4 ms·
Developers of apps that use end-to-end encryption to protect private communications could be considered hostile actors in the UK. <-- HTTPS does this. What ab
by richsouth 10mo ago
Developers of apps that use end-to-end encryption to protect private communications could be considered hostile actors in the UK. <-- HTTPS does this. What about secure sites like baking sites that encrypt end-to-end? Old farts making laws about things they know nothing about.
- neilalexander 10mo ago> Old farts making laws about things they know nothing about. Who's going to stop them?
- ykonstant 10mo agoYoung poops?
- arccy 10mo agobaking sites, the most secure source of cookies
- SirHumphrey 10mo ago>>> Old farts making laws about things they know nothing about. We should probably stop saying and believing that. This is basically the UK government making a deal to the developers they cannot refuse: cooperate (install backdoors) or get prosecuted. The French tried to do something similar not so long ago. A decade ago politicians genuinely didn’t know much about the internet so most of the laws were terribly ill informed good ideas. The new sweep of internet legislation like chat control, age verification and banning of vpns are much more dangerous because those pushing know exactly what they are doing.
- hs586 10mo agoExactly this. I do not think this is a case of Hanlon's razor. Assuming incompetence or stupidity of the government officials trying to push for is very dangerous. (Great username, btw, SirHumphrey)
- CommanderData 10mo agoWhy worry about E2E encryption, in theory just need a cert issued from a vast array of CAs or intermediates. Which I wouldn't be suprised they possess the ability through some type of secret warrant, heck even private keys.
- JoshTriplett 10mo ago> Why worry about E2E encryption, in theory just need a cert issued from a vast array of CAs or intermediates. Certificate Transparency thankfully means this is a tool a government could only use once if at all, and then they've burned an entire CA.
- CommanderData 10mo agoIsn't certificate transparency opt-in, so any trusted CA could be a potential attack route.
- JoshTriplett 10mo agoBrowsers now require it to consider a certificate valid. Firefox, Chrome, and Safari all require a certificate to include proof of being logged in CT logs.