Last rites for the UK's Online Safety Bill, an idea too stupid to notice it's dead
- Reference: 1692606669
- News link: https://www.theregister.co.uk/2023/08/21/opinion_column_monday/
- Source link:
Veilid would seem to be one such place. The open source project has [1]recently announced a secure communications framework, designed for decentralized peer-to-peer use through a multi-hop mesh routing system that combines strong encryption with untraceability. In particular, it is designed to be included in any app that wants to have impervious comms without central servers or third-party visibility. This is new, at least as far as its functionality is not tied to narrow use cases, and important. You never, ever want to roll your own networks, cryptographic systems or security management: now you don't have to.
The irony comes from Veilid's origins, the legendary [2]Cult of the Dead Cow hacker collective. Like Tor before it, where the US Navy intelligence agency gave us an intelligence agency resistant network, Veilid isn't so much poacher turned gamekeeper as the creation of a mirror world. Information may want to be free, but it also wants to be free from interlopers and snoopers. If Veilid achieves its aims of a massive global network of mesh nodes, it will gain that freedom by becoming far too expensive to break.
[3]
This is particularly timely, as it is not just another nail in the coffin of state efforts to defeat personal secure encryption by diktat, but a permanent mausoleum as monumental as the Pyramids of Giza.
Backdoor backwardness
The official madness over data security is particularly bad in the UK. The British state is a world class incompetent at protecting its own data. In the past couple of weeks alone, we have seen the [4]hacking of the Electoral Commission , the state body in charge of elections, the [5]mass exposure of birth, marriage and death data, and the bulk release of confidential personnel information of a number of police forces, most notably [6]the Police Service Northern Ireland . This was immediately picked up by [7]terrorists who like killing police. It doesn't get worse than that.
[8]Veilid: A secure peer-to-peer network for apps that flips off the surveillance economy
[9]OpenZFS 2.2 is nearly here, and ZFSBootMenu 2.2 already is
[10]FYI: Tor Browser is very much still a thing and getting updates
[11]China labels USA 'Empire of hacking' based on old Wikileaks dumps
This same state is, of course, the one demanding that to "protect children," it should get access to whatever encrypted citizen communication it likes via the Online Safety Bill, which is now rumored to be going through British Parliament in October. This is akin to giving an alcoholic uncle the keys to every booze shop in town to "protect children": you will find Uncle in a drunken coma with the doors wide open and the stock disappearing by the vanload.
That assumes the best case scenario, where the deliberately weakened encryption needed for state access somehow resists attack by others. In practice, as those who [12]actually understand encryption have said at endless length, it is impossible to guarantee or even expect this. Companies which don't deliberately compromise user security will be fined – hence Signal, WhatsApp and others have said they'd leave the UK rather than comply. In practice, this will mean geo-locking their apps in the App Store and Google Play to prevent installation to UK devices, a move that will hurt ordinary people but which is absolutely no barrier to anyone with motivation. Like criminals.
[13]
[14]
It is just stupidity stacked on incompetence balanced on political Dunning Krugerism, and the advent of Veilid drowns the lot in a tidal wave of foetid futility. What can a government do about a framework? What can it do about open source? The idea behind Veilid is to add end-to-end, peer-to-peer encrypted functionality to any app that can use it, which by itself is a force multiplier for privacy. The intent is for developers to integrate the framework as any other, as a seamless part of their products. As it stands, if the Online Safety Bill becomes law, then developers who do this will be excluded from UK commercial activity.
Software doesn't have to work like that, as users of open source audio and video tools already know. Codecs can come encumbered with patent and licence fees that exclude them from shipping with FOSS products. Make them external, optional libraries, and the FOSS product can ship and user install the libraries themselves. Those libraries aren't functional products until that point, which makes them trickier to attack legally.
Smack 'em in the supply chain
It is entirely possible to see not just Veilid but other end-to-end encryption systems taking this approach, a UK-only product that complies with the Snooper's Charter but which has the potential to pick up protection from another block of software, which doesn't itself need the ability to communicate with anything. It's not ideal, and opens up the potential for supply chain attacks and user confusion, but these are fixable with a bit of thought and care. Unlike the state strategy which promoted this little bit of evolution.
The only way to outlaw encryption is to outlaw encryption. Anything less will fail, as it is always possible in software to create kits of parts, all legal by themselves, that can be linked together to provide encryption with no single entity to legislate against. Our industry is fully aware of this. Criminals know it too. Ordinary people will learn it as well, if they have to. This information is free to everyone – except the politicians, it seems. For them, reality is far too expensive. ®
Get our [15]Tech Resources
[1] https://www.theregister.com/2023/08/12/veilid_privacy_data/
[2] https://www.theregister.com/2008/01/25/ddos_scientology_controversy/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZOM1wjrihatoY9uoqYVRCgAAAtM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2023/08/11/electoral_commission_vulnerability/
[5] https://www.bbc.co.uk/news/uk-scotland-66523032
[6] https://www.theregister.com/2023/08/17/man_arrested_in_ni_police/
[7] https://www.ft.com/content/7b29e72c-bcba-44a5-abb0-c9a57d35cb9c
[8] https://www.theregister.com/2023/08/12/veilid_privacy_data/
[9] https://www.theregister.com/2023/08/16/openzfs_zfsbootmenu_2_2/
[10] https://www.theregister.com/2023/06/25/tor_browser_update_improves_interface/
[11] https://www.theregister.com/2023/05/05/china_labels_us_hacking_empire/
[12] https://www.theregister.com/2023/06/29/apple_online_safety_bill_opposition/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZOM1wjrihatoY9uoqYVRCgAAAtM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZOM1wjrihatoY9uoqYVRCgAAAtM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Good encryption by default
"if you've nothing to hide, you've nothing to worry about" is unfortuntely untrue, people with something to hide will automatically seek out strong encrytion methods.
The rest of us will put in the minumum effort we think necessary and usually (myself included) that's not enough and we should be worried.
Any tools a government spy agency had a decade ago are probably available on the free market or the black market for criminals to use.
We need to move to a world where it's easier to be secure than not, for the average user. To protect our bank accounts, our images (in a world of deep fakes) and identities.
Veilid sounds like a step in the right direction but it needs a push from above to require it in enough cases to make it easier to include than to leave out. Any data commissioners feeling inspired?
"Nothing to Hide, Nothing to Fear."
Wasn't that used as a Nazi catchphrase?
This is government.
Government "We will listen to science"
Science "Cannabis and LSD have proven positive health benefits and them being illegal is a stupid idea, the same for many recreational drugs"
Government "We listen to scientists, except those that upset the Daily Mail readers"
Re: This is government.
If they get legalised, they're going to be taxed.
Re: This is government.
And they're not already taxed by the people supplying them?
It's not clear the prices would change (competition, in a larger market, may even bring them down) - but the tax recipients would change.
Last Rites, unfortunately...
I believe the graveside service includes a reference to resurrection into life everlasting...
I don't think this simple minded nonsense can ever be finally put to rest. Much like the equally unwelcome vampire.
The wide availability of cryptography based tools which could easily circumvent any legislative requirement means even your average criminal, kiddie fiddler or terrorist will disappear off the radar pretty quickly.
Seems that the headline "too stupid to notice it's dead" could equally apply to the current UK govt which clearly is deceased, too unresponsive to even aspire to be a zombie and on the nose to the extent that its rotting carcass should have been interred months ago. A resting Norwegian Blue would show more initiative.
Not holding my breath
Our government has never been known to limit it's stupidity. I wouldn't put it past them to decide computers needed regular 'M.O.Ts' where they were tested for only having {cough} healthy {cough} software. Oh, and the ISPs would be dumped with the task of ensuring that.