Funny how they’re trying so hard to catch pedos not won’t arrest a single motherfucker in the Epstein files
Jesus. I’m not in the EU, but how is this the first I’m hearing about this?
Time to go back to email and GnuPG.
Because they’re trying to suppress the public reaction.
You won’t hear about this on prime-time TV news, and it’s even censored on some more popular parts of the internet, like Reddit.
nah i just think that lots of people are tired of hearing about it. since it’s an issue year-over-year, they’re just waiting until we’re getting tired about it. then they’ll sneak it in.
It has been approved, it seems that democracy is dead in the EU.
They’ve waited for MPs to be on vacation too.
yeah i keep thinking, we’re not getting around the law. we have to get around an effective implementation though by using 3rd party platforms, i.e. ones that don’t conform to legal pressure. i keep thinking we need to inform people¹ about ways of secure communication in the absence of big-platform support. i.e. how do we send encrypted messages outside of facebook. we need matrix chat with end-to-end encryption that actually works, does not rely on a central “identity confirmation” service but works end-to-end. So instead of saying “i want to connect to bob@server2.net” and looking up the bob@server2.net public key somewhere, you should ideally get the bob@server2.net public key directly from the other user, if you have the chance to meet them irl. it’s the only way to actually secure end-to-end communication.
[1]: Note. This is very important. do NOT under no circumstances come up with the stupid ridiculous and outright dangerous notion that you’re gonna convince large masses of the population to care about their privacy. there needs to be a bit of elitism in this.
But the central service for those keys is only sharing the public key. Only the recipient can decrypt the message.
The only information it would give out is “this IP downloaded this public key”. Which can easily be covered up with multiple downloads from different IPs. You really only need to do this once per recipient too, once you have the public key you can just always keep a copy.
Shit, if your already using GnuPG, encrypt a file that’s got all your friends public keys. When you need to send a message, decrypt your file and grab the key you need.
It’s true that the public keys aren’t sensitive and nothing is compromised (in fact, it’s recommended) if the public key is available from, say, a key server.
But MITM is always a concern. Public-key encryption is supposed to mitigate that by ensuring that any third-party listening in in the middle can only get the ciphertext and cannot derive the plaintext of the communication.
But, if a jurisdiction legally forces a rule like the “we get to snoop on everything” one in this law, it changes things. They could, for instance, force key servers to to only give out keys that are generated/controlled by the EU agency so that they can MITM to their heart’s content. My guess at Aniki’s thought process is that if there’s a central distributor of keys, that can be legally strong-armed into bad things, but the people you’ve talked directly to are a different matter. “Web of trust” as it were.
I do think there are probably better ways to deal with that than what Aniki’s getting at, though. If you have Alice’s public key, you can verify signatures she generated, and you can be sure (hand-waves, rubber-hoses, caveat emptor, blah blah blah) that if you have a valid signature signing Bob’s public key with Alice’s private key, Alice vouches for that specific public key being authentically Bob’s public key.
Now, if you only ever get public keys from a small set of (compromiseable) central key servers, then the very first public key you get could be compromised and any other signature generated from the associated private key could be forged by an adversarial party (like the EU.) And theoretically the EU could generate a whole counterfeit web of signatures. So there’s benefit to having at least some of the public keys you trust come directly from the one who generated the key through a known-secure channel.
Before this law goes into effect, (maybe) we can trust at least some of the signatures in public key servers and use those as a basis for secure communication from which we can create a pool of known-uncompromised (qualifier, caveat, tin hats, etc) public keys, and based on those (maybe) detect forgeries and such.
(Mind you, I don’t know the details of this law or whatever. It might be that the law as written will require, say, GnuPG to introduce backdoors. Not that I think they should, no matter what the law says, but it might be that the EU isn’t really likely to engage in quite the lever of subterfuge that I’ve outlined above. It might be more of a blatant “fuck you, we’re the government and you’re going to comply” approach than a sneaky-sneaky trick-everybody-into-thinking-they’ve-got-security-they-don’t approach.)
Yeah they could MITM to give false keys so they can decrypt before sending on again using the real key, but if that’s what they want to do then it would be much more effective at monitoring people who are actively engaging in protecting their communication do just do that quietly rather than this circus.
This is probably more a combination of boomer levels of technical understanding and incrementally shifting the norm away from any expectation of privacy.
If I ever, ever somehow end up living in a world where it’s not possible to communicate with someone digitally and be completely encrypted, if we get to a point where you MUST put your ID into signal and have the government scan all signal messages, I’ll probably just kill myself.
And take a few politicians with me at the very least.
Oh, come on.
You can still DIY shit like Meshtastic
Been building out a mesh network bit by bit locally. Its pretty cool.
My guy building own ice, to be ready for 2077
… where it’s not possible to communicate with someone digitally…
I’d be thrilled to go back to that, if what we’re getting now instead is the only other option. But, I grew up in the before-times, so I’m not so put off by the idea.
You’re still getting surveilled in real-life conversations … if anyone in the conversation is stupid enough to bring their phone or other ‘smart’ device (including any modern car).
better idea: communicate irl. and also we need proper end-to-end encrypted chats that exchange public keys from device to device directly (NFC or QR code) (which requires physical meeting).
I don’t know a single person in real life that can maintain a conversation about this. And I keep looking.
You cannot ban cryptography, so the messenger is not the problem. You can control computing hardware tho…
Check out Briar and Meshtastic
Great, teach mesh computing to an elderly relative 10k miles away that can’t even log onto a banking website
I don’t know why you’re being hostile. Options are good, I didn’t ever say that it would fit every scenario.
You could always get really into steganography
deleted by creator
I hope you live in DC. Or Florida.
I say, “Arm up and kill authoritarians.” Likelihood is that you’ll also kill lots of pedos at the same time.
Sure would be nice if we could reform economically instead. Not that I feel bad for the pedos or the tyrants, but a lot of other people will have a very bad time if shit really hits the fan without some sort of economic plan in place.
Shit is going to hit the fan. This is all unsustainable.
the brainwashing of the last 20 years has been incredibly effective at distracting people from everything important. people didn’t talk about the economic situation because all the (looks around) instagram and distraction schemes.
Well, it is quite discouraging, yes. But on the bright side, we still have time to build the systems we need to survive the hardships that are coming. Let me know if you are interested in hearing about my efforts.
I will never not be the guy in the bottom-right corner
It’s already done Sir. Our private data is again being scanned by US corporations to protect our children.
* to better optimize ads, and to sell AI surveillance to crackpot dictators.
Hey sudden increase of insurance price is just algorithm not that we sold your hashed house photos to the insurance company. There is no shazam for photos right ?
It’s being scanned by everyone and everything that has access to scan it. Probably your own government too, even if you have laws supposedly prohibiting that.
How can they stop me from just doing this: U2FsdGVkX19+NGkQMc6FHt46SCVJ0SWyaPd8zo6lqiZ3V0H+IbR/EKhIt9B+o8Bu
Inform me pls
Some keyboards (e.g. KryptEY) allow you to exchange keys for E2E encryption with your companion and exchange messages encrypted.
How can they stop people from just sending encrypted messages?
“Punish one, educate hundreds” (Mao i guess?)
Throw the book against a couple of cases where encrypted messaging is involved and tell the public “We don’t know what they wrote… COULD BE $DISGUSTING_CONTENT…”
*fucking. You can type fucking on the internet. Don’t worry, we won’t tell your mommy.
You also don’t have to either? Weird thing to be triggered about.
How are you defining “triggered”? I keep seeing it used this way, and it makes no sense.
Time has come for moving towards !anarchism@lemmy.dbzer0.com Politicians be Politicing too much with themselves in mind.
here we go once again to being fucking embarrassed to be European.
the first try of this made me stop voting altogether because all the fucking parties on my country were a YES. Fuck politicians, hope they all get killed.
Where will we run when the whole world burns?
under the ocean maybe? return to the sea. the whales did it
We won’t we will block the air intake and exhaust and entrances and exits in these billionaire bunkers and rebuild the world as stewards of the earth. To do this we will have to identify and diagnose narcissism and psychopathy to treat it as a disease rather than reward it.
if they really wanted to catch pedophiles they’d be in D.C. right now
genuine question, im not in the EU, how would this affect self hosted/federated E2EE chat services like Matrix and XMPP?
In the US, gun owners like to joke about how great those blue helmets are as targets.
There are many alternatives to the world wide web. Familiarize yourself.
How is your comment relevant to Chat Control?













