then our reality for more than 30 years. Don't criticise the service providers, become the service provider
- Alifatisk 2y agoWhich bill are they talking about? Chat control?
- kazinator 2y ago> The Armed Forces, on the other hand, are negative and write in a letter to the government that the proposal cannot be realized "without introducing vulnerabilities and backdoors that can be exploited by third parties", reports SVT. What is the meaning of this paragraph? Did someone from Sweden's own armed forces write to the government to dissuade them from the initiative?
- liam09 2y ago[flagged]
- mollerhoj 2y agoI know this is a very unpopular take on HN, but coming fra Scandinavia id like the police to have a system to scan for child pornography etc. We trust our gov. Hard to believe I know.. I’m not sure if it would be technically possible to design a system where the backdoor could really only be used by the gov somehow
- nickslaughter02 2y agoJust in case you are counting, there's another proposal in France to force backdoors: > At Tuta, we are deeply concerned about the proposed amendment to the so-called "Narcotrafic" law, which would force encrypted communication providers to implement backdoors for law enforcement. This would threaten everybody’s security and privacy and could be in conflict with European data protection legislation and Germany's IT Security Act. We urge the French National Assembly to reject this dangerous amendment. A backdoor for the good guys only is not possible. > France is about to amend a bill against drug trafficking, the “Narcotrafic” law, which will force encrypted messaging apps like Signal and WhatsApp to backdoor the encryption for being able to hand over decrypted chat messages of suspected criminals within 72 hours of the request. In order to enforce it, the text provides for a “fine of EUR 1.5 million for natural persons and a fine of up to 2% of the annual world turnover for legal persons”. The amendment has already been passed by the Senate and is now moving fast to the National Assembly. https://tuta.com/blog/france-surveillance-nacrotrafic-law https://tuta.com/blog/france-surveillance-nacrotrafic-law