Live data from Hacker News

Encryption is a necessity

blog.mozilla.org

31–40 of 70 posts

Re: Encryption is a necessity

#31

Companies should be encouraged to aggressively strengthen the security of their products, rather than undermine that security. On the other hand, I think they should most certainly not be encouraged to secure products against their users: http://www.gnu.org/philosophy/right-to-read.en.html What worries me the most about this seemingly frantic push for more encryption is that it will accelerate the proliferation and a…

Security requires freedom, and cannot be achieved without it. If you don't have the freedom to determine the behavior of your personal computing device, select the ways it is and isn't locked down, control updates to it, and inspect encrypted communications to/from it, that device and your usage of it are insecure.

We should not reinforce the idea that one must sacrifice freedom for security, sacrifice privacy for security, etc. Those are false choices based on fundamentally flawed definitions of "secure" and "security".

Re: Encryption is a necessity

#32

Companies should be encouraged to aggressively strengthen the security of their products, rather than undermine that security. On the other hand, I think they should most certainly not be encouraged to secure products against their users: http://www.gnu.org/philosophy/right-to-read.en.html What worries me the most about this seemingly frantic push for more encryption is that it will accelerate the proliferation and a…

Security requires freedom, and cannot be achieved without it. If you don't have the freedom to determine the behavior of your personal computing device, select the ways it is and isn't locked down, control updates to it, and inspect encrypted communications to/from it, that device and your usage of it are insecure. We should not reinforce the idea that one must sacrifice freedom for security, sacrifice privacy for se…

Until someone develops an actually secure system that has these properties, the 'false choices' are the real choices.

Re: Encryption is a necessity

#33
post #17

Earlier quoted context omitted.

You don't have another do you? I've been waiting for my invite for over a year now. :-/

Sorry I just saw your reply. Glad you got one. I still have a bunch more, if anyone else wants them.

I could definitely use one.

Thanks in any case!

Re: Encryption is a necessity

#34
post #32

Earlier quoted context omitted.

Security requires freedom, and cannot be achieved without it. If you don't have the freedom to determine the behavior of your personal computing device, select the ways it is and isn't locked down, control updates to it, and inspect encrypted communications to/from it, that device and your usage of it are insecure. We should not reinforce the idea that one must sacrifice freedom for security, sacrifice privacy for se…

Until someone develops an actually secure system that has these properties, the 'false choices' are the real choices.

Transparency is necessary for security. Full transparency requires free/libre software---we need both transparency for the implementation, and transparency for integration into the system as a whole (and, as it follows, the whole system).

Even if the system purports to be secure, that doesn't necessarily mean that it hasn't been tampered with, or that a backdoor hasn't been installed---we've had a number of examples of this lately. A fully free, reproducible system is needed here.

There's an often-used argument to dismiss this concept: that free software can still have security bugs. And then they cite recent issues like "Shellshock" and "Heartbleed". Freedom doesn't guarantee security, but it has stronger assurances than proprietary systems, where you don't even have the chance to look at and study it (to any reasonable degree); and you (collectively) definitely aren't able to modify it to suit your specific needs, study its integration with the larger system, or build it reproducibly.

Any other arguments that can be applied against free software can be applied more strongly to non-free software.

Corollary: Confidence in the security of a proprietary, secret system is always less than a free/libre, transparent one, even if the free system is provably less secure overall.

In a fully free system, it is not possible to lock down users, as the OP was concerned, because someone will just modify the software to remove that anti-feature.

Re: Encryption is a necessity

#35
post #17

Earlier quoted context omitted.

You don't have another do you? I've been waiting for my invite for over a year now. :-/

Sorry I just saw your reply. Glad you got one. I still have a bunch more, if anyone else wants them.

I've been itching to try Keybase. Mind sending one my way too?

Re: Encryption is a necessity

#36
post #19

Earlier quoted context omitted.

it's A) Not transparent and B) No longer supported by mozilla.[0] [0] - http://www.zdnet.com/article/mozilla-scraps-thunderbird-deve... !

Why isn't it transparent? Isn't the code open source?

Not transparent to the user. Good security is one you don't have to have a PhD to configure. How much encryption is in iMessage? (Lots) how much did you do to configure it (none)

Transparent encryption (or, encryption for everyone even my mother) is the best way for it to be effective. So when I say transparent. I mean it should not be obvious to the end user and that user should not have to spend significant time configuring it.

Re: Encryption is a necessity

#37
post #32

Earlier quoted context omitted.

Until someone develops an actually secure system that has these properties, the 'false choices' are the real choices.

Transparency is necessary for security. Full transparency requires free/libre software---we need both transparency for the implementation, and transparency for integration into the system as a whole (and, as it follows, the whole system). Even if the system purports to be secure, that doesn't necessarily mean that it hasn't been tampered with, or that a backdoor hasn't been installed---we've had a number of examples…

I understand the general argument about transparency - without it you have to trust the person who holds hidden component.

The false premise here is that any argument that can be applied against free software can be applied more strongly to non-free software. Here are two contradictions to that:

1. The resources dedicated to securing non-free software may be far greater than those dedicated to free software because of the business interests in maintaining security. Google has done a lot to improve the security of a variety of open source projects, but only because they form part of a non-free core that would otherwise be compromised. The same holds true for Apple albeit to a lesser extent.

2. A free system can much more easily be compromised by the injection of cloaked vulnerabilities by actors such as the NSA.

You actually haven't shown anything. You have simply stated that transparency trumps everything else. This is false. Transparency simply diffuses the trust model.

More importantly, as I keep saying, nobody has ever produced a transparent system that can be substituted for Apple's system. Until they do, these arguments that a theoretical alternative would be better are imaginary. If it was as simple as you suggest, why hasn't it been done, or at least demonstrated?

Re: Encryption is a necessity

#38
post #29

Video on a Mozilla page isn't playing on Firefox. Just saying...

It's a poor video, you're not missing much. Painfully, it suggests "public vs private" hinges on encryption. The implication is that without encryption, your co-workers will see everything you do! Public and private are distinct choices. Things can be private and unencrypted. Lack of encryption means lack of security in the event of a breach, it has nothing to do with choosing public vs private posts and web searches…

Without encryption, anyone on the same network - including your coworkers - can certainly see everything you do. Tools like Firesheep make it dead-simple to do.

What you're talking about is encryption of data at rest, which is a specific subset of encryption. And even then, what makes you think the breached data won't be available to your coworkers? The stuff on Ashley Madison certainly did.

Re: Encryption is a necessity

#39
post #35
post #17

Earlier quoted context omitted.

Sorry I just saw your reply. Glad you got one. I still have a bunch more, if anyone else wants them.

I've been itching to try Keybase. Mind sending one my way too?

Sure, but I don't see your email on your profile (the 'email' field is not public, if you want others to see your email, put it in the 'about' section as well).

Re: Encryption is a necessity

#40
post #33
post #17

Earlier quoted context omitted.

Sorry I just saw your reply. Glad you got one. I still have a bunch more, if anyone else wants them.

I could definitely use one. Thanks in any case!

Sure, but I don't see any emails on your profile (the 'email' field is not public, if you want others to see your email, put it in the 'about' section as well).
Post reply on HN