• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 12:18
CEST 18:18
KST 01:18
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL22] Ro16 Preview: Holy Diver5[ASL22] Ro16 Preview: Rough Waters10[ASL22] Ro24 Preview: Siren's Call8[ASL22] Ro24 Preview: Summer's End9Serral wins HomeStory Cup 2915
Community News
Weekly Cups (Sep 7-12): SHIN, ByuN, MaxPax double down1StarCraft open world shooter announced at BlizzCon100Weekly Cups (Aug 30-Sep 7): herO thrives amid growing schism10Official StarCraft website teases new content ahead of BlizzCon?179Stellar Fest TWO the Moon (Dec 16-20)9
StarCraft 2
General
38 yo Retired SWE looking to save SC IP I have 0 hope Blizzard doing anything with SC IP SC4ALL II: StarCraft 2 Player Announcement 8/8 Balance hotfix patch 5.0.16b (July 16) The Death of Cheese: From a Professional Cheeser
Tourneys
2026 GSTL Announcement Sparkling Tuna Cup - Weekly Open Tournament RSL Revival: Season 6 - Qualifiers and Main Event RSL goes to London! 2026 Offline Finals Nov 21-22 SC2 AI Tournament 2026 Fall
Strategy
[H] ZvP Mid-Late Game: Stalkers Collossi HT
Custom Maps
Nexus Wars 2021 GUIDE [M] (2) Industrial Park
External Content
Mutation # 543 Enhanced Defenses The PondCast: SC2 News & Results Mutation # 542 The Ascended Mutation # 541 Binary Choice
Brood War
General
an AI researcher's take on the ladder bot Working 1v1, 2v2, 3v3 Ladder Bot on ladder Syncronization issues and can't find games Man Bnet can't even load profile now, WTF
Tourneys
[ASL22] Ro16 Group D [BSL23] SM: Ret vs TerrOr - bo7 - Sunday 9pm CEST [Megathread] Daily Proleagues [ASL22] Ro16 Group C
Strategy
Replay Review Process - What do you do? Simple Questions, Simple Answers Odyssey Mineral Stack Saturation Game Theory for Starcraft
Other Games
General Games
Warcraft III: The Frozen Throne Nintendo Switch Thread Stormgate/Frost Giant Megathread EVE Corporation Diablo IV
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
[TL LoL EUW IHs] Teemo shall perish
Heroes of the Storm
Heroes of the Storm 2.0
Hearthstone
Deck construction bug
TL Mafia
TL Mafia Community Thread
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread Canadian Politics Mega-thread Post Your Watch!
Fan Clubs
MarineLorD Fan Club The Creator Fan Club The ShoWTimE Fan Club
Media & Entertainment
Movie Discussion! [Manga] One Piece Diablo Animated Series on Netflix
Sports
Football (Soccer) Thread TeamLiquid Health and Fitness Initiative For 2023 MLB/Baseball 2023
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
Recent Gifted Posts
Blogs
Can Bots Beat Pros?? Starcr…
namkraft
[meme] I finally understa…
LUCKY_NOOB
Virtual Romance, Real-Life C…
TrAiDoS
Regacy Esports:Our Goa…
regacyesports
Dreaming of BW patches (mod…
c3rberUs
Customize Sidebar...

Website Feedback

Closed Threads



Active: 8048 users

UK Politics Mega-thread - Page 307

Forum Index > General Forum
Post a Reply
Prev 1 305 306 307 308 309 648 Next
In order to ensure that this thread meets TL standards and follows the proper guidelines, we ask that everyone please adhere to this mod note.

Posts containing only Tweets or articles adds nothing to the discussions. Therefore, when providing a source, explain why you feel it is relevant and what purpose it adds to the discussion.
Also take note that unsubstantiated tweets/posts meant only to rekindle old arguments will be actioned upon.

All in all, please continue to enjoy posting in TL General and partake in discussions as much as you want! But please be respectful when posting or replying to someone. There is a clear difference between constructive criticism/discussion and just plain being rude and insulting.

https://www.registertovote.service.gov.uk
LegalLord
Profile Blog Joined April 2013
United States13779 Posts
March 27 2017 17:31 GMT
#6121
The continuation of this "no one understands encryption if they disagree with me" game is worth a laugh, for sure. Even if I do agree that backdoors are idiocy this insistence on "I and I alone know how things work" is quite tiresome.
History will sooner or later sweep the European Union away without mercy.
LightSpectra
Profile Blog Joined October 2011
United States3207 Posts
March 27 2017 17:33 GMT
#6122
On March 28 2017 02:26 Plansix wrote:
The justice system functions because there is a reasonable expectation that any order to release information will be complied with. If bank records are needed to prove the state's case or mount a defense against it, the bank will provide them. The same with phone records or any other form of documentation. They may redact information, but they will still provide what they can and justify redacting the information they did.

Companies like Facebook, Google, WhatsApp and others subvert this exception. They offer the ability to communicate through their services, but wash themselves of responsibility to provide the goverment with access. They build locks and keys to assure they don't have access, even to the data on their own servers. And then they make the argument that providing access to that data on the servers they control would be to risky for all their customers.

The argument the goverment and others have been making is if that is sustainable. If they can co-exist with these companies that have active created systems to make it impossible for them to comply with court orders. And tied those systems together to make the argument that they are protecting their clients privacy. If the WhatsApp is any different than a phone company, which is required to keep records and provide them to the court if ordered to do so.

And all of these systems and services were designed to make a profit and place a little burden on the company as possible. To protect them from liability. The companies can argue that it is for the good for everyone, but that is also marketing. Our services are so private even the government can’t get in.


So, again, the choice remains: either everybody is compromised by default, but good AND bad people can become secure with a bit of effort; or everybody is secure by default. Those are the options.

Nothing you say is unreasonable, but none of that changes the fact that there are only two options on the table.
"don't try to pull a LightSpectra-Trumper"
bardtown
Profile Joined June 2011
England2313 Posts
March 27 2017 17:35 GMT
#6123
You risk getting to the stage where searching for how to encrypt your messages will be considered sufficient cause for an investigation.
LightSpectra
Profile Blog Joined October 2011
United States3207 Posts
March 27 2017 17:35 GMT
#6124
On March 28 2017 02:31 LegalLord wrote:
The continuation of this "no one understands encryption if they disagree with me" game is worth a laugh, for sure. Even if I do agree that backdoors are idiocy this insistence on "I and I alone know how things work" is quite tiresome.


I'm sorry, who is making the argument that "no one understands encryption if they disagree with me"?
"don't try to pull a LightSpectra-Trumper"
Plansix
Profile Blog Joined April 2011
United States60190 Posts
Last Edited: 2017-03-27 17:39:06
March 27 2017 17:38 GMT
#6125
On March 28 2017 02:31 LegalLord wrote:
The continuation of this "no one understands encryption if they disagree with me" game is worth a laugh, for sure. Even if I do agree that backdoors are idiocy this insistence on "I and I alone know how things work" is quite tiresome.


It is pretty standard for the tech industry sadly. In the recent lawsuit against Oculus for breaking NDA, John Carmac testified that not only did he break NDA, but freely admitted that he took software he developed for Zenimax. But that was only so he could make his real defense, that stealing the software didn’t matter. That he was such a wizard at code that the software wasn’t even relevant to the final product. So it wasn’t really stealing and only slightly wrong. But not really wrong since no one was really harmed.

He was really grumpy when the jury didn’t find that amazing argument compelling.
I have the Honor to be your Obedient Servant, P.6
TL+ Member
LegalLord
Profile Blog Joined April 2013
United States13779 Posts
March 27 2017 17:43 GMT
#6126
On March 28 2017 02:38 Plansix wrote:
Show nested quote +
On March 28 2017 02:31 LegalLord wrote:
The continuation of this "no one understands encryption if they disagree with me" game is worth a laugh, for sure. Even if I do agree that backdoors are idiocy this insistence on "I and I alone know how things work" is quite tiresome.


It is pretty standard for the tech industry sadly. In the recent lawsuit against Oculus for breaking NDA, John Carmac testified that not only did he break NDA, but freely admitted that he took software he developed for Zenimax. But that was only so he could make his real defense, that stealing the software didn’t matter. That he was such a wizard at code that the software wasn’t even relevant to the final product. So it wasn’t really stealing and only slightly wrong. But not really wrong since no one was really harmed.

He was really grumpy when the jury didn’t find that amazing argument compelling.

I do have to say that the software folks in general seem to be quite bad by the standards of technical experts at convincing people of the validity of their technical concerns in a legal setting. Engineers (not software "engineers" who build websites) tend to be much better at arguing for why science is on their side than programmers.

This reminds me of the FBI "we want Apple to crack open this iPhone for us" case and how stupid some of the software folk looked legally - even though from a technical perspective they were right. I remember you made a point of how the courts would see that that seemed quite effective at describing the problem.
History will sooner or later sweep the European Union away without mercy.
LightSpectra
Profile Blog Joined October 2011
United States3207 Posts
March 27 2017 17:45 GMT
#6127
On March 28 2017 02:43 LegalLord wrote:
This reminds me of the FBI "we want Apple to crack open this iPhone for us" case and how stupid some of the software folk looked legally - even though from a technical perspective they were right.


In what way do you think they looked stupid?

Because they refused to crack the phone of a terrorist at the expense of all of their other customers? Yeah, unfortunately everybody looks bad when they defend human rights contra the universal argument of "but think of the children!!"
"don't try to pull a LightSpectra-Trumper"
Plansix
Profile Blog Joined April 2011
United States60190 Posts
March 27 2017 17:50 GMT
#6128
On March 28 2017 02:45 LightSpectra wrote:
Show nested quote +
On March 28 2017 02:43 LegalLord wrote:
This reminds me of the FBI "we want Apple to crack open this iPhone for us" case and how stupid some of the software folk looked legally - even though from a technical perspective they were right.


In what way do you think they looked stupid?

Because they refused to crack the phone of a terrorist at the expense of all of their other customers? Yeah, unfortunately everybody looks bad when they defend human rights contra the universal argument of "but think of the children!!"

Because they were ordered by a court to do it and they were protecting dead terrorist information on a phone. Of course the argument was that they were protecting everyone’s privacy. But the other argument was that they are protecting their profit margins and lowing their exposure to liability. Apple loves that people feel safe punching their credit card number into their phone.
I have the Honor to be your Obedient Servant, P.6
TL+ Member
Acrofales
Profile Joined August 2010
Spain18441 Posts
Last Edited: 2017-03-27 17:55:18
March 27 2017 17:51 GMT
#6129
On March 28 2017 02:30 LightSpectra wrote:
Show nested quote +
On March 28 2017 02:14 Acrofales wrote:
On March 28 2017 01:48 LightSpectra wrote:
On March 28 2017 01:42 Acrofales wrote:
I have news for you. Facebook CAN already do that. They have total control over the WhatsApp software. If Facebook were to push an update to you tomorrow that instead of encrypting your texts, sent a plain text copy to your worst enemy, the first you would know about it is when your worst enemy uses them against you.


If what you're saying is true, then WhatsApp is already backdoored.

Although it's an easily mitigated backdoor, I suppose, since one could simply turn off automatic updates.

But lets take a step back, because I am not sure you actually know what you're talking about. You speak about exploits and backdoors, but I am talking about a modern equivalent to wiretapping.

Do you agree with me that it is a good thing that government can wiretap phones? And that, if we can sort out internet messaging services to be equally secure to the general public as phone conversations, and get "wiretapping" in there as well, that would be a perfectly decent solution?


Honestly it doesn't really sound like you know what you're talking about. Wiretaps work because the data (i.e. the conversation over the phone) is not encrypted in transit. You can do the same thing to any website that goes over HTTP.

Let me slap my dick on the table then. I have a PhD in Computer Science. Not in security, but I did take some MSc. level courses in security. So yes, I know telephone conversations are not encrypted. And I know that what we're talking about are encrypted conversations. However, they are a specific form of encrypted conversations. More below.


Great, then since you know so much about such an obvious solution, go make a couple million dollars as a government consultant to politicians and stop wasting my time.

Pretty sure I'm not forcing you to respond.


Show nested quote +
I think you severely overestimate the average intelligence of a criminal.


Every terrorist attack that has succeeded in the past 15 years in the first-world is proof that a couple average guys with a negligible amount of resources can overcome an intercontinental multi-trillion dollar surveillance apparatus.

What about... oh wait. That's right. This has nothing to do with the topic at hand.


The problem isn't that terrorists are geniuses, the problem is that encryption actually exists in nature and no force in the world can stop bad people from learning about it.


Nowhere is anybody claiming otherwise.


Show nested quote +
However, that's not how WhatsApp works. WhatsApp (and all other similar services) come with some specific built-in vulnerabilities:

1. Neither Alice nor Bob are in charge of their encryption keys. They are provided by WhatsApp's software.
2. The messages are not routed directly from Alice to Bob, but are sent through WhatsApp's servers.


My focus is not on WhatsApp per se but on really any encrypted communications app in widespread use (Signal, iMessage, et al.). But I'll play along.


Any system where you send information through channels you don't control is compromised. The moment your message leaves your system, you should assume someone is trying to read it. If you didn't encrypt it yourself, someone *may* be able to read it. In the case of WhatsApp the only guarantee you have that Facebook isn't reading your conversation is because Facebook tells you so. If fully secure communication is your aim, you should absolutely not be using WhatsApp, Telegram or whatever other commercial app is available. In my opinion, that is far more tinfoil-hat-worthy than it's worth, though. WhatsApp is hella convenient and I don't care too much if Facebook is listening in to most of my conversations, and know how to switch when I do worry. Moreover, I trust both Facebook and the government when they tell me that they are not reading my conversations.

Am I saying Facebook has already added the wiretap protocol to the WhatsApp software? Of course not. And yes, they'd have to push an update. Of course, they could easily make it mandatory by simply making whatsapp not work anymore for anybody who hasn't updated. This would be very bad for business, but the government could pass legislation that requires messaging services to have this type of protocol.

Moreover, something being open source doesn't make it secure. Unless you also compiled it yourself, there is absolutely no guarantee that whatever you downloaded in the app store (or wherever) is the same thing that you looked at the source code of. If you are indeed downloading source code, compiling it, and installing it on your phone on your own, then kudos. You are very secure. Of course, you're still only as secure as the people you are communicating with...

So it's a backdoor, just one that takes a little bit more concentrated effort to overcome.

Yes, some malicious guy at Facebook with full access to the WhatsApp system could use such a protocol to spy on his girlfriend (or random people). Just as someone at BT/Vodafone/whatever might be listening in to any of your phone conversations. Generally speaking, we (1) don't care and (2) trust them not to care. If you want fully secure conversations, definitely don't use the telephone...

But more broadly, there tend to be protocols in place to stop random employees at Vodafone from listening in on conversations. And those same protocols could be used for WhatsApp. This part of the issue is not a new problem. In fact, modern encryption technology allows a more secure solution through secret sharing.
LightSpectra
Profile Blog Joined October 2011
United States3207 Posts
March 27 2017 17:55 GMT
#6130
On March 28 2017 02:50 Plansix wrote:
Show nested quote +
On March 28 2017 02:45 LightSpectra wrote:
On March 28 2017 02:43 LegalLord wrote:
This reminds me of the FBI "we want Apple to crack open this iPhone for us" case and how stupid some of the software folk looked legally - even though from a technical perspective they were right.


In what way do you think they looked stupid?

Because they refused to crack the phone of a terrorist at the expense of all of their other customers? Yeah, unfortunately everybody looks bad when they defend human rights contra the universal argument of "but think of the children!!"

Because they were ordered by a court to do it and they were protecting dead terrorist information on a phone. Of course the argument was that they were protecting everyone’s privacy. But the other argument was that they are protecting their profit margins and lowing their exposure to liability. Apple loves that people feel safe punching their credit card number into their phone.


That's because there's a distinction there that a lot of people missed.

They weren't refusing to crack the shooter's iPhone. They could not do that. It is not within their means. What Apple was doing was refusing to use their private key to sign some malware that would eliminate security features on the phone, which would have allowed EVERY iPhone to be cracked without a warrant.

Are safe companies stupid if they don't make a custom skeleton key for the FBI to crack every safe they've ever made? No. Nobody would buy safes from them ever again if their security was so compromised. The same is true of Apple. They could either submit to becoming a jewelry company that no serious person would ever use for real work, or they could stand up and say "We're not compromising our millions of customers for the government, because even if we do, those bad people will just stop using iPhones and move on to something else that's otherwise impenetrable."
"don't try to pull a LightSpectra-Trumper"
LightSpectra
Profile Blog Joined October 2011
United States3207 Posts
March 27 2017 18:02 GMT
#6131
Any system where you send information through channels you don't control is compromised. The moment your message leaves your system, you should assume someone is trying to read it. If you didn't encrypt it yourself, someone *may* be able to read it.


That's true to an extent, sure. Of course, there are open source security solutions that demonstrably guarantee that your private key is not in danger and thus nobody will ever be able to read the messages encrypted under your public key, such as Signal and GPG.

WhatsApp is a harder case to judge considering they're not open source, but they've undergone a security review that theoretically is the equivalent. I'm not vouching for the auditors who did the review, maybe they fucked up. I'm just responding to the notion that Facebook could 'easily' backdoor it.

Am I saying Facebook has already added the wiretap protocol to the WhatsApp software? Of course not. And yes, they'd have to push an update. Of course, they could easily make it mandatory by simply making whatsapp not work anymore for anybody who hasn't updated. This would be very bad for business, but the government could pass legislation that requires messaging services to have this type of protocol.


Yeah, and then everybody who's interested in security would switch to extranational solutions that aren't bound by the same legislation. Until we get to a world government, there's no stopping that.

Trump of course wants this, he wants to backdoor every American communications program in order to catch terrorists. His mistake, and the mistake of everybody who agrees with him, is that it takes mere minutes to switch to something not American. All of our companies thus lose all of their business and the bad people are no worse off.

Moreover, something being open source doesn't make it secure. Unless you also compiled it yourself, there is absolutely no guarantee that whatever you downloaded in the app store (or wherever) is the same thing that you looked at the source code of. If you are indeed downloading source code, compiling it, and installing it on your phone on your own, then kudos. You are very secure. Of course, you're still only as secure as the people you are communicating with.


Open source isn't a guarantee of security, no. But it's a guarantee of no backdoors so long as you review the code for backdoors (doesn't take terribly long and even non-programmers can do so) and compile it yourself, which is quite easy to do.

Yes, some malicious guy at Facebook with full access to the WhatsApp system could use such a protocol to spy on his girlfriend (or random people). Just as someone at BT/Vodafone/whatever might be listening in to any of your phone conversations. Generally speaking, we (1) don't care and (2) trust them not to care. If you want fully secure conversations, definitely don't use the telephone...


That's the precise point I'm making here. Ordinary folk need a secure-by-default solution, otherwise it's too much work for them and they'll just settle for being compromised. But that doesn't stop bad people from putting in minutes of effort to use something secure. Do we want to live in a world where innocent people are prone to mass surveillance but bad people are just as secure as they are now?
"don't try to pull a LightSpectra-Trumper"
Acrofales
Profile Joined August 2010
Spain18441 Posts
March 27 2017 18:07 GMT
#6132
On March 28 2017 02:50 Plansix wrote:
Show nested quote +
On March 28 2017 02:45 LightSpectra wrote:
On March 28 2017 02:43 LegalLord wrote:
This reminds me of the FBI "we want Apple to crack open this iPhone for us" case and how stupid some of the software folk looked legally - even though from a technical perspective they were right.


In what way do you think they looked stupid?

Because they refused to crack the phone of a terrorist at the expense of all of their other customers? Yeah, unfortunately everybody looks bad when they defend human rights contra the universal argument of "but think of the children!!"

Because they were ordered by a court to do it and they were protecting dead terrorist information on a phone. Of course the argument was that they were protecting everyone’s privacy. But the other argument was that they are protecting their profit margins and lowing their exposure to liability. Apple loves that people feel safe punching their credit card number into their phone.

Completely different cases. But yes, it would not be a good thing if losing your phone meant you have to cancel your credit card. And I cannot think of a technical way for Apple to ensure they could get into a phone that is locked without compromising the locking mechanism in such a way that any sophisticated hacker could get into any phone that is locked. Because the same asymmetry of control does not apply as in what I described about communication channels.

But if you don't like the pragmatic argument, here's a philosophical one: smartphones should be considered an extension of the body, not of the home. Because for most intents and purposes that's how we treat them. They serve us as an extension of our memory, and as a communication channel, among other things. We store things in our smartphone that we would otherwise memorize. Smartphones have effectively turned us into cyborgs. And a whole new set of issues arises with that. Simply treating a smartphone as a safe that you should be able to open if you have physical access to it is overlooking this fact, and maybe we should treat it more as having access to someone's body, and thus 5th amendment rights apply to their smartphones... or maybe we should treat it as a mix. But technology is opening new ethical conundrums and treating smartphones as a different iteration of the beaten track is an error of category.
Plansix
Profile Blog Joined April 2011
United States60190 Posts
Last Edited: 2017-03-27 18:11:04
March 27 2017 18:07 GMT
#6133
The same is true for the mail. The mail man can open my mail and look at it. Its super illegal, but it can happen.

If Facebook and Apple want a law that makes the act of breaking into their client’s data using internal backdoors illegal, they can ask for it. If they want some protection from liability for having to create it, they can work with congress. If they have special requirements that the warrant to backdoor given software be sealed when issued, or be non specific, they can work with congress to create that system.

There are countless ways to create a system that can be responsibility secure, but not pefect. Perfection is impossible when humans are involved. By Apple and other’s plan to remove all humans and responsibility for their products isn’t going to be sustainable. At some point they become like Uber, yelling that they shouldn’t have to play by the rules everyone else has to.

Edit: Acrofales - I agree that smart phones are a special case and should have different requirements. I would have no problem with them being more secure or having other safeguards built it. I’m not for unlimited access or backdoors on every product. Just an end to the all or nothing argument that the tech industry is making. Because that argument ends with the government saying “Nothing sounds fine.”
I have the Honor to be your Obedient Servant, P.6
TL+ Member
Jockmcplop
Profile Blog Joined February 2012
United Kingdom9999 Posts
March 27 2017 18:07 GMT
#6134
So what's being suggested is that we all give up our privacy because a guy drove a car into a bunch of people and stabbed a cop.
Fair enough, but its not going to stop the next guy driving his car into a bunch of people and stabbing a cop is it?
RIP Meatloaf <3
LightSpectra
Profile Blog Joined October 2011
United States3207 Posts
Last Edited: 2017-03-27 18:13:49
March 27 2017 18:10 GMT
#6135
On March 28 2017 03:07 Plansix wrote:
If Facebook and Apple want a law that makes the act of breaking into their client’s data using internal backdoors illegal, they can ask for it.


Makes perfect sense. Criminals of course always obey the law, so they'll be totally bound to obey this one as well.

On March 28 2017 03:07 Plansix wrote:
There are countless ways to create a system that can be responsibility secure, but not pefect.


Then go make one and become an overnight billionaire for having solved a problem that is widely considered to be unsolvable.

On March 28 2017 03:07 Plansix wrote:
Just an end to the all or nothing argument that the tech industry is making. Because that argument ends with the government saying “Nothing sounds fine.”


Reality is all-or-nothing, and no law is going to change that.

They can pass a law to try, certainly. And that will result in American tech companies losing billions so that European companies who aren't bound by the same laws can pick up where they left off.
"don't try to pull a LightSpectra-Trumper"
Plansix
Profile Blog Joined April 2011
United States60190 Posts
March 27 2017 18:13 GMT
#6136
On March 28 2017 03:10 LightSpectra wrote:
Show nested quote +
On March 28 2017 03:07 Plansix wrote:
If Facebook and Apple want a law that makes the act of breaking into their client’s data using internal backdoors illegal, they can ask for it.


Makes perfect sense. Criminals of course always obey the law, so they'll be totally bound to obey this one as well.

Please refrain from making these garbage arguments.
I have the Honor to be your Obedient Servant, P.6
TL+ Member
LightSpectra
Profile Blog Joined October 2011
United States3207 Posts
March 27 2017 18:16 GMT
#6137
On March 28 2017 03:13 Plansix wrote:
Show nested quote +
On March 28 2017 03:10 LightSpectra wrote:
On March 28 2017 03:07 Plansix wrote:
If Facebook and Apple want a law that makes the act of breaking into their client’s data using internal backdoors illegal, they can ask for it.


Makes perfect sense. Criminals of course always obey the law, so they'll be totally bound to obey this one as well.

Please refrain from making these garbage arguments.


What's garbage about it? Russian/Chinese/North Korean hackers are already breaking the law, why would a law that says "please don't use the backdoor" be any different?
"don't try to pull a LightSpectra-Trumper"
Acrofales
Profile Joined August 2010
Spain18441 Posts
Last Edited: 2017-03-27 18:16:52
March 27 2017 18:16 GMT
#6138
On March 28 2017 03:02 LightSpectra wrote:
Show nested quote +
Any system where you send information through channels you don't control is compromised. The moment your message leaves your system, you should assume someone is trying to read it. If you didn't encrypt it yourself, someone *may* be able to read it.


That's true to an extent, sure. Of course, there are open source security solutions that demonstrably guarantee that your private key is not in danger and thus nobody will ever be able to read the messages encrypted under your public key, such as Signal and GPG.

WhatsApp is a harder case to judge considering they're not open source, but they've undergone a security review that theoretically is the equivalent. I'm not vouching for the auditors who did the review, maybe they fucked up. I'm just responding to the notion that Facebook could 'easily' backdoor it.

Show nested quote +
Am I saying Facebook has already added the wiretap protocol to the WhatsApp software? Of course not. And yes, they'd have to push an update. Of course, they could easily make it mandatory by simply making whatsapp not work anymore for anybody who hasn't updated. This would be very bad for business, but the government could pass legislation that requires messaging services to have this type of protocol.


Yeah, and then everybody who's interested in security would switch to extranational solutions that aren't bound by the same legislation. Until we get to a world government, there's no stopping that.

Well, you could of course make it illegal to use phones of that type. It wouldn't stop criminals from using them, but it would give law enforcement another tool: they could arrest them on the use of contraband technology.


Trump of course wants this, he wants to backdoor every American communications program in order to catch terrorists. His mistake, and the mistake of everybody who agrees with him, is that it takes mere minutes to switch to something not American. All of our companies thus lose all of their business and the bad people are no worse off.

I don't think I'll address this strawman.


Show nested quote +
Moreover, something being open source doesn't make it secure. Unless you also compiled it yourself, there is absolutely no guarantee that whatever you downloaded in the app store (or wherever) is the same thing that you looked at the source code of. If you are indeed downloading source code, compiling it, and installing it on your phone on your own, then kudos. You are very secure. Of course, you're still only as secure as the people you are communicating with.


Open source isn't a guarantee of security, no. But it's a guarantee of no backdoors so long as you review the code for backdoors (doesn't take terribly long and even non-programmers can do so) and compile it yourself, which is quite easy to do.


Absolutely. Do you, though? Or do you just download the app from Google Play? Because I guarantee you that virtually nobody installs their homebrew apps. In fact, most people don't even know where the button to install from "untrusted sources" (irony noted) is.


Show nested quote +
Yes, some malicious guy at Facebook with full access to the WhatsApp system could use such a protocol to spy on his girlfriend (or random people). Just as someone at BT/Vodafone/whatever might be listening in to any of your phone conversations. Generally speaking, we (1) don't care and (2) trust them not to care. If you want fully secure conversations, definitely don't use the telephone...


That's the precise point I'm making here. Ordinary folk need a secure-by-default solution, otherwise it's too much work for them and they'll just settle for being compromised. But that doesn't stop bad people from putting in minutes of effort to use something secure. Do we want to live in a world where innocent people are prone to mass surveillance but bad people are just as secure as they are now?


Where you say mass-surveillance I say court-ordered surveillance. Remember that the default mode is still encryption on. Facebook/Google/Telegram/my homebrew messaging app have absolutely no incentive to switch that off. So unless a court orders a wiretap on you, your WhatsApp messages are encrypted. And if you're paranoid you are free to add extra layers of encryption in there.

It also won't catch smart criminals, who will of course be paranoid and add those extra layers of encryption. But nobody is claiming catching smart criminals will ever be easy. Just that barring law enforcement the possibility to listen in to conversations by very simple design makes catching dumb criminals needlessly hard.
Plansix
Profile Blog Joined April 2011
United States60190 Posts
Last Edited: 2017-03-27 18:23:09
March 27 2017 18:21 GMT
#6139
On March 28 2017 03:16 LightSpectra wrote:
Show nested quote +
On March 28 2017 03:13 Plansix wrote:
On March 28 2017 03:10 LightSpectra wrote:
On March 28 2017 03:07 Plansix wrote:
If Facebook and Apple want a law that makes the act of breaking into their client’s data using internal backdoors illegal, they can ask for it.


Makes perfect sense. Criminals of course always obey the law, so they'll be totally bound to obey this one as well.

Please refrain from making these garbage arguments.


What's garbage about it? Russian/Chinese/North Korean hackers are already breaking the law, why would a law that says "please don't use the backdoor" be any different?

That is a risk with phone calls, mail, checks, faxes(maybe not faxes), wiring funds and all other forms of communication. Why is digital communication different? Why should it be any different than those systems? Why does it gain special protection from court orders that those companies do not? What if the phone companies created a special version of phone line that couldn’t be wire tapped, ever?
I have the Honor to be your Obedient Servant, P.6
TL+ Member
LightSpectra
Profile Blog Joined October 2011
United States3207 Posts
March 27 2017 18:22 GMT
#6140
Well, you could of course make it illegal to use phones of that type. It wouldn't stop criminals from using them, but it would give law enforcement another tool: they could arrest them on the use of contraband technology.


Another charge to add to the "blew themselves up in public" charge, I suppose.

But would that work against scammers and smugglers? Sure, until they decide to just revert back to word-salad as was done in the days of olde.

Absolutely. Do you, though? Or do you just download the app from Google Play? Because I guarantee you that virtually nobody installs their homebrew apps. In fact, most people don't even know where the button to install from "untrusted sources" (irony noted) is.


I do download it from Google Play, but I do a cryptographic hash verification.

Granted most people don't do that, but I'm sure they will the moment the very first bait-and-switch exploit is demonstrated to have been used in the iOS App Store or Google Play.

If I was a Bad Person, I would compile from source. It's not hard. Non-programmers can do it, and in fact many of them probably do.

Where you say mass-surveillance I say court-ordered surveillance. Remember that the default mode is still encryption on. Facebook/Google/Telegram/my homebrew messaging app have absolutely no incentive to switch that off. So unless a court orders a wiretap on you, your WhatsApp messages are encrypted. And if you're paranoid you are free to add extra layers of encryption in there.


I don't know how many times I have to repeat this. If Facebook/Google/Telegram can do it arbitrarily for a court order, they can do it arbitrarily for anyone and any reason.

It also won't catch smart criminals, who will of course be paranoid and add those extra layers of encryption. But nobody is claiming catching smart criminals will ever be easy. Just that barring law enforcement the possibility to listen in to conversations by very simple design makes catching dumb criminals needlessly hard.


I don't agree with the premise that we should compromise billions of people's security for a chance to catch a few dumb criminals.
"don't try to pull a LightSpectra-Trumper"
Prev 1 305 306 307 308 309 648 Next
Please log in or register to reply.
Live Events Refresh
Online Event
14:00
BamPatch 1.0 Weekly #2
SHIN 103
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
ByuN 399
SHIN 103
CosmosSc2 60
MindelVK 29
EmSc Tv 16
StarCraft: Brood War
Shuttle 1021
Mini 548
firebathero 511
Soulkey 361
Soma 345
Stork 263
Dewaltoss 94
Zeus 62
Sea.KH 59
sSak 44
[ Show more ]
Barracks 40
Sharp 32
910 31
ToSsGirL 23
Trap 18
PianO 14
Terrorterran 13
Free 6
Dota 2
Gorgc6824
Dendi1397
Counter-Strike
byalli538
Heroes of the Storm
crisheroes254
Other Games
singsing1383
FrodaN1291
fl0m811
B2W.Neo741
Beastyqt552
Hui .286
KnowMe220
QueenE85
Mew2King78
Trikslyr44
Vindicta12
Organizations
Dota 2
PGL Dota 2 - Main Stream7776
PGL Dota 2 - Secondary Stream3675
Other Games
gamesdonequick1050
EGCTV884
StarCraft 2
WardiTV584
Other Games
BasetradeTV60
StarCraft 2
EmSc Tv 16
EmSc2Tv 16
[ Show 15 non-featured ]
StarCraft 2
• poizon28 50
• EnkiAlexander 26
• mYiSmile120
• intothetv
• AfreecaTV YouTube
• Kozan
• IndyKCrew
• Migwel
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• C_a_k_e 2251
League of Legends
• Jankos1682
Other Games
• WagamamaTV196
• Shiphtur196
Upcoming Events
AI Arena Tournament
42m
Replay Cast
7h 42m
GSL
18h 42m
Shopify Rebellion Sundays
22h 42m
Spirit vs Mixu
BSL
1d 2h
Ret vs TerrOr
Replay Cast
1d 7h
Afreeca Starleague
1d 17h
Shine vs Rush
WardiTV Weekly
1d 18h
Monday Night Weeklies
1d 23h
Sparkling Tuna Cup
2 days
[ Show More ]
Afreeca Starleague
2 days
Light vs EffOrt
PiGosaur Cup
3 days
Kung Fu Cup
3 days
The PondCast
4 days
Replay Cast
5 days
Korean StarCraft League
6 days
CranKy Ducklings
6 days
Liquipedia Results

Completed

Proleague 2026-09-18
Blizzard Classic Cup 2026
Big Dog Cup 2026 Div 1

Ongoing

K-JUNGMAN
ASL Season 22
Super Anchor Qualifying S3
CSL 2026 AUTUMN (S22)
Acropolis #5
Acropolis #5 - GSA
Calamity Invitational
Logitech G Play Connect 2026
SL StarSeries Fall 2026
FISSURE Playground #3
BLAST Open Fall 2026
Esports World Cup 2026
BLAST Bounty Summer 2026
BLAST Bounty Summer Qual
Stake Ranked Episode 3
XSE Pro League 2026

Upcoming

Acropolis #5 - GSB
Acropolis #5 - GSC
SC4ALL II: Brood War
HSC XXX
Stellar Fest 2: Lunar Cup
SC4ALL II: StarCraft II
Kung Fu Cup 2026 Grand Finals
RSL Offline Finals
Copium Cup
PGL Major Singapore 2026
Stake Ranked Episode 6
BLAST Rivals Fall 2026
IEM Beijing 2026
Stake Ranked Episode 5
PGL Masters Bucharest 2026
1win Private Club #2
Thunderpick World Champ. '26
ESL Pro League Season 24
Stake Ranked Episode 4
1win Private Club #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.