Preferences

I think there is a point to this. I’m not saying I’m a fan. But the reality is that it is too simple to communicate secretly, and the government has an interest in protecting its citizens. This is true in many aspects. (Health, technology, electronics, traffic)

Btw. The https communication comparison does not hold, there is always a third party that can read what you say. E2E chats are effectively communication where evidence is instantly destroyed.

Want to have a private communication, I think offline is the right approach.

I agree that it sucks, but it’s probably not about you. It’s about nefarious people that use this as an uber advantage.


   But the reality is that it is too simple to communicate secretly
This is a horrifying thought to be reading on this site of all places, and I can't help but feel that humanity is well and truly screwed if this mentality has seeped this far into the culture. *Communicating secretly is a human right*. A legal right under international law (ICCPR article 17, ECHR article 8), and a constitutional right in any country worth living in. There can not possibly be such a thing as "too simple to exercise your human right to privacy". It's like asserting that it is too simple to choose your line of work, or that it is too simple to live in the city of your choosing.

  and the government has an interest in protecting its citizens
The government has more than an interest, it has a legal obligation to protecting the human rights of its citizens.
>Btw. The https communication comparison does not hold, there is always a third party that can read what you say. E2E chats are effectively communication where evidence is instantly destroyed.

If I use a third party CA this is correct. But what third party can read communications over HTTPS between a client and a server I control with a self signed SSL cert?

This isn't correct with 3rd party CA's with modern TLS either.

TLSv1.2 has Perfect Forward Secrecy with DHE and ECDHE key exchanges and in TLSv1.3 PFS is mandatory. A compromised root CA or even leaf certificate these days protects you from a man-in-the-middle and not a whole lot else - the certificate private key is never used for session key derivation and the keys themselves are ephemeral and never sent over the wire so even intercepting the key exchange doesn't allow decryption of the stream.

Even if you don't have Forward Secrecy, like you decided to use RSA KEX which is a terrible non-default idea even in 2015 let alone today (this feature isn't even present in TLS 1.3 deliberately, lobbying to keep doing this failed), your private key is still needed so a third party CA can't imitate you.

The CAs have never been supposed to know your private key. For a long time now it's straight up forbidden on pain of removal from trust stores for the CAs to learn somebody else's private keys.

For the example of Let's Encrypt your client probably picks a private key and stores it where your web server can use it, but it never sends this key to anybody else. In fact if you care you can even have the key chosen by the web server and literally never send that key to the Let's Encrypt client at all, the client picks up a "Certificate Signing Request" and it goes OK, I see you want a certificate for some key you know but I don't, that's cool I will go ask Let's Encrypt to issue a certificate for that and let you know.

Not even correct for a third party CA (unless they MITM you).
the problem with current government protecting its citizens by collecting their private communications is the next government having access to this sensitive data.
Yep, the next government may be evil tyranny, but it's beyond my comprehension why would I have to trust current or any government with the data I'm sure they'll abuse the moment they have it.
The regime is counting on people like you.

This item has no comments currently.

Keyboard Shortcuts

Story Lists

j
Next story
k
Previous story
Shift+j
Last story
Shift+k
First story
o Enter
Go to story URL
c
Go to comments
u
Go to author

Navigation

Shift+t
Go to top stories
Shift+n
Go to new stories
Shift+b
Go to best stories
Shift+a
Go to Ask HN
Shift+s
Go to Show HN

Miscellaneous

?
Show this modal