Live data from Hacker News

Edward Snowden at IETF 93

gist.github.com

11–20 of 145 posts

Re: Edward Snowden at IETF 93

#11
post #3

I like Snowden's final conclusion: > if the internet and technology does become a danger to us in the future, it's our own fault because we decided not to participate and we let other groups and other influences to decide for us rather than being part of it [...] Before that, he argues that more people should involve themselves more in the IETF and similar groups: > [...] However, when you look at the IETF, they lite…

>>> if the internet and technology does become a danger.

Not sure what his context for this is, but one could easily argue we're already here.

Re: Edward Snowden at IETF 93

#12

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

Law at both federal and state levels (in most states) has fairly strong protection for government whistleblowers in general; the Espionage Act specifically lacks whistleblower provisions, which certainly presents an issue when whistleblowing relates to the kind of defense-related information to which the Espionage Act applies, but that's not indicative of a general approach in law to government whistleblowers.

Re: Edward Snowden at IETF 93

#14

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

> I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers.

It doesn't: there are multiple different programs for reporting perceived illegal activity. Snowden never availed himself of any of these, but instead committed espionage.

Re: Edward Snowden at IETF 93

#15
When Snowden exposed facts about MAC addresses, it's very scary knowing that IoT is coming in our life. I'd like to have a firmware for wireless electronic devices that can use a random MAC address every thirty minutes without using actual spoofing tools that are easy to use only on desktop/laptop/smartphone. I want the same tools for my bluetooth headset, my car wireless devices and so on...

Re: Edward Snowden at IETF 93

#16

Currently this story has 108 points and zero comments. Are people literally scared to comment on Snowden stories?

It could equally be the reverse - that people up-vote such stories based on the headline but don't bother reading or commenting.

Re: Edward Snowden at IETF 93

#17
When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer:

Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. Nobody should trust me. Nobody should grant any sort of outsized weight to what I say.

When I talk about the NSA, I mentioned it in correlation with DANE and the DPRIVE initiative as well because the whole idea is that, yes, providing some mechanism for authentication of the responses between DNS queries is valuable. It's not an end to itself.

We still have to be able to say, "Well, all right, the certificate that you're getting from it, for a server is also reliable," and then we have to actually do more armour the requests themselves to make sure that they don’t become a new vector, they don't become manipulated.

Who knows like if eventually the DNS responses themselves that are provided through this become some sort of vulnerability because of the way they're parsed or whatever, but the whole idea is that we gotta start somewhere and then we've got to iterate from that point.

We've gotta begin building and when I think about things like DNSSEC, I don't think it's the golden age, we can solve all of the problems, but I do think that it's a start. It's better than the status quo. It's better than what we have today

And by getting the community thinking, by coming together and trying to develop some kind of solution, some kind of standard, we can start developing things that will allow us to build a bridge to the next generation of what we need to protect us against the next generation of coming attacks, and there's a lot of things that get in there. I mean cryptographic agility is one of the big hot things that we have to deal with as well.

I can barely follow this at all, but the part where he says DNSSEC is "better than the status quo" is pretty clear. The questioner responds, "so let's implement it".

Please be careful with what Snowden says. Whatever you think of his disclosures --- and most of my friends think they were brave and incredibly useful --- there is very little evidence that Snowden is qualified to advise anyone on cryptographic security, and some pretty significant evidence to the contrary.

Re: Edward Snowden at IETF 93

#19

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

This doesn't strike me as cognitive dissonance. From the government's perspective, Snowden didn't reveal illegal activity and so is not a whistleblower.

Re: Edward Snowden at IETF 93

#20
post #14

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

> I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. It doesn't: there are multiple different programs for reporting perceived illegal activity. Snowden never availed himself of any of these, but instead committed espionage.

> It doesn't: there are multiple different programs for reporting perceived illegal activity. Snowden never availed himself of any of these, but instead committed espionage.

These programs had been used by multiple people before, with no results. They are for show, so that people like you can point to them to show that there's "oversight".

Whistleblowing of the type done by Snowden is a last resort when there is no other option. The options you speak of are not credible avenues for change.

Post reply on HN