this post was submitted on 04 Dec 2024
629 points (99.5% liked)

Technology

59958 readers
3402 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 48 points 1 week ago (2 children)

From RFC 2804:

  • The IETF believes that adding a requirement for wiretapping will make affected protocol designs considerably more complex. Experience has shown that complexity almost inevitably jeopardizes the security of communications even when it is not being tapped by any legal means; there are also obvious risks raised by having to protect the access to the wiretap. This is in conflict with the goal of freedom from security loopholes.

https://datatracker.ietf.org/doc/rfc2804/

This was written in 2000 in response to US government requests to add backdoors to voice-over-IP (VoIP) standards.

It was recognized 25 years ago that having tapping capabilities is fundamentally insecure.

[–] sugar_in_your_tea 12 points 1 week ago (1 children)

You don't need technical knowledge to see the problem.

If you live in an apartment and your landlord has a master key, then all an attacker needs to do is get that master key. In an apartment complex, maybe that's okay because who's going to break in to the landlord's office? But on the internet, tons of people are trying to break in every day, and eventually someone will get the key.

Even for the landlord, I'd rather them have a copy of my key than a master key, because that way they'd need to steal my key specifically.

[–] [email protected] 7 points 1 week ago

And I had one experience where our landlords attempted to rob us.

[–] [email protected] 6 points 1 week ago

It was always recognized.

Every time I go to the Interwebs and read what people have to say on security, it's always the same high horse absolutism.

I've read Attwood's book on Asperger's syndrome a couple weeks ago. There such absolutism was mentioned as a natural trait of aspies, but one that, when applied to social power dynamics or any military logic, gets you assroped in jail.

People who want to spy on you or read all your communications understand too that general security suffers, but just not having that power is out of question for them, and also with the power they already have the security effect on them personally won't be too big.

It's a social problem of the concept of personal freedom being vilified in the Western world via association with organized crime, terrorism, anarchism, you get the idea.

It's not hard to see that the pattern here is that these things are chosen because they challenge state's authority and power, because, well, subsets of what's called organized crime and terrorism that can be prevented by surveillance are not what people generally consider bad, and anarchism is not something bad in any form.

What's more important, people called that do not need to challenge the state if the state is functional, as in - representative, not oppressive and not a tool for some groups to hurt other groups.

As we've seen in all the world history, what's called organized crime and what's called terrorism are necessary sometimes to resolve deadlocks in a society. It has never happened in history that a society could function by its formalized laws for long without breaking consistency of those. And it has never happened that an oppressed group\ideology\movement would be able to make its case in accordance with the laws made by its oppressor.

Why I'm typing all this - it's not a technical problem. It's a problem of bad people who should be afraid not being afraid and thus acting, and good people who should be afraid not being afraid and thus not acting.