this post was submitted on 22 Nov 2023
35 points (90.7% liked)

Privacy

32173 readers
203 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Before I say anything else, I should mention that this is nothing ground-breaking, neither is it terribly difficult to implement. This is simply how I envision a simple solution.

Basically, the EU and the UK want the secret keys to your encrypted media/messages. Which essentially breaks encryption completely, ending E2EE usage.

The alternative is, then, for the user to utilise their own form of E2EE. How though? The answer, in my opinion, is personal exchange of keys utilising asymmetrical encryption. Exchanging public keys in plaintext is fine as long as they don't have your private key. Which means unencrypted services like SMS could also be secured using this method (for example, have the public key of a user in their profile). I believe QKSMS employed encryption for SMSes for as long as it lasted, but no idea about the kind of encryption).

Technically, if everyone started to use p2p messengers with asymmetrical encryption, the EU would have very little they could do without compromising every mobile in the region and preventing people from downloading APKs somehow (sorry iOS users but you're never going to have privacy anyway).

However, this is only possible with a FOSS project, because a company would have to fork over the keys anyway to stay alive. A FOSS project can simply be forked once the OG maintainer stops working on it due to government pressure. That is where the problem comes, since FOSS projects can't really run their own servers to store media, making p2p the only viable option. But with some people behind CG-NAT, that becomes harder for non-technical users.

I don't have a way to solve this other than the general population becoming tech-savvy enough to give a damn.

Tl:dr; FOSS projects are best suited for implementing personal E2EE between users, but that makes p2p the only viable option without a back-end, which makes it difficult for people behind CG-NAT.

Cheers

all 31 comments
sorted by: hot top controversial new old
[–] [email protected] 16 points 1 year ago (3 children)

I highly doubt that it'll ever happen, but if, I'll just host my own matrix server and I'm good to go.

[–] MigratingtoLemmy 5 points 1 year ago

Whatever works really. I don't care which app/system does it as long as the government doesn't have private key

[–] [email protected] 4 points 1 year ago* (last edited 1 year ago) (1 children)
[–] [email protected] 8 points 1 year ago

*In case the EU manages to force all providers to backdoor the services

I don't think that'll happen anyway. But you are right, the server doesn't matter too much in the csse of e2e. The client is more important.

[–] [email protected] 4 points 1 year ago* (last edited 1 year ago) (1 children)

[This comment has been deleted by an automated system]

[–] JubilantJaguar 3 points 1 year ago

And of course this sort of thing happens every day in authoritarian countries.

This is not a technical problem at all, it's a political and cultural one.

[–] [email protected] 6 points 1 year ago (1 children)

sorry iOS users

EU is forcing apple to allow sideloading. not sure when the deadline was, i think next year?

[–] MigratingtoLemmy 2 points 1 year ago

Wow, that's amazing!

[–] [email protected] 6 points 1 year ago (1 children)

Sounds like what you're looking for is PGP/GPG. Been around for a while, but does the job well.

Also, I doubt most projects built outside of the UK (or Europe as the EU seems to be moving in a similar direction) will actually comply and backdoor their own software. As long as you have internet they'll always be actually secure software to download.

[–] MigratingtoLemmy 3 points 1 year ago (1 children)

Well, yes, GnuPG is certainly an option. I don't care how it's implemented though, but I do care about the fact that clients/client apps take encryption into their own hands instead of relying on middleware.

[–] [email protected] 1 points 1 year ago (1 children)

Clients taking it into their own hands reminds me of delta chat. Basically the same thing but the client handles encryption and uses a generic email server as the chat server.

But any good client will handle encryption themselves (heck even "bad" clients will do that). As long as they're not UK based and don't neuter the clients for their UK users they'll still retain proper encryption completely client side (outside of public key infrastructure which is a whole different topic).

[–] MigratingtoLemmy 1 points 1 year ago

From what I understand of PKI and the way the Internet is right now, trust in identity would be very hard to build if clients engage in PKI.

But taking encryption into one's hands basically brings back control into one's hands. You do not specifically need an encrypted connection in such a case, just a tamper-proof connection.

[–] woshang 4 points 1 year ago (1 children)

if everyone started to use p2p messengers with asymmetrical encryption, the EU would have very little they could do

Totally agree with you; a p2p network is resilient and unstoppable. Every user acts as a node within the p2p network, and as long as people are actively online, it can survive. This means it cannot be banned by any country or government.

Plus, since a P2P network is a decentralized network, there is no central server to store user data such as chat histories or contact lists**. From a data privacy perspective, nothing can compare with a p2p network.

I know people are quite familiar with Signal and Whatsapp due to their E2EE services. However, they are managed by tech companies and utilize a centralized network (central server = another computer). All your chat histories and data are kept in their giant computer/server. Even though it is encrypted, who in the world knows if they have memorized your private key (I think they do, by the way, because governments need these things to monitor suspicious activities or potential criminal incidents).

So, start using applications that operate on a decentralized P2P network; it is the safest way to safeguard your privacy rights.

[–] t4k3 3 points 1 year ago* (last edited 1 year ago) (2 children)

start using applications that operate on a decentralized P2P network;

Have you heard of this one? They said it's a secure messenger based on P2P network, also with end-to-end encryption technology.

[–] [email protected] 3 points 1 year ago

… why post a png?
Link to the service

[–] [email protected] 1 points 1 year ago* (last edited 1 year ago)
[–] [email protected] 4 points 1 year ago* (last edited 1 year ago) (1 children)
[–] MigratingtoLemmy 1 points 1 year ago

We need to use some tool. If the government doesn't have your private key, they can't decrypt your messages. I don't care how that is implemented, but companies like Signal will either fight to the death or bow out

[–] Asudox 2 points 1 year ago (1 children)

Basically P2P. The government can't do shit about them.

[–] [email protected] -2 points 1 year ago

Longest shower though I’ve seen for a while. While you seem somewhat clueless in what you talk about you manage to fit in many cool words. That’s a plus.