9 ms·
Are you suggesting end-to-end encryption? Telecom providers have to implement "lawful intercept" interfaces to comply with the law in many jurisdictions.
by whyever 2y ago
Are you suggesting end-to-end encryption? Telecom providers have to implement "lawful intercept" interfaces to comply with the law in many jurisdictions.
- dylan604 2y agoThat's fine. Let them have lawful intercept into my encrypted communications. Let them eat static
- secondcoming 2y agoIf it's all encrypted you wouldn't be able to call land lines.
- dylan604 2y agoyeah? and? so? who does that? if you're concerned about being intercepted and are still using land lines, then you're really not concerned. we learned that in the 80s. if you're using SMS, you're also not really concerned. friends don't let friends use unencrypted.
- lxgr 2y agoI exclusively call landlines from my phone, at least using "actual" phone calls; businesses, to be precise. For all person-to-person calls, my family and friends have long switched to FaceTime and WhatsApp, which are both encrypted. Why would I pay per minute for a less secure and lower fidelity (HD voice usually does not work internationally) channel? That said, I really would prefer if the POTS were better secured, given that SSNs and payment card numbers are transmitted over it all the time.
- immibis 2y agoAs part of lawful intercept, they can't encrypt the traffic and then send the NSA the encrypted traffic. They have to send the unencrypted traffic. Or they go to jail.
- dylan604 2y agoyou've missed the point. if it is e2ee, then there's nothing but noise going down that lawful intercept. the ISP upheld their obligation, yet nosy bitches get nothing.
- immibis 2y agoThe ISP itself can't do E2EE because it's incompatible with lawful intercept.
- dylan604 2y agookay. so let me break it down further. you and i exchange messages via e2ee app. i text you, the app encrypts it, then sends it down the wire. the TLA lawful intercepts that data, but it is just random noise because it is encrypted. your app finally receives the e2ee data, decrypts it, shows you the message. the data in transit is encrypted beyond anything the ISP has control over, so if the ISP provides lawful intercept they have fulfilled their obligation to the TLA because they let them see the data. it's not the ISP's fault that you and I encrypted the data. this isn't TLS encryption. if that's not clear enough, then someone else will have to step in as I have taken as far as I can
- immibis 2y agoSo let me break it down further. The ISP isn't allowed to sell E2EE apps because it would violate its lawful intercept requirement to not encrypt the data it gives to the government. Your E2EE apps have to come from a different company. That's why SMS isn't E2EE.
- dylan604 2y agoAre you seriously just trying to be this obtuse? WTF said anything about the ISP selling anything? You use Signal? You use PGP? Who uses anything from an ISP other than their bandwidth? I've never even heard of an ISP having an app let alone selling it that end users would use. Like it must be painful to think up nonsense like this. It'll be a lot less painful if you just think about it like a normal person using apps instead of whatever it is you have in your head. Damn near troll like
- toast0 2y agoI think they're just suggesting improvements on device-to-network encryption. Requiring the sim card secret to live on the sim card and the network means it needs to be transmitted from manufacturing to the network, which increases exposure. If it were a public/private key pair, and you could generate it on the sim card during manufacturing, the private key would never need to be anywhere but the sim card. Maybe that's infeasible because of seeding, but even if the private key was generated on the manufacturing/programming equipment and stored on the sim card, it wouldn't need to be stored or transmitted and could only be intercepted while the equipment was actively compromised.
- lxgr 2y agoThis really is the least concern in the entire mess that is phone network security. (Credit and debit card issuers have the same key distribution and derivation problem, but it's ~fine, and there are robust standard solutions, such as deriving per-card keys at the personalization site using tamper-proof HSMs.) Even if SIM cards were to feature an asymmetric private key: What would you do with it? How would you look it up, and what would you use it for? There is simply no provision for end-to-end encryption in the phone network at the moment. If there were, it would be a different story, of course, but I doubt that will ever happen.