Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Urgh. This should be better phrased. From the BoingBoing article:

David Cameron says there should be no "means of communication" which "we cannot read"

It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition with "we do not intend to ban encryption" and close it.



The problem with your interpretation is that bank communications are still a means of communication. So the vagueness of the law allows politicians to extend their requirements to any product they wish without exception. This isn't something I believe to be accidental either as terrorism laws are often written to be vague with the intent of common sense regulation - which often gets bypassed when a jobsworth believes they're in the right.


"means of communication" is not in the text of a law. It was a quote from David Cameron. As yet, there is no law.

I think it's reasonable to assume that the terms would be more explicitly defined in an actual law.


Reading "between the lines" is not a valid way to interpret laws. What is written is what is valid, not what you think it should mean.

As yourself used the term, how is "communication between a bank and a customer" not a form of "communication"?


>What is written is what is valid, not what you think it should mean

I am not sure if it would be a good thing or not if this was the case, but leaving that aside laws are, in fact, liberally interpreted all the time, depending on your jurisdiction's legal tradition. This is why you can't hack the law; the interpretation of the law will change to fill in the gaps, provided that's what the justice system wants.


"means of communication" is a quote from David Cameron, and is not the actual valid text of a law. It's hardly uncommon for a politician to sum up the intent of a law while not using the precise language used inside it.

In any case, there is no law yet, so no language to examine.


Oh right, because laws are ironclad codifications of pure, unadulterated Justice, and that's exactly why you can be imprisoned for collecting rainwater on your property: http://cnsnews.com/news/article/oregon-man-sentenced-30-days...

In reality, the correct way to interpret laws is to think about their real purpose. Who benefits? What is the goal here?

The vast majority of laws have one of these two purposes: to enrich the government's cronies, or to cement the government's continued rule.


Apparently our politicians should understand infosec to demand policy, but the people don't have to understand their goverment to demand policy.


How can you have a situation where the HTTPS used to secure communication between two peers is different than the HTTPS used between a bank and one of it's clients ?

This just shows serious misinformation on your part.


We do already have different implementations of TLS/HTTPS used for different purposes. They're called cipher suites. There are already weaker cipher suites in widespread use, which are the cause of most of the big security issues with TLS/SSL/HTTPS. (This is pretty good article on the subject: http://blog.cryptographyengineering.com/2015/03/attack-of-we...)

I'd guess all the UK government would do is insist that, by law, all secured P2P messaging goes via a given cipher suite (one with a government backdoor/decryption key and, I guess, no perfect forward secrecy).

It's pretty conclusive how bad an idea it is, when all of the leading security experts in the world have said that this is impossible without weakening the entire security of the system.


Presumably the government asks the bank what you're up to, and the bank tells them. Which is exactly what already happens today.

Do you think the reason you use HTTPS to talk to your bank is to prevent the government from seeing your account balance?


It's certainly not the only reason but sure it's one of them. Proof of that is Google forcing TLS encryption of all it's traffic after the NSA scandal.


The number of people that can implement secure communications without relying on third parties is close enough to zero that they basically don't count.

ISIS recruitment would plummet to zero if people had to get TLS working before joining.


I don't think that you understand that the TLS technology used for online banking (which would still be legal) is the very same technology that lets you create a secure communication channel with other users.


I don't know why you think that. Perhaps I was unclear.

The average prospective terrorist / criminal etc isn't going to be able to set up TLS. If they encrypt their communications, the odds are it's going to be going via a third party. Next time you send an email, tell the recipient that from now on you're going to communicate directly by TLS, and they'll need to set up a server before you can talk to them again. I believe that most people will have considerable difficulty doing that.

So, you're reliant on third parties who constitute single points of failure and potential targets of legal action.

Individuals who can securely set up TLS (or PGP or whatever) for their own communications are sufficiently rare that they effectively don't matter.


TLS is currently simply a matter of point and click on a graphical interface.

For hosting provider setup, to domain name registration and TSL certificate generation there are thousands of online tutorials.

You don't need to be an expert or a developer to know how to setup TLS on a Wordpress blog.


A Wordpress blog run by a third party does not constitute a secure messaging system, even if you have TLS enabled on it. And it's still a lot less easy than using WhatsApp.


Installing pidging, otr, starting a chat and confirming who you're talking too doesn't exactly require a comp sci degree.

This isn't really about stopping that though, it's about the snooping nanny state plain and simple.


Using PGP securely is as easy as downloading some software, typing in your message, and clicking a button. It's not something that requires any knowledge beyond basic computer usage. You aren't going to be able to stop people from sharing PGP software on the internet.

I think you're severely underestimating the intelligence of people in general. If we're talking about ISIS, all it takes is one moderately experienced computer user to show everyone else how to use PGP.


> Using PGP securely is as easy as downloading some software, typing in your message, and clicking a button. It's not something that requires any knowledge beyond basic computer usage. You aren't going to be able to stop people from sharing PGP software on the internet.

And yet we find a bunch of supposedly encrypted stuff where the user did something wrong, leaving the stuff effectively unencrypted.

See also people uploading keys to github etc.


What software are you talking about? I've seen very clever people struggle with PGP. In fact Ed Snowden famously screwed up when he first emailed Glenn Greenwald.


GPGTools, for example (https://gpgtools.org)

I suppose I omitted the step of copying and pasting your recipient's public key, but that's not especially conceptually difficult, either.


That does look quite nifty.

There's also keypair generation, which is the step that derails most people I think. Plus the fact that people have to grok the concept of public and private keys, and be able to distribute / not distribute them as appropriate. And revocation certificates. And public keyservers. And trust levels. Etc.

I do think an organised, disciplined group might manage to get PGP working as intended, but I doubt there are many such groups.

My point is, I doubt individuals implementing encryption have much to fear from whatever proposals may emerge from this. Maybe they will later. But it seems to me it's much more likely to target companies that offer/facilitate encrypted messaging.

Edit: Thanks to whoever just put my karma over 2000. Does anything exciting happen when you get to 2000 points?


Hmm. I guess my thought is that if it became well-known that using Whatsapp, iMessage, etc. to communicate about illegal activities frequently led to arrest, then knowledge of PGP and the like would spread because it's not too difficult to use. So then government would be able to read everyone's communications through those channels for no appreciable benefit.

Obviously, that's total conjecture, though.


Using PGP is as easy as understanding PKI, which is beyond most people that don't work in tech, and a substantial amount of people that do.


One would hope that the legislating body would be held to a higher standard.


It would be pretty easy to implement messaging between two people who can log in to the same bank account. There are plenty of places you can store text typically, labels on payees, your details etc. Or one could use two accounts under the same login: person A logs in and sets the balance on account 2 to something which represents a character in binary. Then person B "acks" that character by transferring the money back to account 1. Repeat. Those characters could in fact be cipher text for full end to end crypto that even the bank can't decipher.


I expect that a government may be very interested in the content of communications between a bank and a customer


Banks are so closely regulated that they are not really (in fact not at all) off limit for the government. Unless we are talking about a foreign website of a foreign bank, which would not be required to comply anyway.

Webmails, social medias or dating services are of a much greater interest to a nosy government.


Oh, I believe you are mistaken. Governments are quite interested in your financial dealings, even with banks. The more they know, the less you can do without their direct knowledge.


I am not saying they are not interested. I am saying that they just need to ask the banks who will hand over everything no question asked. GCHQ does not need to intercept your connection to get your bank statement.


I bet they don't even need to ask..


Many countries still require warrants.


I think in France the taxman can check your bank account directly so it's a fair bet that the intelligence service have access. I have no reason to think things are different in the UK.


I wouldn't be surprised.

Have you ever read about the various French Intel services after the revolution? Talk about convoluted. They trusted no one or even each other.


I can't see how, without any context, you can say that "Webmails, social medias or dating services are of a much greater interest to a nosy government". As to regulations, if it is the law that backdoors are mandatory, then banks have no say in this.


Because they are services hosted outside the UK and which are not heavily regulated. Banks not only provide everything the gvt asks but actually have a duty to act as a law enforcement agency, i.e. watching their customers on the gvt behalf. Facebook or Gmail aren't required to do that.


You seem to imply that currently (retail? investment?) banks in UK are obligated to provide the government with information regarding customer's accounts. Can you provide a reference?


What if the communications are being sent over HTTPS? E.G. facebook messenger




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: