Live data from Hacker News

It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

27months.com

41–50 of 53 posts

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#41
> ... on vastly more secure servers with every connection under SSL/TLS for end-to-end encryption.

I wish people would stop using the term "end-to-end encryption" to simply mean using encrypted channels. It really does confuse people who have heard that end-to-end is great, but don't actually understand/appreciate the differences between the two.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#42

No advantage hosting in Iceland. Why not just encrypt all data on the VPS? If the VPS provider was required to provide a copy of the VPS, it would be useless to requestor.

Encrypting data on a VPS, for example using LUKS encrypted volumes, does not provide any meaningful security if the host can take a memory dump of the running machine.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#44

I think the author is extremely misguided. 1) Iceland is not a safe harbor from the NSA. Iceland is fully within the U.S. orbit. Iceland, actually does not maintain a standing army and its defense is the responsibility of the U.S. In addition, banking is a significant portion of Iceland's economy, and thus vulnerable to the U.S. cutting of access to SWIFT. Basically, if the U.S. really wants something from Iceland, i…

> Iceland is not a safe harbor from the NSA

A lot of crypto nerds have this fantasy of "NSA-proofing" themselves or their information.

That's near impossible. If the NSA cares enough about someone specifically to use, say, tools from the TAO catalog, they will be able to find out what they want to know. (See http://www.spiegel.de/international/world/a-941262.html ). The FBI also has powerful targeted surveillance tools.

Targeted surveillance is often legitimate, anyway. Authorities have suspicion that someone is, say, planning an attack or running a cartel, or someone is a suspect in murder case. It's good that powerful tool exist to find the truth.

I think the right goal is to stop mass surveillance. Mass surveillance the continuous monitoring of whole populations at a time. Mass surveillance is illegitimate and a threat to liberal democracy.

That leads to a totally different approach. Moving your own personal email server to Iceland does nothing at all to prevent mass surveillance (and honestly doesn't protect you from targeted surveillance either, as others have pointed out).

To roll back mass surveillance, both in the US and around the world, we need tools that are clean and simple and easy to use, even for people who have never heard of a "key" or a "cipher" and don't care what those are. We need to make things like end-to-end encryption, forward secrecy, and metadata security available by default.

Signal and WhatsApp are the biggest success stories so far. Moxie is the boss.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#45

No advantage hosting in Iceland. Why not just encrypt all data on the VPS? If the VPS provider was required to provide a copy of the VPS, it would be useless to requestor.

Encrypting data on a VPS, for example using LUKS encrypted volumes, does not provide any meaningful security if the host can take a memory dump of the running machine.

And just to clarify: taking a memory dump of a virtual machine is trivial. Just click on the 'snapshot' button.

On a physical machine, you have to plug in a dumping device into a DMA-capable port, cool down the RAM and move it to another machine as fast as possible, or reset the machine and boot it from another medium (hoping the BIOS didn't override anything useful). In many jurisdictions you also have better protections in regards to required warrants and such for your own hardware.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#46

No advantage hosting in Iceland. Why not just encrypt all data on the VPS? If the VPS provider was required to provide a copy of the VPS, it would be useless to requestor.

Encrypting data on a VPS, for example using LUKS encrypted volumes, does not provide any meaningful security if the host can take a memory dump of the running machine.

Excellent point. I highly doubt a VPS provider would volunteer a memory dump of a VM when presented with a search warrant for a copy of the VM. Most providers would likely just copy the VM files and call it a day.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#47

Earlier quoted context omitted.

Yes. I was using (al)pine for a while. It's bearable, okay even. But I guess I don't see how you could turn that into a 'mobile' client. For the time I used pine I was ssh-ing into a box of mine for most of the day, while I was in front of a computer. I didn't care much about mail notifications on the go. Now I do. If there's some (reliable! I don't care about the initial one-off effort) way to make that work with em…

But I guess I don't see how you could turn that into a 'mobile' client Solution to this is to remember what the purpose of email actually is. It's supposed to be asynchronous communication, with the expectation that it may be checked, at most, 1-3 times daily. If you need communication immediately and in any location, instant messaging covers that use case much better.

We have to disagree about the purpose here.

For me mail is for async, coherent exchanges. IM is not a replacement: It is usually a conversation, usually short and short-lived and synchronous.

Async doesn't have to imply that I don't get a notification about your mail. It just means that I probably won't answer right away - or at least on my time.

Anyway: Mail plus ~instant~ notification is a thing for me and I don't want to give that up.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#48

Why isn't Switzerland on that list of "safe countries" ?

Ever since .ch violated their own bank secrecy laws to make Uncle Sam happy, they are the same as everyone else in their insatiable quest to please their American masters.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#49
post #10

Hi, Iceland checking in here. While we appreciate you hosting here, we're by no means any safer than other countries now. First I'll note that this posting is from 2013, so quite a bit has changed here since that time. IMMI (immi.is) is still being hashed out in parliaments and making slow progress. Meanwhile we've had some particularly ridiculous public spectacles regarding ppl hosting data here in Iceland thinking…

Thanks for the links. So, what's the word on how much they protect something that's not a crime in Iceland, not proven to be criminal in general (eg crypto app site), and demanded highly by FBI?

Same as any other country I would imagine. If anything we benefit a little further here, since we're so small (pop. 320,000 in total) we tend not to have enough people to do a thorough job of much. Everyone tends to wear several hats. You should be fine, just take necessary technical precautions too, like FDE.

Re: It’s Always Sunny in Reykjavik or How I NSA-Proofed My Email (2013)

#50
post #10

Hi, Iceland checking in here. While we appreciate you hosting here, we're by no means any safer than other countries now. First I'll note that this posting is from 2013, so quite a bit has changed here since that time. IMMI (immi.is) is still being hashed out in parliaments and making slow progress. Meanwhile we've had some particularly ridiculous public spectacles regarding ppl hosting data here in Iceland thinking…

Also from Iceland; can confirm that the Icelandic govt. has taken a 180 on online civil liberties and privacy since the early days of the IMMI, which also never really made it into law.

Well, it goes both ways with that one, the PPI (full disclosure here, I'm one of the founders) is keeping them on constant scrutiny which is good, imho. IMMI status is a mixed bag, the parliamentary committee is still convened however. As of todays date 5 out of 13 law proposals have succeeded. Like all law proposals it takes time and political will.
Post reply on HN