7 ms·
Could you give examples of the US adding backdoors and weakening end-to-end encryption? I'll give you the almost-certain weakening of proposed crypto standards,
by dannyobrien 17d ago
Could you give examples of the US adding backdoors and weakening end-to-end encryption? I'll give you the almost-certain weakening of proposed crypto standards, and Clinton-era export controls, but I don't think I've seen any movement in that direction recently. The most successful attempts statutorily seem to be in the UK and the US.
Also: the European Court of Human Rights, as a non-EU institution, doesn't have an enforcement mechanism, so I'm not sure it's a good example to give in defending against such proposals. For instance, Russia declined to respect that decision, and I don't think it's had much effect on the UK's backdoor regime.
- inigyou 17d agoSurely everyone knows Dual_EC_DRBG, the CLOUD Act, and National Security Letters?
- embedding-shape 17d ago> Could you give examples of the US adding backdoors and weakening end-to-end encryption? Do you really need examples of this? There are countless of them, some programs you cannot have missed are PRISM, STATEROOM and BULLRUN but there are more of them too.
- Semaphor 17d agoI must say I find it interesting you say "cannot have missed" as I never heard of stateroom or bullrun before
- embedding-shape 17d agoI guess not everyone read through the Snowden "revelations" back in 2013: https://en.wikipedia.org/wiki/Snowden_disclosures https://en.wikipedia.org/wiki/Snowden_disclosures > PRISM is a code name for a program under which the United States National Security Agency (NSA) collects internet communications from various U.S. internet companies - https://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/PRISM > STATEROOM is the code name of a highly secretive signals intelligence collection program involving the interception of international radio, telecommunications and Internet traffic - https://en.wikipedia.org/wiki/Stateroom_(surveillance_program) https://en.wikipedia.org/wiki/Stateroom_(surveillance_progra... > Bullrun (stylized BULLRUN) is a clandestine, highly classified program to crack encryption of online communications and data - https://en.wikipedia.org/wiki/Bullrun_(decryption_program) https://en.wikipedia.org/wiki/Bullrun_(decryption_program)
- Semaphor 15d agoThanks, I did read articles about it back then, but while PRISM was mentioned always and everywhere, none of those I read mentioned the other ones, or if they did, just as an aside.
- dannyobrien 17d agoSo none of these are mandated backdoors, or weakening end-to-end encryption. They're examples of the intelligence services pursuing signals collection. Mandated backdoors would be something like the the United States' (as far as we know) failed attempts to compel companies to insert code to allow third parties to enter and read their communications, or the UK's (as far as we know) long-postponed attempts to add ghost devices to Apple and Meta's e2e communication systems. I'm not so much asking as a gotcha, as modern examples of this kind of backdoor (or published encryption weaknesses) would be a big deal. I realise that there are many other tactics that states, especially the US, pursue that undermine privacy online. These just seemed weirdly specific to projects that the US has, in fact, failed to pull off for years: compelled insertion of code, and deliberately weakened encryption. (ObContext: I worked at EFF during the Snowden revelations, and worked on understanding the impact of PRISM, and Bullrun specifically.)
- deleted 16d ago[deleted]
- shakna 17d agoDon't worry. They're still weakening crypto standards today, hand in hand with the UK. [0] [0] https://blog.cr.yp.to/20251004-weakened.html https://blog.cr.yp.to/20251004-weakened.html