7 ms·
I lost count how many times the "lets get rid of encryption" plans have been tried and failed. It's truly ridiculous how these people don't understand anything
by codeptualize 1y ago
I lost count how many times the "lets get rid of encryption" plans have been tried and failed. It's truly ridiculous how these people don't understand anything about encryption and somehow still think this is a good idea.
How is it possible that after years of discussing plans like this, they still managed to not listen to anyone who knows anything about encryption and online safety?
Makes me really worried about the future. There is a lot going on in the world, and somehow they feel the need to focus on making our communications unsafe and basically getting rid of online privacy.
The goal they are trying to achieve is good, but the execution is just stupid and will make everyone, including and maybe especially the people they want to protect, less safe online.
The age verification thing is another example. All it does is send a lot of sensitive traffic over cheap or free VPN's (that might be controlled by foreign states). Great job, great win for safety!
- gjsman-1000 1y agoI think you're confusing technical encryption with the privacy of encryption. For example, let's say I implemented a CSAM-scanning AI model in my chat app, which runs locally against your message, before communicating the message over an encrypted HTTPS channel. If the message is flagged, it can be sent over an encrypted HTTPS channel to authorities, on a secondary separate connection. At no point, did it leave the device, in unencrypted form. Is that message encrypted? Yes. The way that you want? No. Governments have recognized this distinction, and have figured out they can have their cake and eat it too; the security of encryption with none of the privacy.
- Terr_ 1y agoAnother example of such degenerate-encryption would be having messages "end-to-end" encrypted, but a copy of the key is kept by a service-provider or even sent in advance to a government agency.
- nicce 1y ago> In cryptography, encryption (more specifically, encoding) is the process of transforming information in a way that, ideally, only authorized parties can decode. From Wikipedia. They can’t have their cake. You are breaking the concept of information into smaller steps (e.g. message) when that is against the definition.
- gjsman-1000 1y agoGovernments don't define encryption that way - they define encryption as the process of transforming information in a way that, ideally, an adversary cannot decode. Messages are unreadable if Russia hacked Vodafone, or China hacked Verizon, that kind of thing. There's a significant difference there between a government's definition and Wikipedia's idealism. Or, even if they subscribed to the Wikipedia definition, they would say they have the legal right to be an authorized party.
- nicce 1y agoCreating new words and definitions doesn't justify any initiatives. The point is that they try to mislead the common people. So we can't really say that "someone is confusing the terms", when the entity in question just created the new definition? It works, because you already tried to argue with that. And it is not the Wikipedia. The whole existence of encryption is evolved around the concept of information. And even the government's definition can be argued, because the adversary is defined by the sender and the receiver, not by anyone else. When there is law, then the definition matters and there is legal stand, but before that, it is just an initiative which tries to mislead.
- zappb 1y agoPeople usually mean "end to end encryption" in these situations, and by adding a third "end" to the system, you bypass the whole point of end to end encryption.
- gjsman-1000 1y agoMy above example is end to end encryption compatible, it's just that you don't get to pick the end it might go to. However, the connections between ends are still encrypted. As such, it passes the technical mathematical definition (one end having a direct pipe to the second end, with nothing possibly in between), but not the philosophical one. Governments have never cared about the encryption philosophy; only the math aspects and international risk - which, in this example, are technically satisfied.
- fruitworks 1y ago>If the message is flagged, it can be sent over an encrypted HTTPS channel to authorities okay, but how do you prevent me from intercepting that communication. Or even running my own copy of the local model and determing ahead of time whether it will trip the alarm. If the attacker has access to the model, they can effectively make a GAN to modify images to get past the filter.
- Akronymus 1y agoOr even just having a proxy that pretends to be the official service but that just drops the reported messages.
- zaphar 1y agoThe seeming trend that worries me the most these days is the lack of competence at multiple levels of society. Our leaders, their supposed subject matter experts, the people doing "the science" all seem to be demonstrably incompetent at their jobs. I don't know if this is an actual trend or just the perception of one but it's concerning either way.
- choeger 1y agoYou're absolutely right. Competency has lost its value. When was the last time you heard someone praise someone else's competency?
- Ylpertnodi 1y ago>Competency has lost its value. Sycophancy, however, will always gain.
- deleted 1y ago[deleted]
- blibble 1y agoyou think it's bad now wait until they start all using "AI", that'll agree with everything they say
- martin-t 1y agoWhy do you call them "leaders"? They are "people in positions of power". I don't understand where this desire to be led comes from. Other people do not have your best interest in mind. I want others to get out of my way, unless we have a conflict of interest and then we _might_ need a third party to resolve it. But I certainly don't need or want to be led.
- zaphar 1y agoBecause I fundamentally disagree with the whole "power" is everything dynamic that seems to crop up here. They are leaders because people follow them. The only power they have is the power that others give them. Leaders captures that better than "people in positions of power".
- clarkmoody 1y agoThis is about power of the state over the individual. Full stop.
- taminka 1y agoall of this is basically irrelevant, given that the type of ppl who this legislation claims to target can always just resort to email + pgp or some such, over which governments don't really have any meaningful control...
- g-b-r 1y agoThe fact that it instead applies to 99.999% of the population is not exactly irrelevant
- StrLght 1y ago> I lost count how many times the "lets get rid of encryption" plans have been tried and failed. They only need to succeed with it once, so they'll keep trying again and again. That's exactly why it's very important to raise awareness about it everywhere.
- edent 1y agoIt is perfectly possible to encrypt a message such that two different keys can decrypt it. There is nothing in modern encryption that makes that impossible. See https://faculty.cc.gatech.edu/~aboldyre/papers/bbks.pdf https://faculty.cc.gatech.edu/~aboldyre/papers/bbks.pdf and many others. So your chat app encrypts your message with the recipient's public key and the state's public key. Hey presto, you have a message which cannot be read by someone who casually intercepts it. If the state seizes your message - or records it for later analysis - they do not need to break encryption. There's no plain-text version laying around for anyone to sniff. Is this a good idea? No. Even ignoring the civil liberties aspect, we know that key management is extremely difficult. A leak of the state's private key(s) could be devastating. But let's not pretend that this is somehow technologically impossible.
- analog31 1y ago>>> A leak of the state's private key(s) could be devastating. Preventing this leak is what's technologically impossible. A leak includes when the government that's keeping the keys decides to start abusing their access to the data.
- edent 1y agoIt's really hard to say whether something like that is impossible. I'm not aware of, for example, Google's private signing keys for Android being leaked. Sure, plenty of CAs have been breached - but not all. That suggests it is possible to key these keys secure.
- wizzwizz4 1y agoWhy would someone want to breach Google's private signing keys? It's easy enough to get malware signed just by submitting it through their ordinary processes. A better analogy would be the keys used by Microsoft to secure Outlook inboxes.
- analog31 1y agoThat's fair. But it turns "possible" into a statement about a company's or government's expected degree of restraint, rather than a mathematical statement about the robustness of an encryption scheme. The famous case is what happened to government birth records when the Netherlands were overrun by Germany in WWII. They weren't even encrypted, but mere transfer of access led to tragedy.
- rehitman 1y agoI do not agree with you that they have good intention or have good goals. They know what they are doing, and they are doing it to gain control. I think by saying they have good goals, but they don't know better, we are down playing the danger. They know what they are doing, and they are doing it to have more power over people.
- EGreg 1y agoIt’s right there in the name: Chat Control. Take them at their word! Look at Australia’s “hacking” bill. It was about letting the government hack (take over) your account and post as you. The “hacking” referred to ahat THEY would do — to YOUR accounts: https://www.accessnow.org/surveillance-state-incoming-with-australias-hacking-bill/ https://www.accessnow.org/surveillance-state-incoming-with-a... Australians even made a movie about a dystopian future: https://www.youtube.com/watch?v=vJYaXy5mmA8 https://www.youtube.com/watch?v=vJYaXy5mmA8
- skrause 1y agoThe name is "Regulation to Prevent and Combat Child Sexual Abuse". "Chat Control" is not an official term, but a name chosen by critics of the law.
- 1oooqooq 1y agowonder if opposition should first fight for an addendum to correct the title in all those double speak laws, and then fight to curb it.
- frm88 1y agoWow. That movie. Just wow.
- AJ007 1y agoThey have evil intentions, but they are also idiots. The nature of an authoritarian government is one that requires maximizing control for survival. As a particular country shifts to a more authoritarian government, and those people who enabled dumb ideas fall out of power (right, left, or whatever) those same tools will be used by their political adversaries to control, imprison, or kill them. Why are they idiots? Because western Europe is not yet authoritarian and thus there is little personal benefit to hasten a slide towards it, there are so many other ways to gain power in a free society. (I wouldn't bet money that Europe will remain free in 25 years.) There is a secondary problem here -- anything that decreases the information security of European countries hands more power to the US and China (and to a lesser degree other nations with advanced infosec capabilities like Russia and Israel.) If you are European (I'm not) the first thing that should be done is investigate the people pushing this stuff.
- pbasista 1y ago> they still managed to not listen to anyone who knows anything about encryption and online safety Why do you assume something like that? Do you actually know the arguments that the parties in favor of this kind of regulation are presenting? And can you dismiss them based on objective facts? > The goal they are trying to achieve is good That is what should be, in my opinion, the basis of this discussion. Assume good intentions and try to work out with the parties involved to achieve the goal in a reasonable way. This is the way, I believe. Hand-wavingly dismissing other party's arguments would be in my opinion disingenuous.
- hobs 1y agoAfter the 10th time you assume good intentions and they still try to do the wrong thing, are you a fool or a helpful patsy?
- mvanbaak 1y ago> Why do you assume something like that? This is very easy to answer. Just look up what all the responses were, for all the times this kind of stuff was proposed.
- rstat1 1y ago>>Why do you assume something like that? Do you actually know the arguments that the parties in favor of this kind of regulation are presenting? And can you dismiss them based on objective facts? The moment anyone brings up the whole "just put a backdoor in that only we can access" despite years of people who actually know better saying that's not possible, is the moment when any further arguments become moot and not worth any further engagement or assumptions of good intention. That's the single argument all these stupid "chat control" like proposals are based on.
- pbasista 1y ago> just put a backdoor in that only we can access Who is arguing for a backdoor? Do you actually know what are the proposed technical approaches or are you making assumptions? > people who actually know better saying that's not possible What is not possible? > all these stupid "chat control" like proposals For example here, you make your argument by stating that these proposal are "stupid". There is no effort that I can see to even try to understand where the other party is coming from. And that is an issue, in my opinion. I think that a productive and honest conversation about a complex issue like this one requires empathy with the other party's position.
- numpad0 1y agoKey enablers that ensured those plans fall apart were PC platform and default code freedom on it. It doesn't work because anyone can just compile the clean versions of apps using gcc, on PC. Same cannot be guaranteed on Android and is not even happening on iOS. We shouldn't have shrugged off the weird feeling of shackles on our wrist when iOS(iPhoneOS) was first released. We should not have relied on geohot stopping by and dropping a jailbreak he found. We should have voted to force it open by law.
- WorldPeas 1y agocannot emphasize this enough. Workarounds were always tolerated because they silenced the potential competition until the frivolous features that people did it for (namely customization) were all available by default, closing the door for what Apple actually hated (side-loading). They are expert software politicians, just look what they do with the EU's open-ecosystem demands
- beezlewax 1y agoAre vpns controlled by private companies safe?
- thw_9a83c 1y agoDepending on meaning of "safe". They all need to comply with law enforcement data requests.
- raxxorraxor 1y agoPick a VPN outside your jurisdiction. Preferably a country that isn't on good terms with yours. The data might get leaked, but not to relevant authorities.
- croes 1y agoIsn’t the point of Chat Control to scan on the device so that they can say encryption isn’t affected?
- vaylian 1y agoChat control opens an additional data channel where messages are sent through, if the detection algorithm finds something suspicious. It effectively makes encryption useless, because someone else, who shouldn't be part of your conversation, is also able to read your messages.
- nomel 1y ago> Makes me really worried about the future. It's important to remember that government is not your friend, isn't meant to be, and never has been. It's a machine of control that needs to be held in constant restrain by the population. Obtaining more control is the expected behavior of those who come into power, shown through all of history.
- mallowdram 1y agoWhat is progressive about rampant decontextualized chat? I read these anti-control statements by what appear to be tech zombies who know nothing about the tech being promoted. LLMs/ML are based on faulty, Western units that are about defining reality in individualistic, material terms, lacking interdependence and relying on arbitrariness to destroy that chance for shared experiences. If governments are leery of LLMs for the wrong or right reason and the industry and technology lacks any kind of grasp of what it is and what the inputs are, then BOTH are wrong and the tech needs dismantling. If the decontextualizing of communication is epidemic, as it appears to be in Chat, then the industry has failed not grasping the first thing about the technology.
- athrowaway3z 1y agoMy guess has been an unholy alliance between 'IP holders' like Hollywood (and increasingly games), and the surveillance industrial complex. Add in the fact that both China and the US already have practically near omniscient digital oversight of everything their citizens do through server and OS level backdoors, the uninformed politicians in the EU/UK are easier to tempt by lobby groups crying in the name of the children.
- pembrook 1y agoNo, this is not corporate lobbying responsible. Stop giving your beloved politicians an out and acknowledge they do not have your best interests at heart, only a thirst for power. The buck stops with the politicians signing this into law.
- athrowaway3z 1y agoOf course, I almost forgot. No better way to quench your thirst for power than to choose to go into Danish politics and move up to EU politics to herd 500 cats to be in favor of some legislative surveillance scheme that, if implemented, you'll immediately lose all control over to different technocrats. I'm sure you'll find somebody who fits that bill, but since it's a democracy, we're more interested in why the other 45% went along with it because they can be reasoned with.
- matthewdgreen 1y agoThe proximate goal they're trying to achieve is mostly irrelevant when compared to the broader technical goal. That goal is to force all messaging systems to re-architect so they include a "bump on the wire" that hosts a scanning mechanism sophisticated enough to recognize novel (unknown) image content. This implicitly requires re-architecting these systems to contain neural-network image classifiers that operate over a model that's kept secret (to the user/client.) Everything else is sort of irrelevant compared to the implications of this new architecture. The "good news" for now is that the systems deployed in this model won't classify text, only images and URLs. The bad news is that the current draft explicitly allows that question to be reviewed in the future. And of course, once you've re-architected every E2EE system to make image scanning possible, most of the damage to cybersecurity is likely already done; a year or two down the road, text scanning will probably be viewed as a modest and common-sense upgrade. I expect that folks who object to text scanning on cybersecurity grounds will be informed that the risks are already "baked in" to the image-scanning model, and so there's no real harm in adding text scanning. Leaving aside the privacy issues, this is basically an existential national security risk for Europe. It's amazing to me that they're walking right into it.
- deleted 1y ago[deleted]
- thomastjeffery 1y ago> these people don't understand anything about encryption and therefore still think this is a good idea. Fixed that for you. I suspect the primary reason that people in this position fail to understand anything about encryption is that it is their job to do so.
- abtinf 1y agoI don’t understand how people like you continue to grant good faith to government. You are the people who make this kind of repeated attack on freedom possible.
- avodonosov 1y ago> The goal they are trying to achieve is good, but the execution is just stupid and will make everyone, including and maybe especially the people they want to protect, less safe online. If so, the best way to stop that is to sugest a good way to achieve the good goal. How would solve these good goals?
- idle_zealot 1y agoBan targeted advertising, let social media companies die.
- zelphirkalt 1y agoPartially it is new corrupted people getting bought in positions of power. There is interest behind this stuff that we have not eradicated. As long as that is allowed to continue, we have to take down one puppet after another. A new puppet is already waiting for their chance to make buck campaigning for the same shit again. After some years in office they don't care what happens to society afterwards. They only care they got their fat paychecks and post politician positions in management layers of big corp. And we elect their parties and these people over and over again, instead of making them utterly fail the next election. Too many of us do not see through these thinly veiled attempts and too many of us are too comfortable to vote them out.