Live data from Hacker News

Edward Snowden at IETF 93

gist.github.com

21–30 of 145 posts

Re: Edward Snowden at IETF 93

#22

This is the first time I've read his point of view first hand and actually listened to his presentation. He seems to be incredibly smart and well-versed in his subject domain.

You should take the time and watch the documentary. Its a good perspective of his intentions. You can walk away from it with your own opinions if he did the "right" thing.

Re: Edward Snowden at IETF 93

#23
post #17

When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…

The current situation is that anyone can read DNS. If DNSSEC and DANE were implemented, that group would be restricted. In that sense it's better than the status quo, though admittedly only a little bit.

I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandmother would be likely to use.

Do you have a suggestion for how you would like to see DNS evolve to fix these issues?

Re: Edward Snowden at IETF 93

#24
post #17

When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…

The current situation is that anyone can read DNS. If DNSSEC and DANE were implemented, that group would be restricted. In that sense it's better than the status quo, though admittedly only a little bit. I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandm…

No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments.

DNSSEC isn't an imperfect protocol; it's harmful, a net loss.

And here we have Snowden twice advocating for it.

Re: Edward Snowden at IETF 93

#25

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

This doesn't strike me as cognitive dissonance. From the government's perspective, Snowden didn't reveal illegal activity and so is not a whistleblower.

https://en.wikipedia.org/wiki/Whistleblower

"or threat to public interest"

It doesn't have to be illegal.

Re: Edward Snowden at IETF 93

#26
I think it's a shame how mainstream media suggests that Snowden is a "coward" for not "coming home to face his charges." It's clear that he released confidential docs to reporters and this would be incredibly easy to prove in court, thereby landing him in prison for the rest of his life. I don't know any sane person that would surrender to this type of treatment, considering that he wouldn't be able to defend his actions legally. Stay on the run, Ed. Thank you for releasing this information so that the American public has some idea of the degree to which we are electronically surveilled on a daily basis.

Re: Edward Snowden at IETF 93

#27
post #14

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

> I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. It doesn't: there are multiple different programs for reporting perceived illegal activity. Snowden never availed himself of any of these, but instead committed espionage.

He tried. He found out that because he wasn't a government employee, those programs treated him like shit.[0]

> One of the things that has not been widely reported by journalists is that whistle-blower protection laws in the US do not protect contractors in the national security arena. There are so many holes in the laws, the protections they afford are so weak, and the processes for reporting they provide are so ineffective that they appear to be intended to discourage reporting of even the clearest wrongdoing. If I had revealed what I knew about these unconstitutional but classified programs to Congress, they could have charged me with a felony. One only need to look at the case of Thomas Drake to see how the government doesn't have a good history of handling legitimate reports of wrongdoing within the system.

> Despite this, and despite the fact that I could not legally go to the official channels that direct NSA employees have available to them, I still made tremendous efforts to report these programs to co-workers, supervisors, and anyone with the proper clearance who would listen. The reactions of those I told about the scale of the constitutional violations ranged from deeply concerned to appalled, but no one was willing to risk their jobs, families, and possibly even freedom to go through what Drake did.

[0] http://www.cnet.com/news/snowden-not-all-spying-bad-but-nsa-...

Every time I've been a contractor[1], I've been treated likewise.

[1]never been contracted out to a government agency of any level.

Re: Edward Snowden at IETF 93

#28

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

This doesn't strike me as cognitive dissonance. From the government's perspective, Snowden didn't reveal illegal activity and so is not a whistleblower.

Clapper and Alexander lying to congress is illegal.

Re: Edward Snowden at IETF 93

#29
post #14

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

> I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. It doesn't: there are multiple different programs for reporting perceived illegal activity. Snowden never availed himself of any of these, but instead committed espionage.

The legality shouldn't even be part of the conversation.

Government activity that is fascistic is usually going to be completely legal or made legal once revealed. We saw the government do this with the USA Freedom Act. Before that, they claimed to have authorization under the FISA and PATRIOT Acts. They do not want oversight, and the "abuses" are actually functioning exactly as intended. This is also why they endlessly lie to our faces about what is going on and don't get fired, even when they have been outed repeatedly.

Also, there's the documented fact [0][1] that whistleblowers at the NSA who go through the "proper channels" ultimately gets you fired, ostracized, raided, and prosecuted. So really, it's a non-starter to claim that they should have reported illegal activity.

[0]: https://en.wikipedia.org/wiki/Thomas_Andrews_Drake#Drake_act...

[1]: https://en.wikipedia.org/wiki/William_Binney_%28U.S._intelli...

Re: Edward Snowden at IETF 93

#30
post #17

When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…

The current situation is that anyone can read DNS. If DNSSEC and DANE were implemented, that group would be restricted. In that sense it's better than the status quo, though admittedly only a little bit. I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandm…

This is my wish list:

    * DNSCurve
    * Certificate Transparency
    * TACK
    * HPKP headers
    * HSTS headers
    * TLS 1.2 minimum
    * EdDSA TLS certificates (Ed25519 / Ed448-Goldilocks)
Implement all of the above, and you've obsoleted any argument that DNSSEC advocates can make.

Most of the people who I've seen advocate for DNSSEC are graybeard traditionalists who want centralized control, not cryptographers or security experts.

A decentralized system like Namecoin, but more like Stellar (with EdDSA signatures please) than Bitcoin, would probably serve as an appropriate replacement for DNSSEC. But even that probably isn't necessary. Every sane end-to-end encryption protocol assumes DNS is insecure anyway.

Post reply on HN