Remix.run Logo
throw0101a 4 hours ago

Signal, Apple iMessage, and WhatsApp have to announce at some point that they will simply stop providing services to any country/region that insists on breaking E2EE. All you'll be left with is unencrypted RCS.

It's a bit of a 'nuclear option', but at the end of the day, once one jurisdiction forces them to break the math, every other one will as well.

IMHO, it's the only way to force the proponent(s) of these proposal(s) to see the folly of their ways (and it's no guarantee that they will).

VorpalWay 3 hours ago | parent | next [-]

There are peer to peer (or otherwise decentralised, e.g. multiple servers operated by many different people) alternatives to Signal. I haven't tried any of them, nor do I know which ones have been audited. But if the worst comes to the worst, there are alternatives that are hard to block.

In particular I remember reading about DeltaChat which piggiebacks on normal email infrastructure, making it really hard to block without massive collateral damage.

Neikius an hour ago | parent [-]

Been using matrix for years now. Even operating a server for a small community. It is slightly more involved for regular users though so that is not the best but otherwise works. Setting up your own federated instance is quite simple, there is an Ansible playbook around to make it even easier. You could even isolate it and have it only for your org. From what I know there is some traction to get it adopted in a bunch of agencies eu-wide.

microtonal 4 hours ago | parent | prev | next [-]

FWIW, iMessage is largely unencrypted already. Yes, the messages themselves are E2E encrypted, but most people do not enable Advanced Data Protection, but do enable iCloud Backups, which causes messages only to be encrypted at-rest with keys that Apple holds [1]. And even if you enable ADP, most people that you communicate with didn't.

A similar situation applies to WhatsApp. On iPhone, the messages are stored in iCloud Backups. On Android they can be backed up to Google Drive but E2E encryption is not the default.

The only exception is Signal, which opts out of iCloud and Android backups and had to roll their own backup solution for E2E backups.

So in practice, US law enforcement can probably already access iMessage/WhatsApp messages.

[1] See footnote 9: https://support.apple.com/en-us/102651

Hizonner 5 minutes ago | parent | prev | next [-]

> IMHO, it's the only way to force the proponent(s) of these proposal(s) to see the folly of their ways (and it's no guarantee that they will).

I'm pretty sure they'd see it as a win, at least unless it led to massive public backlash. So why not skip that step and just give them the backlash?

jbstack 4 hours ago | parent | prev | next [-]

As someone who uses Signal and WhatsApp, I would be extremely happy if those companies blocked access in my jurisdiction if such laws are implemented. In fact, if they agreed to insert backdoor access I would never trust them again, even if they subsequently reversed it.

We have to be willing to suffer personal inconveniences to stand up to these types of policies.

inigyou 2 hours ago | parent | prev | next [-]

They don't have to. Signal, in particular, since it's not connected to massive revenue streams, can just wait to see if the country blocks it.

burnerthrow008 4 hours ago | parent | prev | next [-]

Sorry, maybe I'm dumb. Why would "gatekeepers" poke the bear?

rdm_blackhole 3 hours ago | parent | prev [-]

There was already a tweet/post from the Signal CEO in which she said that if the Chat Control v2 law was enforced (aka client side scanning of messages before encryption), that they would simply leave the EU market instead of complying.