10 ms·
This ruling makes end-to-end encryption illegal where, a service provider at no time holds the keys to decrypt messages between communicating parties. This is a
by btreesOfSpring 10y ago
This ruling makes end-to-end encryption illegal where, a service provider at no time holds the keys to decrypt messages between communicating parties. This is a protocol decision and since the Snowden revelations, a point of concern for civil libertarians. The Apple v FBI debate is a child of these exact concerns. The idea that governments want to legislate unfettered access to private communications and devices should be met with skepticism and public scrutiny that this Brazilian case will hopefully provide.
- soneca 10y agoI agree with you. And I think all this should be framed "is the law right? should we change it?"; instead is always presented as "an authoritarian, out of his league, small town judge who is arrogant and clueless about tech". He is just following the law, so fight the law, no diminish the judge. Remembering that a "single judge" following the law with authonomy launched the biggest attack on corruption of brazilian history, and the fact that he is not a supreme court justice acted in favor of an independent investigation (search "sergio moro" and "lava-jato" police investiagiont).
- adrenalinelol 10y agoThe ruling punishes Brazilians on order(s) of magnitude more than it'll Facebook(WhatsApp). This heavy-handed approach is a power grab.
- Hondor 10y agoThis is the "too big to fail" that the GP described. Do you really want a world where a company can evade the law just by getting enough people to depend on it? An important idea of rule of law is that it applies equally to everyone, no matter how important they are. Once you make exceptions for powerful people or powerful companies, it can become corrupt and abused. No small local messaging app will have this protection that people demand should be given to Whatsapp. Why should the dominant player in a market be exempt from complying with laws that their competitors must follow?
- MichaelGG 10y agoNo, judges need to notice when a law creates a contradiction or a stupid scenario and not make such rulings. Judges are supposed to have "wisdom". Pointing at a broken law, then breaking communications for everyone hardly seems wise. Unless he's secretly hoping this will force a big change in law and government.
- aninhumer 10y agoContradictions are one thing, but the stupidity of a law is subjective, and the judiciary should not be empowered to rule contrary to the law based on their opinion of it. Which is not to say they shouldn't point out that it's ridiculous when they make their ruling, and suggest that the legislature fixes it quickly.
- Dylan16807 10y agoThey are being asked to provide data that does not exist, and cannot be recreated. The stupidity of that is objective.
- bikamonki 10y agoCorrect,that is the point of judging otherwise we could build software to do it automatically.
- andersonmvd 10y agoIt also happened before end-to-end encryption be available: http://g1.globo.com/tecnologia/noticia/2015/12/operadoras-sao-intimadas-bloquear-whatsapp-no-brasil-por-48-horas.html http://g1.globo.com/tecnologia/noticia/2015/12/operadoras-sa... (portuguese-br), so it's not necessarily about end-to-end encryption.
- cantrevealname 10y ago> This ruling makes end-to-end encryption illegal where, a service provider at no time holds the keys The Big Company (like WhatsApp, Google, Apple) is always the easy target for subpoenas, judicial orders, and National Security Letters when it comes to encrypted transmissions. Here's an idea for a legal maneuver to take Big Company out of the picture: Suppose crypto was handled by an open source 3rd-party program that was outside of the hands of Big Company. This 3rd-party program would encrypt/decrypt all incoming and outgoing messages, and the program would be mandatory. If you want to use WhatsApp or other Big Company apps, you must install this open source and fully vetted program. Then if Big Company gets a subpoena, they can legitimately answer that they have absolutely no control over the encryption. I'm going light on technical details because there are many ways that this could be implemented. The main idea is to insulate Big Companies from renegade legal attacks.