HN user

dane-pgp

8,830 karma
Posts123
Comments3,670
View on HN
cyberlaw.stanford.edu 3y ago

Comment on the UK Gov Proposal to Ban “Bespoke” “Sophisticated” Encrypted Phones

dane-pgp
39pts28
techmonitor.ai 3y ago

Apple must comply with UK end-to-end encryption rules

dane-pgp
4pts3
www.lesswrong.com 3y ago

What's the Least Impressive Thing GPT-4 Won't Be Able to Do

dane-pgp
18pts21
webdevlaw.uk 3y ago

A hypothetical situation, or, your crash introduction to the Online Safety Bill

dane-pgp
2pts1
www.vox.com 3y ago

The plan to save America by killing the partisan primary

dane-pgp
49pts53
www.bbc.co.uk 3y ago

Tory leadership: How secure is the online vote?

dane-pgp
1pts2
blog.dock.io 3y ago

Dock Joins the Decentralized Identity Foundation

dane-pgp
2pts1
www.theguardian.com 3y ago

Covid laws took away our rights with flick of a pen. Don’t let that happen again

dane-pgp
7pts4
www.chicagotribune.com 3y ago

We don’t need a third party. We need ranked choice voting

dane-pgp
93pts47
cryptoslate.com 3y ago

Bellatrix upgrade goes live, sets stage for Ethereum’s Merge

dane-pgp
3pts0
www.independent.co.uk 3y ago

Ethereum Merge: ‘Most important moment in crypto history’ begins

dane-pgp
5pts1
www.reuters.com 3y ago

WhatsApp bans 2.4M Indian accounts in July – monthly report

dane-pgp
3pts1
blog.ericgoldman.org 3y ago

Will California Eliminate Anonymous Web Browsing? (Comments on CA AB 2273)

dane-pgp
191pts281
www.theverge.com 3y ago

California passes sweeping online safety rules for kids

dane-pgp
3pts1
www.politico.com 3y ago

When an election denier becomes an election chief

dane-pgp
3pts1
www.politico.eu 3y ago

Norway wants Facebook fined for illegal data transfers

dane-pgp
2pts1
blog.identity.foundation 3y ago

DIDComm v2 reaches approved spec status

dane-pgp
1pts1
www.theregister.com 3y ago

WhatsApp boss says no to AI filters policing encrypted chat

dane-pgp
21pts5
www.sciencedirect.com 3y ago

US nuclear power: Status, prospects, and climate implications

dane-pgp
2pts0
www.computerweekly.com 3y ago

Home Office ‘unlawfully’ approved MI5 bulk surveillance warrants

dane-pgp
18pts4
www.bloomberglinea.com 3y ago

The global housing market is broken, and it’s dividing entire countries

dane-pgp
145pts360
www.sbs.com.au 4y ago

Mexican president's plea to Biden over Julian Assange as he renews asylum offer

dane-pgp
7pts1
decrypt.co 4y ago

Ethereum Devs Pencil in September Date for Merge

dane-pgp
8pts5
www.lesswrong.com 4y ago

Safety Implications of LeCun's path to machine intelligence

dane-pgp
3pts1
cryptobriefing.com 4y ago

Ethereum Inches Closer to the Merge with Sepolia Testnet Launch

dane-pgp
2pts1
singularityhub.com 4y ago

OpenAI’s New AI Learned to Play Minecraft by Watching 70k Hours of YouTube

dane-pgp
3pts1
www.extremetech.com 4y ago

China Accused of Weaponizing Its Covid Tracker to Stifle Dissent

dane-pgp
11pts1
www.libertyhumanrights.org.uk 4y ago

Liberty wins landmark Snoopers’ Charter case

dane-pgp
46pts7
www.thetelegraphandargus.co.uk 4y ago

Website cookie pop-ups to appear less in new UK Government proposals

dane-pgp
12pts32
energycentral.com 4y ago

Top energy producer Australia braces for blackouts

dane-pgp
1pts1

age verification for the users.

Do you need to verify your age to perform a Google search?

I think "age verification" is just another "think of the children" ploy to force all websites to check their users' government IDs (starting with sites run by people whose politics are different from those of the government that's enacting the ploy).

children can not enter a library and get Adult books

Is that true? Can a 13 year old child in Italy not walk into their local town library and pick a novel off the shelf and start reading all sorts of violent and explicit narratives? Not to mention all the medical textbooks, and books containing images of artistic works depicting undressed humans.

Self-Service SBOMs 3 years ago

I'm glad you agree that knowing someone's name, age, and address doesn't prove their trustworthiness, because I don't want trust decisions to be dependent on threats of state-backed violence or mob vigilantism.

It is possible to build up trust in an identity based on how long that identity has been used, and the "transitivity of trust" principle. So you wouldn't trust someone because "John sounds like a trustworthy name", and instead you'd look at how long the author's key had been associated with the library, and whether their key had previously been endorsed on other people's projects (for example having their PRs reviewed and accepted).

Admittedly this introduces a new danger that the social graphs start to become very dangerous honeypots of metadata, especially if we start letting employers vouch for their employees, but the ultimate goal here should be to use something like Verifiable Credentials with zero knowledge proofs, which will allow very strong probabilistic arguments to be made about whether an author (and all the code reviewers) have suddenly gone rogue and decided to burn their hard-earned reputations.

Self-Service SBOMs 3 years ago

The first step in solving the trust problem is solving the identity problem. At the very least, once you've got cryptographic identities for entities involved in your supply chain, you can use a TOFU policy and check whenever an identity changes.

Simple operations like rotating a key shouldn't trigger any security warnings, as long as they new key is signed by the old one, and even adding new people to a team should happen seamlessly if (a majority of) the existing team members approve that new identity being added.

Of course it doesn't solve key compromise, or someone selling their keys to someone else, but with long-lived (even pseudonymous) identities, it becomes possible to reason about the trust level of packages just based on how long an identity has been used without being compromised.

No system is perfect, and there's still a long way to go, but the existing systems make the remaining problems more tractable, and already increase the cost for attackers, which should reduce attacks.

Sure and they'll be quickly mistrusted. You can't really revoke DNNSEC trust of an ccTLD operator.

But you don't have to, because the blast radius is so much smaller, and the incentives are aligned better. The reason why CAs require such extreme punishment for misbehaviour is that one bad CA can break the trust for every site on the web.

If a country decided to invalidate the security of (predominantly) its own citizens' websites then that wouldn't harm anyone who used any of the other ccTLDs in the world (not to mention the hundreds of gTLDs).

Also, I think you are over-estimating the ease with which a CA can be "quickly mistrusted". What is the record for how quickly a CA has been taken out of browsers' certificate stores, measured from the time of their first misissuance?

And I would argue that revoking CA trust to Let's Encrypt / IdenTrust would be much more disruptive than revoking a single ccTLD operator, since that would mean breaking most sites on the web. So DNSSEC is actually better in terms of the "too big to fail" problem.

This is bypassing a dangerous design, at best.

But that's my point; DNSSEC lets you bypass the danger of a rogue issuer, by swapping to an alternate domain in the worst case, whereas with CAs you have to hope that the rogue issuer doesn't decide to target you, and wait for the bureaucratic and software update processes to remove that CA from all your users' browsers.

There are definitely limitations to the DNSSEC system as currently deployed, just as there were with the web PKI system before browsers started to patch all the holes in that, but I don't know why my position on this technical question is so controversial. Nevertheless, I really appreciate you taking the time to offer intelligent counter-arguments in your comment, thank you.

DNSSEC, ... still does not work in most TLD and registers.

I'd be interested to know where you get your data from. By my count, there are 142 ccTLDs that support it and 106 that don't, out of 248 ccTLDs.[0]

That's already more than half, but if you include the gTLDs then the number of TLDs signed in the DNS root goes up to 92% according to the best data I can find.[1]

[0] https://www.statdns.com/cctlds/

[1] http://rick.eng.br/dnssecstat/

Trusting the country that operates the ccTLD of your website is a much better situation than having to trust all the countries that have CAs operate in them.

A malicious CA in one country can issue a fraudulent certificate for a site in another country, whereas the people operating .ru can't affect the records for example.us so the blast radius is limited by design.

Moreover, no one is required to use a ccTLD, and there are hundreds of gTLDs to choose from, or you could even run one yourself if necessary.

Do you think that the state shouldn't be allowed to kill unwanted Down syndrome babies after they are born because "that's eugenics"?

What about Down syndrome adults, who are reliant on state benefits?

In case it's not clear, I don't support the killing of disabled people at any age, but I understand that different people approach these questions from a different set of assumptions.

My point is that adding scare quotes around "that's eugenics" doesn't stop it from being an accurate description, so your question is not the gotcha you might think it is.

Are they going to outlaw electronics knowledge?

No, but they might ban "bespoke" devices.[0] Maybe you're smart and brave enough to build and maintain your own illegal device, but good luck trying to persuade other people to do the same so that you can communicate with them securely online. Also, the government might force ISPs to block access to devices that don't pass remote attestation checks.

[0] https://cyberlaw.stanford.edu/blog/2023/02/my-comment-uk-gov...

The reason why DRM has failed in the past is that it only takes one person to crack the DRM on their own device, and then they have an unencumbered digital file which can be copied and distributed freely.

Applying DRM to kernels and applications rather than to media files is completely different. If someone wants to have an E2E encrypted conversation, not only do they have to have jailbroken their own device by extracting the secret keys from inside its processor (using an electron microscope, perhaps) but their conversation partner has to have done the same to their own device.

Even if a few brave and well-resourced journalists/lawyers/activists managed to do this among themselves, they would quickly be exposed by traffic analysis, allowing the government to simultaneously arrest all of them and use their devices as evidence.

Even with attestation you could just daisy chain and use the attesting device as a proxy.

But you'd need the attested device to run the proxy server software, which would obviously not be allowed in the app store, and would be blocked by the gatekeeper daemon or the OS-level firewall. Well, proxy software would be allowed, but it would have to perform its own attestation checks on the devices it proxies for.

Not to mentioned the billion of internet enabled devices that would never support it

The billion internet enabled devices would be allowed onto a special "safe" segment of the internet, which companies could apply to add their static IPs to. So your internet connected fridge could still phone home, but the manufacturer would take liability for any data that a rooted fridge managed to send out to the internet.

There might still be millions of old devices that don't support TPMs and don't have manufacturers willing to apply to have their IPs whitelisted, but the government will say that kicking these insecure unpatched devices off their internet would be a huge win for cybersecurity. Making people buy a whole load of new devices would probably also give a temporary boost to the economy too.

The absolute size of the risk is what's relevant.

But you weren't talking about the absolute size, you said "a very small problem compared to things like" (my emphasis). Please at least admit you were wrong about that.

In any case, as an absolute number, even one school shooting is too many, and if the US government can devote resources and legislation to reducing traffic accidents and drug overdoses harming children, then there's no reason why it can't do the same to reduce gun deaths, like every other civilized country does.

Like everywhere in the United states, it's young Black men killing other young Black men

You may be surprised to learn[0] that "Black men and boys ages 15 to 34 ... were among 37% of gun homicides" in 2019, so most killings are not like what you describe at all.

[0] https://www.usatoday.com/story/news/health/2021/02/23/young-...

Thanks for the link. That does seem to be a more thorough analysis than the one in Scientific American, although the latter was good at linking through to the actual studies, so you didn't have to trust the writer or editor of the article.

The RAND analysis doesn't appear to be as equivocal as you suggest though. It says that there are 3 types of laws which have the strongest level of scientific support for their success, but other laws have weaker support, which doesn't mean they aren't effective. Let me highlight two quotes:

"Importantly, however, where we conclude that evidence for a policy is weak, that does not mean that the policy is ineffective; the policy itself might well be quite effective."

"Still, even relatively small effects of gun policies are important to the people and communities affected."

So while it's possible that there are a lot of ineffective laws being proposed, that's far from being evidence that no laws are effective, and it might even be evidence that the problem lies with the Constitution itself (which is another type of law which could be changed).

I wonder, though, what it would take for me to convince you of anything, since you could just dismiss all scientific research as "coming from academia" and therefore tainted by political views that you don't like. Perhaps if the gun lobby commissioned their own researchers to produce a report, you would find that sufficiently neutral, but I won't go looking for such a report.

One area where we might agree, though, is in disapproving of immature ad hominem arguments, so perhaps we just need to make sure that we're both extending that disapproval to mature ad hominem arguments as well. ;-)

Presumably mobile networks will be required to only grant internet service to phones that were bought in the UK (or that have been registered with a foreign network for more than N months).

I'm not sure how easy it is for networks to filter by IMEI (and presumably there would have to be a database for recording which IMEIs were sold with UK-compliant OSes) but eventually there would be a system which covered all access to the internet, not just from phones.

This means broadband ISPs doing a Remote Attestation check before routing any other packets from your device. A proof of concept for this has been implemented for some online games already.[0]

[0] https://arstechnica.com/gaming/2021/09/riot-games-anti-cheat...

There are some good arguments in here, but I think it misses the broader picture.

Clearly someone at GCHQ has told the UK government that if they want to ban secure apps like Signal, they first need to get the apps taken out of the app stores, then they need to mandate that phone OSes don't allow side-loading, then finally they need to ban "bespoke" phones, i.e. ones that allow general purpose computing.

Not only Stallman[0], but Doctorow[1] was right too.

After implementing this, they'll do the same for desktops, using something like Apple's Gatekeeper software[2]. Linux distros will gain support for this using "Secure Boot" and something like systemd-censord, which Microsoft might get Lennart to implement for them.

[0] https://www.gnu.org/philosophy/right-to-read.en.html

[1] https://boingboing.net/2012/01/10/lockdown.html

[2] https://support.apple.com/en-gb/guide/security/sec5599b66df/...

Shootings ... are a very small problem compared to things like ... car crashes, and tiktok.

That's an interesting claim. Perhaps you didn't know that "Firearms now exceed motor vehicle crashes as the leading cause of injury-related death for people ages one to 24" according to [1].

I suppose that statistic might include gun suicides and gun accidents, which (under an extremely contrived definition) don't count as "shootings", but that still misses the point that sensible governments have successfully reduced car accident deaths by tightening regulations related to vehicle ownership and licensing, whereas America is notably bad at doing so for guns, and is paying the price for that failure with the blood of its children.

If you could provide a statistic for the number of annual US deaths due to TikTok, I'd be interested to compare that to shooting deaths too.

[1] https://www.scientificamerican.com/article/guns-now-kill-mor...

Did you miss where I said "in undisclosed locations in different jurisdictions"?

The other seven people would be known only by their public key, and you'd make contact with them through some onion-routed service. You'd never see their face, and all you'd know is that they were based in a different jurisdiction, where presumably the authorities that are after you don't have strong judicial connections.

If your threat model includes an adversary that is willing and able to kidnap and torture 5 innocent people from different countries around the world in order to get to you, then you're literally OBL or the leader of IS, in which case you have bigger problems than securing your passwords.

The best way to get someone's password isn't phishing, it's threatening to hit them in the head with a wrench.

But what if you need to combine that person's password with passwords that are in the heads of 5 out of 7 other people, who are all in undisclosed locations in different jurisdictions?

Perhaps a sufficiently resourced adversary could create a realtime deepfake of you, to attend the property transfer online digital ceremony, but the adversary who imprisoned you would also have to convince all of your friends that you had gone on holiday so that they didn't raise the alarm to warn those keyholders that you are under duress.