back
108 comments
*This is the same government-party which make extensive use of such technology https://www.google.com/search?q=tory+party+whatsapp+groups+e...

*You might start to think they dont practice what they preach, we know they like to party https://www.bbc.co.uk/news/uk-politics-59577129

*If they dont actually belive in the thing they promote, hmmm i wonder who is getting these contracts https://www.theguardian.com/politics/2021/mar/28/high-court-...

Oh don't worry they will still have access to their signal.gov.uk -- national security is too important!
As Sir Humphrey says in Yes, Minister:

The Official Secrets Act is not to protect secrets, it is to protect officials.

[1] https://anilnetto.com/governance/accountability/come-on-guys...

This one doesn't have that quote, but I couldn't stop laughing when watching it:

[2] https://www.youtube.com/watch?v=r-s-Y4xA9pk

YM/YPM aged so well!
Watched their little ad, the text goes scrambled and the scary subwoofer comes on. "Don't give them a place to hide, oh please, let us constantly monitor every reasonably accessible message in our entire society at the hardware level because some marginal percentage of the people out there are gross predators".

Five eyes, burgers and lies; at it again.

It's funny, just a modicum of common sense should tell them that the biggest problem is the government themselves. There have been a number (to understate it) of high profile cases of "gross predators" in Britain who were allowed to operate freely with the government fully aware of what they were doing and turning a blind eye to it or even protecting them.

It's not that breaking encryption could not solve any crimes or help people (on the contrary it clearly could and if we had a perfect benevolent government that was immune to corruption and incompetence we may well want them to have a crypto backdoor). The problem is that governments have clearly and repeatedly demonstrated, by their actions, that they have no intention of using powers like this to help the common person or to better society. They use powers like this to protect and enrich the government and its friends.

This is not surprising at all, as a nation that is second only to China for its density of CCTV surveillance in public places would hate that anyone have the capacity to elude constant monitoring/"oversight".
CCTV has become almost entirely useless when anyone planning on committing some crime just wears a hoodie and face mask. Tracking via the internet and peoples phones is so much more effective.
Not impossible this completely backfires. With trust in the UK government, police and state institutions at pretty much an all time low. Them demonising it will quite possibly result in more people really wanting it.

Kinda like when they poured their entire propaganda machine into staying in the EU.

Tech, law enforcement, and media, folks aside, people will collectively shrug and move on. To most, it's all abstract fights about other people's problems, like most banking regulations are to me, no matter how much they might impact me. See James Comey/FBI vs Apple, Apple iCloud CSAM scanning, etc. etc. etc.
Wow, these guys actually made a pro-surveillance campaign with the slogan "no place to hide". I guess they should also use the URL of miniluv.gov.uk if they're already going all in.
An interesting viewpoint from the UK's privacy and data protection regulator:

https://www.bbc.co.uk/news/technology-60072191

Stephen Bonner, the ICO's executive director for innovation and technology, said end-to-end encryption helped keep children safe online by not allowing "criminals and abusers to send them harmful content or access their pictures or location".

"The discussion on end-to-end encryption use is too unbalanced to make a wise and informed choice. There is too much focus on the costs without also weighing up the significant benefits," he said.

That means it's working. The more noise they make, the better. This technology should be ubiquitous.

The Streisand effect also means that lots of people will discover end to end encryption because of their attempt to discredit it.

Which could indicate the gov has already broken TLS's trusted model. It's known a CA was breached some years back by a state, why would it be so far fetched to say CA's haven't been required to hand over private keys and are prevented from speaking about it?

I would not be surprised in the slightest that the government has subpoenaed a UK based CA or has a UK controlled CA of their own.

Having access to end private keys or being able to sign your own valid cert from a well known entity in the trusted list, to just operating your own all means the user is (almost) none the wiser TLS communication is opened wide to a state actor.

I think this is mostly because Facebook is going to go E2E now. I can understand why Facebook wants to do this, as it's starting to get risky with stuff like Jan 6th and other violent political demonstrations in the US maybe starting to happen more. If they go E2E they don't have to deal with the risk of having to "pick a side".
Government power is inherently corrupt. Everyone wants their government to step in and implement their pet preference, and very few people are willing to say: the less a government does, the better.

Edit: apparently I'm blocked from replying below, so: Saying that people who disagree aren't knowledgeable is the biggest thing making politics so hateful today. Small government works great. The smaller the better. For me, that's no dumb abortion laws or carbon taxes.

> apparently I'm blocked from replying below

There are some rules on replying, I think. Timing, maybe, whether you're replying to someone who replied to you, maybe. I haven't worked them all out. But I will say that if the reply link does not show below the post, clicking on the timestamp link will take you to the post by itself, and on that page there will be a reply link. At least, every time I've needed to use it myself for that reason.

> and very few people are willing to say: the less a government does, the better.

A lot of people are saying that, and in most cases just out themselves as loud and not very knowledgeable people.

Governments exist for a bunch of reasons. Many things are only possible or can only work well if done centrally and without a profit motive (like most things infrastructure and utility, healthcare to name a few). Yes, people want their governments to do things said people want. What's the problem that? If i want more bike lanes in my city, you can bet your ass I'll petition and lobby the mayor for that. Who else could do it? A benevolent rich person? As if.

Same goes for many many many other things. Banning single use plastics? Carbon tax? Giving incentives so that energy generation and transportation switch to less carbon intensive ( nuclear, renewables, EVs, rail electrification) energy? Creating good public transit so that less people need polluting and space wasting vehicles? Etc etc etc.

The US libertarian "small government" dream simply doesn't work. And the best part is that state governments that ostensibly follow that dogma are still able to force their nonsense pet preferences ( like abortions in Texas) or ask for federal help when disaster strikes ( the recent Kentucky natural disasters). Off the top of my head i can't think of other places in developed countries that went so far on the "the less a government does, the better" thing, that's why I'm only giving them as examples.

Of course the only argument they could come up with is "think of the children". Never mind that the UK has a huge problem with child abuse being swept under the rug. All in all I don't think people will be falling for it; in the end the fact that decided to produce propaganda against it means that E2EE is working.
It's either child abuse, organized crime or terrorism.
How does this compare to postal secrecy laws? Post has a special place in law, right? Opening someone's post without a warrant is potentially a serious crime, right?

I'd be happy with something equivalent for encryption: private and protected by default, court warrant can force user to disclose. If it's gone, well...

Clearly, this isn't what's proposed here.

To be fair, 500k is basically nothing
Can I have it please? I feel like I could put it to good use
If anything, it’s a cheap distraction from lockdown Christmas parties.
If we're being fair, it's 500k too much.
Judging by this video, you would think so.
just enough to trigger a Streisand effect?
> Your mobile banking app uses E2EE;

I highly doubt it. Unless the other "end" is the bank in which case this is just transport encryption.

> online chats with HMRC are protected through E2EE

Are they? Why is the other end in this context.

Sounds like ybe author doesn't even know what E2EE is.

Naw mate, you're the one that's mistaken.

Or name me a single one that doesn't use at least https.

With chat apps it's a different story, because the end isn't the server in that case - but in the context of banking https is enough for e2ee

The government is scared of encryption being used against them, but I think we should also be just as scared of companies using encryption against us. Sadly, there doesn't seem to be much of a PR campaign against that.
Disgusting
No place to hide? Could mean the same for the victims of child abuse.
> Your mobile banking app uses E2EE; online chats with HMRC are protected through E2EE; you'd no more have an unsecured web chat with the taxman's helpdesk than read out your P60 in the middle of a shopping centre.

The Register is only showing an example of #3, but leaves #1 and #2 unaddressed:

1. Your Identity (who everyone is)

2. Your Conversations (with whom, when)

3. Your Content (what was said)

Does the UK government have the ability to identify #1 and #2 for E2EE connections, and they desire #3 (content)?

Is the UK government only able to identify #2, and they desire #1 (identities) and #3 (content)? If so, which is more important to them: Identity, or Content?

I suspect they are much more desperate for Identity and Connections, than they necessarily are for Content, and that their attempt to overreach and backdoor all encryption could be shutdown by offering them #1 and #2 but not #3.

This is obviously unpalatable to consider to "perfect anonymity is the only way" adherents, but it's probably time to consider discussing it, when the alternative is a government backdooring or banning all encryption. It's too bad The Register didn't take that chance, but we could at any time.

> when the alternative is a government backdooring or banning all encryption.

That is not the alternative because the mathematics of encryption is already very widely known. In the scenario where all encryption is outlawed, there will be a black market for encryption tools designed for criminals (this already exists today) and society will not be significantly safer. Or alternatively, open source encryption software development will continue happen outside the UK/USA/AU.

Banning encryption will only make inept criminals (those who don't have the resources or aren't smart enough to buy the encryption tools) easier to catch and the general public unsafe. If the police are having trouble catching inept criminals to the point that they want to make the general public unsafe, the issue here isn't the encryption.

Are cases of child exploitation really prevented by the interception of unencrypted chat messages in practice? In the case where chat messages are used retrospectively in court, E2EE does not prevent that, provided that one of the parties did not erase their history.
My first thought was that this is using an emotional subject with a secret intent of a power grab. I could be wrong but I am curious about the actual numbers around CSAM on encrypted networks, and if there's other enforcement avenues.
This UK government is a bunch of maniacs. Too much alcohol got them on one.
They're really hellbent on destroying their financial sector at any cost.
They can spend as much as they want - we are still going to build it
That’s peanuts in the marketing world.
Only £500k? Pikers! In the US the government would spend at least half a billion!
They've spent lots of money on an expensive PR firm from the old school, and what they came up with is "No Place To Hide".

This can be easily undone with the following meme...

1. Take whatever advert they create with the tag line "No Place To Hide".

2. Change the image to Ann Frank.

3. Profit.

* BONUS: Add the text "If you have nothing to hide, you have nothing to worry about".

The unfortunate truth about e2ee is that most people do not understand what it really means, and what real drawbacks it has, like difficulties in multidevice sync, establishing identify of a chat partner, etc.

Users expect e2ee to magically work just like non-encrypted service, but with encryption, pointing to other services that do that, not realising that it is a security theater more often than not.

I'll be the devil's advocate. I can see a need to encrypt privileged communications, like with your lawyer, your health care provider, etc, but chats, for example? Can someone please change my mind?

And by the way, I find arguments of the type "are you ok to have transparent walls at the bathrooom" quite unconvincing. Bathrooms are not protected with encryption, the analogy is very weak. Or, "If you have nothing to hide, can you share with me your bank account password"? Well, no, the communication with my bank is encrypted, and I seriously doubt the Government wants me to put it out in the clear (oh, and also, banks are so heavily regulated, e.g. Anti-Money-Laundering, that if the Government wants to find anything about anything, they probably already can, regardless of how encrypted your communication with the bank is).

I wish people would argue in good faith in these types of discussions about responsible use of encryption.

No one is arguing that we should remove E2EE between you and your bank. With cryptographic systems we can choose what parties can see the plain text. For different situations the people who should be able to decrypt and the requirements needed to be able to decrypt may be different. I feel like this is a challenging discussion to have because there's people on both sides who lack information / knowledge leading them to make poor arguments.