Live data from Hacker News

Edward Snowden: The Internet Is Broken

popsci.com

21–30 of 180 posts

Re: Edward Snowden: The Internet Is Broken

#21

The EFF warned long ago something was going on when AT&T was putting beam splitters on Internet backbones to feed the NSA. Then Snowden revealed how everything is tapped. Then, be sure all mainstream encryption is "NOBUS". Nothing is truly random. Someone somewhere has the master key: elliptic curve cryptography using magic numbers from NIST? "Secure boot" by Intel? OpenSSL? Microsoft software? All backdoored. Trust…

Just possibly old versions of truecrypt. This author's conclusions seem quite sound to me. They collapsed it in a way to comply with a gag order while silently sounding an alarm. https://forum.truecrypt.ch/t/my-analysis-of-what-really-happ... Anyone operating in this space is eventually going to get the same option as Lavabit's founder: compromise or collapse.

If you're super paranoid you shouldn't trust any version of truecrypt. Read the fascinating story of Paul Le Roux...

https://mastermind.atavist.com/

He created E4M (which truecrypt was based on) and is rumored to have been one of the creators of truecrypt. Apparently he's also been a US government asset for a while.

Re: Edward Snowden: The Internet Is Broken

#22
post #10
post #8

Earlier quoted context omitted.

The Dutch for one, whose major ISP Ziggo still does not provide IPv6.

The only cable provider(charter) in northern MI doesn't support IPV6.

The largest provider where I live in Southern California does not support IPv6. The largest cloud providers don't either. Amazon, Google, and Microsoft all lack any IPv6 support at all.

Re: Edward Snowden: The Internet Is Broken

#23

The EFF warned long ago something was going on when AT&T was putting beam splitters on Internet backbones to feed the NSA. Then Snowden revealed how everything is tapped. Then, be sure all mainstream encryption is "NOBUS". Nothing is truly random. Someone somewhere has the master key: elliptic curve cryptography using magic numbers from NIST? "Secure boot" by Intel? OpenSSL? Microsoft software? All backdoored. Trust…

[deleted]

Re: Edward Snowden: The Internet Is Broken

#25
post #22
post #10

Earlier quoted context omitted.

The only cable provider(charter) in northern MI doesn't support IPV6.

The largest provider where I live in Southern California does not support IPv6. The largest cloud providers don't either. Amazon, Google, and Microsoft all lack any IPv6 support at all.

Large cloud providers may have poor IPv6 support, but they do have some support.

For instance, do a DNS lookup on netflix.com. You'll find IPv6 records pointing to Amazon AWS IP space.

Re: Edward Snowden: The Internet Is Broken

#26
post #19
post #16

> But at the same time, we technologists as a class knew academically that these capabilities could be abused, but nobody actually believed they would be abused. Because why would you do that? It seemed so antisocial as a basic concept. I guess so? Not me though. Snowden literally only proved what I had learned on my own. > But we were confronted with documented evidence in 2013 that even what most people would consi…

You knew GCHQ tapped Google's datacenter-to-datacenter links?

http://archive.wired.com/science/discoveries/news/2006/05/70...

This stuff has been going on, and widely discussed, for over a decade. But no one really cared or understood the full scope until Snowden's slapped everyone across the face with it.

Re: Edward Snowden: The Internet Is Broken

#27
post #4

Earlier quoted context omitted.

It's not really ironic - Tor is used for spam all the time.

Just like VPNs, proxies and abuse tolerant networks. If you can't prevent the spam by other means than IP blocking then maybe you should make your website read-only.

It's not exactly difficult to find another IP if the one you're on is blacklisted.

Re: Edward Snowden: The Internet Is Broken

#28
post #16

> But at the same time, we technologists as a class knew academically that these capabilities could be abused, but nobody actually believed they would be abused. Because why would you do that? It seemed so antisocial as a basic concept. I guess so? Not me though. Snowden literally only proved what I had learned on my own. > But we were confronted with documented evidence in 2013 that even what most people would consi…

Foresight has been essential in this.

Without Stallman's foresight of the need for public domain open source software, there would only be proprietary software, all subject to PRISM.

Without the foresight of potential Government's to come the US founding fathers would not have written in such protections as still exist today.

Before Snowden there were many that suspected but now everyone knows.

>Um. Who thought this?

Snowden himself:

"I had too much faith that the government really would do no wrong. I was drinking the Kool-Aid in the post-9/11 moment. I believed the claims of government, that this was a just cause, a moral cause, and we don't need to listen to these people who say we broke this law or that law."

pre Snowden this was unopposable, the NSA's James Clapper lied to Ron Wyden in Congress about mass surveillance.

Re: Edward Snowden: The Internet Is Broken

#29
post #19

Earlier quoted context omitted.

You knew GCHQ tapped Google's datacenter-to-datacenter links?

http://archive.wired.com/science/discoveries/news/2006/05/70... This stuff has been going on, and widely discussed, for over a decade. But no one really cared or understood the full scope until Snowden's slapped everyone across the face with it.

Yeah I know about the AT&T splitters mentioned in the footnotes. But the Snowden leak was a lot bigger than that. Did 0xCMP know that the NSA was recording the full contents of every cell phone call in the Bahamas and keeping them around for at least 30 days?

Re: Edward Snowden: The Internet Is Broken

#30

Earlier quoted context omitted.

Just possibly old versions of truecrypt. This author's conclusions seem quite sound to me. They collapsed it in a way to comply with a gag order while silently sounding an alarm. https://forum.truecrypt.ch/t/my-analysis-of-what-really-happ... Anyone operating in this space is eventually going to get the same option as Lavabit's founder: compromise or collapse.

If you're super paranoid you shouldn't trust any version of truecrypt. Read the fascinating story of Paul Le Roux... https://mastermind.atavist.com/ He created E4M (which truecrypt was based on) and is rumored to have been one of the creators of truecrypt. Apparently he's also been a US government asset for a while.

If you're superparanoid, you should trust that because a superparanoid seemed to build it for himself and open-source it to stick it to the man in his mind. And then built a criminal empire that, if he was still financing it, depended on it for his survival. That's the kind of incentives that get results.
Post reply on HN