8 ms·
'Five Eyes' nations discuss backdoor access to WhatsApp
- xster 7y agoTony Ma's daughter better not go to any of the Five Eyes countries at this point.
- skrowl 7y agoIf this works, it won't actually stop strong e2e encryption, it'll just make people download their strong e2e encryption communication apps from non-mass-surveillance states. This isn't p*rnhub. You can't backdoor everything.
- amfsn 7y agoPeople generally don't care about LE reading what they say, so no. People used whatsapp before e2e and will keep using it after e2e.
- merpnderp 7y agoMaybe your "people" are cool with LE reading their salty messages to significant others, or hot take political commentary, but all the "people" I know expect privacy as good responsible citizens should.
- andyjh 7y agoOne might reasonably assume the "bad guys" they're trying to catch would go elsewhere though, if they have any sense. So then you're just left with innocent people to spy on.
- amfsn 7y agoYou'd be surprised to learn how fucking stupid most bad guys are.
- misterprime 7y agoWe catch lots of stupid bad guys. Smart bad guys get away with it.
- amfsn 7y agoCynical and correct observation, which I know will get downvoted because it goes against the mantra of this website: Being able to read whatsapp would help us catch many more stupid bad guys. Smart bad guys will always be able to get away with it. That doesn't mean we should stop trying to catch stupid bad guys.
- dane-pgp 7y agoWhat if catching the stupid bad guys just means the smart bad guys take their place? Like a spray that kills 99% of bacteria, all you're potentially doing is applying a selective pressure towards being more technically smart. And in this case, being more technically smart might just mean clicking the link to the E2E encrypted web chat site rather than the server-to-client encrypted site. Perhaps, though, the government will start banning websites that offer E2E encrypted chat, and require hosting companies to not let you host such apps yourself.
- coldtea 7y ago>So then you're just left with innocent people to spy on. Those are who they want to spy on anyway. For serious criminals, terrorists etc they have other tools, banning commercial encryption wont help with those...
- driverdan 7y ago> This isn't p*rnhub. Why would you censor pornhub?
- jdauriemma 7y agoFor those of you searching for good E2E-encrypted messaging apps, Wire is really good. It has true cross-platform support without being tied to a phone number.
- bobbyd3 7y agoI know a lot of folks who are technical (and non-technical) and it was a big enough struggle to get them using Signal. I definitely see the advantages of Wire and not being tied to a phone number but I just don't know anyone using it. It's odd because some of those folks are using Keybase chat though... they just bulk at installing yet another messaging app (regardless of features).
- hestipod 7y agoI tried to get people to use Wire but it was buggy enough, and still is with most ignored, the majority of converts have abandoned it. I have continual problems. If it would have been reliable it could have been a killer app as it was basically Skype but encrypted and ostensibly available on all platforms. Having a stand alone (no linked phone) browser (angostic) based option is a great feature. But, it really feels they left the free/Personal version in the dust for their Pro/Enterprise option and from reading Github complaints and seeing a former employee discuss it in another forum I'd assume that to be accurate. Signal isn't much better from reading around and also still requires a phone linked and is only Chrome if you want to use it on the desktop (unless I am behind the times). Seems the space for an all in one encrypted communication/sharing tool available and accessible to all people and platforms has sort of died. I will never trust FB so even if people way smarter than me say Whatsapp is safe it still feels so dirty...and again the phone required bit.
- redthrow 7y agoWire's "not tied to a phone number" part is good but constant delayed messages and lack of (useful) time stamps for each message (a la Signal) make the app pretty much unusable for me (and probably many others).
- humantiy 7y ago>The controversial so-called “ghost protocol” has been fiercely opposed by companies, civil society organizations and some security experts – but intelligence and law enforcement agencies continue to lobby for it. Even if it it was possible I think the bigger question is do we want to live in a society where any and all conversations can be ease-dropped on? I get the point that they want it for investigations, but its been proven over and over that if there is a way it will be abused. Would intelligence and LE also be ok with that same rules applying to them?
- Nasrudith 7y agoThe answer is no of course - they have the thought terminating cliche of "national security" to protect against accountability. Really the fact intelligence and law enforcement agencies are lobbying is actually utterly fucked up. Their purpose is to serve us not the other way around. If people with actual sense were in charge the fuckers pushing for it would be fired and out the door so fast it breaks the sound barrier - actively undermining that which the nation benefits from the most economically and making them weaker to attackers - all while not making adversaries weaker? That is inexcusable incompetence.
- isostatic 7y ago> Their purpose is to serve us not the other way around. However "we" want them to be able to "stop the bad guys" and "monitor bad communication". "We" also have nothing to hide. This yougov poll shows more Americans support backdoors in encryption than oppose it https://today.yougov.com/topics/technology/articles-reports/2015/10/19/americans-all-stripes-worried-about-data-privacy https://today.yougov.com/topics/technology/articles-reports/... https://d25d2506sfb94s.cloudfront.net/cumulus_uploads/inlineimage/2015-10-19/data4.png https://d25d2506sfb94s.cloudfront.net/cumulus_uploads/inline...
- pizza234 7y ago> However "we" want them to be able to "stop the bad guys" and "monitor bad communication". This is appropriate, under the assuption of accountability; right now, three letter agencies aren't subject to it. > "We" also have nothing to hide. This is disingenous or naive (and it's a worringly widespread idea). Literally (as in literal-literal) anybody can be accused and charged, it's just a matter of legal power¹. Giving up privacy makes it dangerously easier. ¹=There's even a book on this subject (although the angle is not precisely this): https://www.amazon.com/Three-Felonies-Day-Target-Innocent/dp/1594035229 https://www.amazon.com/Three-Felonies-Day-Target-Innocent/dp...
- deogeo 7y ago> Dealing with the challenge faced by increasingly effective encryption They weren't able to spy in bulk when communication was primarily offline, and they won't when it's primarily encrypted. Don't let them frame the brief, anomalous period when they could listen in on everyone, as 'normal'.
- tuxxy 7y agoThis. That entire period should be examined as a lapse in judgement, not a time when things were better. Because of our state-of-the-art security, we're now able to do more things online in less secure environments. A secure, distributed internet is normal. One that is insecure by design is not.
- m-p-3 7y agoEven HTTPS was costly in terms of resources back then, thankfully hardware acceleration and better algorithms came and there are no valid reasons anymore not to encrypt communications now.
- xster 7y agoThey brought it up themselves too https://www.youtube.com/watch?v=xozVBAWo8XI https://www.youtube.com/watch?v=xozVBAWo8XI (not dubbed unfortunately) where their users would accuse them of being antiquated for not doing any server sync'ed messages but it's all by intent.
- OrgNet 7y agoproper security has always been "state-of-the-art"
- dmix 7y agoEven burner phones were a technically state-of-the-art which was a story which underpinned an entire season of a TV show's plotline (and title). Cellphones became so cheap and widely available you could buy and throw them away efficiently to not get easily tapped and still make enough money, even as a low level drug dealer living in low income neighbourhoods. That wouldn't have been possible years prior.
- nimbius 7y agofrom what ive learned about encryption and cryptography in general, it seems like you dont get to put this cat back in the bag once it gets out. You can hold all the meetings you want. pound fists to table, elegantly restate your problem, but the mathematic fundamentals of it are your immovable object. your only option is to block it throughout your nation. this just makes room for a new, or an updated version of the fly you swat last week that gets around your flyswatter. Sure, you can try to poison the code base, or inject some kind of malware, but this trick only works once. its not a silver bullet.
- MarcScott 7y agoI wrote a blog post about this awhile back, when the UK government was talking about adding backdoors to encrypted messaging platforms, framed as an open letter to our PM. It's a basic introduction to cryptography (I'm no expert though). http://coding2learn.org/blog/2017/06/11/dear-theresa/ http://coding2learn.org/blog/2017/06/11/dear-theresa/ Given that the maths is "out of the bag", any motivated criminal organisation or group that is intent on not being caught can quite easily encrypt their own communications. The only people who won't are the innocent public, who can be spied on with impunity.
- coldtea 7y ago>Given that the maths is "out of the bag", any motivated criminal organisation or group that is intent on not being caught can quite easily encrypt their own communications. The only people who won't are the innocent public, who can be spied on with impunity. It's always the innocent public who is the target of such moves. The goal is state omniscience, not crime fighting. Competent criminal organisations wouldn't care about laws banning encryption, and would know to use the proper tools. The random non-competent criminals caught this way, would be used to justify the measure...
- mantap 7y agoI wouldn't be so cynical. The real goal is to catch stupid criminals. Not all criminals are stupid, but most are. Of course governments cannot stop tech people from using e2e encryption. That's not what bothers them. What bothers them is that e2e encryption is the default. They want to change the default to be insecure. The people who demand these laws are tasked with making various statistics change, such as crime rates. They are metaphorical paperclip maximisers: a surveillance state is not a goal, it is just a means to an end, a way to make their numbers look better.
- yters 7y agoAs we worry about 'Five Eyes' spying on us, we happily give Google and Facebook all our communications for free...
- beezle 7y agothat is by choice. I have no choice about goverment spying on me.
- est31 7y agoIn contemporary society you are usually quite the outcast when you say you don't do social media. You have the choice between being an outcast and being spied upon. Similarly for government spying in messenger apps: if you are an outcast who doesn't buy a smartphone or computer you are not affected.
- a0-prw 7y agoI can't count the number of assholes I have avoided by not being on Facebook ;)
- 946789987649 7y agoI can count the number of assholes I have met on Facebook. It's 0. I only put people I like in the first place on it, and surprise surprise, I enjoy using it. It's not the tool people, it's how you're using it.
- cirrus-clouds 7y agoSome info about disgraced former International Development Secretary Priti Patel, who is the UK's new Home Secretary (a position that looks after home affairs such as crime, security, terrorism, immigration, citizenship). - She resigned from her previous position as International Development Secretary in 2017 when it was discovered she held secret unauthorised meetings with Israeli officials and lied about it. The meetings were not sanctioned by the Foreign Office and were a breach of ministerial code. - A supporter of Brexit, she suggested last year that the UK leverage the prospect of food shortages in Ireland in order to gain a better Brexit deal. Although, she quickly back-pedalled on her comments, she was rightly criticised for her remarks. The depressing reality is that the current Conservative Party in the UK is stuffed to the rafters with nasty politicians just like her. Priti Patel's voting record in parliament: https://www.theyworkforyou.com/mp/24778/priti_patel/witham/votes https://www.theyworkforyou.com/mp/24778/priti_patel/witham/v... "Generally voted for requiring the mass retention of information about communications" "Voted for mass surveillance of people’s communications and activities"
- p1necone 7y ago>>> The depressing reality is that the current Conservative Party in the UK is stuffed to the rafters with nasty politicians just like her. Give me a single example of a western country with a right wing party that isn't stuffed to the rafters with slimy arseholes. Why is it so taboo to just fucking say it. Conservatives are wrong. Their entire ideology is just wrong. Edit: I know this is going to get downvoted because I am generalizing and being a bit stupid. But it would be nice if someone rebutted me properly too.
- NeedMoreTea 7y agoNot to forget that immediately on being appointed Home Secretary she was accused of breaking the ministerial code yet again, in May! It's currently the only significant point under the Home Secretary section of her Wikipedia page: https://en.wikipedia.org/wiki/Priti_Patel#Home_Secretary:_July_2019–present https://en.wikipedia.org/wiki/Priti_Patel#Home_Secretary:_Ju... Most of the reasonable and moderate members of the Tory party are on the back benches, leaving or about ready to retire. The old, reasonable, one nation Tory party is dead as a dodo.
- sam0x17 7y agoThis will just drive people to more and more distributed platforms until there is nothing they can do.
- 14 7y ago“Creation, distribution, discussion, or any thought about encryption is illegal and will be punishable by up to life in prison under new anti-terrorism laws.” They will certainly try I am sure but at the end of the day encryption is just math and that is impossible to ban.
- s09dfhks 7y agoThoughts eh?
- dumg 7y ago> new home secretary, Priti Patel Third world countries have third world laws.
- motohagiography 7y agoAt some point, people are going to see the problem as not of a lack of privacy technologies, but of a small group who surveils them and exploits their personal information to keep them disadvantaged, and they will decide that this is the problem they need to solve. It is also likely that the technology they use to solve that problem will be much less sophisticated. Ballots, surely.
- taneq 7y ago> Ballots, surely. Well, one of the four boxes, anyway.
- thelittleone 7y agoOr could it be they already have a back door and stories like this serve them by making people believe they don’t.
- dane-pgp 7y agoBy this logic, the fact that there were no stories about the government not being able to spy on messenger apps before, means that those apps were perfectly secure until they added E2E crypto. That doesn't sound right to me.
- fencepost 7y agoDoes nobody realize how inconvenient it is that the relationship between the radius and circumference of a circle cannot be calculated readily by hand? Our manufacturing processes will be greatly improved by silencing those so-called 'mathematicians' and standardizing on a value of 3 for pi not that never ending mess.
- peterkelly 7y agohttps://en.wikipedia.org/wiki/Indiana_Pi_Bill https://en.wikipedia.org/wiki/Indiana_Pi_Bill
- carapace 7y agoCyberSaber..? > By choosing a simple but strong cipher that is already widely published and agreeing on how to use it, anyone with elementary programming skills can write their own encryption program without relying on any products that can be banned. http://ciphersaber.gurus.org/ http://ciphersaber.gurus.org/ And Pontifex, aka the Solitaire Encryption Algorithm (SPOILER ALERT): > In Neal Stephenson's novel Cryptonomicon, the character Enoch Root describes a cryptosystem code-named "Pontifex" to another character named Randy Waterhouse, and later reveals that the steps of the algorithm are intended to be carried out using a deck of playing cards. https://www.schneier.com/academic/solitaire/ https://www.schneier.com/academic/solitaire/ Laws cannot stop encryption, they can stop law-abiding people from using it maybe but not criminals.
- schoen 7y agoThe ciphersaber idea is great, but the cipher that was chosen for the project has been subject to significant attacks (further developments of the ones mentioned on that page) and has been deprecated in TLS. (The attack setting for attacking RC4 in HTTPS is probably a lot easier than attacking short person-to-person communications, but it's still not a good sign.) Also, when you implement the ciphersaber, you're still only about 1/4 of the way to the functionality of early-1990s PGP, notably lacking any public key functionality. > For file encryption, a user need only memorize one key or passphrase. For messaging, users need to exchange pairs of keys through some secure means, most likely in person. Maintaining a list of correspondent's keys or passphrases in a master file, preferably itself encrypted with a memorized master key, is less convenient than public key encryption. But it may be all that is left in a few years if PGP key servers are banned. > It may even be possible to teach a manual version of the Diffie-Hellman key exchange, perhaps using large number calculators (easily built in Java 1.1). The Diffie-Hellman procedure need be carried out just once per pair of correspondents, since CipherSaber eliminates the need to exchange keys for every message. Apart from the implausibility of some of this, you have a very severe issue about key synchronization if you literally only want to do a key exchange once. For example, an attacker who can intercept one party's message and then trick another party into encrypting a known plaintext with the same key material (because that party doesn't know that the keystream has advanced yet?) can then decrypt the intercepted message. Even having the two users accidentally use the same part of the keystream to send separate unknown messages m₁ and m₂ will allow an adversary to compute m₁⊕m₂, which is very bad in many cases. One thing I remember from Dan Boneh's cryptography class is that if either message contains an ASCII space character (' ') at some position, then m₁⊕m₂ will contain the other message's plaintext with uppercase and lowercase inverted (for example,' '^'q' is 'Q'). The ciphersaber idea is conceptually really great, and I love the idea of helping teach people to create their own communications and communications security infrastructure. But I think that, apart from just how archaic the cryptographic technology it teaches is, the project really underestimates how far away this cipher implementation is from a complete system.
- 4ntonius8lock 7y agoThis just in: Dealing with the challenges faced by having a mere 97% conviction rate, federal prosecutors and law enforcement conspire with foreign powers to remove pesky civil liberties.
- peterkelly 7y agoEver since Edward Snowden's revelations in 2013, I've had zero sympathy for or trust in any intelligence service, even in purportedly democratic countries. Last year, my own country (Australia) passed a law which allows the government to force companies or even individuals to add backdoors to their products, and makes it a criminal offence to refuse or publicly disclose their requests. I would go to jail before I complied. For those of you in other five eyes countries, you'll have similar laws soon too. Our intelligence agencies have clearly set themselves up against fundamental principles of human rights, and their efforts to undermine these must be fought.
- midge48 7y agoThis all shows what idiots government parliamentarians are in Australia. If the issue is encryption, then there are very simple ways of using unbreakable encryption systems without relying on asymmetric keys (ie one time pad or Vernam cypher). Granted it will not suit all use cases, since a means of identifying what is the key to use needs be agreed outside of the network processes. That is face to face or via messengers, for instance. But since any file can be used as key (ie music, text, video, object program, etc.) and having a key larger that the text encrypted eliminates repetition patterns, this is a totally unbreakable system. Even quantum computing would totally fail in decrypting a message! It is super simple to implement with a modicum of programming knowledge, it does not require any maths skills! An example of it can be found here: https://gitlab.com/MidGe48/cryptopad https://gitlab.com/MidGe48/cryptopad I can expand on the means of communicating and sharing keys which are simple and untraceable without requiring ongoing communication after an initial, simple, exchange.
- nitemice 7y agoOne of the scariest parts of this to me is that the vast majority of Aussie developers don't seem to even be aware that such a law was proposed, let along already passed.
- throwaway9d0291 7y ago> allows the government to force companies or even individuals to add backdoors to their products I think the tech media and community overstates the impact of this law. The law [0] makes it clear that the backdoor cannot introduce any systematic weakness of vulnerability, which explicitly includes "a new decryption capability in relation to a form of electronic protection". What it allows is stuff that targets a specific person _and_ is incapable of affecting anybody else. The second part overrides the first part, so if it's not possible to target a specific person without weakening protection for everybody else, you're not required to do anything. For example asking you to put code into your app that creates a copy of private keys and sends them to ASIO if the user's ID matches a hard-coded value would be legally okay per my reading of the law. However adding ASIO's key to every single message would not be okay. I'm not saying I'm in favour of the law (I'm not) but its actual effect isn't at all what people assume (I hear a lot of comments about "Australia banned encryption" and other such nonsense). [0]: http://www5.austlii.edu.au/au/legis/cth/consol_act/ta1997214/s317zg.html http://www5.austlii.edu.au/au/legis/cth/consol_act/ta1997214...
- tru3_power 7y agoIn addition to all the ethical and privacy concerns brought up here, another thing that always crosses my mind is do we even trust these entities to properly store this information? What happens if all data that is being collected from these backdoors is compromised? Think about every private conversation you’ve ever had potentially leaking to the entire world.
- lunias 7y ago"We need to ensure that our law enforcement and security and intelligence agencies are able to gain lawful and exceptional access to the information they need" This entitlement is obscene. If backdoor access is granted then a new set of heads will emerge from the hydra.