Live data from Hacker News

Edward Snowden at IETF 93

gist.github.com

31–40 of 145 posts

Re: Edward Snowden at IETF 93

#31
post #17

When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…

there is very little evidence that Snowden is qualified to advise anyone on cryptographic security

I think you're poisoning the well here. I haven't seen anyone suggest we should use Snowden as a technical advisor or anything of the sort.

Re: Edward Snowden at IETF 93

#32
post #17

When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…

there is very little evidence that Snowden is qualified to advise anyone on cryptographic security I think you're poisoning the well here. I haven't seen anyone suggest we should use Snowden as a technical advisor or anything of the sort.

Then why is he advising the IETF? :)

Re: Edward Snowden at IETF 93

#33

I think it's a shame how mainstream media suggests that Snowden is a "coward" for not "coming home to face his charges." It's clear that he released confidential docs to reporters and this would be incredibly easy to prove in court, thereby landing him in prison for the rest of his life. I don't know any sane person that would surrender to this type of treatment, considering that he wouldn't be able to defend his act…

Releasing sensitive information concerning international information collection under the premises of releasing "domestic spying". He said he would only release domestic related information? What happened. Not true. Wake up people he was the best Russian sleeper agent to date.

You can Run ED but you can't hide.

Re: Edward Snowden at IETF 93

#34
post #17

When asked about DNSSEC, which is a forklift upgrade of a core Internet protocol that has the deliberate effect of giving NSA and GCHQ control of TLS keys for hosts in .COM, .UK, .NET, .ORG, and .IO, this was Snowden's answer: Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. No…

there is very little evidence that Snowden is qualified to advise anyone on cryptographic security I think you're poisoning the well here. I haven't seen anyone suggest we should use Snowden as a technical advisor or anything of the sort.

This is a weird response to a comment that quotes Snowden at length providing technical advice to the IETF.

Re: Edward Snowden at IETF 93

#35

I'm always struck by the strange cognitive dissonance US law has for corporate whistleblowers vs governmental whistleblowers. How can you recognize the value of one while dismissing the value of the other? It's not like a whistleblower defense is a get-out-of-jail-free card either, as you must prove that what you did was actually in the public interest. It's a shame that there's no movement for reform in this area, b…

This doesn't strike me as cognitive dissonance. From the government's perspective, Snowden didn't reveal illegal activity and so is not a whistleblower.

The bulk collection of phone metadata (which he exposed) was subsequently ruled unlawful: http://www.theguardian.com/us-news/2015/may/07/nsa-phone-rec...

Re: Edward Snowden at IETF 93

#36
post #34

Earlier quoted context omitted.

there is very little evidence that Snowden is qualified to advise anyone on cryptographic security I think you're poisoning the well here. I haven't seen anyone suggest we should use Snowden as a technical advisor or anything of the sort.

This is a weird response to a comment that quotes Snowden at length providing technical advice to the IETF.

From the screening arranger's words:

https://www.mnot.net/blog/2015/07/20/snowden_meets_the_ietf

   It’s important to point out that this was NOT an official
   IETF event, and neither was it giving external advocacy
   organisations a stage (as some have intimated); rather,
   it was entirely an effort of individuals, working within
   the rules for requesting a room at IETF meetings.

Re: Edward Snowden at IETF 93

#37

Earlier quoted context omitted.

The current situation is that anyone can read DNS. If DNSSEC and DANE were implemented, that group would be restricted. In that sense it's better than the status quo, though admittedly only a little bit. I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandm…

This is my wish list: * DNSCurve * Certificate Transparency * TACK * HPKP headers * HSTS headers * TLS 1.2 minimum * EdDSA TLS certificates (Ed25519 / Ed448-Goldilocks) Implement all of the above, and you've obsoleted any argument that DNSSEC advocates can make. Most of the people who I've seen advocate for DNSSEC are graybeard traditionalists who want centralized control, not cryptographers or security experts. A de…

> Implement all of the above, and you've obsoleted any argument that DNSSEC advocates can make.

Still no offline signatures.

How is it that centralized control is worse than the TLS's "everybody has full power to impersonate you" decentralization? You know that Certificate Transparency is still subject to MITM attacks, right? It just makes it obvious that you were victim of one after the fact (if there is an "after the fact").

Re: Edward Snowden at IETF 93

#38
The internet doesn't belong to vendors. The internet doesn't belong to governments.

The internet belongs to the user, right?

The thing is, this is literally false. The infrastructure of the internet is paid for by governments and vendors. A user wouldn't be called a user if it belonged to them...

The internet is a great decentralization when compared to traditional media like television, but it's not nearly as big a difference as people make it seem. With how most people use it it's not far from just having more channels on your existing cable box.

Re: Edward Snowden at IETF 93

#39
post #35

Earlier quoted context omitted.

This doesn't strike me as cognitive dissonance. From the government's perspective, Snowden didn't reveal illegal activity and so is not a whistleblower.

The bulk collection of phone metadata (which he exposed) was subsequently ruled unlawful: http://www.theguardian.com/us-news/2015/may/07/nsa-phone-rec...

That's great and all, but what about the other one million+ documents he absconded with not related to the phone metadata record collection?

At what point does he cease being a whistle blower?

Re: Edward Snowden at IETF 93

#40
post #34

Earlier quoted context omitted.

there is very little evidence that Snowden is qualified to advise anyone on cryptographic security I think you're poisoning the well here. I haven't seen anyone suggest we should use Snowden as a technical advisor or anything of the sort.

This is a weird response to a comment that quotes Snowden at length providing technical advice to the IETF.

I wouldn't say that Snowden was intending to provide technical (or specifically cryptographic) advice in this Q&A. I would compare it to a power user giving feedback to the engineers working on improving their software.

What he brings to the table in discussions like this is basically having worked with people on surveillance projects. He knows how they operate and where they'd look for attack vectors. I think that's valuable when you have to think about designing any system with any kind of security requirements.

He literally stated himself that what he says shouldn't be accepted as gospel, and in a later question about MITM specifically confirmed that it's not his area of expertise. I don't think there's any risk of people suddenly jumping on the DNSSEC bandwagon just because of his lukewarm support.

Post reply on HN