Live data from Hacker News

Encryption is a necessity

blog.mozilla.org

51–60 of 70 posts

Re: Encryption is a necessity

#51
post #37

Earlier quoted context omitted.

Transparency is necessary for security. Full transparency requires free/libre software---we need both transparency for the implementation, and transparency for integration into the system as a whole (and, as it follows, the whole system). Even if the system purports to be secure, that doesn't necessarily mean that it hasn't been tampered with, or that a backdoor hasn't been installed---we've had a number of examples…

I understand the general argument about transparency - without it you have to trust the person who holds hidden component. The false premise here is that any argument that can be applied against free software can be applied more strongly to non-free software. Here are two contradictions to that: 1. The resources dedicated to securing non-free software may be far greater than those dedicated to free software because o…

>2. A free system can much more easily be compromised by the injection of cloaked vulnerabilities by actors such as the NSA.

I can't see how that is possibly the case. With a non free system the NSA just has to show up with a national security letter and a gag order and the system is compromised.

With the free system the NSA has to push, or get a submitter to push an update that gets missed by anybody that looks at the code.

Re: Encryption is a necessity

#52
post #17

Earlier quoted context omitted.

You don't have another do you? I've been waiting for my invite for over a year now. :-/

Sorry I just saw your reply. Glad you got one. I still have a bunch more, if anyone else wants them.

I would love one, if you still have any left.

Re: Encryption is a necessity

#53
post #37

Earlier quoted context omitted.

Transparency is necessary for security. Full transparency requires free/libre software---we need both transparency for the implementation, and transparency for integration into the system as a whole (and, as it follows, the whole system). Even if the system purports to be secure, that doesn't necessarily mean that it hasn't been tampered with, or that a backdoor hasn't been installed---we've had a number of examples…

I understand the general argument about transparency - without it you have to trust the person who holds hidden component. The false premise here is that any argument that can be applied against free software can be applied more strongly to non-free software. Here are two contradictions to that: 1. The resources dedicated to securing non-free software may be far greater than those dedicated to free software because o…

> The resources dedicated to securing non-free software may be far greater than those dedicated to free software because of the business interests in maintaining security.

My argument is about confidence---you cannot trust a system that you do not have confidence in.

Yes, a proprietary system may have had much more development and research. But that doesn't make it "better". With a free system---even if it's more poorly designed---you gain confidence in being able to observe _exactly_ what it does, faults and all. You know what to expect, and what not to; that's far more important than not knowing either of those.

Further, the general recommendation among cryptographers and security experts is to use public algorithms that have been torn apart by cryptanalysts for years---all security should be in the key, for example, _not_ secrets in the implementation.

> Google has done a lot to improve the security of a variety of open source projects, but only because they form part of a non-free core that would otherwise be compromised. The same holds true for Apple albeit to a lesser extent.

This is security through obscurity, and is antithetical to actual security.

> A free system can much more easily be compromised by the injection of cloaked vulnerabilities by actors such as the NSA.

I don't follow. This is one of those situations where you _always_ have more transparency in a free system than a proprietary one---you are able to see _every_ patch that makes it into the system. That doesn't mean that you'll catch everything, but you have the opportunity to do so. And not just you---everyone.

> You actually haven't shown anything. You have simply stated that transparency trumps everything else. This is false. Transparency simply diffuses the trust model.

You cannot have confidence in an opaque system.

> More importantly, as I keep saying, nobody has ever produced a transparent system that can be substituted for Apple's system. Until they do, these arguments that a theoretical alternative would be better are imaginary. If it was as simple as you suggest, why hasn't it been done, or at least demonstrated?

Which system, in particular?

Apple's system should not be used and cannot be trusted---it is proprietary and designed to control the user in countless ways. Apple may take measures to protect their users' privacy and data, but ultimately, users are at Apple's mercy, and Apple has the final say in everything. Apple is historically one of the most opaque, secretive tech companies in existence.

So any free system is an improvement over Apple's.

Re: Encryption is a necessity

#54
post #50

Earlier quoted context omitted.

Your comment about Signal threw off some thoughts :) I've said before that I think Signal's UX is not great esp compared with other messaging apps. The following just came to me so I'm going to digress for a bit into stream of consciousness. * Signal allows for calling now so why not require a first call to verify the other party. I would think people are pretty good at recognizing voices. * Or send an image and vide…

I find the signal user interface just great. No really, it's fine. Just use it and recommend it to your friends and contacts. Full disclosure, I have no association whatsoever with signal, it's just good.

For example, I hate how the contacts list works. It doesn't show all my contacts, just some. Took me forever to figure out the ones in bold actually have Signal installed. Also, not intuitive that clicking on the name goes to text interface and the phone symbol calls.

Contrast this with the standard Contacts interface. Phone, msg etc. are clearly laid out.

Signal's UX is also confusing with the id being communicated with. For example, if there are multiple numbers, hard to tell which number you are messaging.

These are all little quirks that add up to make it feel much clunkier than other interfaces.

Re: Encryption is a necessity

#55
post #29

Earlier quoted context omitted.

It's a poor video, you're not missing much. Painfully, it suggests "public vs private" hinges on encryption. The implication is that without encryption, your co-workers will see everything you do! Public and private are distinct choices. Things can be private and unencrypted. Lack of encryption means lack of security in the event of a breach, it has nothing to do with choosing public vs private posts and web searches…

Without encryption, anyone on the same network - including your coworkers - can certainly see everything you do. Tools like Firesheep make it dead-simple to do. What you're talking about is encryption of data at rest , which is a specific subset of encryption. And even then, what makes you think the breached data won't be available to your coworkers? The stuff on Ashley Madison certainly did.

There still needs to be a breach, and intent. The video simplifies everything down to the equivalent of shouting your private message across a room when encryption is absent, which it certainly isn't.

If you want to sell encryption, please keep it real. A hand written letter to your mother in the post is private unless intentionally and illegally intercepted. By the logic of the video, the letter is passed along and read by your neighbors before reaching its true destination.

Re: Encryption is a necessity

#56
post #55

Earlier quoted context omitted.

Without encryption, anyone on the same network - including your coworkers - can certainly see everything you do. Tools like Firesheep make it dead-simple to do. What you're talking about is encryption of data at rest , which is a specific subset of encryption. And even then, what makes you think the breached data won't be available to your coworkers? The stuff on Ashley Madison certainly did.

There still needs to be a breach, and intent. The video simplifies everything down to the equivalent of shouting your private message across a room when encryption is absent, which it certainly isn't. If you want to sell encryption, please keep it real. A hand written letter to your mother in the post is private unless intentionally and illegally intercepted. By the logic of the video, the letter is passed along and…

> The video simplifies everything down to the equivalent of shouting your private message across a room when encryption is absent, which it certainly isn't.

Uh, if you're on wifi or a mobile connection, depending on the configuration, it pretty much is exactly like shouting a private message across a room

Re: Encryption is a necessity

#57
post #55

Earlier quoted context omitted.

There still needs to be a breach, and intent. The video simplifies everything down to the equivalent of shouting your private message across a room when encryption is absent, which it certainly isn't. If you want to sell encryption, please keep it real. A hand written letter to your mother in the post is private unless intentionally and illegally intercepted. By the logic of the video, the letter is passed along and…

> The video simplifies everything down to the equivalent of shouting your private message across a room when encryption is absent, which it certainly isn't. Uh, if you're on wifi or a mobile connection, depending on the configuration, it pretty much is exactly like shouting a private message across a room

Except it isn't.

I could press a glass against the wall and listen to people having a private conversation. Does that make their conversation public "like shouting it across the room"? No. Of course it doesn't.

Get your analogies straight.

I could use my zoom lens to spy over your shoulder as you type your message into your super-encrypted phone. I will now publish the video on youtube, your private message now public. Serves you right for "shouting your message across the room".

Re: Encryption is a necessity

#58

Companies should be encouraged to aggressively strengthen the security of their products, rather than undermine that security. On the other hand, I think they should most certainly not be encouraged to secure products against their users: http://www.gnu.org/philosophy/right-to-read.en.html What worries me the most about this seemingly frantic push for more encryption is that it will accelerate the proliferation and a…

You know, someone saw this problem years ahead of the rest of the cs community and started a license to help encourage user freedom. Its just a shame that I see gpl shat on so much in that community. Personally I think RMS is a man ahead of his time, and that history will prove he has the correct view regarding user freedom.

For anyone who cares about the GPL, please financially support GPL enforcement:

https://sfconservancy.org/supporter/

Re: Encryption is a necessity

#59
post #57

Earlier quoted context omitted.

> The video simplifies everything down to the equivalent of shouting your private message across a room when encryption is absent, which it certainly isn't. Uh, if you're on wifi or a mobile connection, depending on the configuration, it pretty much is exactly like shouting a private message across a room

Except it isn't. I could press a glass against the wall and listen to people having a private conversation. Does that make their conversation public "like shouting it across the room"? No. Of course it doesn't. Get your analogies straight. I could use my zoom lens to spy over your shoulder as you type your message into your super-encrypted phone. I will now publish the video on youtube, your private message now publi…

That's not how WiFi works, it's not like a wall or anything. Your device literally "shouts" (transmits in RF) your private message across the room (and into adjoining rooms). Anybody that can connect to the WiFi network (or has a decent machine and half an hour to kill) can read your message (the encryption in WiFi is fucked).

Re: Encryption is a necessity

#60
post #37

Earlier quoted context omitted.

I understand the general argument about transparency - without it you have to trust the person who holds hidden component. The false premise here is that any argument that can be applied against free software can be applied more strongly to non-free software. Here are two contradictions to that: 1. The resources dedicated to securing non-free software may be far greater than those dedicated to free software because o…

> The resources dedicated to securing non-free software may be far greater than those dedicated to free software because of the business interests in maintaining security. My argument is about confidence---you cannot trust a system that you do not have confidence in. Yes, a proprietary system may have had much more development and research. But that doesn't make it "better". With a free system---even if it's more poo…

"Any free system is an improvement over Apple's"

It's hard to take that seriously.

I challenge you to name a single such system. It should be trivial since the class is so large.

Post reply on HN