The UK government has admitted that the technology needed to securely scan encrypted messages sent on Signal and WhatsApp doesn’t exist, weakening its controversial Online Safety Bill.
So they've decided that this part of the bill will be unenforceable and useless, but they plan to go ahead and pass it anyway. I suppose they'll soon need to do the same for the age verification nonsense as well.
They still want to impose these ill-conceived laws on us so as to appear to have done something, but the people who had somehow been convinced that this would do some good will be disappointed. If they stick with this course, they will soon have managed the impressive political feat of pleasing exactly nobody with the results of this excruciating years-long process of counterproductive legislating.
There are plenty of laws out there that nobody cares about enough to try and enforce, but if you aggrevate the wrong people then suddenly you're found in technical violation of them and they have rational to toy with your life. This would be one of them I expect.
The whole premise is dumb like their war on drugs, porn and whatever else offends their Victorian-era sensibilities. You cannot stop encryption, the genie is out of the bottle since the advent of PGP. These Dunning-Kruger morons make me embarrassed to be British.
They'll just focus on baking obscure side channel attacks into firmware wherever they can. Consumer devices also leak a ton of EM energy, and there have been a bunch of "proof of concepts" at deriving device state remotely by observing such energy. I'd be pretty surprised if the right folks can't read private keys being loaded into cache under the right circumstances already.
In a way it's kind of a poetic compromise. They can't do mass surveillance like they want, but they can still "tap" devices via physical access, preferably with a healthy dose of due process.
Agree. If the state is determined to spy on something, no doubt they will find a way but legalising wholesale collection of data is not ethically sound. Governments want a way into every communication channel whenever they feel the need and Facebook, et al have been happy to sell out their users. Encryption provides the necessary and sufficient barrier to prevent this type of whimsical over-reach.
Absolutely agree. It's pandering to a small minority of pressure groups demanding to make the internet safe, without understanding the fundamental nature of what they're trying to do or the implications of doing so.
Absolute shower of cockwombles. We need to vote these arseholes out of danger.
This is a temporary reprieve rather than a victory. The wording of the bill hasn't changed, they've simply added the statement that what they want to do isn't technically possible yet but when it is, this'll be revived.
Not that it's possible but it would be awesome no? That somebody can just read my passwords, access my bank accounts, read my private messages... You trust the government with those keys, Right?