5 ms·
Except Cameron wants to backdoor end-to-end encryption like iMessage/Whatsapp, rather than mess with something like SSL. With SSL they can just get a warrant (o
by c0g 11y ago
Except Cameron wants to backdoor end-to-end encryption like iMessage/Whatsapp, rather than mess with something like SSL. With SSL they can just get a warrant (or you know, don't get a warrant) and look at the server, where everything is in plain text.
One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the person's phone, which is a clearer analogy to getting a warrant to search someone's house to look for things they have stashed.
- visarga 11y agoWhat about apps that keep the encryption keys in the user phones and can't decrypt the contents of messages? Do they intend to ban those apps?
- c0g 11y agoThat was my second paragraph - and to be clear, they don't want to ban it, they want to backdoor it. My idea was that rather than ban it outright and make it like most other internet traffic (decrypted on a server), they could mandate some kind of cacheing of the _encrypted_ data on the server. Then, once they'd lawfully executed a warrant to grab the suspects phone, they can decrypt at their leisure. Apps using per-message keys will probably be a no-no. Myself - I live in the UK - I hope Apple, Google and Facebook all say a big "fuck you" and cut this country off from their services, but I have a feeling the 'compromise' is going to be something like the paragraph above.
- ianamartin 11y agoI'll be very surprised if Apple compromises on this issue. I'll be similarly surprised if Google accepts that kind of compromise. Few things would surprise me about what Facebook is willing to do, but I think this would shock me if fb was willing to go for what you are talking about. The world is run by technology companies now. Not governments. Governments haven't caught on to this yet, at least officially. But the bottom line about law is that the law is whatever Google, Apple, Facebook, Microsoft, and Amazon says it is. That's not the most comforting thought in the world, but that's how it is. And it's sort of okay for now because all of those companies are currently run by idealists. God help us when they are not. For right now though, there isn't a chance in hell that Cameron's ideas will have any traction. He's just saying things that will win him some support from a certain segment of the population.
- jsprogrammer 11y agoUntil technology companies control food and energy production, they don't "run the world".
- swombat 11y agoI would be very surprised if Apple and Facebook (and Google, with GMail, GTalk, Hangouts, etc) didn't use this golden opportunity to swing their weight about and assert who's really in charge of technology around here, by simply wholesale blocking use of all their communication tools in the UK to comply with the law. I have a feeling that if they did this, the uproar would be sufficient to have the law reversed by emergency measures. If they were followed, as they may well be, by a whole host of other essential internet services (Google Search, Wikipedia, Github, etc etc etc) just switching off simultaneously in the UK on the day the law comes into force, that might be sufficient to ensure this sort of dumb shit is never done again. The cost of billions of pounds of lost productivity would probably ensure that.
- cesarb 11y ago> One possible way to backdoor it might be mandate that companies keep copies of the encrypted messages, tagged with a device ID. Then to decrypt you need to get the person's phone, which is a clearer analogy to getting a warrant to search someone's house to look for things they have stashed. That doesn't work if the message has been encrypted on transit with an one-time key, which is discarded after the message has been received. The Axolotl system (used by TextSecure/Signal and AFAIK the new encryption on WhatsApp) does that. Once the message has been received (and thus the corresponding key discarded), any copy of the encrypted message becomes useless. The current tendency in protocol design is to use ephemeral keys (usually through some Diffie-Hellman variant) whenever possible, since it's more secure. > With SSL they can just get a warrant (or you know, don't get a warrant) and look at the server, where everything is in plain text. That doesn't work if the server is outside their jurisdiction.
- c0g 11y agoYour first point: Yep, totally right. I think there's two levels though, the first being that my messages are free from dragnet style surveillance, the second being that my messages are totally secure. Making them get a warrant and get my actual device to decrypt my messages is a damn sight better than having unfettered access to clear text. Second point: Not sure about that, can't I just serve a warrant on Facebook UK to give me the data? If they say "Sorry, we can't get it because America", I imagine the police will say "What? Give it up or go to prison". Similarly, if Google/Apple allow banned apps in their app store, just bring a suit against their UK tentacles.
- cesarb 11y ago> Similarly, if Google/Apple allow banned apps in their app store, just bring a suit against their UK tentacles. The app doesn't have to be in their app store: on Android, it's a simple checkbox to be able to install an app from outside the app store. One can also enable developer mode and install it as if it were a self-developed app.