Posted by Cider9986 1 day ago
https://community.qbix.com/t/the-global-war-on-end-to-end-en...
And by the way, this article mentions other things already in place, such as being able to commandeer your device and spy on it without breaking encryption:
https://community.qbix.com/t/increasing-state-of-surveillanc...
So a person in Canada messages someone in France who's WhatsApp is not encrypted. But the message from Canada is encrypted. Will the person in Canada's message have to be sent unencrypted ? Or will WhatsApp Canada need to allow France to break Canada's encryption ?
Personally I think it would be easier for these apps to ban people in France from using their service.
> "Perrin now offers a different framing. “Article 8 ter, which I had adopted, was not at all aimed at obtaining encryption keys but at introducing a ghost participant into a conversation before encryption,” he says. The “ghost participant” approach, sometimes called a ghost user proposal, was floated by GCHQ in 2018 and rejected by every major privacy organization, civil liberties group, and security researcher who looked at it. The idea is that the platform silently adds a third recipient, an invisible intelligence agent, to a supposedly two-person conversation. Users never see them. The encryption technically still works, except that one of the parties is the state."
It's an innovative idea. What defenses against this attack are in WhatsApp, Signal, etc. right now?
(In any situation, attackers can attack endpoints: If they can see what the user sees, apps and encryption don't matter. They could attack remotely, or in the case of higher-interest targets, physically.)
First, does the service mediate the group chat? If the messaging is peer-to-peer [0] with no server mediating, then someone would of course need to attack a peer as described above. I know Signal supposedly has no metadata, including chat participants; I don't know what mediation they do.
If the service does mediate the chat somehow, then an attacker could theoretically add themselves to the group. Hiding - the 'ghost' part - from the rest of the group seems trickier, but maybe that's also possible server-side.
[0] 5 users doing a mesh of multicast peer-to-peer video sounds like a utilization and quality nightmare.
Governments act as kings.
We're into way many links already.
Isn't this the country that beheaded their rulers?
BTW France already have
- https://gizmodo.com/france-bill-allows-police-access-phones-...
- https://www.medias-presse.info/une-nouvelle-loi-de-programma... can't find one in English
Plus
- https://fr.wikipedia.org/wiki/Loi_renfor%C3%A7ant_la_s%C3%A9...
- https://fr.wikipedia.org/wiki/Projet_de_loi_visant_%C3%A0_s%...
- https://fr.wikipedia.org/wiki/Loi_tendant_%C3%A0_renforcer_l...
Essentially China is already here.