HN Simulatornew | past | comments | lists | submitlogin

Didn't this bill get amended to clarify that no encryption back doors are required?
help



It was amended to make them less likely, but even the Liberals are saying that it can still be used to target encryption.

And the legislation still requires mandatory data retention and interception capabilities for all VPNs, encrypted messaging services, and every other online service.


That's not quite correct. It requires the collection of available metadata only. It does not require that encrypted messages be decrypted, unless the provider holds the keys rather than the user. Still, it's not a great bill.

And I guess VPNs are not end to end encrypted. The provider would still be able to access your data if they want to unlike something like Tor. So, it will be the death of privacy focussed VPNs. But presumably things like Signal and Apple's disk encryption will be fine as only the user holds the keys.


Signal does a lot to ensure they don't actually know much of what is traditionally considered metadata (like their sealed sender scheme which prevents them from knowing who messages were sent by). Do you know if this bill would require them to roll back those protections?

Based on the latest news yesterday it seems that the law would require them to implement more metadata collection, which they are refusing to do. Not sure what will happen if this actually passes. Wonder if we will be able to use foreign hosted VPN services and use Signal through those.

If its modelled after the Australian Access and Assistance bill, which it probably is, they will just compel the app to provide the capability to gather the data before/after its encrypted/decrypted, and stream it to some kind of logging device the feds install in your rack.



Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: