Edward Snowden at IETF 93
21–30 of 145 posts
Re: Edward Snowden at IETF 93
#22This is the first time I've read his point of view first hand and actually listened to his presentation. He seems to be incredibly smart and well-versed in his subject domain.
Re: Edward Snowden at IETF 93
#23When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…
I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandmother would be likely to use.
Do you have a suggestion for how you would like to see DNS evolve to fix these issues?
Re: Edward Snowden at IETF 93
#24When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…
The current situation is that anyone can read DNS. If DNSSEC and DANE were implemented, that group would be restricted. In that sense it's better than the status quo, though admittedly only a little bit. I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandm…
DNSSEC isn't an imperfect protocol; it's harmful, a net loss.
And here we have Snowden twice advocating for it.
Re: Edward Snowden at IETF 93
#25I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…
This doesn't strike me as cognitive dissonance. From the government's perspective, Snowden didn't reveal illegal activity and so is not a whistleblower.
"or threat to public interest"
It doesn't have to be illegal.
Re: Edward Snowden at IETF 93
#26Re: Edward Snowden at IETF 93
#27I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…
> I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. It doesn't: there are multiple different programs for reporting perceived illegal activity. Snowden never availed himself of any of these, but instead committed espionage.
> One of the things that has not been widely reported by journalists is that whistle-blower protection laws in the US do not protect contractors in the national security arena. There are so many holes in the laws, the protections they afford are so weak, and the processes for reporting they provide are so ineffective that they appear to be intended to discourage reporting of even the clearest wrongdoing. If I had revealed what I knew about these unconstitutional but classified programs to Congress, they could have charged me with a felony. One only need to look at the case of Thomas Drake to see how the government doesn't have a good history of handling legitimate reports of wrongdoing within the system.
> Despite this, and despite the fact that I could not legally go to the official channels that direct NSA employees have available to them, I still made tremendous efforts to report these programs to co-workers, supervisors, and anyone with the proper clearance who would listen. The reactions of those I told about the scale of the constitutional violations ranged from deeply concerned to appalled, but no one was willing to risk their jobs, families, and possibly even freedom to go through what Drake did.
[0] http://www.cnet.com/news/snowden-not-all-spying-bad-but-nsa-...
Every time I've been a contractor[1], I've been treated likewise.
[1]never been contracted out to a government agency of any level.
Re: Edward Snowden at IETF 93
#28I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…
This doesn't strike me as cognitive dissonance. From the government's perspective, Snowden didn't reveal illegal activity and so is not a whistleblower.
Re: Edward Snowden at IETF 93
#29I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…
> I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. It doesn't: there are multiple different programs for reporting perceived illegal activity. Snowden never availed himself of any of these, but instead committed espionage.
Government activity that is fascistic is usually going to be completely legal or made legal once revealed. We saw the government do this with the USA Freedom Act. Before that, they claimed to have authorization under the FISA and PATRIOT Acts. They do not want oversight, and the "abuses" are actually functioning exactly as intended. This is also why they endlessly lie to our faces about what is going on and don't get fired, even when they have been outed repeatedly.
Also, there's the documented fact [0][1] that whistleblowers at the NSA who go through the "proper channels" ultimately gets you fired, ostracized, raided, and prosecuted. So really, it's a non-starter to claim that they should have reported illegal activity.
[0]: https://en.wikipedia.org/wiki/Thomas_Andrews_Drake#Drake_act...
[1]: https://en.wikipedia.org/wiki/William_Binney_%28U.S._intelli...
Re: Edward Snowden at IETF 93
#30When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…
The current situation is that anyone can read DNS. If DNSSEC and DANE were implemented, that group would be restricted. In that sense it's better than the status quo, though admittedly only a little bit. I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandm…
* DNSCurve
* Certificate Transparency
* TACK
* HPKP headers
* HSTS headers
* TLS 1.2 minimum
* EdDSA TLS certificates (Ed25519 / Ed448-Goldilocks)
Implement all of the above, and you've obsoleted any argument that DNSSEC advocates can make.Most of the people who I've seen advocate for DNSSEC are graybeard traditionalists who want centralized control, not cryptographers or security experts.
A decentralized system like Namecoin, but more like Stellar (with EdDSA signatures please) than Bitcoin, would probably serve as an appropriate replacement for DNSSEC. But even that probably isn't necessary. Every sane end-to-end encryption protocol assumes DNS is insecure anyway.