Live data from Hacker News

Edward Snowden at IETF 93

gist.github.com

61–70 of 145 posts

Re: Edward Snowden at IETF 93

#61
post #34

Earlier quoted context omitted.

This is a weird response to a comment that quotes Snowden at length providing technical advice to the IETF.

From the screening arranger's words: https://www.mnot.net/blog/2015/07/20/snowden_meets_the_ietf It’s important to point out that this was NOT an official IETF event, and neither was it giving external advocacy organisations a stage (as some have intimated); rather, it was entirely an effort of individuals, working within the rules for requesting a room at IETF meetings.

I do not recognize the significance of "official" versus "unofficial" IETF events. I don't think there's a meaningful distinction to be made between them. Anyone in the world can show up to an "official" event, or participate in the mailing lists. That's a good thing, but it also means that "unofficial" advocacy and advice is as important as the "official" kind.

Re: Edward Snowden at IETF 93

#62
post #40
post #34

Earlier quoted context omitted.

This is a weird response to a comment that quotes Snowden at length providing technical advice to the IETF.

I wouldn't say that Snowden was intending to provide technical (or specifically cryptographic) advice in this Q&A. I would compare it to a power user giving feedback to the engineers working on improving their software. What he brings to the table in discussions like this is basically having worked with people on surveillance projects. He knows how they operate and where they'd look for attack vectors. I think that's…

His support isn't lukewarm. Also: now, when DNSSEC is almost dead, is the most important time to ensure that it actually becomes fully dead. It's like a zombie. You have to cut off the head and burn the body. DNSSEC is still intact and twitching.

Re: Edward Snowden at IETF 93

#63
post #61

Earlier quoted context omitted.

From the screening arranger's words: https://www.mnot.net/blog/2015/07/20/snowden_meets_the_ietf It’s important to point out that this was NOT an official IETF event, and neither was it giving external advocacy organisations a stage (as some have intimated); rather, it was entirely an effort of individuals, working within the rules for requesting a room at IETF meetings.

I do not recognize the significance of "official" versus "unofficial" IETF events. I don't think there's a meaningful distinction to be made between them. Anyone in the world can show up to an "official" event, or participate in the mailing lists. That's a good thing, but it also means that "unofficial" advocacy and advice is as important as the "official" kind.

The real point is that no advice or consultation was being made, it was purely opinion-based commentary. There is no reason to believe it will affect WG charter, and in fact The Tao of IETF explicitly notes that face-to-face WG meetings aren't of high significance to the actual WG's charter. Snowden recommending DNSSEC isn't going to suddenly suspend all rational judgment in those circles.

Re: Edward Snowden at IETF 93

#64
post #60

Earlier quoted context omitted.

> No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments. Fair enough, my knowledge of DNSSEC is limited. I thought it provided confidentiality in addition to authentication, but I see I was mi…

I wrote a long piece that says everything I'd say in a comment here: http://sockpuppet.org/blog/2015/01/15/against-dnssec/

Thanks, that was a good read, and cleared up a lot of misunderstanding I had about DNSSEC!

You make a strong argument that DNSSEC cannot deliver any real advantages. I did not see anything to support your earlier statement that it's worse than nothing, but given the general uselessness of the protocol, I certainly won't be deploying it.

Re: Edward Snowden at IETF 93

#65

Ed's views on Bitcoin are a little surprising. I'm not sure what he means by "nobody likes to talk about Bitcoin any more". It's not that old! One of the problems Bitcoin solves is that you cannot have personas or unlinked identities in the traditional financial system. Governments, and therefore the banks they control, all view financial privacy or pseudonymity as only useful for criminals. That's a rather narrow vi…

Bitcoin does not solve this problem; you can follow the money from the exchange to the consumer's wallet to the merchant. It's only anonymous if you're using a tumbling service, and transferring your money to a tumbling service is an unambiguous broadcast to the entire world that you are committing the federal crime of money laundering. If they ever increase in popularity, you can bet that regulators will routinely trace transfers to tumbling services and prosecute their users for money laundering, because that is what they're doing.

Re: Edward Snowden at IETF 93

#66
post #62
post #40

Earlier quoted context omitted.

I wouldn't say that Snowden was intending to provide technical (or specifically cryptographic) advice in this Q&A. I would compare it to a power user giving feedback to the engineers working on improving their software. What he brings to the table in discussions like this is basically having worked with people on surveillance projects. He knows how they operate and where they'd look for attack vectors. I think that's…

His support isn't lukewarm. Also: now, when DNSSEC is almost dead, is the most important time to ensure that it actually becomes fully dead. It's like a zombie. You have to cut off the head and burn the body. DNSSEC is still intact and twitching.

I wouldn't classify statements like "we gotta start somewhere and then we've got to iterate from that point" or "It's better than what we have today" as a call to action to drop everything and start implementing DNSSEC as-is right away. I would interpret it as "yes, DNSSEC improves the situation in that it provides authenticated DNS replies (which - by itself - is an improvement, even though it's no magic wand that, alone, solves the cert trust issue), but there are legitimate concerns that need to be taken care of before it becomes really useful."

Re: Edward Snowden at IETF 93

#67

Ed's views on Bitcoin are a little surprising. I'm not sure what he means by "nobody likes to talk about Bitcoin any more". It's not that old! One of the problems Bitcoin solves is that you cannot have personas or unlinked identities in the traditional financial system. Governments, and therefore the banks they control, all view financial privacy or pseudonymity as only useful for criminals. That's a rather narrow vi…

Bitcoin isn't just "anonymous cash", it comes with very real-life tradeoffs. A hash might be anonymous, but if you are ever linked with it, all of your transactions are public.

Re: Edward Snowden at IETF 93

#68
post #61

Earlier quoted context omitted.

I do not recognize the significance of "official" versus "unofficial" IETF events. I don't think there's a meaningful distinction to be made between them. Anyone in the world can show up to an "official" event, or participate in the mailing lists. That's a good thing, but it also means that "unofficial" advocacy and advice is as important as the "official" kind.

The real point is that no advice or consultation was being made, it was purely opinion-based commentary. There is no reason to believe it will affect WG charter, and in fact The Tao of IETF explicitly notes that face-to-face WG meetings aren't of high significance to the actual WG's charter. Snowden recommending DNSSEC isn't going to suddenly suspend all rational judgment in those circles.

If you spend some quality time reading IETF mailing lists, you'll learn that it's all "opinion-based commentary". I'm a little confused as to what your argument here is. The IETF works by means of people persuading other people to support proposals. That's the entire mechanism.

Re: Edward Snowden at IETF 93

#69
post #66
post #62

Earlier quoted context omitted.

His support isn't lukewarm. Also: now, when DNSSEC is almost dead, is the most important time to ensure that it actually becomes fully dead. It's like a zombie. You have to cut off the head and burn the body. DNSSEC is still intact and twitching.

I wouldn't classify statements like "we gotta start somewhere and then we've got to iterate from that point" or "It's better than what we have today" as a call to action to drop everything and start implementing DNSSEC as-is right away. I would interpret it as "yes, DNSSEC improves the situation in that it provides authenticated DNS replies (which - by itself - is an improvement, even though it's no magic wand that,…

"DNSSEC improves the situation" is (a) false and (b) a concession to the narrative that DNSSEC is worth doing.

Someone actively engaged in trying to prevent centralization of Internet trust, and decoupling it from the Five Eyes governments --- a worthy goal, I think --- should be adamantly against DNSSEC. But here's Snowden doing the opposite.

It's not because Snowden is disingenuous. I think he's a true-believer. It's because he doesn't understand DNSSEC.

Re: Edward Snowden at IETF 93

#70

Ed's views on Bitcoin are a little surprising. I'm not sure what he means by "nobody likes to talk about Bitcoin any more". It's not that old! One of the problems Bitcoin solves is that you cannot have personas or unlinked identities in the traditional financial system. Governments, and therefore the banks they control, all view financial privacy or pseudonymity as only useful for criminals. That's a rather narrow vi…

Bitcoin does not solve this problem; you can follow the money from the exchange to the consumer's wallet to the merchant. It's only anonymous if you're using a tumbling service, and transferring your money to a tumbling service is an unambiguous broadcast to the entire world that you are committing the federal crime of money laundering. If they ever increase in popularity, you can bet that regulators will routinely t…

A good paper on this point "A Fistful of Bitcoins": https://cseweb.ucsd.edu/~smeiklejohn/files/imc13.pdf
Post reply on HN