News: 1692606669

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Last rites for the UK's Online Safety Bill, an idea too stupid to notice it's dead

(2023/08/21)


Opinion Information wants to be free. This usefully ambiguous battle cry has been the mischievous slogan of hackers since early networking thinker Stuart Brand coined it in the early 1980s. Intended as part of a discussion about the inherent contradictions of intellectual property, it has bestowed irony in many other places since.

Veilid would seem to be one such place. The open source project has [1]recently announced a secure communications framework, designed for decentralized peer-to-peer use through a multi-hop mesh routing system that combines strong encryption with untraceability. In particular, it is designed to be included in any app that wants to have impervious comms without central servers or third-party visibility. This is new, at least as far as its functionality is not tied to narrow use cases, and important. You never, ever want to roll your own networks, cryptographic systems or security management: now you don't have to.

The irony comes from Veilid's origins, the legendary [2]Cult of the Dead Cow hacker collective. Like Tor before it, where the US Navy intelligence agency gave us an intelligence agency resistant network, Veilid isn't so much poacher turned gamekeeper as the creation of a mirror world. Information may want to be free, but it also wants to be free from interlopers and snoopers. If Veilid achieves its aims of a massive global network of mesh nodes, it will gain that freedom by becoming far too expensive to break.

[3]

This is particularly timely, as it is not just another nail in the coffin of state efforts to defeat personal secure encryption by diktat, but a permanent mausoleum as monumental as the Pyramids of Giza.

Backdoor backwardness

The official madness over data security is particularly bad in the UK. The British state is a world class incompetent at protecting its own data. In the past couple of weeks alone, we have seen the [4]hacking of the Electoral Commission , the state body in charge of elections, the [5]mass exposure of birth, marriage and death data, and the bulk release of confidential personnel information of a number of police forces, most notably [6]the Police Service Northern Ireland . This was immediately picked up by [7]terrorists who like killing police. It doesn't get worse than that.

[8]Veilid: A secure peer-to-peer network for apps that flips off the surveillance economy

[9]OpenZFS 2.2 is nearly here, and ZFSBootMenu 2.2 already is

[10]FYI: Tor Browser is very much still a thing and getting updates

[11]China labels USA 'Empire of hacking' based on old Wikileaks dumps

This same state is, of course, the one demanding that to "protect children," it should get access to whatever encrypted citizen communication it likes via the Online Safety Bill, which is now rumored to be going through British Parliament in October. This is akin to giving an alcoholic uncle the keys to every booze shop in town to "protect children": you will find Uncle in a drunken coma with the doors wide open and the stock disappearing by the vanload.

That assumes the best case scenario, where the deliberately weakened encryption needed for state access somehow resists attack by others. In practice, as those who [12]actually understand encryption have said at endless length, it is impossible to guarantee or even expect this. Companies which don't deliberately compromise user security will be fined – hence Signal, WhatsApp and others have said they'd leave the UK rather than comply. In practice, this will mean geo-locking their apps in the App Store and Google Play to prevent installation to UK devices, a move that will hurt ordinary people but which is absolutely no barrier to anyone with motivation. Like criminals.

[13]

[14]

It is just stupidity stacked on incompetence balanced on political Dunning Krugerism, and the advent of Veilid drowns the lot in a tidal wave of foetid futility. What can a government do about a framework? What can it do about open source? The idea behind Veilid is to add end-to-end, peer-to-peer encrypted functionality to any app that can use it, which by itself is a force multiplier for privacy. The intent is for developers to integrate the framework as any other, as a seamless part of their products. As it stands, if the Online Safety Bill becomes law, then developers who do this will be excluded from UK commercial activity.

Software doesn't have to work like that, as users of open source audio and video tools already know. Codecs can come encumbered with patent and licence fees that exclude them from shipping with FOSS products. Make them external, optional libraries, and the FOSS product can ship and user install the libraries themselves. Those libraries aren't functional products until that point, which makes them trickier to attack legally.

Smack 'em in the supply chain

It is entirely possible to see not just Veilid but other end-to-end encryption systems taking this approach, a UK-only product that complies with the Snooper's Charter but which has the potential to pick up protection from another block of software, which doesn't itself need the ability to communicate with anything. It's not ideal, and opens up the potential for supply chain attacks and user confusion, but these are fixable with a bit of thought and care. Unlike the state strategy which promoted this little bit of evolution.

The only way to outlaw encryption is to outlaw encryption. Anything less will fail, as it is always possible in software to create kits of parts, all legal by themselves, that can be linked together to provide encryption with no single entity to legislate against. Our industry is fully aware of this. Criminals know it too. Ordinary people will learn it as well, if they have to. This information is free to everyone – except the politicians, it seems. For them, reality is far too expensive. ®

Get our [15]Tech Resources



[1] https://www.theregister.com/2023/08/12/veilid_privacy_data/

[2] https://www.theregister.com/2008/01/25/ddos_scientology_controversy/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZOM1wjrihatoY9uoqYVRCgAAAtM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2023/08/11/electoral_commission_vulnerability/

[5] https://www.bbc.co.uk/news/uk-scotland-66523032

[6] https://www.theregister.com/2023/08/17/man_arrested_in_ni_police/

[7] https://www.ft.com/content/7b29e72c-bcba-44a5-abb0-c9a57d35cb9c

[8] https://www.theregister.com/2023/08/12/veilid_privacy_data/

[9] https://www.theregister.com/2023/08/16/openzfs_zfsbootmenu_2_2/

[10] https://www.theregister.com/2023/06/25/tor_browser_update_improves_interface/

[11] https://www.theregister.com/2023/05/05/china_labels_us_hacking_empire/

[12] https://www.theregister.com/2023/06/29/apple_online_safety_bill_opposition/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZOM1wjrihatoY9uoqYVRCgAAAtM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZOM1wjrihatoY9uoqYVRCgAAAtM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



Not holding my breath

Will Godfrey

Our government has never been known to limit it's stupidity. I wouldn't put it past them to decide computers needed regular 'M.O.Ts' where they were tested for only having {cough} healthy {cough} software. Oh, and the ISPs would be dumped with the task of ensuring that.

Good encryption by default

Ken G

"if you've nothing to hide, you've nothing to worry about" is unfortuntely untrue, people with something to hide will automatically seek out strong encrytion methods.

The rest of us will put in the minumum effort we think necessary and usually (myself included) that's not enough and we should be worried.

Any tools a government spy agency had a decade ago are probably available on the free market or the black market for criminals to use.

We need to move to a world where it's easier to be secure than not, for the average user. To protect our bank accounts, our images (in a world of deep fakes) and identities.

Veilid sounds like a step in the right direction but it needs a push from above to require it in enough cases to make it easier to include than to leave out. Any data commissioners feeling inspired?

"Nothing to Hide, Nothing to Fear."

Anonymous Coward

Wasn't that used as a Nazi catchphrase?

This is government.

IGotOut

Government "We will listen to science"

Science "Cannabis and LSD have proven positive health benefits and them being illegal is a stupid idea, the same for many recreational drugs"

Government "We listen to scientists, except those that upset the Daily Mail readers"

Re: This is government.

Anonymous Coward

If they get legalised, they're going to be taxed.

Re: This is government.

Graham Cobb

And they're not already taxed by the people supplying them?

It's not clear the prices would change (competition, in a larger market, may even bring them down) - but the tax recipients would change.

Last Rites, unfortunately...

Bebu

I believe the graveside service includes a reference to resurrection into life everlasting...

I don't think this simple minded nonsense can ever be finally put to rest. Much like the equally unwelcome vampire.

The wide availability of cryptography based tools which could easily circumvent any legislative requirement means even your average criminal, kiddie fiddler or terrorist will disappear off the radar pretty quickly.

Seems that the headline "too stupid to notice it's dead" could equally apply to the current UK govt which clearly is deceased, too unresponsive to even aspire to be a zombie and on the nose to the extent that its rotting carcass should have been interred months ago. A resting Norwegian Blue would show more initiative.

NOTICE

LinuxForecast.com has issued a Slashdot Effect Watch for your domain
effective for the next 48 hours. Forecast models indicate that Taco Boy is
planning on posting an article about your "Penguin Porn" site. The models
disagree on the timing or duration of the storm, although we can say that
a moderate risk of server crashes, excess bandwidth usage, and increased
website hosting bills are possible.

Please take appropriate action by mirroring your site. It might be too
late now, but you might also want to consider purchasing Denial Of Service
Insurance.