Live data from Hacker News

Edward Snowden at IETF 93

gist.github.com

51–60 of 145 posts

Re: Edward Snowden at IETF 93

#51

I think it's a shame how mainstream media suggests that Snowden is a "coward" for not "coming home to face his charges." It's clear that he released confidential docs to reporters and this would be incredibly easy to prove in court, thereby landing him in prison for the rest of his life. I don't know any sane person that would surrender to this type of treatment, considering that he wouldn't be able to defend his act…

Agreed, did you see https://petitions.whitehouse.gov/petition/pardon-edward-snow... > If he felt his actions were consistent with civil disobedience, then he should do what those who have taken issue with their own government do: Challenge it, speak out, engage in a constructive act of protest, and -- importantly -- accept the consequences of his actions. He should come home to the United States, and be judged by a j…

Not just prison, the "Espionage Act of 1917", which is he charged with, has death penalty as a possible punishment.

And it is pretty clear that he is guilty of this law. Not much room for whistleblowers in a wartime law.

Re: Edward Snowden at IETF 93

#52

Earlier quoted context omitted.

This is my wish list: * DNSCurve * Certificate Transparency * TACK * HPKP headers * HSTS headers * TLS 1.2 minimum * EdDSA TLS certificates (Ed25519 / Ed448-Goldilocks) Implement all of the above, and you've obsoleted any argument that DNSSEC advocates can make. Most of the people who I've seen advocate for DNSSEC are graybeard traditionalists who want centralized control, not cryptographers or security experts. A de…

> Implement all of the above, and you've obsoleted any argument that DNSSEC advocates can make. Still no offline signatures. How is it that centralized control is worse than the TLS's "everybody has full power to impersonate you" decentralization? You know that Certificate Transparency is still subject to MITM attacks, right? It just makes it obvious that you were victim of one after the fact (if there is an "after t…

You can have offline signatures in a design for a Stellar/Namecoin/EdDSA decentralized protocol.

> How is it that centralized control is worse than the TLS's "everybody has full power to impersonate you" decentralization? You know that Certificate Transparency is still subject to MITM attacks, right? It just makes it obvious that you were victim of one after the fact (if there is an "after the fact").

This is non sequitur. You're comparing a bad option where only a few can screw you over (DNSSEC) with a bad option where lots can screw you over (CAs).

I want a protocol where no one can screw you over, except yourself. And I want the government to be powerless to do anything about it without your consent. And if it function with high anonymity (e.g. with Tor Hidden Services on servers purchased with cryptocurrencies), all the better.

Re: Edward Snowden at IETF 93

#53

Earlier quoted context omitted.

Agreed, did you see https://petitions.whitehouse.gov/petition/pardon-edward-snow... > If he felt his actions were consistent with civil disobedience, then he should do what those who have taken issue with their own government do: Challenge it, speak out, engage in a constructive act of protest, and -- importantly -- accept the consequences of his actions. He should come home to the United States, and be judged by a j…

Not just prison, the "Espionage Act of 1917", which is he charged with, has death penalty as a possible punishment. And it is pretty clear that he is guilty of this law. Not much room for whistleblowers in a wartime law.

Good point. I assumed prison was the most likely outcome if he came back, but you're right, it is possible that he could receive the death penalty. Granted, I doubt the government would use the death penalty to prevent him from going down as a "martyr."

Re: Edward Snowden at IETF 93

#54

Earlier quoted context omitted.

Agreed, did you see https://petitions.whitehouse.gov/petition/pardon-edward-snow... > If he felt his actions were consistent with civil disobedience, then he should do what those who have taken issue with their own government do: Challenge it, speak out, engage in a constructive act of protest, and -- importantly -- accept the consequences of his actions. He should come home to the United States, and be judged by a j…

Exactly! I did see the response to the petition and thought the exact same thing. The government is pretty much saying, "We know what you did was just. But you broke the law, so come back to suffer in federal prison." "In the land of the free and the home of the brave..." Haha. Ed Snowden is brave and we are freer as Americans knowing what the government is capable of when it comes to electronic surveillance.

Are we ? The mass Internet surveillance by the u.s. gov was known well before snowden [1], albeit the specific actors were not. Post snowden I've seen public outcry lead to a destabilization of NSA meanwhile private corporations are collecting more data than ever--is this really freer?

[1] https://en.m.wikipedia.org/wiki/Room_641A

Re: Edward Snowden at IETF 93

#55
post #24

Earlier quoted context omitted.

The current situation is that anyone can read DNS. If DNSSEC and DANE were implemented, that group would be restricted. In that sense it's better than the status quo, though admittedly only a little bit. I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandm…

No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments. DNSSEC isn't an imperfect protocol; it's harmful, a net loss. And here we have Snowden twice advocating for it.

DNSSEC is not DANE. All DNSSEC does is prevent MITM injection of DNS packets which is almost certainly one of the techniques QUANTUM INSERT uses. So no surprise he thinks DNS should be hardened against it.

And as Chrome experimented with DANE then removed support for it, I don't think you have to worry about that either.

But even if you did - so what? There are CAs in areas controlled by the American and British and French and Chinese governments already. I don't see how it makes anything different.

Re: Edward Snowden at IETF 93

#56
Ed's views on Bitcoin are a little surprising. I'm not sure what he means by "nobody likes to talk about Bitcoin any more". It's not that old!

One of the problems Bitcoin solves is that you cannot have personas or unlinked identities in the traditional financial system. Governments, and therefore the banks they control, all view financial privacy or pseudonymity as only useful for criminals. That's a rather narrow viewpoint. Especially as the notion of "criminal" becomes more divergent between ordinary citizens and their rulers. There's some truth to it (anonymity does sometimes enable bad stuff), but it's excessively black and white.

Regardless, given that Snowden views payment methods and such as being very important, he even brought that up himself, I don't know how else he thinks it can be done, other than with Bitcoin. If you try and create a payment method that has privacy the banks won't give you the time of day. Being completely decentralised and independent is the only way to do money that exists outside of the status quo.

Re: Edward Snowden at IETF 93

#57

Earlier quoted context omitted.

Exactly! I did see the response to the petition and thought the exact same thing. The government is pretty much saying, "We know what you did was just. But you broke the law, so come back to suffer in federal prison." "In the land of the free and the home of the brave..." Haha. Ed Snowden is brave and we are freer as Americans knowing what the government is capable of when it comes to electronic surveillance.

Are we ? The mass Internet surveillance by the u.s. gov was known well before snowden [1], albeit the specific actors were not. Post snowden I've seen public outcry lead to a destabilization of NSA meanwhile private corporations are collecting more data than ever--is this really freer? [1] https://en.m.wikipedia.org/wiki/Room_641A

Awesome point. When I used the term "freer" I was suggesting that we were freer because even laypeople now KNOW about electronic surveillance practices. But I'm not sure we are actually "free" in any sense of the word, we just know we are constantly being watched. The reality is complicated and unfortunate. Words like "free" or "freedom" will sadly never be appropriate.

Re: Edward Snowden at IETF 93

#58
post #24

Earlier quoted context omitted.

The current situation is that anyone can read DNS. If DNSSEC and DANE were implemented, that group would be restricted. In that sense it's better than the status quo, though admittedly only a little bit. I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandm…

No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments. DNSSEC isn't an imperfect protocol; it's harmful, a net loss. And here we have Snowden twice advocating for it.

> No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments.

Fair enough, my knowledge of DNSSEC is limited. I thought it provided confidentiality in addition to authentication, but I see I was mistaken.

I'm still not sure how you arrive at the conclusion that it is a net loss. Which attacks will DNSSEC enable that are not possible today? If you mean that it will give people a false sense of security, is that not the same as TLS today? Despite my hangups with the CA system I think we're better off with TLS than without it.

The NSA certainly has no problems with intercepting DNS requests today with their QUANTUM tools.

I am genuinely interested in hearing other ideas about how to provide confidentiality and authentication for DNS without central trust. Since you have clearly investigated these matters, I would like to ask again, are you aware of any promising projects or ideas in this regard? Because I would jump into the anti-DNSSEC camp in a heartbeat if one existed.

Re: Edward Snowden at IETF 93

#59
post #24

Earlier quoted context omitted.

No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments. DNSSEC isn't an imperfect protocol; it's harmful, a net loss. And here we have Snowden twice advocating for it.

DNSSEC is not DANE. All DNSSEC does is prevent MITM injection of DNS packets which is almost certainly one of the techniques QUANTUM INSERT uses. So no surprise he thinks DNS should be hardened against it. And as Chrome experimented with DANE then removed support for it, I don't think you have to worry about that either. But even if you did - so what? There are CAs in areas controlled by the American and British and…

1. He's the one who brought up DANE.

2. DNSSEC is harmful for reasons that go past DANE.

3. I am worried about DNSSEC; I think it's a more reasonable thing to be worried about w/r/t/ surveillance than 95% of what's been posted to The Intercept.

4. QUANTUM INSERT will work fine in an all-DNSSEC world.

5. You can revoke a CA. It has happened more than once. You can't revoke a TLD.

I'm happy to talk more about how I think DANE CAs are different and worse than the 20391 X509 CAs we have today, but I'm not sure you're asking me to go on at length about that.

Re: Edward Snowden at IETF 93

#60
post #24

Earlier quoted context omitted.

No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments. DNSSEC isn't an imperfect protocol; it's harmful, a net loss. And here we have Snowden twice advocating for it.

> No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments. Fair enough, my knowledge of DNSSEC is limited. I thought it provided confidentiality in addition to authentication, but I see I was mi…

I wrote a long piece that says everything I'd say in a comment here:

http://sockpuppet.org/blog/2015/01/15/against-dnssec/

Post reply on HN